{"id":"SUSE-SU-2026:3840-1","summary":"Security update for wicked","details":"This update for wicked fixes the following issues:\n\nUpdate to version 0.6.79.\n\n- CVE-2026-44932: indirect remote shell command injection due to insufficient sanitization of DHCP options written to\n  `/run/wicked/leaseinfo.*` files (bsc#1265221).\n- CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum handling of DHCPv4 capture parsing \n  (bsc#1274627).\n- CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended beyond provided allocation in DHCPv4\n  capture parsing (bsc#1274627).\n\nChanges for wicked:\n\n- Version 0.6.79:\n  - Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and\n    written to the `/run/wicked/leaseinfo.*` files, e.g. to pass them to `netconfig`.\n  - Fix `posix-tz-dbname` and `tz-string` option processing checks to permit only valid characters according to\n    RFC4833.\n  - Discard string values containing single-quotes in other options.\n  - Trigger to regenerate `initrd` that may contain wicked binaries on updates from wicked versions \u003c= 0.6.78.\n- Version 0.6.78:\n  - `man`: small fixes in wireless manpage (gh#opensuse/wicked#1053)\n  - `rtnetlink`: fix `RTM_NEWLINK` name resolution in debug (gh#opensuse/wicked#1052)\n  - Add support for IPVLAN/IPVTAP (jsc#PED-1942, gh#opensuse/wicked#1050, gh#opensuse/wicked#1051)\n  - `fsm`: remove children reference array from worker (gh#opensuse/wicked#1049)\n  - `ifxml`: migrate and generate lower configs/policies (gh#opensuse/wicked#1048)\n  - `fsm`: use refcount and array macros in worker and policy (gh#opensuse/wicked#1047)\n  - `route`: use refcounted array and fix error leaks (gh#opensuse/wicked#1046)\n  - `utils`: add support for refcounted objects in generic array (gh#openSUSE/wicked#1045)\n","modified":"2026-09-04T18:23:16.602654434Z","published":"2026-08-27T12:21:23Z","related":["CVE-2026-44932","CVE-2026-71401","CVE-2026-71402"],"upstream":["CVE-2026-44932","CVE-2026-71401","CVE-2026-71402"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263840-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265221"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274627"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44932"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-71401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-71402"}],"affected":[{"package":{"name":"wicked","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/wicked&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.79-150600.11.20.1"}]}],"ecosystem_specific":{"binaries":[{"wicked":"0.6.79-150600.11.20.1","wicked-nbft":"0.6.79-150600.11.20.1","wicked-service":"0.6.79-150600.11.20.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3840-1.json"}},{"package":{"name":"wicked","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/wicked&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.79-150600.11.20.1"}]}],"ecosystem_specific":{"binaries":[{"wicked-service":"0.6.79-150600.11.20.1","wicked":"0.6.79-150600.11.20.1","wicked-nbft":"0.6.79-150600.11.20.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3840-1.json"}}],"schema_version":"1.9.0"}