This update for ignition fixes the following issues
CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
bypass and privilege escalation (bsc#1266606).
CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing invalid UTF-8 bytes can lead to infinite
loop (bsc#1272059).
Affected Packages
ignition
SUSE Linux Enterprise High Performance Computing 15 SP7SUSE Linux Enterprise Module for HPC 15 SP7SUSE Linux Enterprise Server 15 SP6SUSE Linux Enterprise Server 15 SP6-LTSS
Fixed in:
2.14.0-150400.9.21.1
ignition-dracut-grub2
SUSE Linux Enterprise High Performance Computing 15 SP7SUSE Linux Enterprise Module for HPC 15 SP7SUSE Linux Enterprise Server 15 SP6SUSE Linux Enterprise Server 15 SP6-LTSS