Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Keybase-Client Important Security Issues Update 2026-0195-1

opensuse
Calendar Grey June 9, 2026
Dist Opensuse Esm H88
Critical update for openSUSE keybase-client fixes 20 important security issues including privilege escalation vulnerabilities.
An update that fixes 20 vulnerabilities is now available.

Description

This update for keybase-client fixes the following issues:

- Fixed multiple security issues in golang.org/x/crypto/ssh (boo#1266158).

- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only

Punycode-encoded labels allows for validation bypass and privilege

escalation (boo#1266596).

- Update to version 6.6.2

* Improve git default branch handling

- Switch to go1.25 as required by update go image library.

- Update to version 6.6.0

* Various bug fixes and performance improvements

- Update to version 6.5.1

* Fix team deletion not working

* Chat attachments improvements

* Miscellaneous bugfixes

- Switch source download service from deprecated disabledrun to manualrun.

- Update to version 6.3.1

* Archive your chats/files/repos for easy backups.

* Wrap text in spoiler to hide spoilers.

- Update the used Go version to 1.21 which is the first version to support

the slices modules which is now...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-195=1

Package List

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

kbfs-6.6.2-bp157.2.6.1

kbfs-git-6.6.2-bp157.2.6.1

kbfs-tool-6.6.2-bp157.2.6.1

keybase-client-6.6.2-bp157.2.6.1

References

https://www.suse.com/security/cve/CVE-2024-24792.html

https://www.suse.com/security/cve/CVE-2025-47913.html

https://www.suse.com/security/cve/CVE-2025-47914.html

https://www.suse.com/security/cve/CVE-2025-58181.html

https://www.suse.com/security/cve/CVE-2026-26958.html

https://www.suse.com/security/cve/CVE-2026-33809.html

https://www.suse.com/security/cve/CVE-2026-39821.html

https://www.suse.com/security/cve/CVE-2026-39827.html

https://www.suse.com/security/cve/CVE-2026-39828.html

https://www.suse.com/security/cve/CVE-2026-39829.html

https://www.suse.com/security/cve/CVE-2026-39830.html

https://www.suse.com/security/cve/CVE-2026-39831.html

https://www.suse.com/security/cve/CVE-2026-39832.html

https://www.suse.com/security/cve/CVE-2026-39833.html

https://www.suse.com/security/cve/CVE-2026-39834.html

https://www.suse.com/security/cve/CVE-2026-39835.html

https://www.suse.com/security/cve/CVE-2026-42508.html

https://www.suse.com/security/cve/CVE-2026-46595.html

https://www.suse.com/security/cve/CVE-2026-465...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0195-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here