OPENSUSE-SU-2026:21999-1
Vulnerability from csaf_opensuse - Published: 2026-09-28 15:31 - Updated: 2026-10-01 16:39Summary
Security update for rclone
Severity
Important
Notes
Title of the patch: Security update for rclone
Description of the patch: This update for rclone fixes the following issues:
Changes in rclone:
- Update to version 1.75.1: (boo#1279548)
- Security
- archive
- Fix zip slip path traversal in untrusted zip files
GHSA-66hp-wgxq-6f5q CVE-PENDING (Nick Craig-Wood)
- Hide any archive entry which escapes the directory being
listed GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Reject unsafe entry names when mounting squashfs images
GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Fix zip subdirectory root matching sibling directories
GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Fix zip entry named "." hiding every other file
GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Fix "directory not found" for archive paths containing "./"
or "//" GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- build
- Fix multiple CVEs by upgrading to go1.26.6 (Nick
Craig-Wood)
- CVE-2026-56860: net/url: quadratic complexity in
resolvePath
- CVE-2026-56858: html/template: JavaScript regexp context
tracking
- CVE-2026-56862: crypto/tls: limit handshake messages
accepted post-handshake
- CVE-2026-56853: net/http: apply ReadHeaderTimeout to
unencrypted HTTP/2 check
- CVE-2026-56859: encoding/xml: recursion depth guard
during decode
- CVE-2026-33818: encoding/asn1: enforce maximum recursion
depth
- CVE-2026-46600: net: panic parsing an invalid SVCB or
HTTPS RR in dnsmessage
- CVE-2026-39821: net/http: reject ASCII-only
Punycode-encoded labels in idna
- Update golang.org/x/crypto to v0.56.0 to fix multiple CVEs
(Nick Craig-Wood)
- CVE-2026-56854: ssh: source-address critical option not
enforced for non-public-key auth callbacks
- CVE-2026-78662: ssh: a malicious peer could flood an
undecided channel's incoming requests, deadlocking the
connection
- CVE-2026-56855: ssh: a malicious peer could send crafted
messages on an established channel, deadlocking the
connection
- Update golang.org/x/image to v0.45.0 to fix CVE-2026-46603
(Nick Craig-Wood)
- CVE-2026-46603: excessive memory allocation during VP8L
decoding
- fs: Confine directory listing entries that escape the root
GHSA-3vxh-3pcx-9m8q GHSA-38xv-hf3p-h7mq CVE-PENDING (Nick
Craig-Wood)
- fshttp: Don't send --header values to other hosts on
redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood)
- http: Don't leak configured headers to other hosts or over
plaintext on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick
Craig-Wood)
- lib/rest: Check HTTPS downgrades against the original
request on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick
Craig-Wood)
- local
- Fix dir metadata escaping the root through a planted
symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)
- Fix btime escaping the root via a planted symlink
GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)
- Fix panic on Range request past the end of a symlink
GHSA-p6m2-r3w9-mpxw CVE-PENDING (Nick Craig-Wood)
- serve docker
- Reject volume names that escape the base directory
GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)
- Reject volume names resolving to the base directory
itself GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)
- Re-derive volume mountpoint from name when restoring
state GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)
- serve ftp: Fix auth-proxy sessions sharing credentials by
username GHSA-c476-6w5q-jw77 CVE-PENDING (Nick Craig-Wood)
- serve s3
- Fix memory exhaustion from client-declared multipart part
size GHSA-2p48-j3qc-rx9f CVE-PENDING (Nick Craig-Wood)
- Reject bogus multipart part sizes in the reorder buffer
GHSA-2p48-j3qc-rx9f (Nick Craig-Wood)
- Fix auth proxy accepting any request signed with an empty
secret GHSA-xwwr-4h3p-r22c CVE-PENDING (Nick Craig-Wood)
- NB the auth proxy protocol for serve s3 has changed - the
proxy program is now given the access key ID as user and
must return the secret as _secret_access_key
- Fix each server accepting the --auth-key credentials of
all the others (Nick Craig-Wood)
- Fix misleading anonymous access log when using an auth
proxy via rc GHSA-p569-5gjg-9cmj CVE-PENDING (Nick
Craig-Wood)
- serve sftp: Fix auth proxy configured via rc being silently
ignored GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood)
- Bug Fixes
- accounting
- Fix memory leak on long-running rcd (nielash)
- Fix memory leak from stats groups on long-running rcd
(nielash)
- Fix bwlimit burst overflow (Rayan Salhab)
- bisync
- Fix memory leak when running via the rc (nielash)
- Fix failed transfers of empty files being recorded as
synced (Nick Craig-Wood)
- build: Make go1.26 the minimum required version as needed by
golang.org/x/crypto v0.56.0 (Nick Craig-Wood)
- config: Redact env var config values in logs (Pastalikek65)
- doc fixes (Anton Karpov, CAOShurong, Dean Chen, Nick
Craig-Wood, Recoordinate, Rodrigo Rodrigues, Shantanav
Mukherjee, shaurya)
- lib/batcher: Prevent commits racing shutdown (Loi Nguyen)
- lib/transform: Fix panic in truncate_keep_extension (VXNCXNX)
- multipart: Fix chunked uploads storing truncated objects when
the source ends early (Nick Craig-Wood)
- operations: Fix silent truncation of streaming uploads whose
source ends early (Nick Craig-Wood)
- serve
- Fix VFS instance leaks on server startup failures and
shutdown (Hakan İSMAİL)
- Pass the client IP address to the auth proxy
(am-at-enrollvb)
- serve http: Prevent scrolling to the top on page reload (Sune
Mølgaard)
- serve nfs: Fix EIO when creating symlinks with --vfs-links
(SillyZir)
- serve s3
- Fix failed uploads deleting or corrupting the object at the
key (Nick Craig-Wood)
- Fix crash when a multipart upload is aborted while a part
is uploading (Nick Craig-Wood)
- Fix modtime not being set when only mtime metadata is
supplied on PUT (Nick Craig-Wood)
- Upload all multipart uploads via the VFS so they obey
--bwlimit and show in stats (Nick Craig-Wood)
- Reserve the .rclone_temp_ prefix for temporary objects
(Nick Craig-Wood)
- Clean up abandoned multipart uploads after
--multipart-expiry (Nick Craig-Wood)
- vfscache
- Fix reader deadlock when the item size drops below the read
offset (Dave)
- Fix log message growing without bound on repeated write
errors (Vijay Misal)
- walk: Stop directory traversal when the context is cancelled
(Rahman Yilmaz)
- VFS
- Synchronize poll updates with shutdown (Loi Nguyen)
- Make poll shutdown lifecycle deterministic (Loi Nguyen)
- Crypt
- Fix hash mismatches with no_data_encryption on backends which
check upload hashes (Nick Craig-Wood)
- Fix directory names which look like versioned file names
(TowyTowy)
- Warn about directories with legacy version-like encrypted
names (Nick Craig-Wood)
- Azure Blob
- Fix Entra ID server-side copy source authentication (Edward
Klesel)
- Fix spurious vfs cache corruption errors during chunked reads
(Nick Craig-Wood)
- Azurefiles
- Fix zero padded files being created when the source ends
early (Nick Craig-Wood)
- Box
- Fix truncated files being uploaded successfully when the
source ends early (Rohit Behera)
- Compress
- Fix corrupted objects being created when the source ends
early (Nick Craig-Wood)
- Drive
- Don't list trashed files when removing a directory into the
trash (alliasgher)
- Dropbox
- Preserve Paper export paths on lookup (Loi Nguyen)
- Fix context cancellation (e.g. --max-duration limit) not
stopping in-flight requests (debaditya)
- Fix chunked uploads of truncated files never finishing (Nick
Craig-Wood)
- Don't retry chunked upload requests when the upload has been
cancelled (Nick Craig-Wood)
- Decode received shared-file names (Sanjay Kanth A)
- Fix ChangeNotify when the root's case differs from Dropbox's
(Loi Nguyen)
- Filelu
- Fix truncated files being uploaded successfully when the
source ends early (Nick Craig-Wood)
- Fix duplicate root path during multipart folder creation
(kingston125)
- Huaweidrive
- Fix truncated files being uploaded successfully when the
source ends early (Rohit Behera)
- Iclouddrive
- Fix uploads into an app container failing with 412 (Christian
De Santis)
- Internetarchive
- Fix corrupted files being created when the source ends early
(Nick Craig-Wood)
- Internxt
- Persist rotated token returned by the user info call
(0rangeSeaW0lf)
- Onedrive
- Fix 403 Forbidden for configuration personal onedrive
(machsix)
- Fall back to manual drive ID entry when drive listing fails
(SillyZir)
- Don't retry multipart upload chunk on 404 (upload session not
found) (water)
- Overview
- Fix "internal error: no overview data found" on 32 bit
architectures (Nick Craig-Wood)
- Pikpak
- Fix truncated files being created when the source ends early
(Nick Craig-Wood)
- Fix truncated single part uploads reported as ok when source
ends early (Nick Craig-Wood)
- Protondrive
- Fix files uploaded with v1.75.0 not being readable in the
Proton apps (Nick Craig-Wood)
- Fix corrupted uploads after a retried upload error (Nick
Craig-Wood)
- Quatrix
- Fix chunk upload retries and fix memory leak (Nick
Craig-Wood)
- S3
- Update Mega endpoints (Nick Craig-Wood)
- Treat UploadPart success without ETag as retryable error
(CAOShurong)
- Fix server side copy failing with --s3-no-head-object
(Anatoly Tarnavsky)
- Sia
- Fix corrupted files being created when the source ends early
(Nick Craig-Wood)
- Smb
- Reuse the upload connection for SetModTime (alliasgher)
- WebDAV
- Fix SetModTime failing and hashes missing on Nextcloud (Nick
Craig-Wood)
- Yandex
- Fix truncated files being uploaded successfully when the
source ends early (Rohit Behera)
- Update to version 1.75.0:
- New S3 Providers
- Scality (RING / ARTESCA)
- Zero Services (ZERO-Z3)
- Security
- archive: Don't crash on malformed squashfs images
GHSA-6jcg-q3wp-x2f4 CVE-PENDING (Nick Craig-Wood)
- ftp: Fix ftp command injection when encoding doesn't include
CRLF GHSA-8c48-q9wj-3w37 CVE-PENDING (Nick Craig-Wood)
- lib/http: Use TLS on all --addr listeners when --cert and
--key are set GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)
- lib/proxy: Fix unbounded HTTP CONNECT headers causing OOM
GHSA-xhf4-832v-7xcr CVE-PENDING (Nick Craig-Wood)
- local: Stop source file names escaping the destination
directory GHSA-7p4m-qxvv-g567 CVE-PENDING (Nick Craig-Wood)
- rc
- Don't expose pprof debug handlers on an unauthenticated
server GHSA-mfvx-7rcj-9m5g CVE-PENDING (Nick Craig-Wood)
- Require authentication to list the remotes with --rc-serve
GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)
- Fix leaking stack traces on panics GHSA-gwfq-86j8-7qhv
(Nick Craig-Wood)
- s3
- Fix redirect credential leaks, reject HTTPS->HTTP and strip
secrets GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)
- Strip S3 Express session token on cross-host redirects
GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)
- serve ftp: Use constant time comparison for password check
GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)
- serve restic: Fix path traversal above the served directory
GHSA-45pq-889g-fcgh CVE-PENDING (Nick Craig-Wood)
- serve sftp: Don't crash the whole server on a bad request
GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)
- sftp: Fix command injection via crafted filenames on
PowerShell remotes GHSA-2m8m-jhrm-w6j2 CVE-PENDING (Nick
Craig-Wood)
- vfs: Don't crash the process if a backend panics on a
background goroutine GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)
- webdav
- Fix HTTPS to HTTP redirects leaking credentials
GHSA-h4mf-4v27-hggj (Nick Craig-Wood)
- Tus: fix potential nil pointer crash GHSA-3x6r-wxxg-53vv
(Nick Craig-Wood)
- Update google.golang.org/grpc to fix multiple security
problems (Nick Craig-Wood)
- New Features
- build: Update all dependencies (Nick Craig-Wood)
- config
- Add config unset command to remove options from a remote
(Nick Craig-Wood)
- Add tier to config wizard (dougal)
- docker serve
- Add timeout to volume restore so slow remotes don't block
startup (Nick Craig-Wood)
- Restore volumes concurrently so one slow remote doesn't
block others (Nick Craig-Wood)
- Make Create idempotent to avoid "volume already exists"
after restart (Nick Craig-Wood)
- doc fixes (blackflytech, dougal, Giridhar, KTibow,
mathieulongtin, Nick Craig-Wood, p1, Socialpranker, Søren
Lindberg, yashanil98)
- filter
- Support nested {} alternates in glob filters (maximilize)
- Add --files-from0 to support NUL-delimited input (Gaurav)
- fserrors: Make http2 "server sent GOAWAY" a retriable error
(phatlc)
- fshttp
- Add --dump errors to dump only failed HTTP transactions
(Nick Craig-Wood)
- Add --dump trace to log connection level events via
httptrace (Nick Craig-Wood)
- gui
- Serve static files with gzip/deflate compression (Leon
Brocard)
- Respect explicit --rc-allow-origin instead of always
deriving it from the bind address (Kyue)
- Update embedded release to 1.1.11 (Nick Craig-Wood)
- mount2: Add --allow-idmap to advertise FUSE_ALLOW_IDMAP
(Valerij Fredriksen)
- nfsmount: Call mount_nfs directly on OpenBSD so -T is
accepted (Socialpranker)
- rc
- Respond with 202 if prefer-async header is passed (FTCHD)
- Add config/oauthstop and config/oauthstatus to control
oauth listener (FTCHD)
- Include OAuth authorization URL in rc config/oauthstatus
response (Hakan İSMAİL)
- Allow setting rc config and filter options as flat
parameters (Hakan İSMAİL)
- serve
- Support custom http response headers (kkocdko)
- Update serve remote control to accept nested as well as
flat options (Hakan İSMAİL)
- serve dlna: Bound SOAP request bodies (Acts1631)
- serve nfs
- Allow NFS clients to mount subpaths of the served remote
(Nick Craig-Wood)
- Advertise AUTH_UNIX so the *BSD NFS clients can mount
(Socialpranker)
- serve s3: Stream multipart uploads to the backend instead of
buffering in memory (Nick Craig-Wood)
- serve sftp
- Implement statvfs@openssh.com to report disk usage (Nick
Craig-Wood)
- Use the requested atime when setting file times (Nick
Craig-Wood)
- serve webdav: Add gzip compression for compressible responses
(Leon Brocard)
- serve http: Add --disable-dir-list flag (Leon Brocard)
- Bug Fixes
- archive/squashfs: Fix reading images with no fragment or
xattr table (maximilize)
- chunkedreader: Fix spurious errors when a parallel stream is
closed early (Nick Craig-Wood)
- config
- Fix config_template_file and config_template being ignored
via config/create (hexbinoct)
- Fix normalization when obscuring passwords (Nick
Craig-Wood)
- docker serve: Fix plugin timeout on restart when volumes have
active mounts (Nick Craig-Wood)
- fs: Fix passwords and tokens appearing in the debug log
during rclone config (Nick Craig-Wood)
- gui: Fix cross-origin API requests when bound to a wildcard
address (FTCHD)
- hash: Fix xxh128 hasher size (Yuhang Cao)
- log: Fix side effects when importing rclone as a library
(Sven Rebhan)
- march
- Fix unnecessarily listing dst directory when src listing
finished (Nick Craig-Wood)
- Fix goroutine leak on completed async rc jobs (Yash Anil)
- nfsmount: Fix mount_nfs options incompatible with OpenBSD
(Socialpranker)
- rc
- Fix operations/stat for directories with large parent dirs
(Nick Craig-Wood)
- Fix _filter and _config parameters being ignored by mount/*
commands (Hakan İSMAİL)
- serve: Fix auth proxy using stale config parameters when
making a backend (Nick Craig-Wood)
- serve s3
- Fix aborted multipart uploads appearing as ghosts (Nick
Craig-Wood)
- Fix streamed multipart uploads not being atomic (Nick
Craig-Wood)
- Fix OOM and InvalidPart errors with concurrent multipart
uploads (Nick Craig-Wood)
- sync: Fix --fix-case rename on backends that need upload
before overwrite (Nick Craig-Wood)
- Mount
- Support flat VFS and Mount options in mount RC command
(Hakan İSMAİL)
- VFS
- Fix IO error by recreating the cache file if it has been
removed (Nick Craig-Wood)
- Fix "invalid seek position" error when cache files larger
than the remote (Nick Craig-Wood)
- Fix vfs cache writeback timer not being stopped when
--transfers reached (Nick Craig-Wood)
- Fix crash when multiple mounts or servers share the same
VFS (Nick Craig-Wood)
- Local
- Add --local-fatal-if-no-space flag (ferrumclaudepilgrim)
- Don't resolve relative roots to absolute paths (Nick
Craig-Wood)
- Archive
- Fix squashfs listings failing with invalid argument after
update (Nick Craig-Wood)
- Azure Blob
- Fix MD5 being dropped on range reads causing vfs cache
re-downloads (Nick Craig-Wood)
- Add use_arrow_list flag for experimental Apache Arrow
listing (Nick Craig-Wood)
- List very large containers in parallel with
list_parallelism (Nick Craig-Wood)
- Azurefiles
- Fix incorrect modtime after uploading a file or setting its
modtime (Nick Craig-Wood)
- Improve modtime precision from 1s to 100ns (Nick
Craig-Wood)
- Combine
- Don't return an error message as the remote name for a bad
object (Nick Craig-Wood)
- Drime
- Remove stale mux_status field from Item (Nick Craig-Wood)
- Drive
- Warn in config wizard before using the shared client_id
(Nick Craig-Wood)
- Detect shortcut loops to avoid infinite recursion (Nick
Craig-Wood)
- Dropbox
- Add support for impersonate_admin (Gaurav)
- Add --dropbox-skip-shared-folders and
--dropbox-skip-unowned-folders (Gaurav)
- Make Rmdir use one less API call (Socialpranker)
- Use much less memory when uploading small files (Nick
Craig-Wood)
- Remove an unnecessary API call when uploading small files
(Nick Craig-Wood)
- Filen
- Fix incorrect modtime after updating a file or setting its
modtime (Nick Craig-Wood)
- Filescom
- Fix missing MD5 hash after uploading a file (Nick
Craig-Wood)
- FTP
- Fix incorrect modtime after uploading a file or setting its
modtime (Nick Craig-Wood)
- Googlephotos
- Warn in config wizard before using the shared client_id
(Nick Craig-Wood)
- Hasher
- Fix Update not storing hashes in bolt DB after file
replacement (Nick Craig-Wood)
- Hdfs
- Fix incorrect modtime after uploading a file or setting its
modtime (Nick Craig-Wood)
- Hidrive
- Fix incorrect modtime after setting a file's modtime (Nick
Craig-Wood)
- HTTP
- Don't list parent directory when pointing at a single file
(Nick Craig-Wood)
- Add Prefer to CORS Access-Control-Allow-Headers header
(sijie-Z)
- Iclouddrive
- Fix "cannot unmarshal number" error when listing photo
albums (Nick Craig-Wood)
- Fix 2FA failing with 409 even when the code is valid (Punya
Jain)
- Imagekit
- Fix Open with a RangeOption returning the wrong data (Nick
Craig-Wood)
- Add mtime to the available metadata (Nick Craig-Wood)
- Internxt
- Add Move and DirMove methods for server-side file and
directory operations (jzunigax2)
- Handle file size limit errors during uploads (jzunigax2)
- Surface re-login error when re-auth fails in NewFs
(0rangeSeaW0lf)
- Jottacloud
- Fix incorrect modtime after setting a file's modtime (Nick
Craig-Wood)
- Linkbox
- Retry bot protection HTML challenge responses instead of
failing (Nick Craig-Wood)
- Mailru
- Fix incorrect modtime after updating a file or setting its
modtime (Nick Craig-Wood)
- Mega
- Fix files reappearing in listings after being renamed (Nick
Craig-Wood)
- Fix moved files disappearing from listings between remotes
(Nick Craig-Wood)
- Netstorage
- Fix missing MD5 hash after uploading a file (Nick
Craig-Wood)
- Onedrive
- Add support for no admin mode (TaterLi)
- Treat non-2xx preauth download as error (ifloppy)
- Download malware-flagged files via Graph Prefer header
(ifloppy)
- Opendrive
- Fix uploaded objects returning the wrong hash and modtime
(Nick Craig-Wood)
- Oracleobjectstorage
- Fix crash when downloading objects with unknown length
(Nick Craig-Wood)
- Add --oos-decompress flag to download gzip-encoded files
(Nick Craig-Wood)
- Pixeldrain
- Fix incorrect modtime and missing hash after uploading a
file (Nick Craig-Wood)
- Protondrive
- Implement proper retry logic (tomholford)
- Fix gopenpgp: invalid data: user ID signature with wrong
type on custom-domain account (Nick Craig-Wood)
- Fix long hangs on permanent validation failures (Nick
Craig-Wood)
- Fix incorrect modtime after uploading a file (Nick
Craig-Wood)
- Putio
- Fix incorrect modtime after setting a file's modtime (Nick
Craig-Wood)
- Fix sync deletions failing with 400 TRASH_LOCK_TIMEOUT
errors (Nick Craig-Wood)
- Quatrix
- Fix incorrect modtime after uploading a file (Nick
Craig-Wood)
- S3
- Add Zero Services (ZERO-Z3) provider (Zero Services GmbH)
- Add Scality (RING / ARTESCA) provider (Dzmitry Nianakhau)
- Seafile
- Fix rclone sync files with identical size again and again
(TowyTowy)
- SFTP
- Add --sftp-pin-host-key - Trust On First Use host key
pinning (Nick Craig-Wood)
- Add --sftp-encoding support (Puneet Dixit)
- Don't retry permanent connection errors (Nick Craig-Wood)
- Allow silencing no hostkey validation warning (Noah Zalev)
- Fix cmd shell execution of paths containing
variable-expansion or newline characters (Nick Craig-Wood)
- Shade
- Retry server errors instead of failing the transfer (Nick
Craig-Wood)
- Fix uploads failing with EOF when completing multipart
uploads (Nick Craig-Wood)
- Smb
- Fix Kerberos credentials being reloaded for every
connection (Nick Craig-Wood)
- Fix TCP connection leak when connection setup fails (Nick
Craig-Wood)
- Fix server-side move of directories with special characters
in the name (Nick Craig-Wood)
- Fix spurious "Directory already exists" errors when moving
directories (Nick Craig-Wood)
- Ulozto
- Fix server side moves between differently rooted remotes
losing files (Nick Craig-Wood)
- WebDAV
- Fix incorrect modtime after setting a file's modtime (Nick
Craig-Wood)
- Yandex
- Fix 500 errors by waiting for uploads to complete before
setting modtime (Nick Craig-Wood)
- Fix missing MD5 hash after uploading a file (Nick
Craig-Wood)
- Fix modtime randomly reverting to the upload time after
upload (Nick Craig-Wood)
- Add --yandex-upload-wait to fix 500 errors when uploading
(Nick Craig-Wood)
- Zoho
- Honour Retry-After header on 429 (Erol Ozcan)
- Add --zoho-tpslimit and --zoho-tpslimit-burst (Erol Ozcan)
- Log throttling once per episode at NOTICE (Erol Ozcan)
- Rate limit repeated listings of the same folder (Erol
Ozcan)
- Fix flaky folder list limiter test under concurrent
listings (Nick Craig-Wood)
- Fix large file overwrite creating a duplicate instead of
replacing (Erol Ozcan)
- Treat R008 unauthorized as directory not found (Erol Ozcan)
- Preserve root_folder_id on reconnect and allow setting it
(Erol Ozcan)
Patchnames: openSUSE-Leap-16.0-packagehub-641
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
7.5 (High)
Affected products
Recommended
5 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch | — |
Vendor Fix
|
|
| Unresolved product id: openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch | — |
Vendor Fix
|
Threats
Impact
important
7.4 (High)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
6.5 (Medium)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
moderate
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
7.5 (High)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
8.1 (High)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
7.5 (High)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
6.1 (Medium)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
5.3 (Medium)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
7.5 (High)
Affected products
Recommended
5 products, the same list as for
CVE-2026-33818
Threats
Impact
important
References
42 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "important"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Security update for rclone",
"title": "Title of the patch"
},
{
"category": "description",
"text": "This update for rclone fixes the following issues:\n\nChanges in rclone:\n\n- Update to version 1.75.1: (boo#1279548)\n - Security\n - archive\n - Fix zip slip path traversal in untrusted zip files\n GHSA-66hp-wgxq-6f5q CVE-PENDING (Nick Craig-Wood)\n - Hide any archive entry which escapes the directory being\n listed GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n - Reject unsafe entry names when mounting squashfs images\n GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n - Fix zip subdirectory root matching sibling directories\n GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n - Fix zip entry named \".\" hiding every other file\n GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n - Fix \"directory not found\" for archive paths containing \"./\"\n or \"//\" GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)\n - build\n - Fix multiple CVEs by upgrading to go1.26.6 (Nick\n Craig-Wood)\n - CVE-2026-56860: net/url: quadratic complexity in\n resolvePath\n - CVE-2026-56858: html/template: JavaScript regexp context\n tracking\n - CVE-2026-56862: crypto/tls: limit handshake messages\n accepted post-handshake\n - CVE-2026-56853: net/http: apply ReadHeaderTimeout to\n unencrypted HTTP/2 check\n - CVE-2026-56859: encoding/xml: recursion depth guard\n during decode\n - CVE-2026-33818: encoding/asn1: enforce maximum recursion\n depth\n - CVE-2026-46600: net: panic parsing an invalid SVCB or\n HTTPS RR in dnsmessage\n - CVE-2026-39821: net/http: reject ASCII-only\n Punycode-encoded labels in idna\n - Update golang.org/x/crypto to v0.56.0 to fix multiple CVEs\n (Nick Craig-Wood)\n - CVE-2026-56854: ssh: source-address critical option not\n enforced for non-public-key auth callbacks\n - CVE-2026-78662: ssh: a malicious peer could flood an\n undecided channel\u0027s incoming requests, deadlocking the\n connection\n - CVE-2026-56855: ssh: a malicious peer could send crafted\n messages on an established channel, deadlocking the\n connection\n - Update golang.org/x/image to v0.45.0 to fix CVE-2026-46603\n (Nick Craig-Wood)\n - CVE-2026-46603: excessive memory allocation during VP8L\n decoding\n - fs: Confine directory listing entries that escape the root\n GHSA-3vxh-3pcx-9m8q GHSA-38xv-hf3p-h7mq CVE-PENDING (Nick\n Craig-Wood)\n - fshttp: Don\u0027t send --header values to other hosts on\n redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood)\n - http: Don\u0027t leak configured headers to other hosts or over\n plaintext on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick\n Craig-Wood)\n - lib/rest: Check HTTPS downgrades against the original\n request on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick\n Craig-Wood)\n - local\n - Fix dir metadata escaping the root through a planted\n symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)\n - Fix btime escaping the root via a planted symlink\n GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)\n - Fix panic on Range request past the end of a symlink\n GHSA-p6m2-r3w9-mpxw CVE-PENDING (Nick Craig-Wood)\n - serve docker\n - Reject volume names that escape the base directory\n GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n - Reject volume names resolving to the base directory\n itself GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n - Re-derive volume mountpoint from name when restoring\n state GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)\n - serve ftp: Fix auth-proxy sessions sharing credentials by\n username GHSA-c476-6w5q-jw77 CVE-PENDING (Nick Craig-Wood)\n - serve s3\n - Fix memory exhaustion from client-declared multipart part\n size GHSA-2p48-j3qc-rx9f CVE-PENDING (Nick Craig-Wood)\n - Reject bogus multipart part sizes in the reorder buffer\n GHSA-2p48-j3qc-rx9f (Nick Craig-Wood)\n - Fix auth proxy accepting any request signed with an empty\n secret GHSA-xwwr-4h3p-r22c CVE-PENDING (Nick Craig-Wood)\n - NB the auth proxy protocol for serve s3 has changed - the\n proxy program is now given the access key ID as user and\n must return the secret as _secret_access_key\n - Fix each server accepting the --auth-key credentials of\n all the others (Nick Craig-Wood)\n - Fix misleading anonymous access log when using an auth\n proxy via rc GHSA-p569-5gjg-9cmj CVE-PENDING (Nick\n Craig-Wood)\n - serve sftp: Fix auth proxy configured via rc being silently\n ignored GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood)\n - Bug Fixes\n - accounting\n - Fix memory leak on long-running rcd (nielash)\n - Fix memory leak from stats groups on long-running rcd\n (nielash)\n - Fix bwlimit burst overflow (Rayan Salhab)\n - bisync\n - Fix memory leak when running via the rc (nielash)\n - Fix failed transfers of empty files being recorded as\n synced (Nick Craig-Wood)\n - build: Make go1.26 the minimum required version as needed by\n golang.org/x/crypto v0.56.0 (Nick Craig-Wood)\n - config: Redact env var config values in logs (Pastalikek65)\n - doc fixes (Anton Karpov, CAOShurong, Dean Chen, Nick\n Craig-Wood, Recoordinate, Rodrigo Rodrigues, Shantanav\n Mukherjee, shaurya)\n - lib/batcher: Prevent commits racing shutdown (Loi Nguyen)\n - lib/transform: Fix panic in truncate_keep_extension (VXNCXNX)\n - multipart: Fix chunked uploads storing truncated objects when\n the source ends early (Nick Craig-Wood)\n - operations: Fix silent truncation of streaming uploads whose\n source ends early (Nick Craig-Wood)\n - serve\n - Fix VFS instance leaks on server startup failures and\n shutdown (Hakan \u0130SMA\u0130L)\n - Pass the client IP address to the auth proxy\n (am-at-enrollvb)\n - serve http: Prevent scrolling to the top on page reload (Sune\n M\u00f8lgaard)\n - serve nfs: Fix EIO when creating symlinks with --vfs-links\n (SillyZir)\n - serve s3\n - Fix failed uploads deleting or corrupting the object at the\n key (Nick Craig-Wood)\n - Fix crash when a multipart upload is aborted while a part\n is uploading (Nick Craig-Wood)\n - Fix modtime not being set when only mtime metadata is\n supplied on PUT (Nick Craig-Wood)\n - Upload all multipart uploads via the VFS so they obey\n --bwlimit and show in stats (Nick Craig-Wood)\n - Reserve the .rclone_temp_ prefix for temporary objects\n (Nick Craig-Wood)\n - Clean up abandoned multipart uploads after\n --multipart-expiry (Nick Craig-Wood)\n - vfscache\n - Fix reader deadlock when the item size drops below the read\n offset (Dave)\n - Fix log message growing without bound on repeated write\n errors (Vijay Misal)\n - walk: Stop directory traversal when the context is cancelled\n (Rahman Yilmaz)\n - VFS\n - Synchronize poll updates with shutdown (Loi Nguyen)\n - Make poll shutdown lifecycle deterministic (Loi Nguyen)\n - Crypt\n - Fix hash mismatches with no_data_encryption on backends which\n check upload hashes (Nick Craig-Wood)\n - Fix directory names which look like versioned file names\n (TowyTowy)\n - Warn about directories with legacy version-like encrypted\n names (Nick Craig-Wood)\n - Azure Blob\n - Fix Entra ID server-side copy source authentication (Edward\n Klesel)\n - Fix spurious vfs cache corruption errors during chunked reads\n (Nick Craig-Wood)\n - Azurefiles\n - Fix zero padded files being created when the source ends\n early (Nick Craig-Wood)\n - Box\n - Fix truncated files being uploaded successfully when the\n source ends early (Rohit Behera)\n - Compress\n - Fix corrupted objects being created when the source ends\n early (Nick Craig-Wood)\n - Drive\n - Don\u0027t list trashed files when removing a directory into the\n trash (alliasgher)\n - Dropbox\n - Preserve Paper export paths on lookup (Loi Nguyen)\n - Fix context cancellation (e.g. --max-duration limit) not\n stopping in-flight requests (debaditya)\n - Fix chunked uploads of truncated files never finishing (Nick\n Craig-Wood)\n - Don\u0027t retry chunked upload requests when the upload has been\n cancelled (Nick Craig-Wood)\n - Decode received shared-file names (Sanjay Kanth A)\n - Fix ChangeNotify when the root\u0027s case differs from Dropbox\u0027s\n (Loi Nguyen)\n - Filelu\n - Fix truncated files being uploaded successfully when the\n source ends early (Nick Craig-Wood)\n - Fix duplicate root path during multipart folder creation\n (kingston125)\n - Huaweidrive\n - Fix truncated files being uploaded successfully when the\n source ends early (Rohit Behera)\n - Iclouddrive\n - Fix uploads into an app container failing with 412 (Christian\n De Santis)\n - Internetarchive\n - Fix corrupted files being created when the source ends early\n (Nick Craig-Wood)\n - Internxt\n - Persist rotated token returned by the user info call\n (0rangeSeaW0lf)\n - Onedrive\n - Fix 403 Forbidden for configuration personal onedrive\n (machsix)\n - Fall back to manual drive ID entry when drive listing fails\n (SillyZir)\n - Don\u0027t retry multipart upload chunk on 404 (upload session not\n found) (water)\n - Overview\n - Fix \"internal error: no overview data found\" on 32 bit\n architectures (Nick Craig-Wood)\n - Pikpak\n - Fix truncated files being created when the source ends early\n (Nick Craig-Wood)\n - Fix truncated single part uploads reported as ok when source\n ends early (Nick Craig-Wood)\n - Protondrive\n - Fix files uploaded with v1.75.0 not being readable in the\n Proton apps (Nick Craig-Wood)\n - Fix corrupted uploads after a retried upload error (Nick\n Craig-Wood)\n - Quatrix\n - Fix chunk upload retries and fix memory leak (Nick\n Craig-Wood)\n - S3\n - Update Mega endpoints (Nick Craig-Wood)\n - Treat UploadPart success without ETag as retryable error\n (CAOShurong)\n - Fix server side copy failing with --s3-no-head-object\n (Anatoly Tarnavsky)\n - Sia\n - Fix corrupted files being created when the source ends early\n (Nick Craig-Wood)\n - Smb\n - Reuse the upload connection for SetModTime (alliasgher)\n - WebDAV\n - Fix SetModTime failing and hashes missing on Nextcloud (Nick\n Craig-Wood)\n - Yandex\n - Fix truncated files being uploaded successfully when the\n source ends early (Rohit Behera)\n\n- Update to version 1.75.0:\n - New S3 Providers\n - Scality (RING / ARTESCA)\n - Zero Services (ZERO-Z3)\n - Security\n - archive: Don\u0027t crash on malformed squashfs images\n GHSA-6jcg-q3wp-x2f4 CVE-PENDING (Nick Craig-Wood)\n - ftp: Fix ftp command injection when encoding doesn\u0027t include\n CRLF GHSA-8c48-q9wj-3w37 CVE-PENDING (Nick Craig-Wood)\n - lib/http: Use TLS on all --addr listeners when --cert and\n --key are set GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n - lib/proxy: Fix unbounded HTTP CONNECT headers causing OOM\n GHSA-xhf4-832v-7xcr CVE-PENDING (Nick Craig-Wood)\n - local: Stop source file names escaping the destination\n directory GHSA-7p4m-qxvv-g567 CVE-PENDING (Nick Craig-Wood)\n - rc\n - Don\u0027t expose pprof debug handlers on an unauthenticated\n server GHSA-mfvx-7rcj-9m5g CVE-PENDING (Nick Craig-Wood)\n - Require authentication to list the remotes with --rc-serve\n GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n - Fix leaking stack traces on panics GHSA-gwfq-86j8-7qhv\n (Nick Craig-Wood)\n - s3\n - Fix redirect credential leaks, reject HTTPS-\u003eHTTP and strip\n secrets GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)\n - Strip S3 Express session token on cross-host redirects\n GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)\n - serve ftp: Use constant time comparison for password check\n GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)\n - serve restic: Fix path traversal above the served directory\n GHSA-45pq-889g-fcgh CVE-PENDING (Nick Craig-Wood)\n - serve sftp: Don\u0027t crash the whole server on a bad request\n GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)\n - sftp: Fix command injection via crafted filenames on\n PowerShell remotes GHSA-2m8m-jhrm-w6j2 CVE-PENDING (Nick\n Craig-Wood)\n - vfs: Don\u0027t crash the process if a backend panics on a\n background goroutine GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)\n - webdav\n - Fix HTTPS to HTTP redirects leaking credentials\n GHSA-h4mf-4v27-hggj (Nick Craig-Wood)\n - Tus: fix potential nil pointer crash GHSA-3x6r-wxxg-53vv\n (Nick Craig-Wood)\n - Update google.golang.org/grpc to fix multiple security\n problems (Nick Craig-Wood)\n - New Features\n - build: Update all dependencies (Nick Craig-Wood)\n - config\n - Add config unset command to remove options from a remote\n (Nick Craig-Wood)\n - Add tier to config wizard (dougal)\n - docker serve\n - Add timeout to volume restore so slow remotes don\u0027t block\n startup (Nick Craig-Wood)\n - Restore volumes concurrently so one slow remote doesn\u0027t\n block others (Nick Craig-Wood)\n - Make Create idempotent to avoid \"volume already exists\"\n after restart (Nick Craig-Wood)\n - doc fixes (blackflytech, dougal, Giridhar, KTibow,\n mathieulongtin, Nick Craig-Wood, p1, Socialpranker, S\u00f8ren\n Lindberg, yashanil98)\n - filter\n - Support nested {} alternates in glob filters (maximilize)\n - Add --files-from0 to support NUL-delimited input (Gaurav)\n - fserrors: Make http2 \"server sent GOAWAY\" a retriable error\n (phatlc)\n - fshttp\n - Add --dump errors to dump only failed HTTP transactions\n (Nick Craig-Wood)\n - Add --dump trace to log connection level events via\n httptrace (Nick Craig-Wood)\n - gui\n - Serve static files with gzip/deflate compression (Leon\n Brocard)\n - Respect explicit --rc-allow-origin instead of always\n deriving it from the bind address (Kyue)\n - Update embedded release to 1.1.11 (Nick Craig-Wood)\n - mount2: Add --allow-idmap to advertise FUSE_ALLOW_IDMAP\n (Valerij Fredriksen)\n - nfsmount: Call mount_nfs directly on OpenBSD so -T is\n accepted (Socialpranker)\n - rc\n - Respond with 202 if prefer-async header is passed (FTCHD)\n - Add config/oauthstop and config/oauthstatus to control\n oauth listener (FTCHD)\n - Include OAuth authorization URL in rc config/oauthstatus\n response (Hakan \u0130SMA\u0130L)\n - Allow setting rc config and filter options as flat\n parameters (Hakan \u0130SMA\u0130L)\n - serve\n - Support custom http response headers (kkocdko)\n - Update serve remote control to accept nested as well as\n flat options (Hakan \u0130SMA\u0130L)\n - serve dlna: Bound SOAP request bodies (Acts1631)\n - serve nfs\n - Allow NFS clients to mount subpaths of the served remote\n (Nick Craig-Wood)\n - Advertise AUTH_UNIX so the *BSD NFS clients can mount\n (Socialpranker)\n - serve s3: Stream multipart uploads to the backend instead of\n buffering in memory (Nick Craig-Wood)\n - serve sftp\n - Implement statvfs@openssh.com to report disk usage (Nick\n Craig-Wood)\n - Use the requested atime when setting file times (Nick\n Craig-Wood)\n - serve webdav: Add gzip compression for compressible responses\n (Leon Brocard)\n - serve http: Add --disable-dir-list flag (Leon Brocard)\n - Bug Fixes\n - archive/squashfs: Fix reading images with no fragment or\n xattr table (maximilize)\n - chunkedreader: Fix spurious errors when a parallel stream is\n closed early (Nick Craig-Wood)\n - config\n - Fix config_template_file and config_template being ignored\n via config/create (hexbinoct)\n - Fix normalization when obscuring passwords (Nick\n Craig-Wood)\n - docker serve: Fix plugin timeout on restart when volumes have\n active mounts (Nick Craig-Wood)\n - fs: Fix passwords and tokens appearing in the debug log\n during rclone config (Nick Craig-Wood)\n - gui: Fix cross-origin API requests when bound to a wildcard\n address (FTCHD)\n - hash: Fix xxh128 hasher size (Yuhang Cao)\n - log: Fix side effects when importing rclone as a library\n (Sven Rebhan)\n - march\n - Fix unnecessarily listing dst directory when src listing\n finished (Nick Craig-Wood)\n - Fix goroutine leak on completed async rc jobs (Yash Anil)\n - nfsmount: Fix mount_nfs options incompatible with OpenBSD\n (Socialpranker)\n - rc\n - Fix operations/stat for directories with large parent dirs\n (Nick Craig-Wood)\n - Fix _filter and _config parameters being ignored by mount/*\n commands (Hakan \u0130SMA\u0130L)\n - serve: Fix auth proxy using stale config parameters when\n making a backend (Nick Craig-Wood)\n - serve s3\n - Fix aborted multipart uploads appearing as ghosts (Nick\n Craig-Wood)\n - Fix streamed multipart uploads not being atomic (Nick\n Craig-Wood)\n - Fix OOM and InvalidPart errors with concurrent multipart\n uploads (Nick Craig-Wood)\n - sync: Fix --fix-case rename on backends that need upload\n before overwrite (Nick Craig-Wood)\n - Mount\n - Support flat VFS and Mount options in mount RC command\n (Hakan \u0130SMA\u0130L)\n - VFS\n - Fix IO error by recreating the cache file if it has been\n removed (Nick Craig-Wood)\n - Fix \"invalid seek position\" error when cache files larger\n than the remote (Nick Craig-Wood)\n - Fix vfs cache writeback timer not being stopped when\n --transfers reached (Nick Craig-Wood)\n - Fix crash when multiple mounts or servers share the same\n VFS (Nick Craig-Wood)\n - Local\n - Add --local-fatal-if-no-space flag (ferrumclaudepilgrim)\n - Don\u0027t resolve relative roots to absolute paths (Nick\n Craig-Wood)\n - Archive\n - Fix squashfs listings failing with invalid argument after\n update (Nick Craig-Wood)\n - Azure Blob\n - Fix MD5 being dropped on range reads causing vfs cache\n re-downloads (Nick Craig-Wood)\n - Add use_arrow_list flag for experimental Apache Arrow\n listing (Nick Craig-Wood)\n - List very large containers in parallel with\n list_parallelism (Nick Craig-Wood)\n - Azurefiles\n - Fix incorrect modtime after uploading a file or setting its\n modtime (Nick Craig-Wood)\n - Improve modtime precision from 1s to 100ns (Nick\n Craig-Wood)\n - Combine\n - Don\u0027t return an error message as the remote name for a bad\n object (Nick Craig-Wood)\n - Drime\n - Remove stale mux_status field from Item (Nick Craig-Wood)\n - Drive\n - Warn in config wizard before using the shared client_id\n (Nick Craig-Wood)\n - Detect shortcut loops to avoid infinite recursion (Nick\n Craig-Wood)\n - Dropbox\n - Add support for impersonate_admin (Gaurav)\n - Add --dropbox-skip-shared-folders and\n --dropbox-skip-unowned-folders (Gaurav)\n - Make Rmdir use one less API call (Socialpranker)\n - Use much less memory when uploading small files (Nick\n Craig-Wood)\n - Remove an unnecessary API call when uploading small files\n (Nick Craig-Wood)\n - Filen\n - Fix incorrect modtime after updating a file or setting its\n modtime (Nick Craig-Wood)\n - Filescom\n - Fix missing MD5 hash after uploading a file (Nick\n Craig-Wood)\n - FTP\n - Fix incorrect modtime after uploading a file or setting its\n modtime (Nick Craig-Wood)\n - Googlephotos\n - Warn in config wizard before using the shared client_id\n (Nick Craig-Wood)\n - Hasher\n - Fix Update not storing hashes in bolt DB after file\n replacement (Nick Craig-Wood)\n - Hdfs\n - Fix incorrect modtime after uploading a file or setting its\n modtime (Nick Craig-Wood)\n - Hidrive\n - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n Craig-Wood)\n - HTTP\n - Don\u0027t list parent directory when pointing at a single file\n (Nick Craig-Wood)\n - Add Prefer to CORS Access-Control-Allow-Headers header\n (sijie-Z)\n - Iclouddrive\n - Fix \"cannot unmarshal number\" error when listing photo\n albums (Nick Craig-Wood)\n - Fix 2FA failing with 409 even when the code is valid (Punya\n Jain)\n - Imagekit\n - Fix Open with a RangeOption returning the wrong data (Nick\n Craig-Wood)\n - Add mtime to the available metadata (Nick Craig-Wood)\n - Internxt\n - Add Move and DirMove methods for server-side file and\n directory operations (jzunigax2)\n - Handle file size limit errors during uploads (jzunigax2)\n - Surface re-login error when re-auth fails in NewFs\n (0rangeSeaW0lf)\n - Jottacloud\n - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n Craig-Wood)\n - Linkbox\n - Retry bot protection HTML challenge responses instead of\n failing (Nick Craig-Wood)\n - Mailru\n - Fix incorrect modtime after updating a file or setting its\n modtime (Nick Craig-Wood)\n - Mega\n - Fix files reappearing in listings after being renamed (Nick\n Craig-Wood)\n - Fix moved files disappearing from listings between remotes\n (Nick Craig-Wood)\n - Netstorage\n - Fix missing MD5 hash after uploading a file (Nick\n Craig-Wood)\n - Onedrive\n - Add support for no admin mode (TaterLi)\n - Treat non-2xx preauth download as error (ifloppy)\n - Download malware-flagged files via Graph Prefer header\n (ifloppy)\n - Opendrive\n - Fix uploaded objects returning the wrong hash and modtime\n (Nick Craig-Wood)\n - Oracleobjectstorage\n - Fix crash when downloading objects with unknown length\n (Nick Craig-Wood)\n - Add --oos-decompress flag to download gzip-encoded files\n (Nick Craig-Wood)\n - Pixeldrain\n - Fix incorrect modtime and missing hash after uploading a\n file (Nick Craig-Wood)\n - Protondrive\n - Implement proper retry logic (tomholford)\n - Fix gopenpgp: invalid data: user ID signature with wrong\n type on custom-domain account (Nick Craig-Wood)\n - Fix long hangs on permanent validation failures (Nick\n Craig-Wood)\n - Fix incorrect modtime after uploading a file (Nick\n Craig-Wood)\n - Putio\n - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n Craig-Wood)\n - Fix sync deletions failing with 400 TRASH_LOCK_TIMEOUT\n errors (Nick Craig-Wood)\n - Quatrix\n - Fix incorrect modtime after uploading a file (Nick\n Craig-Wood)\n - S3\n - Add Zero Services (ZERO-Z3) provider (Zero Services GmbH)\n - Add Scality (RING / ARTESCA) provider (Dzmitry Nianakhau)\n - Seafile\n - Fix rclone sync files with identical size again and again\n (TowyTowy)\n - SFTP\n - Add --sftp-pin-host-key - Trust On First Use host key\n pinning (Nick Craig-Wood)\n - Add --sftp-encoding support (Puneet Dixit)\n - Don\u0027t retry permanent connection errors (Nick Craig-Wood)\n - Allow silencing no hostkey validation warning (Noah Zalev)\n - Fix cmd shell execution of paths containing\n variable-expansion or newline characters (Nick Craig-Wood)\n - Shade\n - Retry server errors instead of failing the transfer (Nick\n Craig-Wood)\n - Fix uploads failing with EOF when completing multipart\n uploads (Nick Craig-Wood)\n - Smb\n - Fix Kerberos credentials being reloaded for every\n connection (Nick Craig-Wood)\n - Fix TCP connection leak when connection setup fails (Nick\n Craig-Wood)\n - Fix server-side move of directories with special characters\n in the name (Nick Craig-Wood)\n - Fix spurious \"Directory already exists\" errors when moving\n directories (Nick Craig-Wood)\n - Ulozto\n - Fix server side moves between differently rooted remotes\n losing files (Nick Craig-Wood)\n - WebDAV\n - Fix incorrect modtime after setting a file\u0027s modtime (Nick\n Craig-Wood)\n - Yandex\n - Fix 500 errors by waiting for uploads to complete before\n setting modtime (Nick Craig-Wood)\n - Fix missing MD5 hash after uploading a file (Nick\n Craig-Wood)\n - Fix modtime randomly reverting to the upload time after\n upload (Nick Craig-Wood)\n - Add --yandex-upload-wait to fix 500 errors when uploading\n (Nick Craig-Wood)\n - Zoho\n - Honour Retry-After header on 429 (Erol Ozcan)\n - Add --zoho-tpslimit and --zoho-tpslimit-burst (Erol Ozcan)\n - Log throttling once per episode at NOTICE (Erol Ozcan)\n - Rate limit repeated listings of the same folder (Erol\n Ozcan)\n - Fix flaky folder list limiter test under concurrent\n listings (Nick Craig-Wood)\n - Fix large file overwrite creating a duplicate instead of\n replacing (Erol Ozcan)\n - Treat R008 unauthorized as directory not found (Erol Ozcan)\n - Preserve root_folder_id on reconnect and allow setting it\n (Erol Ozcan)\n",
"title": "Description of the patch"
},
{
"category": "details",
"text": "openSUSE-Leap-16.0-packagehub-641",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_21999-1.json"
},
{
"category": "self",
"summary": "SUSE Bug 1279548",
"url": "https://bugzilla.suse.com/1279548"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-33818 page",
"url": "https://www.suse.com/security/cve/CVE-2026-33818/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-39821 page",
"url": "https://www.suse.com/security/cve/CVE-2026-39821/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-46600 page",
"url": "https://www.suse.com/security/cve/CVE-2026-46600/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-46603 page",
"url": "https://www.suse.com/security/cve/CVE-2026-46603/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-56853 page",
"url": "https://www.suse.com/security/cve/CVE-2026-56853/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-56854 page",
"url": "https://www.suse.com/security/cve/CVE-2026-56854/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-56855 page",
"url": "https://www.suse.com/security/cve/CVE-2026-56855/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-56858 page",
"url": "https://www.suse.com/security/cve/CVE-2026-56858/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-56859 page",
"url": "https://www.suse.com/security/cve/CVE-2026-56859/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-56860 page",
"url": "https://www.suse.com/security/cve/CVE-2026-56860/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-56862 page",
"url": "https://www.suse.com/security/cve/CVE-2026-56862/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-78662 page",
"url": "https://www.suse.com/security/cve/CVE-2026-78662/"
}
],
"title": "Security update for rclone",
"tracking": {
"current_release_date": "2026-10-01T16:39:45Z",
"generator": {
"date": "2026-09-28T15:31:12Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "openSUSE-SU-2026:21999-1",
"initial_release_date": "2026-09-28T15:31:12Z",
"revision_history": [
{
"date": "2026-09-28T15:31:12Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-10-01T16:39:45Z",
"number": "2",
"summary": "unknown changes"
}
],
"status": "final",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "rclone-0:1.75.1-bp160.1.1.aarch64",
"product": {
"name": "rclone-0:1.75.1-bp160.1.1.aarch64",
"product_id": "rclone-0:1.75.1-bp160.1.1.aarch64",
"product_identification_helper": {
"cpe": "cpe:2.3:a:rclone:rclone:1.75.1:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/rclone@1.75.1-bp160.1.1?arch=aarch64"
}
}
}
],
"category": "architecture",
"name": "aarch64"
},
{
"branches": [
{
"category": "product_version",
"name": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"product": {
"name": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"product_id": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/rclone-bash-completion@1.75.1-bp160.1.1?arch=noarch"
}
}
},
{
"category": "product_version",
"name": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
"product": {
"name": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
"product_id": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/rclone-zsh-completion@1.75.1-bp160.1.1?arch=noarch"
}
}
}
],
"category": "architecture",
"name": "noarch"
},
{
"branches": [
{
"category": "product_version",
"name": "rclone-0:1.75.1-bp160.1.1.ppc64le",
"product": {
"name": "rclone-0:1.75.1-bp160.1.1.ppc64le",
"product_id": "rclone-0:1.75.1-bp160.1.1.ppc64le",
"product_identification_helper": {
"cpe": "cpe:2.3:a:rclone:rclone:1.75.1:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/rclone@1.75.1-bp160.1.1?arch=ppc64le"
}
}
}
],
"category": "architecture",
"name": "ppc64le"
},
{
"branches": [
{
"category": "product_version",
"name": "rclone-0:1.75.1-bp160.1.1.x86_64",
"product": {
"name": "rclone-0:1.75.1-bp160.1.1.x86_64",
"product_id": "rclone-0:1.75.1-bp160.1.1.x86_64",
"product_identification_helper": {
"cpe": "cpe:2.3:a:rclone:rclone:1.75.1:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/rclone@1.75.1-bp160.1.1?arch=x86_64"
}
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_name",
"name": "openSUSE Leap 16.0",
"product": {
"name": "openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0"
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "rclone-0:1.75.1-bp160.1.1.aarch64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64"
},
"product_reference": "rclone-0:1.75.1-bp160.1.1.aarch64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "rclone-0:1.75.1-bp160.1.1.ppc64le as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le"
},
"product_reference": "rclone-0:1.75.1-bp160.1.1.ppc64le",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "rclone-0:1.75.1-bp160.1.1.x86_64 as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64"
},
"product_reference": "rclone-0:1.75.1-bp160.1.1.x86_64",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch"
},
"product_reference": "rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch as component of openSUSE Leap 16.0",
"product_id": "openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
},
"product_reference": "rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch",
"relates_to_product_reference": "openSUSE Leap 16.0"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-33818",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-33818"
}
],
"notes": [
{
"category": "general",
"text": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-33818",
"url": "https://www.suse.com/security/cve/CVE-2026-33818"
},
{
"category": "external",
"summary": "SUSE Bug 1275034 for CVE-2026-33818",
"url": "https://bugzilla.suse.com/1275034"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-33818"
},
{
"cve": "CVE-2026-39821",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-39821"
}
],
"notes": [
{
"category": "general",
"text": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-39821",
"url": "https://www.suse.com/security/cve/CVE-2026-39821"
},
{
"category": "external",
"summary": "SUSE Bug 1266474 for CVE-2026-39821",
"url": "https://bugzilla.suse.com/1266474"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-39821"
},
{
"cve": "CVE-2026-46600",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-46600"
}
],
"notes": [
{
"category": "general",
"text": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-46600",
"url": "https://www.suse.com/security/cve/CVE-2026-46600"
},
{
"category": "external",
"summary": "SUSE Bug 1272415 for CVE-2026-46600",
"url": "https://bugzilla.suse.com/1272415"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "moderate"
}
],
"title": "CVE-2026-46600"
},
{
"cve": "CVE-2026-46603",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-46603"
}
],
"notes": [
{
"category": "general",
"text": "VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-46603",
"url": "https://www.suse.com/security/cve/CVE-2026-46603"
},
{
"category": "external",
"summary": "SUSE Bug 1279547 for CVE-2026-46603",
"url": "https://bugzilla.suse.com/1279547"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-46603"
},
{
"cve": "CVE-2026-56853",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-56853"
}
],
"notes": [
{
"category": "general",
"text": "When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-56853",
"url": "https://www.suse.com/security/cve/CVE-2026-56853"
},
{
"category": "external",
"summary": "SUSE Bug 1275028 for CVE-2026-56853",
"url": "https://bugzilla.suse.com/1275028"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-56853"
},
{
"cve": "CVE-2026-56854",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-56854"
}
],
"notes": [
{
"category": "general",
"text": "The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client\u0027s remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-56854",
"url": "https://www.suse.com/security/cve/CVE-2026-56854"
},
{
"category": "external",
"summary": "SUSE Bug 1278446 for CVE-2026-56854",
"url": "https://bugzilla.suse.com/1278446"
},
{
"category": "external",
"summary": "SUSE Bug 1280553 for CVE-2026-56854",
"url": "https://bugzilla.suse.com/1280553"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-56854"
},
{
"cve": "CVE-2026-56855",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-56855"
}
],
"notes": [
{
"category": "general",
"text": "Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-56855",
"url": "https://www.suse.com/security/cve/CVE-2026-56855"
},
{
"category": "external",
"summary": "SUSE Bug 1278446 for CVE-2026-56855",
"url": "https://bugzilla.suse.com/1278446"
},
{
"category": "external",
"summary": "SUSE Bug 1280553 for CVE-2026-56855",
"url": "https://bugzilla.suse.com/1280553"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-56855"
},
{
"cve": "CVE-2026-56858",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-56858"
}
],
"notes": [
{
"category": "general",
"text": "Previously, pathological inputs could close an unescaped \u0027/\u0027 early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-56858",
"url": "https://www.suse.com/security/cve/CVE-2026-56858"
},
{
"category": "external",
"summary": "SUSE Bug 1275033 for CVE-2026-56858",
"url": "https://bugzilla.suse.com/1275033"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "moderate"
}
],
"title": "CVE-2026-56858"
},
{
"cve": "CVE-2026-56859",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-56859"
}
],
"notes": [
{
"category": "general",
"text": "Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-56859",
"url": "https://www.suse.com/security/cve/CVE-2026-56859"
},
{
"category": "external",
"summary": "SUSE Bug 1275026 for CVE-2026-56859",
"url": "https://bugzilla.suse.com/1275026"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-56859"
},
{
"cve": "CVE-2026-56860",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-56860"
}
],
"notes": [
{
"category": "general",
"text": "Previously, resolving relative paths containing parent directory (\u0027..\u0027) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for \u0027..\u0027 segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-56860",
"url": "https://www.suse.com/security/cve/CVE-2026-56860"
},
{
"category": "external",
"summary": "SUSE Bug 1275029 for CVE-2026-56860",
"url": "https://bugzilla.suse.com/1275029"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "moderate"
}
],
"title": "CVE-2026-56860"
},
{
"cve": "CVE-2026-56862",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-56862"
}
],
"notes": [
{
"category": "general",
"text": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-56862",
"url": "https://www.suse.com/security/cve/CVE-2026-56862"
},
{
"category": "external",
"summary": "SUSE Bug 1275032 for CVE-2026-56862",
"url": "https://bugzilla.suse.com/1275032"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-56862"
},
{
"cve": "CVE-2026-78662",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-78662"
}
],
"notes": [
{
"category": "general",
"text": "Previously, a channel registered in the mux\u0027s chanList is not usable until it is established. A malicious peer was able flood the channel\u0027s incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-78662",
"url": "https://www.suse.com/security/cve/CVE-2026-78662"
},
{
"category": "external",
"summary": "SUSE Bug 1278446 for CVE-2026-78662",
"url": "https://bugzilla.suse.com/1278446"
},
{
"category": "external",
"summary": "SUSE Bug 1280553 for CVE-2026-78662",
"url": "https://bugzilla.suse.com/1280553"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.aarch64",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.ppc64le",
"openSUSE Leap 16.0:rclone-0:1.75.1-bp160.1.1.x86_64",
"openSUSE Leap 16.0:rclone-bash-completion-0:1.75.1-bp160.1.1.noarch",
"openSUSE Leap 16.0:rclone-zsh-completion-0:1.75.1-bp160.1.1.noarch"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-09-28T15:31:12Z",
"details": "important"
}
],
"title": "CVE-2026-78662"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…