Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE Leap 16.0 osc Moderate CVE-2024-22038 Security Update 2026-20361-1

opensuse
Calendar Grey March 14, 2026
Dist Opensuse Esm H88
Update for openSUSE addresses a moderate issue in osc and obs-scm-bridge with CVE-2024-22038. Two bug fixes included.
An update that solves one vulnerability and has 2 bug fixes can now be installed.

Description

This update for osc, obs-scm-bridge fixes the following issues:

Changes in osc:

- 1.24.0

- Command-line:

- Add '--target-owner' option to 'git-obs repo fork' command

- Add '--self' parameter to fix 'no matching parent repo' error message in 'git-obs pr create'

- Fix 'osc aggregatepac' for scmsync packages

- Fix 'osc build' to retrieve buildconfig from git package's cache

- Fix 'osc token' error handling for project wide trigger

- Fix string formatting for id in obs-request.xml in 'git-obs pr dump'

- Library:

- Consolidate build types in build.py and commandline.py

- Fix build.get_build_type() by comparing binary_type only if specified

- Make use of queryconfig tool configurable and consistent

- Fix how get_request_collection() filters the projects and packages

- Support copying packages from an scmsync source, when target exists

- Add timestamps to the DEBUG output

- Update new project template

- 1.23.0

- Command-line:

...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

obs-scm-bridge-0.7.4-bp160.1.1

osc-1.24.0-bp160.1.1

References

* bsc#1230469

* bsc#1247410

References:

* https://www.suse.com/security/cve/CVE-2024-22038.html

Announcement ID: openSUSE-SU-2026:20361-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here