This update for cosign fixes the following issue
* CVE-2026-39395: Incorrect attestation verification due to malformed payloads
or mismatched predicate types (bsc#1261859).
Changes for cosign:
* update to 3.0.6:
* Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801)
* Handle whitespace-only certificate annotation (#4760)
* fix(sign): closing SignerVerifier too early when signing with a security key
(#4761)
* Disallow --new-bundle-format and --rfc3161-timestamp (#4762)
* support managed keys in conformance testing (#4728)
* Add support for GCE metadata server env var (#4732)
* fix: preserve per-layer annotations in WriteAttestationsReferrer (#4709)
* Fix parsing of in-toto for string predicates
* Mark batch of flags for deprecation (#4698)
* disallow key and cert identity being used together during verification
(#4636)
* support key creation in GitLab group (#4704)
* Set CGO_ENABLED=1 for fixing s390x failed build
* build against a...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-2365=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2365=1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* cosign-3.0.6-150400.3.42.1
* cosign-debuginfo-3.0.6-150400.3.42.1
* openSUSE Leap 15.4 (noarch)
* cosign-bash-completion-3.0.6-150400.3.42.1
* cosign-zsh-completion-3.0.6-150400.3.42.1
* cosign-fish-completion-3.0.6-150400.3.42.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* cosign-3.0.6-150400.3.42.1
* cosign-debuginfo-3.0.6-150400.3.42.1
* Basesystem Module 15-SP7 (noarch)
* cosign-bash-completion-3.0.6-150400.3.42.1
* cosign-zsh-completion-3.0.6-150400.3.42.1
* bsc#1261859
## References:
* https://www.suse.com/security/cve/CVE-2026-39395.html
* https://bugzilla.suse.com/show_bug.cgi?id=1261859
Get the latest Linux and open source security news straight to your inbox.