FlawAtlas
Search the atlas
SUSE-SU-2026:20244-1 Not scored

Security update for elemental-toolkit, elemental-operator

This update for elemental-toolkit, elemental-operator fixes the following issues: elemental-operator: - Update to version 1.6.10: * Remove 'latest' tag as this overlaps with the latest branch * Bump github.com/rancher-sandbox/go-tpm and its dependencies This bump includes fixes to some CVEs: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) elemental-toolkit: - Update to version 2.1.5: * Update headers for new year 2026 * Disable selinux in installer media - Update to version 2.1.4: * Remove leftovers in installer integration test * Bump to build against go 1.24 * Bump golang.org/x/crypto library This bump includes fixes to some CVEs: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * bsc#1253581 (CVE-2025-47913) * bsc#1253901 (CVE-2025-58181) * bsc#1254079 (CVE-2025-47914)

Exploit probability Not scored
Published January 15, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Micro 6.0 elemental-operator
SUSE:Linux Micro 6.0 elemental-toolkit

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:20244-1

This update for elemental-toolkit, elemental-operator fixes the following issues: elemental-operator: - Update to version 1.6.10: * Remove 'latest' tag as this overlaps with the latest branch * Bump github.com/rancher-sandbox/go-tpm and its dependencies This bump includes fixes to some CVEs: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) elemental-toolkit: - Update to version 2.1.5: * Update headers for new year 2026 * Disable selinux in installer media - Update to version 2.1.4: * Remove leftovers in installer integration test * Bump to build against go 1.24 * Bump golang.org/x/crypto library This bump includes fixes to some CVEs: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * bsc#1253581 (CVE-2025-47913) * bsc#1253901 (CVE-2025-58181) * bsc#1254079 (CVE-2025-47914)

View original source

05 / REFERENCES

Further evidence