<div class="container">
    <h1>Security update for azure-storage-azcopy</h1>

    <table class="table table-striped table-bordered">
        <tbody>
        <tr>
            <th>Announcement ID:</th>
            <td>SUSE-SU-2026:2466-1</td>
        </tr>
        <tr>
            <th>Release Date:</th>
            <td>2026-06-19T11:02:49Z</td>
        </tr>
        
        <tr>
            <th>Rating:</th>
            <td>important</td>
        </tr>
        <tr>
            <th>References:</th>
            <td>
                <ul>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1247720">bsc#1247720</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1260307">bsc#1260307</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262962">bsc#1262962</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1265841">bsc#1265841</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1266311">bsc#1266311</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://bugzilla.suse.com/show_bug.cgi?id=1266657">bsc#1266657</a>
                        </li>
                    
                    
                </ul>
            </td>
        </tr>
        
            <tr>
                <th>
                    Cross-References:
                </th>
                <td>
                    <ul>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2025-47907.html">CVE-2025-47907</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-33186.html">CVE-2026-33186</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-33814.html">CVE-2026-33814</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-34986.html">CVE-2026-34986</a>
                        </li>
                    
                        <li style="display: inline;">
                            <a href="https://www.suse.com/security/cve/CVE-2026-39821.html">CVE-2026-39821</a>
                        </li>
                    
                    </ul>
                </td>
            </tr>
            <tr>
                <th>CVSS scores:</th>
                <td>
                    <ul class="list-group">
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2025-47907</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">2.1</span>
                                <span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2025-47907</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">5.7</span>
                                <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2025-47907</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.0</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33186</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.6</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33186</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33186</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33814</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33814</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-33814</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-34986</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">8.7</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-34986</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-34986</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.5</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-39821</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.1</span>
                                <span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-39821</span>
                                <span class="cvss-source">
                                    (
                                    
                                        SUSE
                                    
                                    ):
                                </span>
                                <span class="cvss-score">7.4</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</span>
                            </li>
                        
                            <li class="list-group-item">
                                <span class="cvss-reference">CVE-2026-39821</span>
                                <span class="cvss-source">
                                    (
                                    
                                        NVD
                                    
                                    ):
                                </span>
                                <span class="cvss-score">9.6</span>
                                <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N</span>
                            </li>
                        
                    </ul>
                </td>
            </tr>
        
        <tr>
            <th>Affected Products:</th>
            <td>
                <ul class="list-group">
                    
                        <li class="list-group-item">openSUSE Leap 15.4</li>
                    
                        <li class="list-group-item">Public Cloud Module 15-SP4</li>
                    
                        <li class="list-group-item">Public Cloud Module 15-SP5</li>
                    
                        <li class="list-group-item">Public Cloud Module 15-SP6</li>
                    
                        <li class="list-group-item">Public Cloud Module 15-SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP6</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server 15 SP7</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP4</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP5</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP6</li>
                    
                        <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP7</li>
                    
                        <li class="list-group-item">SUSE Manager Proxy 4.3</li>
                    
                        <li class="list-group-item">SUSE Manager Retail Branch Server 4.3</li>
                    
                        <li class="list-group-item">SUSE Manager Server 4.3</li>
                    
                </ul>
            </td>
        </tr>
        </tbody>
    </table>

    <p>An update that solves five vulnerabilities and has one security fix can now be installed.</p>

    


    
        <h2>Description:</h2>
    
    <p>This update for azure-storage-azcopy fixes the following issues</p>
<p>Update to 10.32.4:</p>
<ul>
<li>CVE-2025-47907: database/sql: incorrect results returned from Rows.Scan (bsc#1247720).</li>
<li>CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-
  header (bsc#1260307).</li>
<li>CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE
  (bsc#1265841).</li>
<li>CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of
  service (bsc#1262962).</li>
<li>CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
  bypass and privilege escalation (bsc#1266657).</li>
</ul>
<p>Changes:</p>
<ul>
<li>Remove 32-bit Windows ARM7 build</li>
<li>Cover other open CVEs (bsc#1266657, CVE-2026-39821)</li>
<li>Update otel sdk</li>
<li>Update packages and add patch version</li>
<li>Update version.go</li>
<li>Error formatting</li>
<li>Add test to validate changes</li>
<li>Update Changelog</li>
<li>Alter intentional panics to return errors</li>
<li>Correct issues re: MSRC case #110341</li>
<li>Update offending packages</li>
<li>cloud.google.com/go/storage v1.45.0 -> v1.50.0</li>
<li>Golang 1.24.13 -> 1.25.8</li>
<li>Golangci-lint v1.64.8 -> v2.11.3</li>
<li>Fixed a regression where the folder tracker would panic with
   pre-existing folders and --overwrite=ifSourceNewer. (#3403)</li>
<li>Fixed a regression where cancellation was not working via stdin (#3373)</li>
<li>Fixed a regression where we hit segfaults from logging
   to a nil logger in the process checker. (#3384)</li>
<li>Fixed a race condition panic from concurrent access to a
   shared metadata resource by introducing thread safety. (#3341)</li>
<li>Fixed a bug where --posix-properties-style was not being chained
   through the copy flow correctly. (#3401)</li>
<li>Fixed a regression where in tandem use of --list-of-files
   and --include-pattern no longer worked. (#3389)</li>
<li>Golang 1.24.11 -> 1.24.13</li>
<li>Added support for AMLFS style posix metadata. (#3317)</li>
<li>Fixed a bug where hdi_isfolder metadata key would sometimes
   not be sent in all lowercase, resulting in unexpected behavior
   on the service side when fetching properties. (#3312)</li>
<li>Fixed a typo in the benchmark command, to allow the --put-md5 flag to work. (#3324)</li>
<li>Fixed a bug where network errors would not be retried on. (#3338)</li>
<li>Fixed a bug where unexpected requests would be logged in syslog. (#3339)</li>
<li>Fixed a bug where pre-existing folders would be recreated. (#3295)</li>
<li>Updated README to clarify supported source-destination pairs and
   authorization mechanisms. (#3213)</li>
<li>Updated format of wiki generated docs to improve readability. (#3311)</li>
<li>AzCopy download URLs starting with https://azcopyvnext-awgzd8g7aagqhzhe.b02.azurefd.net/
   are no longer supported.</li>
<li>Fixed a bug where throughput was not being displayed for copy and resume. (#3271)</li>
<li>Fixed a bug where S3 and GCP transfers would panic. (#3273)</li>
<li>Refactored copy, sync, resume, login, logout, login status
   business logic into the azcopy package.</li>
<li>Golang 1.24.4 -> 1.24.11</li>
<li>golang.org/x/crypto 0.40.0 -> 0.45.0</li>
<li>Azure Files SMB -> Azure Files NFS transfers.</li>
<li>Symlink support for Azure Files NFS shares.</li>
<li>Introduced support for symbolic links in Azure Files NFS shares.</li>
<li>Symlinks can be preserved, skipped, or followed based on command-line flags.</li>
<li>Added a --check-version flag to make version checking an opt in feature. (#3173)</li>
<li>--include-root flag now allows customers to preserve root properties
   when used in conjunction with --preserve-XXXX flags. (#3163)</li>
<li>Golang 1.24.4 -> 1.24.6 (#3154)</li>
<li>Fixed a bug to retry on various network errors. (#3237) (#3252) (bsc#1266311)</li>
<li>Fixed a bug where remove would not work on paths with encoded characters. (#2977)</li>
<li>Fixed a bug where jobs resume would not produce any output for
   previously failed jobs. (#3103)</li>
<li>Fixed a bug where FileBlob transfers with EntraID on the source
   would pass the wrong service version. (#3242)</li>
<li>Fixed a bug to retry on WSAETIMEDOUT on Windows. (#3195)</li>
<li>Fixed a bug with the folder creation tracker which caused folder
   creation calls to happen more often than necessary. (#3151)</li>
<li>Fixed a bug to redact x-ams-credential from logs. (#3206)</li>
<li>Fixed a bug where powershell login would fail with older versions
   of Az.Accounts. (#3191)</li>
<li>Fixed a bug where symlink direct targets would be handled as a file
   instead of a symlink. (#3222)</li>
<li>Refactored traverser related code into its own package. (#3251)</li>
<li>Refactored OAuth token manager access to use a client-based pattern
   instead of global singleton access. (#3260)</li>
<li>Removed unused code related to credential management. (#3260)</li>
<li>Refactored Lifecycle UI code into the cmd package (#3262).</li>
<li>Error handling code is now injected into JobMgr, or appropriately
   bubbled upwards instead of using global LCM error handling. (#3262)</li>
<li>AzCopy no longer checks version by default. (#3173)</li>
<li>Fixed --exclude-path flag not available in remove operations. (#3165) (#3159)</li>
<li>Fixed regression where AzCopy was not honoring concurrency value
   in copy operations (#3192)</li>
<li>Fixed the incorrect JSON output format of the warning message when
   there are multiple AzCopy processes running. (#3188) (#3182)</li>
<li>Fixed latest_version.txt from being wrongly created in users
   current directory. (#3179)(#3176)</li>
<li>Fixed AzCopy crashing during sync operation from a nil pointer deref
   in the destination authentication policy. (#3186) (#3109) (#3156) (#3175)</li>
<li>Golang 1.24.2 -> 1.24.6 (CVE-2025-47907) (#3154)</li>
<li>For transfers involving Azure Files (NFS or SMB), AzCopy will not auto
   create file shares.</li>
<li>AzCopy binaries and latest version information will now be distributed
   from Github releases instead of the static website. (#3014)</li>
<li>Azure Files NFS Support via REST.</li>
<li>Added support to retry on copy source error code and status code for service
   to service copies. (#3105)</li>
<li>Added support for service to service copies from Azure Files to Blob Storage
   using EntraID. (#3053)</li>
<li>Fixed a bug where when copying a file that has already been deleted with
   --trailing-dot=Disable resulted in the wrong error instead of a 404. (#3092)</li>
<li>Removed the warning message when failing to create a container. This message
   can be misleading when there is insufficient permissions to create a container
   and the container already exists. (#3045)</li>
<li>Improved the error message returned when block size is larger than bandwidth
   limit. (#3051)</li>
<li>Warn user if transfer is going to exceed 10M objects. (#3111)</li>
<li>Warn user if multiple AzCopy processes are running. (#3128)</li>
<li>Golang 1.24.2 -> 1.24.4 (#3085)</li>
<li>Azure Files NFS Support via REST API</li>
</ul>



    

    <h2>Patch Instructions:</h2>
    <p>
        To install this SUSE  update use the SUSE recommended
        installation methods like YaST online_update or "zypper patch".<br/>

        Alternatively you can run the command listed for your product:
    </p>
    <ul class="list-group">
        
            <li class="list-group-item">
                openSUSE Leap 15.4
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-2026-2466=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Public Cloud Module 15-SP4
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2466=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Public Cloud Module 15-SP5
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2466=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Public Cloud Module 15-SP6
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-2466=1</code>
                    
                    
                
            </li>
        
            <li class="list-group-item">
                Public Cloud Module 15-SP7
                
                    
                        <br/>
                        <code>zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2466=1</code>
                    
                    
                
            </li>
        
    </ul>

    <h2>Package List:</h2>
    <ul>
        
            
                <li>
                    openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
                    <ul>
                        
                            <li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    Public Cloud Module 15-SP4 (aarch64 ppc64le x86_64)
                    <ul>
                        
                            <li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    Public Cloud Module 15-SP5 (aarch64 ppc64le x86_64)
                    <ul>
                        
                            <li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    Public Cloud Module 15-SP6 (aarch64 ppc64le x86_64)
                    <ul>
                        
                            <li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
                        
                    </ul>
                </li>
            
        
            
                <li>
                    Public Cloud Module 15-SP7 (aarch64 ppc64le x86_64)
                    <ul>
                        
                            <li>azure-storage-azcopy-10.32.4-150400.9.11.1</li>
                        
                    </ul>
                </li>
            
        
    </ul>

    
        <h2>References:</h2>
        <ul>
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2025-47907.html">https://www.suse.com/security/cve/CVE-2025-47907.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-33186.html">https://www.suse.com/security/cve/CVE-2026-33186.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-33814.html">https://www.suse.com/security/cve/CVE-2026-33814.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-34986.html">https://www.suse.com/security/cve/CVE-2026-34986.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://www.suse.com/security/cve/CVE-2026-39821.html">https://www.suse.com/security/cve/CVE-2026-39821.html</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1247720">https://bugzilla.suse.com/show_bug.cgi?id=1247720</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1260307">https://bugzilla.suse.com/show_bug.cgi?id=1260307</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1262962">https://bugzilla.suse.com/show_bug.cgi?id=1262962</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1265841">https://bugzilla.suse.com/show_bug.cgi?id=1265841</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1266311">https://bugzilla.suse.com/show_bug.cgi?id=1266311</a>
                    </li>
                
            
                
                    <li>
                        <a href="https://bugzilla.suse.com/show_bug.cgi?id=1266657">https://bugzilla.suse.com/show_bug.cgi?id=1266657</a>
                    </li>
                
            
        </ul>
    
</div>