Security update 5.0.8 for Multi-Linux Manager Client Tools
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707) golang-github-prometheus-node_exporter was updated from version 1.5.0 to 1.10.2: - Security Fixes: - Version 1.9.1: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (bsc#1238686) - Version 1.9.0: - CVE-2023-45288: Close connections when receiving too many headers (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Version 1.8.x: - Fixed CPU pressure metric collection, CPU seconds on Solaris, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: - Update the SSG package description - Add SLE16 profiles to the build - Updated to 0.1.79 (jsc#ECO-3319) - Create SLE16 HIPAA profile - Create SLE16 PCI DSS 4 profile - Use Sequoia in RHEL 10 instead of GPG - New Profile for RHEL10: BSI - Move RHEL Control files to product files - Update RHEL 9 CCN profile - Various updates for SLE 12/15 spacecmd: - Version 5.0.16-0 * Update translation strings uyuni-tools: - Version 0.1.39-0 * mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) * Fix default value for helm registry (bsc#1258927). * Use static supportconfig name to avoid dynamic search (bsc#1257941) * Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) * Show where final tarball was generated (bsc#1259208)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707) golang-github-prometheus-node_exporter was updated from version 1.5.0 to 1.10.2: - Security Fixes: - Version 1.9.1: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (bsc#1238686) - Version 1.9.0: - CVE-2023-45288: Close connections when receiving too many headers (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Version 1.8.x: - Fixed CPU pressure metric collection, CPU seconds on Solaris, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: - Update the SSG package description - Add SLE16 profiles to the build - Updated to 0.1.79 (jsc#ECO-3319) - Create SLE16 HIPAA profile - Create SLE16 PCI DSS 4 profile - Use Sequoia in RHEL 10 instead of GPG - New Profile for RHEL10: BSI - Move RHEL Control files to product files - Update RHEL 9 CCN profile - Various updates for SLE 12/15 spacecmd: - Version 5.0.16-0 * Update translation strings uyuni-tools: - Version 0.1.39-0 * mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) * Fix default value for helm registry (bsc#1258927). * Use static supportconfig name to avoid dynamic search (bsc#1257941) * Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) * Show where final tarball was generated (bsc#1259208)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1236516
- https://bugzilla.suse.com/1238686
- https://bugzilla.suse.com/1248699
- https://bugzilla.suse.com/1248707
- https://bugzilla.suse.com/1252964
- https://bugzilla.suse.com/1254619
- https://bugzilla.suse.com/1257941
- https://bugzilla.suse.com/1258927
- https://bugzilla.suse.com/1259208
- https://bugzilla.suse.com/1261810
- https://www.suse.com/security/cve/CVE-2022-21698
- https://www.suse.com/security/cve/CVE-2023-45288
- https://www.suse.com/security/cve/CVE-2025-22870
- https://www.suse.com/support/update/announcement//suse-el-9-client-tools-2026-2254/