FlawAtlas
Search the atlas
SUSE-SU-2026:20357-1 Not scored

Security update for elemental-toolkit, elemental-operator

This update for elemental-toolkit, elemental-operator fixes the following issues: elemental-operator: - Update to v1.7.4: * Bump github.com/rancher-sandbox/go-tpm and its dependencies This bump includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * Install yip config files in before-install step * Revert "Do not delete ManagedOSVersions by default" * Set default channel variable names consistent with OS version * Do not delete ManagedOSVersions by default * Include -channel suffix to channel names * OS channel: enable baremetal channel by default elemental-toolkit: - Update to v2.2.7: * Bump toolkit build to go 1.24 * Bump golang.org/x/crypto library This bumg includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * bsc#1253581 (CVE-2025-47913) * bsc#1253901 (CVE-2025-58181) * bsc#1254079 (CVE-2025-47914) - Update to v2.2.5: * Permissive mode for green selinux * Adapt code and unit tests * Minor change to lookup devices using blkid

Exploit probability Not scored
Published January 15, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Micro 6.1 elemental-operator
SUSE:Linux Micro 6.1 elemental-toolkit

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:20357-1

This update for elemental-toolkit, elemental-operator fixes the following issues: elemental-operator: - Update to v1.7.4: * Bump github.com/rancher-sandbox/go-tpm and its dependencies This bump includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * Install yip config files in before-install step * Revert "Do not delete ManagedOSVersions by default" * Set default channel variable names consistent with OS version * Do not delete ManagedOSVersions by default * Include -channel suffix to channel names * OS channel: enable baremetal channel by default elemental-toolkit: - Update to v2.2.7: * Bump toolkit build to go 1.24 * Bump golang.org/x/crypto library This bumg includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * bsc#1253581 (CVE-2025-47913) * bsc#1253901 (CVE-2025-58181) * bsc#1254079 (CVE-2025-47914) - Update to v2.2.5: * Permissive mode for green selinux * Adapt code and unit tests * Minor change to lookup devices using blkid

View original source

05 / REFERENCES

Further evidence