FlawAtlas
Search the atlas
SUSE-SU-2026:2830-1 Not scored

Security update for warewulf4

This update for warewulf4 fixes the following issues: Update to v4.7.0. Security issues fixed: - CVE-2025-69725: incorrect input validation in the `RedirectSlashes` function can lead to an open redirect (bsc#1258511). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` can lead to a denial of service (bsc#1265653). - CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262810). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266483). Other updates and bugfixes: - Add correct flag `--update-overlays` fix (bsc#1268790). - v4.7.0: * New `wwctl` unset command * Refactored server routes (URLs) * New `/files/` route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - v4.6.5: * New wwctl overlay info command * Fixed `wwctl` image import `--update` option * Cross-arch support for `wwclient` * Improved IPv6 support * Improved support for bonded interfaces * Renamed `debian.interfaces` overlay to `ifupdown` * New `systemd-networkd` overlay * `warewulf-dracut` fixes, including `provision-to-disk` fixes - Remove `slurm-overlay` package. - Fix `wwctl` image import `--update` option (bsc#1254470).

Exploit probability Not scored
Published July 9, 2026
Required by Not available
Last source change July 10, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS warewulf4
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS warewulf4
SUSE:Linux Enterprise Module for HPC 15 SP7 warewulf4
SUSE:Linux Enterprise Server 15 SP6-LTSS warewulf4

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2830-1

This update for warewulf4 fixes the following issues: Update to v4.7.0. Security issues fixed: - CVE-2025-69725: incorrect input validation in the `RedirectSlashes` function can lead to an open redirect (bsc#1258511). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` can lead to a denial of service (bsc#1265653). - CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262810). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266483). Other updates and bugfixes: - Add correct flag `--update-overlays` fix (bsc#1268790). - v4.7.0: * New `wwctl` unset command * Refactored server routes (URLs) * New `/files/` route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - v4.6.5: * New wwctl overlay info command * Fixed `wwctl` image import `--update` option * Cross-arch support for `wwclient` * Improved IPv6 support * Improved support for bonded interfaces * Renamed `debian.interfaces` overlay to `ifupdown` * New `systemd-networkd` overlay * `warewulf-dracut` fixes, including `provision-to-disk` fixes - Remove `slurm-overlay` package. - Fix `wwctl` image import `--update` option (bsc#1254470).

View original source

05 / REFERENCES

Further evidence