SUSE-RU-2026:23471-1: important: Recommended update for s390-tools
SLE-UPDATES
null at suse.de
Wed Sep 9 13:40:13 UTC 2026
# Recommended update for s390-tools
Announcement ID: SUSE-RU-2026:23471-1
Release Date: 2026-09-01T15:58:44Z
Rating: important
References:
* bsc#1273041
* bsc#1275476
* jsc#PED-14586
Affected Products:
* SUSE Linux Micro 6.2
An update that contains one feature and has two fixes can now be installed.
## Description:
This update for s390-tools fixes the following issues:
* Security vulnerabilities for `zkey` and friends (bsc#1275476).
* Fixes:
* zkey: Harden KMS config directory handling - Commit `0eef784`
* zkey: Harden `zkey kms unbind` command - Commit `1b90d15`
* zkey/ekmfweb, zkey/kmip: Harden KMS plugin file handling - Commit `bc81c32`
* Re-vendor `vendor.tar.zst`.
* Upgrade s390-tools to version 2.44.0 for Linux kernel version: 7.2
(jsc#PED-14586).
* Changes of existing tools / libraries:
* `create-sehdr`: Enable quantum safe keys usage
* `dbginfo.sh`: Let `zpcimon` log both optical module and SMART data
* `libutil`/`util_fmt`: Add `util_fmt_type_to_name()`
* `nvmemon`: Skip SCLP on NVMes with non-IBM subsystem vendor ID
* `opticsmon`: `zpcimon`: Rename `opticsmon` to `zpcimon`
* `pvattest`: Enable quantum safe keys usage
* `pvimg`: Add `--flags <...>` and `--disable-flags <...>` option
* `pvimg`: Enable quantum safe keys usage
* `pvsecret`: Enable quantum safe keys usage
* `pvverify`: Enable quantum safe keys usage
* `zmemtopo`: Add CLI option to filter partitions by name
* `zpcimon`: Allow setting output format using `--format` CLI option
* `zpcimon`: Monitor for hotplug of NVMes to trigger SMART collection
* Bug Fixes:
* `opticsmon`: Fix wrong size check for `OPTICS_QSFP28_LOS_IMPLEMENTED_OFFSET`
* `opticsmon`: Handle error return of `ethtool_nl_connect()`
* `opticsmon`: Fix error path free of `struct optics` in `ethtool_nl_get_optics()`
* `opticsmon`: Close `epoll fd` in `monitor_wait_loop()`
* `opticsmon`: Fix wrong JSON print for `tx_fault`
* s390-tools version 2.43.1:
* Changes of existing tools:
* `dasdfmt`: Check disk type before prompting for blocksize
* `iucvterm`/`ts-shell`: Introduce config parameter to specify `iucvconn` binary
* `iucvterm`/`ts-shell`: Introduce pager config to replace env variable
* `pv`: Add root CA organization pinning to certificate verification
* `zdump`/`ngdump`: Use OpenSSL's SHA256 to compute digest of dump image
* Bug Fixes:
* `95sel-ebc`: Add `udev-settle` dependency
* `95sel-ebc`: Add `umount` to boot service
* `95sel-ebc`: Harden boot mount service
* `fdasd`: Fix memory leak in `yes_no()` function
* `iucvterm`/`iucvtty`: Ensure PTY and server fd's are closed at `exec`
* `iucvterm`/`iucvtty`: Prevent connection stalls when receiving `TERM` env
* `iucvterm`/`iucvtty`: Validate `TERM` environment name
* `libkmipclient`: Protect from symlink-following attacks
* `libkmipclient`: Various bugfixes
* `libseckey`: Protect from symlink-following attacks
* `libseckey`: Various bugfixes
* `mon_procd`: Fix possible static buffer overflow
* `osasnmpd`: Fix SNMP non-compliance
* `zdev`: Harden against invalid `udev`, import, firmware, or hypervisor data
* `zipl-editenv`: Check in-bootmap environment block validity
* `zipl`/`boot`: Check in-bootmap environment block syntax
* `zipl`: Check keyword duplications in BLS entries
* `zipl`: Fix bugs in mirror support
* `zkey`: Protect from symlink-following attacks
* Amended the `.spec` file for dependencies (bsc#1273041):
* Added `BuildRequires: zlib-devel` and `BuildRequires: libudev-devel` for
SLES 16.x completeness.
* Added `Requires: iproute2` and `Recommends: cryptsetup, mdevctl, multipath-
tools, net-tools-deprecated` to the main package.
* Corrected recommended package name `sg3-utils` to `sg3_utils`.
* Added/updated `Requires: fuse3` for the FUSE-dependent subpackages `zdsfs`
and `hmcdrvfs`.
* Added `Recommends: snmpd` to the `osasnmpd` subpackage.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Micro 6.2
zypper in -t patch SUSE-SL-Micro-6.2-1580=1
## Package List:
* SUSE Linux Micro 6.2 (s390x)
* s390-tools-2.44.0-160000.1.1
* libkmipclient1-debuginfo-2.44.0-160000.1.1
* s390-tools-debugsource-2.44.0-160000.1.1
* libekmfweb1-debuginfo-2.44.0-160000.1.1
* libkmipclient1-2.44.0-160000.1.1
* s390-tools-debuginfo-2.44.0-160000.1.1
* libekmfweb1-2.44.0-160000.1.1
* SUSE Linux Micro 6.2 (noarch)
* s390-tools-chreipl-fcp-mpath-2.44.0-160000.1.1
* s390-tools-genprotimg-data-2.44.0-160000.1.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id=1273041
* https://bugzilla.suse.com/show_bug.cgi?id=1275476
* https://jira.suse.com/browse/PED-14586
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260909/bc5eb897/attachment-0001.htm>
More information about the sle-updates
mailing list