SUSE-SU-2026:2578-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 23 Jun 2026, 13:12
Last modified:24 Jun 2026, 09:00

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jun 2026, 13:12
Published
Vulnerability first disclosed
24 Jun 2026, 09:00
Last Modified
Vulnerability information updated

Description

Security update for docker-stable This update for docker-stable fixes the following issues - CVE-2026-33747: github.com/moby/buildkit: malicious frontends can craft API messages that cause files to be written outside of the BuildKit state directory (bsc#1260967). - CVE-2026-33748: github.com/moby/buildkit: insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository (bsc#1261078). - CVE-2026-33997: Fixed privilege validation bypass during plugin (bsc#1265907). - CVE-2026-34040: Fixed Authz zero length regression (bsc#1265929).

Affected Systems

  • susedocker-stable&distro=SUSE Linux Enterprise Server 12 SP5-LTSS

    < 24.0.9_ce-1.37.1

  • susedocker-stable&distro=SUSE Linux Enterprise Server LTSS Extended Security 12 SP5

    < 24.0.9_ce-1.37.1

References (9)