SUSE alert SUSE-SU-2026:21437-1 (himmelblau)
| From: | SLE-SECURITY-UPDATES <null@suse.de> | |
| To: | sle-security-updates@lists.suse.com | |
| Subject: | SUSE-SU-2026:21437-1: moderate: Security update for himmelblau | |
| Date: | Mon, 04 May 2026 08:35:29 -0000 | |
| Message-ID: | <177788372952.1375.12721475152681803711@dde0e951fc7e> |
# Security update for himmelblau Announcement ID: SUSE-SU-2026:21437-1 Release Date: 2026-04-30T17:06:48Z Rating: moderate References: * bsc#1261324 * bsc#1261613 Cross-References: * CVE-2026-34397 CVSS scores: * CVE-2026-34397 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-34397 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34397 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34397 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for himmelblau fixes the following issues: Update to version 2.3.9+git0.a9fd29b. Security issues fixed: * CVE-2026-34397: Fixed naming collision that can lead to local privilege escalation (bsc#1261324). Other updates and bugfixes: * update aws-lc-sys to 0.39.0 for security fixes * update rustls-webpki to 0.103.10 for CRL revocation fix * Version 2.3.9: * packaging: fix if/else block for debian's postrm * Update apparmor.unix-chkpwd.local (Issue #1252) * When Hello user encounters SSPR demand, be permissive * add tests for sudo_groups functionality * Fix config tests to ignore local host config * Do not clear $NOTIFY_SOCKET when calling sd_ready * Fix token cache 24h purge * broker: use SSO server nonce for PRT only when provided * Fix pam_himmelblau blocking local user password changes (#1199) * Remove unused File import * Use is_ascii_alphanumeric() for account_id validation * Fix path traversal in LoadProfilePhoto AccountsService writes * Drop initialization tracing span * himmelblau-hsm-pin-init: drop RemainAfterExit=yes * Add fallback behavior when consent is required * qr-greeter: enable extension without socket noise * debian: make install/remove noninteractive; reduce QR postinst noise; soften missing hello prt * Never respond with BadRequest without error detail * deps(rust): bump the all-cargo-updates group across 1 directory with 7 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-664=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-664=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * himmelblau-sso-2.3.9+git0.a9fd29b-160000.1.1 * libnss_himmelblau2-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-debuginfo-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-sso-debuginfo-2.3.9+git0.a9fd29b-160000.1.1 * pam-himmelblau-2.3.9+git0.a9fd29b-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * himmelblau-sshd-config-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-qr-greeter-2.3.9+git0.a9fd29b-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * himmelblau-sso-2.3.9+git0.a9fd29b-160000.1.1 * libnss_himmelblau2-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-debuginfo-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-sso-debuginfo-2.3.9+git0.a9fd29b-160000.1.1 * pam-himmelblau-2.3.9+git0.a9fd29b-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * himmelblau-sshd-config-2.3.9+git0.a9fd29b-160000.1.1 * himmelblau-qr-greeter-2.3.9+git0.a9fd29b-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34397.html * https://bugzilla.suse.com/show_bug.cgi?id=1261324 * https://bugzilla.suse.com/show_bug.cgi?id=1261613
Attachment: None (type=text/html)
(HTML attachment elided)
