openSUSE-SU-2026:21499-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21499-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21499-1
Upstream
CVE (2)
Related
Published
2026-07-29T09:24:08Z
Modified
2026-07-31T18:24:09Z
Summary
Security update for apptainer
Details

This update for apptainer fixes the following issues:

Changes in apptainer:

  • Update to version 1.5.3:

    • If the ptrace() system call does not work while building an image as an unprivileged user, skip using PRoot to preserve file ownership and print an INFO message.
    • Bind getopt from the host when using fakeroot command mode, to make the fakeroot command work with base containers which no longer contain getopt by default.
    • Update fixes CVE-2026-56852 (GO-2026-5970) (bsc#1272115) golang.org/x/text/unicode/norm: A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
  • Update to version 1.5.2:

    • Extended the mksquashfs segmentation fault workaround for cases where mksquashfs uses many processor cores.
  • Update the golang.org/x/net dependency to version v0.57.0 to fix CVE-2026-39821 for good (bsc#1266656). The fix in v0.55.0 only applied to Unicode versions >=16.0.0 which aren't yet available on any Golang versions released.

References

Affected packages

openSUSE:Leap 16.0 / apptainer

Package

Name
apptainer
Purl
pkg:rpm/opensuse/apptainer&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.5.3-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "apptainer":  "1.5.3-bp160.1.1",
            "apptainer-leap":  "1.5.3-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21499-1.json"