SUSE and openSUSE Address DoS Vulnerability CVE-2026-41178

SUSE and openSUSE Address DoS Vulnerability CVE-2026-41178

First seen 3 Sep 2026, 17:39 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

SUSE and openSUSE have released updates to address a moderate denial-of-service (DoS) vulnerability identified as CVE-2026-41178. This vulnerability affects the google-cloud-sap-agent and apptainer, allowing attackers to exploit oversized inputs due to a lack of rejection of raw-length headers in baggage parsing. The vulnerability was published on June 4, 2026, and has a CVSS score of 5.3, indicating a moderate threat level. Users of SUSE Linux Enterprise Server, High Performance Computing, and openSUSE Leap are advised to apply the patches to mitigate potential risks. The patches can be installed using SUSE's recommended methods, such as YaST online_update or zypper patch. Both advisories emphasize the importance of timely updates to maintain system security.

Key Points: • CVE-2026-41178 allows DoS via oversized inputs in baggage parsing. • Affected systems include google-cloud-sap-agent and apptainer on multiple SUSE versions. • Moderate severity with a CVSS score of 5.3; patches are available.

Timeline

2026-06-04
CVE-2026-41178 published
A vulnerability allowing DoS via oversized inputs was disclosed, affecting multiple SUSE products.
Linuxsecurity
2026-08-31
SUSE releases patch for google-cloud-sap-agent
SUSE issued an update to fix the DoS vulnerability in google-cloud-sap-agent, urging users to apply the patch.
Linuxsecurity
2026-09-01
SUSE releases patch for apptainer
openSUSE released an update to address the same vulnerability in apptainer, recommending immediate patching.
Linuxsecurity