SB2026050121 - SUSE update for terraform-provider-local, terraform-provider-random, terraform-provider-tls



SB2026050121 - SUSE update for terraform-provider-local, terraform-provider-random, terraform-provider-tls

Published: May 1, 2026

Security Bulletin ID SB2026050121
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Improper validation of integrity check value (CVE-ID: CVE-2026-25934)

The vulnerability allows a remote attacker to cause integrity issues by supplying corrupted repository data.

The vulnerability exists due to improper validation of integrity check values in .pack and .idx file handling when processing fetched packfiles and generated pack indexes. A remote attacker can provide corrupted repository data to cause integrity issues by making the application consume corrupted files and trigger unexpected errors.

User interaction is required for a client to fetch and process repository data.


2) Improper Authorization (CVE-ID: CVE-2026-33186)

The vulnerability allows a remote attacker to gain access to bypass authorization.

The vulnerability exists due to authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. A remote attacker can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server to bypass authorization.


Remediation

Install update from vendor's website.