openSUSE-SU-2026:21266-1: important: Security update for openQA, os-autoinst

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for openqa, os-autoinst
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21266-1
Rating: important
References:

  * bsc#1258632
  * bsc#1259005
  * bsc#1264376



Cross-References:

  * CVE-2026-26996
  * CVE-2026-27904
  * CVE-2026-6321



CVSS scores:

  * CVE-2026-26996 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-26996 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-27904 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-27904 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-6321 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2026-6321 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

Description:

This update for openQA, os-autoinst fixes the following issues:

Changes in openQA:

- Update to version 5.1783076943.6691832d:
  * test: Stabilize `t/05-scheduler-full.t`

- Clarify resolution of three CVEs
  * The following CVEs have been fixed (see previous changelog
    entries that mentioned only the according Bugzilla tickets):
    - bsc#1259005 - CVE-2026-27904
    - bsc#1264376 - CVE-2026-6321
    - bsc#1258632 - CVE-2026-26996

- Update to version 5.1782995932.ffeb09be:
  * feat: throw 404 for nonexistent groups in overview
  * feat: Avoid logwarn notifications for non-critical auth error
  * chore(deps): Dependency cron 2026-07-02
  * git subrepo pull (merge) external/os-autoinst-common
  * fix: Check also hidden files in checklist plugin
  * test: Enable faster re-connects in full scheduler test consistently
  * test: Avoid silent daemons in verbose mode
  * test: Allow running `t/43-…-scalability.t` in parallel
  * test: Allow running `t/05-scheduler-full.t` in parallel
  * test: Avoid race condition when generating ports in `25-cache.t`
  * test: Avoid wasting seconds in `40-script_load_dump_templates.t`
  * refactor: Remove disabled code in `openqa-load-templates`
  * test: Avoid race condition when generating ports in many tests
  * chore(deps): Dependency cron 2026-07-01
  * fix(ci): format inline comments in workflows to pass yamllint
  * test: Avoid running into "Address already in use" in fullstack test
  * feat(ci): pin GitHub Actions by commit hash

Changes in os-autoinst:

- Update to version 5.1783082953.c3cb41d:
  * test: Disable unstable `t/28-signalblocker.t` on ppc64le OBS builds
  * fix: Check also hidden files in checklist plugin
  * feat(ci): disable Mergify interactive queue controls in PR comments
  * test: assert pipe size adjustment dynamically
  * test: assert terminal session boundary safety
  * refactor: support pretty markers in script_sudo and become_root
  * fix: mmapi test failures and infinite loop hangs
  * test: simplify Level 3 pretty marker detection
  * fix: exclude virt-firmware on all older Leap archs

- Update to version 5.1782917048.dcc97e9:
  * fix: Check also hidden files in checklist plugin
  * feat(ci): disable Mergify interactive queue controls in PR comments
  * fix(ci): format inline comments in workflows to pass yamllint
  * feat(ci): pin GitHub Actions by commit hash
  * test: assert pipe size adjustment dynamically
  * test: assert terminal session boundary safety
  * refactor: support pretty markers in script_sudo and become_root
  * fix: mmapi test failures and infinite loop hangs
  * test: simplify Level 3 pretty marker detection
  * fix: exclude virt-firmware on all older Leap archs


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-packagehub-395=1

Package List:

- openSUSE Leap 16.0:

  openQA-5.1783076943.6691832d-bp160.1.1
  openQA-auto-update-5.1783076943.6691832d-bp160.1.1
  openQA-bootstrap-5.1783076943.6691832d-bp160.1.1
  openQA-client-5.1783076943.6691832d-bp160.1.1
  openQA-client-bash-completion-5.1783076943.6691832d-bp160.1.1
  openQA-client-zsh-completion-5.1783076943.6691832d-bp160.1.1
  openQA-common-5.1783076943.6691832d-bp160.1.1
  openQA-continuous-update-5.1783076943.6691832d-bp160.1.1
  openQA-devel-5.1783076943.6691832d-bp160.1.1
  openQA-doc-5.1783076943.6691832d-bp160.1.1
  openQA-llm-server-5.1783076943.6691832d-bp160.1.1
  openQA-local-db-5.1783076943.6691832d-bp160.1.1
  openQA-mcp-5.1783076943.6691832d-bp160.1.1
  openQA-munin-5.1783076943.6691832d-bp160.1.1
  openQA-python-scripts-5.1783076943.6691832d-bp160.1.1
  openQA-single-instance-5.1783076943.6691832d-bp160.1.1
  openQA-single-instance-nginx-5.1783076943.6691832d-bp160.1.1
  openQA-worker-5.1783076943.6691832d-bp160.1.1
  os-autoinst-5.1783082953.c3cb41d-bp160.1.1
  os-autoinst-devel-5.1783082953.c3cb41d-bp160.1.1
  os-autoinst-ipmi-deps-5.1783082953.c3cb41d-bp160.1.1
  os-autoinst-openvswitch-5.1783082953.c3cb41d-bp160.1.1
  os-autoinst-qemu-kvm-5.1783082953.c3cb41d-bp160.1.1
  os-autoinst-qemu-x86-5.1783082953.c3cb41d-bp160.1.1
  os-autoinst-s390-deps-5.1783082953.c3cb41d-bp160.1.1
  os-autoinst-swtpm-5.1783082953.c3cb41d-bp160.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-26996.html
  * https://www.suse.com/security/cve/CVE-2026-27904.html
  * https://www.suse.com/security/cve/CVE-2026-6321.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.