{"id":"openSUSE-SU-2026:21824-1","summary":"Security update for containerized-data-importer1.65","details":"This update for containerized-data-importer1.65 fixes the following issues:\n\n- CVE-2025-22869: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322).\n- CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238699).\n- CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during\n  DOM construction (bsc#1241838).\n- CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents\n  (bsc#1251495).\n- CVE-2025-47913: client process termination when receiving an unexpected message type in response to a key listing or\n  (bsc#1253506).\n- CVE-2025-47914: non validated message size can cause a panic due to an out of bounds read (bsc#1253967).\n- CVE-2025-58058: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory (bsc#1248946).\n- CVE-2025-58181: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253784).\n- CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially\n  crafted input (bsc#1251689).\n- CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues\n  when parsing HTML files (bsc#1267176).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-\n  header (bsc#1260295).\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265799).\n- CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of\n  service (bsc#1262952).\n- CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service\n  (bsc#1262269).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266639).\n- CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833,\n  CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,\n  CVE-2026-46598: multiple issues in golang.org/x/crypto/ssh (bsc#1266179).\n- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS\n  via oversized inputs (bsc#1276687).\n- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272064).\n- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the\n  crypto/ssh library (bsc#1278621).\n- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization\n  policies via mixed-case or canonical-case header matches (bsc#1279315).\n- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279234).\n","modified":"2026-09-12T18:23:35.140992479Z","published":"2026-09-09T15:12:11Z","related":["CVE-2025-22869","CVE-2025-22870","CVE-2025-22872","CVE-2025-47911","CVE-2025-47913","CVE-2025-47914","CVE-2025-58058","CVE-2025-58181","CVE-2025-58190","CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-35469","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-41178","CVE-2026-42502","CVE-2026-42506","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598","CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-78662","CVE-2026-84303","CVE-2026-84304"],"upstream":["CVE-2025-22869","CVE-2025-22870","CVE-2025-22872","CVE-2025-47911","CVE-2025-47913","CVE-2025-47914","CVE-2025-58058","CVE-2025-58181","CVE-2025-58190","CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-35469","CVE-2026-39821","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-41178","CVE-2026-42502","CVE-2026-42506","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598","CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-78662","CVE-2026-84303","CVE-2026-84304"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238699"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239322"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241838"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251495"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253784"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253967"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260295"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262269"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262952"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265799"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266179"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266639"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267176"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272064"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276687"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278621"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279234"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279315"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22872"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47911"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-47914"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39827"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39828"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39830"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39831"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39832"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39835"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42506"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42508"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84304"}],"affected":[{"package":{"name":"containerized-data-importer1.65","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/containerized-data-importer1.65&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.65.0-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"containerized-data-importer1.65-importer":"1.65.0-160000.3.1","containerized-data-importer1.65-operator":"1.65.0-160000.3.1","containerized-data-importer1.65-cloner":"1.65.0-160000.3.1","containerized-data-importer1.65-controller":"1.65.0-160000.3.1","obs-service-cdi1.65_containers_meta":"1.65.0-160000.3.1","containerized-data-importer1.65-manifests":"1.65.0-160000.3.1","containerized-data-importer1.65-uploadserver":"1.65.0-160000.3.1","containerized-data-importer1.65-uploadproxy":"1.65.0-160000.3.1","containerized-data-importer1.65-api":"1.65.0-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21824-1.json"}}],"schema_version":"1.9.0"}