{"id":"openSUSE-SU-2026:21276-1","summary":"Security update for apptainer","details":"This update for apptainer fixes the following issues:\n\nChanges in apptainer:\n\n- Enable building of SUID starter for SLES 15 (jsc#PED-16347).\n  * Security fix for CVE-2026-2303 (bsc#1270529):\n    Heap Out-of-Bounds Read in GSSAPI Error Handling in\n    go.mongodb.org/mongo-driver. The dependency on mongo-driver\n    has been removed with this version of apptainer.\n","modified":"2026-07-11T18:24:38.236205681Z","published":"2026-07-08T16:27:05Z","related":["CVE-2026-2303"],"upstream":["CVE-2026-2303"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2303"}],"affected":[{"package":{"name":"apptainer","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/apptainer&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.1-bp160.2.1"}]}],"ecosystem_specific":{"binaries":[{"apptainer":"1.5.1-bp160.2.1","apptainer-leap":"1.5.1-bp160.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21276-1.json"}}],"schema_version":"1.7.5"}