Security update for wicked
This update for wicked fixes the following issues: Changes in wicked: - Update to version 0.6.79 - Fix an indirect remote shell command injection via unsanitized dhcp strings and leaseinfo dump (bsc#1265221,CVE-2026-44932): - Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before. - Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833. - Discard string values containing single-quotes in other options. - Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78.
Security update for wicked
Description
This update for wicked fixes the following issues: Changes in wicked: - Update to version 0.6.79 - Fix an indirect remote shell command injection via unsanitized dhcp strings and leaseinfo dump (bsc#1265221,CVE-2026-44932): - Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before. - Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833. - Discard string values containing single-quotes in other options. - Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78.
Affected software
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:20949-1
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6aab497c55bf5e2cf5990e67
Added to database: 09/17/2026, 01:59:24 UTC
Last updated: 09/17/2026, 02:02:24 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.