This update for kanidm fixes the following issues:
- Update to version 1.10.2~git0.f3dc9ef1f:
* Release 1.10.2
* Security - CRITICAL - authenticated user privilege escalation
* Refactor modification access paths to remove duplication
* Revert ClientID header (#4334)
* Disable prompt=login (#4340)
* Add missing `/sbin/kanidm-mail-sender` (#4323)
* Remove debug symbols in release builds. (#4319)
- Update to version 1.10.1~git0.d02660a98:
* Release 1.10.1
* Fix copy in TOTP removal prompt and align TOTP case (#4314)
* Resolve base64 encoding of webauthn fields (#4312)
- Update to version 1.10.0-pre~git1.32e2f8ec6:
* Release 1.10.0
* Release 1.10.0-pre
* Release notes (#4304)
* Update ldap3/webauthn-rs (#4302)
* Merge commit from fork
* Merge commit from fork
* Merge commit from fork
* Merge commit from fork
* Add notes on server migration (#4301)
* 20260517 sparkle (#4280)
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-192=1
- openSUSE Backports SLE-15-SP7 (aarch64 x86_64):
kanidm-1.10.2~git0.f3dc9ef1f-bp157.2.32.1
kanidm-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1
kanidm-docs-1.10.2~git0.f3dc9ef1f-bp157.2.32.1
kanidm-server-1.10.2~git0.f3dc9ef1f-bp157.2.32.1
kanidm-unixd-clients-1.10.2~git0.f3dc9ef1f-bp157.2.32.1
Get the latest Linux and open source security news straight to your inbox.