{"id":"SUSE-SU-2026:23787-1","summary":"Security update for rpm","details":"This update for rpm fixes the following issues:\n\nChanges in rpm:\n\n- split imaevmsign plugin into a multibuild flavor\n\nChanges in rpm:\n\n- Add Requires: (rpm-plugin-selinux if selinux-policy)\n- harden ndb code [bsc#1269584] [CVE-2026-44605]\n- split all plugins into subpackages\n  * this allows for an easy way to get rid of a plugin, it's also\n    what other distributions do\n- make the imaevmsign plugin build in a multibuild flavor\n- rpm2archive: use size 0 for hardlinked files as bnew versions of\n  gnu tar reject non-zero sizes [bsc#1269150]\n- backport fix for add_sysuser macro [bsc#1269571]\n- backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604]\n- switch from rpmpgp_legacy to libpgpr\n  * multiple bug fixes, support for v5 and v6 signatures\n- turn on imaevm file signature support and move the imaevm code\n  that needs the libimaevm library into a plugin. Put this\n  plugin into a new \"rpm-imaevmsign\" subpackage. [jsc#PED-7246]\n- Fix \"unexpected EOF\" when using rpmbuild to install ELF binaries\n  due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215)\n- Remove /var/lib/rpm migration scripting, retain an error if old\n  location is found\n- Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink\n  (boo#1253139)\n- flush scriptlet notification messages in --runposttrans\n  * needed to fix leaking tmp files [bsc#1218459]\n  * added \"rpm_flushes_runposttrans\" provides for libzypp\n","modified":"2026-09-27T18:23:12.078882283Z","published":"2026-09-16T14:30:37Z","related":["CVE-2026-44604","CVE-2026-44605"],"upstream":["CVE-2026-44604","CVE-2026-44605"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623787-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218459"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253139"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259215"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268747"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269150"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269571"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269584"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44604"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44605"}],"affected":[{"package":{"name":"python-rpm","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/python-rpm&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.20.1-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"rpm-devel":"4.20.1-160000.3.1","rpm-plugin-selinux":"4.20.1-160000.3.1","rpm-plugin-ima":"4.20.1-160000.3.1","rpm-build":"4.20.1-160000.3.1","python313-rpm":"4.20.1-160000.3.1","rpm-plugin-prioreset":"4.20.1-160000.3.1","rpm-plugin-imaevmsign":"4.20.1-160000.3.1","librpmbuild10":"4.20.1-160000.3.1","rpm-plugin-fapolicyd":"4.20.1-160000.3.1","rpm-plugin-unshare":"4.20.1-160000.3.1","rpm-plugin-syslog":"4.20.1-160000.3.1","rpm":"4.20.1-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23787-1.json"}},{"package":{"name":"rpm","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/rpm&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.20.1-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"rpm":"4.20.1-160000.3.1","rpm-plugin-fapolicyd":"4.20.1-160000.3.1","rpm-plugin-prioreset":"4.20.1-160000.3.1","librpmbuild10":"4.20.1-160000.3.1","rpm-plugin-ima":"4.20.1-160000.3.1","rpm-plugin-syslog":"4.20.1-160000.3.1","rpm-build":"4.20.1-160000.3.1","rpm-plugin-imaevmsign":"4.20.1-160000.3.1","rpm-devel":"4.20.1-160000.3.1","rpm-plugin-unshare":"4.20.1-160000.3.1","rpm-plugin-selinux":"4.20.1-160000.3.1","python313-rpm":"4.20.1-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23787-1.json"}},{"package":{"name":"rpm-plugin-imaevmsign","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/rpm-plugin-imaevmsign&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.20.1-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"rpm-devel":"4.20.1-160000.3.1","rpm-plugin-prioreset":"4.20.1-160000.3.1","rpm-plugin-selinux":"4.20.1-160000.3.1","rpm-plugin-ima":"4.20.1-160000.3.1","rpm-plugin-fapolicyd":"4.20.1-160000.3.1","rpm-plugin-unshare":"4.20.1-160000.3.1","rpm":"4.20.1-160000.3.1","rpm-plugin-imaevmsign":"4.20.1-160000.3.1","librpmbuild10":"4.20.1-160000.3.1","rpm-build":"4.20.1-160000.3.1","rpm-plugin-syslog":"4.20.1-160000.3.1","python313-rpm":"4.20.1-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23787-1.json"}},{"package":{"name":"python-rpm","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/python-rpm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.20.1-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"rpm-plugin-syslog":"4.20.1-160000.3.1","rpm-plugin-unshare":"4.20.1-160000.3.1","rpm-plugin-ima":"4.20.1-160000.3.1","rpm-devel":"4.20.1-160000.3.1","rpm-plugin-imaevmsign":"4.20.1-160000.3.1","rpm-plugin-selinux":"4.20.1-160000.3.1","python313-rpm":"4.20.1-160000.3.1","rpm-build":"4.20.1-160000.3.1","rpm-plugin-prioreset":"4.20.1-160000.3.1","rpm":"4.20.1-160000.3.1","rpm-plugin-fapolicyd":"4.20.1-160000.3.1","librpmbuild10":"4.20.1-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23787-1.json"}},{"package":{"name":"rpm","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/rpm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.20.1-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"python313-rpm":"4.20.1-160000.3.1","rpm-devel":"4.20.1-160000.3.1","rpm-plugin-prioreset":"4.20.1-160000.3.1","librpmbuild10":"4.20.1-160000.3.1","rpm":"4.20.1-160000.3.1","rpm-plugin-ima":"4.20.1-160000.3.1","rpm-plugin-imaevmsign":"4.20.1-160000.3.1","rpm-plugin-syslog":"4.20.1-160000.3.1","rpm-plugin-unshare":"4.20.1-160000.3.1","rpm-build":"4.20.1-160000.3.1","rpm-plugin-selinux":"4.20.1-160000.3.1","rpm-plugin-fapolicyd":"4.20.1-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23787-1.json"}},{"package":{"name":"rpm-plugin-imaevmsign","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/rpm-plugin-imaevmsign&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.20.1-160000.3.1"}]}],"ecosystem_specific":{"binaries":[{"rpm-plugin-syslog":"4.20.1-160000.3.1","rpm-build":"4.20.1-160000.3.1","rpm-plugin-prioreset":"4.20.1-160000.3.1","rpm-plugin-ima":"4.20.1-160000.3.1","librpmbuild10":"4.20.1-160000.3.1","rpm-plugin-selinux":"4.20.1-160000.3.1","python313-rpm":"4.20.1-160000.3.1","rpm":"4.20.1-160000.3.1","rpm-plugin-imaevmsign":"4.20.1-160000.3.1","rpm-devel":"4.20.1-160000.3.1","rpm-plugin-unshare":"4.20.1-160000.3.1","rpm-plugin-fapolicyd":"4.20.1-160000.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23787-1.json"}}],"schema_version":"1.9.0"}