openSUSE-SU-2026:21982-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21982-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21982-1
Upstream
CVE (19)
Related
Published
2026-09-30T17:58:26Z
Modified
2026-10-01T18:23:14Z
Summary
Security update for sccache
Details

This update for sccache fixes the following issues:

  • CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243868).
  • CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274146).
  • CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257923).
  • CVE-2026-41676: openssl: Deriver:derive and PkeyCtxRef:derive can overflow short buffers on OpenSSL 1.1.1 (bsc#1270206).
  • CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270559).
  • CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270693).
  • CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270736).
  • CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270869).
  • CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270512).
  • CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate (bsc#1270938).
  • CVE-2026-45784: openssl: out-of-bounds write in CipherCtxRef::cipher_update_inplace for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270948).
  • CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response Header Values (bsc#1273881).
  • CVE-2026-66754: rouille: remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL (bsc#1273884).
  • CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding Desynchronization (bsc#1273886).
  • CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access Control Bypass (bsc#1273888).
  • CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282211).
  • CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282211).
  • CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282211).
  • CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282211).

Changes for sccache:

Update to version 0.18.0~2:

  • Add experimental concurrent cache support
  • chore: Remove dependency status badge (#2856)
  • Don't hand the jobserver to children that can't use it
  • dist: refuse to trim rlibs from crates that also emit a cdylib
  • fix(cache): avoid duplicate multilevel reads
  • Strip basedirs from the compiler arguments too
  • tests/integration: replace MinIO with Silo
  • ci: dump sccache logs on integration failures
  • multilevel: a chain with any writable level is writable
  • Fix parsing of #line directives
  • Release 0.18.0
  • daemonize: use an allow-list approach to inherited FDs
  • gcc, clang: make the assembler part of the cache key
  • support cl.exe /openmp:llvm
  • support all current /fsanitize*, /fsanitize-coverage*, and /fno-sanitize* args
  • support MSVC /feature argument
  • msvc: support lots of flags (#2832)
  • Update shlex dependency to version 2 (#2836)
  • gcc: mark flags as TooHard if need to cache something else (#2833)
  • clang: support more CLI options (#2834)
  • msvc: support arm64EC and fastfail flags (#2830)
  • chore: fix typo in comment (#2829)
  • nvcc: accept the --diag-error/--diag-suppress/--diag-warn family (#2816)
  • cache: allow skipping capability checks (#2822)
  • Bump opendal to 0.58.1 and fix fallout (fixes local GCS cache usage) (#2715)
  • nvcc (Windows): protect escaped quotes in dryrun lines before flattening backslashes (#2811)
  • Add an agent (#2812)
  • Add support for d20bforceinline. (#2807)
  • feat: add Microsoft Entra ID (passwordless) auth for the Azure Blob backend (#2802)
  • Bump MSRV to 1.91.0 (#2793)
  • Fix nvcc dryrun parsing for CUDA 13.3 (#2722)
  • test: Fixed hardcoded binary path in test
  • Release 0.17.0
  • tests: pin libc in the dist test crate
  • doc: clarify server-side outputs and drop 'recommended mode' claim
  • doc: document SCCACHE_CLIENT_SIDE env var
  • doc: document client-side and direct modes in Architecture.md
  • Fix description of Unix socket-based Redis connection
  • server: remove redundant async block in start_compile_task
  • server: simplify bind() request loops with ? instead of manual match arms
  • Add support for arg files in Rust (#2782)
  • feat: support S3 SSE-KMS with AWS-managed and customer-managed keys (#2770)
  • abort compile tasks and associated subprocesses when a client disconnects
  • treat -ivfsoverlay as a preprocessor-only argument
  • gcc: refine response-file tokenizer visibility and whitespace handling
  • integration: convert cmake 4.x modules XFAIL test to a passing test
  • gcc/clang: cache and distribute builds using quoted @response files
  • fix: Fix ToolchainPackager cfg gate to build on ppc64le/s390x
  • fix: make gcc diagnostics color output work the same as for rustc
  • implement client-side mode
  • split handle_compile_response so that the compilation result can be handled separately
  • implement IpcStorage -- Storage backend over IPC
  • extend wire protocol with storage RPCs
  • implement AddAssign for ServerStats and related types
  • add Storage::get_path for direct file access
  • implement get_raw/put_raw on MultiLevelStorage
  • add client_side_mode config flag (SCCACHE_CLIENT_SIDE)
  • Extract new_client_runtime() helper to DRY up client runtime creation
  • Clarify single-threaded runtime rationale comment (grammar)
  • fix: use single-threaded tokio runtime in sccache dist-client
  • fix: use single-threaded tokio runtime in sccache client
  • fix: handle disabled cache backend features in multilevel chain
  • Fix ldd output parsing: remove .exists() check that failed on systems where the symlink source path does not exist locally (e.g. aarch64)
  • Fix cfg guard for PanicToolchainPackager to also cover non-x86_64 Linux architectures (e.g. aarch64)
  • Release 0.16.0
  • fix: strip SCCACHE_BASEDIRS from escaped-backslash paths on Windows (#2736)
  • Ignore empty-set environment values (#2639)
  • feat: all backends support making them as read-only (#2705)
  • Enable RE on Linux-aarch64 (#2668)
  • Slightly improve logging (#2734)
  • chore: encode jwt key and cert digest with base64 in logs (#2712)
  • chore: make clippy happy (#2727)
  • feat: avoid sccache wrapper when resolving compiler (#2720)
  • Fall back to direct cache write if tempfile creation on the same fs fails (#2369)
  • remove too noisy bench
  • feat(nvcc): support argument: --dependency-output (#2708)
  • fix: add newline when printing dist-status to stdout
  • Revert "Classify .s files as AssemblerToPreprocess so #include/#ifdef are hon..."
  • Don't wait depfiles for gcc/clang preprocessed inputs
  • Classify .s files as AssemblerToPreprocess so #include/#ifdef are honored
  • prepare release 0.15.0
  • Add cargo-binstall metadata for prebuilt binary installation
  • Fix coverage
  • fix: handle directories in dep-info source file hashing
  • docs(Rust.md): Add caveats from README
  • Add retry for dists docker image build
  • ci: set crt-static for riscv64 musl targets
  • feat: Add loongarch64 support
  • feat: Implement multi-tier caching with fallback and backfilling (#2581)
  • msvc: add support for Y-, YI, Zf flags
  • Group tests logging in CI
  • Add failing test for cmake-modules + cmake 4 version
  • Unfold ninja output in the test
  • Add a comment for maintaining integration tests
  • Move cmake-modules to integration tests
  • fix: exclude CARGO_ENCODED_RUSTFLAGS from env var hash (#2651)
  • chore(deps): update rust crate quinn-proto to v0.11.14
  • Fix sync GCS initialization
  • clippy: fix from_iter_instead_of_collect lint
  • fix: add Win32_Security feature to windows-sys dependency
  • build(deps): bump actions/download-artifact from 5 to 8
  • msvc: Append the default .pdb extension for the /Fd argument (#2621)
  • build(deps): bump actions/upload-artifact from 4 to 7
  • clippy: fix ref_option lint
  • ci: install grcov from prebuilt binary instead of cargo install
  • ci: use default toolchain to install grcov
  • ci: fix artifact_failure action when target dir does not exist
  • Remove benchmark normalize_win_path_utf8 (#2634)
  • Revert "actions: add security audit workflow (#2594)" (#2603)
  • partial c++20 module support (#2516)
  • clippy: fix ptr_as_ptr lint (#2611)
  • Add support for d1nodatetime & await:strict MSVC flags (#2617)
  • chore: switch thirtyfour_sync to thirtyfour (#2613)
  • clippy: fix manual_string_new lint (#2609)
  • clippy: fix unnecessary_semicolon lint (#2615)
  • clippy: fix explicit_into_iter_loop lint (#2616)
  • Avoid double-caching when ccache is installed in PATH (#2524)
  • clippy: fix cloned_instead_of_copied lint (#2605)
  • clippy: fix semicolon_if_nothing_returned lint (#2601)
  • Move PreprocessorCacheModeConfig to src/config.rs (#2604)
  • clippy: fix cloned_ref_to_slice_refs lint (#2602)
  • prepare the new release (#2600)
  • chore: update to toml 0.9 (#2599)
  • ci: Add coverage to integration tests, report it to Codecov.io (#2598)
  • Preparation for multilevel caching (#2597)
  • Add sccache-dist to flake.nix (#2579)
  • fixup! cargo fmt
  • fixup! rustfmt update
  • Extract FileObjectSource, CacheRead and CacheWrite to cache_io.rs
  • chore: update to nix 0.30
  • Add a helper method to get a correct backend name
  • Add cos feature gate to RemoteStorage
  • Simplify profiles for integration tests
  • clippy: fix implicit_clone lint (#2584)
  • actions: add security audit workflow (#2594)
  • docs: fix examples showing an xz-compress toolchain archive (#2587)
  • add benches for normalize_win_path strip_basedirs (#2588)
  • snap: update to core24 (#2570)
  • Add .rustfmt.toml for consistent style between rustfmt and cargo fmt (#2582)
  • add comments about auth token requirements (#2583)
  • chore: update to tokio-serde 0.9 (#2585)
  • ci: update freebsd to 15.0 (#2586)
  • distributed compilation support for asm & preprocessor outputs (#2557)
  • remove unused declaration (#2577)
  • Extract LazyDiskCache to a separated file (#2573)
  • Revert "ci: show diff for toml_format" (#2578)
  • Open Add SCCACHE_BASEDIRS support
  • ci: show diff for toml_format
  • chore: update to syslog 7
  • refactor: use matrix to reduce deduplication
  • fix: remove outdated analysis mode
  • Unbreak the s390x CI
  • ci: add macos-15-intel for prebuilt binary (#2555)
  • Integration tests (#2564)
  • Fix code review.
  • Impl for COS.
  • build(deps): bump opendal from 0.54.0 to 0.55.0
  • Move integration tests related stuff to subdir
  • Add Objective C Header for consistency
  • github action: fix the syntax - fails in the ci
  • sccache: prepare a new release
  • msvc: add msbuild support test
  • msvc: fix detect_showincludes_prefix with MSBuild
  • chore: update to gzp 2
  • build(deps): bump rsa from 0.9.6 to 0.9.10
  • codspeed: evaluate the memory benchmarking
  • remove too quick benchmarks
  • codspeed: move to simulation mode
  • Add realistic LRU cache access pattern benchmarks
  • Add compression characteristics benchmarks
  • Add build workflow simulation benchmarks
  • Add hash computation scenario benchmarks
  • Add batch cache entry benchmarks
  • Add cache artifact serialization benchmarks
  • Add /etc/ld.so.conf.d (if present) to compiler package
  • Assembly language support
  • fix(ci): pin serde_json to avoid zmij dependency
  • fix(ci): update zmij to fix s390x cross-compilation
  • Fix the run of the CI
  • run the benchmark in the ci
  • add benchmarks
  • dedup some code
  • Fix hash logging prefix
  • Add support for C preprocessor output
  • Add GCC pipe flag support
  • Improve save-temps gcc flags detection
  • MSVC: support forward slash as an output dir marker
  • add clang -fplugin=x regression test
  • canbeconcatenated is not accounted for in cmp
  • Reversed the order for looking rustc, added comment
  • Fix failing test_rlib_dep_reader_call for omit CARGO_HOME
  • fix: don't hash -parallel-jobs in Clang
  • docs: add installation steps for nix (#2523)
  • Support clang -fexperimental-assignment-tracking option (#2517)
  • add a nix flake (#2518)
  • Switch from the unmaintained daemonize crate to a maintained fork
  • chore: update to fs-err 3
  • Fix grammar of error message
  • Add server name info to stderr of remote jobs that ran, but failed
  • Remove another pointless destructuring
  • try to unbreak the ci
  • fix s390x build error
  • Add riscv64 support
  • fix: make aarch64-pc-windows-msvc also zip not tar.gz
  • Free up disk space in CI
  • MSVC on Windows only
  • Avoid 'No space left on device' errors in CI
  • GitHub dropped macos-13 runners
  • Proper function pointer to int cast
  • Avoid unused structs with dist-server disabled
  • no check cfg (#2507)
  • chore: switch once_cell crate to standard library (#2499)
  • Avoid unreliable assert_cmd::cargo::cargo_bin (#2489)
  • Fix build on macOS which doesn't have separate 32-bit dirent (#2492)
  • Fix Clippy warnings (#2490)
  • docs: bump MSRV to 1.85.0
  • msvc: handle '/FoRelease' command-line argument
  • chore: drop tower dependency
  • chore: update to itertools 0.14
  • Use generator in CMAKE_MSVC_DEBUG_INFORMATION_FORMAT in README
  • Update directories to 6.0
  • Configuration.md - note logging env variables
  • chore: update to env_logger 0.11
  • deps: update blake3
  • prepare version 0.12.0
  • Update README with winget installation instructions
  • Skip CARGO_BUILD_JOBS in hash keys
  • build(deps): bump object from 0.36.7 to 0.37.1
  • Adjust tests after the rust update
  • Fix CI by adding cargo-features and updating coverage test to use modern -Cinstrument-coverage
  • Fix more clippy warnings
  • bump rustc in the ci too
  • Fix rustc 1.85 clippy warnings
  • bump to rustc 1.85 / edition 2024. mandatory for reqsign-core and run rustfmt with the version
  • fix clippy warnings
  • bump opendal to 0.54.0 & reqsign to 0.18.0
  • github action: when creating a release, make it as draft before (#2458)
  • prepare version 0.11.0 (#2457)
  • document SCCACHE_LOG_MILLIS (#2456)
  • logging: add a option to log milliseconds (Closes: #2454) (#2455)
  • feat: handle human size prefixes (#2405)
  • fix: in stats, Compare values AND keys to have a fully deterministic order (#2403)
  • Add --diagnostic-width to test for args ignored in hash
  • Ignore --diagnostic-width argument when computing hash
  • build(deps): bump actions/checkout from 4 to 5
  • build(deps): bump actions/download-artifact from 4 to 5
  • build(deps): bump actions/github-script from 7 to 8
  • Fix rustfmt
  • Fix comments on request
  • Fix clippy and rustfmt
  • Add test for count toolchain and use Determenistic for create tar archive
  • Fix mtime for reproducable toolchains
  • build(deps): bump chrono from 0.4.41 to 0.4.42
  • fix typo in an environment variable name
  • Fix documentation of azure configuration
  • Account for clippy-driver having extra prefix rustc
  • Fix build on Android (in Termux)
  • add support for s390x build
  • chore: replace retry crate with backon
  • Remove or replace "Windows 2019" CI config
  • Needs another result unwrapping, it seems
  • Test: invoking symlink "compiler" to "sccache" invokes "compiler"
  • Add a comment about the problem with symlinks and current_exe()
  • Fix symbolic links to sccache on linux
  • Allow the CI configuration to disable clang++ for CUDA testing
  • Don't run tests using clang++ as CUDA compiler on Windows
  • add description to sccache-dist commands
  • Display a more user-friendly error when compiling on Linux/arm64
  • Clarify documentation about "the hash" (aka cache key)
  • Remove stray ')'
  • Remove documentation for removed limitations of preprocessor cache mode
  • Fix preprocessor cache mode when the compiler outputs a dep file
  • Partially revert "Don't cache dep file (#2322)"
  • Do not disable preprocessor cache mode if there is a dep file
  • Fix preprocessor cache mode with distributed builds (#2173)
  • Change self of generate_hash_key() from Box to &mut Self
  • Remove a few IMO pointless indirections / aliases
  • Remove workaround for #2173
  • Add test for bug #2173
  • chore: fix some minor issues in comments
  • build(deps): bump chrono from 0.4.40 to 0.4.41
  • build(deps): bump memchr from 2.7.1 to 2.7.5
  • check if we can use a specific version of rust to build grcov
  • Move comment that hadn't moved with its corresponding code
  • Rework direct mode documentation some more
  • Explain what preprocessor cache mode really does
  • Reword and correct the preprocessor cache mode documentation
  • chore: Remove not working mozilla code
  • Add support for -fsanitize-ignorelist
  • github storage: adjust the doc
  • github storage: ACTIONS_CACHE_URL => ACTIONS_RESULTS_URL
  • github storage: force version 2
  • Update codecov badge in README.md
  • Expand tests for dist-server
  • ci: Consolidate testing, coverage
  • ci: Update ubuntu-20.04 runners to ubuntu-22.04
  • chore: fix some comments
  • Give the --dist-status user some information about when a retry will happen.
  • Add support for Xclang flag '-mrelax-all'
  • Add support for Xclang flag '-mconstructor-aliases'
  • feat(utils): Add support for object >= 0.33
  • fix(tests): Remove executable bit from oauth.rs
  • build(deps): bump openssl from 0.10.64 to 0.10.72
  • build(deps): bump tokio from 1.41.0 to 1.43.1
  • Improve the CARGO_INCREMENTAL checking (#2364)
  • build(deps): bump chrono from 0.4.38 to 0.4.40
  • build(deps): bump clap from 4.4.18 to 4.5.13
  • build(deps): bump ring from 0.17.7 to 0.17.13
  • Bail on nvcc -time and nvcc -fdevice-time-trace flags
  • test hip with librandomize_readdir
  • Add randomize_readdir test utility
  • fix non-strict HIP device lib order
  • Create config during testing to collect coverage data
  • Extend coverage to distributed tests
  • chore: replace num_cpus crate with available_parallelism in standard library (#2342)
  • Update CI coverage: grcov/codecov
References

Affected packages

openSUSE:Leap 16.0 / sccache

Package

Name
sccache
Purl
pkg:rpm/opensuse/sccache&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.18.0~2-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "sccache": "0.18.0~2-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21982-1.json"