openSUSE-SU-2026:21882-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21882-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21882-1
Upstream
CVE (8)
Related
Published
2026-09-19T22:39:23Z
Modified
2026-09-25T18:24:22Z
Summary
Security update for google-osconfig-agent
Details

This update for google-osconfig-agent fixes the following issues:

  • CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276722).
  • CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118).
  • CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597).
  • CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297).
  • CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414).
  • CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967).

Changes for google-osconfig-agent:

  • Update to version 20260911.00
  • Add support for all possible SCALIBR os extractor for linux (#1052)
  • Migrate presubmits from deb11 to deb12 (#1050)
  • Bump the go_modules group across 1 directory with 3 updates (#1047)
  • Introduce E2E v2 framework and inventory tests (#1039)
  • Remove test case for asserting JSON marshal error from task_state.go (#1045)
  • security: pin GitHub actions to commit SHAs in CodeQL workflow (#1042)
  • Add Configuration for SCALIBR (#1034)
  • add CheckState and Cleanup tests (#1008)
  • Improve unit tests for osinfo/osinfo_linux.go (#1020)
  • Bump github.com/go-git/go-git/v5 (#1036)
  • Bump cloud.google.com/go/auth from 0.18.0 to 0.22.0 (#1032)
  • Bump golang.org/x/crypto from 0.52.0 to 0.54.0 (#1028)
  • authenticate cloud build to use docker registry (#1030)
  • Migrate e2e build to internal image (#1024)
  • Upgrade google.golang.org/grpc to new version. (#1023)
  • Improve unit tests for ospatch/yum_update.go (#1012)
  • Improve unit tests for ospatch/updates.go (#1011)
  • Add unit tests for config/package_resource.go PART 2 (#1005)
  • Add unit tests for config/package_resource.go PART 1 (#1003)
  • Add unit tests for policies/local.go (#1015)
  • Add unit tests for repository_resource.go (#1002)
  • Add unit tests for installrecipe.go part 2 (#993)
  • Add unit tests for scalibr.go (#1019)
  • Add unit tests for installrecipe.go part 1 (#992)
  • Add test cases for policies/recipes/recipedb.go (#989)
  • Bump golang.org/x/crypto (#1021)
  • Add unit tests for policies/recipes/steps.go PART 3 (#976)
  • Add unit tests for policies/recipes/steps.go PART 2 (#975)
  • Bump golang.org/x/net (#1017)
  • upgrade x/net package. (#1018)
  • Add test cases for config/file_resource.go (#988)
  • Add unit tests for policies/recipes/artifacts.go (#985)
  • Add unit tests for policies/recipes/steps.go PART 1 (#974)
  • Add tests & bugfix for packages/trace.go (#939)
  • Add unit tests for agentendpoint/agentendpoint_beta.go (#983)
  • Replace yum install with yum update (#1009)
  • Bump github.com/containerd/containerd (#1013)
  • Add unit tests for policies/apt.go PART 2 (#957)
  • Add test cases for agentendpoint/task_state.go (#984)
  • Remove deprecated rhel-sap images and add new ones (#1007)
  • Add test cases for clog/clog.go (#986)
References

Affected packages

openSUSE:Leap 16.0 / google-osconfig-agent

Package

Name
google-osconfig-agent
Purl
pkg:rpm/opensuse/google-osconfig-agent&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20260911.00-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "google-osconfig-agent": "20260911.00-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21882-1.json"