{"id":"openSUSE-FU-2026:20453-1","summary":"Feature update for himmelblau","details":"This update for himmelblau fixes the following issues:\n\nUpdate to himmelblau 2.3.8 (jsc#PED-14511):\n\nSecurity issues:\n\n- CVE-2025-54882: world readable cloud TGT token (bsc#1247735).\n- CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249013).\n- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion\n  (bsc#1257904).\n- CVE-2026-31979: race condition when accessiung /tmp/krb5cc_\u003cuid\u003e (bsc#1259548).\n\nNon security issues:\n\n- Fix SELinux module packaging to use standard policy macros (bsc#1258236).\n\nChangelog:\n\nVersion 2.3.8:\n\n * Add PrivateTmp back to Tasks Daemon\n * Drop dead code\n * Drop krb5 ccache dir code\n * Add a TODO comment\n * Drop non working packaged krb5 snippet file\n * Write kerberos config snippet\n * Extend resolver interface to return kerberos config together with TGTs\n * Backport SELinux fixes from main\n * Use libkrimes to store TGTs\n\nVersion 2.3.7:\n\n * cargo vet\n * Fix AWS-LC has PKCS7_verify Certificate Chain Validation Bypass\n * Revert dependency change which broke the nightly build\n * gen_dockerfiles: only himmelblaud has tpm feature, fix all others\n * fix(build): gen_dockerfiles.py mutates shared features list mid-loop\n\nVersion 2.3.5:\n\n * Better handle Intune API version\n * Update make vet from main branch\n * pam_himmelblau: call split_username once in chauthtok\n * pam_himmelblau: return PAM_IGNORE in chauthtok for local users\n * Don't attempt a DAG when Hello fails with SSPR demand\n\nVersion 2.3.4:\n\n * deps(rust): bump the all-cargo-updates group across 1 directory with 8 updates\n * Revert sketching update (which breaks SLE16 build)\n\nVersion 2.3.3:\n\n * /var/cache/private/himmelblaud should not be created tmpfiles\n * Updatee python vers for dataclasses dep\n * deps(rust): bump the all-cargo-updates group across 1 directory with 3 updates\n * Generate pin init service file systemd \u003c 250\n * Checkin missing himmelblaud.if file for SELinux\n * Resolve typos in selinux package commands\n\nVersion 2.3.2:\n\n * Compile SELinux policy at install time for cross-distro compatibility\n * Improve PAM configuration on openSUSE/SLE\n * Fix SELinux policy\n * Add a git hook to ensure selinux policy is tested\n * Ignore generated himmelblau-hsm-pin-init service file\n * Refactor SELinux policy for cross-distro compatibility\n * Fix NSS lookup for mapped local users\n * Skip OS version compliance checks when min/max values are empty\n\nVersion 2.3.1:\n\n * Remove references to qrcodegen (these are 3.x features)\n * QR Greeter compatibility for old GNOME\n * Enable QR greeter automatically\n * ci: Use latest cargo-vet from git to fix CI\n * Fix HSM pin migration failure on Debian/Ubuntu upgrades from v1.4.x\n\nVersion 2.3.0:\n\n * Autostart the daemons on fresh install or upgrade\n * Restart sshd when installing the ssh config\n * Allow tasks daemon to write krb ccache\n * Do not enumerate mapped users in NSS\n * Update libhimmelblau to latest version\n * Fix Tumbleweed build\n\nVersion 2.2.0:\n\n * Update libhimmelblau to 0.8.x series\n * deps(rust): bump the all-cargo-updates group with 17 updates\n * Only use OpenSSH bug workaround for ssh service\n * Fix debug noise from removing user from sudo group\n * systemd: install files to /usr/lib/, not /etc/\n\nVersion 2.1.0:\n\n * Fix nightly authselect build failure\n * Generate the authselect profiles for each distro\n * Improve pam config handling in aad-tool\n * Make `aad-tool configure-pam` detect location of pam files\n\nVersion 2.0.5:\n\n * /var/lib/private/himmelblaud should be owned by root\n * Use tmpfiles.d to create himmelblaud private data directory\n * deps(rust): bump the all-cargo-updates group with 13 updates\n\nVersion 2.0.4:\n\n * Update kanidm_build_profiles mask version\n * Utilize cargo vet from main\n * Add policies cache patch via systemd-tmpfiles\n\n * Fix man page comments about change idmap_range\n * Stub picky-krb for osc build\n * Stub a kanidm_build_profiles which builds in osc\n * Ensure nss cache is created on Ubuntu/Debian\n * Request a user token if NSS hasn't been called\n\nVersion 2.0.3:\n\n * Add nss cache patch via systemd-tmpfiles\n\nVersion 2.0.2:\n\n * Recommend `patch` with the pam package\n * Fix passwordless FIDO authentication not being used when available\n * Git workflow updates for stable-2.x\n * Only warn on Intune failure\n\nVersion 2.0.1:\n\n * Force o365 desktop files to always rebuild\n * Always rebuild the o365 apps\n * Add restart on-failure to systemd services\n * Clarify `domain` SHOULD match login domain\n * Remove warning about `domain` himmelblau.conf opt\n * Pseudo eliminate multi-tenant and domains section\n * Revert \"Fix Hello PIN lookup when an alias domain\"\n * Comment out `KbdInteractiveAuthentication on` in sshd conf\n * Check the nxset sooner, to avoid unwanted errors\n * Recommend oddjob_mkhomedir with authselect\n * Pin libhimmelblau to 0.7.x\n * Deprecate Fedora 41\n * deps(rust): bump the all-cargo-updates group with 11 updates\n * Bump github/codeql-action from 4.30.8 to 4.31.2\n * Bump cachix/install-nix-action from 31.8.1 to 31.8.2\n * Bump actions/upload-artifact from 4.6.2 to 5.0.0\n * cargo clippy and rebase fix\n * fixup! add extra debug output to NotFound error code\n * force error output to show up in CI logs\n * wrap repeated sources of IdpError::NotFound in helper functions\n * add extra debug output to NotFound error code\n * use direnv for loading the nix devshell\n * We should still encourage mapping by name\n * Add support for Fedora 43\n * Provide a offline 'breakglass' mode\n * cargo clippy\n * Add warning about incorrect nsswitch configuration\n * Distinguish between online and offline token fail\n * Ensure user token uses original name\n * Fix alias domain in auth result causing failure\n * Resolve cargo clippy warnings\n * Only map on cn name for the primary domain\n * Install systemd in build scripts for gen service\n * Fix systemd version parsing\n * Update libhimmelblau to 0.7.19\n * Resolve SELinux build failures in nightly (part 2)\n * Rocky container image updates were failing\n * Warn instead of error when no idmap_range specified\n * deps(rust): bump the all-cargo-updates group across 1 directory with 7 updates\n * Trim whitespace from local group names\n * Fix borrowing error\n * Fix reference to local_sudo_group in condition\n * Only run sudo_groups if local_groups does not contain local_sudo_group\n * Leave SELinux in permissive mode for Himmelblau\n * Resolve SELinux build failures in nightly\n * nix: add join_type option to nixos-module settings\n * Build host configuration changes\n * Ensure that hsm_pin isn't present decrypted\n * Document Soft HSM changes to TPM bound\n * Disable SELinux by default on NixOS\n * sh doesn't have `source`\n * Encrypt hsm-pin using systemd-creds\n * Recommend uuid id mapping\n * Improve himmelblau.conf man page formatting\n * Implement Local User Mapping\n * Add o365 dependency for jq\n * Add selinux rules for gdm login\n * Narrow the scope of selinux policy with audit2allow\n * Generate the systemd service files\n * Fix selinux build for SLE16\n * Resolve SLE16 build dependency failure\n * Fix the rawhide build\n * Mask the sshkey-attest package\n * Bump cachix/install-nix-action from 31.7.0 to 31.8.1\n * cargo vet dependency updates\n * deps(rust): bump the all-cargo-updates group across 1 directory with 13 updates\n * Bump actions/dependency-review-action from 4.8.0 to 4.8.1\n * Bump cachix/install-nix-action from 31.7.0 to 31.8.0\n * Bump github/codeql-action from 3.30.5 to 4.30.8\n * Bump ossf/scorecard-action from 2.4.2 to 2.4.3\n * SELinux improvements\n * Fix a typo in package gen scripts\n * cargo fmt\n * Permit NSS response for mapped primary fake group\n * Fix Nix Error With Fuzz\n * Decrease CI fuzzer setup time\n * Document join types\n * Support for Entra registered devices\n * Run `cargo test` in a container\n * Bump cachix/install-nix-action from 31.6.2 to 31.7.0\n * deps(rust): bump the all-cargo-updates group across 1 directory with 2 updates\n * Bump github/codeql-action from 3.30.4 to 3.30.5\n * Use pastey crate instead of unmaintained paste\n * Pin unmaintained serde_cbor dep to serde_cbor_2\n * Resolve tower-http `cargo audit` warning\n * Replace unmaintained fxhash with own version\n * Resolve warning about workflow top level write permissions\n * Remove dependabot automerge\n * Resolve division by 0 in idmap code\n * [StepSecurity] ci: Harden GitHub Actions\n * Only idmap against initialized domains\n * Resolve invalid init of idmap with same domain\n * Add fuzzing of idmap code\n * Add basic fuzzing of the config options\n * Resolve error found by fuzzing\n * cargo vet prune\n * deps(rust): bump regex in the all-cargo-updates group\n * Bump actions/dependency-review-action from 4.7.3 to 4.8.0\n * Bump actions/checkout from 3.6.0 to 5.0.0\n * Bump cachix/cachix-action from 14 to 16\n * Bump ossf/scorecard-action from 2.4.0 to 2.4.2\n * Bump cachix/install-nix-action from 25 to 31\n * Add the OpenSSF Best Practices badge\n * Add scorecard badge\n * [StepSecurity] Apply security best practices\n * Fix group static mapping\n * Move aad-tool idmap cache clear to the idmap cmd\n * Resolve errant \"Hello key missing.\" messages\n * Update flake.nix\n * Slow the dependabot update frequency\n * Audit dependabot updates\n * deps(rust): bump the all-cargo-updates group across 1 directory with 11 updates\n * feat: Add support for aarch64 on Debian-based distributions\n * Resolve possible invalid pointer dereferences\n * Avoid revealing account ids in debug log\n * Cause doc links to open in the correct apps\n * Permit opening multiple instances of Word/Excel\n * Modify systray and app close behavior\n * Don't use questionably licensed icons for o365\n * Resolve NixOS CI failure\n * Fix building w/out deprecated interactive feature\n * Update himmelblau.conf.5 sudo_groups example\n * Entra group based sudo access\n * Audited the cargo updates\n * deps(rust): bump the all-cargo-updates group with 6 updates\n * Vet libhimmelblau\n * Add `make vet` command\n * Update deny.toml\n * Remove incompatible licenses from deps\n * Fix RHEL8 package signing\n * Add SBOM generation\n * Add an IRP checklist for security incidents\n * Run the nixos build/release on the correct version\n * Add crate dependency auditing on MR\n * Add some exceptions\n * Initialize cargo vet\n * Remove in-tree kanidm dependencies\n * Fix Hello PIN lookup when an alias domain\n * Raise maximum group lookup from 100 to 999\n * Always work with lowercase account names\n * Modify FUNDING.yml for funding sources\n * Remove glib dependency\n * deps(rust): bump the all-cargo-updates group with 10 updates\n * Add CI check for licenses\n * Update dependabot.yml to target all stable branches\n * Add authselect module for Rocky/Fedora\n * Recommend packages, instead of require\n * Add a Contributing document\n * Add a Code of Conduct\n * add withSelinux flag to nix build, brings SELinux binaries into the build environment.\n * deps(rust): bump tracing-subscriber in the cargo group\n * Don't overwrite the himmelblau.conf on rpm upgrade\n * Add help output to the Makefile\n * Fix building packages with docker in root mode\n * Update to latest libhimmelblau and identity_dbus_broker\n * Make PRT SSO cookie via broker work as well for Edge\n * Make broker work for Edge\n * Generate Office 365 desktop apps\n * Update README\n * Add `make uninstall` command\n * Remove the deprecated tests suite\n * Himmelblau no longer has git submodules\n * Make install using packages\n * Add Debian 13 packages\n * Generate Dockerfiles automatically\n * Add SELinux configuration\n * Himmelblau daemon requires system tss user\n * Add cron dependency for Intune scripts\n * Do not mangle /usr/etc configuration files\n * deps(rust): bump the all-cargo-updates group with 7 updates\n * Add SLE16 (beta) build target\n * Automatically append to nsswitch.conf in postinst\n * Correct the RPM postinst script syntax\n * Fix Kerberos credential cache permissions\n * Set file owner and group before writing its content\n * Create SECURITY.md\n * Rev the dev version to 2.0.0\n * Ensure alias domains match when checking Intune device id\n * Debian 12 doesn't support ConditionPathExists and notify-reload\n * Write scripts policy to a readable directory\n * Apply Intune policies right after enrollment\n * Add more debug instrumentation\n * Provide device_id to Intune enrollment if not cached\n * Ensure nss cache directory is created during install\n * Remove /var/cache/himmelblaud access from tasks daemon\n * Resolve daemon startup absolute path warnings\n * Delay Intune enrollment on Device Auth fail\n * Do not leak the Intune IW service token in the logs\n\nVersion 1.4.2:\n\n * Revert libhimmelblau unstable update\n\nVersion 1.4.1:\n\n * Update Intune to use app version 1.2511.7\n\nVersion 1.4.0:\n\n * Resolve build failures\n * deps(rust): bump the all-cargo-updates group across 1 directory with 6 updates\n\nVersion 1.3.0:\n\n * Revert the self-hosted runner name\n * deps(rust): bump the all-cargo-updates group with 23 updates\n * Include latest branch in CI\n * Self hosted runners\n\nVersion 1.1.0:\n\n * Fix policy application\n * Add remaining Linux password compliance policies\n * Add custom compliance enforcement\n * deps(rust): bump the all-cargo-updates group with 3 updates\n * deps(rust): bump the all-cargo-updates group with 5 updates\n * Add SLE15SP7 build target\n * Add RHEL 10 build target\n * Fix Intermittent auth issue AADSTSError 16000\n * Remove old utf8proc dependency\n * Add `fedora42` build target\n * Handle PRT expiration and tie to offline auth\n * Correctly delete the Hello keys on bad pin count\n * Add ability to disable Hello PIN per-service\n * Update NixOS support to 25.05\n * Handle disabled device by attempting re-enrollment\n * Always attempt confidential client creds for aad-tool\n * Include HSM option defs in himmelblau.conf man page\n * Improve the aad-tool cache-clear command\n * Add `mfaSshWorkaroundFlag` configuration option to Nix Flake.\n * Add the ability to remove confidential client creds\n * If bad PIN count is exceeded, delete the Hello key\n * deps(rust): bump the all-cargo-updates group with 4 updates\n * Add instructions for creating developer builds\n * Fix GDM3 first time login password prompt\n * Default HsmType should be soft\n * Add himmelblaud to tss group for TPM startup\n * Enforce strict order for the systemd units\n * Update libhimmelblau and compact_jwt\n * Fix builds w/tpm\n * aad-tool Authentication flow improvements\n * Filter out irrelevant debug in aad-tool\n * Create a unified login experience for aad-tool\n * Utilize confidential creds for aad-tool enumerate\n * himmelblau should get posix attributes w/out delegate user access\n * Always use the Object Id for mapping Group to GID\n * Update enhancement-request.md for SPI donations\n * Update bug_report.md with SPI donation\n * Update build requires in README.md\n * Update FUNDING.yml with SPI Paypal donation button\n * Don't break from tasks loop when policies fail\n * Enroll in Intune as soon as it is enabled\n * Implement `decoupled hello` behavior\n * Cache encrypted PRT to disk for offline login SSO\n * Update to latest hsm-crypto\n * Enable tpm functionality\n * Allow altering the password and PIN prompt messages\n * Ensure Hello PIN lockout happens when online\n * Cache the build target output to improve build times\n * Easier build selection w/ Makefile\n * Revert mistaken removal from Makefile\n * Make the user wait longer with each incorrect PIN\n * Make the bad PIN count configurable\n * Improve aad-tool manpage\n * aad-tool fails if the user has FIDO2 enabled\n * Offline auth permits authentication with invalid Hello PIN\n * PIN complexity to match Windows\n * Update to latest SSSD idmap code\n * Add aad-tool options for setting posix attrs\n * Add scopes and redirect uris aad-tool application create\n * Add aad-tool commands for managaging extension attrs\n * Utilize the sidtoname call for object id mapping\n * Add commands for listing/creating App registrations\n * Potential fix for code scanning alert no. 2: Workflow does not contain permissions\n * Potential fix for code scanning alert no. 4: Workflow does not contain permissions\n * Potential fix for code scanning alert: Workflow does not contain permissions\n * Never write the app_id to the server config\n * Disable passwordless Fido by default\n * Stop using deprecated `users` crate\n * When group membership lookup fails, use cached groups\n * aad-tool command for enumerating users and groups\n * Name-Based Group Matching in `pam_allow_groups` Leads to Potential Security Bypass\n * Add the configure-pam option to aad-tool man page\n * Add static idmap cache for on-prem to cloud migration\n * Update bug_report.md with request for himmelblau.conf\n * deps(rust): bump the all-cargo-updates group with 2 updates\n * Update crates in a group\n * Update crate bumps\n * Utilize new Intune compliance enforcement via libhimmelblau\n * Correct the README regarding Intune policy compliance\n * Disable Chromium policy\n * Re-enable Intune policy and add scripts and compliance policies\n * himmelblau.conf alias `domain` as `domains`\n * Support Fido auth in pam passwd\n * Add TAP support to himmelblaud and pam passwd\n * Mixed case names should properly identify Hello Key\n * Update linux-entra-sso to latest version\n * Fix group lookup for Entra Id group name\n * Fix mixed case name lookup from PRT cache\n * Crate updates\n * Fix tasks daemon debug output\n * Remove write locks where unecessary\n * Fix deadlock in nss\n * systemd notify fixes\n * Console\n * Address Feedback\n * Order services before gdb/nss-user-target\n * deps(rust): bump rpassword from 7.3.1 to 7.4.0\n * deps(rust): bump tokio from 1.44.2 to 1.45.0\n * deps(rust): bump sha2 from 0.10.8 to 0.10.9\n * deps(rust): bump systemd-journal-logger from 2.2.0 to 2.2.2\n * deps(rust): bump clap from 4.5.31 to 4.5.38\n * Update notify-debouncer-full\n * Update opentelemetry\n * Update dependencies\n * deps(rust): bump time from 0.3.39 to 0.3.41\n * Replace source filter that blacklists files with filter that whitelists files.\n * Mark himmelblau.conf as config in rpm\n * Update README.md\n * Ensure only the base URL is printed to log\n * If unix_user_get fails, wait, and try again\n * Supplying a PRT cookie to SSO doesn't require network\n * Don't send a password prompt if the network is down\n * Auth via MFA if Hello PIN fails 3 times\n * Improve Hello PIN failed auth error\n * Fix rocky9 build\n * deps(rust): bump anyhow from 1.0.96 to 1.0.98\n * deps(rust): bump libc from 0.2.170 to 0.2.172\n * deps(rust): bump cc from 1.2.16 to 1.2.19\n * deps(rust): bump tokio from 1.43.0 to 1.44.2\n * deps(rust): bump openssl from 0.10.71 to 0.10.72 in the cargo group\n * deps(rust): bump reqwest from 0.12.12 to 0.12.15\n * Update libhimmelblau in Cargo.lock\n * Fix nss and offline checks for domain aliases\n * Report error when MS Authenticator denies authorization\n * Bail out of invalid offline auth\n * Handle AADSTS errors from BeginAuth response\n * Never dump failed reqwests to the log\n * Update sccache-action version to use new cache service\n * Permit daemon to start when network is down\n * Add an nss cache for when daemon is down\n * Additional pam info cues\n * Proceed with Hello auth even with net down\n * Indicate to the user what the password and PIN are\n * Ensure pam messages are seen\n * Display the minimum PIN length during Hello setup\n * PAM should loop, not die on error\n * Ensure prompt msg remains for confirmation\n * Update bug_report.md\n * Ignore demands for setting up MS Authenticator\n * Login fails if Entra is configured to recommend MS authenticator\n * Add pam configure command to aad-tool\n * Update README.md with pam passwd instructions\n * aad-tool authtest needs to map names\n * Update demo video in README.md\n * Sign RPM packages\n * Ensure the pam module is installed correctly for SLE\n * Improve pam error handling and messaging\n * Only push cachix builds for stable releases\n * Terminate linux-entra-sso when browser terminates\n * On deb, push pam config after install\n * Increase priority of deb PAM passwd for Himmelblau\n * Improve offline state handling\n * Specify request for Entra Id password in PAM\n * QR Greeter also supports gnome-shell 47\n * Fix profile photo loading\n * Clarify pam_allow_groups in himmelblau.conf man page\n * Don't hide debug for pam_allow_groups miss\n * Handle failures in passwordless auth\n * build all root packages\n * split config options that can be defined per-domain from those which are global only\n * configure cachix signing and upload in ci\n * deps(rust): bump serde_json from 1.0.138 to 1.0.140\n * deps(rust): bump serde from 1.0.218 to 1.0.219\n * deps(rust): bump time from 0.3.37 to 0.3.39\n * deps(rust): bump bytes from 1.10.0 to 1.10.1\n * deps(rust): bump pkg-config from 0.3.31 to 0.3.32\n * Entra Id is case insensitive, cache lookup must match\n * deps(rust): bump ring from 0.17.9 to 0.17.13 in the cargo group\n * Support CompanionAppsNotification mfa method\n * QR code for gnome-shell greeter\n * Allow tasks to start if AccountsService dir missing\n * Remove invalid python dependency from sso package\n * Fixes https://github.com/himmelblau-idm/himmelblau/issues/397\n * Clear server config when clearing cache\n * Update version in the Cargo.lock\n * deps(rust): bump async-trait from 0.1.86 to 0.1.87\n * deps(rust): bump chrono from 0.4.39 to 0.4.40\n * Fix himmelblau.conf man page cn_name_mapping entry\n * deps(rust): bump pem from 3.0.4 to 3.0.5\n * deps(rust): bump serde from 1.0.217 to 1.0.218\n\nVersion 1.0.0:\n\n * deps(rust): bump cc from 1.2.15 to 1.2.16\n * Update workflow versions\n","modified":"2026-04-03T17:24:08.694081Z","published":"2026-04-01T09:26:05Z","related":["CVE-2025-54882","CVE-2025-58160","CVE-2026-25727","CVE-2026-31979"],"upstream":["CVE-2025-54882","CVE-2025-58160","CVE-2026-25727","CVE-2026-31979"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1247735"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249013"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257904"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258236"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259548"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-54882"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-58160"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31979"}],"affected":[{"package":{"name":"himmelblau","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/himmelblau&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.8+git0.dec3693-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"himmelblau-sshd-config":"2.3.8+git0.dec3693-160000.1.1","himmelblau-sso":"2.3.8+git0.dec3693-160000.1.1","himmelblau":"2.3.8+git0.dec3693-160000.1.1","libnss_himmelblau2":"2.3.8+git0.dec3693-160000.1.1","pam-himmelblau":"2.3.8+git0.dec3693-160000.1.1","himmelblau-qr-greeter":"2.3.8+git0.dec3693-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-FU-2026:20453-1.json"}}],"schema_version":"1.7.5"}