## This update for wicked fixes the following issue * CVE-2026-44932: indirect remote shell command injection via unsanitized DHCP options (bsc#1265221). Changes for wicked: * Update to version 0.6.79 * Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before. * Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833. * Discard string values containing single-quotes in other options. * Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78.
* bsc#1265221
Cross-
* CVE-2026-44932
CVSS scores:
* CVE-2026-44932 ( SUSE ): 5.8
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H
* CVE-2026-44932 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* Basesystem Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
##
* https://www.suse.com/security/cve/CVE-2026-44932.html
* https://bugzilla.suse.com/show_bug.cgi?id=1265221
Get the latest Linux and open source security news straight to your inbox.