OPENSUSE-SU-2026:21999-1

Vulnerability from csaf_opensuse - Published: 2026-09-28 15:31 - Updated: 2026-10-01 16:39
Summary
Security update for rclone
Severity
Important
Notes
Title of the patch: Security update for rclone
Description of the patch: This update for rclone fixes the following issues: Changes in rclone: - Update to version 1.75.1: (boo#1279548) - Security - archive - Fix zip slip path traversal in untrusted zip files GHSA-66hp-wgxq-6f5q CVE-PENDING (Nick Craig-Wood) - Hide any archive entry which escapes the directory being listed GHSA-66hp-wgxq-6f5q (Nick Craig-Wood) - Reject unsafe entry names when mounting squashfs images GHSA-66hp-wgxq-6f5q (Nick Craig-Wood) - Fix zip subdirectory root matching sibling directories GHSA-66hp-wgxq-6f5q (Nick Craig-Wood) - Fix zip entry named "." hiding every other file GHSA-66hp-wgxq-6f5q (Nick Craig-Wood) - Fix "directory not found" for archive paths containing "./" or "//" GHSA-66hp-wgxq-6f5q (Nick Craig-Wood) - build - Fix multiple CVEs by upgrading to go1.26.6 (Nick Craig-Wood) - CVE-2026-56860: net/url: quadratic complexity in resolvePath - CVE-2026-56858: html/template: JavaScript regexp context tracking - CVE-2026-56862: crypto/tls: limit handshake messages accepted post-handshake - CVE-2026-56853: net/http: apply ReadHeaderTimeout to unencrypted HTTP/2 check - CVE-2026-56859: encoding/xml: recursion depth guard during decode - CVE-2026-33818: encoding/asn1: enforce maximum recursion depth - CVE-2026-46600: net: panic parsing an invalid SVCB or HTTPS RR in dnsmessage - CVE-2026-39821: net/http: reject ASCII-only Punycode-encoded labels in idna - Update golang.org/x/crypto to v0.56.0 to fix multiple CVEs (Nick Craig-Wood) - CVE-2026-56854: ssh: source-address critical option not enforced for non-public-key auth callbacks - CVE-2026-78662: ssh: a malicious peer could flood an undecided channel's incoming requests, deadlocking the connection - CVE-2026-56855: ssh: a malicious peer could send crafted messages on an established channel, deadlocking the connection - Update golang.org/x/image to v0.45.0 to fix CVE-2026-46603 (Nick Craig-Wood) - CVE-2026-46603: excessive memory allocation during VP8L decoding - fs: Confine directory listing entries that escape the root GHSA-3vxh-3pcx-9m8q GHSA-38xv-hf3p-h7mq CVE-PENDING (Nick Craig-Wood) - fshttp: Don't send --header values to other hosts on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood) - http: Don't leak configured headers to other hosts or over plaintext on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood) - lib/rest: Check HTTPS downgrades against the original request on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood) - local - Fix dir metadata escaping the root through a planted symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood) - Fix btime escaping the root via a planted symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood) - Fix panic on Range request past the end of a symlink GHSA-p6m2-r3w9-mpxw CVE-PENDING (Nick Craig-Wood) - serve docker - Reject volume names that escape the base directory GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood) - Reject volume names resolving to the base directory itself GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood) - Re-derive volume mountpoint from name when restoring state GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood) - serve ftp: Fix auth-proxy sessions sharing credentials by username GHSA-c476-6w5q-jw77 CVE-PENDING (Nick Craig-Wood) - serve s3 - Fix memory exhaustion from client-declared multipart part size GHSA-2p48-j3qc-rx9f CVE-PENDING (Nick Craig-Wood) - Reject bogus multipart part sizes in the reorder buffer GHSA-2p48-j3qc-rx9f (Nick Craig-Wood) - Fix auth proxy accepting any request signed with an empty secret GHSA-xwwr-4h3p-r22c CVE-PENDING (Nick Craig-Wood) - NB the auth proxy protocol for serve s3 has changed - the proxy program is now given the access key ID as user and must return the secret as _secret_access_key - Fix each server accepting the --auth-key credentials of all the others (Nick Craig-Wood) - Fix misleading anonymous access log when using an auth proxy via rc GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood) - serve sftp: Fix auth proxy configured via rc being silently ignored GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood) - Bug Fixes - accounting - Fix memory leak on long-running rcd (nielash) - Fix memory leak from stats groups on long-running rcd (nielash) - Fix bwlimit burst overflow (Rayan Salhab) - bisync - Fix memory leak when running via the rc (nielash) - Fix failed transfers of empty files being recorded as synced (Nick Craig-Wood) - build: Make go1.26 the minimum required version as needed by golang.org/x/crypto v0.56.0 (Nick Craig-Wood) - config: Redact env var config values in logs (Pastalikek65) - doc fixes (Anton Karpov, CAOShurong, Dean Chen, Nick Craig-Wood, Recoordinate, Rodrigo Rodrigues, Shantanav Mukherjee, shaurya) - lib/batcher: Prevent commits racing shutdown (Loi Nguyen) - lib/transform: Fix panic in truncate_keep_extension (VXNCXNX) - multipart: Fix chunked uploads storing truncated objects when the source ends early (Nick Craig-Wood) - operations: Fix silent truncation of streaming uploads whose source ends early (Nick Craig-Wood) - serve - Fix VFS instance leaks on server startup failures and shutdown (Hakan İSMAİL) - Pass the client IP address to the auth proxy (am-at-enrollvb) - serve http: Prevent scrolling to the top on page reload (Sune Mølgaard) - serve nfs: Fix EIO when creating symlinks with --vfs-links (SillyZir) - serve s3 - Fix failed uploads deleting or corrupting the object at the key (Nick Craig-Wood) - Fix crash when a multipart upload is aborted while a part is uploading (Nick Craig-Wood) - Fix modtime not being set when only mtime metadata is supplied on PUT (Nick Craig-Wood) - Upload all multipart uploads via the VFS so they obey --bwlimit and show in stats (Nick Craig-Wood) - Reserve the .rclone_temp_ prefix for temporary objects (Nick Craig-Wood) - Clean up abandoned multipart uploads after --multipart-expiry (Nick Craig-Wood) - vfscache - Fix reader deadlock when the item size drops below the read offset (Dave) - Fix log message growing without bound on repeated write errors (Vijay Misal) - walk: Stop directory traversal when the context is cancelled (Rahman Yilmaz) - VFS - Synchronize poll updates with shutdown (Loi Nguyen) - Make poll shutdown lifecycle deterministic (Loi Nguyen) - Crypt - Fix hash mismatches with no_data_encryption on backends which check upload hashes (Nick Craig-Wood) - Fix directory names which look like versioned file names (TowyTowy) - Warn about directories with legacy version-like encrypted names (Nick Craig-Wood) - Azure Blob - Fix Entra ID server-side copy source authentication (Edward Klesel) - Fix spurious vfs cache corruption errors during chunked reads (Nick Craig-Wood) - Azurefiles - Fix zero padded files being created when the source ends early (Nick Craig-Wood) - Box - Fix truncated files being uploaded successfully when the source ends early (Rohit Behera) - Compress - Fix corrupted objects being created when the source ends early (Nick Craig-Wood) - Drive - Don't list trashed files when removing a directory into the trash (alliasgher) - Dropbox - Preserve Paper export paths on lookup (Loi Nguyen) - Fix context cancellation (e.g. --max-duration limit) not stopping in-flight requests (debaditya) - Fix chunked uploads of truncated files never finishing (Nick Craig-Wood) - Don't retry chunked upload requests when the upload has been cancelled (Nick Craig-Wood) - Decode received shared-file names (Sanjay Kanth A) - Fix ChangeNotify when the root's case differs from Dropbox's (Loi Nguyen) - Filelu - Fix truncated files being uploaded successfully when the source ends early (Nick Craig-Wood) - Fix duplicate root path during multipart folder creation (kingston125) - Huaweidrive - Fix truncated files being uploaded successfully when the source ends early (Rohit Behera) - Iclouddrive - Fix uploads into an app container failing with 412 (Christian De Santis) - Internetarchive - Fix corrupted files being created when the source ends early (Nick Craig-Wood) - Internxt - Persist rotated token returned by the user info call (0rangeSeaW0lf) - Onedrive - Fix 403 Forbidden for configuration personal onedrive (machsix) - Fall back to manual drive ID entry when drive listing fails (SillyZir) - Don't retry multipart upload chunk on 404 (upload session not found) (water) - Overview - Fix "internal error: no overview data found" on 32 bit architectures (Nick Craig-Wood) - Pikpak - Fix truncated files being created when the source ends early (Nick Craig-Wood) - Fix truncated single part uploads reported as ok when source ends early (Nick Craig-Wood) - Protondrive - Fix files uploaded with v1.75.0 not being readable in the Proton apps (Nick Craig-Wood) - Fix corrupted uploads after a retried upload error (Nick Craig-Wood) - Quatrix - Fix chunk upload retries and fix memory leak (Nick Craig-Wood) - S3 - Update Mega endpoints (Nick Craig-Wood) - Treat UploadPart success without ETag as retryable error (CAOShurong) - Fix server side copy failing with --s3-no-head-object (Anatoly Tarnavsky) - Sia - Fix corrupted files being created when the source ends early (Nick Craig-Wood) - Smb - Reuse the upload connection for SetModTime (alliasgher) - WebDAV - Fix SetModTime failing and hashes missing on Nextcloud (Nick Craig-Wood) - Yandex - Fix truncated files being uploaded successfully when the source ends early (Rohit Behera) - Update to version 1.75.0: - New S3 Providers - Scality (RING / ARTESCA) - Zero Services (ZERO-Z3) - Security - archive: Don't crash on malformed squashfs images GHSA-6jcg-q3wp-x2f4 CVE-PENDING (Nick Craig-Wood) - ftp: Fix ftp command injection when encoding doesn't include CRLF GHSA-8c48-q9wj-3w37 CVE-PENDING (Nick Craig-Wood) - lib/http: Use TLS on all --addr listeners when --cert and --key are set GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood) - lib/proxy: Fix unbounded HTTP CONNECT headers causing OOM GHSA-xhf4-832v-7xcr CVE-PENDING (Nick Craig-Wood) - local: Stop source file names escaping the destination directory GHSA-7p4m-qxvv-g567 CVE-PENDING (Nick Craig-Wood) - rc - Don't expose pprof debug handlers on an unauthenticated server GHSA-mfvx-7rcj-9m5g CVE-PENDING (Nick Craig-Wood) - Require authentication to list the remotes with --rc-serve GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood) - Fix leaking stack traces on panics GHSA-gwfq-86j8-7qhv (Nick Craig-Wood) - s3 - Fix redirect credential leaks, reject HTTPS->HTTP and strip secrets GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood) - Strip S3 Express session token on cross-host redirects GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood) - serve ftp: Use constant time comparison for password check GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood) - serve restic: Fix path traversal above the served directory GHSA-45pq-889g-fcgh CVE-PENDING (Nick Craig-Wood) - serve sftp: Don't crash the whole server on a bad request GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood) - sftp: Fix command injection via crafted filenames on PowerShell remotes GHSA-2m8m-jhrm-w6j2 CVE-PENDING (Nick Craig-Wood) - vfs: Don't crash the process if a backend panics on a background goroutine GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood) - webdav - Fix HTTPS to HTTP redirects leaking credentials GHSA-h4mf-4v27-hggj (Nick Craig-Wood) - Tus: fix potential nil pointer crash GHSA-3x6r-wxxg-53vv (Nick Craig-Wood) - Update google.golang.org/grpc to fix multiple security problems (Nick Craig-Wood) - New Features - build: Update all dependencies (Nick Craig-Wood) - config - Add config unset command to remove options from a remote (Nick Craig-Wood) - Add tier to config wizard (dougal) - docker serve - Add timeout to volume restore so slow remotes don't block startup (Nick Craig-Wood) - Restore volumes concurrently so one slow remote doesn't block others (Nick Craig-Wood) - Make Create idempotent to avoid "volume already exists" after restart (Nick Craig-Wood) - doc fixes (blackflytech, dougal, Giridhar, KTibow, mathieulongtin, Nick Craig-Wood, p1, Socialpranker, Søren Lindberg, yashanil98) - filter - Support nested {} alternates in glob filters (maximilize) - Add --files-from0 to support NUL-delimited input (Gaurav) - fserrors: Make http2 "server sent GOAWAY" a retriable error (phatlc) - fshttp - Add --dump errors to dump only failed HTTP transactions (Nick Craig-Wood) - Add --dump trace to log connection level events via httptrace (Nick Craig-Wood) - gui - Serve static files with gzip/deflate compression (Leon Brocard) - Respect explicit --rc-allow-origin instead of always deriving it from the bind address (Kyue) - Update embedded release to 1.1.11 (Nick Craig-Wood) - mount2: Add --allow-idmap to advertise FUSE_ALLOW_IDMAP (Valerij Fredriksen) - nfsmount: Call mount_nfs directly on OpenBSD so -T is accepted (Socialpranker) - rc - Respond with 202 if prefer-async header is passed (FTCHD) - Add config/oauthstop and config/oauthstatus to control oauth listener (FTCHD) - Include OAuth authorization URL in rc config/oauthstatus response (Hakan İSMAİL) - Allow setting rc config and filter options as flat parameters (Hakan İSMAİL) - serve - Support custom http response headers (kkocdko) - Update serve remote control to accept nested as well as flat options (Hakan İSMAİL) - serve dlna: Bound SOAP request bodies (Acts1631) - serve nfs - Allow NFS clients to mount subpaths of the served remote (Nick Craig-Wood) - Advertise AUTH_UNIX so the *BSD NFS clients can mount (Socialpranker) - serve s3: Stream multipart uploads to the backend instead of buffering in memory (Nick Craig-Wood) - serve sftp - Implement statvfs@openssh.com to report disk usage (Nick Craig-Wood) - Use the requested atime when setting file times (Nick Craig-Wood) - serve webdav: Add gzip compression for compressible responses (Leon Brocard) - serve http: Add --disable-dir-list flag (Leon Brocard) - Bug Fixes - archive/squashfs: Fix reading images with no fragment or xattr table (maximilize) - chunkedreader: Fix spurious errors when a parallel stream is closed early (Nick Craig-Wood) - config - Fix config_template_file and config_template being ignored via config/create (hexbinoct) - Fix normalization when obscuring passwords (Nick Craig-Wood) - docker serve: Fix plugin timeout on restart when volumes have active mounts (Nick Craig-Wood) - fs: Fix passwords and tokens appearing in the debug log during rclone config (Nick Craig-Wood) - gui: Fix cross-origin API requests when bound to a wildcard address (FTCHD) - hash: Fix xxh128 hasher size (Yuhang Cao) - log: Fix side effects when importing rclone as a library (Sven Rebhan) - march - Fix unnecessarily listing dst directory when src listing finished (Nick Craig-Wood) - Fix goroutine leak on completed async rc jobs (Yash Anil) - nfsmount: Fix mount_nfs options incompatible with OpenBSD (Socialpranker) - rc - Fix operations/stat for directories with large parent dirs (Nick Craig-Wood) - Fix _filter and _config parameters being ignored by mount/* commands (Hakan İSMAİL) - serve: Fix auth proxy using stale config parameters when making a backend (Nick Craig-Wood) - serve s3 - Fix aborted multipart uploads appearing as ghosts (Nick Craig-Wood) - Fix streamed multipart uploads not being atomic (Nick Craig-Wood) - Fix OOM and InvalidPart errors with concurrent multipart uploads (Nick Craig-Wood) - sync: Fix --fix-case rename on backends that need upload before overwrite (Nick Craig-Wood) - Mount - Support flat VFS and Mount options in mount RC command (Hakan İSMAİL) - VFS - Fix IO error by recreating the cache file if it has been removed (Nick Craig-Wood) - Fix "invalid seek position" error when cache files larger than the remote (Nick Craig-Wood) - Fix vfs cache writeback timer not being stopped when --transfers reached (Nick Craig-Wood) - Fix crash when multiple mounts or servers share the same VFS (Nick Craig-Wood) - Local - Add --local-fatal-if-no-space flag (ferrumclaudepilgrim) - Don't resolve relative roots to absolute paths (Nick Craig-Wood) - Archive - Fix squashfs listings failing with invalid argument after update (Nick Craig-Wood) - Azure Blob - Fix MD5 being dropped on range reads causing vfs cache re-downloads (Nick Craig-Wood) - Add use_arrow_list flag for experimental Apache Arrow listing (Nick Craig-Wood) - List very large containers in parallel with list_parallelism (Nick Craig-Wood) - Azurefiles - Fix incorrect modtime after uploading a file or setting its modtime (Nick Craig-Wood) - Improve modtime precision from 1s to 100ns (Nick Craig-Wood) - Combine - Don't return an error message as the remote name for a bad object (Nick Craig-Wood) - Drime - Remove stale mux_status field from Item (Nick Craig-Wood) - Drive - Warn in config wizard before using the shared client_id (Nick Craig-Wood) - Detect shortcut loops to avoid infinite recursion (Nick Craig-Wood) - Dropbox - Add support for impersonate_admin (Gaurav) - Add --dropbox-skip-shared-folders and --dropbox-skip-unowned-folders (Gaurav) - Make Rmdir use one less API call (Socialpranker) - Use much less memory when uploading small files (Nick Craig-Wood) - Remove an unnecessary API call when uploading small files (Nick Craig-Wood) - Filen - Fix incorrect modtime after updating a file or setting its modtime (Nick Craig-Wood) - Filescom - Fix missing MD5 hash after uploading a file (Nick Craig-Wood) - FTP - Fix incorrect modtime after uploading a file or setting its modtime (Nick Craig-Wood) - Googlephotos - Warn in config wizard before using the shared client_id (Nick Craig-Wood) - Hasher - Fix Update not storing hashes in bolt DB after file replacement (Nick Craig-Wood) - Hdfs - Fix incorrect modtime after uploading a file or setting its modtime (Nick Craig-Wood) - Hidrive - Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood) - HTTP - Don't list parent directory when pointing at a single file (Nick Craig-Wood) - Add Prefer to CORS Access-Control-Allow-Headers header (sijie-Z) - Iclouddrive - Fix "cannot unmarshal number" error when listing photo albums (Nick Craig-Wood) - Fix 2FA failing with 409 even when the code is valid (Punya Jain) - Imagekit - Fix Open with a RangeOption returning the wrong data (Nick Craig-Wood) - Add mtime to the available metadata (Nick Craig-Wood) - Internxt - Add Move and DirMove methods for server-side file and directory operations (jzunigax2) - Handle file size limit errors during uploads (jzunigax2) - Surface re-login error when re-auth fails in NewFs (0rangeSeaW0lf) - Jottacloud - Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood) - Linkbox - Retry bot protection HTML challenge responses instead of failing (Nick Craig-Wood) - Mailru - Fix incorrect modtime after updating a file or setting its modtime (Nick Craig-Wood) - Mega - Fix files reappearing in listings after being renamed (Nick Craig-Wood) - Fix moved files disappearing from listings between remotes (Nick Craig-Wood) - Netstorage - Fix missing MD5 hash after uploading a file (Nick Craig-Wood) - Onedrive - Add support for no admin mode (TaterLi) - Treat non-2xx preauth download as error (ifloppy) - Download malware-flagged files via Graph Prefer header (ifloppy) - Opendrive - Fix uploaded objects returning the wrong hash and modtime (Nick Craig-Wood) - Oracleobjectstorage - Fix crash when downloading objects with unknown length (Nick Craig-Wood) - Add --oos-decompress flag to download gzip-encoded files (Nick Craig-Wood) - Pixeldrain - Fix incorrect modtime and missing hash after uploading a file (Nick Craig-Wood) - Protondrive - Implement proper retry logic (tomholford) - Fix gopenpgp: invalid data: user ID signature with wrong type on custom-domain account (Nick Craig-Wood) - Fix long hangs on permanent validation failures (Nick Craig-Wood) - Fix incorrect modtime after uploading a file (Nick Craig-Wood) - Putio - Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood) - Fix sync deletions failing with 400 TRASH_LOCK_TIMEOUT errors (Nick Craig-Wood) - Quatrix - Fix incorrect modtime after uploading a file (Nick Craig-Wood) - S3 - Add Zero Services (ZERO-Z3) provider (Zero Services GmbH) - Add Scality (RING / ARTESCA) provider (Dzmitry Nianakhau) - Seafile - Fix rclone sync files with identical size again and again (TowyTowy) - SFTP - Add --sftp-pin-host-key - Trust On First Use host key pinning (Nick Craig-Wood) - Add --sftp-encoding support (Puneet Dixit) - Don't retry permanent connection errors (Nick Craig-Wood) - Allow silencing no hostkey validation warning (Noah Zalev) - Fix cmd shell execution of paths containing variable-expansion or newline characters (Nick Craig-Wood) - Shade - Retry server errors instead of failing the transfer (Nick Craig-Wood) - Fix uploads failing with EOF when completing multipart uploads (Nick Craig-Wood) - Smb - Fix Kerberos credentials being reloaded for every connection (Nick Craig-Wood) - Fix TCP connection leak when connection setup fails (Nick Craig-Wood) - Fix server-side move of directories with special characters in the name (Nick Craig-Wood) - Fix spurious "Directory already exists" errors when moving directories (Nick Craig-Wood) - Ulozto - Fix server side moves between differently rooted remotes losing files (Nick Craig-Wood) - WebDAV - Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood) - Yandex - Fix 500 errors by waiting for uploads to complete before setting modtime (Nick Craig-Wood) - Fix missing MD5 hash after uploading a file (Nick Craig-Wood) - Fix modtime randomly reverting to the upload time after upload (Nick Craig-Wood) - Add --yandex-upload-wait to fix 500 errors when uploading (Nick Craig-Wood) - Zoho - Honour Retry-After header on 429 (Erol Ozcan) - Add --zoho-tpslimit and --zoho-tpslimit-burst (Erol Ozcan) - Log throttling once per episode at NOTICE (Erol Ozcan) - Rate limit repeated listings of the same folder (Erol Ozcan) - Fix flaky folder list limiter test under concurrent listings (Nick Craig-Wood) - Fix large file overwrite creating a duplicate instead of replacing (Erol Ozcan) - Treat R008 unauthorized as directory not found (Erol Ozcan) - Preserve root_folder_id on reconnect and allow setting it (Erol Ozcan)
Patchnames: openSUSE-Leap-16.0-packagehub-641
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Product Identifier Version Remediation
Unresolved product id: openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64 —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch —
Vendor Fix
Unresolved product id: openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch —
Vendor Fix
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact moderate
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact moderate
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact moderate
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
Affected products
Recommended 5 products, the same list as for CVE-2026-33818
Threats
Impact important
References
URL Category
https://www.suse.com/support/security/rating/ external
https://ftp.suse.com/pub/projects/security/csaf/o… self
https://bugzilla.suse.com/1279548 self
https://www.suse.com/security/cve/CVE-2026-33818/ self
https://www.suse.com/security/cve/CVE-2026-39821/ self
https://www.suse.com/security/cve/CVE-2026-46600/ self
https://www.suse.com/security/cve/CVE-2026-46603/ self
https://www.suse.com/security/cve/CVE-2026-56853/ self
https://www.suse.com/security/cve/CVE-2026-56854/ self
https://www.suse.com/security/cve/CVE-2026-56855/ self
https://www.suse.com/security/cve/CVE-2026-56858/ self
https://www.suse.com/security/cve/CVE-2026-56859/ self
https://www.suse.com/security/cve/CVE-2026-56860/ self
https://www.suse.com/security/cve/CVE-2026-56862/ self
https://www.suse.com/security/cve/CVE-2026-78662/ self
https://www.suse.com/security/cve/CVE-2026-33818 external
https://bugzilla.suse.com/1275034 external
https://www.suse.com/security/cve/CVE-2026-39821 external
https://bugzilla.suse.com/1266474 external
https://www.suse.com/security/cve/CVE-2026-46600 external
https://bugzilla.suse.com/1272415 external
https://www.suse.com/security/cve/CVE-2026-46603 external
https://bugzilla.suse.com/1279547 external
https://www.suse.com/security/cve/CVE-2026-56853 external
https://bugzilla.suse.com/1275028 external
https://www.suse.com/security/cve/CVE-2026-56854 external
https://bugzilla.suse.com/1278446 external
https://bugzilla.suse.com/1280553 external
https://www.suse.com/security/cve/CVE-2026-56855 external
https://bugzilla.suse.com/1278446 external
https://bugzilla.suse.com/1280553 external
https://www.suse.com/security/cve/CVE-2026-56858 external
https://bugzilla.suse.com/1275033 external
https://www.suse.com/security/cve/CVE-2026-56859 external
https://bugzilla.suse.com/1275026 external
https://www.suse.com/security/cve/CVE-2026-56860 external
https://bugzilla.suse.com/1275029 external
https://www.suse.com/security/cve/CVE-2026-56862 external
https://bugzilla.suse.com/1275032 external
https://www.suse.com/security/cve/CVE-2026-78662 external
https://bugzilla.suse.com/1278446 external
https://bugzilla.suse.com/1280553 external

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Security update for rclone",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "This update for rclone fixes the following issues:\n\nChanges in rclone:\n\n- Update to version 1.75.1: (boo#1279548)\n  - Security\n    - archive\n      - Fix zip slip path traversal in untrusted zip files\n        GHSA-66hp-wgxq-6f5q CVE-PENDING (Nick Craig-Wood)\n      - Hide any archive entry which escapes the directory being\n        listed GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Reject unsafe entry names when mounting squashfs images\n        GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Fix zip subdirectory root matching sibling directories\n        GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Fix zip entry named \".\" hiding every other file\n        GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n      - Fix \"directory not found\" for archive paths containing \"./\"\n        or \"//\" GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n    - build\n      - Fix multiple CVEs by upgrading to go1.26.6 (Nick\n        Craig-Wood)\n        - CVE-2026-56860: net/url: quadratic complexity in\n          resolvePath\n        - CVE-2026-56858: html/template: JavaScript regexp context\n          tracking\n        - CVE-2026-56862: crypto/tls: limit handshake messages\n          accepted post-handshake\n        - CVE-2026-56853: net/http: apply ReadHeaderTimeout to\n          unencrypted HTTP/2 check\n        - CVE-2026-56859: encoding/xml: recursion depth guard\n          during decode\n        - CVE-2026-33818: encoding/asn1: enforce maximum recursion\n          depth\n        - CVE-2026-46600: net: panic parsing an invalid SVCB or\n          HTTPS RR in dnsmessage\n        - CVE-2026-39821: net/http: reject ASCII-only\n          Punycode-encoded labels in idna\n      - Update golang.org/x/crypto to v0.56.0 to fix multiple CVEs\n        (Nick Craig-Wood)\n        - CVE-2026-56854: ssh: source-address critical option not\n          enforced for non-public-key auth callbacks\n        - CVE-2026-78662: ssh: a malicious peer could flood an\n          undecided channel\u0027s incoming requests, deadlocking the\n          connection\n        - CVE-2026-56855: ssh: a malicious peer could send crafted\n          messages on an established channel, deadlocking the\n          connection\n      - Update golang.org/x/image to v0.45.0 to fix CVE-2026-46603\n        (Nick Craig-Wood)\n        - CVE-2026-46603: excessive memory allocation during VP8L\n          decoding\n      - fs: Confine directory listing entries that escape the root\n        GHSA-3vxh-3pcx-9m8q GHSA-38xv-hf3p-h7mq CVE-PENDING (Nick\n        Craig-Wood)\n      - fshttp: Don\u0027t send --header values to other hosts on\n        redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood)\n      - http: Don\u0027t leak configured headers to other hosts or over\n        plaintext on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick\n        Craig-Wood)\n      - lib/rest: Check HTTPS downgrades against the original\n        request on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick\n        Craig-Wood)\n      - local\n        - Fix dir metadata escaping the root through a planted\n          symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)\n        - Fix btime escaping the root via a planted symlink\n          GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)\n        - Fix panic on Range request past the end of a symlink\n          GHSA-p6m2-r3w9-mpxw CVE-PENDING (Nick Craig-Wood)\n      - serve docker\n        - Reject volume names that escape the base directory\n          GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n        - Reject volume names resolving to the base directory\n          itself GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n        - Re-derive volume mountpoint from name when restoring\n          state GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n      - serve ftp: Fix auth-proxy sessions sharing credentials by\n        username GHSA-c476-6w5q-jw77 CVE-PENDING (Nick Craig-Wood)\n      - serve s3\n        - Fix memory exhaustion from client-declared multipart part\n          size GHSA-2p48-j3qc-rx9f CVE-PENDING (Nick Craig-Wood)\n        - Reject bogus multipart part sizes in the reorder buffer\n          GHSA-2p48-j3qc-rx9f (Nick Craig-Wood)\n        - Fix auth proxy accepting any request signed with an empty\n          secret GHSA-xwwr-4h3p-r22c CVE-PENDING (Nick Craig-Wood)\n        - NB the auth proxy protocol for serve s3 has changed - the\n          proxy program is now given the access key ID as user and\n          must return the secret as _secret_access_key\n        - Fix each server accepting the --auth-key credentials of\n          all the others (Nick Craig-Wood)\n        - Fix misleading anonymous access log when using an auth\n          proxy via rc GHSA-p569-5gjg-9cmj CVE-PENDING (Nick\n          Craig-Wood)\n      - serve sftp: Fix auth proxy configured via rc being silently\n        ignored GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood)\n  - Bug Fixes\n    - accounting\n      - Fix memory leak on long-running rcd (nielash)\n      - Fix memory leak from stats groups on long-running rcd\n        (nielash)\n      - Fix bwlimit burst overflow (Rayan Salhab)\n    - bisync\n      - Fix memory leak when running via the rc (nielash)\n      - Fix failed transfers of empty files being recorded as\n        synced (Nick Craig-Wood)\n    - build: Make go1.26 the minimum required version as needed by\n      golang.org/x/crypto v0.56.0 (Nick Craig-Wood)\n    - config: Redact env var config values in logs (Pastalikek65)\n    - doc fixes (Anton Karpov, CAOShurong, Dean Chen, Nick\n      Craig-Wood, Recoordinate, Rodrigo Rodrigues, Shantanav\n      Mukherjee, shaurya)\n    - lib/batcher: Prevent commits racing shutdown (Loi Nguyen)\n    - lib/transform: Fix panic in truncate_keep_extension (VXNCXNX)\n    - multipart: Fix chunked uploads storing truncated objects when\n      the source ends early (Nick Craig-Wood)\n    - operations: Fix silent truncation of streaming uploads whose\n      source ends early (Nick Craig-Wood)\n    - serve\n      - Fix VFS instance leaks on server startup failures and\n        shutdown (Hakan \u0130SMA\u0130L)\n      - Pass the client IP address to the auth proxy\n        (am-at-enrollvb)\n    - serve http: Prevent scrolling to the top on page reload (Sune\n      M\u00f8lgaard)\n    - serve nfs: Fix EIO when creating symlinks with --vfs-links\n      (SillyZir)\n    - serve s3\n      - Fix failed uploads deleting or corrupting the object at the\n        key (Nick Craig-Wood)\n      - Fix crash when a multipart upload is aborted while a part\n        is uploading (Nick Craig-Wood)\n      - Fix modtime not being set when only mtime metadata is\n        supplied on PUT (Nick Craig-Wood)\n      - Upload all multipart uploads via the VFS so they obey\n        --bwlimit and show in stats (Nick Craig-Wood)\n      - Reserve the .rclone_temp_ prefix for temporary objects\n        (Nick Craig-Wood)\n      - Clean up abandoned multipart uploads after\n        --multipart-expiry (Nick Craig-Wood)\n    - vfscache\n      - Fix reader deadlock when the item size drops below the read\n        offset (Dave)\n      - Fix log message growing without bound on repeated write\n        errors (Vijay Misal)\n    - walk: Stop directory traversal when the context is cancelled\n      (Rahman Yilmaz)\n  - VFS\n    - Synchronize poll updates with shutdown (Loi Nguyen)\n    - Make poll shutdown lifecycle deterministic (Loi Nguyen)\n  - Crypt\n    - Fix hash mismatches with no_data_encryption on backends which\n      check upload hashes (Nick Craig-Wood)\n    - Fix directory names which look like versioned file names\n      (TowyTowy)\n    - Warn about directories with legacy version-like encrypted\n      names (Nick Craig-Wood)\n  - Azure Blob\n    - Fix Entra ID server-side copy source authentication (Edward\n      Klesel)\n    - Fix spurious vfs cache corruption errors during chunked reads\n      (Nick Craig-Wood)\n  - Azurefiles\n    - Fix zero padded files being created when the source ends\n      early (Nick Craig-Wood)\n  - Box\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Rohit Behera)\n  - Compress\n    - Fix corrupted objects being created when the source ends\n      early (Nick Craig-Wood)\n  - Drive\n    - Don\u0027t list trashed files when removing a directory into the\n      trash (alliasgher)\n  - Dropbox\n    - Preserve Paper export paths on lookup (Loi Nguyen)\n    - Fix context cancellation (e.g. --max-duration limit) not\n      stopping in-flight requests (debaditya)\n    - Fix chunked uploads of truncated files never finishing (Nick\n      Craig-Wood)\n    - Don\u0027t retry chunked upload requests when the upload has been\n      cancelled (Nick Craig-Wood)\n    - Decode received shared-file names (Sanjay Kanth A)\n    - Fix ChangeNotify when the root\u0027s case differs from Dropbox\u0027s\n      (Loi Nguyen)\n  - Filelu\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Nick Craig-Wood)\n    - Fix duplicate root path during multipart folder creation\n      (kingston125)\n  - Huaweidrive\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Rohit Behera)\n  - Iclouddrive\n    - Fix uploads into an app container failing with 412 (Christian\n      De Santis)\n  - Internetarchive\n    - Fix corrupted files being created when the source ends early\n      (Nick Craig-Wood)\n  - Internxt\n    - Persist rotated token returned by the user info call\n      (0rangeSeaW0lf)\n  - Onedrive\n    - Fix 403 Forbidden for configuration personal onedrive\n      (machsix)\n    - Fall back to manual drive ID entry when drive listing fails\n      (SillyZir)\n    - Don\u0027t retry multipart upload chunk on 404 (upload session not\n      found) (water)\n  - Overview\n    - Fix \"internal error: no overview data found\" on 32 bit\n      architectures (Nick Craig-Wood)\n  - Pikpak\n    - Fix truncated files being created when the source ends early\n      (Nick Craig-Wood)\n    - Fix truncated single part uploads reported as ok when source\n      ends early (Nick Craig-Wood)\n  - Protondrive\n    - Fix files uploaded with v1.75.0 not being readable in the\n      Proton apps (Nick Craig-Wood)\n    - Fix corrupted uploads after a retried upload error (Nick\n      Craig-Wood)\n  - Quatrix\n    - Fix chunk upload retries and fix memory leak (Nick\n      Craig-Wood)\n  - S3\n    - Update Mega endpoints (Nick Craig-Wood)\n    - Treat UploadPart success without ETag as retryable error\n      (CAOShurong)\n    - Fix server side copy failing with --s3-no-head-object\n      (Anatoly Tarnavsky)\n  - Sia\n    - Fix corrupted files being created when the source ends early\n      (Nick Craig-Wood)\n  - Smb\n    - Reuse the upload connection for SetModTime (alliasgher)\n  - WebDAV\n    - Fix SetModTime failing and hashes missing on Nextcloud (Nick\n      Craig-Wood)\n  - Yandex\n    - Fix truncated files being uploaded successfully when the\n      source ends early (Rohit Behera)\n\n- Update to version 1.75.0:\n  - New S3 Providers\n    - Scality (RING / ARTESCA)\n    - Zero Services (ZERO-Z3)\n  - Security\n    - archive: Don\u0027t crash on malformed squashfs images\n      GHSA-6jcg-q3wp-x2f4 CVE-PENDING (Nick Craig-Wood)\n    - ftp: Fix ftp command injection when encoding doesn\u0027t include\n      CRLF GHSA-8c48-q9wj-3w37 CVE-PENDING (Nick Craig-Wood)\n    - lib/http: Use TLS on all --addr listeners when --cert and\n      --key are set GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n    - lib/proxy: Fix unbounded HTTP CONNECT headers causing OOM\n      GHSA-xhf4-832v-7xcr CVE-PENDING (Nick Craig-Wood)\n    - local: Stop source file names escaping the destination\n      directory GHSA-7p4m-qxvv-g567 CVE-PENDING (Nick Craig-Wood)\n    - rc\n      - Don\u0027t expose pprof debug handlers on an unauthenticated\n        server GHSA-mfvx-7rcj-9m5g CVE-PENDING (Nick Craig-Wood)\n      - Require authentication to list the remotes with --rc-serve\n        GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n      - Fix leaking stack traces on panics GHSA-gwfq-86j8-7qhv\n        (Nick Craig-Wood)\n    - s3\n      - Fix redirect credential leaks, reject HTTPS-\u003eHTTP and strip\n        secrets GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)\n      - Strip S3 Express session token on cross-host redirects\n        GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)\n      - serve ftp: Use constant time comparison for password check\n        GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n      - serve restic: Fix path traversal above the served directory\n        GHSA-45pq-889g-fcgh CVE-PENDING (Nick Craig-Wood)\n      - serve sftp: Don\u0027t crash the whole server on a bad request\n        GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)\n      - sftp: Fix command injection via crafted filenames on\n        PowerShell remotes GHSA-2m8m-jhrm-w6j2 CVE-PENDING (Nick\n        Craig-Wood)\n      - vfs: Don\u0027t crash the process if a backend panics on a\n        background goroutine GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)\n    - webdav\n      - Fix HTTPS to HTTP redirects leaking credentials\n        GHSA-h4mf-4v27-hggj (Nick Craig-Wood)\n      - Tus: fix potential nil pointer crash GHSA-3x6r-wxxg-53vv\n        (Nick Craig-Wood)\n    - Update google.golang.org/grpc to fix multiple security\n      problems (Nick Craig-Wood)\n  - New Features\n    - build: Update all dependencies (Nick Craig-Wood)\n    - config\n      - Add config unset command to remove options from a remote\n        (Nick Craig-Wood)\n      - Add tier to config wizard (dougal)\n    - docker serve\n      - Add timeout to volume restore so slow remotes don\u0027t block\n        startup (Nick Craig-Wood)\n      - Restore volumes concurrently so one slow remote doesn\u0027t\n        block others (Nick Craig-Wood)\n      - Make Create idempotent to avoid \"volume already exists\"\n        after restart (Nick Craig-Wood)\n    - doc fixes (blackflytech, dougal, Giridhar, KTibow,\n      mathieulongtin, Nick Craig-Wood, p1, Socialpranker, S\u00f8ren\n      Lindberg, yashanil98)\n    - filter\n      - Support nested {} alternates in glob filters (maximilize)\n      - Add --files-from0 to support NUL-delimited input (Gaurav)\n    - fserrors: Make http2 \"server sent GOAWAY\" a retriable error\n      (phatlc)\n    - fshttp\n      - Add --dump errors to dump only failed HTTP transactions\n        (Nick Craig-Wood)\n      - Add --dump trace to log connection level events via\n        httptrace (Nick Craig-Wood)\n    - gui\n      - Serve static files with gzip/deflate compression (Leon\n        Brocard)\n      - Respect explicit --rc-allow-origin instead of always\n        deriving it from the bind address (Kyue)\n      - Update embedded release to 1.1.11 (Nick Craig-Wood)\n    - mount2: Add --allow-idmap to advertise FUSE_ALLOW_IDMAP\n      (Valerij Fredriksen)\n    - nfsmount: Call mount_nfs directly on OpenBSD so -T is\n      accepted (Socialpranker)\n    - rc\n      - Respond with 202 if prefer-async header is passed (FTCHD)\n      - Add config/oauthstop and config/oauthstatus to control\n        oauth listener (FTCHD)\n      - Include OAuth authorization URL in rc config/oauthstatus\n        response (Hakan \u0130SMA\u0130L)\n      - Allow setting rc config and filter options as flat\n        parameters (Hakan \u0130SMA\u0130L)\n    - serve\n      - Support custom http response headers (kkocdko)\n      - Update serve remote control to accept nested as well as\n        flat options (Hakan \u0130SMA\u0130L)\n    - serve dlna: Bound SOAP request bodies (Acts1631)\n    - serve nfs\n      - Allow NFS clients to mount subpaths of the served remote\n        (Nick Craig-Wood)\n      - Advertise AUTH_UNIX so the *BSD NFS clients can mount\n        (Socialpranker)\n    - serve s3: Stream multipart uploads to the backend instead of\n      buffering in memory (Nick Craig-Wood)\n    - serve sftp\n      - Implement statvfs@openssh.com to report disk usage (Nick\n        Craig-Wood)\n      - Use the requested atime when setting file times (Nick\n        Craig-Wood)\n    - serve webdav: Add gzip compression for compressible responses\n      (Leon Brocard)\n    - serve http: Add --disable-dir-list flag (Leon Brocard)\n  - Bug Fixes\n    - archive/squashfs: Fix reading images with no fragment or\n      xattr table (maximilize)\n    - chunkedreader: Fix spurious errors when a parallel stream is\n      closed early (Nick Craig-Wood)\n    - config\n      - Fix config_template_file and config_template being ignored\n        via config/create (hexbinoct)\n      - Fix normalization when obscuring passwords (Nick\n        Craig-Wood)\n    - docker serve: Fix plugin timeout on restart when volumes have\n      active mounts (Nick Craig-Wood)\n    - fs: Fix passwords and tokens appearing in the debug log\n      during rclone config (Nick Craig-Wood)\n    - gui: Fix cross-origin API requests when bound to a wildcard\n      address (FTCHD)\n    - hash: Fix xxh128 hasher size (Yuhang Cao)\n    - log: Fix side effects when importing rclone as a library\n      (Sven Rebhan)\n    - march\n      - Fix unnecessarily listing dst directory when src listing\n        finished (Nick Craig-Wood)\n      - Fix goroutine leak on completed async rc jobs (Yash Anil)\n    - nfsmount: Fix mount_nfs options incompatible with OpenBSD\n      (Socialpranker)\n    - rc\n      - Fix operations/stat for directories with large parent dirs\n        (Nick Craig-Wood)\n      - Fix _filter and _config parameters being ignored by mount/*\n        commands (Hakan \u0130SMA\u0130L)\n    - serve: Fix auth proxy using stale config parameters when\n      making a backend (Nick Craig-Wood)\n    - serve s3\n      - Fix aborted multipart uploads appearing as ghosts (Nick\n        Craig-Wood)\n      - Fix streamed multipart uploads not being atomic (Nick\n        Craig-Wood)\n      - Fix OOM and InvalidPart errors with concurrent multipart\n        uploads (Nick Craig-Wood)\n    - sync: Fix --fix-case rename on backends that need upload\n      before overwrite (Nick Craig-Wood)\n    - Mount\n      - Support flat VFS and Mount options in mount RC command\n        (Hakan \u0130SMA\u0130L)\n    - VFS\n      - Fix IO error by recreating the cache file if it has been\n        removed (Nick Craig-Wood)\n      - Fix \"invalid seek position\" error when cache files larger\n        than the remote (Nick Craig-Wood)\n      - Fix vfs cache writeback timer not being stopped when\n        --transfers reached (Nick Craig-Wood)\n      - Fix crash when multiple mounts or servers share the same\n        VFS (Nick Craig-Wood)\n    - Local\n      - Add --local-fatal-if-no-space flag (ferrumclaudepilgrim)\n      - Don\u0027t resolve relative roots to absolute paths (Nick\n        Craig-Wood)\n    - Archive\n      - Fix squashfs listings failing with invalid argument after\n        update (Nick Craig-Wood)\n    - Azure Blob\n      - Fix MD5 being dropped on range reads causing vfs cache\n        re-downloads (Nick Craig-Wood)\n      - Add use_arrow_list flag for experimental Apache Arrow\n        listing (Nick Craig-Wood)\n      - List very large containers in parallel with\n        list_parallelism (Nick Craig-Wood)\n    - Azurefiles\n      - Fix incorrect modtime after uploading a file or setting its\n        modtime (Nick Craig-Wood)\n      - Improve modtime precision from 1s to 100ns (Nick\n        Craig-Wood)\n    - Combine\n      - Don\u0027t return an error message as the remote name for a bad\n        object (Nick Craig-Wood)\n    - Drime\n      - Remove stale mux_status field from Item (Nick Craig-Wood)\n    - Drive\n      - Warn in config wizard before using the shared client_id\n        (Nick Craig-Wood)\n      - Detect shortcut loops to avoid infinite recursion (Nick\n        Craig-Wood)\n    - Dropbox\n      - Add support for impersonate_admin (Gaurav)\n      - Add --dropbox-skip-shared-folders and\n        --dropbox-skip-unowned-folders (Gaurav)\n      - Make Rmdir use one less API call (Socialpranker)\n      - Use much less memory when uploading small files (Nick\n        Craig-Wood)\n      - Remove an unnecessary API call when uploading small files\n        (Nick Craig-Wood)\n    - Filen\n      - Fix incorrect modtime after updating a file or setting its\n        modtime (Nick Craig-Wood)\n    - Filescom\n      - Fix missing MD5 hash after uploading a file (Nick\n        Craig-Wood)\n    - FTP\n      - Fix incorrect modtime after uploading a file or setting its\n        modtime (Nick Craig-Wood)\n    - Googlephotos\n      - Warn in config wizard before using the shared client_id\n        (Nick Craig-Wood)\n    - Hasher\n      - Fix Update not storing hashes in bolt DB after file\n        replacement (Nick Craig-Wood)\n    - Hdfs\n      - Fix incorrect modtime after uploading a file or setting its\n        modtime (Nick Craig-Wood)\n    - Hidrive\n      - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n        Craig-Wood)\n    - HTTP\n      - Don\u0027t list parent directory when pointing at a single file\n        (Nick Craig-Wood)\n      - Add Prefer to CORS Access-Control-Allow-Headers header\n        (sijie-Z)\n    - Iclouddrive\n      - Fix \"cannot unmarshal number\" error when listing photo\n        albums (Nick Craig-Wood)\n      - Fix 2FA failing with 409 even when the code is valid (Punya\n        Jain)\n    - Imagekit\n      - Fix Open with a RangeOption returning the wrong data (Nick\n        Craig-Wood)\n      - Add mtime to the available metadata (Nick Craig-Wood)\n    - Internxt\n      - Add Move and DirMove methods for server-side file and\n        directory operations (jzunigax2)\n      - Handle file size limit errors during uploads (jzunigax2)\n      - Surface re-login error when re-auth fails in NewFs\n        (0rangeSeaW0lf)\n    - Jottacloud\n      - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n        Craig-Wood)\n    - Linkbox\n      - Retry bot protection HTML challenge responses instead of\n        failing (Nick Craig-Wood)\n    - Mailru\n      - Fix incorrect modtime after updating a file or setting its\n        modtime (Nick Craig-Wood)\n    - Mega\n      - Fix files reappearing in listings after being renamed (Nick\n        Craig-Wood)\n      - Fix moved files disappearing from listings between remotes\n        (Nick Craig-Wood)\n    - Netstorage\n      - Fix missing MD5 hash after uploading a file (Nick\n        Craig-Wood)\n    - Onedrive\n      - Add support for no admin mode (TaterLi)\n      - Treat non-2xx preauth download as error (ifloppy)\n      - Download malware-flagged files via Graph Prefer header\n        (ifloppy)\n    - Opendrive\n      - Fix uploaded objects returning the wrong hash and modtime\n        (Nick Craig-Wood)\n    - Oracleobjectstorage\n      - Fix crash when downloading objects with unknown length\n        (Nick Craig-Wood)\n      - Add --oos-decompress flag to download gzip-encoded files\n        (Nick Craig-Wood)\n    - Pixeldrain\n      - Fix incorrect modtime and missing hash after uploading a\n        file (Nick Craig-Wood)\n    - Protondrive\n      - Implement proper retry logic (tomholford)\n      - Fix gopenpgp: invalid data: user ID signature with wrong\n        type on custom-domain account (Nick Craig-Wood)\n      - Fix long hangs on permanent validation failures (Nick\n        Craig-Wood)\n      - Fix incorrect modtime after uploading a file (Nick\n        Craig-Wood)\n    - Putio\n      - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n        Craig-Wood)\n      - Fix sync deletions failing with 400 TRASH_LOCK_TIMEOUT\n        errors (Nick Craig-Wood)\n    - Quatrix\n      - Fix incorrect modtime after uploading a file (Nick\n        Craig-Wood)\n    - S3\n      - Add Zero Services (ZERO-Z3) provider (Zero Services GmbH)\n      - Add Scality (RING / ARTESCA) provider (Dzmitry Nianakhau)\n    - Seafile\n      - Fix rclone sync files with identical size again and again\n        (TowyTowy)\n    - SFTP\n      - Add --sftp-pin-host-key - Trust On First Use host key\n        pinning (Nick Craig-Wood)\n      - Add --sftp-encoding support (Puneet Dixit)\n      - Don\u0027t retry permanent connection errors (Nick Craig-Wood)\n      - Allow silencing no hostkey validation warning (Noah Zalev)\n      - Fix cmd shell execution of paths containing\n        variable-expansion or newline characters (Nick Craig-Wood)\n    - Shade\n      - Retry server errors instead of failing the transfer (Nick\n        Craig-Wood)\n      - Fix uploads failing with EOF when completing multipart\n        uploads (Nick Craig-Wood)\n    - Smb\n      - Fix Kerberos credentials being reloaded for every\n        connection (Nick Craig-Wood)\n      - Fix TCP connection leak when connection setup fails (Nick\n        Craig-Wood)\n      - Fix server-side move of directories with special characters\n        in the name (Nick Craig-Wood)\n      - Fix spurious \"Directory already exists\" errors when moving\n        directories (Nick Craig-Wood)\n    - Ulozto\n      - Fix server side moves between differently rooted remotes\n        losing files (Nick Craig-Wood)\n    - WebDAV\n      - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n        Craig-Wood)\n    - Yandex\n      - Fix 500 errors by waiting for uploads to complete before\n        setting modtime (Nick Craig-Wood)\n      - Fix missing MD5 hash after uploading a file (Nick\n        Craig-Wood)\n      - Fix modtime randomly reverting to the upload time after\n        upload (Nick Craig-Wood)\n      - Add --yandex-upload-wait to fix 500 errors when uploading\n        (Nick Craig-Wood)\n    - Zoho\n      - Honour Retry-After header on 429 (Erol Ozcan)\n      - Add --zoho-tpslimit and --zoho-tpslimit-burst (Erol Ozcan)\n      - Log throttling once per episode at NOTICE (Erol Ozcan)\n      - Rate limit repeated listings of the same folder (Erol\n        Ozcan)\n      - Fix flaky folder list limiter test under concurrent\n        listings (Nick Craig-Wood)\n      - Fix large file overwrite creating a duplicate instead of\n        replacing (Erol Ozcan)\n      - Treat R008 unauthorized as directory not found (Erol Ozcan)\n      - Preserve root_folder_id on reconnect and allow setting it\n        (Erol Ozcan)\n",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "openSUSE-Leap-16.0-packagehub-641",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_21999-1.json"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1279548",
        "url": "https://bugzilla.suse.com/1279548"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-33818 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-33818/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-39821 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-39821/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-46600 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-46600/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-46603 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-46603/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56853 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56853/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56854 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56854/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56855 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56855/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56858 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56858/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56859 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56859/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56860 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56860/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-56862 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-56862/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-78662 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-78662/"
      }
    ],
    "title": "Security update for rclone",
    "tracking": {
      "current_release_date": "2026-10-01T16:39:45Z",
      "generator": {
        "date": "2026-09-28T15:31:12Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "openSUSE-SU-2026:21999-1",
      "initial_release_date": "2026-09-28T15:31:12Z",
      "revision_history": [
        {
          "date": "2026-09-28T15:31:12Z",
          "number": "1",
          "summary": "Current version"
        },
        {
          "date": "2026-10-01T16:39:45Z",
          "number": "2",
          "summary": "unknown changes"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rclone-0:1.75.1-bp160.1.1.aarch64",
                "product": {
                  "name": "rclone-0:1.75.1-bp160.1.1.aarch64",
                  "product_id": "rclone-0:1.75.1-bp160.1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:rclone:rclone:1.75.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/rclone@1.75.1-bp160.1.1?arch=aarch64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
                "product": {
                  "name": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
                  "product_id": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/rclone-bash-completion@1.75.1-bp160.1.1?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
                "product": {
                  "name": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
                  "product_id": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/rclone-zsh-completion@1.75.1-bp160.1.1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rclone-0:1.75.1-bp160.1.1.ppc64le",
                "product": {
                  "name": "rclone-0:1.75.1-bp160.1.1.ppc64le",
                  "product_id": "rclone-0:1.75.1-bp160.1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:rclone:rclone:1.75.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/rclone@1.75.1-bp160.1.1?arch=ppc64le"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "ppc64le"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rclone-0:1.75.1-bp160.1.1.x86_64",
                "product": {
                  "name": "rclone-0:1.75.1-bp160.1.1.x86_64",
                  "product_id": "rclone-0:1.75.1-bp160.1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:rclone:rclone:1.75.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/rclone@1.75.1-bp160.1.1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "openSUSE Leap 16.0",
                "product": {
                  "name": "openSUSE Leap 16.0",
                  "product_id": "openSUSE Leap 16.0"
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rclone-0:1.75.1-bp160.1.1.aarch64 as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64"
        },
        "product_reference": "rclone-0:1.75.1-bp160.1.1.aarch64",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rclone-0:1.75.1-bp160.1.1.ppc64le as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le"
        },
        "product_reference": "rclone-0:1.75.1-bp160.1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rclone-0:1.75.1-bp160.1.1.x86_64 as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64"
        },
        "product_reference": "rclone-0:1.75.1-bp160.1.1.x86_64",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch"
        },
        "product_reference": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        },
        "product_reference": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-33818",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-33818"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-33818",
          "url": "https://www.suse.com/security/cve/CVE-2026-33818"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275034 for CVE-2026-33818",
          "url": "https://bugzilla.suse.com/1275034"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-33818"
    },
    {
      "cve": "CVE-2026-39821",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-39821"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-39821",
          "url": "https://www.suse.com/security/cve/CVE-2026-39821"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1266474 for CVE-2026-39821",
          "url": "https://bugzilla.suse.com/1266474"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-39821"
    },
    {
      "cve": "CVE-2026-46600",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-46600"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-46600",
          "url": "https://www.suse.com/security/cve/CVE-2026-46600"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272415 for CVE-2026-46600",
          "url": "https://bugzilla.suse.com/1272415"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-46600"
    },
    {
      "cve": "CVE-2026-46603",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-46603"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-46603",
          "url": "https://www.suse.com/security/cve/CVE-2026-46603"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279547 for CVE-2026-46603",
          "url": "https://bugzilla.suse.com/1279547"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-46603"
    },
    {
      "cve": "CVE-2026-56853",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56853"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56853",
          "url": "https://www.suse.com/security/cve/CVE-2026-56853"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275028 for CVE-2026-56853",
          "url": "https://bugzilla.suse.com/1275028"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56853"
    },
    {
      "cve": "CVE-2026-56854",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56854"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client\u0027s remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56854",
          "url": "https://www.suse.com/security/cve/CVE-2026-56854"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278446 for CVE-2026-56854",
          "url": "https://bugzilla.suse.com/1278446"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280553 for CVE-2026-56854",
          "url": "https://bugzilla.suse.com/1280553"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56854"
    },
    {
      "cve": "CVE-2026-56855",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56855"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56855",
          "url": "https://www.suse.com/security/cve/CVE-2026-56855"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278446 for CVE-2026-56855",
          "url": "https://bugzilla.suse.com/1278446"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280553 for CVE-2026-56855",
          "url": "https://bugzilla.suse.com/1280553"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56855"
    },
    {
      "cve": "CVE-2026-56858",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56858"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Previously, pathological inputs could close an unescaped \u0027/\u0027 early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56858",
          "url": "https://www.suse.com/security/cve/CVE-2026-56858"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275033 for CVE-2026-56858",
          "url": "https://bugzilla.suse.com/1275033"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-56858"
    },
    {
      "cve": "CVE-2026-56859",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56859"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56859",
          "url": "https://www.suse.com/security/cve/CVE-2026-56859"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275026 for CVE-2026-56859",
          "url": "https://bugzilla.suse.com/1275026"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56859"
    },
    {
      "cve": "CVE-2026-56860",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56860"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Previously, resolving relative paths containing parent directory (\u0027..\u0027) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for \u0027..\u0027 segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56860",
          "url": "https://www.suse.com/security/cve/CVE-2026-56860"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275029 for CVE-2026-56860",
          "url": "https://bugzilla.suse.com/1275029"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-56860"
    },
    {
      "cve": "CVE-2026-56862",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-56862"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-56862",
          "url": "https://www.suse.com/security/cve/CVE-2026-56862"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275032 for CVE-2026-56862",
          "url": "https://bugzilla.suse.com/1275032"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-56862"
    },
    {
      "cve": "CVE-2026-78662",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-78662"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Previously, a channel registered in the mux\u0027s chanList is not usable until it is established. A malicious peer was able flood the channel\u0027s incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
          "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
          "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
          "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-78662",
          "url": "https://www.suse.com/security/cve/CVE-2026-78662"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278446 for CVE-2026-78662",
          "url": "https://bugzilla.suse.com/1278446"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280553 for CVE-2026-78662",
          "url": "https://bugzilla.suse.com/1280553"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
            "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
            "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
            "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-28T15:31:12Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-78662"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…