SUSE-CU-2026:7510-1: Security update of suse/kubectl

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Jul 29 07:56:49 UTC 2026


SUSE Container Update Advisory: suse/kubectl
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7510-1
Container Tags        : suse/kubectl:1.33 , suse/kubectl:1.33.11 , suse/kubectl:1.33.11-2.70.2 , suse/kubectl:oldstable
Container Release     : 70.2
Severity              : important
Type                  : security
References            : 1266598 1271997 CVE-2026-39821 CVE-2026-56852 
-----------------------------------------------------------------

The container suse/kubectl was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3342-1
Released:    Tue Jul 28 12:10:37 2026
Summary:     Security update for helm
Type:        security
Severity:    important
References:  1266598,1271997,CVE-2026-39821,CVE-2026-56852
This update for helm fixes the following issues:

Update to version 3.21.3.

- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
  bypass and privilege escalation (bsc#1266598).
- CVE-2026-56852: golang.org/x/text/unicode/norm: handling input containing truncated or invalid UTF-8 bytes can lead
  to an infinite loop (bsc#1271997).

Other updates and bugfixes:

- Update x/text to 0.40.0.
- Update x/net to 0.57.0.
- Version 3.21.3:
  * Apply suggestions from code review 1ad6e68 (Benoit Tigeot).
  * fix: drop containerd v1 dep to resolve govulncheck CVEs 037733e (Benoit Tigeot).
  * chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 d3e178b.


The following package changes have been done:

- helm-3.21.3-150000.1.85.1 updated
- container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated


More information about the sle-container-updates mailing list