SUSE-SU-2026:4571-1: important: Maintenance update for Multi-Linux Manager 5.2: Server, Proxy and Retail Branch Server

SLE-SECURITY-UPDATES null at suse.de
Thu Oct 8 12:34:29 UTC 2026


# Maintenance update for Multi-Linux Manager 5.2: Server, Proxy and Retail
Branch Server

Announcement ID: SUSE-SU-2026:4571-1  
Release Date: 2026-10-08T08:02:36Z  
Rating: important  
References:

  * bsc#1208800
  * bsc#1230568
  * bsc#1230949
  * bsc#1252286
  * bsc#1257151
  * bsc#1258382
  * bsc#1258500
  * bsc#1258567
  * bsc#1259225
  * bsc#1260342
  * bsc#1262157
  * bsc#1263822
  * bsc#1265219
  * bsc#1265472
  * bsc#1266481
  * bsc#1267261
  * bsc#1267871
  * bsc#1267912
  * bsc#1268228
  * bsc#1268325
  * bsc#1268473
  * bsc#1268587
  * bsc#1268673
  * bsc#1268755
  * bsc#1269192
  * bsc#1269253
  * bsc#1269316
  * bsc#1269534
  * bsc#1269679
  * bsc#1270033
  * bsc#1270039
  * bsc#1270040
  * bsc#1270047
  * bsc#1270141
  * bsc#1270694
  * bsc#1271075
  * bsc#1271116
  * bsc#1271124
  * bsc#1271329
  * bsc#1271332
  * bsc#1271382
  * bsc#1271467
  * bsc#1271523
  * bsc#1271678
  * bsc#1271681
  * bsc#1271841
  * bsc#1271902
  * bsc#1271963
  * bsc#1272298
  * bsc#1272392
  * bsc#1272404
  * bsc#1272538
  * bsc#1272621
  * bsc#1272988
  * bsc#1273073
  * bsc#1273131
  * bsc#1273144
  * bsc#1273846
  * bsc#1273853
  * bsc#1274023
  * bsc#1274227
  * bsc#1274613
  * bsc#1274720
  * bsc#1274775
  * jsc#MSQA-1060

  
Cross-References:

  * CVE-2026-39821
  * CVE-2026-63007
  * CVE-2026-63009
  * CVE-2026-71400

  
CVSS scores:

  * CVE-2026-39821 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-39821 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-39821 ( NVD ):  9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  * CVE-2026-39821 ( NVD ):  8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
  * CVE-2026-71400 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-71400 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

  
Affected Products:

  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE
  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE
  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE

  
  
An update that solves four vulnerabilities, contains one feature and has 60
security fixes can now be installed.

## Security update 5.2.1 for Multi-Linux Manager Proxy

### Description:

This update fixes the following issues:

Release notese highlights:

  * Added a note about the SUSE Registry IP address change.
  * Update to SUSE Multi-Linux Manager 5.2.1
  * Security issues Fixed: CVE-2026-39821
  * Bugs mentioned bsc#1208800, bsc#1230568, bsc#1230949, bsc#1258382,
    bsc#1266481 bsc#1268755, bsc#1270033, bsc#1273131, bsc#1273144, bsc#1273846
    bsc#1274613, bsc#1274775

Container images and uyuni-tools changes:

proxy-httpd-image:

  * Version 5.2.10
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-salt-broker-image:

  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-squid-image:

  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-ssh-image:

  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-tftpd-image:

  * Version 5.2.10
  * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800)
  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

uyuni-tools:

  * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)
  * Version 5.2.17-0
  * Bump the default image tag to 5.2.1
  * Reload systemd daemon before restarting services (bsc#1270033)
  * Check all supported locations for CA file in rotation check script
  * Detect and fix legacy service file (bsc#1268755)
  * Use healthcheck cmd from the image (bsc#1273144)

The following packages are underlying build dependencies and system components
used by the containers:

spacewalk-backend:

  * Version 5.2.10-0
  * Allow diskcheck env vars into containers (bsc#1270033)
  * Use sha256 as the default checksum type for Debian repositories
  * Remove token based authentication mechanism for package_push (bsc#1230949)
  * Fix gpgverify signature file check for file object (bsc#1273131)
  * Allow using spacewalk-diskcheck without running service
  * Increase errata advisory char limit to 150 (bsc#1273846)
  * Use cryptographically secure random generation for secrets (bsc#1230568)

spacewalk-proxy:

  * CVE-2026-71400: Remove cobbler_api endpoint from public interface
    (bsc#1274613, bsc#1274775) - fixed in 5.2.6-0
  * Version 5.2.5-0
  * Remove salt dependency from spacewalk-proxy-salt package

How to apply this update:

  1. Log in as root user to the SUSE Multi-Linux Manager Proxy.
  2. Upgrade mgrpxy.
  3. If you are in a disconnected environment, upgrade the image packages.
  4. Reboot the system.
  5. Run `mgrpxy upgrade podman` which will use the default image tags.

## Security update 5.2.1 for Multi-Linux Manager Retail Branch Server

### Description:

This update fixes the following issues:

Release notese highlights:

  * Added a note about the SUSE Registry IP address change.
  * Update to SUSE Multi-Linux Manager 5.2.1
  * Security issues Fixed: CVE-2026-39821
  * Bugs mentioned bsc#1208800, bsc#1230568, bsc#1230949, bsc#1258382,
    bsc#1266481 bsc#1268755, bsc#1270033, bsc#1273131, bsc#1273144, bsc#1273846
    bsc#1274613, bsc#1274775

Container images and uyuni-tools changes:

proxy-httpd-image:

  * Version 5.2.10
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-salt-broker-image:

  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-squid-image:

  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-ssh-image:

  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

proxy-tftpd-image:

  * Version 5.2.10
  * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800)
  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

uyuni-tools:

  * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)
  * Version 5.2.17-0
  * Bump the default image tag to 5.2.1
  * Reload systemd daemon before restarting services (bsc#1270033)
  * Check all supported locations for CA file in rotation check script
  * Detect and fix legacy service file (bsc#1268755)
  * Use healthcheck cmd from the image (bsc#1273144)

The following packages are underlying build dependencies and system components
used by the containers:

spacewalk-backend:

  * Version 5.2.10-0
  * Allow diskcheck env vars into containers (bsc#1270033)
  * Use sha256 as the default checksum type for Debian repositories
  * Remove token based authentication mechanism for package_push (bsc#1230949)
  * Fix gpgverify signature file check for file object (bsc#1273131)
  * Allow using spacewalk-diskcheck without running service
  * Increase errata advisory char limit to 150 (bsc#1273846)
  * Use cryptographically secure random generation for secrets (bsc#1230568)

spacewalk-proxy:

  * CVE-2026-71400: Remove cobbler_api endpoint from public interface
    (bsc#1274613, bsc#1274775) - fixed in 5.2.6-0
  * Version 5.2.5-0
  * Remove salt dependency from spacewalk-proxy-salt package

How to apply this update:

  1. Log in as root user to the SUSE Multi-Linux Manager Retail Branch Server.
  2. Upgrade mgrpxy.
  3. If you are in a disconnected environment, upgrade the image packages.
  4. Reboot the system.
  5. Run `mgrpxy upgrade podman` which will use the default image tags.

## Security update 5.2.1 for Multi-Linux Manager Server

### Description:

This update fixes the following issues:

Release Notes Highlights:

  * Added a note about the SUSE Registry IP address change.
  * Update to SUSE Multi-Linux Manager 5.2.1
  * Security fixes
  * Ubuntu 26.04 LTS Support
  * Confidential Computing Attestation for IBM Z Series
  * New uyuni-tftpd Container
  * Monitoring: Prometheus upgraded to 3.13.2
  * Monitoring: Grafana upgraded to 12.4.10
  * CVEs Fixed: CVE-2023-45289, CVE-2024-22195, CVE-2025-12141, CVE-2025-13836
    CVE-2025-61686, CVE-2026-15308, CVE-2026-21723, CVE-2026-40181
    CVE-2026-11940, CVE-2026-11972, CVE-2026-13346, CVE-2026-14199
    CVE-2026-17033, CVE-2026-17183, CVE-2026-19197, CVE-2026-19475
    CVE-2026-27459, CVE-2026-33814, CVE-2026-39821, CVE-2026-39882
    CVE-2026-40475, CVE-2026-41066, CVE-2026-41178, CVE-2026-41606
    CVE-2026-42211, CVE-2026-42342, CVE-2026-44431, CVE-2026-44990
    CVE-2026-49825, CVE-2026-49853, CVE-2026-49854, CVE-2026-49855
    CVE-2026-56852, CVE-2026-63007, CVE-2026-63009, CVE-2026-71400
    CVE-2026-42127, CVE-2026-45409, CVE-2026-53606, CVE-2026-73501
    CVE-2025-4673, CVE-2026-0864, CVE-2026-1229, CVE-2026-1502 CVE-2026-1703,
    CVE-2026-2303, CVE-2026-3219, CVE-2026-3276

Container images and uyuni-tools changes:

proxy-tftpd-image:

  * Updated to version 5.2.10
  * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800)
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

server-attestation-image:

  * Version 5.2.11
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

server-database-migration-image:

  * Version 5.2.6
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

server-hub-xmlrpc-api-image:

  * Version 5.2.9
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

server-image:

  * Version 5.2.15
  * Increase start-period (bsc#1271124)
  * Check disk space on startup
  * Use correct healthcheck cmd (bsc#1273144)
  * Detect an existing cgroup2 mount by filesystem type, not mountpoint.

server-postgresql-image:

  * Version 5.2.13
  * Automatically set the log timezone for TZ env (bsc#1267871)
  * Increase start-period and timeout (bsc#1271124)
  * Check disk space on startup

server-saline-image:

  * Version 5.2.11
  * Image rebuilt to the newest version with updated dependencies for SUSE
    Multi-Linux Manager 5.2.1

uyuni-tools:

  * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)
  * Version 5.2.17-0
  * Bump the default image tag to 5.2.1
  * Reload systemd daemon before restarting services (bsc#1270033)
  * Check all supported locations for CA file in rotation check script
  * Detect and fix legacy service file (bsc#1268755)
  * Use healthcheck cmd from the image (bsc#1273144)

The following packages are underlying build dependencies and system components
used by the containers:

apache-commons-fileupload2:

  * Updated to version 2.0.0-M5
  * Add AbstractFileUpload support for a maximum part header size
  * FILEUPLOAD-367: Jakarta and Javax ServletFileUpload
    .isMultipartContent(HttpServletRequest) should allow PUT and PATCH request
    methods in addition to POST
  * FILEUPLOAD-367: Add AbstractFileUpload .isMultipartRequestMethod(String)
  * FILEUPLOAD-295: Clarified the precise meaning of isInMemory(), get(),
    getPath(), etc. in DiskFileItem
  * Better exception type and message if a multipart/mixed part is presented
    without a boundary defined
  * Bump org.apache.commons:commons-parent from 84 to 96
  * Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0
  * Bump commons-io:commons-io from 2.19.0 to 2.21.0

byte-buddy:

  * Updated to version 1.18.8
  * Introduce new versioning concept with -jdk5 suffix for backwards-compatible
    jar and Java 8 baseline for regular jar
  * Eagerly resolve of canonical files during attach emulation to avoid failure
    when process ends before file can be deleted
  * Add super classes to hash code / equals computation in Advice that were
    missing
  * Add support for new build description in Android 9

mgr-push:

  * Version 5.2.5-0
  * Remove token based authentication mechanism for package_push (bsc#1230949)

objectweb-asm:

  * Updated to version 9.10.1
  * New Opcodes.V27 constant for Java 27

python-susemanager-retail:

  * Version 1.2.1
  * Fix issue building package on SLES 16.0

salt:

  * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
  * Support attrlist in ldap.managed (bsc#1257151)
  * Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
  * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)

spacecmd:

  * Version 5.2.10-0
  * Pre-filter errata in system_applyerrata to avoid using API calls for all
    existing errata (bsc#1267261)

spacewalk-backend:

  * Version 5.2.10-0
  * Allow diskcheck env vars into containers (bsc#1270033)
  * Use sha256 as the default checksum type for Debian repositories
  * Remove token based authentication mechanism for package_push (bsc#1230949)
  * Fix gpgverify signature file check for file object (bsc#1273131)
  * Allow using spacewalk-diskcheck without running service
  * Increase errata advisory char limit to 150 (bsc#1273846)
  * Use cryptographically secure random generation for secrets (bsc#1230568)

spacewalk-branding:

  * Version 5.2.7-0
  * No customer facing changes

spacewalk-client-tools:

  * Version 5.2.7-0
  * Update translation strings

spacewalk-config:

  * Version 5.2.5-0
  * CVE-2026-71400: Remove cobbler_api endpoint from public interface
    (bsc#1274613, bsc#1274775)

spacewalk-java:

  * CVE-2026-71400: Remove cobbler_api endpoint from public interface
    (bsc#1274613, bsc#1274775) - fixed in 5.2.21-0
  * CVE-2026-63007: Check access rights on two formula API calls (bsc#1269253) -
    fixed in 5.2.20-0
  * CVE-2026-63009: Sanitize uploaded image name (bsc#1269534) - fixed in
    5.2.20-0
  * Updated to version 5.2.22-0
  * Restored the original reset behavior in isDryRun() by swapping
    subscribedChannels and unsubscribedChannels back (bsc#1271681)
  * Fix mainframe foreign systems showing wrong OS (bsc#1260342)
  * Make setting of column filters in ListTag idempotent (bsc#1269192)
  * Fix hubsync package download checksum lookup (bsc#1270040)
  * Many to many relationships should not cascade deletion (bsc#1272392)
  * Optimized channel model generation logic to improve page load performance
    during peripheral channel selection (bsc#1259225)
  * Fixed Hibernate issue when updating the SSL content sources during a pay-as-
    you-go connection data refresh (bsc#1271382)
  * Allow diskcheck env vars into containers (bsc#1270033)
  * Query only systems for virtual machines which are flagged as virtualization
    hosts (bsc#1273073)
  * Use Channel equality even for ClonedChannel (bsc#1272621)
  * Fix EOL notifications in containers
  * Fix config channel position gaps (bsc#1272988)
  * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039)
  * Prevent cascading package operations to checksums (bsc#1272392)
  * Fixed custom RBAC role names being incorrectly localized. (bsc#1271116)
  * Do not add FQDNs from proxy certificate (bsc#1270141, bsc#1272404)
  * Do not crash on conflicting FQDNs, add error message
  * Add delay to package clean to not interfere with repo-sync (bsc#1258500)
  * Improve handling of invalid issue_date values when creating CLM filters via
    the API. (bsc#1271467)
  * Wait for taskomatic before processing events (bsc#1265472)
  * Use the standard Bootstrap 5 row class in place of legacy layout classes.
  * Remove udevdb salt module leftovers, udev is used now
  * Fix Hibernate session crash on Errata Sync by dynamically loading default
    access groups from the active session (bsc#1272298)
  * Fix Profile tab display in system details menu (bsc#1271963)

spacewalk-search:

  * Version 5.2.6-0
  * No customer facing changes

spacewalk-utils:

  * Version 5.2.8-0
  * Taskotop now handles timezone (bsc#1267871)

spacewalk-web:

  * Version 5.2.14-0
  * Improve product selection checkboxes in the setup UI
  * Show partial selection state for product trees more accurately
  * Fixed the "Clear selected system set" button flickering during page
    navigation. (bsc#1271523)
  * Add web.version.eol setting to provide an end of life date
  * Fix duplicate remaining characters label in the Create Custom Info Key
    description field. (bsc#1269679)
  * Improve handling of invalid issue_date values when creating CLM filters via
    the API. (bsc#1271467)
  * Refactor checkboxes in the RBAC UI
  * Reuse common Check component
  * Use the standard Bootstrap 5 row class in place of legacy layout classes.

struts:

  * Fix JakartaServletFileUpload as setFileSizeMax was renamed to setMaxFileSize
  * Use explicite same java version as spacewalk-java to get around "class file
    has wrong version" errors

subscription-matcher:

  * Updated to version 0.47
  * Added missing part numbers (bsc#1274227, bsc#1265219)
  * Fix unsupported part number (bsc#1271075)

supportutils-plugin-susemanager:

  * Version 5.2.3-0
  * Allow 100 connection difference for apache and tomcat
  * Fix reading connections from the correct source
  * Add reportdb connections to the database connection limit (bsc#1262157)

susemanager:

  * Version 5.2.10-0
  * Add Ubuntu 26.04 LTS

susemanager-build-keys:

  * Update SUSE addon key - extended validity

susemanager-docs_en:

  * Documented requirements and limitations for container image inspection on
    SLES 15 and SLES 16 (bsc#1274720)
  * Documented proxy certificate replacement using spacecmd (bsc#1271329)
  * Documented certificate setup and rotation with unified mgradm ssl rotate
    command
  * Documented allowing diskcheck environment variables into containers
    (bsc#1270033)
  * Clarified availability of Salt's "virt" module in the Salt Bundle
    (bsc#1270694)
  * Added instruction for obtaining the certificate when renaming the server
    (bsc#1273853)
  * Added a common workflow for certificate setup and rotation with ACME
  * Documented how VMs are listed and referenced by virtual hosts (bsc#1273073)
  * Added documentation support for Ubuntu 26.04 client systems
  * Added the missing TFTP image in airgap install command
  * Fixed procedures for OpenSCAP in Administration Guide (bsc#1270047)
  * Fixed the snippet to reflect the correct produst version (bsc#1272538)
  * Corrected verification step order in MLM 5.0 to 5.2 upgrade guide for SL-
    Micro (bsc#1271678)
  * Extended configuration instructions for Saline formula in Specialized Guides
    (bsc#1268587)
  * Enhanced instructions for Liberate formula and reactivation key in
    Specialized Guides (bsc#1268473)
  * Fixed missing line end escapes in kubernetes helm install commands
  * Consolidated multiple duplicated activation key creation procedures into a
    single reusable partial snippet
  * Fixed Traefik installation documentation in Specialized Guides
  * Clarified CA certificate migration requirements (bsc#1271841)
  * Added instructions for enabling reporting dashboards in Specialized Guides
    (bsc#1268228)
  * Remove legacy mgradm and mgrpxy commands
  * Added the --set tag parameter to helm install/upgrade commands as a
    workaround (bsc#1271902)
  * Documented apache2 parameter used for large deployments (bsc#1268673)
  * Documented Grafana reporting database automated setup and Hub Overview in
    Administration and Specialized Guides
  * Update the OpenSCAP packages table in the System Security with OpenSCAP
    article in the Administration guide (bsc#1269316)
  * Added documentation for migrating legacy ISS v1 and ISS v2 peripheral
    servers to ISS v3 (Hub Online Synchronization) and detailed Report DB/XMLRPC
    API dependencies in Specialized Guides
  * Documented SLES 15 SP7 to SLES 16.0 major upgrade via product migration in
    Client Configuration Guide

susemanager-schema:

  * Version 5.2.14-0
  * Updated tables for CoCo attestation restructuring
  * Use temp table for hidden packages (bsc#1267912)
  * Renumber config channel positions to close gaps left by deleting an assigned
    config channel (ON DELETE CASCADE did not compact the survivors), preventing
    multiple failures (bsc#1272988)
  * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039)
  * Increase advisory char limit to 150 in rhnErrata (bsc#1273846)
  * RBAC: add missing endpoints to 'systems.profiles' namespace (bsc#1271963)

susemanager-sls:

  * Version 5.2.15-0
  * Propagate cert validation errors to UI (bsc#1271332)
  * Fix cleanup timeout when deleting minions (bsc#1258567)
  * Fix salt deletion on SSH minions (bsc#1274023)
  * Set podman secrets for proxy directly from salt
  * Fix migration of jmx conf (bsc#1268755)
  * Remove unused udevdb salt module as upstream udev is used

susemanager-sync-data:

  * Version 5.2.6-0
  * Add Ubuntu 26.04 LTS

uyuni-coco-attestation:

  * Version 5.2.7-0
  * Ensure the certs directory is always created
  * Allow pvattest module to be built on s390x

uyuni-java-common:

  * Version 5.2.7-0
  * No customer facing changes

uyuni-java-parent:

  * Version 5.2.7-0
  * No customer facing changes

How to apply this update:

  1. Log in as root user to the SUSE Multi-Linux Manager Server.
  2. Upgrade mgradm and mgrctl.
  3. If you are in a disconnected environment, upgrade the image packages.
  4. Reboot the system.
  5. Run `mgradm upgrade podman` which will use the default image tags.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE  
    zypper in -t patch SUSE-Multi-Linux-Manager-Proxy-SLE-5.2-2026-4571

  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE  
    zypper in -t patch SUSE-Multi-Linux-Manager-Retail-Branch-Server-
SLE-5.2-2026-4571

  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE  
    zypper in -t patch SUSE-Multi-Linux-Manager-Server-SLE-5.2-2026-4571

## Package List:

  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (aarch64 ppc64le s390x
    x86_64)
    * mgrpxy-5.2.17-150750.3.3.8
    * mgrpxy-debuginfo-5.2.17-150750.3.3.8
  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (noarch)
    * mgrpxy-zsh-completion-5.2.17-150750.3.3.8
    * mgrpxy-bash-completion-5.2.17-150750.3.3.8
    * mgrpxy-lang-5.2.17-150750.3.3.8
  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (x86_64)
    * suse-multi-linux-manager-5.2-x86_64-proxy-salt-broker-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-x86_64-proxy-httpd-image-5.2.1-9.3.30
    * suse-multi-linux-manager-5.2-x86_64-proxy-squid-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-x86_64-proxy-ssh-image-5.2.1-9.3.16
  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (s390x)
    * suse-multi-linux-manager-5.2-s390x-proxy-salt-broker-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-s390x-proxy-ssh-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-s390x-proxy-squid-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-s390x-proxy-httpd-image-5.2.1-9.3.30
  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (ppc64le)
    * suse-multi-linux-manager-5.2-ppc64le-proxy-salt-broker-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-ppc64le-proxy-ssh-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-ppc64le-proxy-httpd-image-5.2.1-9.3.30
    * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-ppc64le-proxy-squid-image-5.2.1-9.3.16
  * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (aarch64)
    * suse-multi-linux-manager-5.2-aarch64-proxy-ssh-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-aarch64-proxy-httpd-image-5.2.1-9.3.30
    * suse-multi-linux-manager-5.2-aarch64-proxy-squid-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-aarch64-proxy-salt-broker-image-5.2.1-9.3.19
  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (aarch64
    ppc64le s390x x86_64)
    * mgrpxy-5.2.17-150750.3.3.8
    * mgrpxy-debuginfo-5.2.17-150750.3.3.8
  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (noarch)
    * mgrpxy-zsh-completion-5.2.17-150750.3.3.8
    * mgrpxy-bash-completion-5.2.17-150750.3.3.8
    * mgrpxy-lang-5.2.17-150750.3.3.8
  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (x86_64)
    * suse-multi-linux-manager-5.2-x86_64-proxy-salt-broker-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-x86_64-proxy-httpd-image-5.2.1-9.3.30
    * suse-multi-linux-manager-5.2-x86_64-proxy-squid-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-x86_64-proxy-ssh-image-5.2.1-9.3.16
  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (s390x)
    * suse-multi-linux-manager-5.2-s390x-proxy-salt-broker-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-s390x-proxy-ssh-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-s390x-proxy-squid-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-s390x-proxy-httpd-image-5.2.1-9.3.30
  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE
    (ppc64le)
    * suse-multi-linux-manager-5.2-ppc64le-proxy-salt-broker-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-ppc64le-proxy-ssh-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-ppc64le-proxy-httpd-image-5.2.1-9.3.30
    * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-ppc64le-proxy-squid-image-5.2.1-9.3.16
  * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE
    (aarch64)
    * suse-multi-linux-manager-5.2-aarch64-proxy-ssh-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-aarch64-proxy-httpd-image-5.2.1-9.3.30
    * suse-multi-linux-manager-5.2-aarch64-proxy-squid-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-aarch64-proxy-salt-broker-image-5.2.1-9.3.19
  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (aarch64 ppc64le s390x
    x86_64)
    * mgradm-5.2.17-150750.3.3.8
    * mgrctl-5.2.17-150750.3.3.8
    * mgrctl-debuginfo-5.2.17-150750.3.3.8
    * mgradm-debuginfo-5.2.17-150750.3.3.8
  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (noarch)
    * mgrctl-zsh-completion-5.2.17-150750.3.3.8
    * mgrctl-lang-5.2.17-150750.3.3.8
    * mgrctl-bash-completion-5.2.17-150750.3.3.8
    * mgradm-zsh-completion-5.2.17-150750.3.3.8
    * mgradm-lang-5.2.17-150750.3.3.8
    * mgradm-bash-completion-5.2.17-150750.3.3.8
  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (x86_64)
    * suse-multi-linux-manager-5.2-x86_64-server-image-5.2.1-11.3.29
    * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-x86_64-server-database-migration-image-5.2.1-7.3.16
    * suse-multi-linux-manager-5.2-x86_64-server-saline-image-5.2.1-11.3.24
    * suse-multi-linux-manager-5.2-x86_64-server-postgresql-image-5.2.1-11.3.15
    * suse-multi-linux-manager-5.2-x86_64-server-hub-xmlrpc-api-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-x86_64-server-attestation-image-5.2.1-11.3.23
  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (s390x)
    * suse-multi-linux-manager-5.2-s390x-server-image-5.2.1-11.3.29
    * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-s390x-server-attestation-image-5.2.1-11.3.23
    * suse-multi-linux-manager-5.2-s390x-server-hub-xmlrpc-api-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-s390x-server-postgresql-image-5.2.1-11.3.15
    * suse-multi-linux-manager-5.2-s390x-server-database-migration-image-5.2.1-7.3.16
    * suse-multi-linux-manager-5.2-s390x-server-saline-image-5.2.1-11.3.24
  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (ppc64le)
    * suse-multi-linux-manager-5.2-ppc64le-server-hub-xmlrpc-api-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-ppc64le-server-attestation-image-5.2.1-11.3.23
    * suse-multi-linux-manager-5.2-ppc64le-server-image-5.2.1-11.3.29
    * suse-multi-linux-manager-5.2-ppc64le-server-database-migration-image-5.2.1-7.3.16
    * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-ppc64le-server-postgresql-image-5.2.1-11.3.15
    * suse-multi-linux-manager-5.2-ppc64le-server-saline-image-5.2.1-11.3.24
  * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (aarch64)
    * suse-multi-linux-manager-5.2-aarch64-server-hub-xmlrpc-api-image-5.2.1-9.3.19
    * suse-multi-linux-manager-5.2-aarch64-server-postgresql-image-5.2.1-11.3.15
    * suse-multi-linux-manager-5.2-aarch64-server-saline-image-5.2.1-11.3.24
    * suse-multi-linux-manager-5.2-aarch64-server-attestation-image-5.2.1-11.3.23
    * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16
    * suse-multi-linux-manager-5.2-aarch64-server-image-5.2.1-11.3.29
    * suse-multi-linux-manager-5.2-aarch64-server-database-migration-image-5.2.1-7.3.16

## References:

  * https://www.suse.com/security/cve/CVE-2026-39821.html
  * https://www.suse.com/security/cve/CVE-2026-63007.html
  * https://www.suse.com/security/cve/CVE-2026-63009.html
  * https://www.suse.com/security/cve/CVE-2026-71400.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1208800
  * https://bugzilla.suse.com/show_bug.cgi?id=1230568
  * https://bugzilla.suse.com/show_bug.cgi?id=1230949
  * https://bugzilla.suse.com/show_bug.cgi?id=1252286
  * https://bugzilla.suse.com/show_bug.cgi?id=1257151
  * https://bugzilla.suse.com/show_bug.cgi?id=1258382
  * https://bugzilla.suse.com/show_bug.cgi?id=1258500
  * https://bugzilla.suse.com/show_bug.cgi?id=1258567
  * https://bugzilla.suse.com/show_bug.cgi?id=1259225
  * https://bugzilla.suse.com/show_bug.cgi?id=1260342
  * https://bugzilla.suse.com/show_bug.cgi?id=1262157
  * https://bugzilla.suse.com/show_bug.cgi?id=1263822
  * https://bugzilla.suse.com/show_bug.cgi?id=1265219
  * https://bugzilla.suse.com/show_bug.cgi?id=1265472
  * https://bugzilla.suse.com/show_bug.cgi?id=1266481
  * https://bugzilla.suse.com/show_bug.cgi?id=1267261
  * https://bugzilla.suse.com/show_bug.cgi?id=1267871
  * https://bugzilla.suse.com/show_bug.cgi?id=1267912
  * https://bugzilla.suse.com/show_bug.cgi?id=1268228
  * https://bugzilla.suse.com/show_bug.cgi?id=1268325
  * https://bugzilla.suse.com/show_bug.cgi?id=1268473
  * https://bugzilla.suse.com/show_bug.cgi?id=1268587
  * https://bugzilla.suse.com/show_bug.cgi?id=1268673
  * https://bugzilla.suse.com/show_bug.cgi?id=1268755
  * https://bugzilla.suse.com/show_bug.cgi?id=1269192
  * https://bugzilla.suse.com/show_bug.cgi?id=1269253
  * https://bugzilla.suse.com/show_bug.cgi?id=1269316
  * https://bugzilla.suse.com/show_bug.cgi?id=1269534
  * https://bugzilla.suse.com/show_bug.cgi?id=1269679
  * https://bugzilla.suse.com/show_bug.cgi?id=1270033
  * https://bugzilla.suse.com/show_bug.cgi?id=1270039
  * https://bugzilla.suse.com/show_bug.cgi?id=1270040
  * https://bugzilla.suse.com/show_bug.cgi?id=1270047
  * https://bugzilla.suse.com/show_bug.cgi?id=1270141
  * https://bugzilla.suse.com/show_bug.cgi?id=1270694
  * https://bugzilla.suse.com/show_bug.cgi?id=1271075
  * https://bugzilla.suse.com/show_bug.cgi?id=1271116
  * https://bugzilla.suse.com/show_bug.cgi?id=1271124
  * https://bugzilla.suse.com/show_bug.cgi?id=1271329
  * https://bugzilla.suse.com/show_bug.cgi?id=1271332
  * https://bugzilla.suse.com/show_bug.cgi?id=1271382
  * https://bugzilla.suse.com/show_bug.cgi?id=1271467
  * https://bugzilla.suse.com/show_bug.cgi?id=1271523
  * https://bugzilla.suse.com/show_bug.cgi?id=1271678
  * https://bugzilla.suse.com/show_bug.cgi?id=1271681
  * https://bugzilla.suse.com/show_bug.cgi?id=1271841
  * https://bugzilla.suse.com/show_bug.cgi?id=1271902
  * https://bugzilla.suse.com/show_bug.cgi?id=1271963
  * https://bugzilla.suse.com/show_bug.cgi?id=1272298
  * https://bugzilla.suse.com/show_bug.cgi?id=1272392
  * https://bugzilla.suse.com/show_bug.cgi?id=1272404
  * https://bugzilla.suse.com/show_bug.cgi?id=1272538
  * https://bugzilla.suse.com/show_bug.cgi?id=1272621
  * https://bugzilla.suse.com/show_bug.cgi?id=1272988
  * https://bugzilla.suse.com/show_bug.cgi?id=1273073
  * https://bugzilla.suse.com/show_bug.cgi?id=1273131
  * https://bugzilla.suse.com/show_bug.cgi?id=1273144
  * https://bugzilla.suse.com/show_bug.cgi?id=1273846
  * https://bugzilla.suse.com/show_bug.cgi?id=1273853
  * https://bugzilla.suse.com/show_bug.cgi?id=1274023
  * https://bugzilla.suse.com/show_bug.cgi?id=1274227
  * https://bugzilla.suse.com/show_bug.cgi?id=1274613
  * https://bugzilla.suse.com/show_bug.cgi?id=1274720
  * https://bugzilla.suse.com/show_bug.cgi?id=1274775
  * https://jira.suse.com/browse/MSQA-1060

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20261008/52f2ec06/attachment.htm>


More information about the sle-security-updates mailing list