Linuxsecurity
SUSE and openSUSE Azure Storage AzCopy Security Update Addresses Critical Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
An important security update for azure-storage-azcopy has been released, addressing two critical vulnerabilities: CVE-2026-39821 and CVE-2026-56852. CVE-2026-39821 allows for validation bypass and privilege escalation due to improper handling of Punycode-encoded labels, while CVE-2026-56852 can lead to an infinite loop from invalid UTF-8 input. Both vulnerabilities affect systems using the azcopy tool, with potential impacts on data integrity and system security. The update includes version 10.32.6, which also implements compliance with the FIPS 140-3 standard. Users are advised to apply the patches immediately to mitigate risks. The vulnerabilities were published on May 22 and July 21, 2026, respectively. The update is critical for maintaining the security of affected systems.
Key Points: • Two critical vulnerabilities (CVE-2026-39821, CVE-2026-56852) fixed in the update. • CVE-2026-39821 allows privilege escalation through validation bypass. • Immediate patching is recommended for all users of azure-storage-azcopy.