VDB

ESB-2026.7543

ESB-2026.7543 PUBLISHED CVSS 7.699999809265137 HIGH

=========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2026.7543 Security update 5.1.4 for Multi-Linux Manager Client Tools 7 July 2026 =========================================================================== AUSCERT Security Bulletin Summary --------------------------------- Product: Multi-Linux Manager Publisher: SUSE Operating System: SUSE Resolution: Patch/Upgrade CVE Names: CVE-2026-40179 CVE-2026-42151 CVE-2026-42154 CVE-2026-28374 CVE-2026-28376 CVE-2026-28379 CVE-2026-28380 CVE-2026-28383 CVE-2026-33376 CVE-2026-33377 CVE-2026-33378 CVE-2026-33380 CVE-2026-33381 CVE-2026-41602 CVE-2022-21698 CVE-2026-25680 CVE-2026-25681 CVE-2026-27136 CVE-2026-39821 CVE-2026-42502 CVE-2026-42506 CVE-2026-34986 Original Bulletin: https://www.suse.com/support/update/announcement/2026/suse-su-20262768-1 Comment: CVSS (Max): 7.7 CVE-2026-33380 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) CVSS Source: SUSE Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N EPSS (Max): 6.0% (92nd) CVE-2022-21698 2026-07-06 - --------------------------BEGIN INCLUDED TEXT-------------------- Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2768-1 Release Date: 2026-07-06T07:48:37Z Rating: important o bsc#1227579 o bsc#1229105 o bsc#1232641 o bsc#1248699 o bsc#1248707 o bsc#1249400 o bsc#1249532 o bsc#1253174 o bsc#1259739 o bsc#1260806 o bsc#1260870 o bsc#1260905 o bsc#1261810 o bsc#1261902 o bsc#1262222 o bsc#1262409 o bsc#1262708 o bsc#1262760 o bsc#1262950 o bsc#1263157 References: o bsc#1263501 o bsc#1263823 o bsc#1263986 o bsc#1263987 o bsc#1265281 o bsc#1265282 o bsc#1265283 o bsc#1265284 o bsc#1265285 o bsc#1265286 o bsc#1265287 o bsc#1265288 o bsc#1265289 o bsc#1265290 o bsc#1266012 o bsc#1266556 o bsc#1266600 o bsc#1266608 o bsc#1267153 o jsc#MSQA-1056 o jsc#PED-14816 o CVE-2022-21698 o CVE-2026-25680 o CVE-2026-25681 o CVE-2026-27136 o CVE-2026-28374 o CVE-2026-28376 o CVE-2026-28379 o CVE-2026-28380 o CVE-2026-28383 o CVE-2026-33376 o CVE-2026-33377 Cross-References: o CVE-2026-33378 o CVE-2026-33380 o CVE-2026-33381 o CVE-2026-34986 o CVE-2026-39821 o CVE-2026-40179 o CVE-2026-41602 o CVE-2026-42151 o CVE-2026-42154 o CVE-2026-42502 o CVE-2026-42506 o CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N /S:U/C:N/I:N/A:H o CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N o CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N /S:U/C:N/I:N/A:H o CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:U/C:N/I:N/A:H o CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N o CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R /S:C/C:L/I:L/A:N o CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:C/C:L/I:L/A:N o CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N o CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R /S:C/C:L/I:L/A:N o CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:C/C:L/I:L/A:N o CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L /UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N o CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:U/C:N/I:L/A:N o CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:N/I:L/A:N o CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L /UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N o CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:U/C:N/I:N/A:H o CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L /UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N o CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:U/C:N/I:N/A:H o CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L /UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N o CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:U/C:N/I:H/A:N o CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:N/I:H/A:N o CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L /UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N o CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:U/C:N/I:N/A:H o CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N /UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N o CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N /S:U/C:H/I:H/A:N o CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/ S:U/C:H/I:H/A:N o CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L /UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N o CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:U/C:L/I:H/A:N o CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:L/I:H/A:N o CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L /UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N o CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:U/C:N/I:N/A:H o CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L /UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS scores: o CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N /S:C/C:H/I:N/A:N o CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/ S:C/C:H/I:N/A:N o CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:H/I:N/A:N o CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H /UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N o CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N /S:U/C:H/I:H/A:N o CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/ S:U/C:H/I:H/A:N o CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:U/C:H/I:H/A:N o CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N o CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N /S:U/C:N/I:N/A:H o CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N /UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N o CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N /S:U/C:H/I:H/A:N o CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/ S:C/C:H/I:H/A:N o CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/ S:C/C:H/I:H/A:N o CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N o CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R /S:U/C:L/I:L/A:N o CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/ UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/ MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/ MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X o CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:C/C:L/I:L/A:N o CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N o CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N /S:U/C:N/I:N/A:H o CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N /S:U/C:H/I:N/A:N o CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:H/I:N/A:N o CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:H/I:N/A:N o CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N /S:U/C:N/I:N/A:H o CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/ S:U/C:N/I:N/A:H o CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N o CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R /S:C/C:L/I:L/A:N o CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:C/C:L/I:L/A:N o CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N /UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N o CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R /S:C/C:L/I:L/A:N o CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/ S:C/C:L/I:L/A:N o openSUSE Leap 15.6 o SUSE Linux Enterprise Desktop 15 o SUSE Linux Enterprise Desktop 15 SP1 o SUSE Linux Enterprise Desktop 15 SP2 o SUSE Linux Enterprise Desktop 15 SP3 o SUSE Linux Enterprise Desktop 15 SP4 o SUSE Linux Enterprise Desktop 15 SP5 o SUSE Linux Enterprise Desktop 15 SP6 o SUSE Linux Enterprise Desktop 15 SP7 o SUSE Linux Enterprise High Performance Computing 15 o SUSE Linux Enterprise High Performance Computing 15 SP1 o SUSE Linux Enterprise High Performance Computing 15 SP2 o SUSE Linux Enterprise High Performance Computing 15 SP3 o SUSE Linux Enterprise High Performance Computing 15 SP4 o SUSE Linux Enterprise High Performance Computing 15 SP5 o SUSE Linux Enterprise Micro 5.0 o SUSE Linux Enterprise Micro 5.1 o SUSE Linux Enterprise Micro 5.2 o SUSE Linux Enterprise Micro 5.3 o SUSE Linux Enterprise Micro 5.4 o SUSE Linux Enterprise Micro 5.5 o SUSE Linux Enterprise Real Time 15 SP1 Affected o SUSE Linux Enterprise Real Time 15 SP2 Products: o SUSE Linux Enterprise Real Time 15 SP3 o SUSE Linux Enterprise Real Time 15 SP4 o SUSE Linux Enterprise Real Time 15 SP5 o SUSE Linux Enterprise Real Time 15 SP6 o SUSE Linux Enterprise Real Time 15 SP7 o SUSE Linux Enterprise Server 15 o SUSE Linux Enterprise Server 15 SP1 o SUSE Linux Enterprise Server 15 SP2 o SUSE Linux Enterprise Server 15 SP3 o SUSE Linux Enterprise Server 15 SP4 o SUSE Linux Enterprise Server 15 SP5 o SUSE Linux Enterprise Server 15 SP6 o SUSE Linux Enterprise Server 15 SP7 o SUSE Linux Enterprise Server for SAP Applications 15 o SUSE Linux Enterprise Server for SAP Applications 15 SP1 o SUSE Linux Enterprise Server for SAP Applications 15 SP2 o SUSE Linux Enterprise Server for SAP Applications 15 SP3 o SUSE Linux Enterprise Server for SAP Applications 15 SP4 o SUSE Linux Enterprise Server for SAP Applications 15 SP5 o SUSE Linux Enterprise Server for SAP Applications 15 SP6 o SUSE Linux Enterprise Server for SAP Applications 15 SP7 o SUSE Multi-Linux Manager Client Tools for SLE 15 o SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves 22 vulnerabilities, contains two features and has 17 security fixes can now be installed. Description: This update fixes the following issues: dracut-saltboot updated to version 1.2.1: o Key Update Highlights (v1.2.1) o Added wait check for minion start (default 10s), configurable using rd.saltboot.salt_start_timeout option (bsc#1260870) o Decouple salt key wait check to use separate configurable option rd.saltboot.salt_key_timeout, with default 60s o Introduce rd.saltboot namespace for all options, mark old as deprecated golang-github-QubitProducts-exporter_exporter: o Security issues fixed: o CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-boynux-squid_exporter: o Non customer facing changes golang-github-lusitaniae-apache_exporter: o Non customer facing changes golang-github-prometheus-alertmanager: o Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: o Key Update Highlights (v1.10.0 to v1.10.2): o New Collectors: Added new collectors for PCIe devices and swaps. o New Metrics: Introduced metrics for Zswap/Zswapped, Systemd Virtualization, and WiFi packets (received/transmitted) o Bug Fixes: Resolved a duplicate collection bug in filesystem mount points, fixed a Zswap metric typo, and patched a logging race condition in systemd. o Changes: Switched mdadm to use sysfs for RAID metrics, and added erofs to the default excluded filesystems list. o Internal Refactoring: filesystem mountinfo parsing refactor (bsc#1261810) golang-github-prometheus-prometheus updated to version 3.5.3: o Security issues fixed: o CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (v3.5.3) (bsc#1263986) o CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the limit (v3.5.3) (bsc#1263987) o CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (v3.5.2) (bsc#1262222). o CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (backported patch) (bsc# 1266608) o Other changes: o Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) o Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc# PED-14816) o Internal update with non customer facing changes (v3.5.1) grafana updated to version 11.6.14+security-04: o Security issues fixed in v11.6.14+security-04: o CVE-2026-28374: Fixed insecure direct object reference in Annotations API (bsc#1265290) o CVE-2026-28376: Fixed unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) o CVE-2026-28383: Fixed unbounded memory allocation in Grafana plugin resources (bsc#1265286) o CVE-2026-28380: Fixed broken access control in Snapshot API (bsc#1265287) o CVE-2026-33376: Fixed Auth Proxy IPv6 whitelist bypass (bsc#1265285) o CVE-2026-28379: Fixed viewer-triggered race condition in Grafana Live (bsc# 1265288) o CVE-2026-33377: Fixed dashboard Editor Privilege Escalation (bsc#1265284) o CVE-2026-33378: Fixed OOM exception in Grafana Data Source Plugin (bsc# 1265283) o CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) o CVE-2026-33380: Fixed vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server's filesystem (bsc#1265282) o Security issues fixed through backported patches: o CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) o CVE-2026-34986: Fixed panic in JWE decryption (bsc#1262950) o CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) o CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Fixed multiple issues when parsing HTML files (bsc#1267153) mgr-push updated to version 5.2.4: o Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-blackbox_exporter: o Security issues fixed: o CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266556) prometheus-postgres_exporter: o Security issues fixed: o CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) rhnlib updated to version 5.2.5: o Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: o Key Update Highlights (v5.2.3-0): o Fixed typo in spacecmd help ca-cert flag (bsc#1253174) o Add subcommand to check if reboot is needed after applying all available patches o Key Update Highlights (v5.2.1-0): o Use JSON instead of pickle for spacecmd cache (bsc#1227579) o Fixed methods in api namespace in spacecmd (bsc#1249532) o Other changes (v5.2.2-0 to 5.2.8-0): o Translation strings updates o Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: o Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) supportutils-plugin-salt: o Non customer facing changes supportutils-plugin-susemanager-client updated to version 5.2.3: o Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.3-0) uyuni-tools updated to version 5.2.12: o Key Update Highlights (v5.2.11-0) o Improved pod readiness checks (bsc#1266012) o Key Update Highlights (v5.2.10-0) o Preserve hub replicas during upgrade (bsc#1262708) o Added mgrctl "ssh" and "ssh remove_known_host" commands o Fixed startup checks for main server container (bsc#1263157) o Fixed service dependencies (bsc#1263823) o Updated default tag to 5.1.3.1 (bsc#1262760) o Fixed missing registry for db image (bsc#1259739) o Internal SANs for db and reportdb are no longer required o Generate the same certificate for server and reportdb o Fixed Report DB CA certificate (bsc#1260806) o Removed waitForTraefik function (bsc#1261902) o Key Update Highlights (v5.2.8-0) o Generate service template only after secrets are created o Key Update Highlights (v5.2.7-0) o Admin secrets no longer required on upgrades (bsc#1262409) o Key Update Highlights (v5.2.6-0): o Use podman secrets for SSL on proxy o Fixed database online backup o mgrctl copy command now infers target name automatically o Restored TFTP port to proxy (bsc#1260905) o TFTP disabled by default on server o Fixed incorrect package dependencies declaration (bsc#1229105) o Prevent cobbler port from being exposed o Bumped zerolog to 1.34 o Ignore spacewalk-service stop return code. o Stop automatically unhealthy container o Use container based server setup instead tools bundled one o Key Update Highlights (v5.2.5-0) o Removed migrate command o Removed hub register command o Split TFTP server into separate container o Removed Kubernetes install/upgrade from mgrpxy o Key Update Highlights (v5.2.1-0) o Fixed --dbupgrade-tag parameter (bsc#1249400) o Added --registry-host, --registry-user, --registry-password options o Deprecated --registry option o Added SUSE Linux Enterprise 15 SP7 support o Migrated custom SSL CA certificates (bsc#1232641) o Other changes (v5.2.1-0 to v5.2.12-0): o Translation strings updates o Internal updates with version bump but without customer facing changes uyuni-common-libs updated to version 5.2.5: o Key Update Highlights (v5.2.5-0): o Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly o Other changes: o Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) Special Instructions and Notes: Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: o SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-2768=1 o SUSE Multi-Linux Manager Client Tools for SLE 15 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-15-2026-2768=1 Package List: o SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) mgrctl-5.2.12-150002.3.17.1 golang-github-prometheus-node_exporter-1.10.2-150002.3.6.2 golang-github-prometheus-node_exporter-debuginfo-1.10.2-150002.3.6.2 mgrctl-debuginfo-5.2.12-150002.3.17.1 o SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) mgrctl-zsh-completion-5.2.12-150002.3.17.1 mgrctl-lang-5.2.12-150002.3.17.1 dracut-saltboot-1.2.1-150002.3.9.1 mgrctl-bash-completion-5.2.12-150002.3.17.1 o SUSE Multi-Linux Manager Client Tools for SLE 15 (aarch64 ppc64le s390x x86_64) golang-github-prometheus-node_exporter-1.10.2-150002.3.6.2 prometheus-blackbox_exporter-0.26.0-150002.3.11.1 grafana-debuginfo-11.6.14+security04-150002.4.21.1 golang-github-prometheus-prometheus-debuginfo-3.5.3-150002.3.13.1 grafana-11.6.14+security04-150002.4.21.1 golang-github-prometheus-alertmanager-0.28.1-150002.4.11.1 golang-github-lusitaniae-apache_exporter-debuginfo-1.0.10-150002.3.9.2 golang-github-prometheus-prometheus-3.5.3-150002.3.13.1 golang-github-prometheus-node_exporter-debuginfo-1.10.2-150002.3.6.2 golang-github-QubitProducts-exporter_exporter-0.4.0-150002.3.6.2 prometheus-postgres_exporter-0.10.1-150002.3.3.2 golang-github-prometheus-alertmanager-debuginfo-0.28.1-150002.4.11.1 prometheus-postgres_exporter-debuginfo-0.10.1-150002.3.3.2 mgrctl-debuginfo-5.2.12-150002.3.17.1 golang-github-lusitaniae-apache_exporter-1.0.10-150002.3.9.2 golang-github-boynux-squid_exporter-1.13.0-150002.3.6.2 firewalld-prometheus-config-0.1-150002.3.13.1 golang-github-boynux-squid_exporter-debuginfo-1.13.0-150002.3.6.2 mgrctl-5.2.12-150002.3.17.1 o SUSE Multi-Linux Manager Client Tools for SLE 15 (noarch) python3-mgr-push-5.2.4-150002.3.9.1 python3-spacewalk-client-tools-5.2.6-150002.3.9.1 mgrctl-zsh-completion-5.2.12-150002.3.17.1 python3-defusedxml-0.7.1-150002.1.3.1 spacecmd-5.2.8-150002.3.12.1 supportutils-plugin-susemanager-client-5.2.3-150002.3.9.1 dracut-saltboot-1.2.1-150002.3.9.1 python3-uyuni-common-libs-5.2.5-150002.3.6.1 mgr-push-5.2.4-150002.3.9.1 mgrctl-bash-completion-5.2.12-150002.3.17.1 mgrctl-lang-5.2.12-150002.3.17.1 spacewalk-client-tools-5.2.6-150002.3.9.1 python3-rhnlib-5.2.5-150002.3.9.1 supportutils-plugin-salt-1.2.3-150002.3.3.1 References: o https://www.suse.com/security/cve/CVE-2022-21698.html o https://www.suse.com/security/cve/CVE-2026-25680.html o https://www.suse.com/security/cve/CVE-2026-25681.html o https://www.suse.com/security/cve/CVE-2026-27136.html o https://www.suse.com/security/cve/CVE-2026-28374.html o https://www.suse.com/security/cve/CVE-2026-28376.html o https://www.suse.com/security/cve/CVE-2026-28379.html o https://www.suse.com/security/cve/CVE-2026-28380.html o https://www.suse.com/security/cve/CVE-2026-28383.html o https://www.suse.com/security/cve/CVE-2026-33376.html o https://www.suse.com/security/cve/CVE-2026-33377.html o https://www.suse.com/security/cve/CVE-2026-33378.html o https://www.suse.com/security/cve/CVE-2026-33380.html o https://www.suse.com/security/cve/CVE-2026-33381.html o https://www.suse.com/security/cve/CVE-2026-34986.html o https://www.suse.com/security/cve/CVE-2026-39821.html o https://www.suse.com/security/cve/CVE-2026-40179.html o https://www.suse.com/security/cve/CVE-2026-41602.html o https://www.suse.com/security/cve/CVE-2026-42151.html o https://www.suse.com/security/cve/CVE-2026-42154.html o https://www.suse.com/security/cve/CVE-2026-42502.html o https://www.suse.com/security/cve/CVE-2026-42506.html o https://bugzilla.suse.com/show_bug.cgi?id=1227579 o https://bugzilla.suse.com/show_bug.cgi?id=1229105 o https://bugzilla.suse.com/show_bug.cgi?id=1232641 o https://bugzilla.suse.com/show_bug.cgi?id=1248699 o https://bugzilla.suse.com/show_bug.cgi?id=1248707 o https://bugzilla.suse.com/show_bug.cgi?id=1249400 o https://bugzilla.suse.com/show_bug.cgi?id=1249532 o https://bugzilla.suse.com/show_bug.cgi?id=1253174 o https://bugzilla.suse.com/show_bug.cgi?id=1259739 o https://bugzilla.suse.com/show_bug.cgi?id=1260806 o https://bugzilla.suse.com/show_bug.cgi?id=1260870 o https://bugzilla.suse.com/show_bug.cgi?id=1260905 o https://bugzilla.suse.com/show_bug.cgi?id=1261810 o https://bugzilla.suse.com/show_bug.cgi?id=1261902 o https://bugzilla.suse.com/show_bug.cgi?id=1262222 o https://bugzilla.suse.com/show_bug.cgi?id=1262409 o https://bugzilla.suse.com/show_bug.cgi?id=1262708 o https://bugzilla.suse.com/show_bug.cgi?id=1262760 o https://bugzilla.suse.com/show_bug.cgi?id=1262950 o https://bugzilla.suse.com/show_bug.cgi?id=1263157 o https://bugzilla.suse.com/show_bug.cgi?id=1263501 o https://bugzilla.suse.com/show_bug.cgi?id=1263823 o https://bugzilla.suse.com/show_bug.cgi?id=1263986 o https://bugzilla.suse.com/show_bug.cgi?id=1263987 o https://bugzilla.suse.com/show_bug.cgi?id=1265281 o https://bugzilla.suse.com/show_bug.cgi?id=1265282 o https://bugzilla.suse.com/show_bug.cgi?id=1265283 o https://bugzilla.suse.com/show_bug.cgi?id=1265284 o https://bugzilla.suse.com/show_bug.cgi?id=1265285 o https://bugzilla.suse.com/show_bug.cgi?id=1265286 o https://bugzilla.suse.com/show_bug.cgi?id=1265287 o https://bugzilla.suse.com/show_bug.cgi?id=1265288 o https://bugzilla.suse.com/show_bug.cgi?id=1265289 o https://bugzilla.suse.com/show_bug.cgi?id=1265290 o https://bugzilla.suse.com/show_bug.cgi?id=1266012 o https://bugzilla.suse.com/show_bug.cgi?id=1266556 o https://bugzilla.suse.com/show_bug.cgi?id=1266600 o https://bugzilla.suse.com/show_bug.cgi?id=1266608 o https://bugzilla.suse.com/show_bug.cgi?id=1267153 o https://jira.suse.com/browse/MSQA-1056 o https://jira.suse.com/browse/PED-14816 - --------------------------END INCLUDED TEXT---------------------- You have received this e-mail bulletin as a result of your organisation's registration with AUSCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AUSCERT's members. As AUSCERT did not write the document quoted above, AUSCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AUSCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://portal.auscert.org.au/bulletins/ =========================================================================== AUSCERT The University of Queensland, Brisbane QLD 4072 Australia e: auscert@auscert.org.au t: +61 (0)7 3365 4417 Allies in Cyber Security ===========================================================================

Risk Scores

CVSS 3.1
7.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersions
SUSEMulti-Linux Manager

Timeline

  • Jul 7, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›