SCA: security update for linuxfabrik-lib (GHSA-rh9c-rqvg-f7pr)

medium Tenable Self-Hosted Container Security Plugin ID 446088

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API
integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins.
Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the
first or second element of a --test CSV argument as a filesystem path and returned the file contents as
simulated standard output or standard error without path confinement. The hidden but production-accessible
--test argument was accepted by sudo-authorized plugins, so an attacker controlling the nagios or icinga
account could use check-plugins/deb-updates/deb-updates with its default QUERY=1 to disclose every line of
a root-readable file. Approximately 22 other plugins exposed filtered content or a root file existence and
readability oracle through the same helper, while check-plugins/network-bonding/network-bonding and check-
plugins/openstack-swift-stat/openstack-swift-stat had direct read paths that bypassed the helper. The
library fix confines fixture reads to the invoking plugin's unit-test directory and refuses unsafe
anchors, and the plugin fix routes the two bypasses through that helper. These issues are fixed in
linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0. (CVE-2026-73974)

Solution

Update the linuxfabrik-lib library and its related packages to version 6.1.0 or later.

See Also

https://github.com/advisories/GHSA-rh9c-rqvg-f7pr

Plugin Details

Severity: Medium

ID: 446088

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/19/2026

Updated: 8/19/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-73974

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/18/2026

Vulnerability Publication Date: 8/18/2026

Reference Information

CVE: CVE-2026-73974