SUSE-SU-2026:3674-1: important: Security update for sccache
OPENSUSE-SECURITY-UPDATES <[email protected]>
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <178733065810.20680.12287632648078247002@f059bd5bf0f9> |
# Security update for sccache
Announcement ID: SUSE-SU-2026:3674-1
Release Date: 2026-08-21T09:04:43Z
Rating: important
References:
* bsc#1273881
* bsc#1273884
* bsc#1273886
* bsc#1273888
* bsc#1274146
Cross-References:
* CVE-2026-25541
* CVE-2026-66746
* CVE-2026-66754
* CVE-2026-67181
* CVE-2026-67182
CVSS scores:
* CVE-2026-25541 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-25541 ( NVD ): 5.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-66746 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-66746 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-66746 ( NVD ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-66746 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-66754 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66754 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-66754 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-66754 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-67181 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
* CVE-2026-67181 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
* CVE-2026-67181 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-67181 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
* CVE-2026-67182 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-67182 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-67182 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-67182 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L
Affected Products:
* Development Tools Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves five vulnerabilities can now be installed.
## Description:
This update for sccache fixes the following issues:
* CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to
undefined behavior and crashes (bsc#1274146).
* CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response
Header Values (bsc#1273881).
* CVE-2026-66754: rouille: remove_prefix function that allows remote
unauthenticated attackers to crash the server by sending a crafted percent-
encoded URL (bsc#1273884).
* CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding
Desynchronization (bsc#1273886).
* CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access
Control Bypass (bsc#1273888).
Changes for sccache:
* Update to version 0.17.0~1:
* Add experimental concurrent cache support
* Release 0.17.0
* tests: pin libc in the dist test crate
* doc: clarify server-side outputs and drop 'recommended mode' claim
* doc: document SCCACHE_CLIENT_SIDE env var
* doc: document client-side and direct modes in Architecture.md
* Fix description of Unix socket-based Redis connection
* server: remove redundant async block in start_compile_task
* server: simplify bind() request loops with ? instead of manual match arms
* Add support for arg files in Rust (#2782)
* feat: support S3 SSE-KMS with AWS-managed and customer-managed keys (#2770)
* abort compile tasks and associated subprocesses when a client disconnects
* treat -ivfsoverlay as a preprocessor-only argument
* gcc: refine response-file tokenizer visibility and whitespace handling
* integration: convert cmake 4.x modules XFAIL test to a passing test
* gcc/clang: cache and distribute builds using quoted @response files
* fix: Fix ToolchainPackager cfg gate to build on ppc64le/s390x
* fix: make gcc diagnostics color output work the same as for rustc
* implement client-side mode
* split handle_compile_response so that the compilation result can be handled
separately
* implement IpcStorage -- Storage backend over IPC
* extend wire protocol with storage RPCs
* implement AddAssign for ServerStats and related types
* add Storage::get_path for direct file access
* implement get_raw/put_raw on MultiLevelStorage
* add client_side_mode config flag (SCCACHE_CLIENT_SIDE)
* Extract new_client_runtime() helper to DRY up client runtime creation
* Clarify single-threaded runtime rationale comment (grammar)
* fix: use single-threaded tokio runtime in sccache dist-client
* fix: use single-threaded tokio runtime in sccache client
* fix: handle disabled cache backend features in multilevel chain
* Fix ldd output parsing: remove .exists() check that failed on systems where
the symlink source path does not exist locally (e.g. aarch64)
* Fix cfg guard for PanicToolchainPackager to also cover non-x86_64 Linux
architectures (e.g. aarch64)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3674=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3674=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3674=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3674=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* sccache-debuginfo-0.17.0~1-150600.10.14.1
* sccache-debugsource-0.17.0~1-150600.10.14.1
* sccache-0.17.0~1-150600.10.14.1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* sccache-debuginfo-0.17.0~1-150600.10.14.1
* sccache-0.17.0~1-150600.10.14.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* sccache-debuginfo-0.17.0~1-150600.10.14.1
* sccache-0.17.0~1-150600.10.14.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* sccache-debuginfo-0.17.0~1-150600.10.14.1
* sccache-0.17.0~1-150600.10.14.1
## References:
* https://www.suse.com/security/cve/CVE-2026-25541.html
* https://www.suse.com/security/cve/CVE-2026-66746.html
* https://www.suse.com/security/cve/CVE-2026-66754.html
* https://www.suse.com/security/cve/CVE-2026-67181.html
* https://www.suse.com/security/cve/CVE-2026-67182.html
* https://bugzilla.suse.com/show_bug.cgi?id=1273881
* https://bugzilla.suse.com/show_bug.cgi?id=1273884
* https://bugzilla.suse.com/show_bug.cgi?id=1273886
* https://bugzilla.suse.com/show_bug.cgi?id=1273888
* https://bugzilla.suse.com/show_bug.cgi?id=1274146