openSUSE-SU-2026:0268-1: moderate: Security update for kronosnet

[email protected] Fri, 31 Jul 2026 15:05:03 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for kronosnet
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0268-1
Rating:             moderate
References:         #1257258 #1271923 #1271924 #1271925 
Cross-References:   CVE-2026-15811 CVE-2026-15812 CVE-2026-15813
                   
CVSS scores:
                    CVE-2026-15811 (SUSE): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
                    CVE-2026-15812 (SUSE): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
                    CVE-2026-15813 (SUSE): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that solves three vulnerabilities and has one
   errata is now available.

Description:

   This update for kronosnet fixes the following issues:

   - CVE-2026-15811: encryption key exposure in memory after cryptographic
     configuration changes (bsc#1271923)
   - CVE-2026-15812: access control list bypass via link ID spoofing on
     unencrypted dynamic links (bsc#1271924)
   - CVE-2026-15813: memory corruption and out-of-bounds access via malformed
     network packet defragmentation (bsc#1271925)

   - kronosnet-1.33
    * Build fixes for gcc-15 (boo#1257258)
    * Build fixes for rust coreutils
    * Coverity tests cleanup
    * Release: ship all files for completeness

   - kronosnet-1.32
    * IMPORTANT: sctp support is now officially deprecated. It is disabled by
      default and it will be removed in knet 2.x.
    * Fix potential thread race condition in libnozzle close.
    * Fix wrong pointer in libknet RX thread, only triggered by old gcc (<
      11).
    * Libnozzle: different fixes for BSD to deal with new tap driver changes
      and don“t leak interfaces.
    * New API call in libknet to allow configuring a dscp value for
      KNET_LINK_FLAG_TRAFFICHIPRIO.
    * Bump soname to reflect new API call.
    * Improve OpenSSL error handling.
    * Add support for OpenIndiana.
    * Documentation updates.
    * Fix several tests to better deal with execution timing.
    * Handle some new coverity errors.
    * Create and refine STYLE_GUIDE.md for project contributions.

   - kronosnet-1.31
    * Fixed incorrect lzo1x_decompress call to use the safe version
    * Udp: lower log levels for messages triggered by every single packets to
      trace level.

   - kronosnet-1.30
     * Convert time_t to unsigned long long before formatting
     * Add warning when packets are being received from the wrong interface

   - kronosnet-1.29
     * Fix FORTIFY source detection
     * libknet/tests: fix potential overflow with sprintf
     * [man] update to latest doxyxml from libqb


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-268=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      libknet-devel-1.33-bp157.2.3.1
      libknet1-1.33-bp157.2.3.1
      libknet1-compress-bzip2-plugin-1.33-bp157.2.3.1
      libknet1-compress-lz4-plugin-1.33-bp157.2.3.1
      libknet1-compress-lzma-plugin-1.33-bp157.2.3.1
      libknet1-compress-lzo2-plugin-1.33-bp157.2.3.1
      libknet1-compress-plugins-all-1.33-bp157.2.3.1
      libknet1-compress-zlib-plugin-1.33-bp157.2.3.1
      libknet1-compress-zstd-plugin-1.33-bp157.2.3.1
      libknet1-crypto-nss-plugin-1.33-bp157.2.3.1
      libknet1-crypto-openssl-plugin-1.33-bp157.2.3.1
      libknet1-crypto-plugins-all-1.33-bp157.2.3.1
      libknet1-plugins-all-1.33-bp157.2.3.1
      libnozzle-devel-1.33-bp157.2.3.1
      libnozzle1-1.33-bp157.2.3.1


References:

   https://www.suse.com/security/cve/CVE-2026-15811.html
   https://www.suse.com/security/cve/CVE-2026-15812.html
   https://www.suse.com/security/cve/CVE-2026-15813.html
   https://bugzilla.suse.com/1257258
   https://bugzilla.suse.com/1271923
   https://bugzilla.suse.com/1271924
   https://bugzilla.suse.com/1271925