gpp_maybe
Security update for sccache
SUSE-SLE-Module-Development-Tools-15-SP7-2026-3674
This update for sccache fixes the following issues: - CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274146). - CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response Header Values (bsc#1273881). - CVE-2026-66754: rouille: remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL (bsc#1273884). - CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding Desynchronization (bsc#1273886). - CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access Control Bypass (bsc#1273888). Changes for sccache: - Update to version 0.17.0~1: * Add experimental concurrent cache support * Release 0.17.0 * tests: pin libc in the dist test crate * doc: clarify server-side outputs and drop 'recommended mode' claim * doc: document SCCACHE_CLIENT_SIDE env var * doc: document client-side and direct modes in Architecture.md * Fix description of Unix socket-based Redis connection * server: remove redundant async block in start_compile_task * server: simplify bind() request loops with ? instead of manual match arms * Add support for arg files in Rust (#2782) * feat: support S3 SSE-KMS with AWS-managed and customer-managed keys (#2770) * abort compile tasks and associated subprocesses when a client disconnects * treat -ivfsoverlay as a preprocessor-only argument * gcc: refine response-file tokenizer visibility and whitespace handling * integration: convert cmake 4.x modules XFAIL test to a passing test * gcc/clang: cache and distribute builds using quoted @response files * fix: Fix ToolchainPackager cfg gate to build on ppc64le/s390x * fix: make gcc diagnostics color output work the same as for rustc * implement client-side mode * split handle_compile_response so that the compilation result can be handled separately * implement IpcStorage -- Storage backend over IPC * extend wire protocol with storage RPCs * implement AddAssign for ServerStats and related types * add Storage::get_path for direct file access * implement get_raw/put_raw on MultiLevelStorage * add client_side_mode config flag (SCCACHE_CLIENT_SIDE) * Extract new_client_runtime() helper to DRY up client runtime creation * Clarify single-threaded runtime rationale comment (grammar) * fix: use single-threaded tokio runtime in sccache dist-client * fix: use single-threaded tokio runtime in sccache client * fix: handle disabled cache backend features in multilevel chain * Fix ldd output parsing: remove .exists() check that failed on systems where the symlink source path does not exist locally (e.g. aarch64) * Fix cfg guard for PanicToolchainPackager to also cover non-x86_64 Linux architectures (e.g. aarch64)
-
Release DateAug 21 2026
-
ReferencesBugzilla: 1273881, 1273884, 1273886, 1273888, 1274146
CVEs: CVE-2026-25541, CVE-2026-66746, CVE-2026-66754, CVE-2026-67181, CVE-2026-67182 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.7 ppc64le
-
Packagessccache
A compiler caching tool for Rust, C and C++ with optional cloud storage0.17.0~1-150600.10.14.1 lock rpm lock src
Development Tools Module 15.7 x86_64
-
Packagessccache
A compiler caching tool for Rust, C and C++ with optional cloud storage0.17.0~1-150600.10.14.1 lock rpm lock src
Development Tools Module 15.7 s390x
-
Packagessccache
A compiler caching tool for Rust, C and C++ with optional cloud storage0.17.0~1-150600.10.14.1 lock rpm lock src
Development Tools Module 15.7 aarch64
-
Packagessccache
A compiler caching tool for Rust, C and C++ with optional cloud storage0.17.0~1-150600.10.14.1 lock rpm lock src