SUSE-SU-2026:3840-1: important: Security update for wicked

OPENSUSE-SECURITY-UPDATES <[email protected]>
Newsgroups gmane.linux.suse.security.announce
Message-ID <178786292975.594.16376776781101154416@6bd16ccd9111>
# Security update for wicked

Announcement ID: SUSE-SU-2026:3840-1  
Release Date: 2026-08-27T12:21:23Z  
Rating: important  
References:

  * bsc#1265221
  * bsc#1274627
  * jsc#PED-1942

  
Cross-References:

  * CVE-2026-44932
  * CVE-2026-71401
  * CVE-2026-71402

  
CVSS scores:

  * CVE-2026-44932 ( SUSE ):  5.8
    CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H
  * CVE-2026-44932 ( SUSE ):  8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-44932 ( NVD ):  8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-71401 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-71401 ( NVD ):  5.3
    CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-71402 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  * CVE-2026-71402 ( NVD ):  5.3
    CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-71402 ( NVD ):  5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

  
Affected Products:

  * openSUSE Leap 15.6
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6

  
  
An update that solves three vulnerabilities and contains one feature can now be
installed.

## Description:

This update for wicked fixes the following issues:

Update to version 0.6.79.

  * CVE-2026-44932: indirect remote shell command injection due to insufficient
    sanitization of DHCP options written to `/run/wicked/leaseinfo.*` files
    (bsc#1265221).
  * CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum
    handling of DHCPv4 capture parsing (bsc#1274627).
  * CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended
    beyond provided allocation in DHCPv4 capture parsing (bsc#1274627).

Changes for wicked:

  * Version 0.6.79:
  * Fix to escape single-quotes in leaseinfo dump output used by the `wicked
    test dhcp4` and `wicked test dhcp6` and written to the
    `/run/wicked/leaseinfo.*` files, e.g. to pass them to `netconfig`.
  * Fix `posix-tz-dbname` and `tz-string` option processing checks to permit
    only valid characters according to RFC4833.
  * Discard string values containing single-quotes in other options.
  * Trigger to regenerate `initrd` that may contain wicked binaries on updates
    from wicked versions <= 0.6.78.
  * Version 0.6.78:
  * `man`: small fixes in wireless manpage (gh#opensuse/wicked#1053)
  * `rtnetlink`: fix `RTM_NEWLINK` name resolution in debug
    (gh#opensuse/wicked#1052)
  * Add support for IPVLAN/IPVTAP (jsc#PED-1942, gh#opensuse/wicked#1050,
    gh#opensuse/wicked#1051)
  * `fsm`: remove children reference array from worker (gh#opensuse/wicked#1049)
  * `ifxml`: migrate and generate lower configs/policies
    (gh#opensuse/wicked#1048)
  * `fsm`: use refcount and array macros in worker and policy
    (gh#opensuse/wicked#1047)
  * `route`: use refcounted array and fix error leaks (gh#opensuse/wicked#1046)
  * `utils`: add support for refcounted objects in generic array
    (gh#openSUSE/wicked#1045)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3840=1

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3840=1

  * openSUSE Leap 15.6  
    zypper in -t patch SUSE-2026-3840=1

## Package List:

  * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
    * wicked-nbft-0.6.79-150600.11.20.1
    * wicked-debuginfo-0.6.79-150600.11.20.1
    * wicked-debugsource-0.6.79-150600.11.20.1
    * wicked-0.6.79-150600.11.20.1
    * wicked-service-0.6.79-150600.11.20.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * wicked-nbft-0.6.79-150600.11.20.1
    * wicked-debuginfo-0.6.79-150600.11.20.1
    * wicked-service-0.6.79-150600.11.20.1
    * wicked-0.6.79-150600.11.20.1
    * wicked-debugsource-0.6.79-150600.11.20.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * wicked-nbft-0.6.79-150600.11.20.1
    * wicked-debuginfo-0.6.79-150600.11.20.1
    * wicked-service-0.6.79-150600.11.20.1
    * wicked-0.6.79-150600.11.20.1
    * wicked-debugsource-0.6.79-150600.11.20.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-44932.html
  * https://www.suse.com/security/cve/CVE-2026-71401.html
  * https://www.suse.com/security/cve/CVE-2026-71402.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1265221
  * https://bugzilla.suse.com/show_bug.cgi?id=1274627
  * https://jira.suse.com/browse/PED-1942
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.