This update for cockpit fixes the following issues:
- CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive resource consumption and crash
a Node.js process (bsc#1257836).
- CVE-2026-26996: minimatch: processing of glob pattern containing repeated wildcards followed by a literal character
that doesn't appear in the test string can lead to ReDoS (bsc#1258641).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-520=1
- openSUSE Leap 16.0:
cockpit-354-160000.2.1
cockpit-bridge-354-160000.2.1
cockpit-devel-354-160000.2.1
cockpit-doc-354-160000.2.1
cockpit-firewalld-354-160000.2.1
cockpit-kdump-354-160000.2.1
cockpit-networkmanager-354-160000.2.1
cockpit-packagekit-354-160000.2.1
cockpit-selinux-354-160000.2.1
cockpit-storaged-354-160000.2.1
cockpit-system-354-160000.2.1
cockpit-ws-354-160000.2.1
cockpit-ws-selinux-354-160000.2.1
* bsc#1257836
* bsc#1258641
References:
* https://www.suse.com/security/cve/CVE-2026-25547.html
* https://www.suse.com/security/cve/CVE-2026-26996.html
Get the latest Linux and open source security news straight to your inbox.