{"id":"SUSE-SU-2026:4584-1","summary":"Security update 5.2.1 for Multi-Linux Manager Client Tools","details":"This update fixes the following issues:\n\nmgr-push was updated to version 5.2.5:\n\n- Removed token based authentication mechanism for package_push (bsc#1230949)\n\nspacecmd was updated to version 5.2.10:\n\n- Pre-filter errata in system_applyerrata to avoid using API calls for all existing errata (bsc#1267261)\n- Updated translation strings\n\nspacewalk-client-tools was updated to version 5.2.7::\n\n- Updated translation strings\n\nuyuni-tools was updated to version 5.2.17:\n\nSecurity issues fixed:\n\n- CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)\n\nBug fixes and changes:\n\n- Version 5.2.17-0:\n\n  * Bump the default image tag to 5.2.1\n  * Reload systemd daemon before restarting services (bsc#1270033)\n  * Check all supported locations for CA file in rotation check script\n  * Detect and fix legacy service file (bsc#1268755)\n  * Use healthcheck cmd from the image (bsc#1273144)\n\n- Version 5.2.16-0:\n\n  * Reverted usage of sdnotify as it causes issues with Podman (bsc#1270399, bsc#1270398)\n\n- Version 5.2.15-0:\n\n  * Added requirement for at least Podman v4.7.2\n  * Send READY notification to systemd only once healthy (bsc#1263823)\n\n- Version 5.2.14-0:\n\n  * Include the server environment file in the backup (bsc#1268649)\n  * Added mgradm commands for SSL CA and certificate rotation\n\n- Version 5.2.13-0:\n\n  * Check and warn if CA certificate isn't marked as critical\n  * Disable SSL on database during split (bsc#1267980)\n  * Do not call uyuni-postgres-config.sh in mgradm (bsc#1267980)\n  * Check backup status only after database is started (bsc#1262492)\n\nvenv-salt-minion:\n\n- Security issues:\n\n  * CVE-2026-13346: Fixed an issue where malicious package indexes could install unauthorized files (bsc#1273094)\n  * CVE-2026-0864: Fixed custom configuration injection risks caused by improper line-ending validation (bsc#1269066)\n  * CVE-2026-1502: Fixed web request header manipulation to bypass proxy security protections (bsc#1261969)\n  * CVE-2026-3276: Fixed potential system slow down or freeze when processing crafted Unicode text (bsc#1267581)\n  * CVE-2026-4360: Fixed directory escape risks during archive extraction (bsc#1269959)\n  * CVE-2026-4786: Fixed command injection risks when processing malicious browser links (bsc#1262319)\n  * CVE-2026-6019: Fixed a flaw where cookies could be manipulated to run malicious script (bsc#1262654)\n  * CVE-2026-6100: Fixed crashes or unauthorized code execution during file decompression (bsc#1262098)\n  * CVE-2026-7210: Fixed system freezes triggered by parsing malicious XML files (bsc#1264962)\n  * CVE-2026-7774: Fixed path traversal risks where malicious archives write files outside targets (bsc#1267821)\n  * CVE-2026-8328: Fixed connections being redirected to unsafe systems by compromised FTP servers (bsc#1265268)\n  * CVE-2026-11940: Fixed a bug where extracting malicious archives could overwrite system files (bsc#1268977)\n  * CVE-2026-11972: Fixed infinite loop and system freeze risks during archive decompression (bsc#1269788)\n  * CVE-2026-15308: Fixed crashes when parsing web pages with repetitive, incomplete structures (bsc#1271192)\n  * CVE-2026-8643: Fixed malicious package installs overwriting arbitrary local files (bsc#1266669)\n  * CVE-2026-6357: Fixed package self-updates loading unauthorized modules during install (bsc#1263442)\n  * CVE-2026-3219: Fixed validation failures where combined ZIP archives were not rejected (bsc#1262429)\n  * CVE-2026-1703: Fixed package installations writing files outside target directories (bsc#1257599)\n  * CVE-2024-22195: Fixed HTML template manipulation allowing unauthorized script execution (bsc#1218722)\n  * CVE-2026-45409: Fixed domain name encoding bypass allowing imitation websites (bsc#1265413)\n  * CVE-2026-44431: Fixed data leaks where sensitive headers were sent to external origins (bsc#1265267)\n  * CVE-2026-49825: Fixed missing script cleanup from namespaces in web content (bsc#1270285)\n  * CVE-2026-41066: Fixed leakage of private system data via malicious XML file parsing (bsc#1263254)\n  * CVE-2026-3446: Fixed validation bypasses where hidden excess Base64 data was ignored (bsc#1261970)\n  * CVE-2026-3479: Fixed path traversal risks when loading packages from insecure locations (bsc#1259989)\n  * CVE-2026-27459: Fixed buffer overflow vulnerabilities caused by large cookie headers (bsc#1271428)\n  * CVE-2026-49853: Fixed credentials leakage during redirects to cross-origin servers (bsc#1268395)\n  * CVE-2026-49854: Fixed crashes or unauthorized memory access in compiled components (bsc#1268396)\n  * CVE-2026-49855: Fixed crashes caused by excessively compressed files exhausting memory (bsc#1268397)\n  * CVE-2026-40475: Fixed silent data truncation where hidden null characters bypass checks (bsc#1262803)\n  * CVE-2025-13836: Fixed memory exhaustion risk by limiting HTTP response reading size (bsc#1254400)\n\n- Bug fixes and changes:\n\n  * Updated bundled python module pip to 25.0.1\n  * Updated bundled python module jinja2 to 3.1.6\n  * Updated bundled python module lxml to 6.1.1\n  * Prevent broken Salt Bundle on Ubuntu due regression in 'tar' package from Ubuntu repositories (bsc#1271613)\n  * Remove unused paramiko python module from the bundle.\n  * Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286)\n  * Support attrlist in ldap.managed (bsc#1257151)\n  * Use AsyncHTTPClient in salt.utils.http (bsc#1268325)\n  * Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)\n\n","modified":"2026-10-08T19:15:04.953317343Z","published":"2026-10-08T08:23:05Z","related":["CVE-2024-22195","CVE-2025-13836","CVE-2026-0864","CVE-2026-11940","CVE-2026-11972","CVE-2026-13346","CVE-2026-1502","CVE-2026-15308","CVE-2026-1703","CVE-2026-27459","CVE-2026-3219","CVE-2026-3276","CVE-2026-3446","CVE-2026-3479","CVE-2026-39821","CVE-2026-40475","CVE-2026-41066","CVE-2026-4360","CVE-2026-44431","CVE-2026-45409","CVE-2026-4786","CVE-2026-49825","CVE-2026-49853","CVE-2026-49854","CVE-2026-49855","CVE-2026-6019","CVE-2026-6100","CVE-2026-6357","CVE-2026-7210","CVE-2026-7774","CVE-2026-8328","CVE-2026-8643"],"upstream":["CVE-2024-22195","CVE-2025-13836","CVE-2026-0864","CVE-2026-11940","CVE-2026-11972","CVE-2026-13346","CVE-2026-1502","CVE-2026-15308","CVE-2026-1703","CVE-2026-27459","CVE-2026-3219","CVE-2026-3276","CVE-2026-3446","CVE-2026-3479","CVE-2026-39821","CVE-2026-40475","CVE-2026-41066","CVE-2026-4360","CVE-2026-44431","CVE-2026-45409","CVE-2026-4786","CVE-2026-49825","CVE-2026-49853","CVE-2026-49854","CVE-2026-49855","CVE-2026-6019","CVE-2026-6100","CVE-2026-6357","CVE-2026-7210","CVE-2026-7774","CVE-2026-8328","CVE-2026-8643"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264584-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257151"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257599"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259989"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261969"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261970"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262098"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262492"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262654"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262803"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263442"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263822"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263823"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264962"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265267"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265268"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265413"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266481"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266669"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267261"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267581"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267980"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268325"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268395"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268396"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268397"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268649"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268755"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268977"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269066"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269959"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270033"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270285"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270398"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270399"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271192"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271613"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273094"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-22195"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-13836"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-0864"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27459"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3219"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3446"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40475"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41066"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44431"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49825"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49853"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6100"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7210"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-7774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8643"}],"affected":[{"package":{"name":"mgr-push","ecosystem":"SUSE:Multi Linux Manager Tools SLE-12","purl":"pkg:rpm/suse/mgr-push&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.5-120002.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"mgrctl":"5.2.17-120002.3.18.1","spacewalk-client-tools":"5.2.7-120002.3.12.1","spacecmd":"5.2.10-120002.3.15.1","mgrctl-bash-completion":"5.2.17-120002.3.18.1","mgr-push":"5.2.5-120002.3.12.1","python2-mgr-push":"5.2.5-120002.3.12.1","mgrctl-lang":"5.2.17-120002.3.18.1","mgrctl-zsh-completion":"5.2.17-120002.3.18.1","python2-spacewalk-client-tools":"5.2.7-120002.3.12.1","venv-salt-minion":"3006.0-120002.5.22.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"}},{"package":{"name":"spacecmd","ecosystem":"SUSE:Multi Linux Manager Tools SLE-12","purl":"pkg:rpm/suse/spacecmd&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.10-120002.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"spacecmd":"5.2.10-120002.3.15.1","mgr-push":"5.2.5-120002.3.12.1","spacewalk-client-tools":"5.2.7-120002.3.12.1","venv-salt-minion":"3006.0-120002.5.22.2","mgrctl-lang":"5.2.17-120002.3.18.1","mgrctl-bash-completion":"5.2.17-120002.3.18.1","mgrctl-zsh-completion":"5.2.17-120002.3.18.1","mgrctl":"5.2.17-120002.3.18.1","python2-spacewalk-client-tools":"5.2.7-120002.3.12.1","python2-mgr-push":"5.2.5-120002.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"}},{"package":{"name":"spacewalk-client-tools","ecosystem":"SUSE:Multi Linux Manager Tools SLE-12","purl":"pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.7-120002.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"mgrctl-zsh-completion":"5.2.17-120002.3.18.1","mgrctl-lang":"5.2.17-120002.3.18.1","spacewalk-client-tools":"5.2.7-120002.3.12.1","spacecmd":"5.2.10-120002.3.15.1","mgrctl":"5.2.17-120002.3.18.1","python2-spacewalk-client-tools":"5.2.7-120002.3.12.1","venv-salt-minion":"3006.0-120002.5.22.2","python2-mgr-push":"5.2.5-120002.3.12.1","mgr-push":"5.2.5-120002.3.12.1","mgrctl-bash-completion":"5.2.17-120002.3.18.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"}},{"package":{"name":"uyuni-tools","ecosystem":"SUSE:Multi Linux Manager Tools SLE-12","purl":"pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.17-120002.3.18.1"}]}],"ecosystem_specific":{"binaries":[{"mgrctl-lang":"5.2.17-120002.3.18.1","spacecmd":"5.2.10-120002.3.15.1","python2-spacewalk-client-tools":"5.2.7-120002.3.12.1","mgr-push":"5.2.5-120002.3.12.1","mgrctl":"5.2.17-120002.3.18.1","mgrctl-bash-completion":"5.2.17-120002.3.18.1","mgrctl-zsh-completion":"5.2.17-120002.3.18.1","venv-salt-minion":"3006.0-120002.5.22.2","python2-mgr-push":"5.2.5-120002.3.12.1","spacewalk-client-tools":"5.2.7-120002.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"}},{"package":{"name":"venv-salt-minion","ecosystem":"SUSE:Multi Linux Manager Tools SLE-12","purl":"pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3006.0-120002.5.22.2"}]}],"ecosystem_specific":{"binaries":[{"python2-mgr-push":"5.2.5-120002.3.12.1","mgr-push":"5.2.5-120002.3.12.1","mgrctl-lang":"5.2.17-120002.3.18.1","mgrctl-zsh-completion":"5.2.17-120002.3.18.1","spacecmd":"5.2.10-120002.3.15.1","mgrctl-bash-completion":"5.2.17-120002.3.18.1","python2-spacewalk-client-tools":"5.2.7-120002.3.12.1","mgrctl":"5.2.17-120002.3.18.1","venv-salt-minion":"3006.0-120002.5.22.2","spacewalk-client-tools":"5.2.7-120002.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4584-1.json"}}],"schema_version":"1.9.0"}