FlawAtlas
Search the atlas
SUSE-SU-2024:1838-1 Not scored

Security update for warewulf4

This update for warewulf4 fixes the following issues: - fixed wwctl configure --all doesn't configure ssh (bsc#1225402) - update to 4.5.2 with following changes: * Reorder dnsmasq config to put iPXE last * Update go-digest dependency to fix CVE-2024-3727: digest values not always validated (bsc#1224124) - updated to version 4.5.1 with following changes * wwctl [profile|node] list -a handles now slices correclty * Fix a locking issue with concurrent read/writes for node status - Remove API package as use of this wasn't documented - use tftp.socket for activation (bsc#1216994)

Exploit probability Not scored
Published May 29, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for HPC 15 SP5 warewulf4
SUSE:Linux Enterprise Module for HPC 15 SP6 warewulf4
openSUSE:Leap 15.5 warewulf4
openSUSE:Leap 15.6 warewulf4

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2024:1838-1

This update for warewulf4 fixes the following issues: - fixed wwctl configure --all doesn't configure ssh (bsc#1225402) - update to 4.5.2 with following changes: * Reorder dnsmasq config to put iPXE last * Update go-digest dependency to fix CVE-2024-3727: digest values not always validated (bsc#1224124) - updated to version 4.5.1 with following changes * wwctl [profile|node] list -a handles now slices correclty * Fix a locking issue with concurrent read/writes for node status - Remove API package as use of this wasn't documented - use tftp.socket for activation (bsc#1216994)

View original source

05 / REFERENCES

Further evidence