openSUSE-SU-2026:20581-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20581-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20581-1
Upstream
Related
Published
2026-04-14T16:21:55Z
Modified
2026-04-22T18:25:07Z
Summary
Security update for nebula
Details

This update for nebula fixes the following issues:

Changes in nebula:

  • Update to version 1.10.3:

    • Fix an issue where blocklist bypass is possible when using curve P256 Any newly issued P256 based certificates will have their signature clamped to the low-s form. Nebula will assert the low-s signature form when validating certificates in a future version
  • Update to version 1.10.2:

    • Fix panic when using use_system_route_table
  • Update to version 1.10.1:

    • Fix a bug where an unsafe route derived from the system route table could be lost on a config reload
    • Fix the PEM banner for ECDSA P256 public keys
    • Fix a bug in handshake processing when a peer sends an unexpected public key
    • Add a config option to control accepting recv_error packets which defaults to always
  • Update to version 1.10.0:

    • Support for ipv6 and multiple ipv4/6 addresses in the overlay
    • Add the ability to mark packets on linux to better target nebula packets in iptables/nftables
    • Add ECMP support for unsafe_routes
    • PKCS11 support for P256 keys when built with pkcs11 tag
    • default_local_cidr_any now defaults to false
    • Improve logging when a relay is in use on an inbound packet
    • Avoid fatal errors if rountines is > 1 on systems that <= 1
    • Log a warning if a firewall rule contains an any that negates a more restrictive filter
    • Accept encrypted CA passphrase from an environment variable
    • Allow handshaking with any trusted remote
    • Log only the count of blocklisted certificate fingerprints instead of the entire list
    • Don't fatal when the ssh server is unable to be configured successfully
    • Improve lost packet statistics
    • Honor remote_allow_list in hole punch response
  • remove patch fix-CVE-2025-22869.patch, fixed upstream

  • update to version 1.9.7:

    • Disable sending recv_error messages when a packet is received outside the allowable counter window
    • Improve error messages and remove some unnecessary fatal conditions in the generic udp listener
  • update to version 1.9.6:

    • Support dropping inactive tunnels. This is disabled by default
    • Ensure the same relay tunnel is always used when multiple relay tunnels are present
    • Fix relay migration panic
References

Affected packages

openSUSE:Leap 16.0 / nebula

Package

Name
nebula
Purl
pkg:rpm/opensuse/nebula&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.10.3-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "nebula":  "1.10.3-bp160.1.1",
            "nebula-cert":  "1.10.3-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20581-1.json"