Security update 5.0.8 for Multi-Linux Manager Client Tools
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707) golang-github-prometheus-node_exporter: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics golang-github-prometheus-prometheus: - Security issues fixed: - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987). - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (bsc#1262222) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260267) * Bump google.golang.org/grpc to version 1.79.3 - CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * Bump rollup to version 4.59.0 - Other changes: - Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit. - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) prometheus-postgres_exporter: - Security Fixes: - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987) - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) - Highlights of other changes and bug fixes: - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy grafana was updated from version 11.6.11 to 11.6.14+security01: - Security Fixes: - CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950) - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) - CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results (bsc#1258595) - CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873) - CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881) - CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025) - CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026) - CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029) - CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263) - CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878) - Highlights of other changes and bug fixes: - Version 11.6.13: - Wire the public dashboard service to the HTTP server - Version 11.6.12: - Update authentication redirect logic - Fixed single panel render with variable references spacecmd: - Version 5.0.16-0: - Update translation strings uyuni-tools: - Version 0.1.39-0: - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) - Fixed default value for helm registry (bsc#1258927). - Use static supportconfig name to avoid dynamic search (bsc#1257941) - Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) - Show where final tarball was generated (bsc#1259208)
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707) golang-github-prometheus-node_exporter: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics golang-github-prometheus-prometheus: - Security issues fixed: - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987). - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (bsc#1262222) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260267) * Bump google.golang.org/grpc to version 1.79.3 - CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * Bump rollup to version 4.59.0 - Other changes: - Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit. - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) prometheus-postgres_exporter: - Security Fixes: - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987) - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986) - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) - Highlights of other changes and bug fixes: - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy grafana was updated from version 11.6.11 to 11.6.14+security01: - Security Fixes: - CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950) - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) - CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results (bsc#1258595) - CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873) - CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881) - CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025) - CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026) - CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029) - CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027) - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263) - CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878) - Highlights of other changes and bug fixes: - Version 11.6.13: - Wire the public dashboard service to the HTTP server - Version 11.6.12: - Update authentication redirect logic - Fixed single panel render with variable references spacecmd: - Version 5.0.16-0: - Update translation strings uyuni-tools: - Version 0.1.39-0: - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) - Fixed default value for helm registry (bsc#1258927). - Use static supportconfig name to avoid dynamic search (bsc#1257941) - Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) - Show where final tarball was generated (bsc#1259208)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1248699
- https://bugzilla.suse.com/1248707
- https://bugzilla.suse.com/1252964
- https://bugzilla.suse.com/1254619
- https://bugzilla.suse.com/1257941
- https://bugzilla.suse.com/1258595
- https://bugzilla.suse.com/1258873
- https://bugzilla.suse.com/1258893
- https://bugzilla.suse.com/1258927
- https://bugzilla.suse.com/1259208
- https://bugzilla.suse.com/1259999
- https://bugzilla.suse.com/1260263
- https://bugzilla.suse.com/1260267
- https://bugzilla.suse.com/1260878
- https://bugzilla.suse.com/1260881
- https://bugzilla.suse.com/1261025
- https://bugzilla.suse.com/1261026
- https://bugzilla.suse.com/1261027
- https://bugzilla.suse.com/1261029
- https://bugzilla.suse.com/1261810
- https://bugzilla.suse.com/1262222
- https://bugzilla.suse.com/1262950
- https://bugzilla.suse.com/1263501
- https://bugzilla.suse.com/1263986
- https://bugzilla.suse.com/1263987
- https://www.suse.com/security/cve/CVE-2022-21698
- https://www.suse.com/security/cve/CVE-2025-29923
- https://www.suse.com/security/cve/CVE-2026-21724
- https://www.suse.com/security/cve/CVE-2026-21725
- https://www.suse.com/security/cve/CVE-2026-26958
- https://www.suse.com/security/cve/CVE-2026-27606
- https://www.suse.com/security/cve/CVE-2026-27876
- https://www.suse.com/security/cve/CVE-2026-27877
- https://www.suse.com/security/cve/CVE-2026-27879
- https://www.suse.com/security/cve/CVE-2026-28375
- https://www.suse.com/security/cve/CVE-2026-33186
- https://www.suse.com/security/cve/CVE-2026-33375
- https://www.suse.com/security/cve/CVE-2026-34986
- https://www.suse.com/security/cve/CVE-2026-40179
- https://www.suse.com/security/cve/CVE-2026-41602
- https://www.suse.com/security/cve/CVE-2026-42151
- https://www.suse.com/security/cve/CVE-2026-42154
- https://www.suse.com/support/update/announcement/2026/suse-su-20262243-1/