FlawAtlas
Search the atlas
SUSE-SU-2026:3417-1 Not scored

Security update for apptainer

This update for apptainer fixes the following issues: - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266656). - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272115). Changes for apptainer: - Update apptainer to version 1.5.3: * If the ptrace() system call does not work while building an image as an unprivileged user, skip using PRoot to preserve file ownership and print an INFO message. * Bind getopt from the host when using fakeroot command mode, to make the fakeroot command work with base containers which no longer contain getopt by default. * Extended the mksquashfs segmentation fault workaround for cases where mksquashfs uses many processor cores.

Exploit probability Not scored
Published July 30, 2026
Required by Not available
Last source change July 30, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for HPC 15 SP7 apptainer
SUSE:Linux Enterprise Module for Package Hub 15 SP7 apptainer
SUSE:Linux Enterprise Server 15 SP6-LTSS apptainer

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:3417-1

This update for apptainer fixes the following issues: - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266656). - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272115). Changes for apptainer: - Update apptainer to version 1.5.3: * If the ptrace() system call does not work while building an image as an unprivileged user, skip using PRoot to preserve file ownership and print an INFO message. * Bind getopt from the host when using fakeroot command mode, to make the fakeroot command work with base containers which no longer contain getopt by default. * Extended the mksquashfs segmentation fault workaround for cases where mksquashfs uses many processor cores.

View original source

05 / REFERENCES

Further evidence