SUSE-SU-2026:3327-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263327-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3327-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3327-1
Upstream
CVE (2)
Related
Published
2026-07-28T09:18:17Z
Modified
2026-07-29T18:24:24Z
Summary
Security update for yq
Details

This update for yq fixes the following issues:

Update to v4.53.3.

  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1267199).
  • CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1271994).

Changes for yq:

  • v4.53.3:
    • Add --ini-preserve-quotes flag for INI round-trip quote preservation.
    • Fix: reset INI decoder state on init.
    • Fix: decode properties array bracket paths.
    • Fix: preserve floats with trailing zero when encoding YAML to JSON.
    • Fix: JSON to TOML root scope and null handling.
    • Fix: reset TOML decoder finished flag on Init for multi-doc evaluation.
    • Fix: reset TOML decoder between files when evaluating all at once.
    • Fix: preserve TOML inline table array scope.
    • Fix: preserve empty TOML arrays in tables
    • Fix: TOML encoder uses inline tables for YAML FlowStyle mappings.
    • Fix nested inline YAML merge explode.
    • Fix repeatString overflow test on 32-bit platforms.
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7 / yq

Package

Name
yq
Purl
pkg:rpm/suse/yq&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.53.3-150500.3.12.1

Ecosystem specific

{
    "binaries":  [
        {
            "yq":  "4.53.3-150500.3.12.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3327-1.json"