Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
## This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues: Security issues fixed: * CVE-2025-13465: lodash: prototype pollution in the _.unset and_.omit functions can lead to deletion of methods from global prototypes (bsc#1257325). * CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829). * CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840). * CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test
* bsc#1236149
* bsc#1257033
* bsc#1257325
* bsc#1257698
* bsc#1257836
* bsc#1257838
* bsc#1257840
* bsc#1258040
* bsc#1258637
* bsc#1258640
* bsc#1258641
* bsc#1259010
* bsc#1259013
* bsc#1259015
* bsc#1259210
* bsc#1259774
* bsc#1261829
* jsc#PED-15706
* jsc#PED-15820
Cross-
* CVE-2025-13465
* CVE-2026-25547
* CVE-2026-26996
* CVE-2026-27904
* CVE-2026-4631
* CVE-2026-4802
CVSS scores:
* CVE-2025-13465 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2025-13465 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2025-13465 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Get the latest Linux and open source security news straight to your inbox.