Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
openSUSE released a security update for the gh package to address CVE-2026-39821, which involves rejecting certain Punycode labels in the idna package, rated important.. openSUSE Security Update: Security update for gh ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0259-1 Rating: important References: #1266618 Cross-References: CVE-2026-39821 CVSS scores: CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gh fixes the following issues: - CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored golang.org/x/net/idna package regardless of Go's unicode.Version (boo#1266618). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-259=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): gh-2.96.0-bp157.2.24.1 - openSUSE Backports SLE-15-SP7 (noarch): gh-bash-completion-2.96.0-bp157.2.24.1 gh-fish-completion-2.96.0-bp157.2.24.1 gh-zsh-completion-2.96.0-bp157.2.24.1 References: https://www.suse.com/security/cve/CVE-2026-39821.html https://bugzilla.suse.com/1266618 . Update for openSUSE fixes important Punycode issue in gh affecting Backports SLE-15-SP7 security.. Punycode security, openSUSE updates, gh vulnerabilities, advisory notifications. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.