{"id":"SUSE-SU-2026:4392-1","summary":"Security update for cosign","details":"This update for cosign fixes the following issues:\n\n- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272117).\n- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the\n  crypto/ssh library (bsc#1278614).\n- CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).\n- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279215).\n- Verification bypass via public key in legacy bundle (bsc#1282542).\n\nChanges for cosign:\n\n- update to 3.1.3:\n * Auto-detect default digest algorithm for public keys\n * fix(pkcs11key): return an error instead of panicking when no\n key pair matches\n * Supporting OCI Signing with X.509 Certificate Chain\n * fix: prevent shell completions for various options not taking\n filenames\n * fix(blob): compare file checksums case-insensitively in\n * Verification bypass via public key in legacy bundle (GHSA-\n fx35-mq7g-6g98, bsc#1282542)\n","modified":"2026-09-30T12:00:04.614217979Z","published":"2026-09-29T11:49:16Z","related":["CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-56864","CVE-2026-78662","CVE-2026-84304"],"upstream":["CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-56864","CVE-2026-78662","CVE-2026-84304"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264392-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272117"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278614"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279215"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282542"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84304"}],"affected":[{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign-bash-completion":"3.1.3-150400.3.57.1","cosign-zsh-completion":"3.1.3-150400.3.57.1","cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}},{"package":{"name":"cosign","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/cosign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-150400.3.57.1"}]}],"ecosystem_specific":{"binaries":[{"cosign":"3.1.3-150400.3.57.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4392-1.json"}}],"schema_version":"1.9.0"}