Security update 5.1.4 for Multi-Linux Manager Client Tools
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security issue fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Security issues fixed: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) - CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) - Version 1.8.x: - Fixed CPU pressure metric collection, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts mgr-push updated to version 5.2.4: - Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-postgres_exporter: - Security issue fixed: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) python-simplejson: - Non customer facing changes rhnlib updated to version 5.2.5: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) uyuni-common-libs updated to version 5.2.5: - Key Update Highlights (v5.2.5-0): - Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly - Other changes: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) venv-salt-minion: - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Calculate UUID grain for Xen PV guests (bsc#1255418) - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Security issue fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Security issues fixed: - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) - CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) - Highlights of other changes and bug fixes: - Backward Compatibility and packaging changes: - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility - Version 1.10.2: - Fixed typo in Zswap metric name (meminfo) - Version 1.10.1: - Fixed mount points being collected multiple times (filesystem) - Refactored mountinfo parsing (bsc#1261810) - Added Zswap/Zswapped metrics (meminfo) - Version 1.10.0: - New collectors: PCIe devices, swaps - Added systemd virtualization metrics, AIX metrics - WiFi packet metrics, additional PCIe and TLB metrics - Changed mdadm to use sysfs, added erofs to excluded filesystems - Fixed bugs: cpufreq collector, ethtool metrics - Version 1.9.1: - Fixed missing IRQ on older kernels (pressure) - Version 1.9.0 (jsc#PED-12485): - Switched to Go log/slog for logging - Converted meminfo to use procfs library - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing - Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) - Version 1.8.x: - Fixed CPU pressure metric collection, pressure collector nil reference - Version 1.8.0: - New collectors: xfrm (IPsec), watchdog - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing - Removed caching of os-release file modtime/filename - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): - New: CPU vulnerabilities reporting from sysfs - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index - Version 1.6.0: - Deprecated ntp and supervisord collectors - Removed bcache cache_readaheads_totals metrics - Improved offline CPU handling (removed metrics for offline CPUs) - New: softirqs collector - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts mgr-push updated to version 5.2.4: - Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-postgres_exporter: - Security issue fixed: - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) python-simplejson: - Non customer facing changes rhnlib updated to version 5.2.5: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) uyuni-common-libs updated to version 5.2.5: - Key Update Highlights (v5.2.5-0): - Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly - Other changes: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) venv-salt-minion: - Improved shutdown reliability when the salt-master/minion is terminated - Fixed broken 'pkg.info_installed' after migration to salt.utils.timeutil - Calculate UUID grain for Xen PV guests (bsc#1255418) - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Hardened Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1227579
- https://bugzilla.suse.com/1235516
- https://bugzilla.suse.com/1236516
- https://bugzilla.suse.com/1238686
- https://bugzilla.suse.com/1248699
- https://bugzilla.suse.com/1248707
- https://bugzilla.suse.com/1249532
- https://bugzilla.suse.com/1253174
- https://bugzilla.suse.com/1254900
- https://bugzilla.suse.com/1255418
- https://bugzilla.suse.com/1257583
- https://bugzilla.suse.com/1259700
- https://bugzilla.suse.com/1261810
- https://www.suse.com/security/cve/CVE-2022-21698
- https://www.suse.com/security/cve/CVE-2023-45288
- https://www.suse.com/security/cve/CVE-2025-22870
- https://www.suse.com/support/update/announcement/2026/suse-su-20262765-1/