openSUSE-SU-2026:0232-1: important: Security update for go-sendxmpp

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for go-sendxmpp
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0232-1
Rating:             important
References:         #1265538 #1266617 
Cross-References:   CVE-2026-1229 CVE-2026-39821
CVSS scores:
                    CVE-2026-1229 (SUSE): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
                    CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:

   This update for go-sendxmpp fixes the following issues:

   Update to 0.16.0:

   - CVE-2026-1229: circl: The CombinedMult function produces an incorrect
     value (boo#1265538).
   - CVE-2026-39821: net: Failure to reject ASCII-only Punycode-encoded
     labels allows for validation bypass and privilege escalation
     (boo#1266617).


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-232=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      go-sendxmpp-0.16.0-bp157.2.9.1


References:

   https://www.suse.com/security/cve/CVE-2026-1229.html
   https://www.suse.com/security/cve/CVE-2026-39821.html
   https://bugzilla.suse.com/1265538
   https://bugzilla.suse.com/1266617
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.