SUSE-SU-2026:4585-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264585-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4585-1
Upstream
CVE (58)
Related
Published
2026-10-08T08:24:34Z
Modified
2026-10-08T19:15:05Z
Summary
Security update 5.2.1 for Multi-Linux Manager Client Tools
Details

This update fixes the following issues:

golang-github-prometheus-prometheus was updated to version 3.13.2:

  • Security issues:

    • CVE-2026-39821: Fixed validation bypass and privilege escalation in Punycode label handling (bsc#1266608)
    • CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in unicode/norm handling (bsc#1272102)
    • CVE-2026-44990: Fixed stored XSS in the new React UI by sanitizing disallowed xmp elements (bsc#1275205)
    • CVE-2026-53606: Fixed incomplete URI scheme validation in sanitize-html that could enable XSS (bsc#1269966)
    • CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in mongo-driver (bsc#1269856)
    • CVE-2025-4673: Fixed credential leaks by stopping HTTP client header forwarding on redirects (bsc#1275206)
    • CVE-2023-45289: Fixed credential leaks by stopping header and cookie forwarding on HTTP redirects (bsc#1275207)
    • CVE-2025-61686: Fixed unauthorized file access and path traversal in react-router storage (bsc#1270711)
    • CVE-2026-40181: Fixed open redirect risks to external domains via relative paths in react-router (bsc#1267528)
    • CVE-2026-42342: Fixed DoS risks via unbounded path expansion in the manifest endpoint (bsc#1267538)
    • CVE-2026-42211: Fixed remote code execution risks from prototype pollution in react-router (bsc#1267534)
    • CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading in OpenTelemetry (bsc#1274221)
    • Fixed potential denial-of-service vulnerabilities by updating the gRPC dependency
    • Fixed memory exhaustion and DoS by rejecting snappy-compressed requests exceeding 32MB limit
  • Bug fixes and changes:

    • Fixed scrape manager failing to reload properly when SD configuration changes rapidly.
    • Prevent memory leak in remote-write path when the receiving endpoint is unavailable.
    • Native Histograms are no longer experimental. They are fully supported for production workloads.
    • Added support for OpenTelemetry traces within the Prometheus UI to correlate metrics and traces.
    • TSDB compaction speed optimized by improving the block merging algorithm.
    • Allow scraping of multiple targets using a single HTTP/2 connection to reduce overhead.
    • Added new metrics to monitor the health of the rule evaluation engine.
    • Incompatible: This affects scraping, remote read and write, alerting, and SD. Network paths might need adjustments to avoid redirects.
    • Incompatible: Rule group pagination tokens now use SHA-256 instead of MD5. Custom API consumers must adapt to the new longer token format.
    • Added 'group_limit' parameter to PromQL aggregations to restrict the number of results.
    • Incompatible: promtool relative paths in config files now resolve relative to the config directory itself, instead of the current working directory.
    • Support exporting TSDB blocks directly to cloud storage via the admin API.
    • Incompatible: Deprecated remote-write metrics like prometheus_remote_storage_samples_total are removed in favor of prometheus_wal_watcher_records_read_total.
    • Significant query performance boost for high-cardinality regex matchers.
    • Introduce a new UI interface for safely deleting specific time series data directly.
    • Added dynamic relabeling actions to extract substrings using regex capture groups.
    • Fixed UI displaying incorrect time ranges after a timezone change.
    • Bumped firewalld-prometheus-config to version 0.2 bumping OpenTelemetry to 1.43.0

grafana was updated to version 12.4.10:

  • Security issues:

    • CVE-2026-17183: Fixed exposing data accessible through Grafana's configured datasource credentials (bsc#1275934)
    • CVE-2026-2303: Fixed heap out-of-bounds read in GSSAPI error handling in mongo-driver (bsc#1269841)
    • CVE-2026-17033: Fixed stored cross-site scripting risks via malicious Alertmanager generator URLs (bsc#1276426)
    • CVE-2026-73501: Fixed fail-open authentication bypass in kin-openapi default handlers (bsc#1276973)
    • CVE-2026-19475: Fixed DoS risks in PostgreSQL Datasource by checking timeGroup macros (bsc#1278307)
    • CVE-2026-14199: Fixed auth bypass or session takeover via Auth Proxy cache key collision (bsc#1278322)
    • CVE-2026-19197: Fixed access control and authorization checks in dashboard snapshots (bsc#1277025)
    • CVE-2026-56852: Fixed infinite loop on truncated or invalid UTF-8 input in unicode/norm (bsc#1272008)
    • CVE-2026-41178: Fixed denial-of-service risks in OpenTelemetry baggage parsing (bsc#1276658)
    • CVE-2026-39882: Fixed memory exhaustion via uncapped HTTP response reading in OpenTelemetry (bsc#1274217)
    • CVE-2026-8595: Fixed stored XSS via malicious dashboard field names in table panels (bsc#1271557)
    • CVE-2026-42127: Fixed DoS risks in the public dashboard query endpoint (bsc#1268868)
    • CVE-2026-9029: Fixed arbitrary code execution and script injection in the geomap panel (bsc#1272328)
    • CVE-2026-33814: Fixed infinite loop in HTTP/2 transport during framesize check (bsc#1265763)
    • CVE-2026-8609: Fixed pre-authentication denial-of-service risks in OAuth login routes (bsc#1271330)
    • CVE-2026-1229: Fixed incorrect value calculation in ecc/p384 Package (bsc#1265525, bsc#1262187)
    • CVE-2025-12141: Fixed information disclosure of secure settings via contact point modification (bsc#1262187)
    • CVE-2026-21723: Fixed out-of-memory and denial-of-service risks in templates test endpoint (bsc#1272427)
    • CVE-2026-41606: Fixed denial-of-service risks from nested messages in Apache Thrift parser (bsc#1263330)
  • Bug fixes and changes:

    • Dashboards: Fix adhoc and groupby variable datasource on UI import
    • Dashboards: Fix version dates and user display names in the legacy version history page
    • Dashboard Import: Labels in v2 schema
    • Azure Monitor: fix migration for dimension filters
    • Dashboards: Get annotations and dashboard endpoint performance improvements
    • DashboardDS: Fix Mixed panels with a time override stuck in permanent loading
    • Alerting: Add protected fields authorization check to provisioning API
    • Alerting: Return 403 instead of 500 on contact point provenance mismatch
    • Jaeger: Handle gzip, deflate, and brotli compressed API responses
    • Alerting: fix ORM table mapping bug causing SELECT alert_rule columns FROM user on PostgreSQL

mgr-push was updated to version 5.2.5:

  • Removed token based authentication mechanism for package_push (bsc#1230949)

spacecmd was updated to version 5.2.10:

  • Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261)
  • Updated translation strings

spacewalk-client-tools was updated to version 5.2.7:

  • Updated translation strings

uyuni-tools was updated to version 5.2.17:

Security issues fixed:

  • CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)

Bug fixes and changes:

  • Version 5.2.17-0:

    • Bump the default image tag to 5.2.1
    • Reload systemd daemon before restarting services (bsc#1270033)
    • Check all supported locations for CA file in rotation check script
    • Detect and fix legacy service file (bsc#1268755)
    • Use healthcheck cmd from the image (bsc#1273144)
  • Version 5.2.16-0:

    • Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398)
  • Version 5.2.15-0:

    • Added requirement for at least Podman v4.7.2
    • Send READY notification to systemd only once healthy (bsc#1263823)
  • Version 5.2.14-0:

    • Include the server environment file in the backup (bsc#1268649)
    • Added mgradm commands for SSL CA and certificate rotation
  • Version 5.2.13-0:

    • Check and warn if CA certificate isn't marked as critical
    • Disable SSL on database during split (bsc#1267980)
    • Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980)
    • Check backup status only after database is started (bsc#1262492)

venv-salt-minion:

  • Security issues:

    • CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094)
    • CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066)
    • CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969)
    • CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581)
    • CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959)
    • CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319)
    • CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654)
    • CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098)
    • CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962)
    • CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821)
    • CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268)
    • CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977)
    • CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788)
    • CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192)
    • CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669)
    • CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442)
    • CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429)
    • CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599)
    • CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722)
    • CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413)
    • CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267)
    • CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285)
    • CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254)
    • CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970)
    • CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989)
    • CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428)
    • CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395)
    • CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396)
    • CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397)
    • CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803)
    • CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400)
  • Bug fixes and changes:

    • Updated bundled python module pip to 25.0.1
    • Updated bundled python module jinja2 to 3.1.6
    • Updated bundled python module lxml to 6.1.1
    • Prevent broken Salt Bundle on Ubuntu due regression in 'tar' package from Ubuntu repositories (bsc#1271613)
    • Remove unused paramiko python module from the bundle.
    • Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
    • Support attrlist in ldap.managed (bsc#1257151)
    • Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
    • Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)
References

Affected packages

SUSE:Multi Linux Manager Tools SLE-15
golang-github-prometheus-prometheus

Package

Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.13.2-150002.3.19.1

Ecosystem specific

{
    "binaries": [
        {
            "firewalld-prometheus-config": "0.2-150002.3.19.1",
            "golang-github-prometheus-prometheus": "3.13.2-150002.3.19.1",
            "grafana": "12.4.10-150002.4.27.1",
            "mgr-push": "5.2.5-150002.3.12.1",
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "python3-mgr-push": "5.2.5-150002.3.12.1",
            "python3-spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "spacecmd": "5.2.10-150002.3.15.1",
            "spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
grafana

Package

Name
grafana
Purl
pkg:rpm/suse/grafana&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.4.10-150002.4.27.1

Ecosystem specific

{
    "binaries": [
        {
            "firewalld-prometheus-config": "0.2-150002.3.19.1",
            "golang-github-prometheus-prometheus": "3.13.2-150002.3.19.1",
            "grafana": "12.4.10-150002.4.27.1",
            "mgr-push": "5.2.5-150002.3.12.1",
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "python3-mgr-push": "5.2.5-150002.3.12.1",
            "python3-spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "spacecmd": "5.2.10-150002.3.15.1",
            "spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
mgr-push

Package

Name
mgr-push
Purl
pkg:rpm/suse/mgr-push&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.5-150002.3.12.1

Ecosystem specific

{
    "binaries": [
        {
            "firewalld-prometheus-config": "0.2-150002.3.19.1",
            "golang-github-prometheus-prometheus": "3.13.2-150002.3.19.1",
            "grafana": "12.4.10-150002.4.27.1",
            "mgr-push": "5.2.5-150002.3.12.1",
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "python3-mgr-push": "5.2.5-150002.3.12.1",
            "python3-spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "spacecmd": "5.2.10-150002.3.15.1",
            "spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
spacecmd

Package

Name
spacecmd
Purl
pkg:rpm/suse/spacecmd&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.10-150002.3.15.1

Ecosystem specific

{
    "binaries": [
        {
            "firewalld-prometheus-config": "0.2-150002.3.19.1",
            "golang-github-prometheus-prometheus": "3.13.2-150002.3.19.1",
            "grafana": "12.4.10-150002.4.27.1",
            "mgr-push": "5.2.5-150002.3.12.1",
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "python3-mgr-push": "5.2.5-150002.3.12.1",
            "python3-spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "spacecmd": "5.2.10-150002.3.15.1",
            "spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
spacewalk-client-tools

Package

Name
spacewalk-client-tools
Purl
pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.7-150002.3.12.1

Ecosystem specific

{
    "binaries": [
        {
            "firewalld-prometheus-config": "0.2-150002.3.19.1",
            "golang-github-prometheus-prometheus": "3.13.2-150002.3.19.1",
            "grafana": "12.4.10-150002.4.27.1",
            "mgr-push": "5.2.5-150002.3.12.1",
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "python3-mgr-push": "5.2.5-150002.3.12.1",
            "python3-spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "spacecmd": "5.2.10-150002.3.15.1",
            "spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
uyuni-tools

Package

Name
uyuni-tools
Purl
pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.17-150002.3.20.1

Ecosystem specific

{
    "binaries": [
        {
            "firewalld-prometheus-config": "0.2-150002.3.19.1",
            "golang-github-prometheus-prometheus": "3.13.2-150002.3.19.1",
            "grafana": "12.4.10-150002.4.27.1",
            "mgr-push": "5.2.5-150002.3.12.1",
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "python3-mgr-push": "5.2.5-150002.3.12.1",
            "python3-spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "spacecmd": "5.2.10-150002.3.15.1",
            "spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
venv-salt-minion

Package

Name
venv-salt-minion
Purl
pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3006.0-150002.5.22.1

Ecosystem specific

{
    "binaries": [
        {
            "firewalld-prometheus-config": "0.2-150002.3.19.1",
            "golang-github-prometheus-prometheus": "3.13.2-150002.3.19.1",
            "grafana": "12.4.10-150002.4.27.1",
            "mgr-push": "5.2.5-150002.3.12.1",
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "python3-mgr-push": "5.2.5-150002.3.12.1",
            "python3-spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "spacecmd": "5.2.10-150002.3.15.1",
            "spacewalk-client-tools": "5.2.7-150002.3.12.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
SUSE:Multi Linux Manager Tools SLE-Micro-5
uyuni-tools

Package

Name
uyuni-tools
Purl
pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-Micro-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.2.17-150002.3.20.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"
venv-salt-minion

Package

Name
venv-salt-minion
Purl
pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-Micro-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3006.0-150002.5.22.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.2.17-150002.3.20.1",
            "mgrctl-bash-completion": "5.2.17-150002.3.20.1",
            "mgrctl-lang": "5.2.17-150002.3.20.1",
            "mgrctl-zsh-completion": "5.2.17-150002.3.20.1",
            "venv-salt-minion": "3006.0-150002.5.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4585-1.json"