FlawAtlas
Search the atlas
SUSE-SU-2026:2243-1 Not scored

Security update 5.0.8 for Multi-Linux Manager Client Tools

This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707) golang-github-prometheus-node_exporter: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics golang-github-prometheus-prometheus: - Security issues fixed: - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987). - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (bsc#1262222) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260267) * Bump google.golang.org/grpc to version 1.79.3 - CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * Bump rollup to version 4.59.0 - Other changes: - Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit. - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) prometheus-postgres_exporter: - Security Fixes: - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987) - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) - Highlights of other changes and bug fixes: - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy grafana was updated from version 11.6.11 to 11.6.14+security01: - Security Fixes: - CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950) - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) - CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results (bsc#1258595) - CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873) - CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881) - CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025) - CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026) - CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029) - CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263) - CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878) - Highlights of other changes and bug fixes: - Version 11.6.13: - Wire the public dashboard service to the HTTP server - Version 11.6.12: - Update authentication redirect logic - Fixed single panel render with variable references spacecmd: - Version 5.0.16-0: - Update translation strings uyuni-tools: - Version 0.1.39-0: - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) - Fixed default value for helm registry (bsc#1258927). - Use static supportconfig name to avoid dynamic search (bsc#1257941) - Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) - Show where final tarball was generated (bsc#1259208)

Exploit probability Not scored
Published June 3, 2026
Required by Not available
Last source change June 4, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2243-1

This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707) golang-github-prometheus-node_exporter: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics golang-github-prometheus-prometheus: - Security issues fixed: - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987). - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (bsc#1262222) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260267) * Bump google.golang.org/grpc to version 1.79.3 - CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * Bump rollup to version 4.59.0 - Other changes: - Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit. - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) prometheus-postgres_exporter: - Security Fixes: - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987) - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) - Highlights of other changes and bug fixes: - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy grafana was updated from version 11.6.11 to 11.6.14+security01: - Security Fixes: - CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950) - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) - CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results (bsc#1258595) - CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873) - CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881) - CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025) - CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026) - CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029) - CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263) - CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878) - Highlights of other changes and bug fixes: - Version 11.6.13: - Wire the public dashboard service to the HTTP server - Version 11.6.12: - Update authentication redirect logic - Fixed single panel render with variable references spacecmd: - Version 5.0.16-0: - Update translation strings uyuni-tools: - Version 0.1.39-0: - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) - Fixed default value for helm registry (bsc#1258927). - Use static supportconfig name to avoid dynamic search (bsc#1257941) - Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) - Show where final tarball was generated (bsc#1259208)

View original source

05 / REFERENCES

Further evidence