SUSE-SU-2026:2830-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262830-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2830-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2830-1
Upstream
CVE (4)
Related
Published
2026-07-09T18:42:09Z
Modified
2026-07-10T10:00:08Z
Summary
Security update for warewulf4
Details

This update for warewulf4 fixes the following issues:

Update to v4.7.0.

Security issues fixed:

  • CVE-2025-69725: incorrect input validation in the RedirectSlashes function can lead to an open redirect (bsc#1258511).
  • CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE can lead to a denial of service (bsc#1265653).
  • CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262810).
  • CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266483).

Other updates and bugfixes:

  • Add correct flag --update-overlays fix (bsc#1268790).
  • v4.7.0:
    • New wwctl unset command
    • Refactored server routes (URLs)
    • New /files/ route for serving individual files and templates
    • Server TLS support
    • Removed support for fetching individual overlays and individual files from overlays
    • Fixed whitespace handling around template functions
    • Security fixes, including updated Go and library versions
  • v4.6.5:
    • New wwctl overlay info command
    • Fixed wwctl image import --update option
    • Cross-arch support for wwclient
    • Improved IPv6 support
    • Improved support for bonded interfaces
    • Renamed debian.interfaces overlay to ifupdown
    • New systemd-networkd overlay
    • warewulf-dracut fixes, including provision-to-disk fixes
  • Remove slurm-overlay package.
  • Fix wwctl image import --update option (bsc#1254470).
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
warewulf4

Package

Name
warewulf4
Purl
pkg:rpm/suse/warewulf4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.7.0-150500.6.42.1

Ecosystem specific

{
    "binaries":  [
        {
            "warewulf4":  "4.7.0-150500.6.42.1",
            "warewulf4-dracut":  "4.7.0-150500.6.42.1",
            "warewulf4-man":  "4.7.0-150500.6.42.1",
            "warewulf4-overlay":  "4.7.0-150500.6.42.1",
            "warewulf4-reference-doc":  "4.7.0-150500.6.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2830-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
warewulf4

Package

Name
warewulf4
Purl
pkg:rpm/suse/warewulf4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.7.0-150500.6.42.1

Ecosystem specific

{
    "binaries":  [
        {
            "warewulf4":  "4.7.0-150500.6.42.1",
            "warewulf4-dracut":  "4.7.0-150500.6.42.1",
            "warewulf4-man":  "4.7.0-150500.6.42.1",
            "warewulf4-overlay":  "4.7.0-150500.6.42.1",
            "warewulf4-reference-doc":  "4.7.0-150500.6.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2830-1.json"
SUSE:Linux Enterprise Module for HPC 15 SP7
warewulf4

Package

Name
warewulf4
Purl
pkg:rpm/suse/warewulf4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.7.0-150500.6.42.1

Ecosystem specific

{
    "binaries":  [
        {
            "warewulf4":  "4.7.0-150500.6.42.1",
            "warewulf4-dracut":  "4.7.0-150500.6.42.1",
            "warewulf4-man":  "4.7.0-150500.6.42.1",
            "warewulf4-overlay":  "4.7.0-150500.6.42.1",
            "warewulf4-reference-doc":  "4.7.0-150500.6.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2830-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
warewulf4

Package

Name
warewulf4
Purl
pkg:rpm/suse/warewulf4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.7.0-150500.6.42.1

Ecosystem specific

{
    "binaries":  [
        {
            "warewulf4":  "4.7.0-150500.6.42.1",
            "warewulf4-dracut":  "4.7.0-150500.6.42.1",
            "warewulf4-man":  "4.7.0-150500.6.42.1",
            "warewulf4-overlay":  "4.7.0-150500.6.42.1",
            "warewulf4-reference-doc":  "4.7.0-150500.6.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2830-1.json"