openSUSE-SU-2026:20902-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20902-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20902-1
Upstream
  • CVE-2026-33809
Related
Published
2026-06-03T17:44:01Z
Modified
2026-06-06T18:24:23.494336976Z
Summary
Security update for keybase-client
Details

This update for keybase-client fixes the following issues:

Changes in keybase-client:

  • golang.org/x/crypto/ssh: Fixed multiple issues: CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835 (boo#1266158)
  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (boo#1266596).

  • Update to version 6.6.2

    • Improve git default branch handling
  • CVE-2026-33809: golang.org/x/image/tiff: excessive resource consumption due to large allocation attempt when decoding maliciously crafted TIFF file (bsc#1260696)

  • Switch to go1.25 as required by update go image library.

  • Update to version 6.6.0

    • Various bug fixes and performance improvements
  • CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results and lead to undefined behavior (bsc#1258591).

  • CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1254023).
  • CVE-2025-58181: keybase-client: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253864).
  • CVE-2025-47913: keybase-client: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253563).

  • Update to version 6.5.1

    • Fix team deletion not working
    • Chat attachments improvements
    • Miscellaneous bugfixes
References

Affected packages