openSUSE-SU-2026:21151-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21151-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21151-1
Upstream
CVE (5)
Related
Published
2026-06-23T09:37:25Z
Modified
2026-06-30T18:24:45Z
Summary
Security update for warewulf4
Details

This update for warewulf4 fixes the following issues:

Changes in warewulf4:

  • updated go-jose to fix CVE-2026-34986 (bsc#1262810)

  • chi is fixed in the upstream project

  • updating to v4.7.0 with following security fixes

  • fixed CVE-2026-39821 (bsc#1266483)
  • fixed CVE-2026-33814 (bsc#1265653)
  • v4.7.0 with significant changes relative to the v4.6.x series which are:

    • New wwctl unset command
    • Refactored server routes (URLs)
    • New /files/ route for serving individual files and templates
    • Server TLS support
    • Removed support for fetching individual overlays and individual files from overlays
    • Fixed whitespace handling around template functions
    • Security fixes, including updated Go and library versions
  • changes from v4.6.5:

    • new wwctl overlay info command
    • fixed wwctl image import --update option
    • cross-arch support for wwclient
    • improved IPv6 support
    • improved support for bonded interfaces
    • renamed debian.interfaces overlay to ifupdown
    • new systemd-networkd overlay
    • warewulf-dracut fixes, including "provision-to-disk" fixes
  • remove slurm-overlay package

  • fix CVE-2025-69725 (bsc#1258511) by updating chi

  • updated to v4.6.5 with following changes:

    • new wwctl overlay info command
    • fixed wwctl image import --update option (bsc#1254470)
    • cross-arch support for wwclient
    • improved IPv6 support
    • improved support for bonded interfaces
    • renamed debian.interfaces overlay to ifupdown
    • new systemd-networkd overlay
    • warewulf-dracut fixes, including "provision-to-disk" fixes
  • default to dnsmasq instead of dhcpd and tftp

References

Affected packages

openSUSE:Leap 16.0 / warewulf4

Package

Name
warewulf4
Purl
pkg:rpm/opensuse/warewulf4&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.7.0-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "warewulf4":  "4.7.0-bp160.1.1",
            "warewulf4-dracut":  "4.7.0-bp160.1.1",
            "warewulf4-man":  "4.7.0-bp160.1.1",
            "warewulf4-overlay":  "4.7.0-bp160.1.1",
            "warewulf4-overlay-rke2":  "4.7.0-bp160.1.1",
            "warewulf4-reference-doc":  "4.7.0-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21151-1.json"