openSUSE-SU-2026:21266-1: important: Security update for openQA, os-autoinst
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for openqa, os-autoinst
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21266-1
Rating: important
References:
* bsc#1258632
* bsc#1259005
* bsc#1264376
Cross-References:
* CVE-2026-26996
* CVE-2026-27904
* CVE-2026-6321
CVSS scores:
* CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-27904 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-27904 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-6321 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-6321 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.
Description:
This update for openQA, os-autoinst fixes the following issues:
Changes in openQA:
- Update to version 5.1783076943.6691832d:
* test: Stabilize `t/05-scheduler-full.t`
- Clarify resolution of three CVEs
* The following CVEs have been fixed (see previous changelog
entries that mentioned only the according Bugzilla tickets):
- bsc#1259005 - CVE-2026-27904
- bsc#1264376 - CVE-2026-6321
- bsc#1258632 - CVE-2026-26996
- Update to version 5.1782995932.ffeb09be:
* feat: throw 404 for nonexistent groups in overview
* feat: Avoid logwarn notifications for non-critical auth error
* chore(deps): Dependency cron 2026-07-02
* git subrepo pull (merge) external/os-autoinst-common
* fix: Check also hidden files in checklist plugin
* test: Enable faster re-connects in full scheduler test consistently
* test: Avoid silent daemons in verbose mode
* test: Allow running `t/43-…-scalability.t` in parallel
* test: Allow running `t/05-scheduler-full.t` in parallel
* test: Avoid race condition when generating ports in `25-cache.t`
* test: Avoid wasting seconds in `40-script_load_dump_templates.t`
* refactor: Remove disabled code in `openqa-load-templates`
* test: Avoid race condition when generating ports in many tests
* chore(deps): Dependency cron 2026-07-01
* fix(ci): format inline comments in workflows to pass yamllint
* test: Avoid running into "Address already in use" in fullstack test
* feat(ci): pin GitHub Actions by commit hash
Changes in os-autoinst:
- Update to version 5.1783082953.c3cb41d:
* test: Disable unstable `t/28-signalblocker.t` on ppc64le OBS builds
* fix: Check also hidden files in checklist plugin
* feat(ci): disable Mergify interactive queue controls in PR comments
* test: assert pipe size adjustment dynamically
* test: assert terminal session boundary safety
* refactor: support pretty markers in script_sudo and become_root
* fix: mmapi test failures and infinite loop hangs
* test: simplify Level 3 pretty marker detection
* fix: exclude virt-firmware on all older Leap archs
- Update to version 5.1782917048.dcc97e9:
* fix: Check also hidden files in checklist plugin
* feat(ci): disable Mergify interactive queue controls in PR comments
* fix(ci): format inline comments in workflows to pass yamllint
* feat(ci): pin GitHub Actions by commit hash
* test: assert pipe size adjustment dynamically
* test: assert terminal session boundary safety
* refactor: support pretty markers in script_sudo and become_root
* fix: mmapi test failures and infinite loop hangs
* test: simplify Level 3 pretty marker detection
* fix: exclude virt-firmware on all older Leap archs
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-395=1
Package List:
- openSUSE Leap 16.0:
openQA-5.1783076943.6691832d-bp160.1.1
openQA-auto-update-5.1783076943.6691832d-bp160.1.1
openQA-bootstrap-5.1783076943.6691832d-bp160.1.1
openQA-client-5.1783076943.6691832d-bp160.1.1
openQA-client-bash-completion-5.1783076943.6691832d-bp160.1.1
openQA-client-zsh-completion-5.1783076943.6691832d-bp160.1.1
openQA-common-5.1783076943.6691832d-bp160.1.1
openQA-continuous-update-5.1783076943.6691832d-bp160.1.1
openQA-devel-5.1783076943.6691832d-bp160.1.1
openQA-doc-5.1783076943.6691832d-bp160.1.1
openQA-llm-server-5.1783076943.6691832d-bp160.1.1
openQA-local-db-5.1783076943.6691832d-bp160.1.1
openQA-mcp-5.1783076943.6691832d-bp160.1.1
openQA-munin-5.1783076943.6691832d-bp160.1.1
openQA-python-scripts-5.1783076943.6691832d-bp160.1.1
openQA-single-instance-5.1783076943.6691832d-bp160.1.1
openQA-single-instance-nginx-5.1783076943.6691832d-bp160.1.1
openQA-worker-5.1783076943.6691832d-bp160.1.1
os-autoinst-5.1783082953.c3cb41d-bp160.1.1
os-autoinst-devel-5.1783082953.c3cb41d-bp160.1.1
os-autoinst-ipmi-deps-5.1783082953.c3cb41d-bp160.1.1
os-autoinst-openvswitch-5.1783082953.c3cb41d-bp160.1.1
os-autoinst-qemu-kvm-5.1783082953.c3cb41d-bp160.1.1
os-autoinst-qemu-x86-5.1783082953.c3cb41d-bp160.1.1
os-autoinst-s390-deps-5.1783082953.c3cb41d-bp160.1.1
os-autoinst-swtpm-5.1783082953.c3cb41d-bp160.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-26996.html
* https://www.suse.com/security/cve/CVE-2026-27904.html
* https://www.suse.com/security/cve/CVE-2026-6321.html