Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20878-1

Опубликовано: 02 июн. 2026
Источник: suse-cvrf

Описание

Security update for sdbootutil

This update for sdbootutil fixes the following issues

Security issue:

  • CVE-2026-25701: use of fixed directory /tmp/pcrlock.d.back in sdbootutil-update-predictions.service (bsc#1258241).

Non security issues:

Update to version 1+git20260506.25d47bf:

  • TPM based system does not auto-unlock encryption (bsc#1257612).
  • openQA test fails in reboot_after_installation - sdbootutil does not honor timeout set by user (bsc#1258944).
  • Installation with Systemd-boot fails when Turkish language is selected (bsc#1253652).
  • armv7 installer requires sdbootutil and shim on armv7 (bsc#1254865).
  • sdbootutil default entry not updated after update from 20250411 to 20250522 (bsc#1243889).
  • sdbootutil: consistent naming conventions used for key/pin ? (bsc#1252871).
  • UPDATE_NVRAM is NO when BLS bootloader is used (bsc#1247952).
  • Use tmpfiles.d for /var directories (jsc#PED-14900).
  • yast reports "Cannot enroll authentication" during fresh install of tumbleweed (bsc#1256775).

Список пакетов

openSUSE Leap 16.0
sdbootutil-1+git20260506.25d47bf-160000.1.1
sdbootutil-bash-completion-1+git20260506.25d47bf-160000.1.1
sdbootutil-dracut-measure-pcr-1+git20260506.25d47bf-160000.1.1
sdbootutil-enroll-1+git20260506.25d47bf-160000.1.1
sdbootutil-jeos-firstboot-enroll-1+git20260506.25d47bf-160000.1.1
sdbootutil-kernel-install-1+git20260506.25d47bf-160000.1.1
sdbootutil-snapper-1+git20260506.25d47bf-160000.1.1
sdbootutil-tukit-1+git20260506.25d47bf-160000.1.1

Описание

An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like: * gain access to possible private information found in /var/lib/pcrlock.d * manipulate the data backed up in /tmp/pcrlock.d.bak, therefore violating the integrity of the data should it be restored. * overwrite protected system files with data from /var/lib/pcrlock.d by placing symlinks to existing files in the directory tree in /tmp/pcrlock.d.bak. This issue affects sdbootutil: from ? before 5880246d3a02642dc68f5c8cb474bf63cdb56bca.


Затронутые продукты
openSUSE Leap 16.0:sdbootutil-1+git20260506.25d47bf-160000.1.1
openSUSE Leap 16.0:sdbootutil-bash-completion-1+git20260506.25d47bf-160000.1.1
openSUSE Leap 16.0:sdbootutil-dracut-measure-pcr-1+git20260506.25d47bf-160000.1.1
openSUSE Leap 16.0:sdbootutil-enroll-1+git20260506.25d47bf-160000.1.1

Ссылки