gpp_maybe
Security update for azure-storage-azcopy
SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4125
This update for azure-storage-azcopy fixes the following issues: - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276733). - CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279330). - CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279223). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1279026). Changes for azure-storage-azcopy: - Update to 10.32.8
-
Release DateSep 11 2026
-
ReferencesBugzilla: 1276733, 1279026, 1279223, 1279330
CVEs: CVE-2026-41178, CVE-2026-84303, CVE-2026-84304, CVE-2026-84445 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Public Cloud Module 15.7 ppc64le
-
Packagesazure-storage-azcopy
Microsoft Azure Storage data transfer utility10.32.8-150400.9.21.1 lock rpm lock src
Public Cloud Module 15.7 aarch64
-
Packagesazure-storage-azcopy
Microsoft Azure Storage data transfer utility10.32.8-150400.9.21.1 lock rpm lock src
Public Cloud Module 15.7 x86_64
-
Packagesazure-storage-azcopy
Microsoft Azure Storage data transfer utility10.32.8-150400.9.21.1 lock rpm lock src