SUSE-SU-2026:2578-1
Advisory lineage Upstream: 4 Downstream: 0
Published: 23 Jun 2026, 13:12
Last modified:24 Jun 2026, 09:00
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
23 Jun 2026, 13:12
Published
Vulnerability first disclosed
24 Jun 2026, 09:00
Last Modified
Vulnerability information updated
Description
Security update for docker-stable This update for docker-stable fixes the following issues - CVE-2026-33747: github.com/moby/buildkit: malicious frontends can craft API messages that cause files to be written outside of the BuildKit state directory (bsc#1260967). - CVE-2026-33748: github.com/moby/buildkit: insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository (bsc#1261078). - CVE-2026-33997: Fixed privilege validation bypass during plugin (bsc#1265907). - CVE-2026-34040: Fixed Authz zero length regression (bsc#1265929).
Affected Systems
- suse•docker-stable&distro=SUSE Linux Enterprise Server 12 SP5-LTSS
< 24.0.9_ce-1.37.1
- suse•docker-stable&distro=SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
< 24.0.9_ce-1.37.1
References (9)
- https://www.suse.com/support/update/announcement/2026/suse-su-20262578-1/
- https://bugzilla.suse.com/1260967
- https://bugzilla.suse.com/1261078
- https://bugzilla.suse.com/1265907
- https://bugzilla.suse.com/1265929
- https://www.suse.com/security/cve/CVE-2026-33747
- https://www.suse.com/security/cve/CVE-2026-33748
- https://www.suse.com/security/cve/CVE-2026-33997
- https://www.suse.com/security/cve/CVE-2026-34040