Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE Leap 16.0 Helm Security Risks CVE-2026-33814 CVE-2026-41888

opensuse
Calendar Grey June 3, 2026
Dist Opensuse Esm H88
OpenSUSE Helm Security Update Addresses Important Vulnerabilities and Bug Fixes. Learn about the critical updates and fixes.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description

This update for helm fixes the following issues

Security issues:

- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE

(bsc#1265758).

- CVE-2026-41888: github.com/distribution/distribution/v3: tag deletion bypasses the storage.delete.enabled

configuration (bsc#1265428).

Non security issue:

- Update to version 3.21.0.

- Fix packages for %suse_version bump (jsc#PED-15794)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-829=1

Patch

Package List

- openSUSE Leap 16.0:

helm-3.21.0-160000.1.1

helm-bash-completion-3.21.0-160000.1.1

helm-fish-completion-3.21.0-160000.1.1

helm-zsh-completion-3.21.0-160000.1.1

References

* bsc#1265428

* bsc#1265758

References:

* https://www.suse.com/security/cve/CVE-2026-33814.html

* https://www.suse.com/security/cve/CVE-2026-41888.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20860-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here