SUSE-SU-2026:3674-1: important: Security update for sccache

OPENSUSE-SECURITY-UPDATES <[email protected]>
Newsgroups gmane.linux.suse.security.announce
Message-ID <178733065810.20680.12287632648078247002@f059bd5bf0f9>
# Security update for sccache

Announcement ID: SUSE-SU-2026:3674-1  
Release Date: 2026-08-21T09:04:43Z  
Rating: important  
References:

  * bsc#1273881
  * bsc#1273884
  * bsc#1273886
  * bsc#1273888
  * bsc#1274146

  
Cross-References:

  * CVE-2026-25541
  * CVE-2026-66746
  * CVE-2026-66754
  * CVE-2026-67181
  * CVE-2026-67182

  
CVSS scores:

  * CVE-2026-25541 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-25541 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-25541 ( NVD ):  5.5
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-25541 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-66746 ( SUSE ):  5.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-66746 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-66746 ( NVD ):  5.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-66746 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
  * CVE-2026-66754 ( SUSE ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-66754 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-66754 ( NVD ):  8.2
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-66754 ( NVD ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-67181 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
  * CVE-2026-67181 ( SUSE ):  5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
  * CVE-2026-67181 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-67181 ( NVD ):  5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
  * CVE-2026-67182 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-67182 ( SUSE ):  4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-67182 ( NVD ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-67182 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L

  
Affected Products:

  * Development Tools Module 15-SP7
  * openSUSE Leap 15.6
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves five vulnerabilities can now be installed.

## Description:

This update for sccache fixes the following issues:

  * CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to
    undefined behavior and crashes (bsc#1274146).
  * CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response
    Header Values (bsc#1273881).
  * CVE-2026-66754: rouille: remove_prefix function that allows remote
    unauthenticated attackers to crash the server by sending a crafted percent-
    encoded URL (bsc#1273884).
  * CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding
    Desynchronization (bsc#1273886).
  * CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access
    Control Bypass (bsc#1273888).

Changes for sccache:

  * Update to version 0.17.0~1:

  * Add experimental concurrent cache support

  * Release 0.17.0
  * tests: pin libc in the dist test crate
  * doc: clarify server-side outputs and drop 'recommended mode' claim
  * doc: document SCCACHE_CLIENT_SIDE env var
  * doc: document client-side and direct modes in Architecture.md
  * Fix description of Unix socket-based Redis connection
  * server: remove redundant async block in start_compile_task
  * server: simplify bind() request loops with ? instead of manual match arms
  * Add support for arg files in Rust (#2782)
  * feat: support S3 SSE-KMS with AWS-managed and customer-managed keys (#2770)
  * abort compile tasks and associated subprocesses when a client disconnects
  * treat -ivfsoverlay as a preprocessor-only argument
  * gcc: refine response-file tokenizer visibility and whitespace handling
  * integration: convert cmake 4.x modules XFAIL test to a passing test
  * gcc/clang: cache and distribute builds using quoted @response files
  * fix: Fix ToolchainPackager cfg gate to build on ppc64le/s390x
  * fix: make gcc diagnostics color output work the same as for rustc
  * implement client-side mode
  * split handle_compile_response so that the compilation result can be handled
    separately
  * implement IpcStorage -- Storage backend over IPC
  * extend wire protocol with storage RPCs
  * implement AddAssign for ServerStats and related types
  * add Storage::get_path for direct file access
  * implement get_raw/put_raw on MultiLevelStorage
  * add client_side_mode config flag (SCCACHE_CLIENT_SIDE)
  * Extract new_client_runtime() helper to DRY up client runtime creation
  * Clarify single-threaded runtime rationale comment (grammar)
  * fix: use single-threaded tokio runtime in sccache dist-client
  * fix: use single-threaded tokio runtime in sccache client
  * fix: handle disabled cache backend features in multilevel chain
  * Fix ldd output parsing: remove .exists() check that failed on systems where
    the symlink source path does not exist locally (e.g. aarch64)
  * Fix cfg guard for PanicToolchainPackager to also cover non-x86_64 Linux
    architectures (e.g. aarch64)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * Development Tools Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3674=1

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3674=1

  * openSUSE Leap 15.6  
    zypper in -t patch SUSE-2026-3674=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3674=1

## Package List:

  * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
    * sccache-debuginfo-0.17.0~1-150600.10.14.1
    * sccache-debugsource-0.17.0~1-150600.10.14.1
    * sccache-0.17.0~1-150600.10.14.1
  * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * sccache-debuginfo-0.17.0~1-150600.10.14.1
    * sccache-0.17.0~1-150600.10.14.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * sccache-debuginfo-0.17.0~1-150600.10.14.1
    * sccache-0.17.0~1-150600.10.14.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * sccache-debuginfo-0.17.0~1-150600.10.14.1
    * sccache-0.17.0~1-150600.10.14.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-25541.html
  * https://www.suse.com/security/cve/CVE-2026-66746.html
  * https://www.suse.com/security/cve/CVE-2026-66754.html
  * https://www.suse.com/security/cve/CVE-2026-67181.html
  * https://www.suse.com/security/cve/CVE-2026-67182.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1273881
  * https://bugzilla.suse.com/show_bug.cgi?id=1273884
  * https://bugzilla.suse.com/show_bug.cgi?id=1273886
  * https://bugzilla.suse.com/show_bug.cgi?id=1273888
  * https://bugzilla.suse.com/show_bug.cgi?id=1274146
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.