{"id":"openSUSE-SU-2026:21982-1","summary":"Security update for sccache","details":"This update for sccache fixes the following issues:\n\n- CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243868).\n- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes\n  (bsc#1274146).\n- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion\n  (bsc#1257923).\n- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1\n  (bsc#1270206).\n- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-\n  openssl crate (bsc#1270559).\n- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270693).\n- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate\n  (bsc#1270736).\n- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent\n  memory in rust-openssl crate (bsc#1270869).\n- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate\n  (bsc#1270512).\n- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate\n  (bsc#1270938).\n- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-\n  openssl crate (bsc#1270948).\n- CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response Header Values (bsc#1273881).\n- CVE-2026-66754: rouille: remove_prefix function that allows remote unauthenticated attackers to crash the server by\n  sending a crafted percent-encoded URL (bsc#1273884).\n- CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding Desynchronization (bsc#1273886).\n- CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access Control Bypass (bsc#1273888).\n- CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282211).\n- CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282211).\n- CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282211).\n- CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282211).\n\nChanges for sccache:\n\nUpdate to version 0.18.0~2:\n * Add experimental concurrent cache support\n * chore: Remove dependency status badge (#2856)\n * Don't hand the jobserver to children that can't use it\n * dist: refuse to trim rlibs from crates that also emit a cdylib\n * fix(cache): avoid duplicate multilevel reads\n * Strip basedirs from the compiler arguments too\n * tests/integration: replace MinIO with Silo\n * ci: dump sccache logs on integration failures\n * multilevel: a chain with any writable level is writable\n * Fix parsing of #line directives\n * Release 0.18.0\n * daemonize: use an allow-list approach to inherited FDs\n * gcc, clang: make the assembler part of the cache key\n * support cl.exe /openmp:llvm\n * support all current /fsanitize*, /fsanitize-coverage*, and /fno-sanitize* args\n * support MSVC /feature argument\n * msvc: support lots of flags (#2832)\n * Update shlex dependency to version 2 (#2836)\n * gcc: mark flags as TooHard if need to cache something else (#2833)\n * clang: support more CLI options (#2834)\n * msvc: support arm64EC and fastfail flags (#2830)\n * chore: fix typo in comment (#2829)\n * nvcc: accept the --diag-error/--diag-suppress/--diag-warn family (#2816)\n * cache: allow skipping capability checks (#2822)\n * Bump opendal to 0.58.1 and fix fallout (fixes local GCS cache usage) (#2715)\n * nvcc (Windows): protect escaped quotes in dryrun lines before flattening backslashes (#2811)\n * Add an agent (#2812)\n * Add support for d20bforceinline. (#2807)\n * feat: add Microsoft Entra ID (passwordless) auth for the Azure Blob backend (#2802)\n * Bump MSRV to 1.91.0 (#2793)\n * Fix `nvcc` dryrun parsing for CUDA 13.3 (#2722)\n * test: Fixed hardcoded binary path in test\n * Release 0.17.0\n * tests: pin libc in the dist test crate\n * doc: clarify server-side outputs and drop 'recommended mode' claim\n * doc: document SCCACHE_CLIENT_SIDE env var\n * doc: document client-side and direct modes in Architecture.md\n * Fix description of Unix socket-based Redis connection\n * server: remove redundant async block in start_compile_task\n * server: simplify bind() request loops with ? instead of manual match arms\n * Add support for arg files in Rust (#2782)\n * feat: support S3 SSE-KMS with AWS-managed and customer-managed keys (#2770)\n * abort compile tasks and associated subprocesses when a client disconnects\n * treat -ivfsoverlay as a preprocessor-only argument\n * gcc: refine response-file tokenizer visibility and whitespace handling\n * integration: convert cmake 4.x modules XFAIL test to a passing test\n * gcc/clang: cache and distribute builds using quoted @response files\n * fix: Fix ToolchainPackager cfg gate to build on ppc64le/s390x\n * fix: make gcc diagnostics color output work the same as for rustc\n * implement client-side mode\n * split handle_compile_response so that the compilation result can be handled separately\n * implement IpcStorage -- Storage backend over IPC\n * extend wire protocol with storage RPCs\n * implement AddAssign for ServerStats and related types\n * add Storage::get_path for direct file access\n * implement get_raw/put_raw on MultiLevelStorage\n * add client_side_mode config flag (SCCACHE_CLIENT_SIDE)\n * Extract new_client_runtime() helper to DRY up client runtime creation\n * Clarify single-threaded runtime rationale comment (grammar)\n * fix: use single-threaded tokio runtime in sccache dist-client\n * fix: use single-threaded tokio runtime in sccache client\n * fix: handle disabled cache backend features in multilevel chain\n * Fix ldd output parsing: remove .exists() check that failed on systems where the symlink source path does not exist locally (e.g. aarch64)\n * Fix cfg guard for PanicToolchainPackager to also cover non-x86_64 Linux architectures (e.g. aarch64)\n * Release 0.16.0\n * fix: strip SCCACHE_BASEDIRS from escaped-backslash paths on Windows (#2736)\n * Ignore empty-set environment values (#2639)\n * feat: all backends support making them as read-only (#2705)\n * Enable RE on Linux-aarch64 (#2668)\n * Slightly improve logging (#2734)\n * chore: encode jwt key and cert digest with base64 in logs (#2712)\n * chore: make clippy happy (#2727)\n * feat: avoid sccache wrapper when resolving compiler (#2720)\n * Fall back to direct cache write if tempfile creation on the same fs fails (#2369)\n * remove too noisy bench\n * feat(nvcc): support argument: `--dependency-output` (#2708)\n * fix: add newline when printing dist-status to stdout\n * Revert \"Classify .s files as AssemblerToPreprocess so #include/#ifdef are hon...\"\n * Don't wait depfiles for gcc/clang preprocessed inputs\n * Classify .s files as AssemblerToPreprocess so #include/#ifdef are honored\n * prepare release 0.15.0\n * Add cargo-binstall metadata for prebuilt binary installation\n * Fix coverage\n * fix: handle directories in dep-info source file hashing\n * docs(Rust.md): Add caveats from README\n * Add retry for dists docker image build\n * ci: set crt-static for riscv64 musl targets\n * feat: Add loongarch64 support\n * feat: Implement multi-tier caching with fallback and backfilling (#2581)\n * msvc: add support for Y-, YI, Zf flags\n * Group tests logging in CI\n * Add failing test for cmake-modules + cmake 4 version\n * Unfold ninja output in the test\n * Add a comment for maintaining integration tests\n * Move cmake-modules to integration tests\n * fix: exclude CARGO_ENCODED_RUSTFLAGS from env var hash (#2651)\n * chore(deps): update rust crate quinn-proto to v0.11.14\n * Fix sync GCS initialization\n * clippy: fix from_iter_instead_of_collect lint\n * fix: add Win32_Security feature to windows-sys dependency\n * build(deps): bump actions/download-artifact from 5 to 8\n * msvc: Append the default .pdb extension for the /Fd argument (#2621)\n * build(deps): bump actions/upload-artifact from 4 to 7\n * clippy: fix ref_option lint\n * ci: install grcov from prebuilt binary instead of cargo install\n * ci: use default toolchain to install grcov\n * ci: fix artifact_failure action when target dir does not exist\n * Remove benchmark normalize_win_path_utf8 (#2634)\n * Revert \"actions: add security audit workflow (#2594)\" (#2603)\n * partial c++20 module support (#2516)\n * clippy: fix ptr_as_ptr lint (#2611)\n * Add support for `d1nodatetime` & `await:strict` MSVC flags (#2617)\n * chore: switch thirtyfour_sync to thirtyfour (#2613)\n * clippy: fix manual_string_new lint (#2609)\n * clippy: fix unnecessary_semicolon lint (#2615)\n * clippy: fix explicit_into_iter_loop lint (#2616)\n * Avoid double-caching when ccache is installed in PATH (#2524)\n * clippy: fix cloned_instead_of_copied lint (#2605)\n * clippy: fix semicolon_if_nothing_returned lint (#2601)\n * Move PreprocessorCacheModeConfig to src/config.rs (#2604)\n * clippy: fix cloned_ref_to_slice_refs lint (#2602)\n * prepare the new release (#2600)\n * chore: update to toml 0.9 (#2599)\n * ci: Add coverage to integration tests, report it to Codecov.io (#2598)\n * Preparation for multilevel caching (#2597)\n * Add sccache-dist to flake.nix (#2579)\n * fixup! cargo fmt\n * fixup! rustfmt update\n * Extract FileObjectSource, CacheRead and CacheWrite to cache_io.rs\n * chore: update to nix 0.30\n * Add a helper method to get a correct backend name\n * Add cos feature gate to RemoteStorage\n * Simplify profiles for integration tests\n * clippy: fix implicit_clone lint (#2584)\n * actions: add security audit workflow (#2594)\n * docs: fix examples showing an xz-compress toolchain archive (#2587)\n * add benches for normalize_win_path strip_basedirs (#2588)\n * snap: update to core24 (#2570)\n * Add .rustfmt.toml for consistent style between `rustfmt` and `cargo fmt` (#2582)\n * add comments about auth token requirements (#2583)\n * chore: update to tokio-serde 0.9 (#2585)\n * ci: update freebsd to 15.0 (#2586)\n * distributed compilation support for asm & preprocessor outputs (#2557)\n * remove unused declaration (#2577)\n * Extract LazyDiskCache to a separated file (#2573)\n * Revert \"ci: show diff for toml_format\" (#2578)\n * Open Add SCCACHE_BASEDIRS support\n * ci: show diff for toml_format\n * chore: update to syslog 7\n * refactor: use matrix to reduce deduplication\n * fix: remove outdated `analysis` mode\n * Unbreak the s390x CI\n * ci: add macos-15-intel for prebuilt binary (#2555)\n * Integration tests (#2564)\n * Fix code review.\n * Impl for COS.\n * build(deps): bump opendal from 0.54.0 to 0.55.0\n * Move integration tests related stuff to subdir\n * Add Objective C Header for consistency\n * github action: fix the syntax - fails in the ci\n * sccache: prepare a new release\n * msvc: add msbuild support test\n * msvc: fix detect_showincludes_prefix with MSBuild\n * chore: update to gzp 2\n * build(deps): bump rsa from 0.9.6 to 0.9.10\n * codspeed: evaluate the memory benchmarking\n * remove too quick benchmarks\n * codspeed: move to simulation mode\n * Add realistic LRU cache access pattern benchmarks\n * Add compression characteristics benchmarks\n * Add build workflow simulation benchmarks\n * Add hash computation scenario benchmarks\n * Add batch cache entry benchmarks\n * Add cache artifact serialization benchmarks\n * Add /etc/ld.so.conf.d (if present) to compiler package\n * Assembly language support\n * fix(ci): pin serde_json to avoid zmij dependency\n * fix(ci): update zmij to fix s390x cross-compilation\n * Fix the run of the CI\n * run the benchmark in the ci\n * add benchmarks\n * dedup some code\n * Fix hash logging prefix\n * Add support for C preprocessor output\n * Add GCC pipe flag support\n * Improve save-temps gcc flags detection\n * MSVC: support forward slash as an output dir marker\n * add clang -fplugin=x regression test\n * canbeconcatenated is not accounted for in cmp\n * Reversed the order for looking `rustc`, added comment\n * Fix failing test_rlib_dep_reader_call for omit CARGO_HOME\n * fix: don't hash -parallel-jobs in Clang\n * docs: add installation steps for nix (#2523)\n * Support clang -fexperimental-assignment-tracking option (#2517)\n * add a nix flake (#2518)\n * Switch from the unmaintained daemonize crate to a maintained fork\n * chore: update to fs-err 3\n * Fix grammar of error message\n * Add server name info to stderr of remote jobs that ran, but failed\n * Remove another pointless destructuring\n * try to unbreak the ci\n * fix s390x build error\n * Add riscv64 support\n * fix: make aarch64-pc-windows-msvc also zip not tar.gz\n * Free up disk space in CI\n * MSVC on Windows only\n * Avoid 'No space left on device' errors in CI\n * GitHub dropped macos-13 runners\n * Proper function pointer to int cast\n * Avoid unused structs with dist-server disabled\n * no check cfg (#2507)\n * chore: switch once_cell crate to standard library (#2499)\n * Avoid unreliable assert_cmd::cargo::cargo_bin (#2489)\n * Fix build on macOS which doesn't have separate 32-bit dirent (#2492)\n * Fix Clippy warnings (#2490)\n * docs: bump MSRV to 1.85.0\n * msvc: handle '/FoRelease\\' command-line argument\n * chore: drop tower dependency\n * chore: update to itertools 0.14\n * Use generator in CMAKE_MSVC_DEBUG_INFORMATION_FORMAT in README\n * Update directories to 6.0\n * Configuration.md - note logging env variables\n * chore: update to env_logger 0.11\n * deps: update blake3\n * prepare version 0.12.0\n * Update README with winget installation instructions\n * Skip CARGO_BUILD_JOBS in hash keys\n * build(deps): bump object from 0.36.7 to 0.37.1\n * Adjust tests after the rust update\n * Fix CI by adding cargo-features and updating coverage test to use modern -Cinstrument-coverage\n * Fix more clippy warnings\n * bump rustc in the ci too\n * Fix rustc 1.85 clippy warnings\n * bump to rustc 1.85 / edition 2024. mandatory for reqsign-core and run rustfmt with the version\n * fix clippy warnings\n * bump opendal to 0.54.0 & reqsign to 0.18.0\n * github action: when creating a release, make it as draft before (#2458)\n * prepare version 0.11.0 (#2457)\n * document SCCACHE_LOG_MILLIS (#2456)\n * logging: add a option to log milliseconds (Closes: #2454) (#2455)\n * feat: handle human size prefixes (#2405)\n * fix: in stats, Compare values AND keys to have a fully deterministic order (#2403)\n * Add --diagnostic-width to test for args ignored in hash\n * Ignore --diagnostic-width argument when computing hash\n * build(deps): bump actions/checkout from 4 to 5\n * build(deps): bump actions/download-artifact from 4 to 5\n * build(deps): bump actions/github-script from 7 to 8\n * Fix rustfmt\n * Fix comments on request\n * Fix clippy and rustfmt\n * Add test for count toolchain and use Determenistic for create tar archive\n * Fix mtime for reproducable toolchains\n * build(deps): bump chrono from 0.4.41 to 0.4.42\n * fix typo in an environment variable name\n * Fix documentation of azure configuration\n * Account for clippy-driver having extra prefix `rustc`\n * Fix build on Android (in Termux)\n * add support for s390x build\n * chore: replace retry crate with backon\n * Remove or replace \"Windows 2019\" CI config\n * Needs another result unwrapping, it seems\n * Test: invoking symlink \"compiler\" to \"sccache\" invokes \"compiler\"\n * Add a comment about the problem with symlinks and current_exe()\n * Fix symbolic links to sccache on linux\n * Allow the CI configuration to disable clang++ for CUDA testing\n * Don't run tests using clang++ as CUDA compiler on Windows\n * add description to sccache-dist commands\n * Display a more user-friendly error when compiling on Linux/arm64\n * Clarify documentation about \"the hash\" (aka cache key)\n * Remove stray ')'\n * Remove documentation for removed limitations of preprocessor cache mode\n * Fix preprocessor cache mode when the compiler outputs a dep file\n * Partially revert \"Don't cache dep file (#2322)\"\n * Do not disable preprocessor cache mode if there is a dep file\n * Fix preprocessor cache mode with distributed builds (#2173)\n * Change self of generate_hash_key() from Box\u003cSelf\u003e to &mut Self\n * Remove a few IMO pointless indirections / aliases\n * Remove workaround for #2173\n * Add test for bug #2173\n * chore: fix some minor issues in comments\n * build(deps): bump chrono from 0.4.40 to 0.4.41\n * build(deps): bump memchr from 2.7.1 to 2.7.5\n * check if we can use a specific version of rust to build grcov\n * Move comment that hadn't moved with its corresponding code\n * Rework direct mode documentation some more\n * Explain what preprocessor cache mode really does\n * Reword and correct the preprocessor cache mode documentation\n * chore: Remove not working mozilla code\n * Add support for -fsanitize-ignorelist\n * github storage: adjust the doc\n * github storage: ACTIONS_CACHE_URL =\u003e ACTIONS_RESULTS_URL\n * github storage: force version 2\n * Update codecov badge in README.md\n * Expand tests for dist-server\n * ci: Consolidate testing, coverage\n * ci: Update ubuntu-20.04 runners to ubuntu-22.04\n * chore: fix some comments\n * Give the --dist-status user some information about when a retry will happen.\n * Add support for Xclang flag '-mrelax-all'\n * Add support for Xclang flag '-mconstructor-aliases'\n * feat(utils): Add support for object \u003e= 0.33\n * fix(tests): Remove executable bit from oauth.rs\n * build(deps): bump openssl from 0.10.64 to 0.10.72\n * build(deps): bump tokio from 1.41.0 to 1.43.1\n * Improve the CARGO_INCREMENTAL checking (#2364)\n * build(deps): bump chrono from 0.4.38 to 0.4.40\n * build(deps): bump clap from 4.4.18 to 4.5.13\n * build(deps): bump ring from 0.17.7 to 0.17.13\n * Bail on `nvcc -time` and `nvcc -fdevice-time-trace` flags\n * test hip with librandomize_readdir\n * Add randomize_readdir test utility\n * fix non-strict HIP device lib order\n * Create config during testing to collect coverage data\n * Extend coverage to distributed tests\n * chore: replace num_cpus crate with available_parallelism in standard library (#2342)\n * Update CI coverage: grcov/codecov\n","modified":"2026-10-01T18:23:14.003305110Z","published":"2026-09-30T17:58:26Z","related":["CVE-2024-12224","CVE-2026-25541","CVE-2026-25727","CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784","CVE-2026-66746","CVE-2026-66754","CVE-2026-67181","CVE-2026-67182","CVE-2026-93599","CVE-2026-93600","CVE-2026-93601","CVE-2026-93602"],"upstream":["CVE-2024-12224","CVE-2026-25541","CVE-2026-25727","CVE-2026-41676","CVE-2026-41677","CVE-2026-41678","CVE-2026-41681","CVE-2026-41898","CVE-2026-42327","CVE-2026-44662","CVE-2026-45784","CVE-2026-66746","CVE-2026-66754","CVE-2026-67181","CVE-2026-67182","CVE-2026-93599","CVE-2026-93600","CVE-2026-93601","CVE-2026-93602"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243868"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270206"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270512"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270559"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270693"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270736"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270869"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273881"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273884"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273886"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273888"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274146"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282211"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25727"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-66746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-66754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-67182"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93601"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-93602"}],"affected":[{"package":{"name":"sccache","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/sccache&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.18.0~2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"sccache":"0.18.0~2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21982-1.json"}}],"schema_version":"1.9.0"}