gpp_maybe
Security update for alloy
SUSE-SLE-Module-Basesystem-15-SP7-2026-2824
This update for alloy fixes the following issues - CVE-2026-10722: github.com/cilium/ebpf: BTF string offset boundary check can lead to crash when parsing malformed ELF/BTF input (bsc#1267811). - CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267185). - CVE-2026-33532: Denial of Service via deeply nested YAML document parsing (bsc#1260981). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654). - CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues (bsc#1266196). - CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: SQL injection when placeholders in dollar-quoted string literals are used in the SQL query (bsc#1265440). - CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267333). - CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are processed (bsc#1267481). - CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485). - CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS (bsc#1267488). - CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process and cause denial of service (bsc#1267489).
-
Release DateJul 9 2026
-
ReferencesBugzilla: 1260981, 1265440, 1266196, 1266654, 1267185, 1267333, 1267481, 1267485, 1267488, 1267489, 1267811
CVEs: CVE-2026-39828, CVE-2026-10722, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33532, CVE-2026-39821, CVE-2026-39827, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-41889, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-44740, CVE-2026-45678, CVE-2026-45682, CVE-2026-45685, CVE-2026-45686, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.7 aarch64
-
Packagesalloy
OpenTelemetry Collector distribution with programmable pipelines1.17.1-150700.15.23.1 lock rpm lock src
Basesystem Module 15.7 ppc64le
-
Packagesalloy
OpenTelemetry Collector distribution with programmable pipelines1.17.1-150700.15.23.1 lock rpm lock src
Basesystem Module 15.7 s390x
-
Packagesalloy
OpenTelemetry Collector distribution with programmable pipelines1.17.1-150700.15.23.1 lock rpm lock src
Basesystem Module 15.7 x86_64
-
Packagesalloy
OpenTelemetry Collector distribution with programmable pipelines1.17.1-150700.15.23.1 lock rpm lock src