<div class="container">
<h1>Security update for azure-storage-azcopy</h1>
<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2026:2466-1</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2026-06-19T11:02:49Z</td>
</tr>
<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1247720">bsc#1247720</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1260307">bsc#1260307</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1262962">bsc#1262962</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1265841">bsc#1265841</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1266311">bsc#1266311</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1266657">bsc#1266657</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>
Cross-References:
</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2025-47907.html">CVE-2025-47907</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-33186.html">CVE-2026-33186</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-33814.html">CVE-2026-33814</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-34986.html">CVE-2026-34986</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-39821.html">CVE-2026-39821</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">
<li class="list-group-item">
<span class="cvss-reference">CVE-2025-47907</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">2.1</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2025-47907</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.7</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2025-47907</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.0</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-33186</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.6</span>
<span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-33186</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-33186</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">9.1</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-33814</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-33814</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-33814</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-34986</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.7</span>
<span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-34986</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-34986</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-39821</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">9.1</span>
<span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-39821</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.4</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-39821</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">9.6</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N</span>
</li>
</ul>
</td>
</tr>
<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">
<li class="list-group-item">openSUSE Leap 15.4</li>
<li class="list-group-item">Public Cloud Module 15-SP4</li>
<li class="list-group-item">Public Cloud Module 15-SP5</li>
<li class="list-group-item">Public Cloud Module 15-SP6</li>
<li class="list-group-item">Public Cloud Module 15-SP7</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP6</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP7</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP5</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP6</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP7</li>
<li class="list-group-item">SUSE Manager Proxy 4.3</li>
<li class="list-group-item">SUSE Manager Retail Branch Server 4.3</li>
<li class="list-group-item">SUSE Manager Server 4.3</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>An update that solves five vulnerabilities and has one security fix can now be installed.</p>
<h2>Description:</h2>
<p>This update for azure-storage-azcopy fixes the following issues</p>
<p>Update to 10.32.4:</p>
<ul>
<li>CVE-2025-47907: database/sql: incorrect results returned from Rows.Scan (bsc#1247720).</li>
<li>CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-
header (bsc#1260307).</li>
<li>CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE
(bsc#1265841).</li>
<li>CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of
service (bsc#1262962).</li>
<li>CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
bypass and privilege escalation (bsc#1266657).</li>
</ul>
<p>Changes:</p>
<ul>
<li>Remove 32-bit Windows ARM7 build</li>
<li>Cover other open CVEs (bsc#1266657, CVE-2026-39821)</li>
<li>Update otel sdk</li>
<li>Update packages and add patch version</li>
<li>Update version.go</li>
<li>Error formatting</li>
<li>Add test to validate changes</li>
<li>Update Changelog</li>
<li>Alter intentional panics to return errors</li>
<li>Correct issues re: MSRC case #110341</li>
<li>Update offending packages</li>
<li>cloud.google.com/go/storage v1.45.0 -> v1.50.0</li>
<li>Golang 1.24.13 -> 1.25.8</li>
<li>Golangci-lint v1.64.8 -> v2.11.3</li>
<li>Fixed a regression where the folder tracker would panic with
pre-existing folders and --overwrite=ifSourceNewer. (#3403)</li>
<li>Fixed a regression where cancellation was not working via stdin (#3373)</li>
<li>Fixed a regression where we hit segfaults from logging
to a nil logger in the process checker. (#3384)</li>
<li>Fixed a race condition panic from concurrent access to a
shared metadata resource by introducing thread safety. (#3341)</li>
<li>Fixed a bug where --posix-properties-style was not being chained
through the copy flow correctly. (#3401)</li>
<li>Fixed a regression where in tandem use of --list-of-files
and --include-pattern no longer worked. (#3389)</li>
<li>Golang 1.24.11 -> 1.24.13</li>
<li>Added support for AMLFS style posix metadata. (#3317)</li>
<li>Fixed a bug where hdi_isfolder metadata key would sometimes
not be sent in all lowercase, resulting in unexpected behavior
on the service side when fetching properties. (#3312)</li>
<li>Fixed a typo in the benchmark command, to allow the --put-md5 flag to work. (#3324)</li>
<li>Fixed a bug where network errors would not be retried on. (#3338)</li>
<li>Fixed a bug where unexpected requests would be logged in syslog. (#3339)</li>
<li>Fixed a bug where pre-existing folders would be recreated. (#3295)</li>
<li>Updated README to clarify supported source-destination pairs and
authorization mechanisms. (#3213)</li>
<li>Updated format of wiki generated docs to improve readability. (#3311)</li>
<li>AzCopy download URLs starting with https://azcopyvnext-awgzd8g7aagqhzhe.b02.azurefd.net/
are no longer supported.</li>
<li>Fixed a bug where throughput was not being displayed for copy and resume. (#3271)</li>
<li>Fixed a bug where S3 and GCP transfers would panic. (#3273)</li>
<li>Refactored copy, sync, resume, login, logout, login status
business logic into the azcopy package.</li>
<li>Golang 1.24.4 -> 1.24.11</li>
<li>golang.org/x/crypto 0.40.0 -> 0.45.0</li>
<li>Azure Files SMB -> Azure Files NFS transfers.</li>
<li>Symlink support for Azure Files NFS shares.</li>
<li>Introduced support for symbolic links in Azure Files NFS shares.</li>
<li>Symlinks can be preserved, skipped, or followed based on command-line flags.</li>
<li>Added a --check-version flag to make version checking an opt in feature. (#3173)</li>
<li>--include-root flag now allows customers to preserve root properties
when used in conjunction with --preserve-XXXX flags. (#3163)</li>
<li>Golang 1.24.4 -> 1.24.6 (#3154)</li>
<li>Fixed a bug to retry on various network errors. (#3237) (#3252) (bsc#1266311)</li>
<li>Fixed a bug where remove would not work on paths with encoded characters. (#2977)</li>
<li>Fixed a bug where jobs resume would not produce any output for
previously failed jobs. (#3103)</li>
<li>Fixed a bug where FileBlob transfers with EntraID on the source
would pass the wrong service version. (#3242)</li>
<li>Fixed a bug to retry on WSAETIMEDOUT on Windows. (#3195)</li>
<li>Fixed a bug with the folder creation tracker which caused folder
creation calls to happen more often than necessary. (#3151)</li>
<li>Fixed a bug to redact x-ams-credential from logs. (#3206)</li>
<li>Fixed a bug where powershell login would fail with older versions
of Az.Accounts. (#3191)</li>
<li>Fixed a bug where symlink direct targets would be handled as a file
instead of a symlink. (#3222)</li>
<li>Refactored traverser related code into its own package. (#3251)</li>
<li>Refactored OAuth token manager access to use a client-based pattern
instead of global singleton access. (#3260)</li>
<li>Removed unused code related to credential management. (#3260)</li>
<li>Refactored Lifecycle UI code into the cmd package (#3262).</li>
<li>Error handling code is now injected into JobMgr, or appropriately
bubbled upwards instead of using global LCM error handling. (#3262)</li>
<li>AzCopy no longer checks version by default. (#3173)</li>
<li>Fixed --exclude-path flag not available in remove operations. (#3165) (#3159)</li>
<li>Fixed regression where AzCopy was not honoring concurrency value
in copy operations (#3192)</li>
<li>Fixed the incorrect JSON output format of the warning message when
there are multiple AzCopy processes running. (#3188) (#3182)</li>
<li>Fixed latest_version.txt from being wrongly created in users
current directory. (#3179)(#3176)</li>
<li>Fixed AzCopy crashing during sync operation from a nil pointer deref
in the destination authentication policy. (#3186) (#3109) (#3156) (#3175)</li>
<li>Golang 1.24.2 -> 1.24.6 (CVE-2025-47907) (#3154)</li>
<li>For transfers involving Azure Files (NFS or SMB), AzCopy will not auto
create file shares.</li>
<li>AzCopy binaries and latest version information will now be distributed
from Github releases instead of the static website. (#3014)</li>
<li>Azure Files NFS Support via REST.</li>
<li>Added support to retry on copy source error code and status code for service
to service copies. (#3105)</li>
<li>Added support for service to service copies from Azure Files to Blob Storage
using EntraID. (#3053)</li>
<li>Fixed a bug where when copying a file that has already been deleted with
--trailing-dot=Disable resulted in the wrong error instead of a 404. (#3092)</li>
<li>Removed the warning message when failing to create a container. This message
can be misleading when there is insufficient permissions to create a container
and the container already exists. (#3045)</li>
<li>Improved the error message returned when block size is larger than bandwidth
limit. (#3051)</li>
<li>Warn user if transfer is going to exceed 10M objects. (#3111)</li>
<li>Warn user if multiple AzCopy processes are running. (#3128)</li>
<li>Golang 1.24.2 -> 1.24.4 (#3085)</li>
<li>Azure Files NFS Support via REST API</li>
</ul>
<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">
<li class="list-group-item">
openSUSE Leap 15.4
<br/>
<code>zypper in -t patch SUSE-2026-2466=1</code>
</li>
<li class="list-group-item">
Public Cloud Module 15-SP4
<br/>
<code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2466=1</code>
</li>
<li class="list-group-item">
Public Cloud Module 15-SP5
<br/>
<code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2466=1</code>
</li>
<li class="list-group-item">
Public Cloud Module 15-SP6
<br/>
<code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-2466=1</code>
</li>
<li class="list-group-item">
Public Cloud Module 15-SP7
<br/>
<code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2466=1</code>
</li>
</ul>
<h2>Package List:</h2>
<ul>
<li>
openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
<ul>
<li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
</ul>
</li>
<li>
Public Cloud Module 15-SP4 (aarch64 ppc64le x86_64)
<ul>
<li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
</ul>
</li>
<li>
Public Cloud Module 15-SP5 (aarch64 ppc64le x86_64)
<ul>
<li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
</ul>
</li>
<li>
Public Cloud Module 15-SP6 (aarch64 ppc64le x86_64)
<ul>
<li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
</ul>
</li>
<li>
Public Cloud Module 15-SP7 (aarch64 ppc64le x86_64)
<ul>
<li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
</ul>
</li>
</ul>
<h2>References:</h2>
<ul>
<li>
<a href="https://www.suse.com/security/cve/CVE-2025-47907.html">https://www.suse.com/security/cve/CVE-2025-47907.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-33186.html">https://www.suse.com/security/cve/CVE-2026-33186.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-33814.html">https://www.suse.com/security/cve/CVE-2026-33814.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-34986.html">https://www.suse.com/security/cve/CVE-2026-34986.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-39821.html">https://www.suse.com/security/cve/CVE-2026-39821.html</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1247720">https://bugzilla.suse.com/show_bug.cgi?id=1247720</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1260307">https://bugzilla.suse.com/show_bug.cgi?id=1260307</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1262962">https://bugzilla.suse.com/show_bug.cgi?id=1262962</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1265841">https://bugzilla.suse.com/show_bug.cgi?id=1265841</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1266311">https://bugzilla.suse.com/show_bug.cgi?id=1266311</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1266657">https://bugzilla.suse.com/show_bug.cgi?id=1266657</a>
</li>
</ul>
</div>