{"schema_version":"1.7.5","id":"SUSE-SU-2026:2243-1","published":"2026-06-03T14:10:38Z","modified":"2026-06-04T09:00:07.843013639Z","related":["CVE-2022-21698","CVE-2025-29923","CVE-2026-21724","CVE-2026-21725","CVE-2026-26958","CVE-2026-27606","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28375","CVE-2026-33186","CVE-2026-33375","CVE-2026-34986","CVE-2026-40179","CVE-2026-41602","CVE-2026-42151","CVE-2026-42154"],"upstream":["CVE-2022-21698","CVE-2025-29923","CVE-2026-21724","CVE-2026-21725","CVE-2026-26958","CVE-2026-27606","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28375","CVE-2026-33186","CVE-2026-33375","CVE-2026-34986","CVE-2026-40179","CVE-2026-41602","CVE-2026-42151","CVE-2026-42154"],"summary":"Security update 5.0.8 for Multi-Linux Manager Client Tools","details":"This update fixes the following issues:\n\ngolang-github-QubitProducts-exporter_exporter:\n\n- Security Fixes:\n\n  - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707)\n\ngolang-github-prometheus-node_exporter:\n\n- Backward Compatibility and packaging changes:\n  - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains\n  - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility\n\n- Version 1.10.2:\n  - Fixed typo in Zswap metric name (meminfo)\n\n- Version 1.10.1:\n  - Fixed mount points being collected multiple times (filesystem)\n  - Refactored mountinfo parsing (bsc#1261810)\n  - Added Zswap/Zswapped metrics (meminfo)\n\n- Version 1.10.0:\n  - New collectors: PCIe devices, swaps\n  - Added systemd virtualization metrics, AIX metrics\n  - WiFi packet metrics, additional PCIe and TLB metrics\n  - Changed mdadm to use sysfs, added erofs to excluded filesystems\n  - Fixed bugs: cpufreq collector, ethtool metrics\n\ngolang-github-prometheus-prometheus:\n    \n- Security issues fixed:\n\n  - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret\n    being exposed in plaintext via /-/config endpoint (bsc#1263986)\n  - CVE-2026-42154: Remote-read: Reject snappy-compressed requests\n    whose declared decoded length exceeds the decode limit\n    (bsc#1263987).\n  - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label\n    values in old UI heatmap chart tick labels (bsc#1262222)\n  - CVE-2026-33186: Fixed authorization bypass due to improper\n    validation of the HTTP/2 :path pseudo-header (bsc#1260267)\n    * Bump google.golang.org/grpc to version 1.79.3\n  - CVE-2026-27606: Fixed arbitrary file write via path traversal in\n    rollup (bsc#1258893)\n    * Bump rollup to version 4.59.0\n\n- Other changes:\n\n  - Remote-Write: Reject snappy-compressed requests whose\n    declared decoded length exceeds the decode limit.\n  - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816)  \n\n\nprometheus-postgres_exporter:\n\n- Security Fixes:\n\n  - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode\n    limit (bsc#1263987)\n  - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint\n    (bsc#1263986)\n  - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699)\n\n- Highlights of other changes and bug fixes:\n\n  - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy\n\ngrafana was updated from version 11.6.11 to 11.6.14+security01:\n\n- Security Fixes:\n\n  - CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950)\n  - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501)\n  - CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results \n    (bsc#1258595)\n  - CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)\n  - CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881)\n  - CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025)\n  - CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026)\n  - CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029)\n  - CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027)\n  - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header\n    (bsc#1260263)\n  - CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878)\n\n- Highlights of other changes and bug fixes:\n\n  - Version 11.6.13:\n\n    - Wire the public dashboard service to the HTTP server\n\n  - Version 11.6.12:\n\n    - Update authentication redirect logic\n    - Fixed single panel render with variable references\n\nspacecmd:\n\n- Version 5.0.16-0:\n\n  - Update translation strings\n\nuyuni-tools:\n\n- Version 0.1.39-0:\n\n  - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619)\n  - Fixed default value for helm registry (bsc#1258927).\n  - Use static supportconfig name to avoid dynamic search\n    (bsc#1257941)\n  - Do not nest multiple tarball files and instead collect\n    all files into one tarball (bsc#1252964)\n  - Show where final tarball was generated (bsc#1259208)\n\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262243-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248699"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252964"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260267"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260881"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261026"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261027"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261029"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261810"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262222"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263986"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21698"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-29923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21724"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27876"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27877"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40179"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42151"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42154"}]}