gpp_maybe
Security update for prometheus
SUSE-SLE-Module-Basesystem-15-SP7-2026-1008
This update for Prometheus fixes the following issues: golang-github-prometheus-alertmanager, golang-github-prometheus-node_exporter: - Internal changes to fix build issues with no impact for customers golang-github-prometheus-prometheus: - Security issues fixed: * CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893) * CVE-2026-25547: Fixed unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841) * CVE-2026-1615, CVE-2025-61140 The old web UI is no longer built due to security issues (bsc#1257897, bsc#1257442) * CVE-2025-13465: Bump lodash package to version 4.17.23 to fix prototype pollution vulnerability (bsc#1257329) * CVE-2025-12816: Interpretation conflict vulnerability allowing bypassing cryptographic verifications (bsc#1255588) - Version update from 2.53.4 to 3.5.0 with the following highlighted changes (jsc#PED-13824): * Modernized Interface: Introduced a brand-new UI * Enhanced Cloud and Auth: Added unified AWS service discovery (EC2, ECS, Lightsail) and Azure Workload Identity support for more secure, native cloudauthentication. * Performance Standards: Fully integrated OpenTelemetry (OTLP) ingestion and moved Native Histograms from experimental to a stable feature. * Advanced Data Export: Rolled out Remote Write 2.0, offering better performance and metadata handling when sending data to external systems. * Query Power: Added new PromQL functions (like first_over_time and last_over_time) and optimization for grouping operations. * Better Visibility: The UI now displays detailed relabeling steps, scrape intervals, and timeouts, making it easier to troubleshoot why targets aren't reporting correctly. * Critical Fixes: Resolved significant memory leaks related to query logging and fixed bugs where targets were accidentally being scraped multiple times.
-
Release DateMar 25 2026
-
ReferencesBugzilla: 1257841, 1257442, 1257329, 1257897, 1255588
CVEs: CVE-2026-25547, CVE-2025-12816, CVE-2025-13465, CVE-2026-1615, CVE-2025-61140 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.7 s390x
-
Packagesgolang-github-prometheus-node_exporter
Prometheus exporter for machine metrics1.9.1-150100.3.38.1 lock rpm lock src
Basesystem Module 15.7 ppc64le
-
Packagesgolang-github-prometheus-node_exporter
Prometheus exporter for machine metrics1.9.1-150100.3.38.1 lock rpm lock src
Basesystem Module 15.7 aarch64
-
Packagesgolang-github-prometheus-node_exporter
Prometheus exporter for machine metrics1.9.1-150100.3.38.1 lock rpm lock src
Basesystem Module 15.7 x86_64
-
Packagesgolang-github-prometheus-node_exporter
Prometheus exporter for machine metrics1.9.1-150100.3.38.1 lock rpm lock src