Security update 5.1.4 for Multi-Linux Manager Client Tools
This update fixes the following issues: dracut-saltboot updated to version 1.2.1: - Key Update Highlights (v1.2.1) - Added wait check for minion start (default 10s), configurable using rd.saltboot.salt_start_timeout option (bsc#1260870) - Decouple salt key wait check to use separate configurable option rd.saltboot.salt_key_timeout, with default 60s - Introduce rd.saltboot namespace for all options, mark old as deprecated golang-github-QubitProducts-exporter_exporter: - Security issues fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-boynux-squid_exporter: - Non customer facing changes golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-alertmanager: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Key Update Highlights (v1.10.0 to v1.10.2): - New Collectors: Added new collectors for PCIe devices and swaps. - New Metrics: Introduced metrics for Zswap/Zswapped, Systemd Virtualization, and WiFi packets (received/transmitted) - Bug Fixes: Resolved a duplicate collection bug in filesystem mount points, fixed a Zswap metric typo, and patched a logging race condition in systemd. - Changes: Switched mdadm to use sysfs for RAID metrics, and added erofs to the default excluded filesystems list. - Internal Refactoring: filesystem mountinfo parsing refactor (bsc#1261810) golang-github-prometheus-prometheus updated to version 3.5.3: - Security issues fixed: - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (v3.5.3) (bsc#1263986) - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the limit (v3.5.3) (bsc#1263987) - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (v3.5.2) (bsc#1262222). - CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (backported patch) (bsc#1266608) - Other changes: - Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) - Internal update with non customer facing changes (v3.5.1) grafana updated to version 11.6.14+security-04: - Security issues fixed in v11.6.14+security-04: - CVE-2026-28374: Fixed insecure direct object reference in Annotations API (bsc#1265290) - CVE-2026-28376: Fixed unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) - CVE-2026-28383: Fixed unbounded memory allocation in Grafana plugin resources (bsc#1265286) - CVE-2026-28380: Fixed broken access control in Snapshot API (bsc#1265287) - CVE-2026-33376: Fixed Auth Proxy IPv6 whitelist bypass (bsc#1265285) - CVE-2026-28379: Fixed viewer-triggered race condition in Grafana Live (bsc#1265288) - CVE-2026-33377: Fixed dashboard Editor Privilege Escalation (bsc#1265284) - CVE-2026-33378: Fixed OOM exception in Grafana Data Source Plugin (bsc#1265283) - CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) - CVE-2026-33380: Fixed vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server’s filesystem (bsc#1265282) - Security issues fixed through backported patches: - CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) - CVE-2026-34986: Fixed panic in JWE decryption (bsc#1262950) - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) - CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Fixed multiple issues when parsing HTML files (bsc#1267153) mgr-push updated to version 5.2.4: - Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-blackbox_exporter: - Security issues fixed: - CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266556) prometheus-postgres_exporter: - Security issues fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) rhnlib updated to version 5.2.5: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) supportutils-plugin-salt: - Non customer facing changes supportutils-plugin-susemanager-client updated to version 5.2.3: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.3-0) uyuni-tools updated to version 5.2.12: - Key Update Highlights (v5.2.11-0) - Improved pod readiness checks (bsc#1266012) - Key Update Highlights (v5.2.10-0) - Preserve hub replicas during upgrade (bsc#1262708) - Added mgrctl 'ssh' and 'ssh remove_known_host' commands - Fixed startup checks for main server container (bsc#1263157) - Fixed service dependencies (bsc#1263823) - Updated default tag to 5.1.3.1 (bsc#1262760) - Fixed missing registry for db image (bsc#1259739) - Internal SANs for db and reportdb are no longer required - Generate the same certificate for server and reportdb - Fixed Report DB CA certificate (bsc#1260806) - Removed waitForTraefik function (bsc#1261902) - Key Update Highlights (v5.2.8-0) - Generate service template only after secrets are created - Key Update Highlights (v5.2.7-0) - Admin secrets no longer required on upgrades (bsc#1262409) - Key Update Highlights (v5.2.6-0): - Use podman secrets for SSL on proxy - Fixed database online backup - mgrctl copy command now infers target name automatically - Restored TFTP port to proxy (bsc#1260905) - TFTP disabled by default on server - Fixed incorrect package dependencies declaration (bsc#1229105) - Prevent cobbler port from being exposed - Bumped zerolog to 1.34 - Ignore spacewalk-service stop return code. - Stop automatically unhealthy container - Use container based server setup instead tools bundled one - Key Update Highlights (v5.2.5-0) - Removed migrate command - Removed hub register command - Split TFTP server into separate container - Removed Kubernetes install/upgrade from mgrpxy - Key Update Highlights (v5.2.1-0) - Fixed --dbupgrade-tag parameter (bsc#1249400) - Added --registry-host, --registry-user, --registry-password options - Deprecated --registry option - Added SUSE Linux Enterprise 15 SP7 support - Migrated custom SSL CA certificates (bsc#1232641) - Other changes (v5.2.1-0 to v5.2.12-0): - Translation strings updates - Internal updates with version bump but without customer facing changes uyuni-common-libs updated to version 5.2.5: - Key Update Highlights (v5.2.5-0): - Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly - Other changes: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update fixes the following issues: dracut-saltboot updated to version 1.2.1: - Key Update Highlights (v1.2.1) - Added wait check for minion start (default 10s), configurable using rd.saltboot.salt_start_timeout option (bsc#1260870) - Decouple salt key wait check to use separate configurable option rd.saltboot.salt_key_timeout, with default 60s - Introduce rd.saltboot namespace for all options, mark old as deprecated golang-github-QubitProducts-exporter_exporter: - Security issues fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-boynux-squid_exporter: - Non customer facing changes golang-github-lusitaniae-apache_exporter: - Non customer facing changes golang-github-prometheus-alertmanager: - Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: - Key Update Highlights (v1.10.0 to v1.10.2): - New Collectors: Added new collectors for PCIe devices and swaps. - New Metrics: Introduced metrics for Zswap/Zswapped, Systemd Virtualization, and WiFi packets (received/transmitted) - Bug Fixes: Resolved a duplicate collection bug in filesystem mount points, fixed a Zswap metric typo, and patched a logging race condition in systemd. - Changes: Switched mdadm to use sysfs for RAID metrics, and added erofs to the default excluded filesystems list. - Internal Refactoring: filesystem mountinfo parsing refactor (bsc#1261810) golang-github-prometheus-prometheus updated to version 3.5.3: - Security issues fixed: - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (v3.5.3) (bsc#1263986) - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the limit (v3.5.3) (bsc#1263987) - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (v3.5.2) (bsc#1262222). - CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (backported patch) (bsc#1266608) - Other changes: - Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) - Internal update with non customer facing changes (v3.5.1) grafana updated to version 11.6.14+security-04: - Security issues fixed in v11.6.14+security-04: - CVE-2026-28374: Fixed insecure direct object reference in Annotations API (bsc#1265290) - CVE-2026-28376: Fixed unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) - CVE-2026-28383: Fixed unbounded memory allocation in Grafana plugin resources (bsc#1265286) - CVE-2026-28380: Fixed broken access control in Snapshot API (bsc#1265287) - CVE-2026-33376: Fixed Auth Proxy IPv6 whitelist bypass (bsc#1265285) - CVE-2026-28379: Fixed viewer-triggered race condition in Grafana Live (bsc#1265288) - CVE-2026-33377: Fixed dashboard Editor Privilege Escalation (bsc#1265284) - CVE-2026-33378: Fixed OOM exception in Grafana Data Source Plugin (bsc#1265283) - CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) - CVE-2026-33380: Fixed vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server’s filesystem (bsc#1265282) - Security issues fixed through backported patches: - CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) - CVE-2026-34986: Fixed panic in JWE decryption (bsc#1262950) - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) - CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Fixed multiple issues when parsing HTML files (bsc#1267153) mgr-push updated to version 5.2.4: - Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-blackbox_exporter: - Security issues fixed: - CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266556) prometheus-postgres_exporter: - Security issues fixed: - CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) rhnlib updated to version 5.2.5: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: - Key Update Highlights (v5.2.3-0): - Fixed typo in spacecmd help ca-cert flag (bsc#1253174) - Add subcommand to check if reboot is needed after applying all available patches - Key Update Highlights (v5.2.1-0): - Use JSON instead of pickle for spacecmd cache (bsc#1227579) - Fixed methods in api namespace in spacecmd (bsc#1249532) - Other changes (v5.2.2-0 to 5.2.8-0): - Translation strings updates - Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) supportutils-plugin-salt: - Non customer facing changes supportutils-plugin-susemanager-client updated to version 5.2.3: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.3-0) uyuni-tools updated to version 5.2.12: - Key Update Highlights (v5.2.11-0) - Improved pod readiness checks (bsc#1266012) - Key Update Highlights (v5.2.10-0) - Preserve hub replicas during upgrade (bsc#1262708) - Added mgrctl 'ssh' and 'ssh remove_known_host' commands - Fixed startup checks for main server container (bsc#1263157) - Fixed service dependencies (bsc#1263823) - Updated default tag to 5.1.3.1 (bsc#1262760) - Fixed missing registry for db image (bsc#1259739) - Internal SANs for db and reportdb are no longer required - Generate the same certificate for server and reportdb - Fixed Report DB CA certificate (bsc#1260806) - Removed waitForTraefik function (bsc#1261902) - Key Update Highlights (v5.2.8-0) - Generate service template only after secrets are created - Key Update Highlights (v5.2.7-0) - Admin secrets no longer required on upgrades (bsc#1262409) - Key Update Highlights (v5.2.6-0): - Use podman secrets for SSL on proxy - Fixed database online backup - mgrctl copy command now infers target name automatically - Restored TFTP port to proxy (bsc#1260905) - TFTP disabled by default on server - Fixed incorrect package dependencies declaration (bsc#1229105) - Prevent cobbler port from being exposed - Bumped zerolog to 1.34 - Ignore spacewalk-service stop return code. - Stop automatically unhealthy container - Use container based server setup instead tools bundled one - Key Update Highlights (v5.2.5-0) - Removed migrate command - Removed hub register command - Split TFTP server into separate container - Removed Kubernetes install/upgrade from mgrpxy - Key Update Highlights (v5.2.1-0) - Fixed --dbupgrade-tag parameter (bsc#1249400) - Added --registry-host, --registry-user, --registry-password options - Deprecated --registry option - Added SUSE Linux Enterprise 15 SP7 support - Migrated custom SSL CA certificates (bsc#1232641) - Other changes (v5.2.1-0 to v5.2.12-0): - Translation strings updates - Internal updates with version bump but without customer facing changes uyuni-common-libs updated to version 5.2.5: - Key Update Highlights (v5.2.5-0): - Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly - Other changes: - Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1227579
- https://bugzilla.suse.com/1229105
- https://bugzilla.suse.com/1232641
- https://bugzilla.suse.com/1248699
- https://bugzilla.suse.com/1248707
- https://bugzilla.suse.com/1249400
- https://bugzilla.suse.com/1249532
- https://bugzilla.suse.com/1253174
- https://bugzilla.suse.com/1259739
- https://bugzilla.suse.com/1260806
- https://bugzilla.suse.com/1260870
- https://bugzilla.suse.com/1260905
- https://bugzilla.suse.com/1261810
- https://bugzilla.suse.com/1261902
- https://bugzilla.suse.com/1262222
- https://bugzilla.suse.com/1262409
- https://bugzilla.suse.com/1262708
- https://bugzilla.suse.com/1262760
- https://bugzilla.suse.com/1262950
- https://bugzilla.suse.com/1263157
- https://bugzilla.suse.com/1263501
- https://bugzilla.suse.com/1263823
- https://bugzilla.suse.com/1263986
- https://bugzilla.suse.com/1263987
- https://bugzilla.suse.com/1265281
- https://bugzilla.suse.com/1265282
- https://bugzilla.suse.com/1265283
- https://bugzilla.suse.com/1265284
- https://bugzilla.suse.com/1265285
- https://bugzilla.suse.com/1265286
- https://bugzilla.suse.com/1265287
- https://bugzilla.suse.com/1265288
- https://bugzilla.suse.com/1265289
- https://bugzilla.suse.com/1265290
- https://bugzilla.suse.com/1266012
- https://bugzilla.suse.com/1266556
- https://bugzilla.suse.com/1266600
- https://bugzilla.suse.com/1266608
- https://bugzilla.suse.com/1267153
- https://www.suse.com/security/cve/CVE-2022-21698
- https://www.suse.com/security/cve/CVE-2026-25680
- https://www.suse.com/security/cve/CVE-2026-25681
- https://www.suse.com/security/cve/CVE-2026-27136
- https://www.suse.com/security/cve/CVE-2026-28374
- https://www.suse.com/security/cve/CVE-2026-28376
- https://www.suse.com/security/cve/CVE-2026-28379
- https://www.suse.com/security/cve/CVE-2026-28380
- https://www.suse.com/security/cve/CVE-2026-28383
- https://www.suse.com/security/cve/CVE-2026-33376
- https://www.suse.com/security/cve/CVE-2026-33377
- https://www.suse.com/security/cve/CVE-2026-33378
- https://www.suse.com/security/cve/CVE-2026-33380
- https://www.suse.com/security/cve/CVE-2026-33381
- https://www.suse.com/security/cve/CVE-2026-34986
- https://www.suse.com/security/cve/CVE-2026-39821
- https://www.suse.com/security/cve/CVE-2026-40179
- https://www.suse.com/security/cve/CVE-2026-41602
- https://www.suse.com/security/cve/CVE-2026-42151
- https://www.suse.com/security/cve/CVE-2026-42154
- https://www.suse.com/security/cve/CVE-2026-42502
- https://www.suse.com/security/cve/CVE-2026-42506
- https://www.suse.com/support/update/announcement/2026/suse-su-20262768-1/