{"id":"openSUSE-SU-2026:20380-1","summary":"Security update for snpguest","details":"This update for snpguest fixes the following issues:\n\n- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257927).\n- Update to version 0.10.0 (bsc#1257877):\n  * chore: updating tool version to 0.10.0\n  * refactor(certs): remove redundant branch in file-write logic\n  * Docs: Adding verify measure, host-data, report-data to docs\n  * verify: verify measurent, host data, and report data attributes from the attestation report.\n  * library: Updating sev library to 7.1.0\n  * ci: replace deprecated gh actions\n  * feat: multi-format integer parsing for key subcommand arguments\n  * chore(main): remove unused import `clap::arg`\n  * feat(fetch): add fetch crl subcommand\n  * .github/lint: Bump toolchain version to 1.86\n  * Bump rust version to 1.86\n  * feat: bumping tool to version 0.9.2\n  * fix(verify): silence mismatched_lifetime_syntaxes in SnpOid::oid\n  * feat: support SEV-SNP ABI Spec 1.58 (bump sev to v6.3.0)\n  * docs: restore and clarify Global Options section\n  * doc: fix CL argument orders + address recent changes\n  * fix(hyperv): downgrade VMPL check from error to warning\n  * fix(report.rs): remove conflict check between --random flag and Hyper-V\n  * fix(report.rs): Decouple runtime behavior from hyperv build feature\n  * refactor: clarify --platform error message\n  * docs: add Azure/Hyper-V build note for --platform\n  * docs: Update README.md\n  * report: Writing Req Data as Binary (#101)\n  * deps: bump virtee/sev to 6.2.1 (fix TCB-serialization bug) (#99)\n","modified":"2026-03-26T17:29:09.414716Z","published":"2026-03-17T15:51:45Z","related":["CVE-2026-25727"],"upstream":["CVE-2026-25727"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257877"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257927"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25727"}],"affected":[{"package":{"name":"snpguest","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/snpguest&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"snpguest":"0.10.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20380-1.json"}}],"schema_version":"1.7.5"}