SUSE-SU-2026:3674-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263674-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3674-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3674-1
Upstream
CVE (5)
Related
Published
2026-08-21T09:04:42Z
Modified
2026-08-22T09:45:05Z
Summary
Security update for sccache
Details

This update for sccache fixes the following issues:

  • CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274146).
  • CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response Header Values (bsc#1273881).
  • CVE-2026-66754: rouille: remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL (bsc#1273884).
  • CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding Desynchronization (bsc#1273886).
  • CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access Control Bypass (bsc#1273888).

Changes for sccache:

  • Update to version 0.17.0~1:
  • Add experimental concurrent cache support
  • Release 0.17.0
  • tests: pin libc in the dist test crate
  • doc: clarify server-side outputs and drop 'recommended mode' claim
  • doc: document SCCACHE_CLIENT_SIDE env var
  • doc: document client-side and direct modes in Architecture.md
  • Fix description of Unix socket-based Redis connection
  • server: remove redundant async block in start_compile_task
  • server: simplify bind() request loops with ? instead of manual match arms
  • Add support for arg files in Rust (#2782)
  • feat: support S3 SSE-KMS with AWS-managed and customer-managed keys (#2770)
  • abort compile tasks and associated subprocesses when a client disconnects
  • treat -ivfsoverlay as a preprocessor-only argument
  • gcc: refine response-file tokenizer visibility and whitespace handling
  • integration: convert cmake 4.x modules XFAIL test to a passing test
  • gcc/clang: cache and distribute builds using quoted @response files
  • fix: Fix ToolchainPackager cfg gate to build on ppc64le/s390x
  • fix: make gcc diagnostics color output work the same as for rustc
  • implement client-side mode
  • split handle_compile_response so that the compilation result can be handled separately
  • implement IpcStorage -- Storage backend over IPC
  • extend wire protocol with storage RPCs
  • implement AddAssign for ServerStats and related types
  • add Storage::get_path for direct file access
  • implement get_raw/put_raw on MultiLevelStorage
  • add client_side_mode config flag (SCCACHE_CLIENT_SIDE)
  • Extract new_client_runtime() helper to DRY up client runtime creation
  • Clarify single-threaded runtime rationale comment (grammar)
  • fix: use single-threaded tokio runtime in sccache dist-client
  • fix: use single-threaded tokio runtime in sccache client
  • fix: handle disabled cache backend features in multilevel chain
  • Fix ldd output parsing: remove .exists() check that failed on systems where the symlink source path does not exist locally (e.g. aarch64)
  • Fix cfg guard for PanicToolchainPackager to also cover non-x86_64 Linux architectures (e.g. aarch64)
References

Affected packages

SUSE:Linux Enterprise Module for Development Tools 15 SP7
sccache

Package

Name
sccache
Purl
pkg:rpm/suse/sccache&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.17.0~1-150600.10.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "sccache":  "0.17.0~1-150600.10.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3674-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
sccache

Package

Name
sccache
Purl
pkg:rpm/suse/sccache&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.17.0~1-150600.10.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "sccache":  "0.17.0~1-150600.10.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3674-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
sccache

Package

Name
sccache
Purl
pkg:rpm/suse/sccache&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.17.0~1-150600.10.14.1

Ecosystem specific

{
    "binaries":  [
        {
            "sccache":  "0.17.0~1-150600.10.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3674-1.json"