Linuxsecurity
SUSE and openSUSE Address DoS Vulnerability CVE-2026-41178
Article Content
SUSE and openSUSE have released updates to address a moderate denial-of-service (DoS) vulnerability identified as CVE-2026-41178. This vulnerability affects the google-cloud-sap-agent and apptainer, allowing attackers to exploit oversized inputs due to a lack of rejection of raw-length headers in baggage parsing. The vulnerability was published on June 4, 2026, and has a CVSS score of 5.3, indicating a moderate threat level. Users of SUSE Linux Enterprise Server, High Performance Computing, and openSUSE Leap are advised to apply the patches to mitigate potential risks. The patches can be installed using SUSE's recommended methods, such as YaST online_update or zypper patch. Both advisories emphasize the importance of timely updates to maintain system security.
Key Points: • CVE-2026-41178 allows DoS via oversized inputs in baggage parsing. • Affected systems include google-cloud-sap-agent and apptainer on multiple SUSE versions. • Moderate severity with a CVSS score of 5.3; patches are available.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.