FlawAtlas
Search the atlas
SUSE-SU-2026:22770-1 Not scored

Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions

This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues: Security issues fixed: - CVE-2025-13465: lodash: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from global prototypes (bsc#1257325). - CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829). - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840). - CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641). - CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015). Non security issues fixed: - cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210). - cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149). Changes for cockpit: - Update to 364. - Update to 361 (jsc#PED-15706/jsc#CPT-183): * Remove all "Mount" actions in Anaconda mode * Dependency updates - Update to 360: * ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631 * ws: support loading a custom login page - Update to 358: * Networking: Add Wi-Fi support * Cockpit Client updated to GTK 4 * Bugfixes and translation updates - Update to 357: * lib: Use browser context menu on shift * bridge: support Python 3.14 on old kernels (RHEL 8) - Update to 356: * systemd: Allow editing timers created by Cockpit * Convert license headers to SPDX format - Update to 355: * ws: Remove obsolete pam_cockpit_cert module * shell: add StartTransientUnit as a sudo alternative Changes for cockpit-machines: - Update to 354. - Update to 352: - Improvements to the "Add disk" and "Create Volume" dialogs. - Update suse_version requirement to function with the planned bump (jsc#PED-15820). - Drop explict dependency on libvirt (bsc#1258040, bsc#1236149). - Update to 348: * Translation updates * Convert license headers to SPDX format * Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl - Update to 347: * Bug fixes and translation updates - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-packages: - Update to version 5: * Support transactional systems * Improve error/success messages * Translation updates - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-podman: - Update to 128. - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-repos: - Update to 4.8. - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-subscriptions: - Update to version 16.2 (bsc#1257033). - Patch esbuild to use native runtime on ppc64 (bsc#1257698).

Exploit probability Not scored
Published July 21, 2026
Required by Not available
Last source change July 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Micro 6.2 cockpit
SUSE:Linux Micro 6.2 cockpit-machines
SUSE:Linux Micro 6.2 cockpit-podman
SUSE:Linux Micro 6.2 cockpit-repos
SUSE:Linux Micro 6.2 cockpit-subscriptions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:22770-1

This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues: Security issues fixed: - CVE-2025-13465: lodash: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from global prototypes (bsc#1257325). - CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829). - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840). - CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641). - CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015). Non security issues fixed: - cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210). - cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149). Changes for cockpit: - Update to 364. - Update to 361 (jsc#PED-15706/jsc#CPT-183): * Remove all "Mount" actions in Anaconda mode * Dependency updates - Update to 360: * ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631 * ws: support loading a custom login page - Update to 358: * Networking: Add Wi-Fi support * Cockpit Client updated to GTK 4 * Bugfixes and translation updates - Update to 357: * lib: Use browser context menu on shift * bridge: support Python 3.14 on old kernels (RHEL 8) - Update to 356: * systemd: Allow editing timers created by Cockpit * Convert license headers to SPDX format - Update to 355: * ws: Remove obsolete pam_cockpit_cert module * shell: add StartTransientUnit as a sudo alternative Changes for cockpit-machines: - Update to 354. - Update to 352: - Improvements to the "Add disk" and "Create Volume" dialogs. - Update suse_version requirement to function with the planned bump (jsc#PED-15820). - Drop explict dependency on libvirt (bsc#1258040, bsc#1236149). - Update to 348: * Translation updates * Convert license headers to SPDX format * Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl - Update to 347: * Bug fixes and translation updates - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-packages: - Update to version 5: * Support transactional systems * Improve error/success messages * Translation updates - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-podman: - Update to 128. - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-repos: - Update to 4.8. - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-subscriptions: - Update to version 16.2 (bsc#1257033). - Patch esbuild to use native runtime on ppc64 (bsc#1257698).

View original source

05 / REFERENCES

Further evidence