Security update 5.1.4 for Multi-Linux Manager Client Tools
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security issue fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Security issues fixed: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) - CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) - Version 1.8.x: - Fixed CPU pressure metric collection, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: - Non customer facing changes spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes uyuni-tools: uyuni-tools updated to version 5.2.12: - Key Update Highlights (v5.2.11-0) - Improved pod readiness checks (bsc#1266012) - Key Update Highlights (v5.2.10-0) - Preserve hub replicas during upgrade (bsc#1262708) - Added mgrctl 'ssh' and 'ssh remove_known_host' commands - Fixed startup checks for main server container (bsc#1263157) - Fixed service dependencies (bsc#1263823) - Updated default tag to 5.1.3.1 (bsc#1262760) - Fixed missing registry for db image (bsc#1259739) - Fixed Report DB CA certificate (bsc#1260806) - Key Update Highlights (v5.2.7-0) - Admin secrets no longer required on upgrades (bsc#1262409) - Key Update Highlights (v5.2.6-0) - Fixed database online backup - mgrctl copy command now infers target name automatically - Restored TFTP port to proxy (bsc#1260905) - TFTP disabled by default on server - Key Update Highlights (v5.2.5-0) - Removed migrate command - Removed hub register command - Split TFTP server into separate container - Removed Kubernetes install/upgrade from mgrpxy - Key Update Highlights (v5.2.1-0) - Fixed --dbupgrade-tag parameter (bsc#1249400) - Added --registry-host, --registry-user, --registry-password options - Deprecated --registry option - Added SUSE Linux Enterprise 15 SP7 support - Migrated custom SSL CA certificates (bsc#1232641) - Other changes (v5.2.1-0 to v5.2.12-0): - Translation strings updates - Internal updates with version bump but without customer facing changes venv-salt-minion: - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security issue fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Security issues fixed: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) - CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) - Version 1.8.x: - Fixed CPU pressure metric collection, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: - Security Fixes: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: - Non customer facing changes spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes uyuni-tools: uyuni-tools updated to version 5.2.12: - Key Update Highlights (v5.2.11-0) - Improved pod readiness checks (bsc#1266012) - Key Update Highlights (v5.2.10-0) - Preserve hub replicas during upgrade (bsc#1262708) - Added mgrctl 'ssh' and 'ssh remove_known_host' commands - Fixed startup checks for main server container (bsc#1263157) - Fixed service dependencies (bsc#1263823) - Updated default tag to 5.1.3.1 (bsc#1262760) - Fixed missing registry for db image (bsc#1259739) - Fixed Report DB CA certificate (bsc#1260806) - Key Update Highlights (v5.2.7-0) - Admin secrets no longer required on upgrades (bsc#1262409) - Key Update Highlights (v5.2.6-0) - Fixed database online backup - mgrctl copy command now infers target name automatically - Restored TFTP port to proxy (bsc#1260905) - TFTP disabled by default on server - Key Update Highlights (v5.2.5-0) - Removed migrate command - Removed hub register command - Split TFTP server into separate container - Removed Kubernetes install/upgrade from mgrpxy - Key Update Highlights (v5.2.1-0) - Fixed --dbupgrade-tag parameter (bsc#1249400) - Added --registry-host, --registry-user, --registry-password options - Deprecated --registry option - Added SUSE Linux Enterprise 15 SP7 support - Migrated custom SSL CA certificates (bsc#1232641) - Other changes (v5.2.1-0 to v5.2.12-0): - Translation strings updates - Internal updates with version bump but without customer facing changes venv-salt-minion: - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1227579
- https://bugzilla.suse.com/1229105
- https://bugzilla.suse.com/1232641
- https://bugzilla.suse.com/1235516
- https://bugzilla.suse.com/1236516
- https://bugzilla.suse.com/1238686
- https://bugzilla.suse.com/1248699
- https://bugzilla.suse.com/1248707
- https://bugzilla.suse.com/1249400
- https://bugzilla.suse.com/1249532
- https://bugzilla.suse.com/1253174
- https://bugzilla.suse.com/1254900
- https://bugzilla.suse.com/1257583
- https://bugzilla.suse.com/1259700
- https://bugzilla.suse.com/1259739
- https://bugzilla.suse.com/1260806
- https://bugzilla.suse.com/1260905
- https://bugzilla.suse.com/1261810
- https://bugzilla.suse.com/1261902
- https://bugzilla.suse.com/1262409
- https://bugzilla.suse.com/1262708
- https://bugzilla.suse.com/1262760
- https://bugzilla.suse.com/1263157
- https://bugzilla.suse.com/1263823
- https://bugzilla.suse.com/1266012
- https://www.suse.com/security/cve/CVE-2022-21698
- https://www.suse.com/security/cve/CVE-2023-45288
- https://www.suse.com/security/cve/CVE-2025-22870
- https://www.suse.com/support/update/announcement/2026/suse-su-20262763-1/