FlawAtlas
Search the atlas
OPENSUSE-SU-2026:21574-1 Not scored

Security update for amazon-ecs-init

This update for amazon-ecs-init fixes the following issue: Update to version 1.106.0. Security issues fixed: - CVE-2026-10722: github.com/cilium/ebpf: interger overflow when performing BTF string offset boundary check can lead to crash when malformed ELF/BTF input is parsed (bsc#1267794). Other updates and bugfixes: - Version 1.106.0: * Feature - Feature - Add FIS-driven DNS refresh add-sources endpoint for network-latency and network-packet-loss faults (#5029) * Enhancement - Enhancement: Update SSM Agent version to 3.3.4624.0 for ECS exec (#5054) * Enhancement - Backfill host DNS config on isolated platform (#5047) * Enhancement - Bump github.com/aws/smithy-go from 1.27.3 to 1.27.4 in /agent (#5051) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/credentials in /ecs-agent, /agent and /ecs-init to 1.19.29 (#5050) * Enhancement - Bump actions/setup-go from 6 to 7 in /.github/workflows (#5049) * Enhancement - Update Go version to 1.25.12 (#5048) * Enhancement - Bump github.com/vishvananda/netlink from 1.2.1-beta.2 to 1.3.1 in /ecs-agent, /agent and /ecs-init (#5037) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.22 to 1.19.28 in /agent (#5038) * Enhancement - Bump github.com/hectane/go-acl from 0.0.0-20190604041725-da78bae5fc95 to 1.0.0 in /agent (#5022) * Enhancement - chore(deps): bump github.com/cilium/ebpf from v0.16.0 to v0.22.0 in /agent (#5034) * Enhancement - Bump golang.org/x/net from 0.48.0 to 0.55.0 in /ecs-agent/daemonimages/csidriver (#5031) * Enhancement - api-2.json: Add CONFIDENTIAL_PARTITION and attestationPolicy to api model (#5033) * Bugfix - Fix flaky TestHostResourceManagerTrickleQueue integration test (#5026)

Exploit probability Not scored
Published August 12, 2026
Required by Not available
Last source change August 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 amazon-ecs-init

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:21574-1

This update for amazon-ecs-init fixes the following issue: Update to version 1.106.0. Security issues fixed: - CVE-2026-10722: github.com/cilium/ebpf: interger overflow when performing BTF string offset boundary check can lead to crash when malformed ELF/BTF input is parsed (bsc#1267794). Other updates and bugfixes: - Version 1.106.0: * Feature - Feature - Add FIS-driven DNS refresh add-sources endpoint for network-latency and network-packet-loss faults (#5029) * Enhancement - Enhancement: Update SSM Agent version to 3.3.4624.0 for ECS exec (#5054) * Enhancement - Backfill host DNS config on isolated platform (#5047) * Enhancement - Bump github.com/aws/smithy-go from 1.27.3 to 1.27.4 in /agent (#5051) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/credentials in /ecs-agent, /agent and /ecs-init to 1.19.29 (#5050) * Enhancement - Bump actions/setup-go from 6 to 7 in /.github/workflows (#5049) * Enhancement - Update Go version to 1.25.12 (#5048) * Enhancement - Bump github.com/vishvananda/netlink from 1.2.1-beta.2 to 1.3.1 in /ecs-agent, /agent and /ecs-init (#5037) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.22 to 1.19.28 in /agent (#5038) * Enhancement - Bump github.com/hectane/go-acl from 0.0.0-20190604041725-da78bae5fc95 to 1.0.0 in /agent (#5022) * Enhancement - chore(deps): bump github.com/cilium/ebpf from v0.16.0 to v0.22.0 in /agent (#5034) * Enhancement - Bump golang.org/x/net from 0.48.0 to 0.55.0 in /ecs-agent/daemonimages/csidriver (#5031) * Enhancement - api-2.json: Add CONFIDENTIAL_PARTITION and attestationPolicy to api model (#5033) * Bugfix - Fix flaky TestHostResourceManagerTrickleQueue integration test (#5026)

View original source

05 / REFERENCES

Further evidence