From null at suse.de Thu Oct 8 12:31:18 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 12:31:18 -0000 Subject: SUSE-SU-2026:4576-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179146267884.23937.10115925493267256092@f42c2f07aca2> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4576-1 Release Date: 2026-10-08T08:09:52Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#ECO-3319 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 An update that solves 32 vulnerabilities, contains two features and has 15 security fixes can now be installed. ## Description: This update fixes the following issues: scap-security-guide was updated to version 0.1.79 (jsc#ECO-3319): * Added SLE16 profiles to the build * Create SLE16 HIPAA profile * Create SLE16 PCI DSS 4 profile * Use Sequoia in RHEL 10 instead of GPG * Added new Profile for RHEL10: BSI * Move RHEL Control files to product files * Updated RHEL 9 CCN profile * Various updates for SLE 12/15 spacecmd was updated to version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 zypper in -t patch SUSE-MultiLinuxManagerTools-Ubuntu-22.04-2026-4576 ## Package List: * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 (amd64) * venv-salt-minion-3006.0-220402.3.28.1 * mgrctl-5.2.17-220402.3.21.2 * SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04 2204 (all) * mgrctl-fish-completion-5.2.17-220402.3.21.2 * mgrctl-zsh-completion-5.2.17-220402.3.21.2 * spacecmd-5.2.10-220402.3.21.2 * scap-security-guide-ubuntu-0.1.80-220402.2.15.2 * mgrctl-bash-completion-5.2.17-220402.3.21.2 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/ECO-3319 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 12:32:26 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 12:32:26 -0000 Subject: SUSE-SU-2026:4575-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179146274681.23937.2050220053555297608@f42c2f07aca2> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4575-1 Release Date: 2026-10-08T08:08:46Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 An update that solves 32 vulnerabilities, contains one feature and has 15 security fixes can now be installed. ## Description: This update fixes the following issues: spacecmd was updated to version 5.2.10: * Version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Version 5.2.9: * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) - fixed in 5.2.17-0 Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 zypper in -t patch SUSE-MultiLinuxManagerTools-Ubuntu-24.04-2026-4575 ## Package List: * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 (amd64) * venv-salt-minion-3006.0-240402.3.28.1 * mgrctl-5.2.17-240402.3.21.2 * SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04 2404 (all) * spacecmd-5.2.10-240402.3.26.3 * mgrctl-fish-completion-5.2.17-240402.3.21.2 * mgrctl-zsh-completion-5.2.17-240402.3.21.2 * mgrctl-bash-completion-5.2.17-240402.3.21.2 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 12:34:29 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 12:34:29 -0000 Subject: SUSE-SU-2026:4571-1: important: Maintenance update for Multi-Linux Manager 5.2: Server, Proxy and Retail Branch Server Message-ID: <179146286988.23937.7071703999498262797@f42c2f07aca2> # Maintenance update for Multi-Linux Manager 5.2: Server, Proxy and Retail Branch Server Announcement ID: SUSE-SU-2026:4571-1 Release Date: 2026-10-08T08:02:36Z Rating: important References: * bsc#1208800 * bsc#1230568 * bsc#1230949 * bsc#1252286 * bsc#1257151 * bsc#1258382 * bsc#1258500 * bsc#1258567 * bsc#1259225 * bsc#1260342 * bsc#1262157 * bsc#1263822 * bsc#1265219 * bsc#1265472 * bsc#1266481 * bsc#1267261 * bsc#1267871 * bsc#1267912 * bsc#1268228 * bsc#1268325 * bsc#1268473 * bsc#1268587 * bsc#1268673 * bsc#1268755 * bsc#1269192 * bsc#1269253 * bsc#1269316 * bsc#1269534 * bsc#1269679 * bsc#1270033 * bsc#1270039 * bsc#1270040 * bsc#1270047 * bsc#1270141 * bsc#1270694 * bsc#1271075 * bsc#1271116 * bsc#1271124 * bsc#1271329 * bsc#1271332 * bsc#1271382 * bsc#1271467 * bsc#1271523 * bsc#1271678 * bsc#1271681 * bsc#1271841 * bsc#1271902 * bsc#1271963 * bsc#1272298 * bsc#1272392 * bsc#1272404 * bsc#1272538 * bsc#1272621 * bsc#1272988 * bsc#1273073 * bsc#1273131 * bsc#1273144 * bsc#1273846 * bsc#1273853 * bsc#1274023 * bsc#1274227 * bsc#1274613 * bsc#1274720 * bsc#1274775 * jsc#MSQA-1060 Cross-References: * CVE-2026-39821 * CVE-2026-63007 * CVE-2026-63009 * CVE-2026-71400 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-71400 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-71400 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE * SUSE Multi-Linux Manager Server 5.2 Extension for SLE An update that solves four vulnerabilities, contains one feature and has 60 security fixes can now be installed. ## Security update 5.2.1 for Multi-Linux Manager Proxy ### Description: This update fixes the following issues: Release notese highlights: * Added a note about the SUSE Registry IP address change. * Update to SUSE Multi-Linux Manager 5.2.1 * Security issues Fixed: CVE-2026-39821 * Bugs mentioned bsc#1208800, bsc#1230568, bsc#1230949, bsc#1258382, bsc#1266481 bsc#1268755, bsc#1270033, bsc#1273131, bsc#1273144, bsc#1273846 bsc#1274613, bsc#1274775 Container images and uyuni-tools changes: proxy-httpd-image: * Version 5.2.10 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-salt-broker-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-squid-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-ssh-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-tftpd-image: * Version 5.2.10 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 uyuni-tools: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) * Version 5.2.17-0 * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) The following packages are underlying build dependencies and system components used by the containers: spacewalk-backend: * Version 5.2.10-0 * Allow diskcheck env vars into containers (bsc#1270033) * Use sha256 as the default checksum type for Debian repositories * Remove token based authentication mechanism for package_push (bsc#1230949) * Fix gpgverify signature file check for file object (bsc#1273131) * Allow using spacewalk-diskcheck without running service * Increase errata advisory char limit to 150 (bsc#1273846) * Use cryptographically secure random generation for secrets (bsc#1230568) spacewalk-proxy: * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.6-0 * Version 5.2.5-0 * Remove salt dependency from spacewalk-proxy-salt package How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Security update 5.2.1 for Multi-Linux Manager Retail Branch Server ### Description: This update fixes the following issues: Release notese highlights: * Added a note about the SUSE Registry IP address change. * Update to SUSE Multi-Linux Manager 5.2.1 * Security issues Fixed: CVE-2026-39821 * Bugs mentioned bsc#1208800, bsc#1230568, bsc#1230949, bsc#1258382, bsc#1266481 bsc#1268755, bsc#1270033, bsc#1273131, bsc#1273144, bsc#1273846 bsc#1274613, bsc#1274775 Container images and uyuni-tools changes: proxy-httpd-image: * Version 5.2.10 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-salt-broker-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-squid-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-ssh-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-tftpd-image: * Version 5.2.10 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 uyuni-tools: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) * Version 5.2.17-0 * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) The following packages are underlying build dependencies and system components used by the containers: spacewalk-backend: * Version 5.2.10-0 * Allow diskcheck env vars into containers (bsc#1270033) * Use sha256 as the default checksum type for Debian repositories * Remove token based authentication mechanism for package_push (bsc#1230949) * Fix gpgverify signature file check for file object (bsc#1273131) * Allow using spacewalk-diskcheck without running service * Increase errata advisory char limit to 150 (bsc#1273846) * Use cryptographically secure random generation for secrets (bsc#1230568) spacewalk-proxy: * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.6-0 * Version 5.2.5-0 * Remove salt dependency from spacewalk-proxy-salt package How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Security update 5.2.1 for Multi-Linux Manager Server ### Description: This update fixes the following issues: Release Notes Highlights: * Added a note about the SUSE Registry IP address change. * Update to SUSE Multi-Linux Manager 5.2.1 * Security fixes * Ubuntu 26.04 LTS Support * Confidential Computing Attestation for IBM Z Series * New uyuni-tftpd Container * Monitoring: Prometheus upgraded to 3.13.2 * Monitoring: Grafana upgraded to 12.4.10 * CVEs Fixed: CVE-2023-45289, CVE-2024-22195, CVE-2025-12141, CVE-2025-13836 CVE-2025-61686, CVE-2026-15308, CVE-2026-21723, CVE-2026-40181 CVE-2026-11940, CVE-2026-11972, CVE-2026-13346, CVE-2026-14199 CVE-2026-17033, CVE-2026-17183, CVE-2026-19197, CVE-2026-19475 CVE-2026-27459, CVE-2026-33814, CVE-2026-39821, CVE-2026-39882 CVE-2026-40475, CVE-2026-41066, CVE-2026-41178, CVE-2026-41606 CVE-2026-42211, CVE-2026-42342, CVE-2026-44431, CVE-2026-44990 CVE-2026-49825, CVE-2026-49853, CVE-2026-49854, CVE-2026-49855 CVE-2026-56852, CVE-2026-63007, CVE-2026-63009, CVE-2026-71400 CVE-2026-42127, CVE-2026-45409, CVE-2026-53606, CVE-2026-73501 CVE-2025-4673, CVE-2026-0864, CVE-2026-1229, CVE-2026-1502 CVE-2026-1703, CVE-2026-2303, CVE-2026-3219, CVE-2026-3276 Container images and uyuni-tools changes: proxy-tftpd-image: * Updated to version 5.2.10 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-attestation-image: * Version 5.2.11 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-database-migration-image: * Version 5.2.6 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-hub-xmlrpc-api-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-image: * Version 5.2.15 * Increase start-period (bsc#1271124) * Check disk space on startup * Use correct healthcheck cmd (bsc#1273144) * Detect an existing cgroup2 mount by filesystem type, not mountpoint. server-postgresql-image: * Version 5.2.13 * Automatically set the log timezone for TZ env (bsc#1267871) * Increase start-period and timeout (bsc#1271124) * Check disk space on startup server-saline-image: * Version 5.2.11 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 uyuni-tools: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) * Version 5.2.17-0 * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) The following packages are underlying build dependencies and system components used by the containers: apache-commons-fileupload2: * Updated to version 2.0.0-M5 * Add AbstractFileUpload support for a maximum part header size * FILEUPLOAD-367: Jakarta and Javax ServletFileUpload .isMultipartContent(HttpServletRequest) should allow PUT and PATCH request methods in addition to POST * FILEUPLOAD-367: Add AbstractFileUpload .isMultipartRequestMethod(String) * FILEUPLOAD-295: Clarified the precise meaning of isInMemory(), get(), getPath(), etc. in DiskFileItem * Better exception type and message if a multipart/mixed part is presented without a boundary defined * Bump org.apache.commons:commons-parent from 84 to 96 * Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0 * Bump commons-io:commons-io from 2.19.0 to 2.21.0 byte-buddy: * Updated to version 1.18.8 * Introduce new versioning concept with -jdk5 suffix for backwards-compatible jar and Java 8 baseline for regular jar * Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted * Add super classes to hash code / equals computation in Advice that were missing * Add support for new build description in Android 9 mgr-push: * Version 5.2.5-0 * Remove token based authentication mechanism for package_push (bsc#1230949) objectweb-asm: * Updated to version 9.10.1 * New Opcodes.V27 constant for Java 27 python-susemanager-retail: * Version 1.2.1 * Fix issue building package on SLES 16.0 salt: * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) spacecmd: * Version 5.2.10-0 * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) spacewalk-backend: * Version 5.2.10-0 * Allow diskcheck env vars into containers (bsc#1270033) * Use sha256 as the default checksum type for Debian repositories * Remove token based authentication mechanism for package_push (bsc#1230949) * Fix gpgverify signature file check for file object (bsc#1273131) * Allow using spacewalk-diskcheck without running service * Increase errata advisory char limit to 150 (bsc#1273846) * Use cryptographically secure random generation for secrets (bsc#1230568) spacewalk-branding: * Version 5.2.7-0 * No customer facing changes spacewalk-client-tools: * Version 5.2.7-0 * Update translation strings spacewalk-config: * Version 5.2.5-0 * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) spacewalk-java: * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.21-0 * CVE-2026-63007: Check access rights on two formula API calls (bsc#1269253) - fixed in 5.2.20-0 * CVE-2026-63009: Sanitize uploaded image name (bsc#1269534) - fixed in 5.2.20-0 * Updated to version 5.2.22-0 * Restored the original reset behavior in isDryRun() by swapping subscribedChannels and unsubscribedChannels back (bsc#1271681) * Fix mainframe foreign systems showing wrong OS (bsc#1260342) * Make setting of column filters in ListTag idempotent (bsc#1269192) * Fix hubsync package download checksum lookup (bsc#1270040) * Many to many relationships should not cascade deletion (bsc#1272392) * Optimized channel model generation logic to improve page load performance during peripheral channel selection (bsc#1259225) * Fixed Hibernate issue when updating the SSL content sources during a pay-as- you-go connection data refresh (bsc#1271382) * Allow diskcheck env vars into containers (bsc#1270033) * Query only systems for virtual machines which are flagged as virtualization hosts (bsc#1273073) * Use Channel equality even for ClonedChannel (bsc#1272621) * Fix EOL notifications in containers * Fix config channel position gaps (bsc#1272988) * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039) * Prevent cascading package operations to checksums (bsc#1272392) * Fixed custom RBAC role names being incorrectly localized. (bsc#1271116) * Do not add FQDNs from proxy certificate (bsc#1270141, bsc#1272404) * Do not crash on conflicting FQDNs, add error message * Add delay to package clean to not interfere with repo-sync (bsc#1258500) * Improve handling of invalid issue_date values when creating CLM filters via the API. (bsc#1271467) * Wait for taskomatic before processing events (bsc#1265472) * Use the standard Bootstrap 5 row class in place of legacy layout classes. * Remove udevdb salt module leftovers, udev is used now * Fix Hibernate session crash on Errata Sync by dynamically loading default access groups from the active session (bsc#1272298) * Fix Profile tab display in system details menu (bsc#1271963) spacewalk-search: * Version 5.2.6-0 * No customer facing changes spacewalk-utils: * Version 5.2.8-0 * Taskotop now handles timezone (bsc#1267871) spacewalk-web: * Version 5.2.14-0 * Improve product selection checkboxes in the setup UI * Show partial selection state for product trees more accurately * Fixed the "Clear selected system set" button flickering during page navigation. (bsc#1271523) * Add web.version.eol setting to provide an end of life date * Fix duplicate remaining characters label in the Create Custom Info Key description field. (bsc#1269679) * Improve handling of invalid issue_date values when creating CLM filters via the API. (bsc#1271467) * Refactor checkboxes in the RBAC UI * Reuse common Check component * Use the standard Bootstrap 5 row class in place of legacy layout classes. struts: * Fix JakartaServletFileUpload as setFileSizeMax was renamed to setMaxFileSize * Use explicite same java version as spacewalk-java to get around "class file has wrong version" errors subscription-matcher: * Updated to version 0.47 * Added missing part numbers (bsc#1274227, bsc#1265219) * Fix unsupported part number (bsc#1271075) supportutils-plugin-susemanager: * Version 5.2.3-0 * Allow 100 connection difference for apache and tomcat * Fix reading connections from the correct source * Add reportdb connections to the database connection limit (bsc#1262157) susemanager: * Version 5.2.10-0 * Add Ubuntu 26.04 LTS susemanager-build-keys: * Update SUSE addon key - extended validity susemanager-docs_en: * Documented requirements and limitations for container image inspection on SLES 15 and SLES 16 (bsc#1274720) * Documented proxy certificate replacement using spacecmd (bsc#1271329) * Documented certificate setup and rotation with unified mgradm ssl rotate command * Documented allowing diskcheck environment variables into containers (bsc#1270033) * Clarified availability of Salt's "virt" module in the Salt Bundle (bsc#1270694) * Added instruction for obtaining the certificate when renaming the server (bsc#1273853) * Added a common workflow for certificate setup and rotation with ACME * Documented how VMs are listed and referenced by virtual hosts (bsc#1273073) * Added documentation support for Ubuntu 26.04 client systems * Added the missing TFTP image in airgap install command * Fixed procedures for OpenSCAP in Administration Guide (bsc#1270047) * Fixed the snippet to reflect the correct produst version (bsc#1272538) * Corrected verification step order in MLM 5.0 to 5.2 upgrade guide for SL- Micro (bsc#1271678) * Extended configuration instructions for Saline formula in Specialized Guides (bsc#1268587) * Enhanced instructions for Liberate formula and reactivation key in Specialized Guides (bsc#1268473) * Fixed missing line end escapes in kubernetes helm install commands * Consolidated multiple duplicated activation key creation procedures into a single reusable partial snippet * Fixed Traefik installation documentation in Specialized Guides * Clarified CA certificate migration requirements (bsc#1271841) * Added instructions for enabling reporting dashboards in Specialized Guides (bsc#1268228) * Remove legacy mgradm and mgrpxy commands * Added the --set tag parameter to helm install/upgrade commands as a workaround (bsc#1271902) * Documented apache2 parameter used for large deployments (bsc#1268673) * Documented Grafana reporting database automated setup and Hub Overview in Administration and Specialized Guides * Update the OpenSCAP packages table in the System Security with OpenSCAP article in the Administration guide (bsc#1269316) * Added documentation for migrating legacy ISS v1 and ISS v2 peripheral servers to ISS v3 (Hub Online Synchronization) and detailed Report DB/XMLRPC API dependencies in Specialized Guides * Documented SLES 15 SP7 to SLES 16.0 major upgrade via product migration in Client Configuration Guide susemanager-schema: * Version 5.2.14-0 * Updated tables for CoCo attestation restructuring * Use temp table for hidden packages (bsc#1267912) * Renumber config channel positions to close gaps left by deleting an assigned config channel (ON DELETE CASCADE did not compact the survivors), preventing multiple failures (bsc#1272988) * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039) * Increase advisory char limit to 150 in rhnErrata (bsc#1273846) * RBAC: add missing endpoints to 'systems.profiles' namespace (bsc#1271963) susemanager-sls: * Version 5.2.15-0 * Propagate cert validation errors to UI (bsc#1271332) * Fix cleanup timeout when deleting minions (bsc#1258567) * Fix salt deletion on SSH minions (bsc#1274023) * Set podman secrets for proxy directly from salt * Fix migration of jmx conf (bsc#1268755) * Remove unused udevdb salt module as upstream udev is used susemanager-sync-data: * Version 5.2.6-0 * Add Ubuntu 26.04 LTS uyuni-coco-attestation: * Version 5.2.7-0 * Ensure the certs directory is always created * Allow pvattest module to be built on s390x uyuni-java-common: * Version 5.2.7-0 * No customer facing changes uyuni-java-parent: * Version 5.2.7-0 * No customer facing changes How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgradm upgrade podman` which will use the default image tags. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Proxy-SLE-5.2-2026-4571 * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Retail-Branch-Server- SLE-5.2-2026-4571 * SUSE Multi-Linux Manager Server 5.2 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Server-SLE-5.2-2026-4571 ## Package List: * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-5.2.17-150750.3.3.8 * mgrpxy-debuginfo-5.2.17-150750.3.3.8 * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (noarch) * mgrpxy-zsh-completion-5.2.17-150750.3.3.8 * mgrpxy-bash-completion-5.2.17-150750.3.3.8 * mgrpxy-lang-5.2.17-150750.3.3.8 * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (x86_64) * suse-multi-linux-manager-5.2-x86_64-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-x86_64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-ssh-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (s390x) * suse-multi-linux-manager-5.2-s390x-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-httpd-image-5.2.1-9.3.30 * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.2-ppc64le-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-ppc64le-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-squid-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Proxy 5.2 Extension for SLE (aarch64) * suse-multi-linux-manager-5.2-aarch64-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-aarch64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-salt-broker-image-5.2.1-9.3.19 * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-5.2.17-150750.3.3.8 * mgrpxy-debuginfo-5.2.17-150750.3.3.8 * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (noarch) * mgrpxy-zsh-completion-5.2.17-150750.3.3.8 * mgrpxy-bash-completion-5.2.17-150750.3.3.8 * mgrpxy-lang-5.2.17-150750.3.3.8 * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (x86_64) * suse-multi-linux-manager-5.2-x86_64-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-x86_64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-ssh-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (s390x) * suse-multi-linux-manager-5.2-s390x-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-httpd-image-5.2.1-9.3.30 * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.2-ppc64le-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-ppc64le-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-squid-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Retail Branch Server 5.2 Extension for SLE (aarch64) * suse-multi-linux-manager-5.2-aarch64-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-aarch64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-salt-broker-image-5.2.1-9.3.19 * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgradm-5.2.17-150750.3.3.8 * mgrctl-5.2.17-150750.3.3.8 * mgrctl-debuginfo-5.2.17-150750.3.3.8 * mgradm-debuginfo-5.2.17-150750.3.3.8 * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (noarch) * mgrctl-zsh-completion-5.2.17-150750.3.3.8 * mgrctl-lang-5.2.17-150750.3.3.8 * mgrctl-bash-completion-5.2.17-150750.3.3.8 * mgradm-zsh-completion-5.2.17-150750.3.3.8 * mgradm-lang-5.2.17-150750.3.3.8 * mgradm-bash-completion-5.2.17-150750.3.3.8 * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (x86_64) * suse-multi-linux-manager-5.2-x86_64-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-server-database-migration-image-5.2.1-7.3.16 * suse-multi-linux-manager-5.2-x86_64-server-saline-image-5.2.1-11.3.24 * suse-multi-linux-manager-5.2-x86_64-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-x86_64-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-x86_64-server-attestation-image-5.2.1-11.3.23 * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (s390x) * suse-multi-linux-manager-5.2-s390x-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-server-attestation-image-5.2.1-11.3.23 * suse-multi-linux-manager-5.2-s390x-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-s390x-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-s390x-server-database-migration-image-5.2.1-7.3.16 * suse-multi-linux-manager-5.2-s390x-server-saline-image-5.2.1-11.3.24 * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.2-ppc64le-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-ppc64le-server-attestation-image-5.2.1-11.3.23 * suse-multi-linux-manager-5.2-ppc64le-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-ppc64le-server-database-migration-image-5.2.1-7.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-ppc64le-server-saline-image-5.2.1-11.3.24 * SUSE Multi-Linux Manager Server 5.2 Extension for SLE (aarch64) * suse-multi-linux-manager-5.2-aarch64-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-aarch64-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-aarch64-server-saline-image-5.2.1-11.3.24 * suse-multi-linux-manager-5.2-aarch64-server-attestation-image-5.2.1-11.3.23 * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-aarch64-server-database-migration-image-5.2.1-7.3.16 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-63007.html * https://www.suse.com/security/cve/CVE-2026-63009.html * https://www.suse.com/security/cve/CVE-2026-71400.html * https://bugzilla.suse.com/show_bug.cgi?id=1208800 * https://bugzilla.suse.com/show_bug.cgi?id=1230568 * https://bugzilla.suse.com/show_bug.cgi?id=1230949 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1258382 * https://bugzilla.suse.com/show_bug.cgi?id=1258500 * https://bugzilla.suse.com/show_bug.cgi?id=1258567 * https://bugzilla.suse.com/show_bug.cgi?id=1259225 * https://bugzilla.suse.com/show_bug.cgi?id=1260342 * https://bugzilla.suse.com/show_bug.cgi?id=1262157 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1265219 * https://bugzilla.suse.com/show_bug.cgi?id=1265472 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267871 * https://bugzilla.suse.com/show_bug.cgi?id=1267912 * https://bugzilla.suse.com/show_bug.cgi?id=1268228 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268473 * https://bugzilla.suse.com/show_bug.cgi?id=1268587 * https://bugzilla.suse.com/show_bug.cgi?id=1268673 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1269192 * https://bugzilla.suse.com/show_bug.cgi?id=1269253 * https://bugzilla.suse.com/show_bug.cgi?id=1269316 * https://bugzilla.suse.com/show_bug.cgi?id=1269534 * https://bugzilla.suse.com/show_bug.cgi?id=1269679 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270039 * https://bugzilla.suse.com/show_bug.cgi?id=1270040 * https://bugzilla.suse.com/show_bug.cgi?id=1270047 * https://bugzilla.suse.com/show_bug.cgi?id=1270141 * https://bugzilla.suse.com/show_bug.cgi?id=1270694 * https://bugzilla.suse.com/show_bug.cgi?id=1271075 * https://bugzilla.suse.com/show_bug.cgi?id=1271116 * https://bugzilla.suse.com/show_bug.cgi?id=1271124 * https://bugzilla.suse.com/show_bug.cgi?id=1271329 * https://bugzilla.suse.com/show_bug.cgi?id=1271332 * https://bugzilla.suse.com/show_bug.cgi?id=1271382 * https://bugzilla.suse.com/show_bug.cgi?id=1271467 * https://bugzilla.suse.com/show_bug.cgi?id=1271523 * https://bugzilla.suse.com/show_bug.cgi?id=1271678 * https://bugzilla.suse.com/show_bug.cgi?id=1271681 * https://bugzilla.suse.com/show_bug.cgi?id=1271841 * https://bugzilla.suse.com/show_bug.cgi?id=1271902 * https://bugzilla.suse.com/show_bug.cgi?id=1271963 * https://bugzilla.suse.com/show_bug.cgi?id=1272298 * https://bugzilla.suse.com/show_bug.cgi?id=1272392 * https://bugzilla.suse.com/show_bug.cgi?id=1272404 * https://bugzilla.suse.com/show_bug.cgi?id=1272538 * https://bugzilla.suse.com/show_bug.cgi?id=1272621 * https://bugzilla.suse.com/show_bug.cgi?id=1272988 * https://bugzilla.suse.com/show_bug.cgi?id=1273073 * https://bugzilla.suse.com/show_bug.cgi?id=1273131 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://bugzilla.suse.com/show_bug.cgi?id=1273846 * https://bugzilla.suse.com/show_bug.cgi?id=1273853 * https://bugzilla.suse.com/show_bug.cgi?id=1274023 * https://bugzilla.suse.com/show_bug.cgi?id=1274227 * https://bugzilla.suse.com/show_bug.cgi?id=1274613 * https://bugzilla.suse.com/show_bug.cgi?id=1274720 * https://bugzilla.suse.com/show_bug.cgi?id=1274775 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:46:58 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:46:58 -0000 Subject: SUSE-SU-2026:24018-1: moderate: Security update 5.2.1 for Multi-Linux Manager Server, Proxy and Retail Branch Server Message-ID: <179147801822.421.13647877400583866456@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Server, Proxy and Retail Branch Server Announcement ID: SUSE-SU-2026:24018-1 Release Date: 2026-10-08T07:45:40Z Rating: moderate References: * bsc#1208800 * bsc#1230568 * bsc#1230949 * bsc#1252286 * bsc#1257151 * bsc#1258382 * bsc#1258500 * bsc#1258567 * bsc#1259225 * bsc#1260342 * bsc#1262157 * bsc#1263822 * bsc#1265219 * bsc#1265472 * bsc#1266481 * bsc#1267261 * bsc#1267871 * bsc#1267912 * bsc#1268228 * bsc#1268325 * bsc#1268473 * bsc#1268587 * bsc#1268673 * bsc#1268755 * bsc#1269192 * bsc#1269253 * bsc#1269316 * bsc#1269534 * bsc#1269679 * bsc#1270033 * bsc#1270039 * bsc#1270040 * bsc#1270047 * bsc#1270141 * bsc#1270694 * bsc#1271075 * bsc#1271116 * bsc#1271124 * bsc#1271329 * bsc#1271332 * bsc#1271382 * bsc#1271467 * bsc#1271523 * bsc#1271678 * bsc#1271681 * bsc#1271841 * bsc#1271902 * bsc#1271963 * bsc#1272298 * bsc#1272392 * bsc#1272404 * bsc#1272538 * bsc#1272621 * bsc#1272988 * bsc#1273073 * bsc#1273131 * bsc#1273144 * bsc#1273846 * bsc#1273853 * bsc#1274023 * bsc#1274227 * bsc#1274613 * bsc#1274720 * bsc#1274775 * jsc#MSQA-1060 Cross-References: * CVE-2026-39821 * CVE-2026-63007 * CVE-2026-63009 * CVE-2026-71400 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-71400 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-71400 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 * SUSE Multi-Linux Manager Proxy 5.2 * SUSE Multi-Linux Manager Retail Branch Server 5.2 * SUSE Multi-Linux Manager Server 5.2 An update that solves four vulnerabilities, contains one feature and has 60 fixes can now be installed. ## Security update 5.2.1 for Multi-Linux Manager Server, Proxy and Retail Branch Server ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.2.10 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-salt-broker-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-squid-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-ssh-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-tftpd-image: * Version 5.2.10 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 * Updated to version 5.2.10 server-attestation-image: * Version 5.2.11 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-database-migration-image: * Version 5.2.6 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-hub-xmlrpc-api-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-image: * Version 5.2.15 * Increase start-period (bsc#1271124) * Check disk space on startup * Use correct healthcheck cmd (bsc#1273144) * Detect an existing cgroup2 mount by filesystem type, not mountpoint. server-postgresql-image: * Version 5.2.13 * Automatically set the log timezone for TZ env (bsc#1267871) * Increase start-period and timeout (bsc#1271124) * Check disk space on startup server-saline-image: * Version 5.2.11 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 uyuni-tools: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) * Version 5.2.17-0 * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) The following packages are underlying build dependencies and system components used by the containers: apache-commons-fileupload2: * Updated to version 2.0.0-M5 * Add AbstractFileUpload support for a maximum part header size * FILEUPLOAD-367: Jakarta and Javax ServletFileUpload .isMultipartContent(HttpServletRequest) should allow PUT and PATCH request methods in addition to POST * FILEUPLOAD-367: Add AbstractFileUpload .isMultipartRequestMethod(String) * FILEUPLOAD-295: Clarified the precise meaning of isInMemory(), get(), getPath(), etc. in DiskFileItem * Better exception type and message if a multipart/mixed part is presented without a boundary defined * Bump org.apache.commons:commons-parent from 84 to 96 * Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0 * Bump commons-io:commons-io from 2.19.0 to 2.21.0 byte-buddy: * Updated to version 1.18.8 * Introduce new versioning concept with -jdk5 suffix for backwards-compatible jar and Java 8 baseline for regular jar * Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted * Add super classes to hash code / equals computation in Advice that were missing * Add support for new build description in Android 9 mgr-push: * Version 5.2.5-0 * Remove token based authentication mechanism for package_push (bsc#1230949) objectweb-asm: * Updated to version 9.10.1 * New Opcodes.V27 constant for Java 27 python-susemanager-retail: * Version 1.2.1 * Fix issue building package on SLES 16.0 salt: * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) spacecmd: * Version 5.2.10-0 * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) spacewalk-backend: * Version 5.2.10-0 * Allow diskcheck env vars into containers (bsc#1270033) * Use sha256 as the default checksum type for Debian repositories * Remove token based authentication mechanism for package_push (bsc#1230949) * Fix gpgverify signature file check for file object (bsc#1273131) * Allow using spacewalk-diskcheck without running service * Increase errata advisory char limit to 150 (bsc#1273846) * Use cryptographically secure random generation for secrets (bsc#1230568) spacewalk-branding: * Version 5.2.7-0 * No customer facing changes spacewalk-client-tools: * Version 5.2.7-0 * Update translation strings spacewalk-config: * Version 5.2.5-0 * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) spacewalk-java: * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.21-0 * CVE-2026-63007: Check access rights on two formula API calls (bsc#1269253) - fixed in 5.2.20-0 * CVE-2026-63009: Sanitize uploaded image name (bsc#1269534) - fixed in 5.2.20-0 * Updated to version 5.2.22-0 * Restored the original reset behavior in isDryRun() by swapping subscribedChannels and unsubscribedChannels back (bsc#1271681) * Fix mainframe foreign systems showing wrong OS (bsc#1260342) * Make setting of column filters in ListTag idempotent (bsc#1269192) * Fix hubsync package download checksum lookup (bsc#1270040) * Many to many relationships should not cascade deletion (bsc#1272392) * Optimized channel model generation logic to improve page load performance during peripheral channel selection (bsc#1259225) * Fixed Hibernate issue when updating the SSL content sources during a pay-as- you-go connection data refresh (bsc#1271382) * Allow diskcheck env vars into containers (bsc#1270033) * Query only systems for virtual machines which are flagged as virtualization hosts (bsc#1273073) * Use Channel equality even for ClonedChannel (bsc#1272621) * Fix EOL notifications in containers * Fix config channel position gaps (bsc#1272988) * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039) * Prevent cascading package operations to checksums (bsc#1272392) * Fixed custom RBAC role names being incorrectly localized. (bsc#1271116) * Do not add FQDNs from proxy certificate (bsc#1270141, bsc#1272404) * Do not crash on conflicting FQDNs, add error message * Add delay to package clean to not interfere with repo-sync (bsc#1258500) * Improve handling of invalid issue_date values when creating CLM filters via the API. (bsc#1271467) * Wait for taskomatic before processing events (bsc#1265472) * Use the standard Bootstrap 5 row class in place of legacy layout classes. * Remove udevdb salt module leftovers, udev is used now * Fix Hibernate session crash on Errata Sync by dynamically loading default access groups from the active session (bsc#1272298) * Fix Profile tab display in system details menu (bsc#1271963) spacewalk-proxy: * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.6-0 * Version 5.2.5-0 * Remove salt dependency from spacewalk-proxy-salt package spacewalk-search: * Version 5.2.6-0 * No customer facing changes spacewalk-utils: * Version 5.2.8-0 * Taskotop now handles timezone (bsc#1267871) spacewalk-web: * Version 5.2.14-0 * Improve product selection checkboxes in the setup UI * Show partial selection state for product trees more accurately * Fixed the "Clear selected system set" button flickering during page navigation. (bsc#1271523) * Add web.version.eol setting to provide an end of life date * Fix duplicate remaining characters label in the Create Custom Info Key description field. (bsc#1269679) * Improve handling of invalid issue_date values when creating CLM filters via the API. (bsc#1271467) * Refactor checkboxes in the RBAC UI * Reuse common Check component * Use the standard Bootstrap 5 row class in place of legacy layout classes. struts: * Fix JakartaServletFileUpload as setFileSizeMax was renamed to setMaxFileSize * Use explicite same java version as spacewalk-java to get around "class file has wrong version" errors subscription-matcher: * Updated to version 0.47 * Added missing part numbers (bsc#1274227, bsc#1265219) * Fix unsupported part number (bsc#1271075) supportutils-plugin-susemanager: * Version 5.2.3-0 * Allow 100 connection difference for apache and tomcat * Fix reading connections from the correct source * Add reportdb connections to the database connection limit (bsc#1262157) susemanager: * Version 5.2.10-0 * Add Ubuntu 26.04 LTS susemanager-build-keys: * Update SUSE addon key - extended validity susemanager-docs_en: * Documented requirements and limitations for container image inspection on SLES 15 and SLES 16 (bsc#1274720) * Documented proxy certificate replacement using spacecmd (bsc#1271329) * Documented certificate setup and rotation with unified mgradm ssl rotate command * Documented allowing diskcheck environment variables into containers (bsc#1270033) * Clarified availability of Salt's "virt" module in the Salt Bundle (bsc#1270694) * Added instruction for obtaining the certificate when renaming the server (bsc#1273853) * Added a common workflow for certificate setup and rotation with ACME * Documented how VMs are listed and referenced by virtual hosts (bsc#1273073) * Added documentation support for Ubuntu 26.04 client systems * Added the missing TFTP image in airgap install command * Fixed procedures for OpenSCAP in Administration Guide (bsc#1270047) * Fixed the snippet to reflect the correct produst version (bsc#1272538) * Corrected verification step order in MLM 5.0 to 5.2 upgrade guide for SL- Micro (bsc#1271678) * Extended configuration instructions for Saline formula in Specialized Guides (bsc#1268587) * Enhanced instructions for Liberate formula and reactivation key in Specialized Guides (bsc#1268473) * Fixed missing line end escapes in kubernetes helm install commands * Consolidated multiple duplicated activation key creation procedures into a single reusable partial snippet * Fixed Traefik installation documentation in Specialized Guides * Clarified CA certificate migration requirements (bsc#1271841) * Added instructions for enabling reporting dashboards in Specialized Guides (bsc#1268228) * Remove legacy mgradm and mgrpxy commands * Added the --set tag parameter to helm install/upgrade commands as a workaround (bsc#1271902) * Documented apache2 parameter used for large deployments (bsc#1268673) * Documented Grafana reporting database automated setup and Hub Overview in Administration and Specialized Guides * Update the OpenSCAP packages table in the System Security with OpenSCAP article in the Administration guide (bsc#1269316) * Added documentation for migrating legacy ISS v1 and ISS v2 peripheral servers to ISS v3 (Hub Online Synchronization) and detailed Report DB/XMLRPC API dependencies in Specialized Guides * Documented SLES 15 SP7 to SLES 16.0 major upgrade via product migration in Client Configuration Guide susemanager-schema: * Version 5.2.14-0 * Updated tables for CoCo attestation restructuring * Use temp table for hidden packages (bsc#1267912) * Renumber config channel positions to close gaps left by deleting an assigned config channel (ON DELETE CASCADE did not compact the survivors), preventing multiple failures (bsc#1272988) * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039) * Increase advisory char limit to 150 in rhnErrata (bsc#1273846) * RBAC: add missing endpoints to 'systems.profiles' namespace (bsc#1271963) susemanager-sls: * Version 5.2.15-0 * Propagate cert validation errors to UI (bsc#1271332) * Fix cleanup timeout when deleting minions (bsc#1258567) * Fix salt deletion on SSH minions (bsc#1274023) * Set podman secrets for proxy directly from salt * Fix migration of jmx conf (bsc#1268755) * Remove unused udevdb salt module as upstream udev is used susemanager-sync-data: * Version 5.2.6-0 * Add Ubuntu 26.04 LTS uyuni-coco-attestation: * Version 5.2.7-0 * Ensure the certs directory is always created * Allow pvattest module to be built on s390x uyuni-java-common: * Version 5.2.7-0 * No customer facing changes uyuni-java-parent: * Version 5.2.7-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run 'mgradm upgrade podman' which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run 'mgrpxy upgrade podman' which will use the default image tags. ## Security update 5.2.1 for Multi-Linux Manager Server, Proxy and Retail Branch Server ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.2.10 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-salt-broker-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-squid-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-ssh-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 proxy-tftpd-image: * Version 5.2.10 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 * Updated to version 5.2.10 server-attestation-image: * Version 5.2.11 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-database-migration-image: * Version 5.2.6 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-hub-xmlrpc-api-image: * Version 5.2.9 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 server-image: * Version 5.2.15 * Increase start-period (bsc#1271124) * Check disk space on startup * Use correct healthcheck cmd (bsc#1273144) * Detect an existing cgroup2 mount by filesystem type, not mountpoint. server-postgresql-image: * Version 5.2.13 * Automatically set the log timezone for TZ env (bsc#1267871) * Increase start-period and timeout (bsc#1271124) * Check disk space on startup server-saline-image: * Version 5.2.11 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1 uyuni-tools: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) * Version 5.2.17-0 * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) The following packages are underlying build dependencies and system components used by the containers: apache-commons-fileupload2: * Updated to version 2.0.0-M5 * Add AbstractFileUpload support for a maximum part header size * FILEUPLOAD-367: Jakarta and Javax ServletFileUpload .isMultipartContent(HttpServletRequest) should allow PUT and PATCH request methods in addition to POST * FILEUPLOAD-367: Add AbstractFileUpload .isMultipartRequestMethod(String) * FILEUPLOAD-295: Clarified the precise meaning of isInMemory(), get(), getPath(), etc. in DiskFileItem * Better exception type and message if a multipart/mixed part is presented without a boundary defined * Bump org.apache.commons:commons-parent from 84 to 96 * Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0 * Bump commons-io:commons-io from 2.19.0 to 2.21.0 byte-buddy: * Updated to version 1.18.8 * Introduce new versioning concept with -jdk5 suffix for backwards-compatible jar and Java 8 baseline for regular jar * Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted * Add super classes to hash code / equals computation in Advice that were missing * Add support for new build description in Android 9 mgr-push: * Version 5.2.5-0 * Remove token based authentication mechanism for package_push (bsc#1230949) objectweb-asm: * Updated to version 9.10.1 * New Opcodes.V27 constant for Java 27 python-susemanager-retail: * Version 1.2.1 * Fix issue building package on SLES 16.0 salt: * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) spacecmd: * Version 5.2.10-0 * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) spacewalk-backend: * Version 5.2.10-0 * Allow diskcheck env vars into containers (bsc#1270033) * Use sha256 as the default checksum type for Debian repositories * Remove token based authentication mechanism for package_push (bsc#1230949) * Fix gpgverify signature file check for file object (bsc#1273131) * Allow using spacewalk-diskcheck without running service * Increase errata advisory char limit to 150 (bsc#1273846) * Use cryptographically secure random generation for secrets (bsc#1230568) spacewalk-branding: * Version 5.2.7-0 * No customer facing changes spacewalk-client-tools: * Version 5.2.7-0 * Update translation strings spacewalk-config: * Version 5.2.5-0 * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) spacewalk-java: * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.21-0 * CVE-2026-63007: Check access rights on two formula API calls (bsc#1269253) - fixed in 5.2.20-0 * CVE-2026-63009: Sanitize uploaded image name (bsc#1269534) - fixed in 5.2.20-0 * Updated to version 5.2.22-0 * Restored the original reset behavior in isDryRun() by swapping subscribedChannels and unsubscribedChannels back (bsc#1271681) * Fix mainframe foreign systems showing wrong OS (bsc#1260342) * Make setting of column filters in ListTag idempotent (bsc#1269192) * Fix hubsync package download checksum lookup (bsc#1270040) * Many to many relationships should not cascade deletion (bsc#1272392) * Optimized channel model generation logic to improve page load performance during peripheral channel selection (bsc#1259225) * Fixed Hibernate issue when updating the SSL content sources during a pay-as- you-go connection data refresh (bsc#1271382) * Allow diskcheck env vars into containers (bsc#1270033) * Query only systems for virtual machines which are flagged as virtualization hosts (bsc#1273073) * Use Channel equality even for ClonedChannel (bsc#1272621) * Fix EOL notifications in containers * Fix config channel position gaps (bsc#1272988) * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039) * Prevent cascading package operations to checksums (bsc#1272392) * Fixed custom RBAC role names being incorrectly localized. (bsc#1271116) * Do not add FQDNs from proxy certificate (bsc#1270141, bsc#1272404) * Do not crash on conflicting FQDNs, add error message * Add delay to package clean to not interfere with repo-sync (bsc#1258500) * Improve handling of invalid issue_date values when creating CLM filters via the API. (bsc#1271467) * Wait for taskomatic before processing events (bsc#1265472) * Use the standard Bootstrap 5 row class in place of legacy layout classes. * Remove udevdb salt module leftovers, udev is used now * Fix Hibernate session crash on Errata Sync by dynamically loading default access groups from the active session (bsc#1272298) * Fix Profile tab display in system details menu (bsc#1271963) spacewalk-proxy: * CVE-2026-71400: Remove cobbler_api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.6-0 * Version 5.2.5-0 * Remove salt dependency from spacewalk-proxy-salt package spacewalk-search: * Version 5.2.6-0 * No customer facing changes spacewalk-utils: * Version 5.2.8-0 * Taskotop now handles timezone (bsc#1267871) spacewalk-web: * Version 5.2.14-0 * Improve product selection checkboxes in the setup UI * Show partial selection state for product trees more accurately * Fixed the "Clear selected system set" button flickering during page navigation. (bsc#1271523) * Add web.version.eol setting to provide an end of life date * Fix duplicate remaining characters label in the Create Custom Info Key description field. (bsc#1269679) * Improve handling of invalid issue_date values when creating CLM filters via the API. (bsc#1271467) * Refactor checkboxes in the RBAC UI * Reuse common Check component * Use the standard Bootstrap 5 row class in place of legacy layout classes. struts: * Fix JakartaServletFileUpload as setFileSizeMax was renamed to setMaxFileSize * Use explicite same java version as spacewalk-java to get around "class file has wrong version" errors subscription-matcher: * Updated to version 0.47 * Added missing part numbers (bsc#1274227, bsc#1265219) * Fix unsupported part number (bsc#1271075) supportutils-plugin-susemanager: * Version 5.2.3-0 * Allow 100 connection difference for apache and tomcat * Fix reading connections from the correct source * Add reportdb connections to the database connection limit (bsc#1262157) susemanager: * Version 5.2.10-0 * Add Ubuntu 26.04 LTS susemanager-build-keys: * Update SUSE addon key - extended validity susemanager-docs_en: * Documented requirements and limitations for container image inspection on SLES 15 and SLES 16 (bsc#1274720) * Documented proxy certificate replacement using spacecmd (bsc#1271329) * Documented certificate setup and rotation with unified mgradm ssl rotate command * Documented allowing diskcheck environment variables into containers (bsc#1270033) * Clarified availability of Salt's "virt" module in the Salt Bundle (bsc#1270694) * Added instruction for obtaining the certificate when renaming the server (bsc#1273853) * Added a common workflow for certificate setup and rotation with ACME * Documented how VMs are listed and referenced by virtual hosts (bsc#1273073) * Added documentation support for Ubuntu 26.04 client systems * Added the missing TFTP image in airgap install command * Fixed procedures for OpenSCAP in Administration Guide (bsc#1270047) * Fixed the snippet to reflect the correct produst version (bsc#1272538) * Corrected verification step order in MLM 5.0 to 5.2 upgrade guide for SL- Micro (bsc#1271678) * Extended configuration instructions for Saline formula in Specialized Guides (bsc#1268587) * Enhanced instructions for Liberate formula and reactivation key in Specialized Guides (bsc#1268473) * Fixed missing line end escapes in kubernetes helm install commands * Consolidated multiple duplicated activation key creation procedures into a single reusable partial snippet * Fixed Traefik installation documentation in Specialized Guides * Clarified CA certificate migration requirements (bsc#1271841) * Added instructions for enabling reporting dashboards in Specialized Guides (bsc#1268228) * Remove legacy mgradm and mgrpxy commands * Added the --set tag parameter to helm install/upgrade commands as a workaround (bsc#1271902) * Documented apache2 parameter used for large deployments (bsc#1268673) * Documented Grafana reporting database automated setup and Hub Overview in Administration and Specialized Guides * Update the OpenSCAP packages table in the System Security with OpenSCAP article in the Administration guide (bsc#1269316) * Added documentation for migrating legacy ISS v1 and ISS v2 peripheral servers to ISS v3 (Hub Online Synchronization) and detailed Report DB/XMLRPC API dependencies in Specialized Guides * Documented SLES 15 SP7 to SLES 16.0 major upgrade via product migration in Client Configuration Guide susemanager-schema: * Version 5.2.14-0 * Updated tables for CoCo attestation restructuring * Use temp table for hidden packages (bsc#1267912) * Renumber config channel positions to close gaps left by deleting an assigned config channel (ON DELETE CASCADE did not compact the survivors), preventing multiple failures (bsc#1272988) * Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039) * Increase advisory char limit to 150 in rhnErrata (bsc#1273846) * RBAC: add missing endpoints to 'systems.profiles' namespace (bsc#1271963) susemanager-sls: * Version 5.2.15-0 * Propagate cert validation errors to UI (bsc#1271332) * Fix cleanup timeout when deleting minions (bsc#1258567) * Fix salt deletion on SSH minions (bsc#1274023) * Set podman secrets for proxy directly from salt * Fix migration of jmx conf (bsc#1268755) * Remove unused udevdb salt module as upstream udev is used susemanager-sync-data: * Version 5.2.6-0 * Add Ubuntu 26.04 LTS uyuni-coco-attestation: * Version 5.2.7-0 * Ensure the certs directory is always created * Allow pvattest module to be built on s390x uyuni-java-common: * Version 5.2.7-0 * No customer facing changes uyuni-java-parent: * Version 5.2.7-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run 'mgradm upgrade podman' which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run 'mgrpxy upgrade podman' which will use the default image tags. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Proxy 5.2 zypper in -t patch SUSE-Multi-Linux-Manager-5.2-SUSE_SLFO_Products_Multi-Linux- Manager_5.2_Packages__patchinfo.20260915031526576964.188000203993655 SUSE-Multi- Linux-Manager-5.2-SUSE_SLFO_Products_Multi-Linux- Manager_5.2_Packages__patchinfo.20260915031526576964.188000203993655 * SUSE Multi-Linux Manager Retail Branch Server 5.2 zypper in -t patch SUSE-Multi-Linux-Manager-5.2-SUSE_SLFO_Products_Multi-Linux- Manager_5.2_Packages__patchinfo.20260915031526576964.188000203993655 * SUSE Multi-Linux Manager Server 5.2 zypper in -t patch SUSE-Multi-Linux-Manager-5.2-SUSE_SLFO_Products_Multi-Linux- Manager_5.2_Packages__patchinfo.20260915031526576964.188000203993655 SUSE-Multi- Linux-Manager-5.2-SUSE_SLFO_Products_Multi-Linux- Manager_5.2_Packages__patchinfo.20260915031526576964.188000203993655 ## Package List: * SUSE Multi-Linux Manager Proxy 5.2 (aarch64 ppc64le s390x x86_64) * mgrpxy-5.2.17-160000.1.1 * mgrpxy-debuginfo-5.2.17-160000.1.1 * SUSE Multi-Linux Manager Proxy 5.2 (noarch) * mgrpxy-bash-completion-5.2.17-160000.1.1 * mgrpxy-zsh-completion-5.2.17-160000.1.1 * SUSE Multi-Linux Manager Proxy 5.2 (aarch64) * suse-multi-linux-manager-5.2-aarch64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-aarch64-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Proxy 5.2 (ppc64le) * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-ppc64le-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-httpd-image-5.2.1-9.3.30 * SUSE Multi-Linux Manager Proxy 5.2 (s390x) * suse-multi-linux-manager-5.2-s390x-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-s390x-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-s390x-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Proxy 5.2 (x86_64) * suse-multi-linux-manager-5.2-x86_64-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-x86_64-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Retail Branch Server 5.2 (aarch64 ppc64le s390x x86_64) * mgrpxy-5.2.17-160000.1.1 * mgrpxy-debuginfo-5.2.17-160000.1.1 * SUSE Multi-Linux Manager Retail Branch Server 5.2 (noarch) * mgrpxy-bash-completion-5.2.17-160000.1.1 * mgrpxy-zsh-completion-5.2.17-160000.1.1 * SUSE Multi-Linux Manager Retail Branch Server 5.2 (aarch64) * suse-multi-linux-manager-5.2-aarch64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-aarch64-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Retail Branch Server 5.2 (ppc64le) * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-ppc64le-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-proxy-httpd-image-5.2.1-9.3.30 * SUSE Multi-Linux Manager Retail Branch Server 5.2 (s390x) * suse-multi-linux-manager-5.2-s390x-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-s390x-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-s390x-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Retail Branch Server 5.2 (x86_64) * suse-multi-linux-manager-5.2-x86_64-proxy-ssh-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-squid-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-proxy-httpd-image-5.2.1-9.3.30 * suse-multi-linux-manager-5.2-x86_64-proxy-salt-broker-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Server 5.2 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.2.17-160000.1.1 * mgradm-5.2.17-160000.1.1 * mgradm-debuginfo-5.2.17-160000.1.1 * mgrctl-5.2.17-160000.1.1 * SUSE Multi-Linux Manager Server 5.2 (noarch) * mgrctl-zsh-completion-5.2.17-160000.1.1 * mgrctl-bash-completion-5.2.17-160000.1.1 * mgradm-bash-completion-5.2.17-160000.1.1 * mgradm-zsh-completion-5.2.17-160000.1.1 * SUSE Multi-Linux Manager Server 5.2 (aarch64) * suse-multi-linux-manager-5.2-aarch64-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-aarch64-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-aarch64-server-saline-image-5.2.1-11.3.24 * suse-multi-linux-manager-5.2-aarch64-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-aarch64-server-attestation-image-5.2.1-11.3.23 * suse-multi-linux-manager-5.2-aarch64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-aarch64-server-database-migration-image-5.2.1-7.3.16 * SUSE Multi-Linux Manager Server 5.2 (ppc64le) * suse-multi-linux-manager-5.2-ppc64le-server-saline-image-5.2.1-11.3.24 * suse-multi-linux-manager-5.2-ppc64le-server-database-migration-image-5.2.1-7.3.16 * suse-multi-linux-manager-5.2-ppc64le-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-ppc64le-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-ppc64le-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-ppc64le-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-ppc64le-server-attestation-image-5.2.1-11.3.23 * SUSE Multi-Linux Manager Server 5.2 (s390x) * suse-multi-linux-manager-5.2-s390x-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-s390x-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-s390x-server-attestation-image-5.2.1-11.3.23 * suse-multi-linux-manager-5.2-s390x-server-database-migration-image-5.2.1-7.3.16 * suse-multi-linux-manager-5.2-s390x-server-saline-image-5.2.1-11.3.24 * suse-multi-linux-manager-5.2-s390x-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-s390x-proxy-tftpd-image-5.2.1-9.3.16 * SUSE Multi-Linux Manager Server 5.2 (x86_64) * suse-multi-linux-manager-5.2-x86_64-server-image-5.2.1-11.3.29 * suse-multi-linux-manager-5.2-x86_64-server-saline-image-5.2.1-11.3.24 * suse-multi-linux-manager-5.2-x86_64-server-postgresql-image-5.2.1-11.3.15 * suse-multi-linux-manager-5.2-x86_64-server-database-migration-image-5.2.1-7.3.16 * suse-multi-linux-manager-5.2-x86_64-server-hub-xmlrpc-api-image-5.2.1-9.3.19 * suse-multi-linux-manager-5.2-x86_64-proxy-tftpd-image-5.2.1-9.3.16 * suse-multi-linux-manager-5.2-x86_64-server-attestation-image-5.2.1-11.3.23 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-63007.html * https://www.suse.com/security/cve/CVE-2026-63009.html * https://www.suse.com/security/cve/CVE-2026-71400.html * https://bugzilla.suse.com/show_bug.cgi?id=1208800 * https://bugzilla.suse.com/show_bug.cgi?id=1230568 * https://bugzilla.suse.com/show_bug.cgi?id=1230949 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1258382 * https://bugzilla.suse.com/show_bug.cgi?id=1258500 * https://bugzilla.suse.com/show_bug.cgi?id=1258567 * https://bugzilla.suse.com/show_bug.cgi?id=1259225 * https://bugzilla.suse.com/show_bug.cgi?id=1260342 * https://bugzilla.suse.com/show_bug.cgi?id=1262157 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1265219 * https://bugzilla.suse.com/show_bug.cgi?id=1265472 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267871 * https://bugzilla.suse.com/show_bug.cgi?id=1267912 * https://bugzilla.suse.com/show_bug.cgi?id=1268228 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268473 * https://bugzilla.suse.com/show_bug.cgi?id=1268587 * https://bugzilla.suse.com/show_bug.cgi?id=1268673 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1269192 * https://bugzilla.suse.com/show_bug.cgi?id=1269253 * https://bugzilla.suse.com/show_bug.cgi?id=1269316 * https://bugzilla.suse.com/show_bug.cgi?id=1269534 * https://bugzilla.suse.com/show_bug.cgi?id=1269679 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270039 * https://bugzilla.suse.com/show_bug.cgi?id=1270040 * https://bugzilla.suse.com/show_bug.cgi?id=1270047 * https://bugzilla.suse.com/show_bug.cgi?id=1270141 * https://bugzilla.suse.com/show_bug.cgi?id=1270694 * https://bugzilla.suse.com/show_bug.cgi?id=1271075 * https://bugzilla.suse.com/show_bug.cgi?id=1271116 * https://bugzilla.suse.com/show_bug.cgi?id=1271124 * https://bugzilla.suse.com/show_bug.cgi?id=1271329 * https://bugzilla.suse.com/show_bug.cgi?id=1271332 * https://bugzilla.suse.com/show_bug.cgi?id=1271382 * https://bugzilla.suse.com/show_bug.cgi?id=1271467 * https://bugzilla.suse.com/show_bug.cgi?id=1271523 * https://bugzilla.suse.com/show_bug.cgi?id=1271678 * https://bugzilla.suse.com/show_bug.cgi?id=1271681 * https://bugzilla.suse.com/show_bug.cgi?id=1271841 * https://bugzilla.suse.com/show_bug.cgi?id=1271902 * https://bugzilla.suse.com/show_bug.cgi?id=1271963 * https://bugzilla.suse.com/show_bug.cgi?id=1272298 * https://bugzilla.suse.com/show_bug.cgi?id=1272392 * https://bugzilla.suse.com/show_bug.cgi?id=1272404 * https://bugzilla.suse.com/show_bug.cgi?id=1272538 * https://bugzilla.suse.com/show_bug.cgi?id=1272621 * https://bugzilla.suse.com/show_bug.cgi?id=1272988 * https://bugzilla.suse.com/show_bug.cgi?id=1273073 * https://bugzilla.suse.com/show_bug.cgi?id=1273131 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://bugzilla.suse.com/show_bug.cgi?id=1273846 * https://bugzilla.suse.com/show_bug.cgi?id=1273853 * https://bugzilla.suse.com/show_bug.cgi?id=1274023 * https://bugzilla.suse.com/show_bug.cgi?id=1274227 * https://bugzilla.suse.com/show_bug.cgi?id=1274613 * https://bugzilla.suse.com/show_bug.cgi?id=1274720 * https://bugzilla.suse.com/show_bug.cgi?id=1274775 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:49:00 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:49:00 -0000 Subject: SUSE-SU-2026:4585-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147814012.421.16196313939043306476@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4585-1 Release Date: 2026-10-08T08:24:35Z Rating: important References: * bsc#1218722 * bsc#1230949 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262187 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263330 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1265525 * bsc#1265763 * bsc#1266481 * bsc#1266608 * bsc#1266669 * bsc#1267261 * bsc#1267528 * bsc#1267534 * bsc#1267538 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268868 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269841 * bsc#1269856 * bsc#1269959 * bsc#1269966 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1270711 * bsc#1271192 * bsc#1271330 * bsc#1271428 * bsc#1271557 * bsc#1271613 * bsc#1272008 * bsc#1272102 * bsc#1272328 * bsc#1272427 * bsc#1273094 * bsc#1273144 * bsc#1274217 * bsc#1274221 * bsc#1275205 * bsc#1275206 * bsc#1275207 * bsc#1275934 * bsc#1276426 * bsc#1276658 * bsc#1276973 * bsc#1277025 * bsc#1278307 * bsc#1278322 * jsc#MSQA-1060 * jsc#PED-16707 Cross-References: * CVE-2023-45289 * CVE-2024-22195 * CVE-2025-13836 * CVE-2025-4673 * CVE-2025-61686 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-1229 * CVE-2026-13346 * CVE-2026-14199 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-17033 * CVE-2026-17183 * CVE-2026-19197 * CVE-2026-19475 * CVE-2026-21723 * CVE-2026-2303 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-33814 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-39882 * CVE-2026-40181 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-41178 * CVE-2026-41606 * CVE-2026-42127 * CVE-2026-42211 * CVE-2026-42342 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-44990 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-53606 * CVE-2026-56852 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-73501 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8595 * CVE-2026-8609 * CVE-2026-8643 * CVE-2026-9029 CVSS scores: * CVE-2023-45289 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-45289 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4673 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2025-4673 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2025-61686 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-61686 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-61686 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-1229 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-1229 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2026-1229 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber * CVE-2026-1229 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-14199 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-14199 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-14199 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-17033 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-17033 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L * CVE-2026-17033 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L * CVE-2026-17183 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-17183 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-19197 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19197 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19475 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19475 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21723 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21723 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2303 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-2303 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-2303 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39882 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39882 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40181 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-40181 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40181 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42127 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42127 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42211 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-42211 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42342 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42342 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-44990 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-44990 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44990 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-44990 ( NVD ): 9.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53606 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53606 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73501 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-73501 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8595 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-8595 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-8595 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L * CVE-2026-8609 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-8609 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-8609 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-9029 ( SUSE ): 4.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-9029 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-9029 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2026-9029 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 * SUSE Linux Enterprise Desktop 15 SP1 * SUSE Linux Enterprise Desktop 15 SP2 * SUSE Linux Enterprise Desktop 15 SP3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP1 * SUSE Linux Enterprise Real Time 15 SP2 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Multi-Linux Manager Client Tools for SLE 15 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves 58 vulnerabilities, contains two features and has 21 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-prometheus was updated to version 3.13.2: * Security issues: * CVE-2026-39821: Fixed validation bypass and privilege escalation in Punycode label handling (bsc#1266608) * CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in unicode/norm handling (bsc#1272102) * CVE-2026-44990: Fixed stored XSS in the new React UI by sanitizing disallowed xmp elements (bsc#1275205) * CVE-2026-53606: Fixed incomplete URI scheme validation in sanitize-html that could enable XSS (bsc#1269966) * CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in mongo-driver (bsc#1269856) * CVE-2025-4673: Fixed credential leaks by stopping HTTP client header forwarding on redirects (bsc#1275206) * CVE-2023-45289: Fixed credential leaks by stopping header and cookie forwarding on HTTP redirects (bsc#1275207) * CVE-2025-61686: Fixed unauthorized file access and path traversal in react- router storage (bsc#1270711) * CVE-2026-40181: Fixed open redirect risks to external domains via relative paths in react-router (bsc#1267528) * CVE-2026-42342: Fixed DoS risks via unbounded path expansion in the manifest endpoint (bsc#1267538) * CVE-2026-42211: Fixed remote code execution risks from prototype pollution in react-router (bsc#1267534) * CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading in OpenTelemetry (bsc#1274221) * Fixed potential denial-of-service vulnerabilities by updating the gRPC dependency * Fixed memory exhaustion and DoS by rejecting snappy-compressed requests exceeding 32MB limit * Bug fixes and changes: * Fixed scrape manager failing to reload properly when SD configuration changes rapidly. * Prevent memory leak in remote-write path when the receiving endpoint is unavailable. * Native Histograms are no longer experimental. They are fully supported for production workloads. * Added support for OpenTelemetry traces within the Prometheus UI to correlate metrics and traces. * TSDB compaction speed optimized by improving the block merging algorithm. * Allow scraping of multiple targets using a single HTTP/2 connection to reduce overhead. * Added new metrics to monitor the health of the rule evaluation engine. * Incompatible: This affects scraping, remote read and write, alerting, and SD. Network paths might need adjustments to avoid redirects. * Incompatible: Rule group pagination tokens now use SHA-256 instead of MD5. Custom API consumers must adapt to the new longer token format. * Added 'group_limit' parameter to PromQL aggregations to restrict the number of results. * Incompatible: promtool relative paths in config files now resolve relative to the config directory itself, instead of the current working directory. * Support exporting TSDB blocks directly to cloud storage via the admin API. * Incompatible: Deprecated remote-write metrics like prometheus_remote_storage_samples_total are removed in favor of prometheus_wal_watcher_records_read_total. * Significant query performance boost for high-cardinality regex matchers. * Introduce a new UI interface for safely deleting specific time series data directly. * Added dynamic relabeling actions to extract substrings using regex capture groups. * Fixed UI displaying incorrect time ranges after a timezone change. * Bumped firewalld-prometheus-config to version 0.2 bumping OpenTelemetry to 1.43.0 grafana was updated to version 12.4.10: * Security issues: * CVE-2026-17183: Fixed exposing data accessible through Grafana's configured datasource credentials (bsc#1275934) * CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in mongo-driver (bsc#1269841) * CVE-2026-17033: Fixed stored cross-site scripting risks via malicious Alertmanager generator URLs (bsc#1276426) * CVE-2026-73501: Fixed fail-open authentication bypass in kin-openapi default handlers (bsc#1276973) * CVE-2026-19475: Fixed DoS risks in PostgreSQL Datasource by checking timeGroup macros (bsc#1278307) * CVE-2026-14199: Fixed auth bypass or session takeover via Auth Proxy cache key collision (bsc#1278322) * CVE-2026-19197: Fixed access control and authorization checks in dashboard snapshots (bsc#1277025) * CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in unicode/norm (bsc#1272008) * CVE-2026-41178: Fixed denial-of-service risks in OpenTelemetry baggage parsing (bsc#1276658) * CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading in OpenTelemetry (bsc#1274217) * CVE-2026-8595: Fixed stored XSS via malicious dashboard field names in table panels (bsc#1271557) * CVE-2026-42127: Fixed DoS risks in the public dashboard query endpoint (bsc#1268868) * CVE-2026-9029: Fixed arbitrary code execution and script injection in the geomap panel (bsc#1272328) * CVE-2026-33814: Fixed infinite loop in HTTP/2 transport during framesize check (bsc#1265763) * CVE-2026-8609: Fixed pre-authentication denial-of-service risks in OAuth login routes (bsc#1271330) * CVE-2026-1229: Fixed incorrect value calculation in ecc/p384 Package (bsc#1265525, bsc#1262187) * CVE-2025-12141: Fixed information disclosure of secure settings via contact point modification (bsc#1262187) * CVE-2026-21723: Fixed out-of-memory and denial-of-service risks in templates test endpoint (bsc#1272427) * CVE-2026-41606: Fixed denial-of-service risks from nested messages in Apache Thrift parser (bsc#1263330) * Bug fixes and changes: * Dashboards: Fix adhoc and groupby variable datasource on UI import * Dashboards: Fix version dates and user display names in the legacy version history page * Dashboard Import: Labels in v2 schema * Azure Monitor: fix migration for dimension filters * Dashboards: Get annotations and dashboard endpoint performance improvements * DashboardDS: Fix Mixed panels with a time override stuck in permanent loading * Alerting: Add protected fields authorization check to provisioning API * Alerting: Return 403 instead of 500 on contact point provenance mismatch * Jaeger: Handle gzip, deflate, and brotli compressed API responses * Alerting: fix ORM table mapping bug causing SELECT alert_rule columns FROM user on PostgreSQL mgr-push was updated to version 5.2.5: * Removed token based authentication mechanism for package_push (bsc#1230949) spacecmd was updated to version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Updated translation strings spacewalk-client-tools was updated to version 5.2.7: * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE 15 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-15-2026-4585 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-4585 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 15 (aarch64 ppc64le s390x x86_64) * grafana-12.4.10-150002.4.27.1 * venv-salt-minion-3006.0-150002.5.22.1 * golang-github-prometheus-prometheus-3.13.2-150002.3.19.1 * mgrctl-5.2.17-150002.3.20.1 * grafana-debuginfo-12.4.10-150002.4.27.1 * mgrctl-debuginfo-5.2.17-150002.3.20.1 * firewalld-prometheus-config-0.2-150002.3.19.1 * golang-github-prometheus-prometheus-debuginfo-3.13.2-150002.3.19.1 * SUSE Multi-Linux Manager Client Tools for SLE 15 (noarch) * mgrctl-lang-5.2.17-150002.3.20.1 * mgr-push-5.2.5-150002.3.12.1 * python3-spacewalk-client-tools-5.2.7-150002.3.12.1 * spacecmd-5.2.10-150002.3.15.1 * mgrctl-zsh-completion-5.2.17-150002.3.20.1 * spacewalk-client-tools-5.2.7-150002.3.12.1 * python3-mgr-push-5.2.5-150002.3.12.1 * mgrctl-bash-completion-5.2.17-150002.3.20.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-150002.5.22.1 * mgrctl-5.2.17-150002.3.20.1 * mgrctl-debuginfo-5.2.17-150002.3.20.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * mgrctl-bash-completion-5.2.17-150002.3.20.1 * mgrctl-zsh-completion-5.2.17-150002.3.20.1 * mgrctl-lang-5.2.17-150002.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45289.html * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-4673.html * https://www.suse.com/security/cve/CVE-2025-61686.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-1229.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-14199.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-17033.html * https://www.suse.com/security/cve/CVE-2026-17183.html * https://www.suse.com/security/cve/CVE-2026-19197.html * https://www.suse.com/security/cve/CVE-2026-19475.html * https://www.suse.com/security/cve/CVE-2026-21723.html * https://www.suse.com/security/cve/CVE-2026-2303.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39882.html * https://www.suse.com/security/cve/CVE-2026-40181.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-41606.html * https://www.suse.com/security/cve/CVE-2026-42127.html * https://www.suse.com/security/cve/CVE-2026-42211.html * https://www.suse.com/security/cve/CVE-2026-42342.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-44990.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-53606.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-73501.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8595.html * https://www.suse.com/security/cve/CVE-2026-8609.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://www.suse.com/security/cve/CVE-2026-9029.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1230949 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262187 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263330 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1265525 * https://bugzilla.suse.com/show_bug.cgi?id=1265763 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266608 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267528 * https://bugzilla.suse.com/show_bug.cgi?id=1267534 * https://bugzilla.suse.com/show_bug.cgi?id=1267538 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268868 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269841 * https://bugzilla.suse.com/show_bug.cgi?id=1269856 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1269966 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1270711 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271330 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271557 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1272008 * https://bugzilla.suse.com/show_bug.cgi?id=1272102 * https://bugzilla.suse.com/show_bug.cgi?id=1272328 * https://bugzilla.suse.com/show_bug.cgi?id=1272427 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://bugzilla.suse.com/show_bug.cgi?id=1274217 * https://bugzilla.suse.com/show_bug.cgi?id=1274221 * https://bugzilla.suse.com/show_bug.cgi?id=1275205 * https://bugzilla.suse.com/show_bug.cgi?id=1275206 * https://bugzilla.suse.com/show_bug.cgi?id=1275207 * https://bugzilla.suse.com/show_bug.cgi?id=1275934 * https://bugzilla.suse.com/show_bug.cgi?id=1276426 * https://bugzilla.suse.com/show_bug.cgi?id=1276658 * https://bugzilla.suse.com/show_bug.cgi?id=1276973 * https://bugzilla.suse.com/show_bug.cgi?id=1277025 * https://bugzilla.suse.com/show_bug.cgi?id=1278307 * https://bugzilla.suse.com/show_bug.cgi?id=1278322 * https://jira.suse.com/browse/MSQA-1060 * https://jira.suse.com/browse/PED-16707 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:50:04 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:50:04 -0000 Subject: SUSE-SU-2026:4584-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147820477.421.6248176768776739500@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4584-1 Release Date: 2026-10-08T08:23:06Z Rating: important References: * bsc#1218722 * bsc#1230949 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Multi-Linux Manager Client Tools for SLE 12 An update that solves 32 vulnerabilities, contains one feature and has 16 security fixes can now be installed. ## Description: This update fixes the following issues: mgr-push was updated to version 5.2.5: * Removed token based authentication mechanism for package_push (bsc#1230949) spacecmd was updated to version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Updated translation strings spacewalk-client-tools was updated to version 5.2.7:: * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE 12 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-12-2026-4584 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-120002.5.22.2 * mgrctl-5.2.17-120002.3.18.1 * mgrctl-debuginfo-5.2.17-120002.3.18.1 * SUSE Multi-Linux Manager Client Tools for SLE 12 (noarch) * mgr-push-5.2.5-120002.3.12.1 * python2-mgr-push-5.2.5-120002.3.12.1 * python2-spacewalk-client-tools-5.2.7-120002.3.12.1 * mgrctl-zsh-completion-5.2.17-120002.3.18.1 * spacecmd-5.2.10-120002.3.15.1 * mgrctl-lang-5.2.17-120002.3.18.1 * mgrctl-bash-completion-5.2.17-120002.3.18.1 * spacewalk-client-tools-5.2.7-120002.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1230949 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:50:58 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:50:58 -0000 Subject: SUSE-SU-2026:4583-1: moderate: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147825848.421.5798106670442431101@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4583-1 Release Date: 2026-10-08T08:21:48Z Rating: moderate References: * bsc#1218722 * bsc#1230949 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270285 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Liberty Linux 7 * SUSE Liberty Linux 7 LTSS * SUSE Liberty Linux LTSS 7 for Oracle Linux * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones An update that solves 31 vulnerabilities, contains one feature and has seven security fixes can now be installed. ## Description: This update fixes the following issues: mgr-push: * Version 5.2.5-0 * Remove token based authentication mechanism for package_push (bsc#1230949) spacecmd: * Version 5.2.10-0 * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Version 5.2.9-0 * Update translation strings spacewalk-client-tools: * Version 5.2.7-0 * Update translation strings venv-salt-minion: * CVE-2026-13346: Arbitrary file installation via malicious package indexes. Remove ensurepip with bundled .whl files. (bsc#1273094) * CVE-2026-0864: Normalize all line endings (CR, CRLF, and LF) in configparser (bsc#1269066, gh#python/cpython#143927) * CVE-2026-1502: reject CR/LF in HTTP tunnel request headers (bsc#1261969, gh#python/cpython#146211) * CVE-2026-3276: Fix O(n^2) canonical ordering in unicodedata.normalize() (bsc#1267581, gh#python/cpython#149079) * CVE-2026-4360: Pass filter_function to TarFile._extract_one() during .extract() (bsc#1269959, gh#python/cpython#151987) * CVE-2026-4786: fix webbrowser %action substitution bypass of dash-prefix check (bsc#1262319, gh#python/cpython#148169) * CVE-2026-6019: protect against HTML injection by Base64-encoding cookie values embedded in JS (bsc#1262654, gh#python/cpython#90309) * CVE-2026-6100: prevent dangling pointer, which can end in the use-after-free error (bsc#1262098, gh#python/cpython#148395) * CVE-2026-7210: Use XML_SetHashSalt16Bytes in pyexpat/_elementtree when possible (bsc#1264962, gh#python/cpython#149018) * CVE-2026-7774: tarfile.data_filter: validate written link target (bsc#1267821, gh#149486) * CVE-2026-8328: Make ftplib not trust the PASV response (bsc#1265268) * CVE-2026-11940: fix the symlink escape via tarfile hardlink-extraction fallback (bsc#1268977) * CVE-2026-11972: Make tarfile._Stream.seek break at EOF (bsc#1269788, gh#python/cpython#151981) * CVE-2026-15308: Fix quadratic complexity in incremental parsing in HTMLParser (bsc#1271192, gh#python/cpython#153030) * CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669) * CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442) * CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429) * CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1257599, gh#pypa/pip#13777) * CVE-2024-22195: Fix compiler error when checking if required blocks in parent templates are xmlattr filter does not allow keys with spaces. (bsc#1218722) * CVE-2026-45409: Specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413) * CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267) * CVE-2026-49825: The known link attributes in `lxml.html.defs.link_attrs` were missing `xlink:href`, which can be used for URL bypass attributes in embedded SVG/MathML/etc. content. (bsc#1270285) https://github.com/fedora- python/lxml_html_clean/security/advisories/GHSA-4jhm-jv67-739f * CVE-2026-41066: This release fixes a possible external entity injection (XXE) vulnerability in `iterparse()` and the `ETCompatXMLParser`. (bsc#1263254) * CVE-2026-3446: Preventing ignoring excess Base64 data after the first padded quad in non-strict (default) mode. (bsc#1261970, gh#python/cpython#145264) * CVE-2026-3479: pkgutil.get_data() has the same security model as open(). The documented limitations ensure compatibility with non-filesystem loaders; Python doesn't check that. (bsc#1259989, gh#python/cpython#146121) * CVE-2026-27459: large cookie value can lead to a buffer overflow (bsc#1271428) * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395) * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396) * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) (bsc#1268397) * CVE-2026-40475: improper input handling of null bytes can lead to silent data truncation and security-state inconsistency (bsc#1262803) * CVE-2025-13836: limit http.client response read in NXOS modules (bsc#1254400) * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-RES-7-2026-4583 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (noarch) * spacecmd-5.2.10-70002.3.15.1 * python2-mgr-push-5.2.5-70002.3.12.2 * python2-spacewalk-client-tools-5.2.7-70002.3.12.1 * spacewalk-client-tools-5.2.7-70002.3.12.1 * mgr-push-5.2.5-70002.3.12.2 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (aarch64 ppc64le x86_64) * venv-salt-minion-3006.0-70002.5.22.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1230949 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:52:04 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:52:04 -0000 Subject: SUSE-SU-2026:4582-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147832427.421.9656174073178808036@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4582-1 Release Date: 2026-10-08T08:20:36Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#ECO-3319 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones An update that solves 32 vulnerabilities, contains two features and has 15 security fixes can now be installed. ## Description: This update fixes the following issues: scap-security-guide was updated to version 0.1.79: * Version 0.1.79 (jsc#ECO-3319) * Added SLE16 profiles to the build * Create SLE16 HIPAA profile * Create SLE16 PCI DSS 4 profile * Use Sequoia in RHEL 10 instead of GPG * New Profile for RHEL10: BSI * Move RHEL Control files to product files * Update RHEL 9 CCN profile * Various updates for SLE 12/15 spacecmd was updated to version 5.2.10: * Version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Version 5.2.9: * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) - fixed in 5.2.17-0 Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-9-2026-4582 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (aarch64 ppc64le s390x x86_64) * mgrctl-5.2.17-90002.3.15.1 * venv-salt-minion-3006.0-90002.5.22.1 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (noarch) * spacecmd-5.2.10-90002.3.15.1 * mgrctl-bash-completion-5.2.17-90002.3.15.1 * scap-security-guide-redhat-0.1.80-90002.3.12.1 * mgrctl-zsh-completion-5.2.17-90002.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/ECO-3319 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:53:08 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:53:08 -0000 Subject: SUSE-SU-2026:4581-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147838848.421.2184786761534770598@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4581-1 Release Date: 2026-10-08T08:18:32Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#ECO-3319 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones An update that solves 32 vulnerabilities, contains two features and has 15 security fixes can now be installed. ## Description: This update fixes the following issues: scap-security-guide was updated to version 0.1.79: * Version 0.1.79 (jsc#ECO-3319) * Added SLE16 profiles to the build * Create SLE16 HIPAA profile * Create SLE16 PCI DSS 4 profile * Use Sequoia in RHEL 10 instead of GPG * New Profile for RHEL10: BSI * Move RHEL Control files to product files * Update RHEL 9 CCN profile * Various updates for SLE 12/15 spacecmd was updated to version 5.2.10: * Version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Version 5.2.9: * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) - fixed in 5.2.17-0 Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-8-2026-4581 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones (aarch64 ppc64le x86_64) * mgrctl-5.2.17-80002.3.15.3 * venv-salt-minion-3006.0-80002.5.22.3 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones (noarch) * scap-security-guide-redhat-0.1.80-80002.3.12.4 * spacecmd-5.2.10-80002.3.15.3 * mgrctl-zsh-completion-5.2.17-80002.3.15.3 * mgrctl-bash-completion-5.2.17-80002.3.15.3 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/ECO-3319 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:54:14 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:54:14 -0000 Subject: SUSE-SU-2026:4580-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147845430.421.14436989785647800041@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4580-1 Release Date: 2026-10-08T08:17:25Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#ECO-3319 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones An update that solves 32 vulnerabilities, contains two features and has 15 security fixes can now be installed. ## Description: This update fixes the following issues: scap-security-guide was updated to version 0.1.79: * Version 0.1.79 (jsc#ECO-3319) * Added SLE16 profiles to the build * Create SLE16 HIPAA profile * Create SLE16 PCI DSS 4 profile * Use Sequoia in RHEL 10 instead of GPG * New Profile for RHEL10: BSI * Move RHEL Control files to product files * Update RHEL 9 CCN profile * Various updates for SLE 12/15 spacecmd was updated to version 5.2.10: * Version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Version 5.2.9: * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) - fixed in 5.2.17-0 Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-10-2026-4580 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones (aarch64 ppc64le s390x x86_64) * mgrctl-5.2.17-100002.1.9.1 * venv-salt-minion-3006.0-100002.1.13.1 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 10, RHEL and clones (noarch) * mgrctl-bash-completion-5.2.17-100002.1.9.1 * scap-security-guide-redhat-0.1.80-100002.1.6.1 * spacecmd-5.2.10-100002.1.9.1 * mgrctl-zsh-completion-5.2.17-100002.1.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/ECO-3319 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:55:20 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:55:20 -0000 Subject: SUSE-SU-2026:4579-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147852027.421.6883564267303724717@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4579-1 Release Date: 2026-10-08T08:16:09Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for Debian 13 An update that solves 32 vulnerabilities, contains one feature and has 15 security fixes can now be installed. ## Description: This update fixes the following issues: spacecmd was updated to version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Debian 13 zypper in -t patch SUSE-MultiLinuxManagerTools-Debian-13-2026-4579 ## Package List: * SUSE Multi-Linux Manager Client Tools for Debian 13 (amd64 arm64) * mgrctl-5.2.17-130002.2.9.1 * venv-salt-minion-3006.0-130002.2.13.1 * SUSE Multi-Linux Manager Client Tools for Debian 13 (all) * mgrctl-bash-completion-5.2.17-130002.2.9.1 * mgrctl-fish-completion-5.2.17-130002.2.9.1 * mgrctl-zsh-completion-5.2.17-130002.2.9.1 * spacecmd-5.2.10-130002.2.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:56:28 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:56:28 -0000 Subject: SUSE-SU-2026:4578-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147858840.421.15547906082829600842@d580628b9e86> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:4578-1 Release Date: 2026-10-08T08:15:01Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271428 * bsc#1271613 * bsc#1273094 * bsc#1273144 * jsc#MSQA-1060 Cross-References: * CVE-2024-22195 * CVE-2025-13836 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for Debian 12 An update that solves 32 vulnerabilities, contains one feature and has 15 security fixes can now be installed. ## Description: This update fixes the following issues: spacecmd was updated to version 5.2.10: * Version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Version 5.2.9: * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) - fixed in 5.2.17-0 Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues fixed: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Debian 12 zypper in -t patch SUSE-MultiLinuxManagerTools-Debian-12-2026-4578 ## Package List: * SUSE Multi-Linux Manager Client Tools for Debian 12 (amd64 arm64) * venv-salt-minion-3006.0-120002.3.30.1 * mgrctl-5.2.17-120002.3.23.1 * SUSE Multi-Linux Manager Client Tools for Debian 12 (all) * mgrctl-bash-completion-5.2.17-120002.3.23.1 * spacecmd-5.2.10-120002.3.23.1 * mgrctl-fish-completion-5.2.17-120002.3.23.1 * mgrctl-zsh-completion-5.2.17-120002.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 16:57:01 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 16:57:01 -0000 Subject: SUSE-RU-2026:4577-1: important: Recommended update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179147862181.421.3878336270158671790@d580628b9e86> # Recommended update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-RU-2026:4577-1 Release Date: 2026-10-08T08:13:49Z Rating: important References: * bsc#1257599 * bsc#1261969 * bsc#1262098 * bsc#1262319 * bsc#1262429 * bsc#1262654 * bsc#1263442 * bsc#1264962 * bsc#1265268 * bsc#1266481 * bsc#1266669 * bsc#1267261 * bsc#1267581 * bsc#1267821 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1270033 * bsc#1271192 * bsc#1273094 * bsc#1273144 * jsc#MSQA-1060 Cross-References: * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-39821 * CVE-2026-4360 * CVE-2026-4786 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8643 CVSS scores: * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Multi-Linux Manager Client Tools for Ubuntu 26.04 2604 An update that solves 19 vulnerabilities, contains one feature and has four fixes can now be installed. ## Description: This update fixes the following issues: spacecmd: * Initial package release uyuni-tools: * Initial package release venv-salt-minion: * Initial package release ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for Ubuntu 26.04 2604 zypper in -t patch SUSE-MultiLinuxManagerTools-Ubuntu-26.04-2026-4577 ## Package List: * SUSE Multi-Linux Manager Client Tools for Ubuntu 26.04 2604 (amd64) * mgrctl-5.2.17-240402.2.3.4 * venv-salt-minion-3006.0-240402.2.3.1 * SUSE Multi-Linux Manager Client Tools for Ubuntu 26.04 2604 (all) * mgrctl-fish-completion-5.2.17-240402.2.3.4 * mgrctl-zsh-completion-5.2.17-240402.2.3.4 * mgrctl-bash-completion-5.2.17-240402.2.3.4 * spacecmd-5.2.10-240402.2.3.4 ## References: * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Oct 8 20:46:51 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Thu, 08 Oct 2026 20:46:51 -0000 Subject: SUSE-SU-2026:24055-1: important: Security update 5.2.1 for Multi-Linux Manager Client Tools Message-ID: <179149241177.3924.14135711198031428935@35d72aa18c5b> # Security update 5.2.1 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:24055-1 Release Date: 2026-10-08T09:47:48Z Rating: important References: * bsc#1218722 * bsc#1252286 * bsc#1254400 * bsc#1257151 * bsc#1257599 * bsc#1259989 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262187 * bsc#1262319 * bsc#1262429 * bsc#1262492 * bsc#1262654 * bsc#1262803 * bsc#1263254 * bsc#1263330 * bsc#1263442 * bsc#1263822 * bsc#1263823 * bsc#1264962 * bsc#1265267 * bsc#1265268 * bsc#1265413 * bsc#1265525 * bsc#1265763 * bsc#1266481 * bsc#1266608 * bsc#1266669 * bsc#1267261 * bsc#1267528 * bsc#1267534 * bsc#1267538 * bsc#1267581 * bsc#1267821 * bsc#1267980 * bsc#1268325 * bsc#1268395 * bsc#1268396 * bsc#1268397 * bsc#1268649 * bsc#1268755 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269841 * bsc#1269856 * bsc#1269959 * bsc#1269966 * bsc#1270033 * bsc#1270285 * bsc#1270398 * bsc#1270399 * bsc#1271192 * bsc#1271330 * bsc#1271428 * bsc#1271613 * bsc#1272008 * bsc#1272102 * bsc#1272427 * bsc#1273094 * bsc#1273144 * bsc#1274217 * bsc#1274221 * bsc#1275205 * bsc#1275206 * bsc#1275207 * bsc#1275934 * bsc#1276426 * bsc#1276658 * bsc#1276973 * bsc#1277025 * bsc#1278307 * bsc#1278322 * jsc#MSQA-1060 * jsc#PED-16707 Cross-References: * CVE-2023-45289 * CVE-2024-22195 * CVE-2025-13836 * CVE-2025-4673 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-1229 * CVE-2026-13346 * CVE-2026-14199 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-17033 * CVE-2026-17183 * CVE-2026-19197 * CVE-2026-19475 * CVE-2026-21723 * CVE-2026-2303 * CVE-2026-27459 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-33814 * CVE-2026-3446 * CVE-2026-3479 * CVE-2026-39821 * CVE-2026-39882 * CVE-2026-40181 * CVE-2026-40475 * CVE-2026-41066 * CVE-2026-41178 * CVE-2026-41606 * CVE-2026-42211 * CVE-2026-42342 * CVE-2026-4360 * CVE-2026-44431 * CVE-2026-44990 * CVE-2026-45409 * CVE-2026-4786 * CVE-2026-49825 * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 * CVE-2026-53606 * CVE-2026-56852 * CVE-2026-6019 * CVE-2026-6100 * CVE-2026-6357 * CVE-2026-7210 * CVE-2026-73501 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-8609 * CVE-2026-8643 CVSS scores: * CVE-2023-45289 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-45289 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4673 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2025-4673 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-1229 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-1229 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2026-1229 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber * CVE-2026-1229 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-14199 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-14199 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-14199 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-17033 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-17033 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L * CVE-2026-17033 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L * CVE-2026-17183 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-17183 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-19197 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19197 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19475 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19475 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21723 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21723 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2303 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-2303 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-2303 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3479 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3479 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-3479 ( NVD ): 0.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39882 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39882 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40181 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-40181 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40181 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-40475 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42211 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-42211 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42342 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42342 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44431 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44431 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44431 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44431 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-44990 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-44990 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44990 ( NVD ): 9.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N * CVE-2026-44990 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-49825 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49853 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49854 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53606 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53606 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73501 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-73501 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8609 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-8609 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-8609 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 * SUSE Linux Micro 6.2 * SUSE Multi-Linux Manager Client Tools for SLE 16 An update that solves 54 vulnerabilities, contains two features and has 20 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-prometheus was updated to version 3.13.2: * Security issues: * CVE-2026-39821: Fixed validation bypass and privilege escalation in Punycode label handling (bsc#1266608) * CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in unicode/norm handling (bsc#1272102) * CVE-2026-44990: Fixed stored XSS in the new React UI by sanitizing disallowed xmp elements (bsc#1275205) * CVE-2026-53606: Fixed incomplete URI scheme validation in sanitize-html that could enable XSS (bsc#1269966) * CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in mongo-driver (bsc#1269856) * CVE-2025-4673: Fixed credential leaks by stopping HTTP client header forwarding on redirects (bsc#1275206) * CVE-2023-45289: Fixed credential leaks by stopping header and cookie forwarding on HTTP redirects (bsc#1275207) * CVE-2026-40181: Fixed open redirect risks to external domains via relative paths in react-router (bsc#1267528) * CVE-2026-42342: Fixed DoS risks via unbounded path expansion in the manifest endpoint (bsc#1267538) * CVE-2026-42211: Fixed remote code execution risks from prototype pollution in react-router (bsc#1267534) * CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading in OpenTelemetry (bsc#1274221) * Fixed potential denial-of-service vulnerabilities by updating the gRPC dependency * Fixed memory exhaustion and DoS by rejecting snappy-compressed requests exceeding 32MB limit * Bug fixes and changes: * Fixed scrape manager failing to reload properly when SD configuration changes rapidly. * Prevent memory leak in remote-write path when the receiving endpoint is unavailable. * Native Histograms are no longer experimental. They are fully supported for production workloads. * Added support for OpenTelemetry traces within the Prometheus UI to correlate metrics and traces. * TSDB compaction speed optimized by improving the block merging algorithm. * Allow scraping of multiple targets using a single HTTP/2 connection to reduce overhead. * Added new metrics to monitor the health of the rule evaluation engine. * Incompatible: This affects scraping, remote read and write, alerting, and SD. Network paths might need adjustments to avoid redirects. * Incompatible: Rule group pagination tokens now use SHA-256 instead of MD5. Custom API consumers must adapt to the new longer token format. * Added 'group_limit' parameter to PromQL aggregations to restrict the number of results. * Incompatible: promtool relative paths in config files now resolve relative to the config directory itself, instead of the current working directory. * Support exporting TSDB blocks directly to cloud storage via the admin API. * Incompatible: Deprecated remote-write metrics like prometheus_remote_storage_samples_total are removed in favor of prometheus_wal_watcher_records_read_total. * Significant query performance boost for high-cardinality regex matchers. * Introduce a new UI interface for safely deleting specific time series data directly. * Added dynamic relabeling actions to extract substrings using regex capture groups. * Fixed UI displaying incorrect time ranges after a timezone change. * Bumped firewalld-prometheus-config to version 0.2 bumping OpenTelemetry to 1.43.0 grafana was updated to version 12.4.10: * Security issues: * CVE-2026-17183: Fixed exposing data accessible through Grafana's configured datasource credentials (bsc#1275934) * CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in mongo-driver (bsc#1269841) * CVE-2026-17033: Fixed stored cross-site scripting risks via malicious Alertmanager generator URLs (bsc#1276426) * CVE-2026-73501: Fixed fail-open authentication bypass in kin-openapi default handlers (bsc#1276973) * CVE-2026-19475: Fixed DoS risks in PostgreSQL Datasource by checking timeGroup macros (bsc#1278307) * CVE-2026-14199: Fixed auth bypass or session takeover via Auth Proxy cache key collision (bsc#1278322) * CVE-2026-19197: Fixed access control and authorization checks in dashboard snapshots (bsc#1277025) * CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in unicode/norm (bsc#1272008) * CVE-2026-41178: Fixed denial-of-service risks in OpenTelemetry baggage parsing (bsc#1276658) * CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading in OpenTelemetry (bsc#1274217) * CVE-2026-33814: Fixed infinite loop in HTTP/2 transport during framesize check (bsc#1265763) * CVE-2026-8609: Fixed pre-authentication denial-of-service risks in OAuth login routes (bsc#1271330) * CVE-2026-1229: Fixed incorrect value calculation in ecc/p384 Package (bsc#1265525, bsc#1262187) * CVE-2026-21723: Fixed out-of-memory and denial-of-service risks in templates test endpoint (bsc#1272427) * CVE-2026-41606: Fixed denial-of-service risks from nested messages in Apache Thrift parser (bsc#1263330) * Bug fixes and changes: * Dashboards: Fix adhoc and groupby variable datasource on UI import * Dashboards: Fix version dates and user display names in the legacy version history page * Dashboard Import: Labels in v2 schema * Azure Monitor: fix migration for dimension filters * Dashboards: Get annotations and dashboard endpoint performance improvements * DashboardDS: Fix Mixed panels with a time override stuck in permanent loading * Alerting: Add protected fields authorization check to provisioning API * Alerting: Return 403 instead of 500 on contact point provenance mismatch * Jaeger: Handle gzip, deflate, and brotli compressed API responses * Alerting: fix ORM table mapping bug causing SELECT alert_rule columns FROM user on PostgreSQL spacecmd was updated to version 5.2.10: * Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261) * Updated translation strings uyuni-tools was updated to version 5.2.17: Security issues fixed: * CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481) Bug fixes and changes: * Version 5.2.17-0: * Bump the default image tag to 5.2.1 * Reload systemd daemon before restarting services (bsc#1270033) * Check all supported locations for CA file in rotation check script * Detect and fix legacy service file (bsc#1268755) * Use healthcheck cmd from the image (bsc#1273144) * Version 5.2.16-0: * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398) * Version 5.2.15-0: * Added requirement for at least Podman v4.7.2 * Send READY notification to systemd only once healthy (bsc#1263823) * Version 5.2.14-0: * Include the server environment file in the backup (bsc#1268649) * Added mgradm commands for SSL CA and certificate rotation * Version 5.2.13-0: * Check and warn if CA certificate isn't marked as critical * Disable SSL on database during split (bsc#1267980) * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980) * Check backup status only after database is started (bsc#1262492) venv-salt-minion: * Security issues: * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094) * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066) * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969) * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581) * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959) * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319) * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654) * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098) * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962) * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821) * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268) * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977) * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788) * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192) * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669) * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442) * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429) * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599) * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722) * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413) * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267) * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285) * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254) * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970) * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989) * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428) * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395) * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396) * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397) * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803) * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400) * Bug fixes and changes: * Updated bundled python module pip to 25.0.1 * Updated bundled python module jinja2 to 3.1.6 * Updated bundled python module lxml to 6.1.1 * Prevent broken Salt Bundle on Ubuntu due regression in "tar" package from Ubuntu repositories (bsc#1271613) * Remove unused paramiko python module from the bundle. * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) * Support attrlist in ldap.managed (bsc#1257151) * Use AsyncHTTPClient in salt.utils.http (bsc#1268325) * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE 16 zypper in -t patch Multi-Linux-ManagerTools-SLE-16-6 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 16 (aarch64 ppc64le s390x x86_64) * mgrctl-5.2.17-160002.1.1 * golang-github-prometheus-prometheus-debuginfo-3.13.2-160002.1.1 * grafana-debuginfo-12.4.10-160002.1.1 * golang-github-prometheus-prometheus-3.13.2-160002.1.1 * grafana-12.4.10-160002.1.1 * mgrctl-debuginfo-5.2.17-160002.1.1 * venv-salt-minion-3006.0-160002.7.1 * SUSE Multi-Linux Manager Client Tools for SLE 16 (noarch) * spacecmd-5.2.10-160002.1.1 * mgrctl-bash-completion-5.2.17-160002.1.1 * mgrctl-lang-5.2.17-160002.1.1 * mgrctl-zsh-completion-5.2.17-160002.1.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45289.html * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-4673.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-1229.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-14199.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-17033.html * https://www.suse.com/security/cve/CVE-2026-17183.html * https://www.suse.com/security/cve/CVE-2026-19197.html * https://www.suse.com/security/cve/CVE-2026-19475.html * https://www.suse.com/security/cve/CVE-2026-21723.html * https://www.suse.com/security/cve/CVE-2026-2303.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-3479.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39882.html * https://www.suse.com/security/cve/CVE-2026-40181.html * https://www.suse.com/security/cve/CVE-2026-40475.html * https://www.suse.com/security/cve/CVE-2026-41066.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-41606.html * https://www.suse.com/security/cve/CVE-2026-42211.html * https://www.suse.com/security/cve/CVE-2026-42342.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-44431.html * https://www.suse.com/security/cve/CVE-2026-44990.html * https://www.suse.com/security/cve/CVE-2026-45409.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-49825.html * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://www.suse.com/security/cve/CVE-2026-53606.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-73501.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-8609.html * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1252286 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1257151 * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1259989 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262187 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1262803 * https://bugzilla.suse.com/show_bug.cgi?id=1263254 * https://bugzilla.suse.com/show_bug.cgi?id=1263330 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 * https://bugzilla.suse.com/show_bug.cgi?id=1263822 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265267 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1265413 * https://bugzilla.suse.com/show_bug.cgi?id=1265525 * https://bugzilla.suse.com/show_bug.cgi?id=1265763 * https://bugzilla.suse.com/show_bug.cgi?id=1266481 * https://bugzilla.suse.com/show_bug.cgi?id=1266608 * https://bugzilla.suse.com/show_bug.cgi?id=1266669 * https://bugzilla.suse.com/show_bug.cgi?id=1267261 * https://bugzilla.suse.com/show_bug.cgi?id=1267528 * https://bugzilla.suse.com/show_bug.cgi?id=1267534 * https://bugzilla.suse.com/show_bug.cgi?id=1267538 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267980 * https://bugzilla.suse.com/show_bug.cgi?id=1268325 * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 * https://bugzilla.suse.com/show_bug.cgi?id=1268649 * https://bugzilla.suse.com/show_bug.cgi?id=1268755 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269841 * https://bugzilla.suse.com/show_bug.cgi?id=1269856 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1269966 * https://bugzilla.suse.com/show_bug.cgi?id=1270033 * https://bugzilla.suse.com/show_bug.cgi?id=1270285 * https://bugzilla.suse.com/show_bug.cgi?id=1270398 * https://bugzilla.suse.com/show_bug.cgi?id=1270399 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1271330 * https://bugzilla.suse.com/show_bug.cgi?id=1271428 * https://bugzilla.suse.com/show_bug.cgi?id=1271613 * https://bugzilla.suse.com/show_bug.cgi?id=1272008 * https://bugzilla.suse.com/show_bug.cgi?id=1272102 * https://bugzilla.suse.com/show_bug.cgi?id=1272427 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1273144 * https://bugzilla.suse.com/show_bug.cgi?id=1274217 * https://bugzilla.suse.com/show_bug.cgi?id=1274221 * https://bugzilla.suse.com/show_bug.cgi?id=1275205 * https://bugzilla.suse.com/show_bug.cgi?id=1275206 * https://bugzilla.suse.com/show_bug.cgi?id=1275207 * https://bugzilla.suse.com/show_bug.cgi?id=1275934 * https://bugzilla.suse.com/show_bug.cgi?id=1276426 * https://bugzilla.suse.com/show_bug.cgi?id=1276658 * https://bugzilla.suse.com/show_bug.cgi?id=1276973 * https://bugzilla.suse.com/show_bug.cgi?id=1277025 * https://bugzilla.suse.com/show_bug.cgi?id=1278307 * https://bugzilla.suse.com/show_bug.cgi?id=1278322 * https://jira.suse.com/browse/MSQA-1060 * https://jira.suse.com/browse/PED-16707 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Oct 9 12:30:34 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Fri, 09 Oct 2026 12:30:34 -0000 Subject: SUSE-SU-2026:4597-1: important: Security update for bind Message-ID: <179154903418.27557.7165782989740661411@35d72aa18c5b> # Security update for bind Announcement ID: SUSE-SU-2026:4597-1 Release Date: 2026-10-08T22:03:19Z Rating: important References: * bsc#1280433 * bsc#1280435 * bsc#1280443 Cross-References: * CVE-2026-19666 * CVE-2026-19667 * CVE-2026-80274 CVSS scores: * CVE-2026-19666 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-19666 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19666 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19667 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-19667 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19667 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80274 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80274 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves three vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2026-19666: Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (bsc#1280433). * CVE-2026-19667: Remote assertion failure via 16-bit length truncation in dns_ncache_add() (bsc#1280435). * CVE-2026-80274: Validating resolver can abort while caching a mismatched NOQNAME proof (bsc#1280443). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-4597 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * libisc1606-debuginfo-9.16.6-150000.12.94.1 * libbind9-1600-debuginfo-9.16.6-150000.12.94.1 * libisccc1600-debuginfo-9.16.6-150000.12.94.1 * libisccc1600-9.16.6-150000.12.94.1 * libns1604-debuginfo-9.16.6-150000.12.94.1 * libirs1601-9.16.6-150000.12.94.1 * bind-debuginfo-9.16.6-150000.12.94.1 * bind-debugsource-9.16.6-150000.12.94.1 * libisccfg1600-9.16.6-150000.12.94.1 * libns1604-9.16.6-150000.12.94.1 * libdns1605-debuginfo-9.16.6-150000.12.94.1 * libirs1601-debuginfo-9.16.6-150000.12.94.1 * bind-utils-debuginfo-9.16.6-150000.12.94.1 * libisccfg1600-debuginfo-9.16.6-150000.12.94.1 * libisc1606-9.16.6-150000.12.94.1 * libbind9-1600-9.16.6-150000.12.94.1 * libdns1605-9.16.6-150000.12.94.1 * bind-utils-9.16.6-150000.12.94.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.94.1 ## References: * https://www.suse.com/security/cve/CVE-2026-19666.html * https://www.suse.com/security/cve/CVE-2026-19667.html * https://www.suse.com/security/cve/CVE-2026-80274.html * https://bugzilla.suse.com/show_bug.cgi?id=1280433 * https://bugzilla.suse.com/show_bug.cgi?id=1280435 * https://bugzilla.suse.com/show_bug.cgi?id=1280443 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Oct 9 16:30:55 2026 From: null at suse.de (SUSE-MANAGER-UPDATES) Date: Fri, 09 Oct 2026 16:30:55 -0000 Subject: SUSE-RU-2026:4601-1: moderate: Recommended update for system-user-grafana, system-user-prometheus Message-ID: <179156345549.1649.10917850653521193363@929e079ff995> # Recommended update for system-user-grafana, system-user-prometheus Announcement ID: SUSE-RU-2026:4601-1 Release Date: 2026-10-09T09:03:32Z Rating: moderate References: * jsc#MSQA-1060 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 * SUSE Linux Enterprise Desktop 15 SP1 * SUSE Linux Enterprise Desktop 15 SP2 * SUSE Linux Enterprise Desktop 15 SP3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP1 * SUSE Linux Enterprise Real Time 15 SP2 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Multi-Linux Manager Client Tools for SLE 15 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 * SUSE Package Hub 15 15-SP7 An update that contains one feature can now be installed. ## Description: This update for system-user-grafana, system-user-prometheus fixes the following issues: system-user-grafana, system-user-prometheus: * Build only for SUSE distributions ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4601 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4601 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4601 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4601 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4601 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4601 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4601 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4601 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4601 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4601 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4601 * SUSE Multi-Linux Manager Client Tools for SLE 15 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-15-2026-4601 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-4601 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4601 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * system-user-prometheus-1.0.0-150000.19.2 * Basesystem Module 15-SP7 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Package Hub 15 15-SP7 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Multi-Linux Manager Client Tools for SLE 15 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * system-user-grafana-1.0.0-150000.3.22.2 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * system-user-prometheus-1.0.0-150000.19.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * system-user-prometheus-1.0.0-150000.19.2 ## References: * https://jira.suse.com/browse/MSQA-1060 -------------- next part -------------- An HTML attachment was scrubbed... URL: