SUSE-SU-2026:23983-1: important: Security update for sccache

SLE-SECURITY-UPDATES null at suse.de
Mon Oct 5 08:42:24 UTC 2026


# Security update for sccache

Announcement ID: SUSE-SU-2026:23983-1  
Release Date: 2026-09-30T17:58:26Z  
Rating: important  
References:

  * bsc#1243868
  * bsc#1257923
  * bsc#1270206
  * bsc#1270512
  * bsc#1270559
  * bsc#1270693
  * bsc#1270736
  * bsc#1270869
  * bsc#1270938
  * bsc#1270948
  * bsc#1273881
  * bsc#1273884
  * bsc#1273886
  * bsc#1273888
  * bsc#1274146
  * bsc#1282211

  
Cross-References:

  * CVE-2024-12224
  * CVE-2026-25541
  * CVE-2026-25727
  * CVE-2026-41676
  * CVE-2026-41677
  * CVE-2026-41678
  * CVE-2026-41681
  * CVE-2026-41898
  * CVE-2026-42327
  * CVE-2026-44662
  * CVE-2026-45784
  * CVE-2026-66746
  * CVE-2026-66754
  * CVE-2026-67181
  * CVE-2026-67182
  * CVE-2026-93599
  * CVE-2026-93600
  * CVE-2026-93601
  * CVE-2026-93602

  
CVSS scores:

  * CVE-2024-12224 ( SUSE ):  2.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2024-12224 ( SUSE ):  4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2024-12224 ( NVD ):  5.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-25541 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-25541 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-25541 ( NVD ):  5.5
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-25541 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-25727 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-25727 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-25727 ( NVD ):  6.8
    CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-25727 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2026-41676 ( SUSE ):  8.3
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-41676 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
  * CVE-2026-41676 ( NVD ):  7.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-41676 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-41677 ( SUSE ):  1.7
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
  * CVE-2026-41677 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-41677 ( NVD ):  1.7
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-41677 ( NVD ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  * CVE-2026-41678 ( SUSE ):  8.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-41678 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
  * CVE-2026-41678 ( NVD ):  7.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-41678 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-41681 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-41681 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-41681 ( NVD ):  8.1
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-41681 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-41898 ( SUSE ):  8.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-41898 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
  * CVE-2026-41898 ( NVD ):  8.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-41898 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-42327 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-42327 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-42327 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-44662 ( SUSE ):  5.1
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-44662 ( SUSE ):  4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-44662 ( NVD ):  5.1
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-45784 ( SUSE ):  5.1
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-45784 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-45784 ( NVD ):  5.1
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-45784 ( NVD ):  7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
  * CVE-2026-66746 ( SUSE ):  5.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-66746 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-66746 ( NVD ):  5.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-66746 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-66754 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-66754 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-66754 ( NVD ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-66754 ( NVD ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-67181 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
  * CVE-2026-67181 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
  * CVE-2026-67181 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-67181 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
  * CVE-2026-67182 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-67182 ( SUSE ):  4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-67182 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-67182 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L
  * CVE-2026-93599 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-93599 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93599 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-93599 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-93600 ( SUSE ):  2.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93600 ( SUSE ):  2.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-93600 ( NVD ):  2.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-93600 ( NVD ):  2.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-93601 ( SUSE ):  5.9
    CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93601 ( SUSE ):  4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93601 ( NVD ):  2.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-93601 ( NVD ):  2.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-93602 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-93602 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-93602 ( NVD ):  5.9
    CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-93602 ( NVD ):  4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0

  
  
An update that solves 19 vulnerabilities can now be installed.

## Description:

This update for sccache fixes the following issues:

  * CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any
    non-ASCII when decoded (bsc#1243868).
  * CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to
    undefined behavior and crashes (bsc#1274146).
  * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date
    parser can lead to stack exhaustion (bsc#1257923).
  * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can
    overflow short buffers on OpenSSL 1.1.1 (bsc#1270206).
  * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when
    returning an oversized length in rust- openssl crate (bsc#1270559).
  * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-
    openssl crate (bsc#1270693).
  * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer
    with no length check in rust-openssl crate (bsc#1270736).
  * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and
    cookie generate trampolines can leak adjacent memory in rust-openssl crate
    (bsc#1270869).
  * CVE-2026-42327: openssl: arbitrary code execution via specially crafted
    certificate in rust-openssl crate (bsc#1270512).
  * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-
    wrap-with-padding in rust-openssl crate (bsc#1270938).
  * CVE-2026-45784: openssl: out-of-bounds write in
    `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-
    openssl crate (bsc#1270948).
  * CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response
    Header Values (bsc#1273881).
  * CVE-2026-66754: rouille: remove_prefix function that allows remote
    unauthenticated attackers to crash the server by sending a crafted percent-
    encoded URL (bsc#1273884).
  * CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding
    Desynchronization (bsc#1273886).
  * CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access
    Control Bypass (bsc#1273888).
  * CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282211).
  * CVE-2026-93600: rustls-webpki: name constraints URI validation bypass
    (bsc#1282211).
  * CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282211).
  * CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282211).

Changes for sccache:

Update to version 0.18.0~2: * Add experimental concurrent cache support * chore:
Remove dependency status badge (#2856) * Don't hand the jobserver to children
that can't use it * dist: refuse to trim rlibs from crates that also emit a
cdylib * fix(cache): avoid duplicate multilevel reads * Strip basedirs from the
compiler arguments too * tests/integration: replace MinIO with Silo * ci: dump
sccache logs on integration failures * multilevel: a chain with any writable
level is writable * Fix parsing of #line directives * Release 0.18.0 *
daemonize: use an allow-list approach to inherited FDs * gcc, clang: make the
assembler part of the cache key * support cl.exe /openmp:llvm * support all
current /fsanitize _, /fsanitize-coverage_ , and /fno-sanitize* args * support
MSVC /feature argument * msvc: support lots of flags (#2832) * Update shlex
dependency to version 2 (#2836) * gcc: mark flags as TooHard if need to cache
something else (#2833) * clang: support more CLI options (#2834) * msvc: support
arm64EC and fastfail flags (#2830) * chore: fix typo in comment (#2829) * nvcc:
accept the --diag-error/--diag-suppress/--diag-warn family (#2816) * cache:
allow skipping capability checks (#2822) * Bump opendal to 0.58.1 and fix
fallout (fixes local GCS cache usage) (#2715) * nvcc (Windows): protect escaped
quotes in dryrun lines before flattening backslashes (#2811) * Add an agent
(#2812) * Add support for d20bforceinline. (#2807) * feat: add Microsoft Entra
ID (passwordless) auth for the Azure Blob backend (#2802) * Bump MSRV to 1.91.0
(#2793) * Fix `nvcc` dryrun parsing for CUDA 13.3 (#2722) * test: Fixed
hardcoded binary path in test * Release 0.17.0 * tests: pin libc in the dist
test crate * doc: clarify server-side outputs and drop 'recommended mode' claim
* doc: document SCCACHE_CLIENT_SIDE env var * doc: document client-side and
direct modes in Architecture.md * Fix description of Unix socket-based Redis
connection * server: remove redundant async block in start_compile_task *
server: simplify bind() request loops with ? instead of manual match arms * Add
support for arg files in Rust (#2782) * feat: support S3 SSE-KMS with AWS-
managed and customer-managed keys (#2770) * abort compile tasks and associated
subprocesses when a client disconnects * treat -ivfsoverlay as a preprocessor-
only argument * gcc: refine response-file tokenizer visibility and whitespace
handling * integration: convert cmake 4.x modules XFAIL test to a passing test *
gcc/clang: cache and distribute builds using quoted @response files * fix: Fix
ToolchainPackager cfg gate to build on ppc64le/s390x * fix: make gcc diagnostics
color output work the same as for rustc * implement client-side mode * split
handle_compile_response so that the compilation result can be handled separately
* implement IpcStorage -- Storage backend over IPC * extend wire protocol with
storage RPCs * implement AddAssign for ServerStats and related types * add
Storage::get_path for direct file access * implement get_raw/put_raw on
MultiLevelStorage * add client_side_mode config flag (SCCACHE_CLIENT_SIDE) *
Extract new_client_runtime() helper to DRY up client runtime creation * Clarify
single-threaded runtime rationale comment (grammar) * fix: use single-threaded
tokio runtime in sccache dist-client * fix: use single-threaded tokio runtime in
sccache client * fix: handle disabled cache backend features in multilevel chain
* Fix ldd output parsing: remove .exists() check that failed on systems where
the symlink source path does not exist locally (e.g. aarch64) * Fix cfg guard
for PanicToolchainPackager to also cover non-x86_64 Linux architectures (e.g.
aarch64) * Release 0.16.0 * fix: strip SCCACHE_BASEDIRS from escaped-backslash
paths on Windows (#2736) * Ignore empty-set environment values (#2639) * feat:
all backends support making them as read-only (#2705) * Enable RE on Linux-
aarch64 (#2668) * Slightly improve logging (#2734) * chore: encode jwt key and
cert digest with base64 in logs (#2712) * chore: make clippy happy (#2727) *
feat: avoid sccache wrapper when resolving compiler (#2720) * Fall back to
direct cache write if tempfile creation on the same fs fails (#2369) * remove
too noisy bench * feat(nvcc): support argument: `--dependency-output` (#2708) *
fix: add newline when printing dist-status to stdout * Revert "Classify .s files
as AssemblerToPreprocess so #include/#ifdef are hon..." * Don't wait depfiles
for gcc/clang preprocessed inputs * Classify .s files as AssemblerToPreprocess
so #include/#ifdef are honored * prepare release 0.15.0 * Add cargo-binstall
metadata for prebuilt binary installation * Fix coverage * fix: handle
directories in dep-info source file hashing * docs(Rust.md): Add caveats from
README * Add retry for dists docker image build * ci: set crt-static for riscv64
musl targets * feat: Add loongarch64 support * feat: Implement multi-tier
caching with fallback and backfilling (#2581) * msvc: add support for Y-, YI, Zf
flags * Group tests logging in CI * Add failing test for cmake-modules + cmake 4
version * Unfold ninja output in the test * Add a comment for maintaining
integration tests * Move cmake-modules to integration tests * fix: exclude
CARGO_ENCODED_RUSTFLAGS from env var hash (#2651) * chore(deps): update rust
crate quinn-proto to v0.11.14 * Fix sync GCS initialization * clippy: fix
from_iter_instead_of_collect lint * fix: add Win32_Security feature to windows-
sys dependency * build(deps): bump actions/download-artifact from 5 to 8 * msvc:
Append the default .pdb extension for the /Fd argument (#2621) * build(deps):
bump actions/upload-artifact from 4 to 7 * clippy: fix ref_option lint * ci:
install grcov from prebuilt binary instead of cargo install * ci: use default
toolchain to install grcov * ci: fix artifact_failure action when target dir
does not exist * Remove benchmark normalize_win_path_utf8 (#2634) * Revert
"actions: add security audit workflow (#2594)" (#2603) * partial c++20 module
support (#2516) * clippy: fix ptr_as_ptr lint (#2611) * Add support for
`d1nodatetime` & `await:strict` MSVC flags (#2617) * chore: switch
thirtyfour_sync to thirtyfour (#2613) * clippy: fix manual_string_new lint
(#2609) * clippy: fix unnecessary_semicolon lint (#2615) * clippy: fix
explicit_into_iter_loop lint (#2616) * Avoid double-caching when ccache is
installed in PATH (#2524) * clippy: fix cloned_instead_of_copied lint (#2605) *
clippy: fix semicolon_if_nothing_returned lint (#2601) * Move
PreprocessorCacheModeConfig to src/config.rs (#2604) * clippy: fix
cloned_ref_to_slice_refs lint (#2602) * prepare the new release (#2600) * chore:
update to toml 0.9 (#2599) * ci: Add coverage to integration tests, report it to
Codecov.io (#2598) * Preparation for multilevel caching (#2597) * Add sccache-
dist to flake.nix (#2579) * fixup! cargo fmt * fixup! rustfmt update * Extract
FileObjectSource, CacheRead and CacheWrite to cache_io.rs * chore: update to nix
0.30 * Add a helper method to get a correct backend name * Add cos feature gate
to RemoteStorage * Simplify profiles for integration tests * clippy: fix
implicit_clone lint (#2584) * actions: add security audit workflow (#2594) *
docs: fix examples showing an xz-compress toolchain archive (#2587) * add
benches for normalize_win_path strip_basedirs (#2588) * snap: update to core24
(#2570) * Add .rustfmt.toml for consistent style between `rustfmt` and `cargo
fmt` (#2582) * add comments about auth token requirements (#2583) * chore:
update to tokio-serde 0.9 (#2585) * ci: update freebsd to 15.0 (#2586) *
distributed compilation support for asm & preprocessor outputs (#2557) * remove
unused declaration (#2577) * Extract LazyDiskCache to a separated file (#2573) *
Revert "ci: show diff for toml_format" (#2578) * Open Add SCCACHE_BASEDIRS
support * ci: show diff for toml_format * chore: update to syslog 7 * refactor:
use matrix to reduce deduplication * fix: remove outdated `analysis` mode *
Unbreak the s390x CI * ci: add macos-15-intel for prebuilt binary (#2555) *
Integration tests (#2564) * Fix code review. * Impl for COS. * build(deps): bump
opendal from 0.54.0 to 0.55.0 * Move integration tests related stuff to subdir *
Add Objective C Header for consistency * github action: fix the syntax - fails
in the ci * sccache: prepare a new release * msvc: add msbuild support test *
msvc: fix detect_showincludes_prefix with MSBuild * chore: update to gzp 2 *
build(deps): bump rsa from 0.9.6 to 0.9.10 * codspeed: evaluate the memory
benchmarking * remove too quick benchmarks * codspeed: move to simulation mode *
Add realistic LRU cache access pattern benchmarks * Add compression
characteristics benchmarks * Add build workflow simulation benchmarks * Add hash
computation scenario benchmarks * Add batch cache entry benchmarks * Add cache
artifact serialization benchmarks * Add /etc/ld.so.conf.d (if present) to
compiler package * Assembly language support * fix(ci): pin serde_json to avoid
zmij dependency * fix(ci): update zmij to fix s390x cross-compilation * Fix the
run of the CI * run the benchmark in the ci * add benchmarks * dedup some code *
Fix hash logging prefix * Add support for C preprocessor output * Add GCC pipe
flag support * Improve save-temps gcc flags detection * MSVC: support forward
slash as an output dir marker * add clang -fplugin=x regression test *
canbeconcatenated is not accounted for in cmp * Reversed the order for looking
`rustc`, added comment * Fix failing test_rlib_dep_reader_call for omit
CARGO_HOME * fix: don't hash -parallel-jobs in Clang * docs: add installation
steps for nix (#2523) * Support clang -fexperimental-assignment-tracking option
(#2517) * add a nix flake (#2518) * Switch from the unmaintained daemonize crate
to a maintained fork * chore: update to fs-err 3 * Fix grammar of error message
* Add server name info to stderr of remote jobs that ran, but failed * Remove
another pointless destructuring * try to unbreak the ci * fix s390x build error
* Add riscv64 support * fix: make aarch64-pc-windows-msvc also zip not tar.gz *
Free up disk space in CI * MSVC on Windows only * Avoid 'No space left on
device' errors in CI * GitHub dropped macos-13 runners * Proper function pointer
to int cast * Avoid unused structs with dist-server disabled * no check cfg
(#2507) * chore: switch once_cell crate to standard library (#2499) * Avoid
unreliable assert_cmd::cargo::cargo_bin (#2489) * Fix build on macOS which
doesn't have separate 32-bit dirent (#2492) * Fix Clippy warnings (#2490) *
docs: bump MSRV to 1.85.0 * msvc: handle '/FoRelease\' command-line argument *
chore: drop tower dependency * chore: update to itertools 0.14 * Use generator
in CMAKE_MSVC_DEBUG_INFORMATION_FORMAT in README * Update directories to 6.0 *
Configuration.md - note logging env variables * chore: update to env_logger 0.11
* deps: update blake3 * prepare version 0.12.0 * Update README with winget
installation instructions * Skip CARGO_BUILD_JOBS in hash keys * build(deps):
bump object from 0.36.7 to 0.37.1 * Adjust tests after the rust update * Fix CI
by adding cargo-features and updating coverage test to use modern -Cinstrument-
coverage * Fix more clippy warnings * bump rustc in the ci too * Fix rustc 1.85
clippy warnings * bump to rustc 1.85 / edition 2024. mandatory for reqsign-core
and run rustfmt with the version * fix clippy warnings * bump opendal to 0.54.0
& reqsign to 0.18.0 * github action: when creating a release, make it as draft
before (#2458) * prepare version 0.11.0 (#2457) * document SCCACHE_LOG_MILLIS
(#2456) * logging: add a option to log milliseconds (Closes: #2454) (#2455) *
feat: handle human size prefixes (#2405) * fix: in stats, Compare values AND
keys to have a fully deterministic order (#2403) * Add --diagnostic-width to
test for args ignored in hash * Ignore --diagnostic-width argument when
computing hash * build(deps): bump actions/checkout from 4 to 5 * build(deps):
bump actions/download-artifact from 4 to 5 * build(deps): bump actions/github-
script from 7 to 8 * Fix rustfmt * Fix comments on request * Fix clippy and
rustfmt * Add test for count toolchain and use Determenistic for create tar
archive * Fix mtime for reproducable toolchains * build(deps): bump chrono from
0.4.41 to 0.4.42 * fix typo in an environment variable name * Fix documentation
of azure configuration * Account for clippy-driver having extra prefix `rustc` *
Fix build on Android (in Termux) * add support for s390x build * chore: replace
retry crate with backon * Remove or replace "Windows 2019" CI config * Needs
another result unwrapping, it seems * Test: invoking symlink "compiler" to
"sccache" invokes "compiler" * Add a comment about the problem with symlinks and
current_exe() * Fix symbolic links to sccache on linux * Allow the CI
configuration to disable clang++ for CUDA testing * Don't run tests using
clang++ as CUDA compiler on Windows * add description to sccache-dist commands *
Display a more user-friendly error when compiling on Linux/arm64 * Clarify
documentation about "the hash" (aka cache key) * Remove stray ')' * Remove
documentation for removed limitations of preprocessor cache mode * Fix
preprocessor cache mode when the compiler outputs a dep file * Partially revert
"Don't cache dep file (#2322)" * Do not disable preprocessor cache mode if there
is a dep file * Fix preprocessor cache mode with distributed builds (#2173) *
Change self of generate_hash_key() from Box<Self> to &mut Self * Remove a few
IMO pointless indirections / aliases * Remove workaround for #2173 * Add test
for bug #2173 * chore: fix some minor issues in comments * build(deps): bump
chrono from 0.4.40 to 0.4.41 * build(deps): bump memchr from 2.7.1 to 2.7.5 *
check if we can use a specific version of rust to build grcov * Move comment
that hadn't moved with its corresponding code * Rework direct mode documentation
some more * Explain what preprocessor cache mode really does * Reword and
correct the preprocessor cache mode documentation * chore: Remove not working
mozilla code * Add support for -fsanitize-ignorelist * github storage: adjust
the doc * github storage: ACTIONS_CACHE_URL => ACTIONS_RESULTS_URL * github
storage: force version 2 * Update codecov badge in README.md * Expand tests for
dist-server * ci: Consolidate testing, coverage * ci: Update ubuntu-20.04
runners to ubuntu-22.04 * chore: fix some comments * Give the --dist-status user
some information about when a retry will happen. * Add support for Xclang flag
'-mrelax-all' * Add support for Xclang flag '-mconstructor-aliases' *
feat(utils): Add support for object >= 0.33 * fix(tests): Remove executable bit
from oauth.rs * build(deps): bump openssl from 0.10.64 to 0.10.72 * build(deps):
bump tokio from 1.41.0 to 1.43.1 * Improve the CARGO_INCREMENTAL checking
(#2364) * build(deps): bump chrono from 0.4.38 to 0.4.40 * build(deps): bump
clap from 4.4.18 to 4.5.13 * build(deps): bump ring from 0.17.7 to 0.17.13 *
Bail on `nvcc -time` and `nvcc -fdevice-time-trace` flags * test hip with
librandomize_readdir * Add randomize_readdir test utility * fix non-strict HIP
device lib order * Create config during testing to collect coverage data *
Extend coverage to distributed tests * chore: replace num_cpus crate with
available_parallelism in standard library (#2342) * Update CI coverage:
grcov/codecov

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP applications 16.0  
    zypper in -t patch SUSE-SLES-16.0-1793

  * SUSE Linux Enterprise Server 16.0  
    zypper in -t patch SUSE-SLES-16.0-1793

## Package List:

  * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
    * sccache-debugsource-0.18.0~2-160000.1.1
    * sccache-debuginfo-0.18.0~2-160000.1.1
    * sccache-0.18.0~2-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
    * sccache-debugsource-0.18.0~2-160000.1.1
    * sccache-debuginfo-0.18.0~2-160000.1.1
    * sccache-0.18.0~2-160000.1.1

## References:

  * https://www.suse.com/security/cve/CVE-2024-12224.html
  * https://www.suse.com/security/cve/CVE-2026-25541.html
  * https://www.suse.com/security/cve/CVE-2026-25727.html
  * https://www.suse.com/security/cve/CVE-2026-41676.html
  * https://www.suse.com/security/cve/CVE-2026-41677.html
  * https://www.suse.com/security/cve/CVE-2026-41678.html
  * https://www.suse.com/security/cve/CVE-2026-41681.html
  * https://www.suse.com/security/cve/CVE-2026-41898.html
  * https://www.suse.com/security/cve/CVE-2026-42327.html
  * https://www.suse.com/security/cve/CVE-2026-44662.html
  * https://www.suse.com/security/cve/CVE-2026-45784.html
  * https://www.suse.com/security/cve/CVE-2026-66746.html
  * https://www.suse.com/security/cve/CVE-2026-66754.html
  * https://www.suse.com/security/cve/CVE-2026-67181.html
  * https://www.suse.com/security/cve/CVE-2026-67182.html
  * https://www.suse.com/security/cve/CVE-2026-93599.html
  * https://www.suse.com/security/cve/CVE-2026-93600.html
  * https://www.suse.com/security/cve/CVE-2026-93601.html
  * https://www.suse.com/security/cve/CVE-2026-93602.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1243868
  * https://bugzilla.suse.com/show_bug.cgi?id=1257923
  * https://bugzilla.suse.com/show_bug.cgi?id=1270206
  * https://bugzilla.suse.com/show_bug.cgi?id=1270512
  * https://bugzilla.suse.com/show_bug.cgi?id=1270559
  * https://bugzilla.suse.com/show_bug.cgi?id=1270693
  * https://bugzilla.suse.com/show_bug.cgi?id=1270736
  * https://bugzilla.suse.com/show_bug.cgi?id=1270869
  * https://bugzilla.suse.com/show_bug.cgi?id=1270938
  * https://bugzilla.suse.com/show_bug.cgi?id=1270948
  * https://bugzilla.suse.com/show_bug.cgi?id=1273881
  * https://bugzilla.suse.com/show_bug.cgi?id=1273884
  * https://bugzilla.suse.com/show_bug.cgi?id=1273886
  * https://bugzilla.suse.com/show_bug.cgi?id=1273888
  * https://bugzilla.suse.com/show_bug.cgi?id=1274146
  * https://bugzilla.suse.com/show_bug.cgi?id=1282211

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20261005/efd79043/attachment.htm>


More information about the sle-security-updates mailing list