SUSE-SU-2026:4584-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264584-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4584-1
Upstream
CVE (32)
Related
Published
2026-10-08T08:23:05Z
Modified
2026-10-08T19:15:04Z
Summary
Security update 5.2.1 for Multi-Linux Manager Client Tools
Details

This update fixes the following issues:

mgr-push was updated to version 5.2.5:

  • Removed token based authentication mechanism for package_push (bsc#1230949)

spacecmd was updated to version 5.2.10:

  • Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261)
  • Updated translation strings

spacewalk-client-tools was updated to version 5.2.7::

  • Updated translation strings

uyuni-tools was updated to version 5.2.17:

Security issues fixed:

  • CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)

Bug fixes and changes:

  • Version 5.2.17-0:

    • Bump the default image tag to 5.2.1
    • Reload systemd daemon before restarting services (bsc#1270033)
    • Check all supported locations for CA file in rotation check script
    • Detect and fix legacy service file (bsc#1268755)
    • Use healthcheck cmd from the image (bsc#1273144)
  • Version 5.2.16-0:

    • Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398)
  • Version 5.2.15-0:

    • Added requirement for at least Podman v4.7.2
    • Send READY notification to systemd only once healthy (bsc#1263823)
  • Version 5.2.14-0:

    • Include the server environment file in the backup (bsc#1268649)
    • Added mgradm commands for SSL CA and certificate rotation
  • Version 5.2.13-0:

    • Check and warn if CA certificate isn't marked as critical
    • Disable SSL on database during split (bsc#1267980)
    • Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980)
    • Check backup status only after database is started (bsc#1262492)

venv-salt-minion:

  • Security issues:

    • CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094)
    • CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066)
    • CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969)
    • CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581)
    • CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959)
    • CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319)
    • CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654)
    • CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098)
    • CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962)
    • CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821)
    • CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268)
    • CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977)
    • CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788)
    • CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192)
    • CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669)
    • CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442)
    • CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429)
    • CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599)
    • CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722)
    • CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413)
    • CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267)
    • CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285)
    • CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254)
    • CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970)
    • CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989)
    • CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428)
    • CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395)
    • CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396)
    • CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397)
    • CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803)
    • CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400)
  • Bug fixes and changes:

    • Updated bundled python module pip to 25.0.1
    • Updated bundled python module jinja2 to 3.1.6
    • Updated bundled python module lxml to 6.1.1
    • Prevent broken Salt Bundle on Ubuntu due regression in 'tar' package from Ubuntu repositories (bsc#1271613)
    • Remove unused paramiko python module from the bundle.
    • Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
    • Support attrlist in ldap.managed (bsc#1257151)
    • Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
    • Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)
References

Affected packages

SUSE:Multi Linux Manager Tools SLE-12
mgr-push

Package

Name
mgr-push
Purl
pkg:rpm/suse/mgr-push&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.5-120002.3.12.1

Ecosystem specific

{
    "binaries": [
        {
            "mgr-push": "5.2.5-120002.3.12.1",
            "mgrctl": "5.2.17-120002.3.18.1",
            "mgrctl-bash-completion": "5.2.17-120002.3.18.1",
            "mgrctl-lang": "5.2.17-120002.3.18.1",
            "mgrctl-zsh-completion": "5.2.17-120002.3.18.1",
            "python2-mgr-push": "5.2.5-120002.3.12.1",
            "python2-spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "spacecmd": "5.2.10-120002.3.15.1",
            "spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "venv-salt-minion": "3006.0-120002.5.22.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"
spacecmd

Package

Name
spacecmd
Purl
pkg:rpm/suse/spacecmd&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.10-120002.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "mgr-push": "5.2.5-120002.3.12.1",
            "mgrctl": "5.2.17-120002.3.18.1",
            "mgrctl-bash-completion": "5.2.17-120002.3.18.1",
            "mgrctl-lang": "5.2.17-120002.3.18.1",
            "mgrctl-zsh-completion": "5.2.17-120002.3.18.1",
            "python2-mgr-push": "5.2.5-120002.3.12.1",
            "python2-spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "spacecmd": "5.2.10-120002.3.15.1",
            "spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "venv-salt-minion": "3006.0-120002.5.22.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"
spacewalk-client-tools

Package

Name
spacewalk-client-tools
Purl
pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.7-120002.3.12.1

Ecosystem specific

{
    "binaries": [
        {
            "mgr-push": "5.2.5-120002.3.12.1",
            "mgrctl": "5.2.17-120002.3.18.1",
            "mgrctl-bash-completion": "5.2.17-120002.3.18.1",
            "mgrctl-lang": "5.2.17-120002.3.18.1",
            "mgrctl-zsh-completion": "5.2.17-120002.3.18.1",
            "python2-mgr-push": "5.2.5-120002.3.12.1",
            "python2-spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "spacecmd": "5.2.10-120002.3.15.1",
            "spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "venv-salt-minion": "3006.0-120002.5.22.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"
uyuni-tools

Package

Name
uyuni-tools
Purl
pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.17-120002.3.18.1

Ecosystem specific

{
    "binaries": [
        {
            "mgr-push": "5.2.5-120002.3.12.1",
            "mgrctl": "5.2.17-120002.3.18.1",
            "mgrctl-bash-completion": "5.2.17-120002.3.18.1",
            "mgrctl-lang": "5.2.17-120002.3.18.1",
            "mgrctl-zsh-completion": "5.2.17-120002.3.18.1",
            "python2-mgr-push": "5.2.5-120002.3.12.1",
            "python2-spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "spacecmd": "5.2.10-120002.3.15.1",
            "spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "venv-salt-minion": "3006.0-120002.5.22.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"
venv-salt-minion

Package

Name
venv-salt-minion
Purl
pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3006.0-120002.5.22.2

Ecosystem specific

{
    "binaries": [
        {
            "mgr-push": "5.2.5-120002.3.12.1",
            "mgrctl": "5.2.17-120002.3.18.1",
            "mgrctl-bash-completion": "5.2.17-120002.3.18.1",
            "mgrctl-lang": "5.2.17-120002.3.18.1",
            "mgrctl-zsh-completion": "5.2.17-120002.3.18.1",
            "python2-mgr-push": "5.2.5-120002.3.12.1",
            "python2-spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "spacecmd": "5.2.10-120002.3.15.1",
            "spacewalk-client-tools": "5.2.7-120002.3.12.1",
            "venv-salt-minion": "3006.0-120002.5.22.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"