openSUSE-SU-2026:0239-1: important: Security update for flannel

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for flannel
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0239-1
Rating:             important
References:         #1265780 #1266620 
Cross-References:   CVE-2026-33814 CVE-2026-39821
CVSS scores:
                    CVE-2026-33814 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
                    CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:

   This update for flannel fixes the following issues:

   - Update to version 0.28.7:
     * prepare for release v0.28.7 (#2485)
     * fix: use install-conf in chart (#2484)
     * fix: use semver tag type in Docker meta to support release events
       (#2483)
     * build(deps): bump github/codeql-action/upload-sarif (#2480)
     * build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 (#2473), fix
       for CVE-2026-33814 (boo#1265780) and CVE-2026-39821 (boo#1266620)
     * build(deps): bump docker/build-push-action from 7.2.0 to 7.3.0 (#2479)
     * build(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0
       (#2478)
     * build(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 (#2476)
     * build(deps): bump the tencent group with 2 updates (#2475)
     * build(deps): bump the etcd group with 4 updates (#2474)
     * fix: skip invalid CIDRs in subnet file readers (#2454)
     * subnet/etcd: recover subnet watch from compaction (#2471)
     * Bump the tencent group across 1 directory with 2 updates (#2461)
     * Bump actions/attest-build-provenance from 4.1.0 to 4.1.1 (#2467)
     * Bump actions/setup-go from 6.4.0 to 6.5.0 (#2468)
     * feat: new install_conf cmd to install flannel's config file (#2466)
     * Bump the other-go-modules group with 2 updates (#2464)
     * Bump actions/checkout from 6.0.2 to 7.0.0 (#2465)
     * Bump github/codeql-action from 4.36.0 to 4.36.2 (#2463)


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-239=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      flannel-0.28.7-bp157.2.12.1

   - openSUSE Backports SLE-15-SP7 (noarch):

      flannel-k8s-yaml-0.28.7-bp157.2.12.1


References:

   https://www.suse.com/security/cve/CVE-2026-33814.html
   https://www.suse.com/security/cve/CVE-2026-39821.html
   https://bugzilla.suse.com/1265780
   https://bugzilla.suse.com/1266620
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.