<div class="container">
<h1>Security update 5.1.4 for Multi-Linux Manager Client Tools</h1>
<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2026:2765-1</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2026-07-06T07:47:16Z</td>
</tr>
<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1227579">bsc#1227579</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1235516">bsc#1235516</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1236516">bsc#1236516</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1238686">bsc#1238686</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1248699">bsc#1248699</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1248707">bsc#1248707</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1249532">bsc#1249532</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1253174">bsc#1253174</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1254900">bsc#1254900</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1255418">bsc#1255418</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1257583">bsc#1257583</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1259700">bsc#1259700</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1261810">bsc#1261810</a>
</li>
<li style="display: inline;">
<a href="https://jira.suse.com/browse/MSQA-1056">jsc#MSQA-1056</a>
</li>
<li style="display: inline;">
<a href="https://jira.suse.com/browse/PED-12485">jsc#PED-12485</a>
</li>
<li style="display: inline;">
<a href="https://jira.suse.com/browse/PED-7893">jsc#PED-7893</a>
</li>
<li style="display: inline;">
<a href="https://jira.suse.com/browse/PED-7928">jsc#PED-7928</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>
Cross-References:
</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2022-21698.html">CVE-2022-21698</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2023-45288.html">CVE-2023-45288</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2025-22870.html">CVE-2025-22870</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">
<li class="list-group-item">
<span class="cvss-reference">CVE-2022-21698</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2022-21698</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-45288</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">6.9</span>
<span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-45288</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.3</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2023-45288</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.5</span>
<span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2025-22870</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">4.8</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2025-22870</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">4.4</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2025-22870</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">4.4</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L</span>
</li>
</ul>
</td>
</tr>
<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">
<li class="list-group-item">SUSE Liberty Linux 7</li>
<li class="list-group-item">SUSE Liberty Linux 7 LTSS</li>
<li class="list-group-item">SUSE Liberty Linux LTSS 7 for Oracle Linux</li>
<li class="list-group-item">SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>An update that solves three vulnerabilities, contains four features and has 10 security fixes can now be installed.</p>
<h2>Description:</h2>
<p>This update fixes the following issues:</p>
<p>golang-github-QubitProducts-exporter_exporter:</p>
<ul>
<li>Security issue fixed:</li>
<li>CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter
(bsc#1248699)</li>
</ul>
<p>golang-github-lusitaniae-apache_exporter:</p>
<ul>
<li>Non customer facing changes</li>
</ul>
<p>golang-github-prometheus-node_exporter updated to version 1.10.2:</p>
<ul>
<li>
<p>Security issues fixed:</p>
<ul>
<li>CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686)</li>
<li>CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516)</li>
</ul>
</li>
<li>
<p>Highlights of other changes and bug fixes:</p>
</li>
<li>
<p>Backward Compatibility and packaging changes:</p>
<ul>
<li>Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains</li>
<li>Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility</li>
</ul>
</li>
<li>Version 1.10.2:<ul>
<li>Fixed typo in Zswap metric name (meminfo)</li>
</ul>
</li>
<li>Version 1.10.1:<ul>
<li>Fixed mount points being collected multiple times (filesystem)</li>
<li>Refactored mountinfo parsing (bsc#1261810)</li>
<li>Added Zswap/Zswapped metrics (meminfo)</li>
</ul>
</li>
<li>Version 1.10.0:<ul>
<li>New collectors: PCIe devices, swaps</li>
<li>Added systemd virtualization metrics, AIX metrics</li>
<li>WiFi packet metrics, additional PCIe and TLB metrics</li>
<li>Changed mdadm to use sysfs, added erofs to excluded filesystems</li>
<li>Fixed bugs: cpufreq collector, ethtool metrics</li>
</ul>
</li>
<li>Version 1.9.1:<ul>
<li>Fixed missing IRQ on older kernels (pressure)</li>
</ul>
</li>
<li>Version 1.9.0 (jsc#PED-12485):<ul>
<li>Switched to Go log/slog for logging</li>
<li>Converted meminfo to use procfs library</li>
<li>New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics,
hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support,</li>
<li>Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance
optimizations</li>
<li>Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing</li>
<li>Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516)</li>
</ul>
</li>
<li>Version 1.8.x:<ul>
<li>Fixed CPU pressure metric collection, pressure collector nil reference</li>
</ul>
</li>
<li>Version 1.8.0:<ul>
<li>New collectors: xfrm (IPsec), watchdog</li>
<li>Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing</li>
<li>Removed caching of os-release file modtime/filename</li>
<li>Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race</li>
</ul>
</li>
<li>Version 1.7.0 (jsc#PED-7893, jsc#PED-7928):<ul>
<li>New: CPU vulnerabilities reporting from sysfs</li>
<li>Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values,
qdisc performance, hwmon filtering, rtnetlink for ARP stats</li>
<li>Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index</li>
</ul>
</li>
<li>Version 1.6.0:<ul>
<li>Deprecated ntp and supervisord collectors</li>
<li>Removed bcache cache_readaheads_totals metrics</li>
<li>Improved offline CPU handling (removed metrics for offline CPUs)</li>
<li>New: softirqs collector</li>
<li>Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced
btrfs privileges</li>
<li>Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts</li>
</ul>
</li>
</ul>
<p>mgr-push updated to version 5.2.4:</p>
<ul>
<li>Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0)</li>
</ul>
<p>prometheus-postgres_exporter:</p>
<ul>
<li>Security issue fixed:</li>
<li>CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699)</li>
</ul>
<p>python-simplejson:</p>
<ul>
<li>Non customer facing changes</li>
</ul>
<p>rhnlib updated to version 5.2.5:</p>
<ul>
<li>Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0)</li>
</ul>
<p>spacecmd updated to version 5.2.8:</p>
<ul>
<li>Key Update Highlights (v5.2.3-0):</li>
<li>Fixed typo in spacecmd help ca-cert flag (bsc#1253174)</li>
<li>Add subcommand to check if reboot is needed after applying all available patches</li>
<li>Key Update Highlights (v5.2.1-0):</li>
<li>Use JSON instead of pickle for spacecmd cache (bsc#1227579)</li>
<li>Fixed methods in api namespace in spacecmd (bsc#1249532)</li>
<li>Other changes (v5.2.2-0 to 5.2.8-0):</li>
<li>Translation strings updates</li>
<li>Internal updates with non customer facing changes</li>
</ul>
<p>spacewalk-client-tools updated to version 5.2.6:</p>
<ul>
<li>Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0)</li>
</ul>
<p>uyuni-common-libs updated to version 5.2.5:</p>
<ul>
<li>Key Update Highlights (v5.2.5-0):</li>
<li>Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using
standard hashlib directly</li>
<li>Other changes:</li>
<li>Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0)</li>
</ul>
<p>venv-salt-minion:</p>
<ul>
<li>Improved shutdown reliability when the salt-master/minion is terminated</li>
<li>Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil</li>
<li>Calculate UUID grain for Xen PV guests (bsc#1255418)</li>
<li>Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700)</li>
<li>Hardened Tornado from invalid HTTP reason phrases</li>
<li>Read full URI from ldap pillar config (bsc#1254900)</li>
</ul>
<h2>Special Instructions and Notes:</h2>
<ul>
</ul>
<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">
<li class="list-group-item">
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones
<br/>
<code>zypper in -t patch SUSE-MultiLinuxManagerTools-RES-7-2026-2765=1</code>
</li>
</ul>
<h2>Package List:</h2>
<ul>
<li>
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (aarch64 ppc64le x86_64)
<ul>
<li>python-simplejson-3.3.1-70002.1.3.1</li>
<li>venv-salt-minion-3006.0-70002.5.19.1</li>
<li>prometheus-postgres_exporter-0.10.1-70002.3.3.3</li>
<li>golang-github-lusitaniae-apache_exporter-1.0.10-70002.3.9.3</li>
<li>golang-github-prometheus-node_exporter-1.10.2-70002.3.3.3</li>
<li>golang-github-QubitProducts-exporter_exporter-0.4.0-70002.3.6.2</li>
</ul>
</li>
<li>
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (noarch)
<ul>
<li>spacewalk-client-tools-5.2.6-70002.3.9.1</li>
<li>mgr-push-5.2.4-70002.3.9.2</li>
<li>python2-rhnlib-5.2.5-70002.3.9.1</li>
<li>python2-uyuni-common-libs-5.2.5-70002.3.6.1</li>
<li>spacecmd-5.2.8-70002.3.12.1</li>
<li>python2-spacewalk-client-tools-5.2.6-70002.3.9.1</li>
<li>python2-mgr-push-5.2.4-70002.3.9.2</li>
</ul>
</li>
</ul>
<h2>References:</h2>
<ul>
<li>
<a href="https://www.suse.com/security/cve/CVE-2022-21698.html">https://www.suse.com/security/cve/CVE-2022-21698.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2023-45288.html">https://www.suse.com/security/cve/CVE-2023-45288.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2025-22870.html">https://www.suse.com/security/cve/CVE-2025-22870.html</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1227579">https://bugzilla.suse.com/show_bug.cgi?id=1227579</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1235516">https://bugzilla.suse.com/show_bug.cgi?id=1235516</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1236516">https://bugzilla.suse.com/show_bug.cgi?id=1236516</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1238686">https://bugzilla.suse.com/show_bug.cgi?id=1238686</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1248699">https://bugzilla.suse.com/show_bug.cgi?id=1248699</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1248707">https://bugzilla.suse.com/show_bug.cgi?id=1248707</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1249532">https://bugzilla.suse.com/show_bug.cgi?id=1249532</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1253174">https://bugzilla.suse.com/show_bug.cgi?id=1253174</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1254900">https://bugzilla.suse.com/show_bug.cgi?id=1254900</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1255418">https://bugzilla.suse.com/show_bug.cgi?id=1255418</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1257583">https://bugzilla.suse.com/show_bug.cgi?id=1257583</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1259700">https://bugzilla.suse.com/show_bug.cgi?id=1259700</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1261810">https://bugzilla.suse.com/show_bug.cgi?id=1261810</a>
</li>
<li>
<a href="https://jira.suse.com/browse/MSQA-1056">https://jira.suse.com/browse/MSQA-1056</a>
</li>
<li>
<a href="https://jira.suse.com/browse/PED-12485">https://jira.suse.com/browse/PED-12485</a>
</li>
<li>
<a href="https://jira.suse.com/browse/PED-7893">https://jira.suse.com/browse/PED-7893</a>
</li>
<li>
<a href="https://jira.suse.com/browse/PED-7928">https://jira.suse.com/browse/PED-7928</a>
</li>
</ul>
</div>