{"id":"SUSE-SU-2026:21518-1","summary":"Security update for build, product-composer","details":"This update for build, product-composer fixes the following issues:\n\nChanges in build:\n\n- Support a new \"IgnoreRebuild\" config.\n\n- build-recipe-kiwi:\n\n  * Add support for oci containers\n  * Avoid needlessly compressing container images\n  * Detect container images based on build result file name\n\n- Fix queryrecipe to use the summary and the description from the main package\n\n- config: Add slfo-main build configuration\n- drop the inner quotes, not needed on bash 4 and breaks on bash 3\n- build: in the ccache case, after test -e also accept -L\n\n- container:\n\n  * Add microdnf package manager support\n  * Add experimental support for the container-timestamp build option\n\n- sbom:\n\n  * allow to create v1 intoto data\n  * spdx: connect OPERATING-SYSTEM package to the root package\n  * Transfer product vcs and disturl\n\n- Support --cms-nocerts and --cms-keyid in the signdummy\n- Support chroot builds inside of containers\n- runservice tool, allow to specify the modes. Can be\n  used on plain git source now also\n- Support --mtime option for cpio creation\n- generate_sbom:\n\n   * Support also unzck compressed repomd files\n   * Fail when given --product directory is missing\n   * support zstd compressed repomd data\n\n- build-vm-lxc: support lxc \u003e= 5\n- vc: Hide an annoying error message when not using NIS\n\n- added leap-16.0 and leap-16.1 build configs.\n  (not named sl16.0 anymore, but using same string as the git branch)\n\n- Implement cmssign support in signdummy\n- pbuild: mark git assets with a fixed commit as immutable\n- mkosi\n  * check if old parameters are supported before passing them\n  * support old bash version\n- Do not crash on small files that start with the PE magic\n\n- Harden export_debian_orig_from_git (CVE-2024-22038, boo#1230469)\n\nChanges in product-composer:\n\nupdate to version 0.9.6:\n\n  * Speed-up reading of rpm headers\n  * Flush output lines to get get correct timestamps in OBS\n\nupdate to version 0.9.5:\n\n  * Be a bit more verbose to track used times per step in OBS\n  * Fix a crash when doing version compare with an epoch\n\nupdate to version 0.9.4:\n\n  * Give an error when trying to add updateinfo meta data\n    without all binary revisions.\n  * Hand over vcs and disturl data to generate_sbom.\n    (We require a recent build package therefore)\n","modified":"2026-07-09T18:24:06.840453748Z","published":"2026-05-05T06:49:04Z","related":["CVE-2024-22038"],"upstream":["CVE-2024-22038"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621518-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-22038"}],"affected":[{"package":{"name":"build","ecosystem":"SUSE:Linux Micro Extras 6.2","purl":"pkg:rpm/suse/build&distro=SUSE%20Linux%20Micro%20Extras%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20260415-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"build-mkbaselibs":"20260415-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21518-1.json"}}],"schema_version":"1.7.5"}