openSUSE-SU-2026:21856-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21856-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21856-1
Upstream
CVE (2)
  • CVE-2026-44604
  • CVE-2026-44605
Related
Published
2026-09-16T14:28:22Z
Modified
2026-09-17T18:23:13Z
Summary
Security update for rpm
Details

This update for rpm fixes the following issues:

Changes in rpm:

  • split imaevmsign plugin into a multibuild flavor

Changes in rpm:

  • Add Requires: (rpm-plugin-selinux if selinux-policy)
  • harden ndb code [bsc#1269584] [CVE-2026-44605]
  • split all plugins into subpackages
    • this allows for an easy way to get rid of a plugin, it's also what other distributions do
  • make the imaevmsign plugin build in a multibuild flavor
  • rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150]
  • backport fix for add_sysuser macro [bsc#1269571]
  • backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604]
  • switch from rpmpgp_legacy to libpgpr
    • multiple bug fixes, support for v5 and v6 signatures
  • turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new "rpm-imaevmsign" subpackage. [jsc#PED-7246]
  • Fix "unexpected EOF" when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215)
  • Remove /var/lib/rpm migration scripting, retain an error if old location is found
  • Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139)
  • flush scriptlet notification messages in --runposttrans
    • needed to fix leaking tmp files [bsc#1218459]
    • added "rpm_flushes_runposttrans" provides for libzypp
References

Affected packages

openSUSE:Leap 16.0 / python-rpm

Package

Name
python-rpm
Purl
pkg:rpm/opensuse/python-rpm&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.20.1-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "librpmbuild10":  "4.20.1-160000.3.1",
            "python313-rpm":  "4.20.1-160000.3.1",
            "rpm":  "4.20.1-160000.3.1",
            "rpm-build":  "4.20.1-160000.3.1",
            "rpm-devel":  "4.20.1-160000.3.1",
            "rpm-plugin-fapolicyd":  "4.20.1-160000.3.1",
            "rpm-plugin-ima":  "4.20.1-160000.3.1",
            "rpm-plugin-imaevmsign":  "4.20.1-160000.3.1",
            "rpm-plugin-prioreset":  "4.20.1-160000.3.1",
            "rpm-plugin-selinux":  "4.20.1-160000.3.1",
            "rpm-plugin-syslog":  "4.20.1-160000.3.1",
            "rpm-plugin-unshare":  "4.20.1-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21856-1.json"

openSUSE:Leap 16.0 / rpm

Package

Name
rpm
Purl
pkg:rpm/opensuse/rpm&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.20.1-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "librpmbuild10":  "4.20.1-160000.3.1",
            "python313-rpm":  "4.20.1-160000.3.1",
            "rpm":  "4.20.1-160000.3.1",
            "rpm-build":  "4.20.1-160000.3.1",
            "rpm-devel":  "4.20.1-160000.3.1",
            "rpm-plugin-fapolicyd":  "4.20.1-160000.3.1",
            "rpm-plugin-ima":  "4.20.1-160000.3.1",
            "rpm-plugin-imaevmsign":  "4.20.1-160000.3.1",
            "rpm-plugin-prioreset":  "4.20.1-160000.3.1",
            "rpm-plugin-selinux":  "4.20.1-160000.3.1",
            "rpm-plugin-syslog":  "4.20.1-160000.3.1",
            "rpm-plugin-unshare":  "4.20.1-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21856-1.json"

openSUSE:Leap 16.0 / rpm-plugin-imaevmsign

Package

Name
rpm-plugin-imaevmsign
Purl
pkg:rpm/opensuse/rpm-plugin-imaevmsign&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.20.1-160000.3.1

Ecosystem specific

{
    "binaries":  [
        {
            "librpmbuild10":  "4.20.1-160000.3.1",
            "python313-rpm":  "4.20.1-160000.3.1",
            "rpm":  "4.20.1-160000.3.1",
            "rpm-build":  "4.20.1-160000.3.1",
            "rpm-devel":  "4.20.1-160000.3.1",
            "rpm-plugin-fapolicyd":  "4.20.1-160000.3.1",
            "rpm-plugin-ima":  "4.20.1-160000.3.1",
            "rpm-plugin-imaevmsign":  "4.20.1-160000.3.1",
            "rpm-plugin-prioreset":  "4.20.1-160000.3.1",
            "rpm-plugin-selinux":  "4.20.1-160000.3.1",
            "rpm-plugin-syslog":  "4.20.1-160000.3.1",
            "rpm-plugin-unshare":  "4.20.1-160000.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21856-1.json"