{"id":"SUSE-SU-2026:3528-1","summary":"Security update for azure-storage-azcopy","details":"This update for azure-storage-azcopy fixes the following issues:\n\nUpdate to 10.32.6.\n\nSecurity issues fixed:\n\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266657).\n- CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of truncated/invalid UTF-8 input can lead to\n  infinite loop (bsc#1272123).\n\nOther updates and bugfixes:\n\n- Version 10.32.6:\n  * Run go mod tidy\n  * Merge tag 'v10.32.4' into release/fips\n  * Merge remote-tracking branch 'origin/wendi/10.32.5' into release/fips\n  * Merge branch 'main' into wendi/10.32.5\n  * TASK 38260338: Updated the release pipeline to produce Linux builds\n    capable of complying with the FIPS 140-3 standard. (#3488)\n  * Bump Go toolchain and security-relevant dependencies (#3486)\n  * stylistic changes from copilot :)\n- Update golang.org/x/text to v0.40.0\n- Update golang.org/x/net to v0.57.0\n- Version 10.32.5:\n  * Create new patch release\n  * Merge branch 'main' into seanmcc/bump-deps-2026-06\n  * Ensure get/set ACLs are on URLs with paths (#3453)\n  * Print out help command on just `azcopy` (#3485)\n  * Bump Go toolchain and security-relevant dependencies\n  * Centralize HTTP client into a shared global instance (#3436)\n  * Remove 0-padding in mode with SetUID (#3467)\n  * Updated trivy dependency to known safe version (#3421)\n","modified":"2026-08-08T09:00:04.318069339Z","published":"2026-08-07T14:20:22Z","related":["CVE-2026-39821","CVE-2026-56852"],"upstream":["CVE-2026-39821","CVE-2026-56852"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263528-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266657"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272123"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"}],"affected":[{"package":{"name":"azure-storage-azcopy","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP4","purl":"pkg:rpm/suse/azure-storage-azcopy&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.32.6-150400.9.16.2"}]}],"ecosystem_specific":{"binaries":[{"azure-storage-azcopy":"10.32.6-150400.9.16.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3528-1.json"}},{"package":{"name":"azure-storage-azcopy","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP5","purl":"pkg:rpm/suse/azure-storage-azcopy&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.32.6-150400.9.16.2"}]}],"ecosystem_specific":{"binaries":[{"azure-storage-azcopy":"10.32.6-150400.9.16.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3528-1.json"}},{"package":{"name":"azure-storage-azcopy","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP6","purl":"pkg:rpm/suse/azure-storage-azcopy&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.32.6-150400.9.16.2"}]}],"ecosystem_specific":{"binaries":[{"azure-storage-azcopy":"10.32.6-150400.9.16.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3528-1.json"}},{"package":{"name":"azure-storage-azcopy","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP7","purl":"pkg:rpm/suse/azure-storage-azcopy&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.32.6-150400.9.16.2"}]}],"ecosystem_specific":{"binaries":[{"azure-storage-azcopy":"10.32.6-150400.9.16.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3528-1.json"}}],"schema_version":"1.8.0"}