|
|
Log in / Subscribe / Register

SUSE alert openSUSE-SU-2026:20994-1 (helm)

From:  null@suse.de
To:  security-announce@lists.opensuse.org
Subject:  openSUSE-SU-2026:20994-1: important: Security update for helm
Date:  Tue, 30 Jun 2026 09:47:50 +0200
Message-ID:  <20260630074750.1B8B0FF21@maintenance.suse.de>
Archive-link:  Article

openSUSE security update: security update for helm ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20994-1 Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for helm fixes the following issue - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: - Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates - chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 - chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 - chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 - chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 - chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 - chore(deps): bump github.com/distribution/distribution/v3 - chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 - chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 - chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 - chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 - chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 - chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1006=1 Package List: - openSUSE Leap 16.0: helm-3.21.1-160000.1.1 helm-bash-completion-3.21.1-160000.1.2 helm-fish-completion-3.21.1-160000.1.2 helm-zsh-completion-3.21.1-160000.1.2 References: * https://www.suse.com/security/cve/CVE-2026-39821.html


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds