Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update fixes the following issues: cobbler: - Make `fence_ipmitool` a wrapper for `fence_ipmilan` using always `lanplus`. (bsc#1184361) - Remove unused template for `fence_ipmitool`. - Prevent some race conditions when writting tftpboot files and the destination directory is not existing. (bsc#1186124) - Fix trail stripping in case of using UTF symbols. (bsc#1184561) golang-github-prometheus-node_exporter: - Update to 1.1.2 * Bug fixes + Handle errors from disabled PSI subsystem + Sanitize strings from /sys/class/power_supply + Silence missing netclass errors + Fix ineffassign issue + Fix some noisy log lines + filesystem_freebsd: Fix label values + Fix various procfs parsing errors + Handle no data from powersupplyclass + udp_queues_linux.go: change upd to udp in two error strings
#1151558 #1172711 #1175216 #1178767 #1180673
#1182744 #1183573 #1183649 #1183845 #1183864
#1184005 #1184286 #1184311 #1184332 #1184351
#1184361 #1184471 #1184475 #1184561 #1184617
#1184849 #1184892 #1184929 #1184940 #1185042
#1185097 #1185281 #1185506 #1185568 #1185965
#1186025 #1186124 #1186346 #1186508 #1186765
#1186852 #1186858
Cross- CVE-2021-28657 CVE-2021-31607
CVSS scores:
CVE-2021-28657 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2021-28657 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2021-31607 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2021-31607 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
SUSE Linux Enterprise Module for SUSE Manager Server 4.1
Get the latest Linux and open source security news straight to your inbox.