Alerts This Week
Warning Icon 1 815
Alerts This Week
Warning Icon 1 815

openSUSE 2026-0151-1 rclone Critical Update for Multiple Issues

opensuse
Calendar Grey April 24, 2026
Dist Opensuse Esm H88
Critical security update for rclone in openSUSE addressing multiple vulnerabilities requiring immediate action.
An update that fixes 18 vulnerabilities is now available.

Description

This update for rclone fixes the following issues:

- Update to version 1.73.5: (boo#1262439 boo#1262438)

* operations: add AuthRequired to operations/fsinfo to prevent backend

creation CVE-2026-41179

* rc: snapshot NoAuth at startup to prevent runtime auth bypass

CVE-2026-41176

* rc: add AuthRequired to options/set to prevent auth bypass

CVE-2026-41176

* s3: fix empty delimiter parameter rejected by Archiware P5 server

* azureblob/auth: add Microsoft Partner Network User-Agent prefix

* drime: fix User.EntryPermissions JSON unmarshalling

* filter: fix debug logs that fire before logger is configured - fixes

#9291

* s3: fix TencentCOS CDN endpoint failing on bucket check

* iclouddrive: fix 'directory not found' error when the directory

contains accent marks

* Start v1.73.5-DEV development

- Update to version 1.73.4:

* Version v1.73.4

* Update to go 1.25.9 to fix multiple CVEs

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-151=1

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2026-151=1

Package List

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

rclone-1.73.5-bp157.2.3.1

rclone-debuginfo-1.73.5-bp157.2.3.1

- openSUSE Backports SLE-15-SP7 (noarch):

rclone-bash-completion-1.73.5-bp157.2.3.1

rclone-zsh-completion-1.73.5-bp157.2.3.1

- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):

rclone-1.73.5-bp156.2.6.1

- openSUSE Backports SLE-15-SP6 (noarch):

rclone-bash-completion-1.73.5-bp156.2.6.1

rclone-zsh-completion-1.73.5-bp156.2.6.1

References

https://www.suse.com/security/cve/CVE-2023-45286.html

https://www.suse.com/security/cve/CVE-2023-45288.html

https://www.suse.com/security/cve/CVE-2023-48795.html

https://www.suse.com/security/cve/CVE-2024-24786.html

https://www.suse.com/security/cve/CVE-2024-45337.html

https://www.suse.com/security/cve/CVE-2024-45338.html

https://www.suse.com/security/cve/CVE-2024-51744.html

https://www.suse.com/security/cve/CVE-2024-52522.html

https://www.suse.com/security/cve/CVE-2025-22869.html

https://www.suse.com/security/cve/CVE-2025-22870.html

https://www.suse.com/security/cve/CVE-2025-30204.html

https://www.suse.com/security/cve/CVE-2025-58181.html

https://www.suse.com/security/cve/CVE-2025-68121.html

https://www.suse.com/security/cve/CVE-2026-1229.html

https://www.suse.com/security/cve/CVE-2026-27141.html

https://www.suse.com/security/cve/CVE-2026-33186.html

https://www.suse.com/security/cve/CVE-2026-41176.html

https://www.suse.com/security/cve/CVE-2026-41179.html

https://bugzilla.suse.com/1140423

https://bugzil...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0151-1
Rating: critical
Affected Products: openSUSE Backports SLE-15-SP6 openSUSE Backports SLE-15-SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here