SUSE-SU-2026:4212-1
Vulnerability Summary
Timeline
Description
Security update for distribution This update for distribution fixes the following issues: Security issues fixed: - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260283). - CVE-2026-33540: information disclosure via improper validation of authentication realm URL (bsc#1261793). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265788). - CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262951). - CVE-2026-35172: information disclosure via stale references after content deletion (bsc#1262096). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266629). - CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831, CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508, CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues (bsc#1268884). - CVE-2026-41888: tag deletion bypasses the storage.delete.enabled configuration (bsc#1265429). - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272132). Changes for distribution: Update to 3.1.1: * Bounds-check the file basename in PurgeUploads Walk callback * Add S3 Express One Zone support to the S3 storage driver * Fix tag list endpoint in proxy mode * Clamp oversized `n` query parameter in proxy mode instead of returning 400 * See the full changelog below for the full list of changes. * internal/client/auth/challenge: cleanups and minor refactor * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp from 0.18.0 to 0.19.0 in the go_modules group across 1 directory * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otl ptrace/otlptracehttp from 1.42.0 to 1.43.0 in the go_modules group across 1 directory * build(deps): bump github/codeql-action from 4.34.1 to 4.35.1 * chore(build): Bump go version to latest * refactor: use slices.Backward to simplify the code * fix(proxy): fix tag list endpoint in proxy mode * Update docker-compose structure in deploying.md * build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 * build(deps): bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 * build(deps): bump docker/login-action from 4.0.0 to 4.1.0 * build(deps): bump docker/bake-action from 7.0.0 to 7.1.0 * fix(proxy): clamp oversized n query param instead of * feat(s3): add express zone one support to S3 driver * fix(storage): bounds-check the file basename in PurgeUploads Walk callback * chore(release): prepare for v3.1.1 release * Adds support for tag pagination * Fixes default credentials in Azure storage provider * Drops support for go1.23 and go1.24 and updates to go1.25 * docs: Update to refer to new image tag v3 * Fix default_credentials in azure storage provider * chore: make function comment match function name * build(deps): bump golang.org/x/net from 0.37.0 to 0.38.0 in the go_modules group across 1 directory * fix: implement JWK thumbprint for Ed25519 public keys * fix: Annotate code block from validation.indexes configuration docs * feat: extract redis config to separate struct * Fix: resolve issue #4478 by using a temporary file for non- append writes * build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 * docs: Add note about `OTEL_TRACES_EXPORTER` * fix: set OTEL traces to disabled by default * Fix markdown syntax for OTEL traces link in docs * Switch UUIDs to UUIDv7 * refactor: replace map iteration with maps.Copy/Clone * s3-aws: fix build for 386 * docs: Add OpenTelemetry links to quickstart docs * Fix S3 driver loglevel param * Fixed data race in TestSchedule test * Fixes #4683 - uses X/Y instead of Gx/Gy for thumbprint of ecdsa keys * build(deps): bump actions/checkout from 4 to 5 * Fix broken link to Docker Hub fair use policy * fix(registry/handlers/app): redis CAs * build(deps): bump actions/labeler from 5 to 6 * build(deps): bump actions/setup-go from 5 to 6 * build(deps): bump actions/upload-pages-artifact from 3 to 4 * build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 * build(deps): bump github/codeql-action from 3.26.5 to 4.30.7 * build(deps): bump github/codeql-action from 4.30.7 to 4.30.8 * chore: labeler: add area/client mapping for internal/client/** * client: add Accept headers to Exists() HEAD * feat(registry): Make graceful shutdown test robust * fix(registry): Correct log formatting for upstream challenge * build(deps): bump github/codeql-action from 4.30.8 to 4.30.9 * build(deps): bump github/codeql-action from 4.30.9 to 4.31.3 * refactor: remove redundant variable declarations in for loops * 'should' -> 'must' regarding redis eviction policy * build(deps): bump actions/checkout from 5 to 6 * Incorrect warning hint * Add return error when list object * build(deps): bump actions/checkout from 5.0.1 to 6.0.0 * build(deps): bump peter-evans/dockerhub-description from 4 to 5 * fix: Logging regression for manifest HEAD requests * Add boolean parsing util * Expose `useFIPSEndpoint` for S3 * Add Cloudfleet Container Registry to adopters * fix(ci): Fix broken Azure e2e storage tests * BUG: Fix notification filtering to work with actions when mediatypes is empty * build(deps): bump actions/checkout from 6.0.0 to 6.0.1 * build(deps): bump actions/upload-artifact from 4.6.2 to 6.0.0 * build(deps): bump github/codeql-action from 4.31.3 to 4.31.10 * build(deps): bump github/codeql-action from 4.31.10 to 4.32.2 * build(deps): bump actions/checkout from 6.0.1 to 6.0.2 * update golangci-lint to v2.9 and fix linting issues * update to go1.25.7, alpine 3.23, xx v1.9.0 * vendor: github.com/sirupsen/logrus v1.9.4 * vendor: update golang.org/x/* dependencies * vendor: github.com/docker/docker-credential-helpers v0.9.5 * vendor: github.com/opencontainers/image-spec v1.1.1 * vendor: github.com/klauspost/compress v1.18.4 * fix: prefer otel variables over hard coded service name * vendor: github.com/spf13/cobra v1.10.2 * vendor: github.com/bshuster-repo/logrus-logstash-hook v1.1.0 * fix: sync parent dir to ensure data is reliably stored * modernize code * vendor: github.com/docker/go-events 605354379745 * vendor: github.com/go-jose/go-jose/v4 v4.1.3 * build(deps): bump github/codeql-action from 4.32.2 to 4.32.5 * build(deps): bump docker/login-action from 3 to 4 * build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 * build(deps): bump docker/setup-buildx-action from 3 to 4 * build(deps): bump docker/bake-action from 6 to 7 * build(deps): bump docker/metadata-action from 5 to 6 * fix: nil-check scheduler in `proxyingRegistry.Close()` * fix: set MD5 on GCS writer before first `Write` call in `putContent` * docs: pull through cache will pull from remote multiple times * Update s3.md regionendpoint option * chore(deps): Bump Go to latest 1.25 in CI workflows and go.mod * fix: correct Ed25519 JWK thumbprint `kty` from `'OTP'` to `'OKP'` * Update vacuum.go * Opt: refector tag list pagination support (stage 1) * Correctly match environment variables to YAML-inlined structs in configuration * Enable Redis TLS without client certificates * build(deps): bump actions/deploy-pages from 4 to 5 * build(deps): bump github/codeql-action from 4.32.5 to 4.34.1 * fix(registry/proxy): use detached context when flushing write buffer * ci: pin actions and apply zizmor auto-fixes * build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 * build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in the go_modules group across 1 directory * chore(app): warn when partial TLS config is used in Redis * feat(registry): enhance authentication checks in htpasswd implementation * Opt: refactor tag list pagination support * build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0 * build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 * fix(vendor): fix broke vendor validation * chore(ci): Prep for v3.1 release - Update to version 3.1.0: * fix(vendor): fix broke vendpor validation * fix redis repo-scoped blob descriptor revocation * proxy: bind bearer realms to upstream trust boundary - restore directory ownership after last change - Move config files in systemd tmpfiles dir for immutable mode (jsc#PED-14747) * Add distribution-registry.tmpfiles * This is the first v3 stable release since `v2.8.3` which is a culmination of years of hard work of the container community and registry maintainers! * If you are upgrading from `v2.x` and have never used any of the release candidates, please familiarise yourselves with the `v2.x` deprecations properly. * oss and swift storage drivers are no longer supported * `docker/libtrust` has been replaced with `go-jose/go-jose` in https://github.com/distribution/distribution/pull/4096 * `client` is no longer supported as a standalone package in https://github.com/distribution/distribution/pull/4126 * the default configuration path has changed to `/etc/distribution/config.yml` * `ManifestBuilder` interface in 3886 * `manifest.Versioned` has been deprecated in favor of `oci.Versioned` in 3887 * `reference` package has been moved to github.com/distribution/reference in https://github.com/distribution/distribution/pull/4063
Affected Systems
- suse•distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise Module for Containers 15 SP7
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise Server 15 SP4-LTSS
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise Server 15 SP5-LTSS
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise Server 15 SP6-LTSS
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP5
< 3.1.1-150400.9.41.1
- suse•distribution&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP6
< 3.1.1-150400.9.41.1
References (32)
- https://www.suse.com/support/update/announcement/2026/suse-su-20264212-1/
- https://bugzilla.suse.com/1259718
- https://bugzilla.suse.com/1260283
- https://bugzilla.suse.com/1261793
- https://bugzilla.suse.com/1262096
- https://bugzilla.suse.com/1262951
- https://bugzilla.suse.com/1265429
- https://bugzilla.suse.com/1265788
- https://bugzilla.suse.com/1266629
- https://bugzilla.suse.com/1268884
- https://bugzilla.suse.com/1272132
- https://www.suse.com/security/cve/CVE-2026-33186
- https://www.suse.com/security/cve/CVE-2026-33540
- https://www.suse.com/security/cve/CVE-2026-33814
- https://www.suse.com/security/cve/CVE-2026-34986
- https://www.suse.com/security/cve/CVE-2026-35172
- https://www.suse.com/security/cve/CVE-2026-39821
- https://www.suse.com/security/cve/CVE-2026-39827
- https://www.suse.com/security/cve/CVE-2026-39828
- https://www.suse.com/security/cve/CVE-2026-39829
- https://www.suse.com/security/cve/CVE-2026-39830
- https://www.suse.com/security/cve/CVE-2026-39831
- https://www.suse.com/security/cve/CVE-2026-39832
- https://www.suse.com/security/cve/CVE-2026-39833
- https://www.suse.com/security/cve/CVE-2026-39834
- https://www.suse.com/security/cve/CVE-2026-39835
- https://www.suse.com/security/cve/CVE-2026-41888
- https://www.suse.com/security/cve/CVE-2026-42508
- https://www.suse.com/security/cve/CVE-2026-46595
- https://www.suse.com/security/cve/CVE-2026-46597
- https://www.suse.com/security/cve/CVE-2026-46598
- https://www.suse.com/security/cve/CVE-2026-56852