openSUSE-SU-2026:21406-1: important: Security update for aws-nitro-enclaves-cli

[email protected] Fri, 24 Jul 2026 17:52:22 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for aws-nitro-enclaves-cli
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21406-1
Rating: important
References:

  * bsc#1270492
  * bsc#1270542
  * bsc#1270705
  * bsc#1270747
  * bsc#1270839
  * bsc#1270932
  * bsc#1270952



Cross-References:

  * CVE-2026-41677
  * CVE-2026-41678
  * CVE-2026-41681
  * CVE-2026-41898
  * CVE-2026-42327
  * CVE-2026-44662
  * CVE-2026-45784



CVSS scores:

  * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
  * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
  * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
  * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 7 vulnerabilities and has 7 bug fixes can now be installed.

Description:

This update for aws-nitro-enclaves-cli fixes the following issues:

- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-
  openssl crate (bsc#1270542).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270705).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate
  (bsc#1270747).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent
  memory in rust-openssl crate (bsc#1270839).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate
  (bsc#1270492).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate
  (bsc#1270932).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-
  openssl crate (bsc#1270952).

Changes for aws-nitro-enclaves-cli:

- Update to version 1.4.5.


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1316=1

Package List:

- openSUSE Leap 16.0:

  aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-160000.1.1
  aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-160000.1.1
  system-group-ne-1.4.5~git0.18a5f6f-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-41677.html
  * https://www.suse.com/security/cve/CVE-2026-41678.html
  * https://www.suse.com/security/cve/CVE-2026-41681.html
  * https://www.suse.com/security/cve/CVE-2026-41898.html
  * https://www.suse.com/security/cve/CVE-2026-42327.html
  * https://www.suse.com/security/cve/CVE-2026-44662.html
  * https://www.suse.com/security/cve/CVE-2026-45784.html