Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves 18 vulnerabilities, contains two features and has 65 security fixes can now be installed.. # Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server Announcement ID: SUSE-SU-2026:2774-1 Release Date: 2026-07-06T07:52:26Z Rating: important References: * bsc#1208800 * bsc#1226578 * bsc#1234567 * bsc#1238890 * bsc#1242916 * bsc#1245107 * bsc#1247707 * bsc#1248699 * bsc#1249243 * bsc#1253032 * bsc#1254900 * bsc#1257583 * bsc#1257894 * bsc#1258041 * bsc#1258079 * bsc#1258144 * bsc#1258382 * bsc#1258816 * bsc#1259087 * bsc#1259230 * bsc#1259261 * bsc#1259474 * bsc#1259479 * bsc#1259482 * bsc#1259521 * bsc#1259590 * bsc#1259591 * bsc#1259700 * bsc#1259739 * bsc#1259787 * bsc#1259960 * bsc#1260031 * bsc#1260614 * bsc#1260806 * bsc#1261305 * bsc#1261307 * bsc#1261327 * bsc#1261631 * bsc#1261723 * bsc#1261753 * bsc#1261841 * bsc#1261902 * bsc#1262090 * bsc#1262222 * bsc#1262285 * bsc#1262460 * bsc#1262471 * bsc#1262492 * bsc#1262595 * bsc#1262708 * bsc#1262720 * bsc#1262760 * bsc#1262761 * bsc#1262950 * bsc#1263501 * bsc#1263814 * bsc#1263841 * bsc#1263986 * bsc#1263987 * bsc#1264149 * bsc#1264174 * bsc#1264234 * bsc#1264256 * bsc#1264966 * bsc#1265134 * bsc#1265281 * bsc#1265282 * bsc#1265283 * bsc#1265284 * bsc#1265285 * bsc#1265286 * bsc#1265287 * bsc#1265288 * bsc#1265289 * bsc#1265290 * bsc#1265319 * bsc#1265358 * bsc#1265975 * bsc#1266012 * bsc#1266556 * bsc#1266600 * bsc#1269253 * bsc#1269534 * jsc#MSQA-1056 * jsc#SUMA-320 Cross-References: * CVE-2022-21698 * CVE-2026-28374 * CVE-2026-28376 * CVE-2026-28379 * CVE-2026-28380 * CVE-2026-28383 * CVE-2026-33376 * CVE-2026-33377 * CVE-2026-33378 * CVE-2026-33380 * CVE-2026-33381 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-40179 * CVE-2026-41602 * CVE-2026-42151 * CVE-2026-42154 * CVE-2026-42198 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N *CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE * SUSE Multi-Linux Manager Server 5.1 Extension for SLE An update that solves 18 vulnerabilities, contains two features and has 65 security fixes can now be installed. ## Recommended update 5.1.4 for Multi-Linux Manager Proxy ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4: * Bugs mentioned: bsc#1208800, bsc#1234567, bsc#1238890, bsc#1253032, bsc#1257894 bsc#1258382, bsc#1259474, bsc#1259739, bsc#1260806, bsc#1261902 bsc#1262708, bsc#1264966, bsc#1266012 Container images and uyuni-tools changes: proxy-httpd-image, proxy-salt-broker-image, proxy-salt-broker-image, proxy- squid-image, proxy-ssh-image: * Removed unused repositories proxy-tftpd-image: * Use custom entry id for grub saltboot entries(bsc#1258382, bsc#1208800) * Removed unused repositories uyuni-tools: * Version 5.1.29-0 * Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Removed waitForTraefik function (bsc#1261902) * Fixed inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: spacecmd: * Version 5.1.14-0 * Updated translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhanced buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Aligned subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facingchanges susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc uyuni-common-libs: * Version 5.1.6-0 * security(checksums): dropped md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Recommended update 5.1.4 for Multi-Linux Manager Retail Branch Server ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4: * Bugs mentioned: bsc#1208800, bsc#1234567, bsc#1238890, bsc#1253032, bsc#1257894 bsc#1258382, bsc#1259474, bsc#1259739, bsc#1260806, bsc#1261902 bsc#1262708, bsc#1264966, bsc#1266012 Container images and uyuni-tools changes: proxy-httpd-image, proxy-salt-broker-image, proxy-salt-broker-image, proxy- squid-image, proxy-ssh-image: * Removed unused repositories proxy-tftpd-image: * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Removed unused repositories uyuni-tools: * Version 5.1.29-0 * Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Removed waitForTraefik function (bsc#1261902) * Fixed inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: spacecmd: * Version 5.1.14-0 * Updated translation strings spacewalk-backend: * Version 5.1.17-0 *Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhanced buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Aligned subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc uyuni-common-libs: * Version 5.1.6-0 * security(checksums): dropped md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Security update 5.1.4 for Multi-Linux Manager Server ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager5.1.4 * Added note about migration for SUSE Linux Enterprise Server 16 on SSH managed minions * Product Migration from SUSE Linux Enterprise Server 15 SP7 to 16.0 * SUSE Liberty Linux 9.6 Support * New API Endpoint - listMigrationTargetsWithChannels * Debian 12 End-of-Life Notice * SUSE Registry URL Change * Security fixes: CVE-2026-34986, CVE-2026-41602, CVE-2026-39821, CVE-2026-42198 CVE-2022-21698, CVE-2026-40179, CVE-2026-42151, CVE-2026-42154 CVE-2026-28374, CVE-2026-28376, CVE-2026-28379, CVE-2026-28380 CVE-2026-28383, CVE-2026-33376, CVE-2026-33377, CVE-2026-33378 CVE-2026-33380, CVE-2026-33381 * Bugs mentioned: bsc#1226578, bsc#1234567, bsc#1238890, bsc#1242916, bsc#1245107 bsc#1247707, bsc#1248699, bsc#1249243, bsc#1253032, bsc#1257583 bsc#1257894, bsc#1258041, bsc#1258079, bsc#1258144, bsc#1258382 bsc#1258816, bsc#1259087, bsc#1259230, bsc#1259261, bsc#1259474 bsc#1259479, bsc#1259482, bsc#1259521, bsc#1259590, bsc#1259591 bsc#1259700, bsc#1259739, bsc#1259787, bsc#1259960, bsc#1260031 bsc#1260614, bsc#1260806, bsc#1261305, bsc#1261307, bsc#1261327 bsc#1261631, bsc#1261723, bsc#1261753, bsc#1261841, bsc#1261902 bsc#1262090, bsc#1262285, bsc#1262460, bsc#1262471, bsc#1262492 bsc#1262595, bsc#1262708, bsc#1262720, bsc#1262761, bsc#1263814 bsc#1263841, bsc#1264149, bsc#1264234, bsc#1264256, bsc#1264966 bsc#1265134, bsc#1265319, bsc#1265358, bsc#1265975, bsc#1266012 bsc#1262950, bsc#1263501, bsc#1266600, bsc#1266556, bsc#1264174 bsc#1262222, bsc#1263986, bsc#1263987, bsc#1265290, bsc#1265289 bsc#1265288, bsc#1265287, bsc#1265286, bsc#1265285, bsc#1265284 bsc#1265283, bsc#1265282, bsc#1265281, bsc#1269253, bsc#1269534 Container images and uyuni-tools changes: server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updateddependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Added "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Added support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fixed the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.28-0 * Check access rights on two formula API calls (bsc#1269253) * Sanitize uploaded image name (bsc#1269534) * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fixed CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fixed missing translations (bsc#1259787) * Fixed hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fixed enforcement of consecutive chars in password policy (bsc#1262761) * Use salt'snetwork module if host or nslookup are not installed (bsc#1262720) * Fixed Remote Commands hang on direct hostname (bsc#1226578) * Fixed Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Added 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Added missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fixed Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fixed CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fixed conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscriptionmatching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fixed 2 missing part numbers (bsc#1264256) susemanager: * Version 5.1.17-0 * Added SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Removed spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicensed mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bcs#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open EnterpriseServer 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed comamnd for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Added index on rhnPackage (checksum_id) (bsc#1258041) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Added 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fixed GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fixed CPU reporting for ppc64le clients (bsc#1259521) * Fixed refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Added missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Added SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecuritydetection uyuni-reportdb-schema: * version 5.1.7-0 * Increased url on table repository (bsc#1259230) uyuni-setup-reportdb: * Version 5.1.5-0 * Fixed delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Dropped SUSECloud module as not longer maintainednor used * Version 1.0.30-0 * No customer facing changes How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgradm upgrade podman` which will use the default image tags. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Server 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Server-SLE-5.1-2026-2774=1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Retail-Branch-Server- SLE-5.1-2026-2774=1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Proxy-SLE-5.1-2026-2774=1 ## Package List: * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (noarch) * mgrpxy-lang-5.1.29-150700.3.26.1 * mgrpxy-bash-completion-5.1.29-150700.3.26.1 * mgrpxy-zsh-completion-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Proxy 5.1 Extensionfor SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-5.1.29-150700.3.26.1 * mgrpxy-debuginfo-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.25 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-ppc64le-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-ppc64le-server-saline-image-5.1.4-9.20.24 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE(x86_64) * suse-multi-linux-manager-5.1-x86_64-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-x86_64-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-x86_64-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (noarch) * mgrctl-zsh-completion-5.1.29-150700.3.26.1 * mgrctl-lang-5.1.29-150700.3.26.1 * mgradm-bash-completion-5.1.29-150700.3.26.1 * mgrctl-bash-completion-5.1.29-150700.3.26.1 * mgradm-zsh-completion-5.1.29-150700.3.26.1 * mgradm-lang-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.1.29-150700.3.26.1 * mgradm-5.1.29-150700.3.26.1 * mgradm-debuginfo-5.1.29-150700.3.26.1 * mgrctl-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-aarch64-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-aarch64-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-aarch64-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image-5.1.4-8.20.13 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-s390x-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image-5.1.4-8.20.12 *suse-multi-linux-manager-5.1-s390x-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-s390x-server-postgresql-image-5.1.4-6.24.3 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (noarch) * mgrpxy-lang-5.1.29-150700.3.26.1 * mgrpxy-bash-completion-5.1.29-150700.3.26.1 * mgrpxy-zsh-completion-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-debuginfo-5.1.29-150700.3.26.1 * mgrpxy-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (x86_64) *suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.25 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2026-28374.html * https://www.suse.com/security/cve/CVE-2026-28376.html * https://www.suse.com/security/cve/CVE-2026-28379.html * https://www.suse.com/security/cve/CVE-2026-28380.html * https://www.suse.com/security/cve/CVE-2026-28383.html * https://www.suse.com/security/cve/CVE-2026-33376.html * https://www.suse.com/security/cve/CVE-2026-33377.html * https://www.suse.com/security/cve/CVE-2026-33378.html * https://www.suse.com/security/cve/CVE-2026-33380.html * https://www.suse.com/security/cve/CVE-2026-33381.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40179.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-42151.html * https://www.suse.com/security/cve/CVE-2026-42154.html * https://www.suse.com/security/cve/CVE-2026-42198.html * https://bugzilla.suse.com/show_bug.cgi?id=1208800 * https://bugzilla.suse.com/show_bug.cgi?id=1226578 * https://bugzilla.suse.com/show_bug.cgi?id=1234567 * https://bugzilla.suse.com/show_bug.cgi?id=1238890 * https://bugzilla.suse.com/show_bug.cgi?id=1242916 * https://bugzilla.suse.com/show_bug.cgi?id=1245107 * https://bugzilla.suse.com/show_bug.cgi?id=1247707 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1249243 * https://bugzilla.suse.com/show_bug.cgi?id=1253032 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 *https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1257894 * https://bugzilla.suse.com/show_bug.cgi?id=1258041 * https://bugzilla.suse.com/show_bug.cgi?id=1258079 * https://bugzilla.suse.com/show_bug.cgi?id=1258144 * https://bugzilla.suse.com/show_bug.cgi?id=1258382 * https://bugzilla.suse.com/show_bug.cgi?id=1258816 * https://bugzilla.suse.com/show_bug.cgi?id=1259087 * https://bugzilla.suse.com/show_bug.cgi?id=1259230 * https://bugzilla.suse.com/show_bug.cgi?id=1259261 * https://bugzilla.suse.com/show_bug.cgi?id=1259474 * https://bugzilla.suse.com/show_bug.cgi?id=1259479 * https://bugzilla.suse.com/show_bug.cgi?id=1259482 * https://bugzilla.suse.com/show_bug.cgi?id=1259521 * https://bugzilla.suse.com/show_bug.cgi?id=1259590 * https://bugzilla.suse.com/show_bug.cgi?id=1259591 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1259787 * https://bugzilla.suse.com/show_bug.cgi?id=1259960 * https://bugzilla.suse.com/show_bug.cgi?id=1260031 * https://bugzilla.suse.com/show_bug.cgi?id=1260614 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1261305 * https://bugzilla.suse.com/show_bug.cgi?id=1261307 * https://bugzilla.suse.com/show_bug.cgi?id=1261327 * https://bugzilla.suse.com/show_bug.cgi?id=1261631 * https://bugzilla.suse.com/show_bug.cgi?id=1261723 * https://bugzilla.suse.com/show_bug.cgi?id=1261753 * https://bugzilla.suse.com/show_bug.cgi?id=1261841 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262090 * https://bugzilla.suse.com/show_bug.cgi?id=1262222 * https://bugzilla.suse.com/show_bug.cgi?id=1262285 * https://bugzilla.suse.com/show_bug.cgi?id=1262460 * https://bugzilla.suse.com/show_bug.cgi?id=1262471 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 *https://bugzilla.suse.com/show_bug.cgi?id=1262595 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262720 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1262761 * https://bugzilla.suse.com/show_bug.cgi?id=1262950 * https://bugzilla.suse.com/show_bug.cgi?id=1263501 * https://bugzilla.suse.com/show_bug.cgi?id=1263814 * https://bugzilla.suse.com/show_bug.cgi?id=1263841 * https://bugzilla.suse.com/show_bug.cgi?id=1263986 * https://bugzilla.suse.com/show_bug.cgi?id=1263987 * https://bugzilla.suse.com/show_bug.cgi?id=1264149 * https://bugzilla.suse.com/show_bug.cgi?id=1264174 * https://bugzilla.suse.com/show_bug.cgi?id=1264234 * https://bugzilla.suse.com/show_bug.cgi?id=1264256 * https://bugzilla.suse.com/show_bug.cgi?id=1264966 * https://bugzilla.suse.com/show_bug.cgi?id=1265134 * https://bugzilla.suse.com/show_bug.cgi?id=1265281 * https://bugzilla.suse.com/show_bug.cgi?id=1265282 * https://bugzilla.suse.com/show_bug.cgi?id=1265283 * https://bugzilla.suse.com/show_bug.cgi?id=1265284 * https://bugzilla.suse.com/show_bug.cgi?id=1265285 * https://bugzilla.suse.com/show_bug.cgi?id=1265286 * https://bugzilla.suse.com/show_bug.cgi?id=1265287 * https://bugzilla.suse.com/show_bug.cgi?id=1265288 * https://bugzilla.suse.com/show_bug.cgi?id=1265289 * https://bugzilla.suse.com/show_bug.cgi?id=1265290 * https://bugzilla.suse.com/show_bug.cgi?id=1265319 * https://bugzilla.suse.com/show_bug.cgi?id=1265358 * https://bugzilla.suse.com/show_bug.cgi?id=1265975 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://bugzilla.suse.com/show_bug.cgi?id=1266556 * https://bugzilla.suse.com/show_bug.cgi?id=1266600 * https://bugzilla.suse.com/show_bug.cgi?id=1269253 * https://bugzilla.suse.com/show_bug.cgi?id=1269534 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/SUMA-320 . SUSE announces an important maintenance update for Multi-Linux Manager5.1 with 65 security fixes.. SUSE maintenance update, Multi-Linux Manager security, Linux vulnerability patching. . Severity: Important. LinuxSecurity.com Team
An update that solves four vulnerabilities can now be installed.. # Security update for apache2 Announcement ID: SUSE-SU-2025:4518-1 Release Date: 2025-12-23T19:07:46Z Rating: important References: * bsc#1254511 * bsc#1254512 * bsc#1254514 * bsc#1254515 Cross-References: * CVE-2025-55753 * CVE-2025-58098 * CVE-2025-65082 * CVE-2025-66200 CVSS scores: * CVE-2025-55753 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-55753 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-55753 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-58098 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-58098 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-58098 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2025-65082 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-65082 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2025-65082 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-66200 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-66200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-66200 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues: * CVE-2025-55753: Fixed mod_md (ACME) unintended retry intervals (bsc#1254511) * CVE-2025-65082: Fixed CGI environment variable override (bsc#1254514) *CVE-2025-58098: Fixed Server Side Includes adding query string to #exec cmd=... (bsc#1254512) * CVE-2025-66200: Fixed mod_userdir+suexec bypass via AllowOverride FileInfo (bsc#1254515) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-4518=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-4518=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2025-4518=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-prefork-debugsource-2.4.62-150700.4.9.1 * apache2-2.4.62-150700.4.9.1 * apache2-debuginfo-2.4.62-150700.4.9.1 * apache2-prefork-2.4.62-150700.4.9.1 * apache2-debugsource-2.4.62-150700.4.9.1 * apache2-prefork-debuginfo-2.4.62-150700.4.9.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-event-debuginfo-2.4.62-150700.4.9.1 * apache2-event-2.4.62-150700.4.9.1 * apache2-event-debugsource-2.4.62-150700.4.9.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-utils-2.4.62-150700.4.9.1 * apache2-worker-2.4.62-150700.4.9.1 * apache2-worker-debuginfo-2.4.62-150700.4.9.1 * apache2-worker-debugsource-2.4.62-150700.4.9.1 * apache2-utils-debuginfo-2.4.62-150700.4.9.1 * apache2-utils-debugsource-2.4.62-150700.4.9.1 * apache2-devel-2.4.62-150700.4.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-55753.html * https://www.suse.com/security/cve/CVE-2025-58098.html * https://www.suse.com/security/cve/CVE-2025-65082.html * https://www.suse.com/security/cve/CVE-2025-66200.html * https://bugzilla.suse.com/show_bug.cgi?id=1254511 * https://bugzilla.suse.com/show_bug.cgi?id=1254512 * https://bugzilla.suse.com/show_bug.cgi?id=1254514 * https://bugzilla.suse.com/show_bug.cgi?id=1254515 . Update addresses four important issues in Apache2, improving security and functionality on SUSE systems. Immediate install recommended.. apache2 security, SUSE update, important vulnerabilities, server security fixes. . Severity: Important. LinuxSecurity.com Team
* bsc#1227268 * bsc#1227269 Cross-References: * CVE-2024-38475 . # Security update for apache2 Announcement ID: SUSE-SU-2024:2591-1 Rating: important References: * bsc#1227268 * bsc#1227269 Cross-References: * CVE-2024-38475 * CVE-2024-38476 CVSS scores: * CVE-2024-38475 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2024-38476 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves two vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues: * CVE-2024-38475: Fixed improper escaping of output in mod_rewrite (bsc#1227268) * CVE-2024-38476: Fixed server may use exploitable/malicious backend application output to run local handlers via internal redirect (bsc#1227269) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-2591=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-2591=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patchSUSE-SLE-Product-SLES-15-SP2-LTSS-2024-2591=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-2591=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-2591=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-2591=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-2591=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * apache2-debugsource-2.4.51-150200.3.70.1 * apache2-worker-debuginfo-2.4.51-150200.3.70.1 * apache2-devel-2.4.51-150200.3.70.1 * apache2-utils-debuginfo-2.4.51-150200.3.70.1 * apache2-debuginfo-2.4.51-150200.3.70.1 * apache2-2.4.51-150200.3.70.1 * apache2-utils-2.4.51-150200.3.70.1 * apache2-prefork-2.4.51-150200.3.70.1 * apache2-prefork-debuginfo-2.4.51-150200.3.70.1 * apache2-worker-2.4.51-150200.3.70.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * apache2-doc-2.4.51-150200.3.70.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * apache2-debugsource-2.4.51-150200.3.70.1 * apache2-worker-debuginfo-2.4.51-150200.3.70.1 * apache2-devel-2.4.51-150200.3.70.1 * apache2-utils-debuginfo-2.4.51-150200.3.70.1 * apache2-debuginfo-2.4.51-150200.3.70.1 * apache2-2.4.51-150200.3.70.1 * apache2-utils-2.4.51-150200.3.70.1 * apache2-prefork-2.4.51-150200.3.70.1 * apache2-prefork-debuginfo-2.4.51-150200.3.70.1 * apache2-worker-2.4.51-150200.3.70.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * apache2-doc-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * apache2-debugsource-2.4.51-150200.3.70.1 * apache2-worker-debuginfo-2.4.51-150200.3.70.1 *apache2-devel-2.4.51-150200.3.70.1 * apache2-utils-debuginfo-2.4.51-150200.3.70.1 * apache2-debuginfo-2.4.51-150200.3.70.1 * apache2-2.4.51-150200.3.70.1 * apache2-utils-2.4.51-150200.3.70.1 * apache2-prefork-2.4.51-150200.3.70.1 * apache2-prefork-debuginfo-2.4.51-150200.3.70.1 * apache2-worker-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * apache2-doc-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * apache2-debugsource-2.4.51-150200.3.70.1 * apache2-worker-debuginfo-2.4.51-150200.3.70.1 * apache2-devel-2.4.51-150200.3.70.1 * apache2-utils-debuginfo-2.4.51-150200.3.70.1 * apache2-debuginfo-2.4.51-150200.3.70.1 * apache2-2.4.51-150200.3.70.1 * apache2-utils-2.4.51-150200.3.70.1 * apache2-prefork-2.4.51-150200.3.70.1 * apache2-prefork-debuginfo-2.4.51-150200.3.70.1 * apache2-worker-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * apache2-doc-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * apache2-debugsource-2.4.51-150200.3.70.1 * apache2-worker-debuginfo-2.4.51-150200.3.70.1 * apache2-devel-2.4.51-150200.3.70.1 * apache2-utils-debuginfo-2.4.51-150200.3.70.1 * apache2-debuginfo-2.4.51-150200.3.70.1 * apache2-2.4.51-150200.3.70.1 * apache2-utils-2.4.51-150200.3.70.1 * apache2-prefork-2.4.51-150200.3.70.1 * apache2-prefork-debuginfo-2.4.51-150200.3.70.1 * apache2-worker-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * apache2-doc-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * apache2-debugsource-2.4.51-150200.3.70.1 * apache2-worker-debuginfo-2.4.51-150200.3.70.1 * apache2-devel-2.4.51-150200.3.70.1 * apache2-utils-debuginfo-2.4.51-150200.3.70.1 * apache2-debuginfo-2.4.51-150200.3.70.1 *apache2-2.4.51-150200.3.70.1 * apache2-utils-2.4.51-150200.3.70.1 * apache2-prefork-2.4.51-150200.3.70.1 * apache2-prefork-debuginfo-2.4.51-150200.3.70.1 * apache2-worker-2.4.51-150200.3.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * apache2-doc-2.4.51-150200.3.70.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * apache2-debugsource-2.4.51-150200.3.70.1 * apache2-worker-debuginfo-2.4.51-150200.3.70.1 * apache2-devel-2.4.51-150200.3.70.1 * apache2-utils-debuginfo-2.4.51-150200.3.70.1 * apache2-debuginfo-2.4.51-150200.3.70.1 * apache2-2.4.51-150200.3.70.1 * apache2-utils-2.4.51-150200.3.70.1 * apache2-prefork-2.4.51-150200.3.70.1 * apache2-prefork-debuginfo-2.4.51-150200.3.70.1 * apache2-worker-2.4.51-150200.3.70.1 * SUSE Enterprise Storage 7.1 (noarch) * apache2-doc-2.4.51-150200.3.70.1 ## References: * https://www.suse.com/security/cve/CVE-2024-38475.html * https://www.suse.com/security/cve/CVE-2024-38476.html * https://bugzilla.suse.com/show_bug.cgi?id=1227268 * https://bugzilla.suse.com/show_bug.cgi?id=1227269 . Crucial notifications concerning Apache2 that tackle vulnerabilities within SUSE Enterprise offerings. Apply the updates to fortify your environment.. Apache2 Security Updates,SUSE Linux Updates,Security Fixes,Remote Code Execution,Server Security. . Severity: Important. LinuxSecurity.com Team
* bsc#1218544 Cross-References: * CVE-2024-0217 . # Security update for PackageKit Announcement ID: SUSE-SU-2024:0966-1 Rating: moderate References: * bsc#1218544 Cross-References: * CVE-2024-0217 CVSS scores: * CVE-2024-0217 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2024-0217 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for PackageKit fixes the following issues: * CVE-2024-0217: Check that Finished signal is emitted at most once (bsc#1218544). ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-966=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-966=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-966=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-966=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-966=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libpackagekit-glib2-devel-1.1.3-24.18.1 * PackageKit-debugsource-1.1.3-24.18.1 * PackageKit-devel-1.1.3-24.18.1 * PackageKit-devel-debuginfo-1.1.3-24.18.1 *PackageKit-debuginfo-1.1.3-24.18.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * PackageKit-debugsource-1.1.3-24.18.1 * PackageKit-backend-zypp-1.1.3-24.18.1 * PackageKit-1.1.3-24.18.1 * libpackagekit-glib2-18-debuginfo-1.1.3-24.18.1 * PackageKit-backend-zypp-debuginfo-1.1.3-24.18.1 * libpackagekit-glib2-18-1.1.3-24.18.1 * PackageKit-debuginfo-1.1.3-24.18.1 * typelib-1_0-PackageKitGlib-1_0-1.1.3-24.18.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * PackageKit-lang-1.1.3-24.18.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * PackageKit-debugsource-1.1.3-24.18.1 * PackageKit-backend-zypp-1.1.3-24.18.1 * PackageKit-1.1.3-24.18.1 * libpackagekit-glib2-18-debuginfo-1.1.3-24.18.1 * PackageKit-backend-zypp-debuginfo-1.1.3-24.18.1 * libpackagekit-glib2-18-1.1.3-24.18.1 * PackageKit-debuginfo-1.1.3-24.18.1 * typelib-1_0-PackageKitGlib-1_0-1.1.3-24.18.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * PackageKit-lang-1.1.3-24.18.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * PackageKit-debugsource-1.1.3-24.18.1 * PackageKit-backend-zypp-1.1.3-24.18.1 * PackageKit-1.1.3-24.18.1 * libpackagekit-glib2-18-debuginfo-1.1.3-24.18.1 * PackageKit-backend-zypp-debuginfo-1.1.3-24.18.1 * libpackagekit-glib2-18-1.1.3-24.18.1 * PackageKit-debuginfo-1.1.3-24.18.1 * typelib-1_0-PackageKitGlib-1_0-1.1.3-24.18.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * PackageKit-lang-1.1.3-24.18.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * PackageKit-gstreamer-plugin-debuginfo-1.1.3-24.18.1 * PackageKit-debugsource-1.1.3-24.18.1 * PackageKit-gstreamer-plugin-1.1.3-24.18.1 * PackageKit-debuginfo-1.1.3-24.18.1 * PackageKit-gtk3-module-1.1.3-24.18.1 * PackageKit-gtk3-module-debuginfo-1.1.3-24.18.1 ## References: *https://www.suse.com/security/cve/CVE-2024-0217.html * https://bugzilla.suse.com/show_bug.cgi?id=1218544 . An essential notice announcing a significant patch for PackageKit related to a notable security vulnerability. Please remain informed!. PackageKit Security Update, SUSE Announcement, Software Vulnerability, Linux Update. . LinuxSecurity.com Team
A vulnerability has been identified in h2o, a high-performance web server with support for HTTP/2. A security vulnerability CVE-2023-44487 was discovered that could potentially . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3638-1
This update for libyajl fixes the following issues: CVE-2023-33460: Fixed memory leak which could cause out-of-memory in server (bsc#1212928).. # Security update for libyajl Announcement ID: SUSE-SU-2023:3301-1 Rating: moderate References: * #1212928 Cross-References: * CVE-2023-33460 CVSS scores: * CVE-2023-33460 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-33460 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for libyajl fixes the following issues: * CVE-2023-33460: Fixed memory leak which could cause out-of-memory in server (bsc#1212928). ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaSTonline_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-3301=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-3301=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3301=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3301=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3301=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3301=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3301=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3301=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3301=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3301=1 * SUSE Linux Enterprise Real Time 15 SP3 zypper in -t patch SUSE-SLE-Product-RT-15-SP3-2023-3301=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3301=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3301=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3301=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-3301=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3301=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3301=1 ## Package List: * openSUSE Leap Micro 5.3 (aarch64 x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) *libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * yajl-debuginfo-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * yajl-2.1.0-150000.4.6.1 * libyajl-devel-static-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.4 (x86_64) * libyajl-devel-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * yajl-debuginfo-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * yajl-2.1.0-150000.4.6.1 * libyajl-devel-static-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.5 (x86_64) * libyajl-devel-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Real Time 15 SP3 (x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Manager Proxy 4.2 (x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-33460.html * https://bugzilla.suse.com/show_bug.cgi?id=1212928 . An important update regarding libyajl details a significant memory leak flaw that impacts several openSUSE offerings.. libyajl Update, openSUSE Security Advisory, memory leak fixes. . LinuxSecurity.com Team
Update to version 4.18.5, Security fixes for CVE-2022-2127, CVE-2023-3347, CVE-2023-34966, CVE-2023-34967 and CVE-2023-34968. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-76c06c8576 2023-07-22 01:21:09.480892 -------------------------------------------------------------------------------- Name : samba Product : Fedora 38 Version : 4.18.5 Release : 0.fc38 URL : Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. --------------------------------------------------------------------------------Update Information: Update to version 4.18.5, Security fixes for CVE-2022-2127, CVE-2023-3347, CVE-2023-34966, CVE-2023-34967 and CVE-2023-34968 --------------------------------------------------------------------------------ChangeLog: * Thu Jul 20 2023 Guenther Deschner - 4.18.5-0 - resolves: #2224040 - Update to version 4.18.5 - resolves: #2222791, #2224254 - Security fix for CVE-2022-2127 - resolves: #2222792, #2224255 - Security fix for CVE-2023-3347 - resolves: #2222793, #2224253 - Security fix for CVE-2023-34966 - resolves: #2222794, #2224252 - Security fix for CVE-2023-34967 - resolves: #2222795, #2224250 - Security fix for CVE-2023-34968 --------------------------------------------------------------------------------References: [ 1 ] Bug #2222791 - CVE-2022-2127 samba: out-of-bounds read in winbind AUTH_CRAP https://bugzilla.redhat.com/show_bug.cgi?id=2222791 [ 2 ] Bug #2222792 - CVE-2023-3347 samba: SMB2 packet signing is not enforced when "server signing = required" is set https://bugzilla.redhat.com/show_bug.cgi?id=2222792 [ 3 ] Bug #2222793 - CVE-2023-34966 samba: infinite loop in mdssvc RPC service for spotlight https://bugzilla.redhat.com/show_bug.cgi?id=2222793 [ 4 ] Bug #2222794 - CVE-2023-34967 samba: typeconfusion in mdssvc RPC service for spotlight https://bugzilla.redhat.com/show_bug.cgi?id=2222794 [ 5 ] Bug #2222795 - CVE-2023-34968 samba: spotlight server-side share path disclosure https://bugzilla.redhat.com/show_bug.cgi?id=2222795 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-76c06c8576' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that solves four vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for java-1_8_0-ibm ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3152-1 Rating: important References: #1201684 #1201685 #1201692 #1201694 #1202427 Cross-References: CVE-2022-21540 CVE-2022-21541 CVE-2022-21549 CVE-2022-34169 CVSS scores: CVE-2022-21540 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-21540 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-21541 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-21541 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-21549 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-21549 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2022-34169 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2022-34169 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that solves four vulnerabilities and has one errata is now available. Description: This update for java-1_8_0-ibm fixes the following issues: Note: the issues listed below were NOT fixed with the previous update (8.0-7.11). - Update to Java 8.0 Service Refresh 7 Fix Pack 15 (bsc#1202427): - CVE-2022-34169: Fixed an integer truncation issue in the Xalan Java XSLT library that occurred when processing malicious stylesheets (bsc#1201684). - CVE-2022-21549: Fixed an issue that could lead to computing negative random exponentials (bsc#1201685). - CVE-2022-21541: Fixed a potential bypass of sandbox restrictions in the Hotspot component (bsc#1201692). - CVE-2022-21540: Fixed a potential bypass of sandbox restrictions in the Hotspot component (bsc#1201694).. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-3152=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-3152=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3152=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2022-3152=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3152=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2022-3152=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-3152=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-3152=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): java-1_8_0-ibm-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-alsa-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-plugin-1.8.0_sr7.15-30.96.1 - SUSE OpenStackCloud 9 (x86_64): java-1_8_0-ibm-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-alsa-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-plugin-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (ppc64le s390x x86_64): java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): java-1_8_0-ibm-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-plugin-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server 12-SP5 (ppc64le s390x x86_64): java-1_8_0-ibm-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server 12-SP5 (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-plugin-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (ppc64le s390x x86_64): java-1_8_0-ibm-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (x86_64): java-1_8_0-ibm-alsa-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-plugin-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): java-1_8_0-ibm-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-alsa-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-plugin-1.8.0_sr7.15-30.96.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): java-1_8_0-ibm-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-alsa-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-devel-1.8.0_sr7.15-30.96.1 java-1_8_0-ibm-plugin-1.8.0_sr7.15-30.96.1 References: https://www.suse.com/security/cve/CVE-2022-21540.html https://www.suse.com/security/cve/CVE-2022-21541.html https://www.suse.com/security/cve/CVE-2022-21549.html https://www.suse.com/security/cve/CVE-2022-34169.html https://bugzilla.suse.com/1201684 https://bugzilla.suse.com/1201685 https://bugzilla.suse.com/1201692 https://bugzilla.suse.com/1201694 https://bugzilla.suse.com/1202427 . SUSE Security Update for python-3_9: Resolves high-priority vulnerabilities to ensure system reliability. Check patch notes for specifics.. SUSE Security Update, java-1_8_0-ibm Patch, Java Security Issues, SUSE Sandbox Bypass. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.