SUSE-SU-2026:3528-1: important: Security update for azure-storage-azcopy
SLE-SECURITY-UPDATES
null at suse.de
Fri Aug 7 20:33:51 UTC 2026
# Security update for azure-storage-azcopy
Announcement ID: SUSE-SU-2026:3528-1
Release Date: 2026-08-07T14:20:23Z
Rating: important
References:
* bsc#1266657
* bsc#1272123
Cross-References:
* CVE-2026-39821
* CVE-2026-56852
CVSS scores:
* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Public Cloud Module 15-SP5
* Public Cloud Module 15-SP6
* Public Cloud Module 15-SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3
An update that solves two vulnerabilities can now be installed.
## Description:
This update for azure-storage-azcopy fixes the following issues:
Update to 10.32.6.
Security issues fixed:
* CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only
Punycode-encoded labels allows for validation bypass and privilege
escalation (bsc#1266657).
* CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of
truncated/invalid UTF-8 input can lead to infinite loop (bsc#1272123).
Other updates and bugfixes:
* Version 10.32.6:
* Run `go mod tidy`
* Merge tag `v10.32.4` into release/fips
* Merge `remote-tracking` branch `origin/wendi/10.32.5` into `release/fips`
* Merge branch `main` into `wendi/10.32.5`
* TASK 38260338: Updated the release pipeline to produce Linux builds capable
of complying with the FIPS 140-3 standard. (#3488)
* Bump Go toolchain and security-relevant dependencies (#3486)
* stylistic changes from copilot :)
* Update `golang.org/x/text` to v0.40.0
* Update `golang.org/x/net` to v0.57.0
* Version 10.32.5:
* Create new patch release
* Merge branch `main` into `seanmcc/bump-deps-2026-06`
* Ensure get/set ACLs are on URLs with paths (#3453)
* Print out help command on just `azcopy` (#3485)
* Bump Go toolchain and security-relevant dependencies
* Centralize HTTP client into a shared global instance (#3436)
* Remove 0-padding in mode with SetUID (#3467)
* Updated `trivy` dependency to known safe version (#3421)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Public Cloud Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3528=1
* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3528=1
* Public Cloud Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3528=1
* Public Cloud Module 15-SP5
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3528=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3528=1
## Package List:
* Public Cloud Module 15-SP7 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* Public Cloud Module 15-SP5 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* Public Cloud Module 15-SP4 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* Public Cloud Module 15-SP6 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
## References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://bugzilla.suse.com/show_bug.cgi?id=1266657
* https://bugzilla.suse.com/show_bug.cgi?id=1272123
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260807/d95db757/attachment.htm>
More information about the sle-security-updates
mailing list