PT-2026-108717 · Suse · Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Httpd-Image+44

CVE-2026-63009

·

Publicado

2026-10-08

·

Atualizado

2026-10-08

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
This update fixes the following issues:
Release Notes Highlights:
  • Added a note about the SUSE Registry IP address change.
  • Update to SUSE Multi-Linux Manager 5.2.1
  • Security fixes
  • Ubuntu 26.04 LTS Support
  • Confidential Computing Attestation for IBM Z Series
  • New uyuni-tftpd Container
  • Monitoring: Prometheus upgraded to 3.13.2
  • Monitoring: Grafana upgraded to 12.4.10
  • CVEs Fixed: CVE-2023-45289, CVE-2024-22195, CVE-2025-12141, CVE-2025-13836 CVE-2025-61686, CVE-2026-15308, CVE-2026-21723, CVE-2026-40181 CVE-2026-11940, CVE-2026-11972, CVE-2026-13346, CVE-2026-14199 CVE-2026-17033, CVE-2026-17183, CVE-2026-19197, CVE-2026-19475 CVE-2026-27459, CVE-2026-33814, CVE-2026-39821, CVE-2026-39882 CVE-2026-40475, CVE-2026-41066, CVE-2026-41178, CVE-2026-41606 CVE-2026-42211, CVE-2026-42342, CVE-2026-44431, CVE-2026-44990 CVE-2026-49825, CVE-2026-49853, CVE-2026-49854, CVE-2026-49855 CVE-2026-56852, CVE-2026-63007, CVE-2026-63009, CVE-2026-71400 CVE-2026-42127, CVE-2026-45409, CVE-2026-53606, CVE-2026-73501 CVE-2025-4673, CVE-2026-0864, CVE-2026-1229, CVE-2026-1502 CVE-2026-1703, CVE-2026-2303, CVE-2026-3219, CVE-2026-3276
Container images and uyuni-tools changes:
proxy-tftpd-image:
  • Updated to version 5.2.10
  • Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800)
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-attestation-image:
  • Version 5.2.11
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-database-migration-image:
  • Version 5.2.6
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-hub-xmlrpc-api-image:
  • Version 5.2.9
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-image:
  • Version 5.2.15
  • Increase start-period (bsc#1271124)
  • Check disk space on startup
  • Use correct healthcheck cmd (bsc#1273144)
  • Detect an existing cgroup2 mount by filesystem type, not mountpoint.
server-postgresql-image:
  • Version 5.2.13
  • Automatically set the log timezone for TZ env (bsc#1267871)
  • Increase start-period and timeout (bsc#1271124)
  • Check disk space on startup
server-saline-image:
  • Version 5.2.11
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
uyuni-tools:
  • CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)
  • Version 5.2.17-0
  • Bump the default image tag to 5.2.1
  • Reload systemd daemon before restarting services (bsc#1270033)
  • Check all supported locations for CA file in rotation check script
  • Detect and fix legacy service file (bsc#1268755)
  • Use healthcheck cmd from the image (bsc#1273144)
The following packages are underlying build dependencies and system components used by the containers:
apache-commons-fileupload2:
  • Updated to version 2.0.0-M5
  • Add AbstractFileUpload support for a maximum part header size
  • FILEUPLOAD-367: Jakarta and Javax ServletFileUpload .isMultipartContent(HttpServletRequest) should allow PUT and PATCH request methods in addition to POST
  • FILEUPLOAD-367: Add AbstractFileUpload .isMultipartRequestMethod(String)
  • FILEUPLOAD-295: Clarified the precise meaning of isInMemory(), get(), getPath(), etc. in DiskFileItem
  • Better exception type and message if a multipart/mixed part is presented without a boundary defined
  • Bump org.apache.commons:commons-parent from 84 to 96
  • Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0
  • Bump commons-io:commons-io from 2.19.0 to 2.21.0
byte-buddy:
  • Updated to version 1.18.8
  • Introduce new versioning concept with -jdk5 suffix for backwards-compatible jar and Java 8 baseline for regular jar
  • Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted
  • Add super classes to hash code / equals computation in Advice that were missing
  • Add support for new build description in Android 9
mgr-push:
  • Version 5.2.5-0
  • Remove token based authentication mechanism for package push (bsc#1230949)
objectweb-asm:
  • Updated to version 9.10.1
  • New Opcodes.V27 constant for Java 27
python-susemanager-retail:
  • Version 1.2.1
  • Fix issue building package on SLES 16.0
salt:
  • Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
  • Support attrlist in ldap.managed (bsc#1257151)
  • Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
  • Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)
spacecmd:
  • Version 5.2.10-0
  • Pre-filter errata in system applyerrata to avoid using API calls for all existing errata (bsc#1267261)
spacewalk-backend:
  • Version 5.2.10-0
  • Allow diskcheck env vars into containers (bsc#1270033)
  • Use sha256 as the default checksum type for Debian repositories
  • Remove token based authentication mechanism for package push (bsc#1230949)
  • Fix gpgverify signature file check for file object (bsc#1273131)
  • Allow using spacewalk-diskcheck without running service
  • Increase errata advisory char limit to 150 (bsc#1273846)
  • Use cryptographically secure random generation for secrets (bsc#1230568)
spacewalk-branding:
  • Version 5.2.7-0
  • No customer facing changes
spacewalk-client-tools:
  • Version 5.2.7-0
  • Update translation strings
spacewalk-config:
  • Version 5.2.5-0
  • CVE-2026-71400: Remove cobbler api endpoint from public interface (bsc#1274613, bsc#1274775)
spacewalk-java:
  • CVE-2026-71400: Remove cobbler api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.21-0
  • CVE-2026-63007: Check access rights on two formula API calls (bsc#1269253) - fixed in 5.2.20-0
  • CVE-2026-63009: Sanitize uploaded image name (bsc#1269534) - fixed in 5.2.20-0
  • Updated to version 5.2.22-0
  • Restored the original reset behavior in isDryRun() by swapping subscribedChannels and unsubscribedChannels back (bsc#1271681)
  • Fix mainframe foreign systems showing wrong OS (bsc#1260342)
  • Make setting of column filters in ListTag idempotent (bsc#1269192)
  • Fix hubsync package download checksum lookup (bsc#1270040)
  • Many to many relationships should not cascade deletion (bsc#1272392)
  • Optimized channel model generation logic to improve page load performance during peripheral channel selection (bsc#1259225)
  • Fixed Hibernate issue when updating the SSL content sources during a pay-as-you-go connection data refresh (bsc#1271382)
  • Allow diskcheck env vars into containers (bsc#1270033)
  • Query only systems for virtual machines which are flagged as virtualization hosts (bsc#1273073)
  • Use Channel equality even for ClonedChannel (bsc#1272621)
  • Fix EOL notifications in containers
  • Fix config channel position gaps (bsc#1272988)
  • Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039)
  • Prevent cascading package operations to checksums (bsc#1272392)
  • Fixed custom RBAC role names being incorrectly localized. (bsc#1271116)
  • Do not add FQDNs from proxy certificate (bsc#1270141, bsc#1272404)
  • Do not crash on conflicting FQDNs, add error message
  • Add delay to package clean to not interfere with repo-sync (bsc#1258500)
  • Improve handling of invalid issue date values when creating CLM filters via the API. (bsc#1271467)
  • Wait for taskomatic before processing events (bsc#1265472)
  • Use the standard Bootstrap 5 row class in place of legacy layout classes.
  • Remove udevdb salt module leftovers, udev is used now
  • Fix Hibernate session crash on Errata Sync by dynamically loading default access groups from the active session (bsc#1272298)
  • Fix Profile tab display in system details menu (bsc#1271963)
spacewalk-search:
  • Version 5.2.6-0
  • No customer facing changes
spacewalk-utils:
  • Version 5.2.8-0
  • Taskotop now handles timezone (bsc#1267871)
spacewalk-web:
  • Version 5.2.14-0
  • Improve product selection checkboxes in the setup UI
  • Show partial selection state for product trees more accurately
  • Fixed the 'Clear selected system set' button flickering during page navigation. (bsc#1271523)
  • Add web.version.eol setting to provide an end of life date
  • Fix duplicate remaining characters label in the Create Custom Info Key description field. (bsc#1269679)
  • Improve handling of invalid issue date values when creating CLM filters via the API. (bsc#1271467)
  • Refactor checkboxes in the RBAC UI
  • Reuse common Check component
  • Use the standard Bootstrap 5 row class in place of legacy layout classes.
struts:
  • Fix JakartaServletFileUpload as setFileSizeMax was renamed to setMaxFileSize
  • Use explicite same java version as spacewalk-java to get around 'class file has wrong version' errors
subscription-matcher:
  • Updated to version 0.47
  • Added missing part numbers (bsc#1274227, bsc#1265219)
  • Fix unsupported part number (bsc#1271075)
supportutils-plugin-susemanager:
  • Version 5.2.3-0
  • Allow 100 connection difference for apache and tomcat
  • Fix reading connections from the correct source
  • Add reportdb connections to the database connection limit (bsc#1262157)
susemanager:
  • Version 5.2.10-0
  • Add Ubuntu 26.04 LTS
susemanager-build-keys:
  • Update SUSE addon key - extended validity
susemanager-docs en:
  • Documented requirements and limitations for container image inspection on SLES 15 and SLES 16 (bsc#1274720)
  • Documented proxy certificate replacement using spacecmd (bsc#1271329)
  • Documented certificate setup and rotation with unified mgradm ssl rotate command
  • Documented allowing diskcheck environment variables into containers (bsc#1270033)
  • Clarified availability of Salt's 'virt' module in the Salt Bundle (bsc#1270694)
  • Added instruction for obtaining the certificate when renaming the server (bsc#1273853)
  • Added a common workflow for certificate setup and rotation with ACME
  • Documented how VMs are listed and referenced by virtual hosts (bsc#1273073)
  • Added documentation support for Ubuntu 26.04 client systems
  • Added the missing TFTP image in airgap install command
  • Fixed procedures for OpenSCAP in Administration Guide (bsc#1270047)
  • Fixed the snippet to reflect the correct produst version (bsc#1272538)
  • Corrected verification step order in MLM 5.0 to 5.2 upgrade guide for SL-Micro (bsc#1271678)
  • Extended configuration instructions for Saline formula in Specialized Guides (bsc#1268587)
  • Enhanced instructions for Liberate formula and reactivation key in Specialized Guides (bsc#1268473)
  • Fixed missing line end escapes in kubernetes helm install commands
  • Consolidated multiple duplicated activation key creation procedures into a single reusable partial snippet
  • Fixed Traefik installation documentation in Specialized Guides
  • Clarified CA certificate migration requirements (bsc#1271841)
  • Added instructions for enabling reporting dashboards in Specialized Guides (bsc#1268228)
  • Remove legacy mgradm and mgrpxy commands
  • Added the --set tag parameter to helm install/upgrade commands as a workaround (bsc#1271902)
  • Documented apache2 parameter used for large deployments (bsc#1268673)
  • Documented Grafana reporting database automated setup and Hub Overview in Administration and Specialized Guides
  • Update the OpenSCAP packages table in the System Security with OpenSCAP article in the Administration guide (bsc#1269316)
  • Added documentation for migrating legacy ISS v1 and ISS v2 peripheral servers to ISS v3 (Hub Online Synchronization) and detailed Report DB/XMLRPC API dependencies in Specialized Guides
  • Documented SLES 15 SP7 to SLES 16.0 major upgrade via product migration in Client Configuration Guide
susemanager-schema:
  • Version 5.2.14-0
  • Updated tables for CoCo attestation restructuring
  • Use temp table for hidden packages (bsc#1267912)
  • Renumber config channel positions to close gaps left by deleting an assigned config channel (ON DELETE CASCADE did not compact the survivors), preventing multiple failures (bsc#1272988)
  • Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039)
  • Increase advisory char limit to 150 in rhnErrata (bsc#1273846)
  • RBAC: add missing endpoints to 'systems.profiles' namespace (bsc#1271963)
susemanager-sls:
  • Version 5.2.15-0
  • Propagate cert validation errors to UI (bsc#1271332)
  • Fix cleanup timeout when deleting minions (bsc#1258567)
  • Fix salt deletion on SSH minions (bsc#1274023)
  • Set podman secrets for proxy directly from salt
  • Fix migration of jmx conf (bsc#1268755)
  • Remove unused udevdb salt module as upstream udev is used
susemanager-sync-data:
  • Version 5.2.6-0
  • Add Ubuntu 26.04 LTS
uyuni-coco-attestation:
  • Version 5.2.7-0
  • Ensure the certs directory is always created
  • Allow pvattest module to be built on s390x
uyuni-java-common:
  • Version 5.2.7-0
  • No customer facing changes
uyuni-java-parent:
  • Version 5.2.7-0
  • No customer facing changes
How to apply this update:
  1. Log in as root user to the SUSE Multi-Linux Manager Server.
  2. Upgrade mgradm and mgrctl.
  3. If you are in a disconnected environment, upgrade the image packages.
  4. Reboot the system.
  5. Run mgradm upgrade podman which will use the default image tags.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-63009
SUSE-SU-2026:4571-1

Produtos afetados

Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Saline-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Saline-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Saline-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Saline-Image
Uyuni-Tools