OPENSUSE-SU-2026:21151-1
Vulnerability Summary
Timeline
Description
Security update for warewulf4 This update for warewulf4 fixes the following issues: Changes in warewulf4: - updated go-jose to fix CVE-2026-34986 (bsc#1262810) - chi is fixed in the upstream project - updating to v4.7.0 with following security fixes * fixed CVE-2026-39821 (bsc#1266483) * fixed CVE-2026-33814 (bsc#1265653) - v4.7.0 with significant changes relative to the v4.6.x series which are: * New wwctl unset command * Refactored server routes (URLs) * New /files/ route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - changes from v4.6.5: * new wwctl overlay info command * fixed wwctl image import --update option * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - remove slurm-overlay package - fix CVE-2025-69725 (bsc#1258511) by updating chi - updated to v4.6.5 with following changes: * new wwctl overlay info command * fixed wwctl image import --update option (bsc#1254470) * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - default to dnsmasq instead of dhcpd and tftp
Affected Systems
- opensuse•warewulf4&distro=openSUSE Leap 16.0
< 4.7.0-bp160.1.1
References (10)
- https://bugzilla.suse.com/1254470
- https://bugzilla.suse.com/1258511
- https://bugzilla.suse.com/1262810
- https://bugzilla.suse.com/1265653
- https://bugzilla.suse.com/1266483
- https://www.suse.com/security/cve/CVE-2025-58058
- https://www.suse.com/security/cve/CVE-2025-69725
- https://www.suse.com/security/cve/CVE-2026-33814
- https://www.suse.com/security/cve/CVE-2026-34986
- https://www.suse.com/security/cve/CVE-2026-39821