Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE 2026 Multi-Linux Manager Critical Update 11 Issues Fixed

suse
Calendar Grey March 30, 2026
Dist Suse Esm H88
Critical security update for SUSE Multi-Linux Manager Client Tools fixes 11 issues and offers new features. Install it now.
An update that solves 11 vulnerabilities, contains two features and has two security fixes can now be installed.

Summary

## This update fixes the following issues: golang-github-prometheus-prometheus: * CVE-2026-27606: Fix arbitrary file write via path traversal in rollup (bsc#1258893) * Bump rollup to version 4.59.0 * Drop SLE 12 support (jsc#PED-15474) * CVE-2026-25547: Fix unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841): * Bump brace-expansion to version 5.0.2 * Do not build old web UI. Fixes following security vulnerabilities: * CVE-2026-1615: jsonpath: arbitrary code injection due to unsafe evaluation of user-supplied JSON Path expressions (bsc#1257897) * CVE-2025-61140: jsonpath: the `value` function is vulnerable to prototype pollution (bsc#1257442) * Set source URL in the spec file and drop tar service grafana: * Drop support for SLE 12 (jsc#PED-15474)

References

* bsc#1254256

* bsc#1254257

* bsc#1254903

* bsc#1254904

* bsc#1254905

* bsc#1257442

* bsc#1257447

* bsc#1257841

* bsc#1257897

* bsc#1258015

* bsc#1258136

* bsc#1258893

* bsc#1258957

* jsc#MSQA-1044

* jsc#PED-15474

Cross-

* CVE-2025-3415

* CVE-2025-61140

* CVE-2025-62348

* CVE-2025-62349

* CVE-2025-67724

* CVE-2025-67725

* CVE-2025-67726

* CVE-2026-1615

* CVE-2026-21722

* CVE-2026-25547

* CVE-2026-27606

CVSS scores:

* CVE-2025-3415 ( SUSE ): 5.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2025-3415 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

* CVE-2025-3415 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

* CVE-2025-61140 ( SUSE ): 9.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1148-1
Release Date: 2026-03-30T11:21:21Z
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here