{"schema_version":"1.7.5","id":"SUSE-EL-9-CLIENT-TOOLS-2026-2254","published":"2026-06-03T14:18:09Z","modified":"2026-07-24T18:24:21.017409876Z","related":["CVE-2022-21698","CVE-2023-45288","CVE-2025-22870"],"upstream":["CVE-2022-21698","CVE-2023-45288","CVE-2025-22870"],"summary":"Security update 5.0.8 for Multi-Linux Manager Client Tools","details":"This update fixes the following issues:\n\ngolang-github-QubitProducts-exporter_exporter:\n\n- Security Fixes:\n\n  - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707)\n\ngolang-github-prometheus-node_exporter was updated from version 1.5.0 to 1.10.2:\n\n- Security Fixes:\n\n  - Version 1.9.1:\n    - CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (bsc#1238686)\n\n  - Version 1.9.0:\n    - CVE-2023-45288: Close connections when receiving too many headers (bsc#1236516)\n\n- Highlights of other changes and bug fixes:\n\n  - Backward Compatibility and packaging changes:\n    - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains\n    - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility\n\n  - Version 1.10.2:\n    - Fixed typo in Zswap metric name (meminfo)\n\n  - Version 1.10.1:\n    - Fixed mount points being collected multiple times (filesystem)\n    - Refactored mountinfo parsing (bsc#1261810)\n    - Added Zswap/Zswapped metrics (meminfo)\n\n  - Version 1.10.0:\n    - New collectors: PCIe devices, swaps\n    - Added systemd virtualization metrics, AIX metrics\n    - WiFi packet metrics, additional PCIe and TLB metrics\n    - Changed mdadm to use sysfs, added erofs to excluded filesystems\n    - Fixed bugs: cpufreq collector, ethtool metrics\n\n  - Version 1.9.1:\n    - Fixed missing IRQ on older kernels (pressure)\n\n  - Version 1.9.0 (jsc#PED-12485):\n    - Switched to Go log/slog for logging\n    - Converted meminfo to use procfs library\n    - New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics,\n      hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support,\n    - Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance \n      optimizations\n    - Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing\n\n  - Version 1.8.x:\n    - Fixed CPU pressure metric collection, CPU seconds on Solaris, pressure collector nil reference\n\n  - Version 1.8.0:\n    - New collectors: xfrm (IPsec), watchdog\n    - Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing\n    - Removed caching of os-release file modtime/filename\n    - Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race\n\n  - Version 1.7.0 (jsc#PED-7893, jsc#PED-7928):\n    - New: CPU vulnerabilities reporting from sysfs\n    - Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values,\n      qdisc performance, hwmon filtering, rtnetlink for ARP stats\n    - Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index\n\n  - Version 1.6.0:\n    - Deprecated ntp and supervisord collectors\n    - Removed bcache cache_readaheads_totals metrics\n    - Improved offline CPU handling (removed metrics for offline CPUs)\n    - New: softirqs collector\n    - Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced\n      btrfs privileges\n    - Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts\n\nprometheus-postgres_exporter:\n\n- Security Fixes:\n\n  - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699)    \n    \nscap-security-guide:\n\n- Update the SSG package description \n- Add SLE16 profiles to the build\n- Updated to 0.1.79 (jsc#ECO-3319)\n    - Create SLE16 HIPAA profile\n    - Create SLE16 PCI DSS 4 profile\n    - Use Sequoia in RHEL 10 instead of GPG\n    - New Profile for RHEL10: BSI\n    - Move RHEL Control files to product files\n    - Update RHEL 9 CCN profile\n    - Various updates for SLE 12/15\n\nspacecmd:\n\n- Version 5.0.16-0\n  * Update translation strings\n\nuyuni-tools:\n\n- Version 0.1.39-0\n  * mgrpxy ssh tuning should happen before crypto policies (bsc#1254619)\n  * Fix default value for helm registry (bsc#1258927).\n  * Use static supportconfig name to avoid dynamic search\n    (bsc#1257941)\n  * Do not nest multiple tarball files and instead collect\n    all files into one tarball (bsc#1252964)\n  * Show where final tarball was generated (bsc#1259208)\n\n","affected":[{"package":{"name":"golang-github-QubitProducts-exporter_exporter","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/golang-github-QubitProducts-exporter_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.0-1.9.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-QubitProducts-exporter_exporter":"0.4.0-1.9.1","golang-github-prometheus-node_exporter":"1.10.2-1.12.1","mgrctl":"0.1.39-1.32.1","mgrctl-bash-completion":"0.1.39-1.32.1","mgrctl-zsh-completion":"0.1.39-1.32.1","prometheus-postgres_exporter":"0.10.1-1.15.1","scap-security-guide-redhat":"0.1.80-1.44.1","spacecmd":"5.0.16-1.61.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2026-2254.json"}},{"package":{"name":"golang-github-prometheus-node_exporter","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.2-1.12.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-QubitProducts-exporter_exporter":"0.4.0-1.9.1","golang-github-prometheus-node_exporter":"1.10.2-1.12.1","mgrctl":"0.1.39-1.32.1","mgrctl-bash-completion":"0.1.39-1.32.1","mgrctl-zsh-completion":"0.1.39-1.32.1","prometheus-postgres_exporter":"0.10.1-1.15.1","scap-security-guide-redhat":"0.1.80-1.44.1","spacecmd":"5.0.16-1.61.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2026-2254.json"}},{"package":{"name":"prometheus-postgres_exporter","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/prometheus-postgres_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.1-1.15.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-QubitProducts-exporter_exporter":"0.4.0-1.9.1","golang-github-prometheus-node_exporter":"1.10.2-1.12.1","mgrctl":"0.1.39-1.32.1","mgrctl-bash-completion":"0.1.39-1.32.1","mgrctl-zsh-completion":"0.1.39-1.32.1","prometheus-postgres_exporter":"0.10.1-1.15.1","scap-security-guide-redhat":"0.1.80-1.44.1","spacecmd":"5.0.16-1.61.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2026-2254.json"}},{"package":{"name":"scap-security-guide","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/scap-security-guide&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.80-1.44.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-QubitProducts-exporter_exporter":"0.4.0-1.9.1","golang-github-prometheus-node_exporter":"1.10.2-1.12.1","mgrctl":"0.1.39-1.32.1","mgrctl-bash-completion":"0.1.39-1.32.1","mgrctl-zsh-completion":"0.1.39-1.32.1","prometheus-postgres_exporter":"0.10.1-1.15.1","scap-security-guide-redhat":"0.1.80-1.44.1","spacecmd":"5.0.16-1.61.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2026-2254.json"}},{"package":{"name":"spacecmd","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.16-1.61.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-QubitProducts-exporter_exporter":"0.4.0-1.9.1","golang-github-prometheus-node_exporter":"1.10.2-1.12.1","mgrctl":"0.1.39-1.32.1","mgrctl-bash-completion":"0.1.39-1.32.1","mgrctl-zsh-completion":"0.1.39-1.32.1","prometheus-postgres_exporter":"0.10.1-1.15.1","scap-security-guide-redhat":"0.1.80-1.44.1","spacecmd":"5.0.16-1.61.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2026-2254.json"}},{"package":{"name":"uyuni-tools","ecosystem":"SUSE:Manager Client Tools for RHEL, Liberty and Clones 9-CLIENT-TOOLS","purl":"pkg:rpm/suse/uyuni-tools&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.39-1.32.1"}]}],"ecosystem_specific":{"binaries":[{"golang-github-QubitProducts-exporter_exporter":"0.4.0-1.9.1","golang-github-prometheus-node_exporter":"1.10.2-1.12.1","mgrctl":"0.1.39-1.32.1","mgrctl-bash-completion":"0.1.39-1.32.1","mgrctl-zsh-completion":"0.1.39-1.32.1","prometheus-postgres_exporter":"0.10.1-1.15.1","scap-security-guide-redhat":"0.1.80-1.44.1","spacecmd":"5.0.16-1.61.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-EL-9-CLIENT-TOOLS-2026-2254.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement//suse-el-9-client-tools-2026-2254/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236516"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238686"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248699"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252964"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261810"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21698"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22870"}]}