OPENSUSE-SU-2026:21151-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 23 Jun 2026, 09:37
Last modified:30 Jun 2026, 18:24

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jun 2026, 09:37
Published
Vulnerability first disclosed
30 Jun 2026, 18:24
Last Modified
Vulnerability information updated

Description

Security update for warewulf4 This update for warewulf4 fixes the following issues: Changes in warewulf4: - updated go-jose to fix CVE-2026-34986 (bsc#1262810) - chi is fixed in the upstream project - updating to v4.7.0 with following security fixes * fixed CVE-2026-39821 (bsc#1266483) * fixed CVE-2026-33814 (bsc#1265653) - v4.7.0 with significant changes relative to the v4.6.x series which are: * New wwctl unset command * Refactored server routes (URLs) * New /files/ route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - changes from v4.6.5: * new wwctl overlay info command * fixed wwctl image import --update option * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - remove slurm-overlay package - fix CVE-2025-69725 (bsc#1258511) by updating chi - updated to v4.6.5 with following changes: * new wwctl overlay info command * fixed wwctl image import --update option (bsc#1254470) * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - default to dnsmasq instead of dhcpd and tftp

Affected Systems

  • opensusewarewulf4&distro=openSUSE Leap 16.0

    < 4.7.0-bp160.1.1

References (10)