PT-2026-108717 · Suse · Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Httpd-Image+44

CVE-2026-63009

·

Published

2026-10-08

·

Updated

2026-10-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This update fixes the following issues:
Release Notes Highlights:
  • Added a note about the SUSE Registry IP address change.
  • Update to SUSE Multi-Linux Manager 5.2.1
  • Security fixes
  • Ubuntu 26.04 LTS Support
  • Confidential Computing Attestation for IBM Z Series
  • New uyuni-tftpd Container
  • Monitoring: Prometheus upgraded to 3.13.2
  • Monitoring: Grafana upgraded to 12.4.10
  • CVEs Fixed: CVE-2023-45289, CVE-2024-22195, CVE-2025-12141, CVE-2025-13836 CVE-2025-61686, CVE-2026-15308, CVE-2026-21723, CVE-2026-40181 CVE-2026-11940, CVE-2026-11972, CVE-2026-13346, CVE-2026-14199 CVE-2026-17033, CVE-2026-17183, CVE-2026-19197, CVE-2026-19475 CVE-2026-27459, CVE-2026-33814, CVE-2026-39821, CVE-2026-39882 CVE-2026-40475, CVE-2026-41066, CVE-2026-41178, CVE-2026-41606 CVE-2026-42211, CVE-2026-42342, CVE-2026-44431, CVE-2026-44990 CVE-2026-49825, CVE-2026-49853, CVE-2026-49854, CVE-2026-49855 CVE-2026-56852, CVE-2026-63007, CVE-2026-63009, CVE-2026-71400 CVE-2026-42127, CVE-2026-45409, CVE-2026-53606, CVE-2026-73501 CVE-2025-4673, CVE-2026-0864, CVE-2026-1229, CVE-2026-1502 CVE-2026-1703, CVE-2026-2303, CVE-2026-3219, CVE-2026-3276
Container images and uyuni-tools changes:
proxy-tftpd-image:
  • Updated to version 5.2.10
  • Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800)
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-attestation-image:
  • Version 5.2.11
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-database-migration-image:
  • Version 5.2.6
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-hub-xmlrpc-api-image:
  • Version 5.2.9
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
server-image:
  • Version 5.2.15
  • Increase start-period (bsc#1271124)
  • Check disk space on startup
  • Use correct healthcheck cmd (bsc#1273144)
  • Detect an existing cgroup2 mount by filesystem type, not mountpoint.
server-postgresql-image:
  • Version 5.2.13
  • Automatically set the log timezone for TZ env (bsc#1267871)
  • Increase start-period and timeout (bsc#1271124)
  • Check disk space on startup
server-saline-image:
  • Version 5.2.11
  • Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.2.1
uyuni-tools:
  • CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)
  • Version 5.2.17-0
  • Bump the default image tag to 5.2.1
  • Reload systemd daemon before restarting services (bsc#1270033)
  • Check all supported locations for CA file in rotation check script
  • Detect and fix legacy service file (bsc#1268755)
  • Use healthcheck cmd from the image (bsc#1273144)
The following packages are underlying build dependencies and system components used by the containers:
apache-commons-fileupload2:
  • Updated to version 2.0.0-M5
  • Add AbstractFileUpload support for a maximum part header size
  • FILEUPLOAD-367: Jakarta and Javax ServletFileUpload .isMultipartContent(HttpServletRequest) should allow PUT and PATCH request methods in addition to POST
  • FILEUPLOAD-367: Add AbstractFileUpload .isMultipartRequestMethod(String)
  • FILEUPLOAD-295: Clarified the precise meaning of isInMemory(), get(), getPath(), etc. in DiskFileItem
  • Better exception type and message if a multipart/mixed part is presented without a boundary defined
  • Bump org.apache.commons:commons-parent from 84 to 96
  • Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0
  • Bump commons-io:commons-io from 2.19.0 to 2.21.0
byte-buddy:
  • Updated to version 1.18.8
  • Introduce new versioning concept with -jdk5 suffix for backwards-compatible jar and Java 8 baseline for regular jar
  • Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted
  • Add super classes to hash code / equals computation in Advice that were missing
  • Add support for new build description in Android 9
mgr-push:
  • Version 5.2.5-0
  • Remove token based authentication mechanism for package push (bsc#1230949)
objectweb-asm:
  • Updated to version 9.10.1
  • New Opcodes.V27 constant for Java 27
python-susemanager-retail:
  • Version 1.2.1
  • Fix issue building package on SLES 16.0
salt:
  • Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)
  • Support attrlist in ldap.managed (bsc#1257151)
  • Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
  • Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)
spacecmd:
  • Version 5.2.10-0
  • Pre-filter errata in system applyerrata to avoid using API calls for all existing errata (bsc#1267261)
spacewalk-backend:
  • Version 5.2.10-0
  • Allow diskcheck env vars into containers (bsc#1270033)
  • Use sha256 as the default checksum type for Debian repositories
  • Remove token based authentication mechanism for package push (bsc#1230949)
  • Fix gpgverify signature file check for file object (bsc#1273131)
  • Allow using spacewalk-diskcheck without running service
  • Increase errata advisory char limit to 150 (bsc#1273846)
  • Use cryptographically secure random generation for secrets (bsc#1230568)
spacewalk-branding:
  • Version 5.2.7-0
  • No customer facing changes
spacewalk-client-tools:
  • Version 5.2.7-0
  • Update translation strings
spacewalk-config:
  • Version 5.2.5-0
  • CVE-2026-71400: Remove cobbler api endpoint from public interface (bsc#1274613, bsc#1274775)
spacewalk-java:
  • CVE-2026-71400: Remove cobbler api endpoint from public interface (bsc#1274613, bsc#1274775) - fixed in 5.2.21-0
  • CVE-2026-63007: Check access rights on two formula API calls (bsc#1269253) - fixed in 5.2.20-0
  • CVE-2026-63009: Sanitize uploaded image name (bsc#1269534) - fixed in 5.2.20-0
  • Updated to version 5.2.22-0
  • Restored the original reset behavior in isDryRun() by swapping subscribedChannels and unsubscribedChannels back (bsc#1271681)
  • Fix mainframe foreign systems showing wrong OS (bsc#1260342)
  • Make setting of column filters in ListTag idempotent (bsc#1269192)
  • Fix hubsync package download checksum lookup (bsc#1270040)
  • Many to many relationships should not cascade deletion (bsc#1272392)
  • Optimized channel model generation logic to improve page load performance during peripheral channel selection (bsc#1259225)
  • Fixed Hibernate issue when updating the SSL content sources during a pay-as-you-go connection data refresh (bsc#1271382)
  • Allow diskcheck env vars into containers (bsc#1270033)
  • Query only systems for virtual machines which are flagged as virtualization hosts (bsc#1273073)
  • Use Channel equality even for ClonedChannel (bsc#1272621)
  • Fix EOL notifications in containers
  • Fix config channel position gaps (bsc#1272988)
  • Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039)
  • Prevent cascading package operations to checksums (bsc#1272392)
  • Fixed custom RBAC role names being incorrectly localized. (bsc#1271116)
  • Do not add FQDNs from proxy certificate (bsc#1270141, bsc#1272404)
  • Do not crash on conflicting FQDNs, add error message
  • Add delay to package clean to not interfere with repo-sync (bsc#1258500)
  • Improve handling of invalid issue date values when creating CLM filters via the API. (bsc#1271467)
  • Wait for taskomatic before processing events (bsc#1265472)
  • Use the standard Bootstrap 5 row class in place of legacy layout classes.
  • Remove udevdb salt module leftovers, udev is used now
  • Fix Hibernate session crash on Errata Sync by dynamically loading default access groups from the active session (bsc#1272298)
  • Fix Profile tab display in system details menu (bsc#1271963)
spacewalk-search:
  • Version 5.2.6-0
  • No customer facing changes
spacewalk-utils:
  • Version 5.2.8-0
  • Taskotop now handles timezone (bsc#1267871)
spacewalk-web:
  • Version 5.2.14-0
  • Improve product selection checkboxes in the setup UI
  • Show partial selection state for product trees more accurately
  • Fixed the 'Clear selected system set' button flickering during page navigation. (bsc#1271523)
  • Add web.version.eol setting to provide an end of life date
  • Fix duplicate remaining characters label in the Create Custom Info Key description field. (bsc#1269679)
  • Improve handling of invalid issue date values when creating CLM filters via the API. (bsc#1271467)
  • Refactor checkboxes in the RBAC UI
  • Reuse common Check component
  • Use the standard Bootstrap 5 row class in place of legacy layout classes.
struts:
  • Fix JakartaServletFileUpload as setFileSizeMax was renamed to setMaxFileSize
  • Use explicite same java version as spacewalk-java to get around 'class file has wrong version' errors
subscription-matcher:
  • Updated to version 0.47
  • Added missing part numbers (bsc#1274227, bsc#1265219)
  • Fix unsupported part number (bsc#1271075)
supportutils-plugin-susemanager:
  • Version 5.2.3-0
  • Allow 100 connection difference for apache and tomcat
  • Fix reading connections from the correct source
  • Add reportdb connections to the database connection limit (bsc#1262157)
susemanager:
  • Version 5.2.10-0
  • Add Ubuntu 26.04 LTS
susemanager-build-keys:
  • Update SUSE addon key - extended validity
susemanager-docs en:
  • Documented requirements and limitations for container image inspection on SLES 15 and SLES 16 (bsc#1274720)
  • Documented proxy certificate replacement using spacecmd (bsc#1271329)
  • Documented certificate setup and rotation with unified mgradm ssl rotate command
  • Documented allowing diskcheck environment variables into containers (bsc#1270033)
  • Clarified availability of Salt's 'virt' module in the Salt Bundle (bsc#1270694)
  • Added instruction for obtaining the certificate when renaming the server (bsc#1273853)
  • Added a common workflow for certificate setup and rotation with ACME
  • Documented how VMs are listed and referenced by virtual hosts (bsc#1273073)
  • Added documentation support for Ubuntu 26.04 client systems
  • Added the missing TFTP image in airgap install command
  • Fixed procedures for OpenSCAP in Administration Guide (bsc#1270047)
  • Fixed the snippet to reflect the correct produst version (bsc#1272538)
  • Corrected verification step order in MLM 5.0 to 5.2 upgrade guide for SL-Micro (bsc#1271678)
  • Extended configuration instructions for Saline formula in Specialized Guides (bsc#1268587)
  • Enhanced instructions for Liberate formula and reactivation key in Specialized Guides (bsc#1268473)
  • Fixed missing line end escapes in kubernetes helm install commands
  • Consolidated multiple duplicated activation key creation procedures into a single reusable partial snippet
  • Fixed Traefik installation documentation in Specialized Guides
  • Clarified CA certificate migration requirements (bsc#1271841)
  • Added instructions for enabling reporting dashboards in Specialized Guides (bsc#1268228)
  • Remove legacy mgradm and mgrpxy commands
  • Added the --set tag parameter to helm install/upgrade commands as a workaround (bsc#1271902)
  • Documented apache2 parameter used for large deployments (bsc#1268673)
  • Documented Grafana reporting database automated setup and Hub Overview in Administration and Specialized Guides
  • Update the OpenSCAP packages table in the System Security with OpenSCAP article in the Administration guide (bsc#1269316)
  • Added documentation for migrating legacy ISS v1 and ISS v2 peripheral servers to ISS v3 (Hub Online Synchronization) and detailed Report DB/XMLRPC API dependencies in Specialized Guides
  • Documented SLES 15 SP7 to SLES 16.0 major upgrade via product migration in Client Configuration Guide
susemanager-schema:
  • Version 5.2.14-0
  • Updated tables for CoCo attestation restructuring
  • Use temp table for hidden packages (bsc#1267912)
  • Renumber config channel positions to close gaps left by deleting an assigned config channel (ON DELETE CASCADE did not compact the survivors), preventing multiple failures (bsc#1272988)
  • Separate Live-Patching Errata for SLE15 SP7 (bsc#1270039)
  • Increase advisory char limit to 150 in rhnErrata (bsc#1273846)
  • RBAC: add missing endpoints to 'systems.profiles' namespace (bsc#1271963)
susemanager-sls:
  • Version 5.2.15-0
  • Propagate cert validation errors to UI (bsc#1271332)
  • Fix cleanup timeout when deleting minions (bsc#1258567)
  • Fix salt deletion on SSH minions (bsc#1274023)
  • Set podman secrets for proxy directly from salt
  • Fix migration of jmx conf (bsc#1268755)
  • Remove unused udevdb salt module as upstream udev is used
susemanager-sync-data:
  • Version 5.2.6-0
  • Add Ubuntu 26.04 LTS
uyuni-coco-attestation:
  • Version 5.2.7-0
  • Ensure the certs directory is always created
  • Allow pvattest module to be built on s390x
uyuni-java-common:
  • Version 5.2.7-0
  • No customer facing changes
uyuni-java-parent:
  • Version 5.2.7-0
  • No customer facing changes
How to apply this update:
  1. Log in as root user to the SUSE Multi-Linux Manager Server.
  2. Upgrade mgradm and mgrctl.
  3. If you are in a disconnected environment, upgrade the image packages.
  4. Reboot the system.
  5. Run mgradm upgrade podman which will use the default image tags.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63009
SUSE-SU-2026:4571-1

Affected Products

Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-Aarch64-Server-Saline-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-Ppc64Le-Server-Saline-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-S390X-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-S390X-Server-Saline-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Httpd-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Salt-Broker-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Squid-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Ssh-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Proxy-Tftpd-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Attestation-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Database-Migration-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Hub-Xmlrpc-Api-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Postgresql-Image
Suse-Multi-Linux-Manager-5.2-X86 64-Server-Saline-Image
Uyuni-Tools