SUSE-SU-2026:24055-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools
SLE-SECURITY-UPDATES
null at suse.de
Thu Oct 8 20:46:51 UTC 2026
# Security update 5.2.1 for Multi-Linux Manager Client Tools
Announcement ID: SUSE-SU-2026:24055-1
Release Date: 2026-10-08T09:47:48Z
Rating: important
References:
* bsc#1218722
* bsc#1252286
* bsc#1254400
* bsc#1257151
* bsc#1257599
* bsc#1259989
* bsc#1261969
* bsc#1261970
* bsc#1262098
* bsc#1262187
* bsc#1262319
* bsc#1262429
* bsc#1262492
* bsc#1262654
* bsc#1262803
* bsc#1263254
* bsc#1263330
* bsc#1263442
* bsc#1263822
* bsc#1263823
* bsc#1264962
* bsc#1265267
* bsc#1265268
* bsc#1265413
* bsc#1265525
* bsc#1265763
* bsc#1266481
* bsc#1266608
* bsc#1266669
* bsc#1267261
* bsc#1267528
* bsc#1267534
* bsc#1267538
* bsc#1267581
* bsc#1267821
* bsc#1267980
* bsc#1268325
* bsc#1268395
* bsc#1268396
* bsc#1268397
* bsc#1268649
* bsc#1268755
* bsc#1268977
* bsc#1269066
* bsc#1269788
* bsc#1269841
* bsc#1269856
* bsc#1269959
* bsc#1269966
* bsc#1270033
* bsc#1270285
* bsc#1270398
* bsc#1270399
* bsc#1271192
* bsc#1271330
* bsc#1271428
* bsc#1271613
* bsc#1272008
* bsc#1272102
* bsc#1272427
* bsc#1273094
* bsc#1273144
* bsc#1274217
* bsc#1274221
* bsc#1275205
* bsc#1275206
* bsc#1275207
* bsc#1275934
* bsc#1276426
* bsc#1276658
* bsc#1276973
* bsc#1277025
* bsc#1278307
* bsc#1278322
* jsc#MSQA-1060
* jsc#PED-16707
Cross-References:
* CVE-2023-45289
* CVE-2024-22195
* CVE-2025-13836
* CVE-2025-4673
* CVE-2026-0864
* CVE-2026-11940
* CVE-2026-11972
* CVE-2026-1229
* CVE-2026-13346
* CVE-2026-14199
* CVE-2026-1502
* CVE-2026-15308
* CVE-2026-1703
* CVE-2026-17033
* CVE-2026-17183
* CVE-2026-19197
* CVE-2026-19475
* CVE-2026-21723
* CVE-2026-2303
* CVE-2026-27459
* CVE-2026-3219
* CVE-2026-3276
* CVE-2026-33814
* CVE-2026-3446
* CVE-2026-3479
* CVE-2026-39821
* CVE-2026-39882
* CVE-2026-40181
* CVE-2026-40475
* CVE-2026-41066
* CVE-2026-41178
* CVE-2026-41606
* CVE-2026-42211
* CVE-2026-42342
* CVE-2026-4360
* CVE-2026-44431
* CVE-2026-44990
* CVE-2026-45409
* CVE-2026-4786
* CVE-2026-49825
* CVE-2026-49853
* CVE-2026-49854
* CVE-2026-49855
* CVE-2026-53606
* CVE-2026-56852
* CVE-2026-6019
* CVE-2026-6100
* CVE-2026-6357
* CVE-2026-7210
* CVE-2026-73501
* CVE-2026-7774
* CVE-2026-8328
* CVE-2026-8609
* CVE-2026-8643
CVSS scores:
* CVE-2023-45289 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2023-45289 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2025-13836 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2025-13836 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-4673 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2025-4673 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-0864 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-0864 ( NVD ): 4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( NVD ): 7.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11972 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11972 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-1229 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-1229 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
* CVE-2026-1229 ( NVD ): 2.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber
* CVE-2026-1229 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-13346 ( SUSE ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-13346 ( NVD ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-14199 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-14199 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-14199 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-1502 ( SUSE ): 5.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-1502 ( NVD ): 5.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15308 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-1703 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-1703 ( NVD ): 2.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-17033 ( SUSE ): 7.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-17033 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
* CVE-2026-17033 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
* CVE-2026-17183 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
* CVE-2026-17183 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
* CVE-2026-19197 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-19197 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-19475 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-19475 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-21723 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-21723 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-2303 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-2303 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-2303 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-27459 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-27459 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-3219 ( SUSE ): 4.6
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-3219 ( NVD ): 4.6
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-3276 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3446 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-3446 ( NVD ): 6.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-3479 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-3479 ( NVD ): 0.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39882 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-39882 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-40181 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-40181 ( NVD ): 6.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-40181 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-40475 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41066 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41606 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-42211 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-42211 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42342 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-42342 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-4360 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-4360 ( NVD ): 2.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-44431 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-44431 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-44990 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
* CVE-2026-44990 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-44990 ( NVD ): 9.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
* CVE-2026-44990 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-45409 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-45409 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-4786 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
* CVE-2026-4786 ( NVD ): 7.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
* CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
* CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
* CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53606 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-53606 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-6019 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-6019 ( NVD ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-6100 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-6100 ( NVD ): 9.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-6357 ( SUSE ): 5.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-6357 ( NVD ): 5.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-7210 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-73501 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-73501 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-7774 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-7774 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8328 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( NVD ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8609 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-8609 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-8609 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-8643 ( NVD ): 4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected Products:
* SUSE Linux Enterprise Server 16.0
* SUSE Linux Enterprise Server for SAP applications 16.0
* SUSE Linux Micro 6.2
* SUSE Multi-Linux Manager Client Tools for SLE 16
An update that solves 54 vulnerabilities, contains two features and has 20 fixes
can now be installed.
## Description:
This update fixes the following issues:
golang-github-prometheus-prometheus was updated to version 3.13.2:
* Security issues:
* CVE-2026-39821: Fixed validation bypass and privilege escalation in Punycode
label handling (bsc#1266608)
* CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in
unicode/norm handling (bsc#1272102)
* CVE-2026-44990: Fixed stored XSS in the new React UI by sanitizing
disallowed xmp elements (bsc#1275205)
* CVE-2026-53606: Fixed incomplete URI scheme validation in sanitize-html that
could enable XSS (bsc#1269966)
* CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in
mongo-driver (bsc#1269856)
* CVE-2025-4673: Fixed credential leaks by stopping HTTP client header
forwarding on redirects (bsc#1275206)
* CVE-2023-45289: Fixed credential leaks by stopping header and cookie
forwarding on HTTP redirects (bsc#1275207)
* CVE-2026-40181: Fixed open redirect risks to external domains via relative
paths in react-router (bsc#1267528)
* CVE-2026-42342: Fixed DoS risks via unbounded path expansion in the manifest
endpoint (bsc#1267538)
* CVE-2026-42211: Fixed remote code execution risks from prototype pollution
in react-router (bsc#1267534)
* CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading
in OpenTelemetry (bsc#1274221)
* Fixed potential denial-of-service vulnerabilities by updating the gRPC
dependency
* Fixed memory exhaustion and DoS by rejecting snappy-compressed requests
exceeding 32MB limit
* Bug fixes and changes:
* Fixed scrape manager failing to reload properly when SD configuration
changes rapidly.
* Prevent memory leak in remote-write path when the receiving endpoint is
unavailable.
* Native Histograms are no longer experimental. They are fully supported for
production workloads.
* Added support for OpenTelemetry traces within the Prometheus UI to correlate
metrics and traces.
* TSDB compaction speed optimized by improving the block merging algorithm.
* Allow scraping of multiple targets using a single HTTP/2 connection to
reduce overhead.
* Added new metrics to monitor the health of the rule evaluation engine.
* Incompatible: This affects scraping, remote read and write, alerting, and
SD. Network paths might need adjustments to avoid redirects.
* Incompatible: Rule group pagination tokens now use SHA-256 instead of MD5.
Custom API consumers must adapt to the new longer token format.
* Added 'group_limit' parameter to PromQL aggregations to restrict the number
of results.
* Incompatible: promtool relative paths in config files now resolve relative
to the config directory itself, instead of the current working directory.
* Support exporting TSDB blocks directly to cloud storage via the admin API.
* Incompatible: Deprecated remote-write metrics like
prometheus_remote_storage_samples_total are removed in favor of
prometheus_wal_watcher_records_read_total.
* Significant query performance boost for high-cardinality regex matchers.
* Introduce a new UI interface for safely deleting specific time series data
directly.
* Added dynamic relabeling actions to extract substrings using regex capture
groups.
* Fixed UI displaying incorrect time ranges after a timezone change.
* Bumped firewalld-prometheus-config to version 0.2 bumping OpenTelemetry to
1.43.0
grafana was updated to version 12.4.10:
* Security issues:
* CVE-2026-17183: Fixed exposing data accessible through Grafana's configured
datasource credentials (bsc#1275934)
* CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in
mongo-driver (bsc#1269841)
* CVE-2026-17033: Fixed stored cross-site scripting risks via malicious
Alertmanager generator URLs (bsc#1276426)
* CVE-2026-73501: Fixed fail-open authentication bypass in kin-openapi default
handlers (bsc#1276973)
* CVE-2026-19475: Fixed DoS risks in PostgreSQL Datasource by checking
timeGroup macros (bsc#1278307)
* CVE-2026-14199: Fixed auth bypass or session takeover via Auth Proxy cache
key collision (bsc#1278322)
* CVE-2026-19197: Fixed access control and authorization checks in dashboard
snapshots (bsc#1277025)
* CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in
unicode/norm (bsc#1272008)
* CVE-2026-41178: Fixed denial-of-service risks in OpenTelemetry baggage
parsing (bsc#1276658)
* CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading
in OpenTelemetry (bsc#1274217)
* CVE-2026-33814: Fixed infinite loop in HTTP/2 transport during framesize
check (bsc#1265763)
* CVE-2026-8609: Fixed pre-authentication denial-of-service risks in OAuth
login routes (bsc#1271330)
* CVE-2026-1229: Fixed incorrect value calculation in ecc/p384 Package
(bsc#1265525, bsc#1262187)
* CVE-2026-21723: Fixed out-of-memory and denial-of-service risks in templates
test endpoint (bsc#1272427)
* CVE-2026-41606: Fixed denial-of-service risks from nested messages in Apache
Thrift parser (bsc#1263330)
* Bug fixes and changes:
* Dashboards: Fix adhoc and groupby variable datasource on UI import
* Dashboards: Fix version dates and user display names in the legacy version
history page
* Dashboard Import: Labels in v2 schema
* Azure Monitor: fix migration for dimension filters
* Dashboards: Get annotations and dashboard endpoint performance improvements
* DashboardDS: Fix Mixed panels with a time override stuck in permanent
loading
* Alerting: Add protected fields authorization check to provisioning API
* Alerting: Return 403 instead of 500 on contact point provenance mismatch
* Jaeger: Handle gzip, deflate, and brotli compressed API responses
* Alerting: fix ORM table mapping bug causing SELECT alert_rule columns FROM
user on PostgreSQL
spacecmd was updated to version 5.2.10:
* Pre-filter errata in system_applyerrata to avoid using API calls for all
existing errata (bsc#1267261)
* Updated translation strings
uyuni-tools was updated to version 5.2.17:
Security issues fixed:
* CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)
Bug fixes and changes:
* Version 5.2.17-0:
* Bump the default image tag to 5.2.1
* Reload systemd daemon before restarting services (bsc#1270033)
* Check all supported locations for CA file in rotation check script
* Detect and fix legacy service file (bsc#1268755)
* Use healthcheck cmd from the image (bsc#1273144)
* Version 5.2.16-0:
* Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399,
bsc#1270398)
* Version 5.2.15-0:
* Added requirement for at least Podman v4.7.2
* Send READY notification to systemd only once healthy (bsc#1263823)
* Version 5.2.14-0:
* Include the server environment file in the backup (bsc#1268649)
* Added mgradm commands for SSL CA and certificate rotation
* Version 5.2.13-0:
* Check and warn if CA certificate isn't marked as critical
* Disable SSL on database during split (bsc#1267980)
* Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980)
* Check backup status only after database is started (bsc#1262492)
venv-salt-minion:
* Security issues:
* CVE-2026-13346: Fixed an issue where malicious package indexes could install
unauthorized files (bsc#1273094)
* CVE-2026-0864: Fixed custom configuration injection risks caused by improper
line-ending validation (bsc#1269066)
* CVE-2026-1502: Fixed web request header manipulation to bypass proxy
security protections (bsc#1261969)
* CVE-2026-3276: Fixed potential system slow down or freeze when processing
crafted Unicode text (bsc#1267581)
* CVE-2026-4360: Fixed directory escape risks during archive extraction
(bsc#1269959)
* CVE-2026-4786: Fixed command injection risks when processing malicious
browser links (bsc#1262319)
* CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run
malicious script (bsc#1262654)
* CVE-2026-6100: Fixed crashes or unauthorized code execution during file
decompression (bsc#1262098)
* CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files
(bsc#1264962)
* CVE-2026-7774: Fixed path traversal risks where malicious archives write
files outside targets (bsc#1267821)
* CVE-2026-8328: Fixed connections being redirected to unsafe systems by
compromised FTP servers (bsc#1265268)
* CVE-2026-11940: Fixed a bug where extracting malicious archives could
overwrite system files (bsc#1268977)
* CVE-2026-11972: Fixed infinite loop and system freeze risks during archive
decompression (bsc#1269788)
* CVE-2026-15308: Fixed crashes when parsing web pages with repetitive,
incomplete structures (bsc#1271192)
* CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local
files (bsc#1266669)
* CVE-2026-6357: Fixed package self-updates loading unauthorized modules
during install (bsc#1263442)
* CVE-2026-3219: Fixed validation failures where combined ZIP archives were
not rejected (bsc#1262429)
* CVE-2026-1703: Fixed package installations writing files outside target
directories (bsc#1257599)
* CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized
script execution (bsc#1218722)
* CVE-2026-45409: Fixed domain name encoding bypass allowing imitation
websites (bsc#1265413)
* CVE-2026-44431: Fixed data leaks where sensitive headers were sent to
external origins (bsc#1265267)
* CVE-2026-49825: Fixed missing script cleanup from namespaces in web content
(bsc#1270285)
* CVE-2026-41066: Fixed leakage of private system data via malicious XML file
parsing (bsc#1263254)
* CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was
ignored (bsc#1261970)
* CVE-2026-3479: Fixed path traversal risks when loading packages from
insecure locations (bsc#1259989)
* CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie
headers (bsc#1271428)
* CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin
servers (bsc#1268395)
* CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled
components (bsc#1268396)
* CVE-2026-49855: Fixed crashes caused by excessively compressed files
exhausting memory (bsc#1268397)
* CVE-2026-40475: Fixed silent data truncation where hidden null characters
bypass checks (bsc#1262803)
* CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response
reading size (bsc#1254400)
* Bug fixes and changes:
* Updated bundled python module pip to 25.0.1
* Updated bundled python module jinja2 to 3.1.6
* Updated bundled python module lxml to 6.1.1
* Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from
Ubuntu repositories (bsc#1271613)
* Remove unused paramiko python module from the bundle.
* Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
* Support attrlist in ldap.managed (bsc#1257151)
* Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
* Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)
## Special Instructions and Notes:
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Multi-Linux Manager Client Tools for SLE 16
zypper in -t patch Multi-Linux-ManagerTools-SLE-16-6
## Package List:
* SUSE Multi-Linux Manager Client Tools for SLE 16 (aarch64 ppc64le s390x
x86_64)
* mgrctl-5.2.17-160002.1.1
* golang-github-prometheus-prometheus-debuginfo-3.13.2-160002.1.1
* grafana-debuginfo-12.4.10-160002.1.1
* golang-github-prometheus-prometheus-3.13.2-160002.1.1
* grafana-12.4.10-160002.1.1
* mgrctl-debuginfo-5.2.17-160002.1.1
* venv-salt-minion-3006.0-160002.7.1
* SUSE Multi-Linux Manager Client Tools for SLE 16 (noarch)
* spacecmd-5.2.10-160002.1.1
* mgrctl-bash-completion-5.2.17-160002.1.1
* mgrctl-lang-5.2.17-160002.1.1
* mgrctl-zsh-completion-5.2.17-160002.1.1
## References:
* https://www.suse.com/security/cve/CVE-2023-45289.html
* https://www.suse.com/security/cve/CVE-2024-22195.html
* https://www.suse.com/security/cve/CVE-2025-13836.html
* https://www.suse.com/security/cve/CVE-2025-4673.html
* https://www.suse.com/security/cve/CVE-2026-0864.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-11972.html
* https://www.suse.com/security/cve/CVE-2026-1229.html
* https://www.suse.com/security/cve/CVE-2026-13346.html
* https://www.suse.com/security/cve/CVE-2026-14199.html
* https://www.suse.com/security/cve/CVE-2026-1502.html
* https://www.suse.com/security/cve/CVE-2026-15308.html
* https://www.suse.com/security/cve/CVE-2026-1703.html
* https://www.suse.com/security/cve/CVE-2026-17033.html
* https://www.suse.com/security/cve/CVE-2026-17183.html
* https://www.suse.com/security/cve/CVE-2026-19197.html
* https://www.suse.com/security/cve/CVE-2026-19475.html
* https://www.suse.com/security/cve/CVE-2026-21723.html
* https://www.suse.com/security/cve/CVE-2026-2303.html
* https://www.suse.com/security/cve/CVE-2026-27459.html
* https://www.suse.com/security/cve/CVE-2026-3219.html
* https://www.suse.com/security/cve/CVE-2026-3276.html
* https://www.suse.com/security/cve/CVE-2026-33814.html
* https://www.suse.com/security/cve/CVE-2026-3446.html
* https://www.suse.com/security/cve/CVE-2026-3479.html
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-39882.html
* https://www.suse.com/security/cve/CVE-2026-40181.html
* https://www.suse.com/security/cve/CVE-2026-40475.html
* https://www.suse.com/security/cve/CVE-2026-41066.html
* https://www.suse.com/security/cve/CVE-2026-41178.html
* https://www.suse.com/security/cve/CVE-2026-41606.html
* https://www.suse.com/security/cve/CVE-2026-42211.html
* https://www.suse.com/security/cve/CVE-2026-42342.html
* https://www.suse.com/security/cve/CVE-2026-4360.html
* https://www.suse.com/security/cve/CVE-2026-44431.html
* https://www.suse.com/security/cve/CVE-2026-44990.html
* https://www.suse.com/security/cve/CVE-2026-45409.html
* https://www.suse.com/security/cve/CVE-2026-4786.html
* https://www.suse.com/security/cve/CVE-2026-49825.html
* https://www.suse.com/security/cve/CVE-2026-49853.html
* https://www.suse.com/security/cve/CVE-2026-49854.html
* https://www.suse.com/security/cve/CVE-2026-49855.html
* https://www.suse.com/security/cve/CVE-2026-53606.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://www.suse.com/security/cve/CVE-2026-6019.html
* https://www.suse.com/security/cve/CVE-2026-6100.html
* https://www.suse.com/security/cve/CVE-2026-6357.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-73501.html
* https://www.suse.com/security/cve/CVE-2026-7774.html
* https://www.suse.com/security/cve/CVE-2026-8328.html
* https://www.suse.com/security/cve/CVE-2026-8609.html
* https://www.suse.com/security/cve/CVE-2026-8643.html
* https://bugzilla.suse.com/show_bug.cgi?id=1218722
* https://bugzilla.suse.com/show_bug.cgi?id=1252286
* https://bugzilla.suse.com/show_bug.cgi?id=1254400
* https://bugzilla.suse.com/show_bug.cgi?id=1257151
* https://bugzilla.suse.com/show_bug.cgi?id=1257599
* https://bugzilla.suse.com/show_bug.cgi?id=1259989
* https://bugzilla.suse.com/show_bug.cgi?id=1261969
* https://bugzilla.suse.com/show_bug.cgi?id=1261970
* https://bugzilla.suse.com/show_bug.cgi?id=1262098
* https://bugzilla.suse.com/show_bug.cgi?id=1262187
* https://bugzilla.suse.com/show_bug.cgi?id=1262319
* https://bugzilla.suse.com/show_bug.cgi?id=1262429
* https://bugzilla.suse.com/show_bug.cgi?id=1262492
* https://bugzilla.suse.com/show_bug.cgi?id=1262654
* https://bugzilla.suse.com/show_bug.cgi?id=1262803
* https://bugzilla.suse.com/show_bug.cgi?id=1263254
* https://bugzilla.suse.com/show_bug.cgi?id=1263330
* https://bugzilla.suse.com/show_bug.cgi?id=1263442
* https://bugzilla.suse.com/show_bug.cgi?id=1263822
* https://bugzilla.suse.com/show_bug.cgi?id=1263823
* https://bugzilla.suse.com/show_bug.cgi?id=1264962
* https://bugzilla.suse.com/show_bug.cgi?id=1265267
* https://bugzilla.suse.com/show_bug.cgi?id=1265268
* https://bugzilla.suse.com/show_bug.cgi?id=1265413
* https://bugzilla.suse.com/show_bug.cgi?id=1265525
* https://bugzilla.suse.com/show_bug.cgi?id=1265763
* https://bugzilla.suse.com/show_bug.cgi?id=1266481
* https://bugzilla.suse.com/show_bug.cgi?id=1266608
* https://bugzilla.suse.com/show_bug.cgi?id=1266669
* https://bugzilla.suse.com/show_bug.cgi?id=1267261
* https://bugzilla.suse.com/show_bug.cgi?id=1267528
* https://bugzilla.suse.com/show_bug.cgi?id=1267534
* https://bugzilla.suse.com/show_bug.cgi?id=1267538
* https://bugzilla.suse.com/show_bug.cgi?id=1267581
* https://bugzilla.suse.com/show_bug.cgi?id=1267821
* https://bugzilla.suse.com/show_bug.cgi?id=1267980
* https://bugzilla.suse.com/show_bug.cgi?id=1268325
* https://bugzilla.suse.com/show_bug.cgi?id=1268395
* https://bugzilla.suse.com/show_bug.cgi?id=1268396
* https://bugzilla.suse.com/show_bug.cgi?id=1268397
* https://bugzilla.suse.com/show_bug.cgi?id=1268649
* https://bugzilla.suse.com/show_bug.cgi?id=1268755
* https://bugzilla.suse.com/show_bug.cgi?id=1268977
* https://bugzilla.suse.com/show_bug.cgi?id=1269066
* https://bugzilla.suse.com/show_bug.cgi?id=1269788
* https://bugzilla.suse.com/show_bug.cgi?id=1269841
* https://bugzilla.suse.com/show_bug.cgi?id=1269856
* https://bugzilla.suse.com/show_bug.cgi?id=1269959
* https://bugzilla.suse.com/show_bug.cgi?id=1269966
* https://bugzilla.suse.com/show_bug.cgi?id=1270033
* https://bugzilla.suse.com/show_bug.cgi?id=1270285
* https://bugzilla.suse.com/show_bug.cgi?id=1270398
* https://bugzilla.suse.com/show_bug.cgi?id=1270399
* https://bugzilla.suse.com/show_bug.cgi?id=1271192
* https://bugzilla.suse.com/show_bug.cgi?id=1271330
* https://bugzilla.suse.com/show_bug.cgi?id=1271428
* https://bugzilla.suse.com/show_bug.cgi?id=1271613
* https://bugzilla.suse.com/show_bug.cgi?id=1272008
* https://bugzilla.suse.com/show_bug.cgi?id=1272102
* https://bugzilla.suse.com/show_bug.cgi?id=1272427
* https://bugzilla.suse.com/show_bug.cgi?id=1273094
* https://bugzilla.suse.com/show_bug.cgi?id=1273144
* https://bugzilla.suse.com/show_bug.cgi?id=1274217
* https://bugzilla.suse.com/show_bug.cgi?id=1274221
* https://bugzilla.suse.com/show_bug.cgi?id=1275205
* https://bugzilla.suse.com/show_bug.cgi?id=1275206
* https://bugzilla.suse.com/show_bug.cgi?id=1275207
* https://bugzilla.suse.com/show_bug.cgi?id=1275934
* https://bugzilla.suse.com/show_bug.cgi?id=1276426
* https://bugzilla.suse.com/show_bug.cgi?id=1276658
* https://bugzilla.suse.com/show_bug.cgi?id=1276973
* https://bugzilla.suse.com/show_bug.cgi?id=1277025
* https://bugzilla.suse.com/show_bug.cgi?id=1278307
* https://bugzilla.suse.com/show_bug.cgi?id=1278322
* https://jira.suse.com/browse/MSQA-1060
* https://jira.suse.com/browse/PED-16707
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20261008/2bd02702/attachment.htm>
More information about the sle-security-updates
mailing list