{"id":"SUSE-SU-2026:1361-1","summary":"Security update for himmelblau","details":"This update for himmelblau fixes the following issues:\n\nUpdate to version 2.3.9+git0.a9fd29b; (jsc#PED-14511):\n\n- CVE-2026-34397: Fix LPE due to name collision during NSS fake-primary group lookup (bsc#1261324).\n- CVE-2026-31979: Fix race condition when accessiung /tmp/krb5cc_uid (bsc#1259548).\n- CVE-2026-25727: deps(rust): Bump the `all-cargo-updates` group with 8 updates (bsc#1257904).\n- CVE-2025-58160: deps(rust): Bump `tracing-subscriber` in the cargo group (bsc#1249013).\n- CVE-2025-54882: Fix Kerberos credential cache permissions (bsc#1247735).\n- CVE-2025-53013: Fix permitted authentication with invalid Hello PIN (bsc#1245437).\n- CVE-2024-11738: Fix `rustls` network-reachable panic in `Acceptor::accept` (bsc#1233949).\n\nOther bug fixes:\n\n- Fix SELinux module packaging to use standard policy macros (bsc#1258236).\n","modified":"2026-04-16T08:31:18.653814Z","published":"2026-04-15T14:14:00Z","related":["CVE-2024-11738","CVE-2025-53013","CVE-2025-54882","CVE-2025-58160","CVE-2026-25727","CVE-2026-31979","CVE-2026-34397"],"upstream":["CVE-2024-11738","CVE-2025-53013","CVE-2025-54882","CVE-2025-58160","CVE-2026-25727","CVE-2026-31979","CVE-2026-34397"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261361-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245437"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247735"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249013"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257904"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258236"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259548"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261324"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-11738"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-53013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-54882"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58160"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31979"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34397"}],"affected":[{"package":{"name":"himmelblau","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/himmelblau&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.9+git0.a9fd29b-150700.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"himmelblau":"2.3.9+git0.a9fd29b-150700.3.15.1","libnss_himmelblau2":"2.3.9+git0.a9fd29b-150700.3.15.1","pam-himmelblau":"2.3.9+git0.a9fd29b-150700.3.15.1","himmelblau-sshd-config":"2.3.9+git0.a9fd29b-150700.3.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1361-1.json"}}],"schema_version":"1.7.5"}