{"id":"openSUSE-SU-2026:21918-1","summary":"Security update for warewulf4","details":"This update for warewulf4 fixes the following issues:\n\nChanges in warewulf4:\n\n- updating to v4.7.1 with the following changes\n  * wwctl power no longer falls back to the local BMC for nodes with no\n    ipmi: ipaddr:, which could power off the Warewulf server itself\n  * wwclient is built with GOAMD64=v1 and no longer fails with an illegal\n    instruction on older nodes\n  * prevent image and overlay corruption from 64-bit inode numbers\n    truncating in cpio\n  * fix kernel version detection for releases with a version-like suffix\n    after the dist tag\n  * several fixes for IPv6-only servers and nodes: dracut boot,\n    wwctl node status, dnsmasq, NetworkManager\n  * remove dsa from the default ssh: key types, which could leave nodes\n    with no usable host keys on EL9\n  * mount non-root filesystems before image extraction during\n    provision-to-disk\n  * overlay template fixes for parent directories and symbolic links\n- dependency updates, including go-jose 4.1.4 for CVE-2026-34986 (bsc#1262805)\n- updated go-chi to v5.3.2 to fix CVE-2026-72815, CVE-2026-72816 and\n  CVE-2026-72817 (IP spoofing: authentication bypass, authorization\n  override, and log forgery) (bsc#1276100)\n","modified":"2026-09-25T18:23:53.536445368Z","published":"2026-09-18T10:51:38Z","related":["CVE-2026-34986","CVE-2026-72815","CVE-2026-72816","CVE-2026-72817"],"upstream":["CVE-2026-34986","CVE-2026-72815","CVE-2026-72816","CVE-2026-72817"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262805"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276100"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-72817"}],"affected":[{"package":{"name":"warewulf4","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/warewulf4&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.7.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"warewulf4-dracut":"4.7.1-bp160.1.1","warewulf4-man":"4.7.1-bp160.1.1","warewulf4-overlay":"4.7.1-bp160.1.1","warewulf4-overlay-rke2":"4.7.1-bp160.1.1","warewulf4-reference-doc":"4.7.1-bp160.1.1","warewulf4":"4.7.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21918-1.json"}}],"schema_version":"1.9.0"}