SUSE-SU-2026:1008-1
Vulnerability Summary
Timeline
Description
Security update for Prometheus This update for Prometheus fixes the following issues: golang-github-prometheus-alertmanager, golang-github-prometheus-node_exporter: - Internal changes to fix build issues with no impact for customers golang-github-prometheus-prometheus: - Security issues fixed: * CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * CVE-2026-25547: Fixed unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841) * CVE-2026-1615, CVE-2025-61140 The old web UI is no longer built due to security issues (bsc#1257897, bsc#1257442) * CVE-2025-13465: Bump lodash package to version 4.17.23 to fix prototype pollution vulnerability (bsc#1257329) * CVE-2025-12816: Interpretation conflict vulnerability allowing bypassing cryptographic verifications (bsc#1255588) - Version update from 2.53.4 to 3.5.0 with the following highlighted changes (jsc#PED-13824): * Modernized Interface: Introduced a brand-new UI * Enhanced Cloud and Auth: Added unified AWS service discovery (EC2, ECS, Lightsail) and Azure Workload Identity support for more secure, native cloudauthentication. * Performance Standards: Fully integrated OpenTelemetry (OTLP) ingestion and moved Native Histograms from experimental to a stable feature. * Advanced Data Export: Rolled out Remote Write 2.0, offering better performance and metadata handling when sending data to external systems. * Query Power: Added new PromQL functions (like first_over_time and last_over_time) and optimization for grouping operations. * Better Visibility: The UI now displays detailed relabeling steps, scrape intervals, and timeouts, making it easier to troubleshoot why targets aren't reporting correctly. * Critical Fixes: Resolved significant memory leaks related to query logging and fixed bugs where targets were accidentally being scraped multiple times.
Affected Systems
- opensuse•golang-github-prometheus-alertmanager&distro=openSUSE Leap 15.6
< 0.28.1-150100.4.31.1
- opensuse•golang-github-prometheus-node_exporter&distro=openSUSE Leap 15.6
< 1.9.1-150100.3.38.1
- opensuse•golang-github-prometheus-prometheus&distro=openSUSE Leap 15.6
< 3.5.0-150100.4.29.1
- suse•golang-github-prometheus-alertmanager&distro=SUSE Linux Enterprise Module for Package Hub 15 SP7
< 0.28.1-150100.4.31.1
- suse•golang-github-prometheus-alertmanager&distro=SUSE Manager Client Tools 15
< 0.28.1-150100.4.31.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Server 15 SP4-LTSS
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Server 15 SP5-LTSS
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Server 15 SP6-LTSS
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP5
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP6
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-node_exporter&distro=SUSE Manager Client Tools for SLE Micro 5
< 1.9.1-150100.3.38.1
- suse•golang-github-prometheus-prometheus&distro=SUSE Linux Enterprise Module for Package Hub 15 SP7
< 3.5.0-150100.4.29.1
References (11)
- https://www.suse.com/support/update/announcement/2026/suse-su-20261008-1/
- https://bugzilla.suse.com/1255588
- https://bugzilla.suse.com/1257329
- https://bugzilla.suse.com/1257442
- https://bugzilla.suse.com/1257841
- https://bugzilla.suse.com/1257897
- https://www.suse.com/security/cve/CVE-2025-12816
- https://www.suse.com/security/cve/CVE-2025-13465
- https://www.suse.com/security/cve/CVE-2025-61140
- https://www.suse.com/security/cve/CVE-2026-1615
- https://www.suse.com/security/cve/CVE-2026-25547