SUSE-SU-2026:22075-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622075-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22075-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:22075-1
Upstream
CVE (9)
Related
Published
2026-06-10T07:45:47Z
Modified
2026-06-13T18:24:14Z
Summary
Security update for elemental-operator
Details

This update for elemental-operator fixes the following issue

  • CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277).

Changes for elemental-operator:

  • Changes on top of v1.7.5:
  • 41f54076 Fix reference in labels
  • 3bdb9321 Adapt labels to pass OBS container checks
  • Update to v1.7.5:
  • ecfa8d9c Bump unit test environment artifacts
  • 03803c72 Bump test environment tools in Makefile
  • bc886323 Update auto-generated code (make generate)
  • f4d26385 Bump controller generator to version 0.19
  • a7fe515d Bump golangci/golangci-lint-action
  • b45c5e56 Bump to Dockerfiles and spec to go1.25
  • a7d78295 Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186)
  • 2c012c2e Bump golang.org/x/net to v0.55.0, includes fixes for:
  • bsc#1266789 bsc#1265921 bsc#1267197 bsc#1267168 bsc#1251679
  • 46e7c635 Update headers to 2026
References

Affected packages

SUSE:Linux Micro 6.1 / elemental-operator

Package

Name
elemental-operator
Purl
pkg:rpm/suse/elemental-operator&distro=SUSE%20Linux%20Micro%206.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.7.5-slfo.1.1_1.1

Ecosystem specific

{
    "binaries":  [
        {
            "elemental-register":  "1.7.5-slfo.1.1_1.1",
            "elemental-support":  "1.7.5-slfo.1.1_1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22075-1.json"