{"id":"SUSE-SU-2026:4417-1","summary":"Security update for helm","details":"This update for helm fixes the following issues:\n\n- CVE-2026-85731: oras.land/oras-go/v2: arbitrary file write outside file.Store root via symlink-chain bypass in tar\n  extraction (bsc#1281104).\n- CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network\n  probing (bsc#1281112).\n\nChanges for helm:\n\n- Update to version 3.22.0:\n * chore(deps): bump the k8s-io group across 1 directory with 6 updates\n * bump version to 3.22 (#32606)\n * fix: set [pull,push] scope when helm push to a registry(use token auth) (backport) (#32362)\n * chore(deps): bump the k8s-io group with 7 updates (#32573)\n * chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#32563)\n * chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#32554)\n * chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#32542)\n * [dev-v3 backport] deps: bump google.golang.org/grpc@v1.82.1 for GO-2026-6061 (#32536)\n * fix: bump go.opentelemetry.io/otel@v1.44.0 for GO-2026-5158 (#32535)\n * chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6\n * fix(provenance): migrate to ProtonMail/go-crypto to resolve GO-2026-5932\n * chore(deps): bump the k8s-io group with 7 updates\n * chore(deps): bump github/codeql-action/upload-sarif (#32449)\n * chore(deps): bump github/codeql-action/analyze from 4.37.1 to 4.37.2\n * chore(deps): bump github/codeql-action/autobuild from 4.37.1 to 4.37.2\n * chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.2\n * chore(deps): bump github/codeql-action/autobuild from 4.37.0 to 4.37.1 (#32381)\n * chore(deps): bump github/codeql-action/upload-sarif (#32382)\n * ci: auto-label PRs targeting dev-v3 (#32340)\n * chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#32331)\n * chore(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 (#32332)\n * chore(deps): bump github/codeql-action/analyze from 3.26.6 to 4.37.0 (#32357)\n * chore(deps): bump github/codeql-action/upload-sarif (#32360)\n * chore(deps): bump github/codeql-action/init from 3.26.6 to 4.37.0 (#32359)\n * chore(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#32356)\n * chore(deps): bump golangci/golangci-lint-action from 6.1.1 to 9.3.0 (#32354)\n * chore(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3 (#32353)\n * chore(deps): bump golang.org/x/text from 0.38.0 to 0.40.0 (#32310)\n * chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#32308)\n * chore(deps): bump golang.org/x/term from 0.44.0 to 0.45.0 (#32306)\n * fix(engine): prevent Files.Lines panic on empty file\n * fix: drop containerd v1 dep to resolve govulncheck CVEs\n * chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33\n * chore(deps): bump github.com/cyphar/filepath-securejoin\n * chore(deps): bump the k8s-io group with 2 updates\n * chore(deps): bump the k8s-io group across 1 directory with 2 updates\n * fix(registry): keep credentials on plain-HTTP fallback with oras-go v2.6.1\n * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1\n * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0\n * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0\n * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0\n * ci: bump golangci-lint to v2.11.3 for go 1.26\n * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3\n * chore(deps): bump github.com/distribution/distribution/v3\n * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32\n * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0\n * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13\n * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0\n * fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026\n * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0\n * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0\n * [v3] Bump to version v3.21 (#32103)\n * [v3 backport] Fix rollback for missing resources\n * fix(action): avoid nil REST client getter panic when installing CRDs\n","modified":"2026-10-02T18:30:40.420932415Z","published":"2026-10-02T09:20:18Z","related":["CVE-2026-85731","CVE-2026-85732"],"upstream":["CVE-2026-85731","CVE-2026-85732"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264417-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281104"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281112"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85731"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-85732"}],"affected":[{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Micro 5.5","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Micro%205.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-bash-completion":"3.22.0-150000.1.99.1","helm":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Module for Containers 15 SP7","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-zsh-completion":"3.22.0-150000.1.99.1","helm":"3.22.0-150000.1.99.1","helm-bash-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-fish-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.22.0-150000.1.99.1","helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1","helm":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-zsh-completion":"3.22.0-150000.1.99.1","helm":"3.22.0-150000.1.99.1","helm-bash-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1","helm":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1","helm":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.22.0-150000.1.99.1","helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.22.0-150000.1.99.1","helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1","helm":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.22.0-150000.1.99.1","helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}},{"package":{"name":"helm","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/helm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.0-150000.1.99.1"}]}],"ecosystem_specific":{"binaries":[{"helm":"3.22.0-150000.1.99.1","helm-bash-completion":"3.22.0-150000.1.99.1","helm-zsh-completion":"3.22.0-150000.1.99.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4417-1.json"}}],"schema_version":"1.9.0"}