openSUSE-SU-2026:20206-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20206-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:20206-1
Upstream
CVE (2)
Related
Published
2026-02-13T08:53:10Z
Modified
2026-03-12T02:08:11Z
Summary
Security update for kepler
Details

This update for kepler fixes the following issues:

Update to version 0.11.3.

Security issues fixed:

  • CVE-2025-47911: golang.org/x/net/html: quadratic complexity algorithms used when parsing untrusted HTML documents (bsc#1251427).
  • CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by html.ParseFragment when processing specially crafted input (bsc#1251632).

Other updates and bugfixes:

  • Version 0.11.2:

    • Fix: Fix node power metrics for Virtual Machines.
    • Fix: Resolve an issue with pod energy metrics when a container has no usage.
  • Version 0.11.1:

    • Fix: Added missing serviceaccount in the Helm chart.
  • Version 0.11.0:

    • Feature: Added support for platform power metrics (AC).
    • Feature: Introduced experimental support for trained power models.
    • Fix: Improved the accuracy of power estimation for Virtual Machines.
    • Breaking Change: Metrics related to kepler_vm_ have been refactored.
  • Version 0.10.1:

    • Feature: Added support for the ARM64 architecture.
    • Fix: Addressed issues when running on Virtual Machines without RAPL.
    • Fix: Includes several other bug fixes and stability improvements.
  • Version 0.10.0:

    • Breaking Change: This is a major rewrite with significant architectural changes.
    • Breaking Change: Legacy versions (0.9.0 and earlier) are now frozen, with no new features or bug fixes.
    • Breaking Change: The configuration format has been updated.
    • Breaking Change: The Kepler Model Server is not compatible with this version and above.
    • Feature: New modular architecture for better extensibility.
    • Feature: Enhanced performance and accuracy with dynamic detection of RAPL zones.
    • Feature: Reduced security requirements, no longer needing CAP_SYS_ADMIN or CAP_BPF capabilities.
    • Fix: Significantly reduced resource usage.
  • Version 0.9.0:

    • Note: This is the final legacy release.
    • Feature: Added support for GPU power monitoring.
    • Feature: Introduced a model server for training power models.
  • Version 0.8.2:

    • Fix: Addressed a bug in RAPL power calculation on multi-socket systems.
  • Version 0.8.1:

    • Fix: This version includes multiple bug fixes and stability improvements.
  • Version 0.8.0:

    • Feature: Introduced a new estimator framework.
    • Breaking Change: The API is backward incompatible with previous versions.
  • Version 0.7.12:

    • Fix: This version includes multiple bug fixes and stability improvements.
References

Affected packages

openSUSE:Leap 16.0 / kepler

Package

Name
kepler
Purl
pkg:rpm/opensuse/kepler&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.11.3-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "kepler":  "0.11.3-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20206-1.json"