🛡️ SUSE-SU-2026:22837-1 — cockpit (CVE-2025-13465 +5 more)
Description
Security update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions
This update for cockpit, cockpit-machines, cockpit-packages, cockpit-podman, cockpit-repos, cockpit-subscriptions fixes the following issues:
Security issues fixed:
- CVE-2025-13465: lodash: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from
global prototypes (bsc#1257325).
- CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829).
- CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and
may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840).
- CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character
that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641).
- CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking
complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015).
Non security issues fixed:
- cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210).
- cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149).
Changes for cockpit:
- Update to 364.
- Update to 361 (jsc#PED-15706/jsc#CPT-183):
- Remove all "Mount" actions in Anaconda mode
- Dependency updates
- Update to 360:
- ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631
- ws: support loading a custom login page
- Update to 358:
- Networking: Add Wi-Fi support
- Cockpit Client updated to GTK 4
- Bugfixes and translation updates
- Update to 357:
- lib: Use browser context menu on shift
- bridge: support Python 3.14 on old kernels (RHEL 8)
- Update to 356:
- systemd: Allow editing timers created by Cockpit
- Convert license headers to SPDX format
- Update to 355:
- ws: Remove obsolete pam_cockpit_cert module
- shell: add StartTransientUnit as a sudo alternative
Changes for cockpit-machines:
- Update to 354.
- Update to 352:
- Improvements to the "Add disk" and "Create Volume" dialogs.
- Update suse_version requirement to function with the planned bump (jsc#PED-15820).
- Drop explict dependency on libvirt (bsc#1258040, bsc#1236149).
- Update to 348:
- Translation updates
- Convert license headers to SPDX format
- Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl
- Update to 347:
- Bug fixes and translation updates
- Fix esbuild for ppc64le (bsc#1257698).
Changes for cockpit-packages:
- Update to version 5:
- Support transactional systems
- Improve error/success messages
- Translation updates
- Patch esbuild to use native runtime on ppc64 (bsc#1257698).
Changes for cockpit-podman:
- Update to 128.
- Fix esbuild for ppc64le (bsc#1257698).
Changes for cockpit-repos:
- Update to 4.8.
- Patch esbuild to use native runtime on ppc64 (bsc#1257698).
Changes for cockpit-subscriptions:
- Update to version 16.2 (bsc#1257033).
- Patch esbuild to use native runtime on ppc64 (bsc#1257698).
Affected software
SUSE-SU-2026:22837-1 is recorded against 6 packages.
- cockpit (fixed in 364-160000.1.1)
- cockpit-machines (fixed in 354-160000.1.1)
- cockpit-packages (fixed in 5-160000.1.1)
- cockpit-podman (fixed in 128-160000.1.1)
- cockpit-repos (fixed in 4.8-160000.1.1)
- cockpit-subscriptions (fixed in 16.2-160000.1.1)
Timeline and source
Published on 21 July 2026 and last revised on 28 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| cockpit | — | 364-160000.1.1 |
| cockpit-machines | — | 354-160000.1.1 |
| cockpit-packages | — | 5-160000.1.1 |
| cockpit-podman | — | 128-160000.1.1 |
| cockpit-repos | — | 4.8-160000.1.1 |
| cockpit-subscriptions | — | 16.2-160000.1.1 |
References
Similar Threats
- Unknown ALSA-2026:21676
- Unknown ALSA-2026:21700
- Unknown ALSA-2026:21468
- Unknown CLSA-2026-1777452220
- Unknown ALSA-2026:7384
Free Vulnerability Check
Is your site affected by SUSE-SU-2026:22837-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:22837-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.