{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20581-1","published":"2026-04-14T16:21:55Z","modified":"2026-04-22T18:25:07.682353Z","related":["CVE-2025-22869"],"upstream":["CVE-2025-22869"],"summary":"Security update for nebula","details":"This update for nebula fixes the following issues:\n\nChanges in nebula:\n\n- Update to version 1.10.3:\n  * Fix an issue where blocklist bypass is possible when using curve P256\n    Any newly issued P256 based certificates will have their signature clamped\n    to the low-s form.  Nebula will assert the low-s signature form when\n    validating certificates in a future version\n\n- Update to version 1.10.2:\n  * Fix panic when using use_system_route_table\n\n- Update to version 1.10.1:\n  * Fix a bug where an unsafe route derived from the system route table could\n    be lost on a config reload\n  * Fix the PEM banner for ECDSA P256 public keys\n  * Fix a bug in handshake processing when a peer sends an unexpected public key\n  * Add a config option to control accepting recv_error packets which defaults\n    to always\n\n- Update to version 1.10.0:\n  * Support for ipv6 and multiple ipv4/6 addresses in the overlay\n  * Add the ability to mark packets on linux to better target nebula packets in\n    iptables/nftables\n  * Add ECMP support for unsafe_routes\n  * PKCS11 support for P256 keys when built with pkcs11 tag\n  * default_local_cidr_any now defaults to false\n  * Improve logging when a relay is in use on an inbound packet\n  * Avoid fatal errors if rountines is > 1 on systems that <= 1\n  * Log a warning if a firewall rule contains an any that negates a more\n    restrictive filter\n  * Accept encrypted CA passphrase from an environment variable\n  * Allow handshaking with any trusted remote\n  * Log only the count of blocklisted certificate fingerprints instead of the\n    entire list\n  * Don't fatal when the ssh server is unable to be configured successfully\n  * Improve lost packet statistics\n  * Honor remote_allow_list in hole punch response\n- remove patch fix-CVE-2025-22869.patch, fixed upstream\n\n- update to version 1.9.7:\n  * Disable sending recv_error messages when a packet is received outside the\n    allowable counter window\n  * Improve error messages and remove some unnecessary fatal conditions in the\n    generic udp listener\n\n- update to version 1.9.6:\n  * Support dropping inactive tunnels. This is disabled by default\n  * Ensure the same relay tunnel is always used when multiple relay\n    tunnels are present\n  * Fix relay migration panic\n","affected":[{"package":{"name":"nebula","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/nebula&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.3-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"nebula":"1.10.3-bp160.1.1","nebula-cert":"1.10.3-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20581-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22869"}]}