Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions
This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues: Security issues fixed: - CVE-2025-13465: lodash: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from global prototypes (bsc#1257325). - CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829). - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840). - CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641). - CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015). Non security issues fixed: - cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210). - cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149). Changes for cockpit: - Update to 364. - Update to 361 (jsc#PED-15706/jsc#CPT-183): * Remove all "Mount" actions in Anaconda mode * Dependency updates - Update to 360: * ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631 * ws: support loading a custom login page - Update to 358: * Networking: Add Wi-Fi support * Cockpit Client updated to GTK 4 * Bugfixes and translation updates - Update to 357: * lib: Use browser context menu on shift * bridge: support Python 3.14 on old kernels (RHEL 8) - Update to 356: * systemd: Allow editing timers created by Cockpit * Convert license headers to SPDX format - Update to 355: * ws: Remove obsolete pam_cockpit_cert module * shell: add StartTransientUnit as a sudo alternative Changes for cockpit-machines: - Update to 354. - Update to 352: - Improvements to the "Add disk" and "Create Volume" dialogs. - Update suse_version requirement to function with the planned bump (jsc#PED-15820). - Drop explict dependency on libvirt (bsc#1258040, bsc#1236149). - Update to 348: * Translation updates * Convert license headers to SPDX format * Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl - Update to 347: * Bug fixes and translation updates - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-packages: - Update to version 5: * Support transactional systems * Improve error/success messages * Translation updates - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-podman: - Update to 128. - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-repos: - Update to 4.8. - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-subscriptions: - Update to version 16.2 (bsc#1257033). - Patch esbuild to use native runtime on ppc64 (bsc#1257698).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues: Security issues fixed: - CVE-2025-13465: lodash: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from global prototypes (bsc#1257325). - CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829). - CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840). - CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641). - CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015). Non security issues fixed: - cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210). - cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149). Changes for cockpit: - Update to 364. - Update to 361 (jsc#PED-15706/jsc#CPT-183): * Remove all "Mount" actions in Anaconda mode * Dependency updates - Update to 360: * ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631 * ws: support loading a custom login page - Update to 358: * Networking: Add Wi-Fi support * Cockpit Client updated to GTK 4 * Bugfixes and translation updates - Update to 357: * lib: Use browser context menu on shift * bridge: support Python 3.14 on old kernels (RHEL 8) - Update to 356: * systemd: Allow editing timers created by Cockpit * Convert license headers to SPDX format - Update to 355: * ws: Remove obsolete pam_cockpit_cert module * shell: add StartTransientUnit as a sudo alternative Changes for cockpit-machines: - Update to 354. - Update to 352: - Improvements to the "Add disk" and "Create Volume" dialogs. - Update suse_version requirement to function with the planned bump (jsc#PED-15820). - Drop explict dependency on libvirt (bsc#1258040, bsc#1236149). - Update to 348: * Translation updates * Convert license headers to SPDX format * Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl - Update to 347: * Bug fixes and translation updates - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-packages: - Update to version 5: * Support transactional systems * Improve error/success messages * Translation updates - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-podman: - Update to 128. - Fix esbuild for ppc64le (bsc#1257698). Changes for cockpit-repos: - Update to 4.8. - Patch esbuild to use native runtime on ppc64 (bsc#1257698). Changes for cockpit-subscriptions: - Update to version 16.2 (bsc#1257033). - Patch esbuild to use native runtime on ppc64 (bsc#1257698).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1236149
- https://bugzilla.suse.com/1257033
- https://bugzilla.suse.com/1257325
- https://bugzilla.suse.com/1257698
- https://bugzilla.suse.com/1257836
- https://bugzilla.suse.com/1257838
- https://bugzilla.suse.com/1257840
- https://bugzilla.suse.com/1258040
- https://bugzilla.suse.com/1258637
- https://bugzilla.suse.com/1258640
- https://bugzilla.suse.com/1258641
- https://bugzilla.suse.com/1259010
- https://bugzilla.suse.com/1259013
- https://bugzilla.suse.com/1259015
- https://bugzilla.suse.com/1259210
- https://bugzilla.suse.com/1259774
- https://bugzilla.suse.com/1261829
- https://www.suse.com/security/cve/CVE-2025-13465
- https://www.suse.com/security/cve/CVE-2026-25547
- https://www.suse.com/security/cve/CVE-2026-26996
- https://www.suse.com/security/cve/CVE-2026-27904
- https://www.suse.com/security/cve/CVE-2026-4631
- https://www.suse.com/security/cve/CVE-2026-4802
- https://www.suse.com/support/update/announcement/2026/suse-su-202622837-1/