FlawAtlas
Search the atlas
SUSE-SU-2026:2763-1 Not scored

Security update 5.1.4 for Multi-Linux Manager Client Tools

This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security issue fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Security issues fixed: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) - CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) - Version 1.8.x: - Fixed CPU pressure metric collection, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: - Non customer facing changes spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes uyuni-tools: uyuni-tools updated to version 5.2.12: - Key Update Highlights (v5.2.11-0) - Improved pod readiness checks (bsc#1266012) - Key Update Highlights (v5.2.10-0) - Preserve hub replicas during upgrade (bsc#1262708) - Added mgrctl 'ssh' and 'ssh remove_known_host' commands - Fixed startup checks for main server container (bsc#1263157) - Fixed service dependencies (bsc#1263823) - Updated default tag to 5.1.3.1 (bsc#1262760) - Fixed missing registry for db image (bsc#1259739) - Fixed Report DB CA certificate (bsc#1260806) - Key Update Highlights (v5.2.7-0) - Admin secrets no longer required on upgrades (bsc#1262409) - Key Update Highlights (v5.2.6-0) - Fixed database online backup - mgrctl copy command now infers target name automatically - Restored TFTP port to proxy (bsc#1260905) - TFTP disabled by default on server - Key Update Highlights (v5.2.5-0) - Removed migrate command - Removed hub register command - Split TFTP server into separate container - Removed Kubernetes install/upgrade from mgrpxy - Key Update Highlights (v5.2.1-0) - Fixed --dbupgrade-tag parameter (bsc#1249400) - Added --registry-host, --registry-user, --registry-password options - Deprecated --registry option - Added SUSE Linux Enterprise 15 SP7 support - Migrated custom SSL CA certificates (bsc#1232641) - Other changes (v5.2.1-0 to v5.2.12-0): - Translation strings updates - Internal updates with version bump but without customer facing changes venv-salt-minion: - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)

Exploit probability Not scored
Published July 6, 2026
Required by Not available
Last source change July 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-urllib3
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-tornado
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update prometheus-postgres_exporter
SUSE:Multi Linux Manager Tools EL-9 prometheus-postgres_exporter
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update scap-security-guide
SUSE:Multi Linux Manager Tools EL-9 scap-security-guide
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update golang-packaging
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-passlib-test
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-wheel
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update golang-github-prometheus-promu
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update golang-github-lusitaniae-apache_exporter
SUSE:Multi Linux Manager Tools EL-9 golang-github-lusitaniae-apache_exporter
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update uyuni-tools
SUSE:Multi Linux Manager Tools EL-9 uyuni-tools
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update fdupes
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-passlib
SUSE:Multi Linux Manager Tools EL-9 golang-github-QubitProducts-exporter_exporter
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-pyopenssl
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-core
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundle-swig
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-m2crypto
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update go1.22-EL
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update spacecmd
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update golang-github-prometheus-node_exporter
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-pynacl
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update venv-salt-minion
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-lxml
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-docker
SUSE:Multi Linux Manager Tools EL-9 spacecmd
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundle-zeromq
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundle-libsodium
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-wheel-test
SUSE:Multi Linux Manager Tools EL-9 golang-github-prometheus-node_exporter
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update golang-github-QubitProducts-exporter_exporter
SUSE:Multi Linux Manager Tools EL-9 venv-salt-minion
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy-requests
SUSE:EL-9:Update:Products:MultiLinuxManagerTools:Update saltbundlepy

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2763-1

This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security issue fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Security issues fixed: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) - CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) - Version 1.8.x: - Fixed CPU pressure metric collection, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: - Non customer facing changes spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes uyuni-tools: uyuni-tools updated to version 5.2.12: - Key Update Highlights (v5.2.11-0) - Improved pod readiness checks (bsc#1266012) - Key Update Highlights (v5.2.10-0) - Preserve hub replicas during upgrade (bsc#1262708) - Added mgrctl 'ssh' and 'ssh remove_known_host' commands - Fixed startup checks for main server container (bsc#1263157) - Fixed service dependencies (bsc#1263823) - Updated default tag to 5.1.3.1 (bsc#1262760) - Fixed missing registry for db image (bsc#1259739) - Fixed Report DB CA certificate (bsc#1260806) - Key Update Highlights (v5.2.7-0) - Admin secrets no longer required on upgrades (bsc#1262409) - Key Update Highlights (v5.2.6-0) - Fixed database online backup - mgrctl copy command now infers target name automatically - Restored TFTP port to proxy (bsc#1260905) - TFTP disabled by default on server - Key Update Highlights (v5.2.5-0) - Removed migrate command - Removed hub register command - Split TFTP server into separate container - Removed Kubernetes install/upgrade from mgrpxy - Key Update Highlights (v5.2.1-0) - Fixed --dbupgrade-tag parameter (bsc#1249400) - Added --registry-host, --registry-user, --registry-password options - Deprecated --registry option - Added SUSE Linux Enterprise 15 SP7 support - Migrated custom SSL CA certificates (bsc#1232641) - Other changes (v5.2.1-0 to v5.2.12-0): - Translation strings updates - Internal updates with version bump but without customer facing changes venv-salt-minion: - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)

View original source

05 / REFERENCES

Further evidence