Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 30 articles for you...
202

openSUSE Leap 16.0 Apptainer Vulnerability CVE-2026-39821 Resolved

An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for apptainer ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20888-1 Rating: important References: * bsc#1266656 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for apptainer fixes the following issues: Changes in apptainer: - CVE-2026-39821: Update golang.org/x/net to 0.55.0. (bsc#1266656) - Add improved handling of suid-starter: * Add system group `apptainer` * Make sure, only users belonging to this group are able to run the application. * Document this in a README and point user to it if execution fails. Building of the 'suid-root' starter is still optional. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-290=1 Package List: - openSUSE Leap 16.0: apptainer-1.4.5-bp160.3.1 apptainer-leap-1.4.5-bp160.3.1 References: * https://www.suse.com/security/cve/CVE-2026-39821.html . An important security update for openSUSE Leap 16.0's apptainer addresses a critical vulnerability identified as CVE-2026-39821.. openSUSE security update, apptainer exploits, CVE-2026-39821 patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 03, 2026 Important OpenSUSE
202

openSUSE Tumbleweed Apptainer Security Advisory 2026-10887-1 CVE-2026-39821

An update that solves one vulnerability can now be installed.. # apptainer-1.4.5-6.1 on GA media Announcement ID: openSUSE-SU-2026:10887-1 Rating: moderate Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the apptainer-1.4.5-6.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * apptainer 1.4.5-6.1 * apptainer-leap 1.4.5-6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html . Apptainer update now available for openSUSE Tumbleweed to close a significant security issue rated moderate.. Apptainer Update, openSUSE Security, CVE-2026-39821, Linux Security, Apptainer Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 30, 2026 Important OpenSUSE
202

openSUSE Leap 16.0 Apptainer Important Fixes Vuln 2026-20834-1

An update that solves 15 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for apptainer ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20834-1 Rating: important References: * bsc#1257432 * bsc#1265844 * bsc#1266202 Cross-References: * CVE-2024-45310 * CVE-2026-33814 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2024-45310 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N *CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 15 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for apptainer fixes the following issues: Changes in apptainer: - Fix CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835 (bsc#1266202) Update golang.org/x/crypto to v0.52.0 - Fix CVE-2026-33814 GO-2026-4918 (bsc#1265844) Update golang.org/x/net to version v0.53.0 - Integrate vulnchecker into %check stage (optional). - Sync with Factory version which also fixes CVE-2024-45310 tracked in bsc#1257432 - Readded SLE-15SP6.def as it was removed from Factory Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or"zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-273=1 Package List: - openSUSE Leap 16.0: apptainer-1.4.5-bp160.2.1 apptainer-leap-1.4.5-bp160.2.1 References: * https://www.suse.com/security/cve/CVE-2024-45310.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html . Update for apptainer resolves 15 issues with important security fixes and bug corrections to enhance system protection.. openSUSE patch security apptainer update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 29, 2026 Important OpenSUSE
89

Fedora 42 Apptainer Addresses Critical Denial of Service Vulnerability

Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-db5621b65e 2026-05-18 01:23:32.591522+00:00 -------------------------------------------------------------------------------- Name : apptainer Product : Fedora 42 Version : 1.5.0 Release : 1.fc42 URL : https://apptainer.org Summary : Application and environment virtualization formerly known as Singularity Description : Apptainer provides functionality to make portable containers that can be used across host environments. -------------------------------------------------------------------------------- Update Information: Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Dave Dykstra - 1.5.0 - Update to upstream 1.5.0 * Tue Apr 14 2026 Dave Dykstra - 1.5.0~rc.2 - Update to upstream 1.5.0~rc.2 * Thu Mar 12 2026 Dave Dykstra - 1.5.0~rc.1 - Update to upstream 1.5.0~rc.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447072 - apptainer-1.5.0-rc.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447072 [ 2 ] Bug #2452369 - CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452369 [ 3 ] Bug #2455644 - CVE-2026-34986 apptainer: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455644 [ 4 ] Bug #2467573 - apptainer-1.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-db5621b65e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to Apptainer 1.5.0 addresses critical DoS issues from CVE-2026-32285 and CVE-2026-34986.. Fedora Apptainer Update Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 18, 2026 Critical Fedora
89

Fedora 43 Apptainer Denial of Service Mitigation CVE-2026-32285 Advisory

Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6c547e9f64 2026-05-18 00:58:32.597366+00:00 -------------------------------------------------------------------------------- Name : apptainer Product : Fedora 43 Version : 1.5.0 Release : 1.fc43 URL : https://apptainer.org Summary : Application and environment virtualization formerly known as Singularity Description : Apptainer provides functionality to make portable containers that can be used across host environments. -------------------------------------------------------------------------------- Update Information: Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Dave Dykstra - 1.5.0 - Update to upstream 1.5.0 * Tue Apr 14 2026 Dave Dykstra - 1.5.0~rc.2 - Update to upstream 1.5.0~rc.2 * Thu Mar 12 2026 Dave Dykstra - 1.5.0~rc.1 - Update to upstream 1.5.0~rc.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447072 - apptainer-1.5.0-rc.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447072 [ 2 ] Bug #2452369 - CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452369 [ 3 ] Bug #2455644 - CVE-2026-34986 apptainer: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455644 [ 4 ] Bug #2467573 - apptainer-1.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6c547e9f64' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update for Fedora 43 Apptainer addresses CVE-2026-32285 and CVE-2026-34986 improving container security.. Fedora Apptainer Update CVE-2026-32285 CVE-2026-34986 container security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 18, 2026 Important Fedora
89

Fedora 44 Apptainer Update 1.5.0 Critical DoS Issues Fixed 2026-d516d12934

Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d516d12934 2026-05-18 00:40:49.528977+00:00 -------------------------------------------------------------------------------- Name : apptainer Product : Fedora 44 Version : 1.5.0 Release : 1.fc44 URL : https://apptainer.org Summary : Application and environment virtualization formerly known as Singularity Description : Apptainer provides functionality to make portable containers that can be used across host environments. -------------------------------------------------------------------------------- Update Information: Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Dave Dykstra - 1.5.0 - Update to upstream 1.5.0 * Tue Apr 14 2026 Dave Dykstra - 1.5.0~rc.2 - Update to upstream 1.5.0~rc.2 * Thu Mar 12 2026 Dave Dykstra - 1.5.0~rc.1 - Update to upstream 1.5.0~rc.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447072 - apptainer-1.5.0-rc.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447072 [ 2 ] Bug #2452369 - CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452369 [ 3 ] Bug #2455644 - CVE-2026-34986 apptainer: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455644 [ 4 ] Bug #2467573 - apptainer-1.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d516d12934' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fedora 44 Apptainer update to version 1.5.0 addresses CVE-2026-32285 and CVE-2026-34986 handling denial of service.. Apptainer Fedora update JSON DenialOfService CVE. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 18, 2026 Critical Fedora
202

openSUSE 16.0 apptainer Critical DoS Advisory 2026-20730-1

An update that solves 20 vulnerabilities and has 15 bug fixes can now be installed.. openSUSE security update: security update for apptainer ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20730-1 Rating: critical References: * bsc#1228324 * bsc#1234595 * bsc#1234794 * bsc#1235211 * bsc#1236528 * bsc#1237679 * bsc#1238611 * bsc#1239341 * bsc#1253924 * bsc#1255462 * bsc#1258047 * bsc#1258048 * bsc#1260311 * bsc#1262956 * bsc#1264177 Cross-References: * CVE-2023-45288 * CVE-2024-28180 * CVE-2024-3727 * CVE-2024-41110 * CVE-2024-45337 * CVE-2024-45338 * CVE-2025-22869 * CVE-2025-22870 * CVE-2025-22872 * CVE-2025-27144 * CVE-2025-47911 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-58181 * CVE-2025-58190 * CVE-2025-65105 * CVE-2025-8556 * CVE-2026-24137 * CVE-2026-33186 * CVE-2026-34986 CVSS scores: * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-28180 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2024-28180 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-3727 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2024-41110 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45338 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45338 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N *CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58181 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-65105 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-24137 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-24137 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 20 vulnerabilities and has 15 bug fixes can now be installed. Description: This updatefor apptainer fixes the following issues: Changes in apptainer: - Fix CVE-2026-34986 (bsc#1262956) * github.com/go-jose/go-jose/v4@v4.1.4 CVE-2026-33186 GO-2026-4762 (bsc#1260311) * google.golang.org/grpc@v1.79.3 CVE-2026-24137 GO-2026-4358 (bsc#1264177) * github.com/sigstore/sigstore@v1.10.4 Fix fallout: github.com/moby/go-archive@v0.1.0 github.com/containers/image/v5=github.com/containers/image/v5@v5.36.0 - Fix HTML parser misimplementation of a part of the HTML specification for table related tags (CVE-2025-58190, GO-2026-4441, bsc#1258048). - Fix issue where the HTML parser takes a very long time or even never returns (CVE-2025-47911, GO-2026-4440, bsc#1258047). - Update ot 1.4.5 * Fix for moderate severity GO-2025-4176 / CVE-2025-65105 / GHSA-j3rw-fx6g-q46j (bsc#1255462): Ineffective application of selinux / apparmor --security option. Updates of a few dependent go libraries for related security fixes. * Other fix Run FUSE processes in a separate process group. This detaches them from the main process so they don't receive signals such as interrupts sent to a terminal there. This was not a problem with interactive shells because they start their own group, but was a problem with some programs with interactive Read/Eval/Print/Loops such as python. An interrupt there would kill the FUSE processes. - From 1.4.4 * By applying patches to the bundled fuse2fs, allow again the possibility of using a non-writable ext3 image file as an overlay. Fixes regression introduced in 1.4.3. * If an overlay or bound data image is asked to be mounted writable but the user has no write access to the image, show a warning message instead of silently switching to readonly. * Avoid a fatal error when starting fakeroot from suid mode while in an NFS directory. * Fix 32-bit builds which were accidentally broken by a library upgrade that was done for a minor security issue. - Fix CVEs: * GO-2025-4135 -CVE-2025-47914 Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent. * GO-2025-4134 - CVE-2025-58181 - bsc#1253924 Unbounded memory consumption in golang.org/x/crypto/ssh. * GO-2025-4116 - CVE-2025-47913 Potential denial of service in golang.org/x/crypto/ssh/agent. * GO-2025-3595 - CVE-2025-22872 Incorrect Neutralization of Input During Web Page Generation in x/net. * GO-2025-3503 - CVE-2025-22870 HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net. * GO-2025-3487 - CVE-2025-22869 Potential denial of service in golang.org/x/crypto. * GO-2025-3485 - CVE-2025-27144 DoS in go-jose Parsing in github.com/go-jose/go-jose. * GO-2025-3754 - CVE-2025-8556 CIRCL-Fourq: Missing and wrong validation can lead to incorrect results in github.com/cloudflare/circl. - No need for binutils-gold for aarch64 - Update to 1.4.3 * Corrected the mconfig -s option for statically building apptainer and starter binaries. * Resolved an issue where the Makefile generated by mconfig -b failed when the build directory was not a subdirectory of the Apptainer source code. * Fixed %files in definition files to correctly copy symlinks pointing above the destination directory but within the destination stage root filesystem. * Addressed a typo in nvliblist.conf ( libnvoptix.so.1 was corrected to libnvoptix.so). * Prevented timeouts during cleanup after building gocryptfs-encrypted SIF files. * Fixed a bug that prevented build with --passphrase or --pem-path (without --encrypt) from implying fakeroot. * Resolved a hang when copying files between build stages while using suid mode without user namespaces. * Fixed issues with running and building containers of different architectures than the host via binfmt_misc when using rootless fakeroot. * Corrected "target: no such file or directory" errors when extracting layers from certain OCI images that manipulate hard links across layers. *Fixed a crash when executing a privilege-encrypted container as root. * Improved documentation for the remote list command. * Removed the fakerootcallback functionality. * Updated the default pacman confURL for Bootstrap: arch container builds. * Updated bundled fuse programs to their latest releases. * Changed the default message level from silent to normal in nested apptainer executions of a build's %post section, and suppressed an unnecessary warning. * Invalid environment variables are now ignored when pulling oci/docker containers. - Add definition file for SLE 16 (SLE-16.def). - Remove definition files for SLE15 SP5 (SLE-15SP5.def) and SP6 (SLE-15SP6.def). - Update to 1.4.2 * Restore looking for registry mirrors in /etc/containers/registry.conf and related files. This had been inadvertently dropped beginning in 1.4.0. * Fix use of the image cache when the home directory contains @ characters. Previously it would assume that it was the start of a digest in the oci-dir. * Fix signature verification failures on unsigned images. * Add additional .deb packages to the release assets that include the label trixie+ to indicate that they are for installing on Debian 13 or later. Those packages are necessary to work with the new libfuse3 library in Debian13. They also support libsubid, unlike the default packages because they are built on Debian 11 which doesn't have that library. * Add automatic triggering of Ubuntu PPA builds whenever there's a new apptainer release. - Update to 1.4.1 * Fix the use of libsubid which had been broken by the revision applied in 1.4.0-rc.2. * Fix a bug introduced in 1.4.0 that caused arm64 to be mis-converted to arm64v8 and resulted in a failure when pulling OCI containers. * Fix user database lookup in master process preventing instance from starting correctly on systems using winbind. * Check for existence of `/run/systemd/system` when verifying cgroups can be used via systemdmanager. * Add a clear error message if someone tries to use privileged network options while not using setuid mode. * Allow multi-arch oci-archive files that have a nested index with the manifest. This is the default format (both for Docker and OCI) when using `nerdctl save`. * Test if docker-archive is actually an oci-archive (since Docker version 25), and if it is oci then use the OCI parser to avoid bugs in the Docker parser. Save the daemon-daemon references to a temporary docker-archive, to benefit from the same improvements also for those references. Parse as oci-archive. - New Features & Functionality in from ineherited 1.4.0 * Add new build option `--mksquashfs-args` to pass additional arguments to the `mksquashfs` command when building SIF files. If a compression method other than gzip is selected, the SIF file might not work with older installations of Apptainer or Singularity, so an INFO message about that is printed. On the other hand, an INFO message that was printed (twice) when running an image with non-gzip compression has been removed. * If the `mksquashfs` version is new enough (version 4.6 in Leaep 16.0), then show a percentage progress bar (with ETA) during SIF creation in the default log level. If the `mksquashfs` version is older, then in verbose or debug log level show the output of mksquashfs with its own progress bar. * Statistics are now normally available for instances that are started by non-root users on cgroups v2 systems. The instance will be started in the current cgroup. Information about configuration issues that prevent collection of statistics are displayed as INFO messages by default. * Add a `--sandbox` option to `apptainer pull`. * Add configuration file binding to the `--nv` option. Files that are recognized in the NVIDIA Container Toolkit, including files for EGL ICD, were added to the default `nvliblist.conf`. * It is now possible to use multiple environmentvariable files using the `--env-file` flag. Files can be specified as a comma-separated list or by using the flag multiple times. Variables defined in later files take precedence over earlier files. * The registry login and registry logout commands now support a `--authfile ` option, which causes OCI credentials to be written to / removed from a custom file located at ` ` instead of the default location (`$HOME/.apptainer/docker-config.json`). The commands `pull`, `push`, `run`, `exec`, `shell` and instance start can now also be passed a `--authfile ` option, to read OCI registry credentials from this custom file. * A new `--netns-path` option takes a path to a network namespace to join when starting a container. The root user may join any network namespace. An unprivileged user can only join a network namespace specified in the new `allow netns paths` directive in `apptainer.conf`, if they are also listed in `allow net users` / `allow net groups` and apptainer is installed with setuid privileges. Not supported with `--fakeroot`. * `apptainer.conf` now accepts setting the following options: `allow ipc ns` -- Default value is `yes`; when set to `no`, it will disable the use of the `--ipc` flag. `allow uts ns` -- Default value is `yes`; when set to `no`, it will invalidate the use of the `--uts` and `--hostname` flags. `allow user ns` -- Default value is `yes`; when set to `no`, it will disable creation of user namespaces. Note that this will prevent execution of containers with the `--userns` or `--fakeroot` flags and with unprivileged installations of Apptainer. - Changed defaults / behaviours * Label the starter process seen in `ps` with the image filename, for example: Apptainer runtime parent: `example.sif`. * Remove runtime and compute libraries from `rocmliblist.conf`. They should instead be provided by the container image. * Allow overriding the build architecture with `--arch` and `--arch-variant`, to build images for another architecture than the current host arch. This requires that the host has been set up to support multiple architectures (`binfmt_misc`). * Complete the previously partial support for the riscv64 architecture. * Show a warning message if changing directory to the cwd fails, instead of silently switching to the home directory or `/`. * Write starter messages to stderr when an instance fails to start. Previously they were incorrectly written to stdout. * Skip attempting to bind inaccessible mount points when handling the `mount hostfs = yes` configuration option. * Fix storage of credentials for `docker.io` to behave the same as for `index.docker.io`. * Change message log level from warning to debug when environment variables set inside a container or by `APPTAINERENV` have a different value than the environment variable on the host. * Change the default message level from silent to the normal level in the nested apptainer that executes a build's `%post` section, and suppress an unnecessary warning message. * Ignore invalid environment variables when pulling oci/docker containers. * Remove the little-known `fakerootcallback` functionality. * Update the default pacman confURL for `Bootstrap: arch` container builds. * Update the bundled fuse programs to their latest releases. - Bug fixes * Fix the `mconfig -s` option to build the apptainer and starter binaries statically as documented. * `%files from` in a definition file will now correctly copy symlinks that `%point` to a target above the destination directory but inside the `%destination` stage root filesystem. * Fixed typo in `nvliblist.conf` (`libnvoptix.so.1` -> `libnvoptix.so`). * Avoid timeouts when cleaning up from building gocryptfs-encrypted SIF files. * Fix bug that prevented build with `--passphrase` or `--pem-path` but without `--encrypt` from implying fakeroot. * Fix hang when copying files betweenbuild stages while using suid mode without user namespaces. * Fix running and building containers of different architectures than the host via binfmt_misc when using rootless fakeroot. * Fix `target: no such file or directory` error when extracting layers from certain OCI images that manipulate hard links across layers. * Fix the crash that happened when executing a privilege-encrypted container as root. - Fix CVE-2024-45338, CVE-2025-22870, CVE-2024-45337, CVE-2025-22869, CVE-2025-27144 CVE-2024-41110 * GO-2024-3333 CVE-2024-45338 (bsc#1234794) GO-2025-3503 CVE-2025-22870 (bsc#1238611): Update to: golang.org/x/net@v0.36.0 * GO-2024-3321 CVE-2024-45337 (bsc#1234595) GO-2025-3487 CVE-2025-22869 (bsc#1239341): Update to: golang.org/x/crypto@v0.35.0 * GO-2025-3485 CVE-2025-27144 (bsc#1237679): Update to: github.com/go-jose/go-jose/v3@v3.0.4 * GO-2024-3005 CVE-2024-41110 (bsc#1228324): Update to: github.com/docker/docker@v25.0.6+incompatible - Update golang.org/x/net to v0.23 to fix CVE-2023-45288 (bnc#1236528). - Update to version 1.3.6 * Avoid using kernel overlayfs when the lower layer is a sandbox on an incompatible filesystem type such as GPFS or Lustre. For those cases use fuse-overlayfs instead. This fixes a regression introduced in 1.3.0. The regression didn't much impact Lustre because kernel overlayfs refused to try to use it and Apptainer proceeded to use fuse-overlayfs anyway, but with GPFS the kernel overlayfs allowed mounting but returned stale file handle errors. - Version 1.3.5 * Fix a regression introduced in 1.3.4 that overwrote existing standard `/.singularity.d` files such as `runscript` in container images even if they had been modified. * Skip attempting to bind inaccessible mount points when handling the `mount hostfs = yes` configuration option. * Support parsing nested variables defined inside `%arguments` section of definition files. * Ignore invalid environment variables whenpulling oci/docker containers. - Version 1.3.4 * Fixed sif-embedded overlay partitions for containers that are larger than 2 gigabytes. * Fixed the failure when starting apptainer with `instance --fakeroot`. * `apptainer build -B ...` can now be used to mount custom resolv.conf and hosts files from non-standard outside locations. This can be used to run `apptainer build` in a nix-build sandbox that has no `/etc/resolv.conf`. * Fixed failing builds from local images that have symbolic links for paths that are part of the base container environment (e.g. /var/tmp -> /tmp). * Show info messages suggesting to use `enable underlay = preferred` or the `--underlay` flag when overlay is implied for bind mounts but the kernel is too old to support fuse mounts in user namespaces and so tries to use fusermount. * When someone uses a `yum` bootstrap to build a container without using subuid-based fakeroot or root, warn that it is unlikely to work. * Allow a writable `--overlay` to be used with `--nvccli` instead of `--writable-tmpfs`. * If an error "no descriptor found for reference" is seen while getting an oci container, retry the operation up to five times. * Make fakeroot Recommended for SUSE rpms instead of Required. * Allow bind mounts onto existing files on r/o NFS filesystems. * If an error is seen in the %post section when building a container using fakeroot mode 3 (with the fakeroot command) then show a message suggesting using `--ignore-fakeroot-command` and referring to the documentation about how to install and use it inside the container definition file. * Show a more helpful error message when using fakeroot in suid mode and there's an `/etc/subuid` mapping even though user namespaces are not available (user namespaces are required for `/etc/subuid` mapping). - Version 1.3.3 * Added libcudadebugger.so to nvliblist.conf to support cuda-gdb in CUDA 12+. * Ensure opened/kept filedescriptors in stage 1 are not closed during the Go garbage collection to avoid "bad file descriptor" errors at startup. * Fixed a segmentation violation issue when running Apptainer checkpoint. * Fixed an issue that Apptainer won't read default docker credentials. - Version 1.3.2 * Fix for [CVE-2024-3727](https://bugzilla.suse.com/show_bug.cgi?id=1224114) in a dependent library which describes a flaw that can allow attackers to trigger unexpected authenticated registry accesses due to object digest values not being validated in all cases. * Fixed the issue when nesting `apptainer instance start` inside a container on cgroups-v2 capable host. * Fixed the issue that oras download progress bar gets stuck when downloading large images. - Version 1.3.1 * Make 'apptainer build' work with signed Docker containers. * Fixed regression introduced in 1.3.0 that prevented closing cryptsetup and the corresponding loop device after running an encrypted sif container file in suid mode. * Stopped binding over the default timezone in the container with the host's timezone, which led to unexpected behavior if the application changed timezones. * Added progress bars for `oras://` push and pull. * Hide `Instance stats will not be available` message under `--sharens` mode. * Fix problem where credentials locally stored with `registry login` command were not usable in some execution flows. Run `registry login` again with latest version to ensure credentials are stored correctly. * Make runscript timeout configurable. * Return invalid bind path mount options during bind path parsing. * Make the INFO message more helpful when a running background process at exit time causes a FUSE mount to not shut down cleanly. * Fixed the wrong mediaType in the oras push manifest. - Add Apptainer definition template for SLE15-SP7. - Make sure, build is reproducible by setting the GNU build ID to one derived from the Go one. Seehttps://pkg.go.dev/cmd/link. - Use go-jose version with fix for CVE-2024-28180 (bsc#1235211). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-255=1 Package List: - openSUSE Leap 16.0: apptainer-1.4.5-bp160.1.1 apptainer-leap-1.4.5-bp160.1.1 apptainer-sle15_7-1.4.5-bp160.1.1 apptainer-sle16-1.4.5-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2024-28180.html * https://www.suse.com/security/cve/CVE-2024-3727.html * https://www.suse.com/security/cve/CVE-2024-41110.html * https://www.suse.com/security/cve/CVE-2024-45337.html * https://www.suse.com/security/cve/CVE-2024-45338.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://www.suse.com/security/cve/CVE-2025-22872.html * https://www.suse.com/security/cve/CVE-2025-27144.html * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-58181.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://www.suse.com/security/cve/CVE-2025-65105.html * https://www.suse.com/security/cve/CVE-2025-8556.html * https://www.suse.com/security/cve/CVE-2026-24137.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-34986.html . Critical update for openSUSE apptainer addressing 20 vulnerabilities and 15 bug fixes to enhance security performance.. openSUSE Apptainer security patch critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2026 Critical OpenSUSE
202

openSUSE apptainer Minor HTML Analyzer Concerns Resolution 2026-0580-1

An update that solves two vulnerabilities and has one security fix can now be installed.. # Security update for apptainer Announcement ID: SUSE-SU-2026:0580-1 Release Date: 2026-02-19T11:38:12Z Rating: moderate References: * bsc#1253924 * bsc#1258047 * bsc#1258048 Cross-References: * CVE-2025-47911 * CVE-2025-58190 CVSS scores: * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for apptainer fixes the following issues: * CVE-2025-58190: Fixed a HTML parser misimplementation of a part of the HTML specification for table related tags. (bsc#1258048). * CVE-2025-47911: Fixed an issue where the HTML parser takes a very long time or even never returns. (bsc#1258047). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-580=1 openSUSE-SLE-15.6-2026-580=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-580=1 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) *apptainer-1.4.5-150600.4.15.1 * apptainer-debuginfo-1.4.5-150600.4.15.1 * openSUSE Leap 15.6 (noarch) * apptainer-leap-1.4.5-150600.4.15.1 * apptainer-sle15_6-1.4.5-150600.4.15.1 * apptainer-sle15_7-1.4.5-150600.4.15.1 * apptainer-sle16-1.4.5-150600.4.15.1 * HPC Module 15-SP7 (aarch64 x86_64) * apptainer-1.4.5-150600.4.15.1 * apptainer-debuginfo-1.4.5-150600.4.15.1 * HPC Module 15-SP7 (noarch) * apptainer-sle15_7-1.4.5-150600.4.15.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://bugzilla.suse.com/show_bug.cgi?id=1253924 * https://bugzilla.suse.com/show_bug.cgi?id=1258047 * https://bugzilla.suse.com/show_bug.cgi?id=1258048 . An update for apptainer addresses critical HTML parser issues in openSUSE, improving stability and security.. apptainer security update, openSUSE patch, HTML parser issues, SUSE vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Feb 19, 2026 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here