Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-EL-9-CLIENT-TOOLS-2026-2254 — golang-github-prometheus-node-exporter (CVE-2022-21698 +2 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update 5.0.8 for Multi-Linux Manager Client Tools

This update fixes the following issues:

golang-github-QubitProducts-exporter_exporter:

  • Security Fixes:
  • CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707)

golang-github-prometheus-node_exporter was updated from version 1.5.0 to 1.10.2:

  • Security Fixes:
  • Version 1.9.1:
  • CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (bsc#1238686)
  • Version 1.9.0:
  • CVE-2023-45288: Close connections when receiving too many headers (bsc#1236516)
  • Highlights of other changes and bug fixes:
  • Backward Compatibility and packaging changes:
  • Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains
  • Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility
  • Version 1.10.2:
  • Fixed typo in Zswap metric name (meminfo)
  • Version 1.10.1:
  • Fixed mount points being collected multiple times (filesystem)
  • Refactored mountinfo parsing (bsc#1261810)
  • Added Zswap/Zswapped metrics (meminfo)
  • Version 1.10.0:
  • New collectors: PCIe devices, swaps
  • Added systemd virtualization metrics, AIX metrics
  • WiFi packet metrics, additional PCIe and TLB metrics
  • Changed mdadm to use sysfs, added erofs to excluded filesystems
  • Fixed bugs: cpufreq collector, ethtool metrics
  • Version 1.9.1:
  • Fixed missing IRQ on older kernels (pressure)
  • Version 1.9.0 (jsc#PED-12485):
  • Switched to Go log/slog for logging
  • Converted meminfo to use procfs library
  • New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics,

hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support,

  • Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance

optimizations

  • Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing
  • Version 1.8.x:
  • Fixed CPU pressure metric collection, CPU seconds on Solaris, pressure collector nil reference
  • Version 1.8.0:
  • New collectors: xfrm (IPsec), watchdog
  • Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing
  • Removed caching of os-release file modtime/filename
  • Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race
  • Version 1.7.0 (jsc#PED-7893, jsc#PED-7928):
  • New: CPU vulnerabilities reporting from sysfs
  • Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values,

qdisc performance, hwmon filtering, rtnetlink for ARP stats

  • Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index
  • Version 1.6.0:
  • Deprecated ntp and supervisord collectors
  • Removed bcache cache_readaheads_totals metrics
  • Improved offline CPU handling (removed metrics for offline CPUs)
  • New: softirqs collector
  • Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced

btrfs privileges

  • Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts

prometheus-postgres_exporter:

  • Security Fixes:
  • CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699)

scap-security-guide:

  • Update the SSG package description
  • Add SLE16 profiles to the build
  • Updated to 0.1.79 (jsc#ECO-3319)
  • Create SLE16 HIPAA profile
  • Create SLE16 PCI DSS 4 profile
  • Use Sequoia in RHEL 10 instead of GPG
  • New Profile for RHEL10: BSI
  • Move RHEL Control files to product files
  • Update RHEL 9 CCN profile
  • Various updates for SLE 12/15

spacecmd:

  • Version 5.0.16-0
  • Update translation strings

uyuni-tools:

  • Version 0.1.39-0
  • mgrpxy ssh tuning should happen before crypto policies (bsc#1254619)
  • Fix default value for helm registry (bsc#1258927).
  • Use static supportconfig name to avoid dynamic search

(bsc#1257941)

  • Do not nest multiple tarball files and instead collect

all files into one tarball (bsc#1252964)

  • Show where final tarball was generated (bsc#1259208)

Affected software

SUSE-EL-9-CLIENT-TOOLS-2026-2254 is recorded against 6 packages.

  • golang-github-prometheus-node-exporter (fixed in 1.10.2-1.12.1)
  • golang-github-qubitproducts-exporter-exporter (fixed in 0.4.0-1.9.1)
  • prometheus-postgres-exporter (fixed in 0.10.1-1.15.1)
  • scap-security-guide (fixed in 0.1.80-1.44.1)
  • spacecmd (fixed in 5.0.16-1.61.1)
  • uyuni-tools (fixed in 0.1.39-1.32.1)

Timeline and source

Published on 3 June 2026 and last revised on 24 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-06-03
Updated 2026-08-20
Modified 2026-07-24
Fix URL N/A

Affected Packages

Software From version Fixed in
golang-github-prometheus-node-exporter 1.10.2-1.12.1
golang-github-qubitproducts-exporter-exporter 0.4.0-1.9.1
prometheus-postgres-exporter 0.10.1-1.15.1
scap-security-guide 0.1.80-1.44.1
spacecmd 5.0.16-1.61.1
uyuni-tools 0.1.39-1.32.1

Free Vulnerability Check

Is your site affected by SUSE-EL-9-CLIENT-TOOLS-2026-2254?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-EL-9-CLIENT-TOOLS-2026-2254 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026