Security update for cockpit
| Announcement ID: | SUSE-SU-2026:2005-1 |
|---|---|
| Release Date: | 2026-05-19T08:23:18Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves three vulnerabilities can now be installed.
Description:
This update for cockpit fixes the following issues
- CVE-2026-0775: npm: loading of modules from an unsecured location can be used for local privilege escalation and arbitrary code execution in the context of a target user (bsc#1256521).
- CVE-2026-4802: remote command execution via unsanitized user-controlled parameters within crafted links in system logs UI (bsc#1265040).
- CVE-2026-29074: svgo: no guard against entity expansion or recursion when processing XML with custom entities can lead to DoS (bsc#1259290).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-2005=1 -
SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-2005=1
Package List:
-
SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
- cockpit-debugsource-251.3-150400.8.6.1
- cockpit-bridge-251.3-150400.8.6.1
- cockpit-bridge-debuginfo-251.3-150400.8.6.1
- cockpit-ws-debuginfo-251.3-150400.8.6.1
- cockpit-251.3-150400.8.6.1
- cockpit-ws-251.3-150400.8.6.1
- cockpit-debuginfo-251.3-150400.8.6.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
- cockpit-selinux-251.3-150400.8.6.1
- cockpit-networkmanager-251.3-150400.8.6.1
- cockpit-system-251.3-150400.8.6.1
- cockpit-storaged-251.3-150400.8.6.1
-
SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
- cockpit-debugsource-251.3-150400.8.6.1
- cockpit-bridge-251.3-150400.8.6.1
- cockpit-bridge-debuginfo-251.3-150400.8.6.1
- cockpit-ws-debuginfo-251.3-150400.8.6.1
- cockpit-251.3-150400.8.6.1
- cockpit-ws-251.3-150400.8.6.1
- cockpit-debuginfo-251.3-150400.8.6.1
-
SUSE Linux Enterprise Micro 5.3 (noarch)
- cockpit-selinux-251.3-150400.8.6.1
- cockpit-networkmanager-251.3-150400.8.6.1
- cockpit-system-251.3-150400.8.6.1
- cockpit-storaged-251.3-150400.8.6.1
References:
- https://www.suse.com/security/cve/CVE-2026-0775.html
- https://www.suse.com/security/cve/CVE-2026-29074.html
- https://www.suse.com/security/cve/CVE-2026-4802.html
- https://bugzilla.suse.com/show_bug.cgi?id=1256521
- https://bugzilla.suse.com/show_bug.cgi?id=1259290
- https://bugzilla.suse.com/show_bug.cgi?id=1265040