{"id":"SUSE-SU-2026:23233-1","summary":"Security update for himmelblau","details":"This update for himmelblau fixes the following issues:\n\nUpdate to version 2.3.14+git0.e23b4c54.\n\nSecurity issues fixed:\n\n- CVE-2026-45784: incorrect sizing of output buffers in `CipherCtxRef::cipher_update_inplace` when used with\n  AES key-wrap-with-padding ciphers can lead to attacker-controlled heap corruption (bsc#1270985).\n- Arbitrary HTTP or HTTPS URLs classified as Office documents based on an attacker-controlled file query parameters are\n  forwarded to Electron applications and allow for code execution through Electron (bsc#1273910).\n- Directory-provided RFC2307 user identifiers accepted without exclusion of systemd's dynamic-user range allows for\n  daemon impersonation and command execution through the task helper (bsc#1273911).\n- Daemon acts on Hello PIN enrollment requests whose identity claims it never cryptographically verifies and allows for\n  local authentication bypass (bsc#1273912).\n\nOther updates and bugfixes:\n\n- Version 2.3.14+git0.e23b4c54:\n  * fix(`nss`): avoid locked shadow entries\n  * fix(`deps`): update libhimmelblau lockfile\n  * fix(`pam`): make account denials terminal\n  * `debian`: make the `pam_allow_groups` denial terminal in the account phase\n- Version 2.3.13:\n  * Update `cargo vet` audits for backport\n  * Fix `cargo-fuzz` install in fuzz CI\n  * `cargo vet`\n  * Update `ldap3_proto` to 0.7.1\n  * Update `openssl`\n- Version 2.3.12:\n  * Remove invalid `himmelblau.conf` example info\n  * Fix SSHd configuration load order on Fedora/RHEL systems\n  * `himmelblau-init-hsm-pin`: don't bind the `hsm-pin` to PCR7\n  * `qr-greeter`: support GNOME Shell 50\n  * Update `libhimmelblau` to latest version\n  * deps(`rust`): bump `tonic` in the `all-cargo-updates` group across 1 directory\n  * `cargo audit`\n","modified":"2026-08-27T18:23:33.405275968Z","published":"2026-08-12T08:11:08Z","related":["CVE-2026-45784"],"upstream":["CVE-2026-45784"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623233-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270985"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273910"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273911"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273912"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45784"}],"affected":[{"package":{"name":"himmelblau","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/himmelblau&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.14+git0.e23b4c54-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"himmelblau-sshd-config":"2.3.14+git0.e23b4c54-160000.1.1","himmelblau-sso":"2.3.14+git0.e23b4c54-160000.1.1","libnss_himmelblau2":"2.3.14+git0.e23b4c54-160000.1.1","pam-himmelblau":"2.3.14+git0.e23b4c54-160000.1.1","himmelblau":"2.3.14+git0.e23b4c54-160000.1.1","himmelblau-qr-greeter":"2.3.14+git0.e23b4c54-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23233-1.json"}},{"package":{"name":"himmelblau","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/himmelblau&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.14+git0.e23b4c54-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"pam-himmelblau":"2.3.14+git0.e23b4c54-160000.1.1","himmelblau":"2.3.14+git0.e23b4c54-160000.1.1","himmelblau-qr-greeter":"2.3.14+git0.e23b4c54-160000.1.1","himmelblau-sshd-config":"2.3.14+git0.e23b4c54-160000.1.1","himmelblau-sso":"2.3.14+git0.e23b4c54-160000.1.1","libnss_himmelblau2":"2.3.14+git0.e23b4c54-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23233-1.json"}}],"schema_version":"1.9.0"}