From 00faed4a9182a096d3a83b9766714b955b2e97d6174f4e291e7841318ab3135f Mon Sep 17 00:00:00 2001 From: Robert Frohl <1426+rfrohl@noreply.src.opensuse.org> Date: Thu, 16 Jul 2026 12:39:18 +0200 Subject: [PATCH] Update submodules from pool/ctop#2 and create patchinfo.20260716103918513562.93181000773252/_patchinfo --- ctop | 2 +- .../_patchinfo | 27 +++++++++++++++++++ 2 files changed, 28 insertions(+), 1 deletion(-) create mode 100644 patchinfo.20260716103918513562.93181000773252/_patchinfo diff --git a/ctop b/ctop index e73e88e..6f9aa5d 160000 --- a/ctop +++ b/ctop @@ -1 +1 @@ -Subproject commit e73e88ec78b4a21da69ae18d1adaac572ae461e88ab28d33d9e4262732cc48fb +Subproject commit 6f9aa5d5edb29199c76c8a04a94e05d7b38e94467a697eaeb14a57c63728a13d diff --git a/patchinfo.20260716103918513562.93181000773252/_patchinfo b/patchinfo.20260716103918513562.93181000773252/_patchinfo new file mode 100644 index 0000000..2d944ba --- /dev/null +++ b/patchinfo.20260716103918513562.93181000773252/_patchinfo @@ -0,0 +1,27 @@ + + VUL-0: CVE-2022-21698: ctop: github.com/prometheus/client_golang/prometheus/promhttp: Denial of service using InstrumentHandlerCounter + + + + VUL-0: CVE-2026-33814: ctop: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE + VUL-0: CVE-2026-39821: ctop: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation + + + VUL-0: CVE-2024-45310: ctop: github.com/opencontainers/runc/libcontainer/utils: runc can be tricked into creating empty files/directories on host + VUL-0: CVE-2026-10722: ctop: github.com/cilium/ebpf: BTF string offset boundary check can lead to crash when parsing malformed ELF/BTF input + jubalh + important + security + Security update for ctop + This update for ctop fixes the following issues: + +Changes in ctop embedded dependencies: + +- CVE-2022-21698: client_golang: Denial of service using InstrumentHandlerCounter (bsc#1248710) +- CVE-2024-45310: runc: runc can be tricked into creating empty files (bsc#1257431) +- CVE-2026-10722: ebpf: Crash when parsing malformed ELF/BTF input (bsc#1267805) +- CVE-2026-33814: net: Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265800) +- CVE-2026-39821: net: Failure to reject ASCII-only Punycode-encoded labels (bsc#1266632) + + ctop +