SUSE-CU-2026:10585-1: Security update of suse/kubectl

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Sep 16 08:43:08 UTC 2026


SUSE Container Update Advisory: suse/kubectl
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10585-1
Container Tags        : suse/kubectl:1.37 , suse/kubectl:1.37.0 , suse/kubectl:1.37.0-1.61.10 , suse/kubectl:latest , suse/kubectl:stable
Container Release     : 61.10
Severity              : important
Type                  : security
References            : 1276644 1277949 1278270 1278273 1278688 CVE-2026-37236 CVE-2026-41178
                        CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 
-----------------------------------------------------------------

The container suse/kubectl was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4175-1
Released:    Mon Sep 14 12:27:42 2026
Summary:     Security update for helm
Type:        security
Severity:    important
References:  1276644,1277949,1278270,1278273,1278688,CVE-2026-37236,CVE-2026-41178,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445
This update for helm fixes the following issues:

- CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST
  request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277949).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS
  via oversized inputs (bsc#1276644).
- CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization
  policies via mixed-case or canonical-case header matches (bsc#1278270).
- CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273).
- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS
  servers (bsc#1278688).


The following package changes have been done:

- helm-3.21.3-150000.1.96.1 updated
- container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated
- container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated


More information about the sle-container-updates mailing list