Security update for elemental-toolkit, elemental-operator
This update for elemental-toolkit, elemental-operator fixes the following issues: elemental-operator: - Update to v1.7.4: * Bump github.com/rancher-sandbox/go-tpm and its dependencies This bump includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * Install yip config files in before-install step * Revert "Do not delete ManagedOSVersions by default" * Set default channel variable names consistent with OS version * Do not delete ManagedOSVersions by default * Include -channel suffix to channel names * OS channel: enable baremetal channel by default elemental-toolkit: - Update to v2.2.7: * Bump toolkit build to go 1.24 * Bump golang.org/x/crypto library This bumg includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * bsc#1253581 (CVE-2025-47913) * bsc#1253901 (CVE-2025-58181) * bsc#1254079 (CVE-2025-47914) - Update to v2.2.5: * Permissive mode for green selinux * Adapt code and unit tests * Minor change to lookup devices using blkid
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for elemental-toolkit, elemental-operator fixes the following issues: elemental-operator: - Update to v1.7.4: * Bump github.com/rancher-sandbox/go-tpm and its dependencies This bump includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * Install yip config files in before-install step * Revert "Do not delete ManagedOSVersions by default" * Set default channel variable names consistent with OS version * Do not delete ManagedOSVersions by default * Include -channel suffix to channel names * OS channel: enable baremetal channel by default elemental-toolkit: - Update to v2.2.7: * Bump toolkit build to go 1.24 * Bump golang.org/x/crypto library This bumg includes few CVE fixes: * bsc#1241826 (CVE-2025-22872) * bsc#1241857 (CVE-2025-22872) * bsc#1251511 (CVE-2025-47911) * bsc#1251679 (CVE-2025-58190) * bsc#1253581 (CVE-2025-47913) * bsc#1253901 (CVE-2025-58181) * bsc#1254079 (CVE-2025-47914) - Update to v2.2.5: * Permissive mode for green selinux * Adapt code and unit tests * Minor change to lookup devices using blkid
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1241826
- https://bugzilla.suse.com/1241857
- https://bugzilla.suse.com/1251511
- https://bugzilla.suse.com/1251679
- https://bugzilla.suse.com/1253581
- https://bugzilla.suse.com/1253901
- https://bugzilla.suse.com/1254079
- https://www.suse.com/security/cve/CVE-2025-22872
- https://www.suse.com/security/cve/CVE-2025-47911
- https://www.suse.com/security/cve/CVE-2025-47913
- https://www.suse.com/security/cve/CVE-2025-47914
- https://www.suse.com/security/cve/CVE-2025-58181
- https://www.suse.com/security/cve/CVE-2025-58190
- https://www.suse.com/support/update/announcement/2026/suse-su-202620357-1/