shield
Recommended update for supportutils-scrub
SUSE-SLE-Module-Basesystem-15-SP7-2026-1401
This update for supportutils-scrub fixes the following issues: - Update to version 1.2.0 + New input modes * Folder mode: pass any directory, output written to {dir}_scrubbed/ * Stdin/pipe mode: cat log | supportutils-scrub (scrubbed text to stdout) * Single file mode: process a plain file, output to {file}_scrubbed * Multi-archive mode: process several .txz/.tgz in one run with shared mappings ensuring consistent obfuscation across all archives + Improved automatic entity detection for pipe/file/stdin modes * PAM log patterns: pam_unix([...]) and unix_chkpwd extract usernames * logname= field now recognised as username source * NFS server lines extract hostname and domain automatically * RFC 5424 syslog hostname (field repeated >= 3 lines) auto-detected + Fixed domain parser false positives * Added TLD allowlist rejecting D-Bus names, container runtime interfaces, version strings, systemd scopes and hardware IDs + Bug fixes * Fixed IP pool exhaustion crash when mixed prefix lengths allocated - Update to version 1.1.0 + Major enhancement: Subnet-aware IP obfuscation * Maps entire IPv4 subnets to fake subnets preserving host offsets * Gateway .1 remains .1, broadcast .255 remains .255 * Maintains network topology for effective troubleshooting + Added PCAP obfuscation support with tcprewrite integration * Rewrites packet captures using same subnet mappings as logs * Ensures consistency across supportconfigs and network traces * Exports tcprewrite-compatible subnet rules + Enhanced mapping file structure * Added 'subnet' section with subnet-to-subnet translations * Added 'state' section tracking IP pool allocation cursors * Enables reproducible obfuscation across multiple runs + Improved IP processing * Two-pass processing: learns subnets then applies mapping * Preserves special IPs (0.0.0.0, 127.0.0.1, multicast) * Protects version strings from incorrect obfuscation + Enhanced domain and hostname extraction * Multiple source parsing (resolv.conf, hosts, NFS, NTP) * Fixed word boundary detection preventing partial replacements * Added minimum length requirements for hostnames + Security improvements * Dataset JSON files created with 0600 permissions * System users excluded from obfuscation + Added command-line options for PCAP processing * --rewrite-pcap: Enable PCAP rewriting mode * --pcap-in: Specify input PCAP files * --pcap-out-dir: Output directory for obfuscated PCAPs * --print-tcprewrite: Display tcprewrite command + Bug fixes * Fixed /32 host route handling * Corrected inline comment processing in hostnames * Resolved IPv6 subnet awareness issues * Fixed MAC address parsing false positives - Initial release version 1.0.0 + Basic obfuscation for supportconfig tarballs + Supports IP, domain, hostname, username, MAC, IPv6 + Configuration file support + Keyword-based obfuscation + Mapping file for consistency across runs
-
Release DateApr 16 2026
-
References
-
Typerecommended
-
Severitymoderate
cloud_download Downloads
Basesystem Module 15.7 x86_64
-
Packagessupportutils-scrub
Utility to sanitize and remove sensitive data from supportconfig tarballs1.2-150100.3.6.1 lock rpm lock src
Basesystem Module 15.7 s390x
-
Packagessupportutils-scrub
Utility to sanitize and remove sensitive data from supportconfig tarballs1.2-150100.3.6.1 lock rpm lock src
Basesystem Module 15.7 aarch64
-
Packagessupportutils-scrub
Utility to sanitize and remove sensitive data from supportconfig tarballs1.2-150100.3.6.1 lock rpm lock src
Basesystem Module 15.7 ppc64le
-
Packagessupportutils-scrub
Utility to sanitize and remove sensitive data from supportconfig tarballs1.2-150100.3.6.1 lock rpm lock src