{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21151-1","published":"2026-06-23T09:37:25Z","modified":"2026-06-30T18:24:45.673043944Z","related":["CVE-2025-58058","CVE-2025-69725","CVE-2026-33814","CVE-2026-34986","CVE-2026-39821"],"upstream":["CVE-2025-58058","CVE-2025-69725","CVE-2026-33814","CVE-2026-34986","CVE-2026-39821"],"summary":"Security update for warewulf4","details":"This update for warewulf4 fixes the following issues:\n\nChanges in warewulf4:\n\n- updated go-jose to fix CVE-2026-34986 (bsc#1262810)\n- chi is fixed in the upstream project\n\n- updating to v4.7.0 with following security fixes\n * fixed CVE-2026-39821 (bsc#1266483)\n * fixed CVE-2026-33814 (bsc#1265653)\n- v4.7.0 with significant changes relative to the v4.6.x series which are:\n  * New wwctl unset command\n  * Refactored server routes (URLs)\n  * New /files/ route for serving individual files and templates\n  * Server TLS support\n  * Removed support for fetching individual overlays and individual files from overlays\n  * Fixed whitespace handling around template functions\n  * Security fixes, including updated Go and library versions\n- changes from v4.6.5:\n  * new wwctl overlay info command\n  * fixed wwctl image import --update option\n  * cross-arch support for wwclient\n  * improved IPv6 support\n  * improved support for bonded interfaces\n  * renamed debian.interfaces overlay to ifupdown\n  * new systemd-networkd overlay\n  * warewulf-dracut fixes, including \"provision-to-disk\" fixes\n- remove slurm-overlay package\n\n- fix CVE-2025-69725 (bsc#1258511) by updating chi\n\n- updated to v4.6.5 with following changes:\n  * new wwctl overlay info command\n  * fixed wwctl image import --update option (bsc#1254470)\n  * cross-arch support for wwclient\n  * improved IPv6 support\n  * improved support for bonded interfaces\n  * renamed debian.interfaces overlay to ifupdown\n  * new systemd-networkd overlay\n  * warewulf-dracut fixes, including \"provision-to-disk\" fixes\n- default to dnsmasq instead of dhcpd and tftp\n","affected":[{"package":{"name":"warewulf4","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/warewulf4&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"warewulf4":"4.7.0-bp160.1.1","warewulf4-dracut":"4.7.0-bp160.1.1","warewulf4-man":"4.7.0-bp160.1.1","warewulf4-overlay":"4.7.0-bp160.1.1","warewulf4-overlay-rke2":"4.7.0-bp160.1.1","warewulf4-reference-doc":"4.7.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21151-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254470"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258511"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262810"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265653"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266483"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-69725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"}]}