SUSE-SU-2026:24055-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools

SLE-SECURITY-UPDATES null at suse.de
Thu Oct 8 20:46:51 UTC 2026


# Security update 5.2.1 for Multi-Linux Manager Client Tools

Announcement ID: SUSE-SU-2026:24055-1  
Release Date: 2026-10-08T09:47:48Z  
Rating: important  
References:

  * bsc#1218722
  * bsc#1252286
  * bsc#1254400
  * bsc#1257151
  * bsc#1257599
  * bsc#1259989
  * bsc#1261969
  * bsc#1261970
  * bsc#1262098
  * bsc#1262187
  * bsc#1262319
  * bsc#1262429
  * bsc#1262492
  * bsc#1262654
  * bsc#1262803
  * bsc#1263254
  * bsc#1263330
  * bsc#1263442
  * bsc#1263822
  * bsc#1263823
  * bsc#1264962
  * bsc#1265267
  * bsc#1265268
  * bsc#1265413
  * bsc#1265525
  * bsc#1265763
  * bsc#1266481
  * bsc#1266608
  * bsc#1266669
  * bsc#1267261
  * bsc#1267528
  * bsc#1267534
  * bsc#1267538
  * bsc#1267581
  * bsc#1267821
  * bsc#1267980
  * bsc#1268325
  * bsc#1268395
  * bsc#1268396
  * bsc#1268397
  * bsc#1268649
  * bsc#1268755
  * bsc#1268977
  * bsc#1269066
  * bsc#1269788
  * bsc#1269841
  * bsc#1269856
  * bsc#1269959
  * bsc#1269966
  * bsc#1270033
  * bsc#1270285
  * bsc#1270398
  * bsc#1270399
  * bsc#1271192
  * bsc#1271330
  * bsc#1271428
  * bsc#1271613
  * bsc#1272008
  * bsc#1272102
  * bsc#1272427
  * bsc#1273094
  * bsc#1273144
  * bsc#1274217
  * bsc#1274221
  * bsc#1275205
  * bsc#1275206
  * bsc#1275207
  * bsc#1275934
  * bsc#1276426
  * bsc#1276658
  * bsc#1276973
  * bsc#1277025
  * bsc#1278307
  * bsc#1278322
  * jsc#MSQA-1060
  * jsc#PED-16707

  
Cross-References:

  * CVE-2023-45289
  * CVE-2024-22195
  * CVE-2025-13836
  * CVE-2025-4673
  * CVE-2026-0864
  * CVE-2026-11940
  * CVE-2026-11972
  * CVE-2026-1229
  * CVE-2026-13346
  * CVE-2026-14199
  * CVE-2026-1502
  * CVE-2026-15308
  * CVE-2026-1703
  * CVE-2026-17033
  * CVE-2026-17183
  * CVE-2026-19197
  * CVE-2026-19475
  * CVE-2026-21723
  * CVE-2026-2303
  * CVE-2026-27459
  * CVE-2026-3219
  * CVE-2026-3276
  * CVE-2026-33814
  * CVE-2026-3446
  * CVE-2026-3479
  * CVE-2026-39821
  * CVE-2026-39882
  * CVE-2026-40181
  * CVE-2026-40475
  * CVE-2026-41066
  * CVE-2026-41178
  * CVE-2026-41606
  * CVE-2026-42211
  * CVE-2026-42342
  * CVE-2026-4360
  * CVE-2026-44431
  * CVE-2026-44990
  * CVE-2026-45409
  * CVE-2026-4786
  * CVE-2026-49825
  * CVE-2026-49853
  * CVE-2026-49854
  * CVE-2026-49855
  * CVE-2026-53606
  * CVE-2026-56852
  * CVE-2026-6019
  * CVE-2026-6100
  * CVE-2026-6357
  * CVE-2026-7210
  * CVE-2026-73501
  * CVE-2026-7774
  * CVE-2026-8328
  * CVE-2026-8609
  * CVE-2026-8643

  
CVSS scores:

  * CVE-2023-45289 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2023-45289 ( NVD ):  4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2024-22195 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2024-22195 ( NVD ):  6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2024-22195 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2025-13836 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2025-13836 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2025-13836 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2025-13836 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2025-4673 ( SUSE ):  8.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
  * CVE-2025-4673 ( SUSE ):  6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
  * CVE-2025-4673 ( NVD ):  6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
  * CVE-2026-0864 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-0864 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-0864 ( NVD ):  4.1
    CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-0864 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11940 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-11940 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-11940 ( NVD ):  7.8
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-11972 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-11972 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-11972 ( NVD ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-1229 ( SUSE ):  8.3
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-1229 ( SUSE ):  7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
  * CVE-2026-1229 ( NVD ):  2.9
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber
  * CVE-2026-1229 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-13346 ( SUSE ):  5.6
    CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-13346 ( SUSE ):  4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
  * CVE-2026-13346 ( NVD ):  5.6
    CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-13346 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
  * CVE-2026-14199 ( SUSE ):  7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-14199 ( NVD ):  7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-14199 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-1502 ( SUSE ):  5.7
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-1502 ( SUSE ):  4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-1502 ( NVD ):  5.7
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-15308 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-15308 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-15308 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-15308 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-1703 ( SUSE ):  2.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-1703 ( SUSE ):  3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-1703 ( NVD ):  2.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-17033 ( SUSE ):  7.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-17033 ( SUSE ):  6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
  * CVE-2026-17033 ( NVD ):  6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
  * CVE-2026-17183 ( SUSE ):  7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
  * CVE-2026-17183 ( NVD ):  7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
  * CVE-2026-19197 ( SUSE ):  6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-19197 ( NVD ):  6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-19475 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-19475 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-21723 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-21723 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-2303 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
  * CVE-2026-2303 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-2303 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-27459 ( SUSE ):  8.3
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-27459 ( SUSE ):  7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  * CVE-2026-27459 ( NVD ):  7.2
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-27459 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-27459 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-3219 ( SUSE ):  4.6
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-3219 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-3219 ( NVD ):  4.6
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-3276 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-3276 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-3276 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-33814 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-33814 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-33814 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-33814 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-3446 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-3446 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-3446 ( NVD ):  6.0
    CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-3479 ( SUSE ):  2.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-3479 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-3479 ( NVD ):  0.0
    CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-39821 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-39821 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-39821 ( NVD ):  8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
  * CVE-2026-39821 ( NVD ):  9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  * CVE-2026-39882 ( SUSE ):  5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-39882 ( NVD ):  5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-40181 ( SUSE ):  4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-40181 ( NVD ):  6.6
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-40181 ( NVD ):  6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-40475 ( SUSE ):  6.8
    CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-40475 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-41066 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-41066 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-41066 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-41178 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-41178 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-41606 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-41606 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-41606 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-41606 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-42211 ( SUSE ):  5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-42211 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-42342 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-42342 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-4360 ( SUSE ):  2.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-4360 ( SUSE ):  2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
  * CVE-2026-4360 ( NVD ):  2.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4360 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-44431 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-44431 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-44431 ( NVD ):  8.2
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-44431 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-44990 ( SUSE ):  5.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
  * CVE-2026-44990 ( SUSE ):  6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-44990 ( NVD ):  9.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  * CVE-2026-44990 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
  * CVE-2026-45409 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-45409 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-45409 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-45409 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-4786 ( SUSE ):  7.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4786 ( SUSE ):  7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
  * CVE-2026-4786 ( NVD ):  7.0
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-4786 ( NVD ):  7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
  * CVE-2026-49825 ( NVD ):  8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
  * CVE-2026-49853 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
  * CVE-2026-49853 ( NVD ):  7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
  * CVE-2026-49854 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-49854 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-49855 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-49855 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-53606 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-53606 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-56852 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-56852 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-56852 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-6019 ( SUSE ):  2.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-6019 ( SUSE ):  3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-6019 ( NVD ):  2.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-6019 ( NVD ):  6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  * CVE-2026-6100 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-6100 ( SUSE ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-6100 ( NVD ):  9.1
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-6100 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-6357 ( SUSE ):  5.3
    CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-6357 ( SUSE ):  5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
  * CVE-2026-6357 ( NVD ):  5.3
    CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-7210 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-7210 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-7210 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-7210 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-73501 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-73501 ( NVD ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-7774 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-7774 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-7774 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-8328 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-8328 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-8328 ( NVD ):  5.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-8609 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-8609 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-8609 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-8643 ( SUSE ):  8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
  * CVE-2026-8643 ( NVD ):  4.1
    CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-8643 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-8643 ( NVD ):  8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0
  * SUSE Linux Micro 6.2
  * SUSE Multi-Linux Manager Client Tools for SLE 16

  
  
An update that solves 54 vulnerabilities, contains two features and has 20 fixes
can now be installed.

## Description:

This update fixes the following issues:

golang-github-prometheus-prometheus was updated to version 3.13.2:

  * Security issues:

  * CVE-2026-39821: Fixed validation bypass and privilege escalation in Punycode
    label handling (bsc#1266608)

  * CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in
    unicode/norm handling (bsc#1272102)
  * CVE-2026-44990: Fixed stored XSS in the new React UI by sanitizing
    disallowed xmp elements (bsc#1275205)
  * CVE-2026-53606: Fixed incomplete URI scheme validation in sanitize-html that
    could enable XSS (bsc#1269966)
  * CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in
    mongo-driver (bsc#1269856)
  * CVE-2025-4673: Fixed credential leaks by stopping HTTP client header
    forwarding on redirects (bsc#1275206)
  * CVE-2023-45289: Fixed credential leaks by stopping header and cookie
    forwarding on HTTP redirects (bsc#1275207)
  * CVE-2026-40181: Fixed open redirect risks to external domains via relative
    paths in react-router (bsc#1267528)
  * CVE-2026-42342: Fixed DoS risks via unbounded path expansion in the manifest
    endpoint (bsc#1267538)
  * CVE-2026-42211: Fixed remote code execution risks from prototype pollution
    in react-router (bsc#1267534)
  * CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading
    in OpenTelemetry (bsc#1274221)
  * Fixed potential denial-of-service vulnerabilities by updating the gRPC
    dependency
  * Fixed memory exhaustion and DoS by rejecting snappy-compressed requests
    exceeding 32MB limit

  * Bug fixes and changes:

  * Fixed scrape manager failing to reload properly when SD configuration
    changes rapidly.

  * Prevent memory leak in remote-write path when the receiving endpoint is
    unavailable.
  * Native Histograms are no longer experimental. They are fully supported for
    production workloads.
  * Added support for OpenTelemetry traces within the Prometheus UI to correlate
    metrics and traces.
  * TSDB compaction speed optimized by improving the block merging algorithm.
  * Allow scraping of multiple targets using a single HTTP/2 connection to
    reduce overhead.
  * Added new metrics to monitor the health of the rule evaluation engine.
  * Incompatible: This affects scraping, remote read and write, alerting, and
    SD. Network paths might need adjustments to avoid redirects.
  * Incompatible: Rule group pagination tokens now use SHA-256 instead of MD5.
    Custom API consumers must adapt to the new longer token format.
  * Added 'group_limit' parameter to PromQL aggregations to restrict the number
    of results.
  * Incompatible: promtool relative paths in config files now resolve relative
    to the config directory itself, instead of the current working directory.
  * Support exporting TSDB blocks directly to cloud storage via the admin API.
  * Incompatible: Deprecated remote-write metrics like
    prometheus_remote_storage_samples_total are removed in favor of
    prometheus_wal_watcher_records_read_total.
  * Significant query performance boost for high-cardinality regex matchers.
  * Introduce a new UI interface for safely deleting specific time series data
    directly.
  * Added dynamic relabeling actions to extract substrings using regex capture
    groups.
  * Fixed UI displaying incorrect time ranges after a timezone change.
  * Bumped firewalld-prometheus-config to version 0.2 bumping OpenTelemetry to
    1.43.0

grafana was updated to version 12.4.10:

  * Security issues:

  * CVE-2026-17183: Fixed exposing data accessible through Grafana's configured
    datasource credentials (bsc#1275934)

  * CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in
    mongo-driver (bsc#1269841)
  * CVE-2026-17033: Fixed stored cross-site scripting risks via malicious
    Alertmanager generator URLs (bsc#1276426)
  * CVE-2026-73501: Fixed fail-open authentication bypass in kin-openapi default
    handlers (bsc#1276973)
  * CVE-2026-19475: Fixed DoS risks in PostgreSQL Datasource by checking
    timeGroup macros (bsc#1278307)
  * CVE-2026-14199: Fixed auth bypass or session takeover via Auth Proxy cache
    key collision (bsc#1278322)
  * CVE-2026-19197: Fixed access control and authorization checks in dashboard
    snapshots (bsc#1277025)
  * CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in
    unicode/norm (bsc#1272008)
  * CVE-2026-41178: Fixed denial-of-service risks in OpenTelemetry baggage
    parsing (bsc#1276658)
  * CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading
    in OpenTelemetry (bsc#1274217)
  * CVE-2026-33814: Fixed infinite loop in HTTP/2 transport during framesize
    check (bsc#1265763)
  * CVE-2026-8609: Fixed pre-authentication denial-of-service risks in OAuth
    login routes (bsc#1271330)
  * CVE-2026-1229: Fixed incorrect value calculation in ecc/p384 Package
    (bsc#1265525, bsc#1262187)
  * CVE-2026-21723: Fixed out-of-memory and denial-of-service risks in templates
    test endpoint (bsc#1272427)
  * CVE-2026-41606: Fixed denial-of-service risks from nested messages in Apache
    Thrift parser (bsc#1263330)

  * Bug fixes and changes:

  * Dashboards: Fix adhoc and groupby variable datasource on UI import

  * Dashboards: Fix version dates and user display names in the legacy version
    history page
  * Dashboard Import: Labels in v2 schema
  * Azure Monitor: fix migration for dimension filters
  * Dashboards: Get annotations and dashboard endpoint performance improvements
  * DashboardDS: Fix Mixed panels with a time override stuck in permanent
    loading
  * Alerting: Add protected fields authorization check to provisioning API
  * Alerting: Return 403 instead of 500 on contact point provenance mismatch
  * Jaeger: Handle gzip, deflate, and brotli compressed API responses
  * Alerting: fix ORM table mapping bug causing SELECT alert_rule columns FROM
    user on PostgreSQL

spacecmd was updated to version 5.2.10:

  * Pre-filter errata in system_applyerrata to avoid using API calls for all
    existing errata (bsc#1267261)
  * Updated translation strings

uyuni-tools was updated to version 5.2.17:

Security issues fixed:

  * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)

Bug fixes and changes:

  * Version 5.2.17-0:

  * Bump the default image tag to 5.2.1

  * Reload systemd daemon before restarting services (bsc#1270033)
  * Check all supported locations for CA file in rotation check script
  * Detect and fix legacy service file (bsc#1268755)
  * Use healthcheck cmd from the image (bsc#1273144)

  * Version 5.2.16-0:

  * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399,
    bsc#1270398)

  * Version 5.2.15-0:

  * Added requirement for at least Podman v4.7.2

  * Send READY notification to systemd only once healthy (bsc#1263823)

  * Version 5.2.14-0:

  * Include the server environment file in the backup (bsc#1268649)

  * Added mgradm commands for SSL CA and certificate rotation

  * Version 5.2.13-0:

  * Check and warn if CA certificate isn't marked as critical

  * Disable SSL on database during split (bsc#1267980)
  * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980)
  * Check backup status only after database is started (bsc#1262492)

venv-salt-minion:

  * Security issues:

  * CVE-2026-13346: Fixed an issue where malicious package indexes could install
    unauthorized files (bsc#1273094)

  * CVE-2026-0864: Fixed custom configuration injection risks caused by improper
    line-ending validation (bsc#1269066)
  * CVE-2026-1502: Fixed web request header manipulation to bypass proxy
    security protections (bsc#1261969)
  * CVE-2026-3276: Fixed potential system slow down or freeze when processing
    crafted Unicode text (bsc#1267581)
  * CVE-2026-4360: Fixed directory escape risks during archive extraction
    (bsc#1269959)
  * CVE-2026-4786: Fixed command injection risks when processing malicious
    browser links (bsc#1262319)
  * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run
    malicious script (bsc#1262654)
  * CVE-2026-6100: Fixed crashes or unauthorized code execution during file
    decompression (bsc#1262098)
  * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files
    (bsc#1264962)
  * CVE-2026-7774: Fixed path traversal risks where malicious archives write
    files outside targets (bsc#1267821)
  * CVE-2026-8328: Fixed connections being redirected to unsafe systems by
    compromised FTP servers (bsc#1265268)
  * CVE-2026-11940: Fixed a bug where extracting malicious archives could
    overwrite system files (bsc#1268977)
  * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive
    decompression (bsc#1269788)
  * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive,
    incomplete structures (bsc#1271192)
  * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local
    files (bsc#1266669)
  * CVE-2026-6357: Fixed package self-updates loading unauthorized modules
    during install (bsc#1263442)
  * CVE-2026-3219: Fixed validation failures where combined ZIP archives were
    not rejected (bsc#1262429)
  * CVE-2026-1703: Fixed package installations writing files outside target
    directories (bsc#1257599)
  * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized
    script execution (bsc#1218722)
  * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation
    websites (bsc#1265413)
  * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to
    external origins (bsc#1265267)
  * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content
    (bsc#1270285)
  * CVE-2026-41066: Fixed leakage of private system data via malicious XML file
    parsing (bsc#1263254)
  * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was
    ignored (bsc#1261970)
  * CVE-2026-3479: Fixed path traversal risks when loading packages from
    insecure locations (bsc#1259989)
  * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie
    headers (bsc#1271428)
  * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin
    servers (bsc#1268395)
  * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled
    components (bsc#1268396)
  * CVE-2026-49855: Fixed crashes caused by excessively compressed files
    exhausting memory (bsc#1268397)
  * CVE-2026-40475: Fixed silent data truncation where hidden null characters
    bypass checks (bsc#1262803)
  * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response
    reading size (bsc#1254400)

  * Bug fixes and changes:

  * Updated bundled python module pip to 25.0.1

  * Updated bundled python module jinja2 to 3.1.6
  * Updated bundled python module lxml to 6.1.1
  * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from
    Ubuntu repositories (bsc#1271613)
  * Remove unused paramiko python module from the bundle.
  * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
  * Support attrlist in ldap.managed (bsc#1257151)
  * Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
  * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)

## Special Instructions and Notes:

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Multi-Linux Manager Client Tools for SLE 16  
    zypper in -t patch Multi-Linux-ManagerTools-SLE-16-6

## Package List:

  * SUSE Multi-Linux Manager Client Tools for SLE 16 (aarch64 ppc64le s390x
    x86_64)
    * mgrctl-5.2.17-160002.1.1
    * golang-github-prometheus-prometheus-debuginfo-3.13.2-160002.1.1
    * grafana-debuginfo-12.4.10-160002.1.1
    * golang-github-prometheus-prometheus-3.13.2-160002.1.1
    * grafana-12.4.10-160002.1.1
    * mgrctl-debuginfo-5.2.17-160002.1.1
    * venv-salt-minion-3006.0-160002.7.1
  * SUSE Multi-Linux Manager Client Tools for SLE 16 (noarch)
    * spacecmd-5.2.10-160002.1.1
    * mgrctl-bash-completion-5.2.17-160002.1.1
    * mgrctl-lang-5.2.17-160002.1.1
    * mgrctl-zsh-completion-5.2.17-160002.1.1

## References:

  * https://www.suse.com/security/cve/CVE-2023-45289.html
  * https://www.suse.com/security/cve/CVE-2024-22195.html
  * https://www.suse.com/security/cve/CVE-2025-13836.html
  * https://www.suse.com/security/cve/CVE-2025-4673.html
  * https://www.suse.com/security/cve/CVE-2026-0864.html
  * https://www.suse.com/security/cve/CVE-2026-11940.html
  * https://www.suse.com/security/cve/CVE-2026-11972.html
  * https://www.suse.com/security/cve/CVE-2026-1229.html
  * https://www.suse.com/security/cve/CVE-2026-13346.html
  * https://www.suse.com/security/cve/CVE-2026-14199.html
  * https://www.suse.com/security/cve/CVE-2026-1502.html
  * https://www.suse.com/security/cve/CVE-2026-15308.html
  * https://www.suse.com/security/cve/CVE-2026-1703.html
  * https://www.suse.com/security/cve/CVE-2026-17033.html
  * https://www.suse.com/security/cve/CVE-2026-17183.html
  * https://www.suse.com/security/cve/CVE-2026-19197.html
  * https://www.suse.com/security/cve/CVE-2026-19475.html
  * https://www.suse.com/security/cve/CVE-2026-21723.html
  * https://www.suse.com/security/cve/CVE-2026-2303.html
  * https://www.suse.com/security/cve/CVE-2026-27459.html
  * https://www.suse.com/security/cve/CVE-2026-3219.html
  * https://www.suse.com/security/cve/CVE-2026-3276.html
  * https://www.suse.com/security/cve/CVE-2026-33814.html
  * https://www.suse.com/security/cve/CVE-2026-3446.html
  * https://www.suse.com/security/cve/CVE-2026-3479.html
  * https://www.suse.com/security/cve/CVE-2026-39821.html
  * https://www.suse.com/security/cve/CVE-2026-39882.html
  * https://www.suse.com/security/cve/CVE-2026-40181.html
  * https://www.suse.com/security/cve/CVE-2026-40475.html
  * https://www.suse.com/security/cve/CVE-2026-41066.html
  * https://www.suse.com/security/cve/CVE-2026-41178.html
  * https://www.suse.com/security/cve/CVE-2026-41606.html
  * https://www.suse.com/security/cve/CVE-2026-42211.html
  * https://www.suse.com/security/cve/CVE-2026-42342.html
  * https://www.suse.com/security/cve/CVE-2026-4360.html
  * https://www.suse.com/security/cve/CVE-2026-44431.html
  * https://www.suse.com/security/cve/CVE-2026-44990.html
  * https://www.suse.com/security/cve/CVE-2026-45409.html
  * https://www.suse.com/security/cve/CVE-2026-4786.html
  * https://www.suse.com/security/cve/CVE-2026-49825.html
  * https://www.suse.com/security/cve/CVE-2026-49853.html
  * https://www.suse.com/security/cve/CVE-2026-49854.html
  * https://www.suse.com/security/cve/CVE-2026-49855.html
  * https://www.suse.com/security/cve/CVE-2026-53606.html
  * https://www.suse.com/security/cve/CVE-2026-56852.html
  * https://www.suse.com/security/cve/CVE-2026-6019.html
  * https://www.suse.com/security/cve/CVE-2026-6100.html
  * https://www.suse.com/security/cve/CVE-2026-6357.html
  * https://www.suse.com/security/cve/CVE-2026-7210.html
  * https://www.suse.com/security/cve/CVE-2026-73501.html
  * https://www.suse.com/security/cve/CVE-2026-7774.html
  * https://www.suse.com/security/cve/CVE-2026-8328.html
  * https://www.suse.com/security/cve/CVE-2026-8609.html
  * https://www.suse.com/security/cve/CVE-2026-8643.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1218722
  * https://bugzilla.suse.com/show_bug.cgi?id=1252286
  * https://bugzilla.suse.com/show_bug.cgi?id=1254400
  * https://bugzilla.suse.com/show_bug.cgi?id=1257151
  * https://bugzilla.suse.com/show_bug.cgi?id=1257599
  * https://bugzilla.suse.com/show_bug.cgi?id=1259989
  * https://bugzilla.suse.com/show_bug.cgi?id=1261969
  * https://bugzilla.suse.com/show_bug.cgi?id=1261970
  * https://bugzilla.suse.com/show_bug.cgi?id=1262098
  * https://bugzilla.suse.com/show_bug.cgi?id=1262187
  * https://bugzilla.suse.com/show_bug.cgi?id=1262319
  * https://bugzilla.suse.com/show_bug.cgi?id=1262429
  * https://bugzilla.suse.com/show_bug.cgi?id=1262492
  * https://bugzilla.suse.com/show_bug.cgi?id=1262654
  * https://bugzilla.suse.com/show_bug.cgi?id=1262803
  * https://bugzilla.suse.com/show_bug.cgi?id=1263254
  * https://bugzilla.suse.com/show_bug.cgi?id=1263330
  * https://bugzilla.suse.com/show_bug.cgi?id=1263442
  * https://bugzilla.suse.com/show_bug.cgi?id=1263822
  * https://bugzilla.suse.com/show_bug.cgi?id=1263823
  * https://bugzilla.suse.com/show_bug.cgi?id=1264962
  * https://bugzilla.suse.com/show_bug.cgi?id=1265267
  * https://bugzilla.suse.com/show_bug.cgi?id=1265268
  * https://bugzilla.suse.com/show_bug.cgi?id=1265413
  * https://bugzilla.suse.com/show_bug.cgi?id=1265525
  * https://bugzilla.suse.com/show_bug.cgi?id=1265763
  * https://bugzilla.suse.com/show_bug.cgi?id=1266481
  * https://bugzilla.suse.com/show_bug.cgi?id=1266608
  * https://bugzilla.suse.com/show_bug.cgi?id=1266669
  * https://bugzilla.suse.com/show_bug.cgi?id=1267261
  * https://bugzilla.suse.com/show_bug.cgi?id=1267528
  * https://bugzilla.suse.com/show_bug.cgi?id=1267534
  * https://bugzilla.suse.com/show_bug.cgi?id=1267538
  * https://bugzilla.suse.com/show_bug.cgi?id=1267581
  * https://bugzilla.suse.com/show_bug.cgi?id=1267821
  * https://bugzilla.suse.com/show_bug.cgi?id=1267980
  * https://bugzilla.suse.com/show_bug.cgi?id=1268325
  * https://bugzilla.suse.com/show_bug.cgi?id=1268395
  * https://bugzilla.suse.com/show_bug.cgi?id=1268396
  * https://bugzilla.suse.com/show_bug.cgi?id=1268397
  * https://bugzilla.suse.com/show_bug.cgi?id=1268649
  * https://bugzilla.suse.com/show_bug.cgi?id=1268755
  * https://bugzilla.suse.com/show_bug.cgi?id=1268977
  * https://bugzilla.suse.com/show_bug.cgi?id=1269066
  * https://bugzilla.suse.com/show_bug.cgi?id=1269788
  * https://bugzilla.suse.com/show_bug.cgi?id=1269841
  * https://bugzilla.suse.com/show_bug.cgi?id=1269856
  * https://bugzilla.suse.com/show_bug.cgi?id=1269959
  * https://bugzilla.suse.com/show_bug.cgi?id=1269966
  * https://bugzilla.suse.com/show_bug.cgi?id=1270033
  * https://bugzilla.suse.com/show_bug.cgi?id=1270285
  * https://bugzilla.suse.com/show_bug.cgi?id=1270398
  * https://bugzilla.suse.com/show_bug.cgi?id=1270399
  * https://bugzilla.suse.com/show_bug.cgi?id=1271192
  * https://bugzilla.suse.com/show_bug.cgi?id=1271330
  * https://bugzilla.suse.com/show_bug.cgi?id=1271428
  * https://bugzilla.suse.com/show_bug.cgi?id=1271613
  * https://bugzilla.suse.com/show_bug.cgi?id=1272008
  * https://bugzilla.suse.com/show_bug.cgi?id=1272102
  * https://bugzilla.suse.com/show_bug.cgi?id=1272427
  * https://bugzilla.suse.com/show_bug.cgi?id=1273094
  * https://bugzilla.suse.com/show_bug.cgi?id=1273144
  * https://bugzilla.suse.com/show_bug.cgi?id=1274217
  * https://bugzilla.suse.com/show_bug.cgi?id=1274221
  * https://bugzilla.suse.com/show_bug.cgi?id=1275205
  * https://bugzilla.suse.com/show_bug.cgi?id=1275206
  * https://bugzilla.suse.com/show_bug.cgi?id=1275207
  * https://bugzilla.suse.com/show_bug.cgi?id=1275934
  * https://bugzilla.suse.com/show_bug.cgi?id=1276426
  * https://bugzilla.suse.com/show_bug.cgi?id=1276658
  * https://bugzilla.suse.com/show_bug.cgi?id=1276973
  * https://bugzilla.suse.com/show_bug.cgi?id=1277025
  * https://bugzilla.suse.com/show_bug.cgi?id=1278307
  * https://bugzilla.suse.com/show_bug.cgi?id=1278322
  * https://jira.suse.com/browse/MSQA-1060
  * https://jira.suse.com/browse/PED-16707

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20261008/2bd02702/attachment.htm>


More information about the sle-security-updates mailing list