openSUSE-SU-2026:0292-1: important: Security update for ctop

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for ctop
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0292-1
Rating:             important
References:         #1248710 #1257431 #1265800 #1266632 #1267805 
                    
Cross-References:   CVE-2022-21698 CVE-2024-45310 CVE-2026-10722
                    CVE-2026-33814 CVE-2026-39821
CVSS scores:
                    CVE-2022-21698 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
                    CVE-2024-45310 (SUSE): 3.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
                    CVE-2026-10722 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
                    CVE-2026-33814 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
                    CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes 5 vulnerabilities is now available.

Description:

   This update for ctop fixes the following issues:

   - CVE-2022-21698: Denial of service using InstrumentHandlerCounter
     (boo#1248710) Bump client_golang to 1.11.1
   - CVE-2024-45310: runc can be tricked into creating empty files
     (boo#1257431) Add disable-runc.patch
   - CVE-2026-10722: Crash when parsing malformed ELF/BTF input (boo#1267805)
     ebpf is a transitive dependency of runc. Which isn't used anymore.
   - CVE-2026-33814: Infinite loop in HTTP/2 transport when given bad
     SETTINGS_MAX_FRAME_SIZE (boo#1265800) Bump net to 0.47.0
   - CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels
     (boo#1266632) Bump net to 0.47.0


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-292=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      ctop-0.7.7-bp157.2.3.1


References:

   https://www.suse.com/security/cve/CVE-2022-21698.html
   https://www.suse.com/security/cve/CVE-2024-45310.html
   https://www.suse.com/security/cve/CVE-2026-10722.html
   https://www.suse.com/security/cve/CVE-2026-33814.html
   https://www.suse.com/security/cve/CVE-2026-39821.html
   https://bugzilla.suse.com/1248710
   https://bugzilla.suse.com/1257431
   https://bugzilla.suse.com/1265800
   https://bugzilla.suse.com/1266632
   https://bugzilla.suse.com/1267805
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.