SUSE-SU-2026:4392-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264392-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4392-1
Upstream
CVE (6)
Related
Published
2026-09-29T11:49:16Z
Modified
2026-09-30T12:00:04Z
Summary
Security update for cosign
Details

This update for cosign fixes the following issues:

  • CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272117).
  • CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278614).
  • CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).
  • CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279215).
  • Verification bypass via public key in legacy bundle (bsc#1282542).

Changes for cosign:

  • update to 3.1.3:
  • Auto-detect default digest algorithm for public keys
  • fix(pkcs11key): return an error instead of panicking when no key pair matches
  • Supporting OCI Signing with X.509 Certificate Chain
  • fix: prevent shell completions for various options not taking filenames
  • fix(blob): compare file checksums case-insensitively in
  • Verification bypass via public key in legacy bundle (GHSA- fx35-mq7g-6g98, bsc#1282542)
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise Module for Basesystem 15 SP7
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1",
            "cosign-bash-completion":  "3.1.3-150400.3.57.1",
            "cosign-zsh-completion":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
cosign

Package

Name
cosign
Purl
pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.3-150400.3.57.1

Ecosystem specific

{
    "binaries":  [
        {
            "cosign":  "3.1.3-150400.3.57.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"