openSUSE-SU-2026:21918-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21918-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21918-1
Upstream
CVE (4)
Related
Published
2026-09-18T10:51:38Z
Modified
2026-09-25T18:23:13Z
Summary
Security update for warewulf4
Details

This update for warewulf4 fixes the following issues:

Changes in warewulf4:

  • updating to v4.7.1 with the following changes
    • wwctl power no longer falls back to the local BMC for nodes with no ipmi: ipaddr:, which could power off the Warewulf server itself
    • wwclient is built with GOAMD64=v1 and no longer fails with an illegal instruction on older nodes
    • prevent image and overlay corruption from 64-bit inode numbers truncating in cpio
    • fix kernel version detection for releases with a version-like suffix after the dist tag
    • several fixes for IPv6-only servers and nodes: dracut boot, wwctl node status, dnsmasq, NetworkManager
    • remove dsa from the default ssh: key types, which could leave nodes with no usable host keys on EL9
    • mount non-root filesystems before image extraction during provision-to-disk
    • overlay template fixes for parent directories and symbolic links
  • dependency updates, including go-jose 4.1.4 for CVE-2026-34986 (bsc#1262805)
  • updated go-chi to v5.3.2 to fix CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing: authentication bypass, authorization override, and log forgery) (bsc#1276100)
References

Affected packages

openSUSE:Leap 16.0 / warewulf4

Package

Name
warewulf4
Purl
pkg:rpm/opensuse/warewulf4&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.7.1-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "warewulf4":  "4.7.1-bp160.1.1",
            "warewulf4-dracut":  "4.7.1-bp160.1.1",
            "warewulf4-man":  "4.7.1-bp160.1.1",
            "warewulf4-overlay":  "4.7.1-bp160.1.1",
            "warewulf4-overlay-rke2":  "4.7.1-bp160.1.1",
            "warewulf4-reference-doc":  "4.7.1-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21918-1.json"