{"id":"openSUSE-SU-2026:21793-1","summary":"Security update for hauler","details":"This update for hauler fixes the following issues:\n\nChanges in hauler:\n\n- update to 2.1.0 (bsc#1265425, CVE-2026-41888):\n  * `v2.1.0` is a **minor** release built on the containerd-\n    native foundation laid down in `v2.0.0`. The headline is that\n    `hauler store sync` and `hauler store add` are now fully\n    concurrent, with signature verification pinned to digests and\n    running in parallel too. Alongside that, this release adds an\n    audit trail, a store integrity checker, store-to-manifest\n    generation, private/insecure registry support across every\n    pull path, and a set of fixes for containerd imports, chunked\n    hauls, and Docker Hub reference handling.\n  * **Notable dependency bumps:** Go → **1.26.6**;\n    `containerd/v2` → 2.3.4; `sigstore/cosign/v3` → 3.1.3;\n    `sigstore/sigstore` → 1.10.9; `go-containerregistry` →\n    0.22.0; `helm/v4` → 4.2.4; `k8s.io` libs (apimachinery, api,\n    client-go) → 0.37.0; `logrus` → 1.10.2; `docker/go-metrics` →\n    0.1.0; `sigstore/rekor` → 1.5.4 (CVE resolution); plus\n    `x/mod` and `go-isatty`.\n\n- update to 2.0.3 (bsc#1276124,\n  CVE-2026-72817,CVE-2026-72815,CVE-2026-72816):\n  * Bump k8s.io/apimachinery from 0.36.2 to 0.36.3 (backport\n    #688)\n  * Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 in the\n    go_modules group across 1 directory (backport #691)\n  * fix for homebrew macOS binary quarantine (backport #690)\n  * fix: process Helm deps before --add-images discovery\n    (backport #703)\n  * update hauler store remove to handle registry reference as\n    part of string (backport #705)\n  * fixed vuln for golang grpc\n","modified":"2026-09-09T18:23:35.833994638Z","published":"2026-09-03T12:32:31Z","related":["CVE-2026-37236","CVE-2026-41178","CVE-2026-41888","CVE-2026-72815","CVE-2026-72816","CVE-2026-72817"],"upstream":["CVE-2026-37236","CVE-2026-41178","CVE-2026-41888","CVE-2026-72815","CVE-2026-72816","CVE-2026-72817"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265425"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276124"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276651"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-37236"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41888"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72817"}],"affected":[{"package":{"name":"hauler","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/hauler&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"hauler":"2.1.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21793-1.json"}}],"schema_version":"1.9.0"}