FlawAtlas
Search the atlas
SUSE-SU-2026:2774-1 Not scored

Security update 5.1.4 for Multi-Linux Manager Server

This update fixes the following issues: Release Notes Highlights: - Update to SUSE Multi-Linux Manager 5.1.4 * Added note about migration for SUSE Linux Enterprise Server 16 on SSH managed minions * Product Migration from SUSE Linux Enterprise Server 15 SP7 to 16.0 * SUSE Liberty Linux 9.6 Support * New API Endpoint - listMigrationTargetsWithChannels * Debian 12 End-of-Life Notice * SUSE Registry URL Change * Security fixes: CVE-2026-34986, CVE-2026-41602, CVE-2026-39821, CVE-2026-42198 CVE-2022-21698, CVE-2026-40179, CVE-2026-42151, CVE-2026-42154 CVE-2026-28374, CVE-2026-28376, CVE-2026-28379, CVE-2026-28380 CVE-2026-28383, CVE-2026-33376, CVE-2026-33377, CVE-2026-33378 CVE-2026-33380, CVE-2026-33381 * Bugs mentioned: bsc#1226578, bsc#1234567, bsc#1238890, bsc#1242916, bsc#1245107 bsc#1247707, bsc#1248699, bsc#1249243, bsc#1253032, bsc#1257583 bsc#1257894, bsc#1258041, bsc#1258079, bsc#1258144, bsc#1258382 bsc#1258816, bsc#1259087, bsc#1259230, bsc#1259261, bsc#1259474 bsc#1259479, bsc#1259482, bsc#1259521, bsc#1259590, bsc#1259591 bsc#1259700, bsc#1259739, bsc#1259787, bsc#1259960, bsc#1260031 bsc#1260614, bsc#1260806, bsc#1261305, bsc#1261307, bsc#1261327 bsc#1261631, bsc#1261723, bsc#1261753, bsc#1261841, bsc#1261902 bsc#1262090, bsc#1262285, bsc#1262460, bsc#1262471, bsc#1262492 bsc#1262595, bsc#1262708, bsc#1262720, bsc#1262761, bsc#1263814 bsc#1263841, bsc#1264149, bsc#1264234, bsc#1264256, bsc#1264966 bsc#1265134, bsc#1265319, bsc#1265358, bsc#1265975, bsc#1266012 bsc#1262950, bsc#1263501, bsc#1266600, bsc#1266556, bsc#1264174 bsc#1262222, bsc#1263986, bsc#1263987, bsc#1265290, bsc#1265289 bsc#1265288, bsc#1265287, bsc#1265286, bsc#1265285, bsc#1265284 bsc#1265283, bsc#1265282, bsc#1265281, bsc#1269253, bsc#1269534 Container images and uyuni-tools changes: server-attestation-image: - Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: - Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: - Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Added 'susemanager-tools', 'susemanager' and 'susemanager-tools-salt' packages to server-image server-migration-14-16-image: - Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: - Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: - Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: - Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) - Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: - Added the distro signature for rhel10 (bsc#1265134) liberate-formula: - Version 0.1.4 * No customer facing changes - Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: - Version 1.4.3 * Added support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: - CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: - Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fixed the issue of using non-vendored tornado with Python 3.11 salt: - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: - Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: - Version 5.1.14-0 * Update translation strings spacewalk-backend: - Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt-minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: - Version 5.1.28-0 * Check access rights on two formula API calls (bsc#1269253) * Sanitize uploaded image name (bsc#1269534) - Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fixed CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fixed missing translations (bsc#1259787) * Fixed hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fixed enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fixed Remote Commands hang on direct hostname (bsc#1226578) * Fixed Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Added 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt-minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Added missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fixed Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fixed CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fixed conflicting cobbler system migrations spacewalk-web: - Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Fixed an issue where the 'Create Token' modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) subscription-matcher: - Version 0.44 * Fixed 2 missing part numbers (bsc#1264256) susemanager: - Version 5.1.17-0 * Added SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Removed spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicensed mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: - Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: - Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones - Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD - Added Code 16 to Monitoring documentation (bsc#1263814) - Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) - Rephrased instructions for RBAC in Administration Guide (bsc#1258079) - Added troubleshooting section for BTRFS to Administration Guide (bcs#1258816) - Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) - Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) - Removed mention of CIS profile (bsc#1262460) - Corrected path for Salt minion in Retail Guide (#1262090) - Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) - Removed Google Cloud Compute from PAYG documentation (bsc#1261631) - Added link to proxy creation from client to an existing document in Installation and Upgrade Guide - Updated features table for EL 10 based distributions - Document Debian 13 - Added support for Open Enterprise Server 25.4 - Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) - SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) - Added instructions about accessing git repositories when building images to Administration Guide - Added online database backup instructions to Administration Guide - Fixed comamnd for product deployment in Installation and Upgrade Guide (bsc#1259479) - Added online database backup instructions susemanager-schema: - Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Added index on rhnPackage (checksum_id) (bsc#1258041) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Added 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: - Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fixed GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fixed CPU reporting for ppc64le clients (bsc#1259521) * Fixed refresh of virtual instance information (bsc#1261723) susemanager-sync-data: - Version 5.1.10-0 * Added missing RES-EMS channel family (bsc#1265358) - Version 5.1.9-0 * Added SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: - Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-reportdb-schema: - version 5.1.7-0 * Increased url on table repository (bsc#1259230) uyuni-setup-reportdb: - Version 5.1.5-0 * Fixed delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: - Version 1.0.31-0 * Dropped SUSECloud module as not longer maintainednor used - Version 1.0.30-0 * No customer facing changes How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgradm upgrade podman` which will use the default image tags.

Exploit probability Not scored
Published July 6, 2026
Required by Not available
Last source change July 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-proxy-squid-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-server-attestation-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-server-saline-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-proxy-squid-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-server-saline-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-server-saline-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-server-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-server-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-server-attestation-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-server-attestation-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-server-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-proxy-ssh-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-server-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-server-attestation-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-proxy-httpd-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-server-postgresql-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-x86_64-server-postgresql-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-server-saline-image
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 suse-multi-linux-manager-5.1-s390x-proxy-squid-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-aarch64-server-postgresql-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image
SUSE:Multi-Linux Manager Server Extension for SLE 5.1 uyuni-tools
SUSE:Multi-Linux Manager Proxy Extension for SLE 5.1 uyuni-tools

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2774-1

This update fixes the following issues: Release Notes Highlights: - Update to SUSE Multi-Linux Manager 5.1.4 * Added note about migration for SUSE Linux Enterprise Server 16 on SSH managed minions * Product Migration from SUSE Linux Enterprise Server 15 SP7 to 16.0 * SUSE Liberty Linux 9.6 Support * New API Endpoint - listMigrationTargetsWithChannels * Debian 12 End-of-Life Notice * SUSE Registry URL Change * Security fixes: CVE-2026-34986, CVE-2026-41602, CVE-2026-39821, CVE-2026-42198 CVE-2022-21698, CVE-2026-40179, CVE-2026-42151, CVE-2026-42154 CVE-2026-28374, CVE-2026-28376, CVE-2026-28379, CVE-2026-28380 CVE-2026-28383, CVE-2026-33376, CVE-2026-33377, CVE-2026-33378 CVE-2026-33380, CVE-2026-33381 * Bugs mentioned: bsc#1226578, bsc#1234567, bsc#1238890, bsc#1242916, bsc#1245107 bsc#1247707, bsc#1248699, bsc#1249243, bsc#1253032, bsc#1257583 bsc#1257894, bsc#1258041, bsc#1258079, bsc#1258144, bsc#1258382 bsc#1258816, bsc#1259087, bsc#1259230, bsc#1259261, bsc#1259474 bsc#1259479, bsc#1259482, bsc#1259521, bsc#1259590, bsc#1259591 bsc#1259700, bsc#1259739, bsc#1259787, bsc#1259960, bsc#1260031 bsc#1260614, bsc#1260806, bsc#1261305, bsc#1261307, bsc#1261327 bsc#1261631, bsc#1261723, bsc#1261753, bsc#1261841, bsc#1261902 bsc#1262090, bsc#1262285, bsc#1262460, bsc#1262471, bsc#1262492 bsc#1262595, bsc#1262708, bsc#1262720, bsc#1262761, bsc#1263814 bsc#1263841, bsc#1264149, bsc#1264234, bsc#1264256, bsc#1264966 bsc#1265134, bsc#1265319, bsc#1265358, bsc#1265975, bsc#1266012 bsc#1262950, bsc#1263501, bsc#1266600, bsc#1266556, bsc#1264174 bsc#1262222, bsc#1263986, bsc#1263987, bsc#1265290, bsc#1265289 bsc#1265288, bsc#1265287, bsc#1265286, bsc#1265285, bsc#1265284 bsc#1265283, bsc#1265282, bsc#1265281, bsc#1269253, bsc#1269534 Container images and uyuni-tools changes: server-attestation-image: - Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: - Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: - Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Added 'susemanager-tools', 'susemanager' and 'susemanager-tools-salt' packages to server-image server-migration-14-16-image: - Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: - Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: - Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: - Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) - Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: - Added the distro signature for rhel10 (bsc#1265134) liberate-formula: - Version 0.1.4 * No customer facing changes - Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: - Version 1.4.3 * Added support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: - CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: - Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fixed the issue of using non-vendored tornado with Python 3.11 salt: - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: - Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: - Version 5.1.14-0 * Update translation strings spacewalk-backend: - Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt-minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: - Version 5.1.28-0 * Check access rights on two formula API calls (bsc#1269253) * Sanitize uploaded image name (bsc#1269534) - Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fixed CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fixed missing translations (bsc#1259787) * Fixed hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fixed enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fixed Remote Commands hang on direct hostname (bsc#1226578) * Fixed Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Added 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt-minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Added missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fixed Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fixed CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fixed conflicting cobbler system migrations spacewalk-web: - Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin → Setup Wizard * Fixed an issue where the 'Create Token' modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) subscription-matcher: - Version 0.44 * Fixed 2 missing part numbers (bsc#1264256) susemanager: - Version 5.1.17-0 * Added SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Removed spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicensed mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: - Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: - Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones - Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD - Added Code 16 to Monitoring documentation (bsc#1263814) - Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) - Rephrased instructions for RBAC in Administration Guide (bsc#1258079) - Added troubleshooting section for BTRFS to Administration Guide (bcs#1258816) - Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) - Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) - Removed mention of CIS profile (bsc#1262460) - Corrected path for Salt minion in Retail Guide (#1262090) - Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) - Removed Google Cloud Compute from PAYG documentation (bsc#1261631) - Added link to proxy creation from client to an existing document in Installation and Upgrade Guide - Updated features table for EL 10 based distributions - Document Debian 13 - Added support for Open Enterprise Server 25.4 - Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) - SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) - Added instructions about accessing git repositories when building images to Administration Guide - Added online database backup instructions to Administration Guide - Fixed comamnd for product deployment in Installation and Upgrade Guide (bsc#1259479) - Added online database backup instructions susemanager-schema: - Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Added index on rhnPackage (checksum_id) (bsc#1258041) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Added 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: - Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fixed GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fixed CPU reporting for ppc64le clients (bsc#1259521) * Fixed refresh of virtual instance information (bsc#1261723) susemanager-sync-data: - Version 5.1.10-0 * Added missing RES-EMS channel family (bsc#1265358) - Version 5.1.9-0 * Added SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: - Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-reportdb-schema: - version 5.1.7-0 * Increased url on table repository (bsc#1259230) uyuni-setup-reportdb: - Version 5.1.5-0 * Fixed delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: - Version 1.0.31-0 * Dropped SUSECloud module as not longer maintainednor used - Version 1.0.30-0 * No customer facing changes How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgradm upgrade podman` which will use the default image tags.

View original source

05 / REFERENCES

Further evidence