openSUSE-SU-2026:21573-1: important: Security update for himmelblau

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for himmelblau
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21573-1
Rating: important
References:

  * bsc#1270946
  * bsc#1270985
  * bsc#1273910
  * bsc#1273911
  * bsc#1273912



Cross-References:

  * CVE-2026-45784



CVSS scores:

  * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
  * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has 5 bug fixes can now be installed.

Description:

This update for himmelblau fixes the following issues:

Update to version 2.3.14+git0.e23b4c54.

Security issues fixed:

- CVE-2026-45784: incorrect sizing of output buffers in `CipherCtxRef::cipher_update_inplace` when used with
  AES key-wrap-with-padding ciphers can lead to attacker-controlled heap corruption (bsc#1270985).
- Arbitrary HTTP or HTTPS URLs classified as Office documents based on an attacker-controlled file query parameters are
  forwarded to Electron applications and allow for code execution through Electron (bsc#1273910).
- Directory-provided RFC2307 user identifiers accepted without exclusion of systemd's dynamic-user range allows for
  daemon impersonation and command execution through the task helper (bsc#1273911).
- Daemon acts on Hello PIN enrollment requests whose identity claims it never cryptographically verifies and allows for
  local authentication bypass (bsc#1273912).

Other updates and bugfixes:

- Version 2.3.14+git0.e23b4c54:
  * fix(`nss`): avoid locked shadow entries
  * fix(`deps`): update libhimmelblau lockfile
  * fix(`pam`): make account denials terminal
  * `debian`: make the `pam_allow_groups` denial terminal in the account phase
- Version 2.3.13:
  * Update `cargo vet` audits for backport
  * Fix `cargo-fuzz` install in fuzz CI
  * `cargo vet`
  * Update `ldap3_proto` to 0.7.1
  * Update `openssl`
- Version 2.3.12:
  * Remove invalid `himmelblau.conf` example info
  * Fix SSHd configuration load order on Fedora/RHEL systems
  * `himmelblau-init-hsm-pin`: don't bind the `hsm-pin` to PCR7
  * `qr-greeter`: support GNOME Shell 50
  * Update `libhimmelblau` to latest version
  * deps(`rust`): bump `tonic` in the `all-cargo-updates` group across 1 directory
  * `cargo audit`


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1455=1

Package List:

- openSUSE Leap 16.0:

  himmelblau-2.3.14+git0.e23b4c54-160000.1.1
  himmelblau-qr-greeter-2.3.14+git0.e23b4c54-160000.1.1
  himmelblau-sshd-config-2.3.14+git0.e23b4c54-160000.1.1
  himmelblau-sso-2.3.14+git0.e23b4c54-160000.1.1
  libnss_himmelblau2-2.3.14+git0.e23b4c54-160000.1.1
  pam-himmelblau-2.3.14+git0.e23b4c54-160000.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-45784.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.