SUSE alert SUSE-SU-2026:3421-1 (prometheus-ha_cluster_exporter)
| From: | SLE-SECURITY-UPDATES <null@suse.de> | |
| To: | sle-security-updates@lists.suse.com | |
| Subject: | SUSE-SU-2026:3421-1: important: Security update for prometheus-ha_cluster_exporter | |
| Date: | Thu, 30 Jul 2026 12:33:12 -0000 | |
| Message-ID: | <178541479224.1210.3529482929465284771@cdce4c525ac1> |
# Security update for prometheus-ha_cluster_exporter Announcement ID: SUSE-SU-2026:3421-1 Release Date: 2026-07-30T07:37:12Z Rating: important References: * bsc#1266552 * jsc#PED-2560 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for prometheus-ha_cluster_exporter fixes the following issue: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266552). Other updates and bugfixes: * Release 1.4.2 * Use proper obs time format on changes generation. * Upgrade x/net to 0.57. * Full changelog *: https://github.com/ClusterLabs/ha_cluster_exporter/compar... * Release 1.4.1 * Upgrade to use go 1.25. * Bump github.com/prometheus/common from 0.59.1 to 0.61.0. * Bump golang.org/x/net from 0.33.0 to 0.55.0. * Full changelog: https://github.com/ClusterLabs/ha_cluster_exporter/compar... * Release 1.4.0 * add support to show overall cluster maintenance mode. * add supportconfig plugin (jsc#PED-2560). * update the CI workflow. * change default OBS development project. * bump required Go version to 1.23. * fix corosync collector parser when using IPv6 hostnames (#245). * Bump github.com/prometheus/client_model from 0.3.0 to 0.4.0 . * Bump github.com/prometheus/client_golang from 1.15.0 to 1.15.1 . * Bump github.com/prometheus/common from 0.42.0 to 0.44.0. * Bump github.com/spf13/viper from 1.15.0 to 1.16.0. * Bump github.com/stretchr/testify from 1.8.2 to 1.8.4. * Bump github.com/prometheus/client_golang from 1.15.1 to 1.16.0. * Bump github.com/prometheus/client_golang from 1.16.0 to 1.17.0. * Bump golang.org/x/net from 0.10.0 to 0.17.0. * Bump github.com/prometheus/common from 0.44.0 to 0.55.0. * Bump github.com/spf13/viper from 1.16.0 to 1.19.0. * Bump actions/download-artifact from 3 to 4.1.7. * Bump github.com/prometheus/client_golang from 1.19.1 to 1.20.2. * Bump github.com/prometheus/common from 0.55.0 to 0.59.1. * Bump github.com/prometheus/client_golang from 1.20.2 to 1.20.4. * Bump github.com/prometheus/client_golang from 1.20.4 to 1.20.5. * Bump github.com/stretchr/testify from 1.9.0 to 1.10.0. * Bump golang.org/x/crypto from 0.26.0 to 0.31.0. * Full changelog: https://github.com/ClusterLabs/ha_cluster_exporter/compar... ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SAP-12-SP5-2026-3421=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * prometheus-ha_cluster_exporter-1.4.2-4.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266552 * https://jira.suse.com/browse/PED-2560
Attachment: None (type=text/html)
(HTML attachment elided)
