{"id":"openSUSE-SU-2026:21933-1","summary":"Security update for sdbootutil","details":"This update for sdbootutil fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2026-41676: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1\n  (bsc#1270192).\n- CVE-2026-41677: out-of-bounds read in PEM password callback when returning an oversized length in rust-openssl\n  crate (bsc#1270616).\n- CVE-2026-41678: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270670).\n- CVE-2026-41681: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate\n  (bsc#1270742).\n- CVE-2026-41898: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent\n  memory in rust-openssl crate (bsc#1270863).\n- CVE-2026-42327: arbitrary code execution via specially crafted certificate in rust-openssl crate\n  (bsc#1270471).\n- CVE-2026-44662: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate\n  (bsc#1270922).\n- CVE-2026-45784: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-\n  openssl crate (bsc#1270995).\n\nNon security issues fixed:\n\n- sdbootutil-update-predictions.service fails with  Failed to start Update TPM predictions (bsc#1273384).\n- systemd ordering cycle and other service problems with snapshot 20260722 (bsc#1272525).\n- Unable to unlock multiple encrypted partitions with FIDO2 Key, Systemdboot+LUKS (bsc#1234010).\n\nChanges for sdbootutil:\n\n- Update to version 1+git20260908.c641fc2:\n * Update the shim when required\n * Warn when recovery PIN is different from recovery key\n * Improves extra boot entries support\n * Better report when the default snapshot diverges\n * Explain how to do re-enrolling if recovery PIN fails\n * Explain why update-prediction fails and how to solve it\n * Hide comparison output\n * Add bootctl default entry in the prediction\n- Update to version 1+git20260903.f91f636:\n * Include FIDO2 unlocked devices for ordering (bsc#1234010)\n * Test in parallel for speed up\n * Add --repair parameter to cleanup\n * Fix shellcheck complain\n * Report entries with missing files\n * Avoid duplicate entries in non-snapper systems\n * Add initial tests for sdbootutil\n * Report the error if bootctl clean fails\n- Update to version 1+git20260901.41540d5:\n * No warn if a component is not in the event log\n * Add status command\n * Select the new sdbootutil if available\n * Skip blank lines in measure-pcr-generator.sh\n * Do not change crypttab for unrelated entries\n * Report the bad PCR when update-prediction fail\n * Do not write the recovery PIN in the journal\n * Improves non snapshot system support\n * Update help message for --measure-pcr\n * Report when PCR 7 is dropped because shim update\n * Add --strict parameter for --pcr policy\n * Report dropped PCRs via a warn\n * Adjust the limits for PolicyOR issues\n * Avoid update predictions if the service is up\n * Keep the exit status of sdbootutil call\n- Update to version 1+git20260827.786f9a8:\n * Do not accept empty passwords\n * jeos-firstboot-enroll: report errors also in the journal\n * Restore old crypttab via the exit trap\n * Update CLAUDE data\n * Detect half created openssl keys\n * check_enrolled report when something was written in the LUKS2 header\n * Improve a bit the disk-encryption-tool keyslot detection\n * Avoid leak of env var secrets\n * Wipe the d-e-t key in the enroll service and jeos module\n * Remove the correct keyslot left by d-e-t\n * Differentiate tpm2 and tpm2+pin for unattended unlock\n * Use is_same_device in detect_tracked_device and drop greps\n * Refactor check to avoid shellcheck complain\n * Parse the entry file in a sigle place\n * Validate the entry with the new kernel name\n * Refactor enrollment interface and deprecate the old one\n * New kernels will have different hash\n * Warn If no crypttab entry found\n * Extend is_same_device\n * jeos-firstboot-enroll: validate the passwords\n * sdbootutil-enroll: report when no encryption method is provided\n * Write recovery pin after enrollment in jeos module\n * Write recovery pin after enrollment\n * Improve error detection in sdbootutil-enroll\n * Increase keyctl timeout\n * Merge require_unlock and set_unlock_method\n * Be sure that the terminal check works with snapper\n * Renerate initrd when new measure-pcr keys are created\n * Separate ask-* parameters\n * Fix reading credential and keyctl password\n * Get the device password for each enrolling mechanism\n * Drop elements from crypttab if the enrollment fails\n * Validate the enrollment for each method\n * Add warning when enrolling FIDO2 token\n- Update to version 1+git20260825.c7a5a97:\n * Refactor free space calculation\n * Do not use /proc/cmdline in half configured systems\n * Warning when the recovery PIN is not validated\n * Show default and booted snapshots with marks\n * Improve detection of snapshot systems\n * Fix when searching for a boot entry\n * Fix boot order and boot order entry\n * Create the entries directory in the ESP\n * Fix get_final_pcr parser\n * Keep btrfs error and show it when fails\n * Fix set -e early exit instances\n * Fix measure-pcr-validator when there is no terminal\n * Don't include measure-pcr-validator in initrd if TPM2 is not used\n * Update predictions even if crypttab did not change\n * Improve PCR 15 signing\n * Detect NAME=VALUE passed as parameters and complain\n * When asking a password, require a terminal\n * Filter some warnings from pcrlock\n * Detect directories that are not part of the snapshot\n * Write bash completion errors to /dev/null\n * Detect when t-u apply is done and avoid data corruption\n * Detect pcr-oracle leftovers\n * Show in title that it's the initial version for transactional systems\n * Manually generate PCR7 measurements\n * Regenerate pcrlock.json when it is missing\n- Update to version 1+git20260813.357956d:\n * Do not update the predictions without a TPM2 enrollment (bsc#1273384)\n- Update to version 1+git20260812.305d9f2:\n * Do not supplement if GRUB2-EFI is installed (bsc#1272525)\n- Update to version 1+git20260714.d9bb736:\n * tukit: do not fail if service is not found\n- Update to version 1+git20260713.d869cf8:\n * Ignore errors in the snapper plugin\n- Update to version 1+git20260709.7dfd021:\n * Remove the background process in the plugin\n * Fix missing initrd condition (bsc#1270420)\n * After reboot the shutdown service is not active\n * Disable the shutdown service after main service\n * Update uhmac dependencies (rust-openssl)\n bsc#1270192, CVE-2026-41676\n bsc#1270995, CVE-2026-45784\n bsc#1270922, CVE-2026-44662\n bsc#1270863, CVE-2026-41898\n bsc#1270742, CVE-2026-41681\n bsc#1270670, CVE-2026-41678\n bsc#1270616, CVE-2026-41677\n bsc#1270471, CVE-2026-42327\n * Add systemd transient service to update predictions\n * Install extra EFI binaries\n- Update to version 1+git20260625.7fa275e:\n * Remove duplicate code and parametrize timers\n * Check boot entry before kernel installation\n * Re-install an old kernel if initrd cannot be reused\n * Skip installation for already installed kernel\n * Add configurable devicetree entry support\n * Set explicit kernel and initrd paths\n * Remove the full tmpdir in the service\n * Fix /run/sdbootutil permissions\n * Execute predictions in the background\n * Add --disable-predictions parameter\n * Fix comparison operator\n * Add print-loader-path command\n","modified":"2026-09-25T18:23:14.233701522Z","published":"2026-09-23T09:16:27Z","related":["CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784"],"upstream":["CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270192"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270420"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270471"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270616"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270670"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270742"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270863"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270922"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270995"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272525"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45784"}],"affected":[{"package":{"name":"sdbootutil","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/sdbootutil&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1+git20260908.c641fc2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"sdbootutil-bash-completion":"1+git20260908.c641fc2-160000.1.1","sdbootutil-dracut-measure-pcr":"1+git20260908.c641fc2-160000.1.1","sdbootutil-enroll":"1+git20260908.c641fc2-160000.1.1","sdbootutil-jeos-firstboot-enroll":"1+git20260908.c641fc2-160000.1.1","sdbootutil-kernel-install":"1+git20260908.c641fc2-160000.1.1","sdbootutil-snapper":"1+git20260908.c641fc2-160000.1.1","sdbootutil-tukit":"1+git20260908.c641fc2-160000.1.1","sdbootutil":"1+git20260908.c641fc2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21933-1.json"}}],"schema_version":"1.9.0"}