Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Major Fix for openSUSE Buildah Addressing Container Breakouts 2026-20080-1

opensuse
Calendar Grey January 25, 2026
Dist Opensuse Esm H88
Important update for openSUSE's buildah addressing multiple vulnerabilities, including container breakouts and bug fixes.
An update that solves 5 vulnerabilities and has 3 bug fixes can now be installed.

Description

This update for buildah fixes the following issues:

- CVE-2025-47914: golang.org/x/crypto/ssh/agent: Fixed non validated message size causing a panic due to an out

of bounds read (bsc#1254054)

- CVE-2025-47913: golang.org/x/crypto/ssh/agent: Fixed client process termination when receiving an unexpected

message type in response to a key listing or signing request (bsc#1253598)

- CVE-2025-31133,CVE-2025-52565,CVE-2025-52881: Fixed container breakouts by bypassing runc's restrictions for writing to arbitrary /proc

files (bsc#1253096)

Other fixes:

- Updated to version 1.39.5.

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-169=1

Patch

Package List

- openSUSE Leap 16.0:

buildah-1.39.5-160000.1.1

References

* bsc#1253096

* bsc#1253598

* bsc#1254054

References:

* https://www.suse.com/security/cve/CVE-2025-31133.html

* https://www.suse.com/security/cve/CVE-2025-47913.html

* https://www.suse.com/security/cve/CVE-2025-47914.html

* https://www.suse.com/security/cve/CVE-2025-52565.html

* https://www.suse.com/security/cve/CVE-2025-52881.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20080-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here