This update for apptainer fixes the following issues:
Changes in apptainer:
- Fix CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829,
CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830,
CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595,
CVE-2026-39835 (bsc#1266202)
Update golang.org/x/crypto to v0.52.0
- Fix CVE-2026-33814 GO-2026-4918 (bsc#1265844)
Update golang.org/x/net to version v0.53.0
- Integrate vulnchecker into %check stage (optional).
- Sync with Factory version which also fixes CVE-2024-45310
tracked in bsc#1257432
- Readded SLE-15SP6.def as it was removed from Factory
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-273=1
- openSUSE Leap 16.0:
apptainer-1.4.5-bp160.2.1
apptainer-leap-1.4.5-bp160.2.1
* bsc#1257432
* bsc#1265844
* bsc#1266202
References:
* https://www.suse.com/security/cve/CVE-2024-45310.html
* https://www.suse.com/security/cve/CVE-2026-33814.html
* https://www.suse.com/security/cve/CVE-2026-39827.html
* https://www.suse.com/security/cve/CVE-2026-39828.html
* https://www.suse.com/security/cve/CVE-2026-39829.html
* https://www.suse.com/security/cve/CVE-2026-39830.html
* https://www.suse.com/security/cve/CVE-2026-39831.html
* https://www.suse.com/security/cve/CVE-2026-39832.html
* https://www.suse.com/security/cve/CVE-2026-39833.html
* https://www.suse.com/security/cve/CVE-2026-39834.html
* https://www.suse.com/security/cve/CVE-2026-39835.html
* https://www.suse.com/security/cve/CVE-2026-42508.html
* https://www.suse.com/security/cve/CVE-2026-46595.html
* https://www.suse.com/security/cve/CVE-2026-46597.html
* https://www.suse.com/security/cve/CVE-2026-46598.html
Get the latest Linux and open source security news straight to your inbox.