SUSE-SU-2026:2243-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262243-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2243-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:2243-1
Upstream
CVE (17)
Related
Published
2026-06-03T14:10:38Z
Modified
2026-06-04T09:00:04Z
Summary
Security update 5.0.8 for Multi-Linux Manager Client Tools
Details

This update fixes the following issues:

golang-github-QubitProducts-exporter_exporter:

  • Security Fixes:

    • CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707)

golang-github-prometheus-node_exporter:

  • Backward Compatibility and packaging changes:

    • Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains
    • Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility
  • Version 1.10.2:

    • Fixed typo in Zswap metric name (meminfo)
  • Version 1.10.1:

    • Fixed mount points being collected multiple times (filesystem)
    • Refactored mountinfo parsing (bsc#1261810)
    • Added Zswap/Zswapped metrics (meminfo)
  • Version 1.10.0:

    • New collectors: PCIe devices, swaps
    • Added systemd virtualization metrics, AIX metrics
    • WiFi packet metrics, additional PCIe and TLB metrics
    • Changed mdadm to use sysfs, added erofs to excluded filesystems
    • Fixed bugs: cpufreq collector, ethtool metrics

golang-github-prometheus-prometheus:

  • Security issues fixed:

    • CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986)
    • CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987).
    • CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (bsc#1262222)
    • CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260267)
      • Bump google.golang.org/grpc to version 1.79.3
    • CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893)
      • Bump rollup to version 4.59.0
  • Other changes:

    • Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit.
    • Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816)

prometheus-postgres_exporter:

  • Security Fixes:

    • CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (bsc#1263987)
    • CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (bsc#1263986)
    • CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699)
  • Highlights of other changes and bug fixes:

    • Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy

grafana was updated from version 11.6.11 to 11.6.14+security01:

  • Security Fixes:

    • CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950)
    • CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501)
    • CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results (bsc#1258595)
    • CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)
    • CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881)
    • CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025)
    • CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026)
    • CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029)
    • CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027)
    • CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263)
    • CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878)
  • Highlights of other changes and bug fixes:

    • Version 11.6.13:

      • Wire the public dashboard service to the HTTP server
    • Version 11.6.12:

      • Update authentication redirect logic
      • Fixed single panel render with variable references

spacecmd:

  • Version 5.0.16-0:

    • Update translation strings

uyuni-tools:

  • Version 0.1.39-0:

    • mgrpxy ssh tuning should happen before crypto policies (bsc#1254619)
    • Fixed default value for helm registry (bsc#1258927).
    • Use static supportconfig name to avoid dynamic search (bsc#1257941)
    • Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964)
    • Show where final tarball was generated (bsc#1259208)
References

Affected packages