{"id":"SUSE-SU-2026:2365-1","summary":"Security update for cosign","details":"This update for cosign fixes the following issue\n\n- CVE-2026-39395: Incorrect attestation verification due to malformed payloads or mismatched predicate types\n  (bsc#1261859).\n\nChanges for cosign:\n\n- update to 3.0.6:\n * Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801)\n * Handle whitespace-only certificate annotation (#4760)\n * fix(sign): closing SignerVerifier too early when signing with\n a security key (#4761)\n * Disallow --new-bundle-format and --rfc3161-timestamp (#4762)\n * support managed keys in conformance testing (#4728)\n * Add support for GCE metadata server env var (#4732)\n * fix: preserve per-layer annotations in\n WriteAttestationsReferrer (#4709)\n * Fix parsing of in-toto for string predicates\n * Mark batch of flags for deprecation (#4698)\n * disallow key and cert identity being used together\n during verification (#4636)\n * support key creation in GitLab group (#4704)\n- Set CGO_ENABLED=1 for fixing s390x failed build\n- build against a maintained golang version (upstream uses go1.20)\n","modified":"2026-06-12T08:45:05.167298788Z","published":"2026-06-11T07:58:17Z","related":["CVE-2026-39395"],"upstream":["CVE-2026-39395"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262365-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261859"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39395"}],"affected":[{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.6-150400.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"cosign-bash-completion":"3.0.6-150400.3.42.1","cosign-zsh-completion":"3.0.6-150400.3.42.1","cosign":"3.0.6-150400.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2365-1.json"}}],"schema_version":"1.7.5"}