FlawAtlas
Search the atlas
SUSE-SU-2026:22101-1 Not scored

Security update for elemental-system-agent

This update for elemental-system-agent fixes the following issue - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277). Changes for elemental-system-agent: - Update to version 0.3.16: * setup for immutable releases (#274) * align system-agent image publishing for signed releases (#270) * Bumo github.com/docker/cli to v29.2.0 and go.opentelemetry.io/otel to v1.43.0 * run go mod tidy in /test folder * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (bsc#1260277 CVE-2026-33186) * Bump github.com/docker/cli in /test * export CATTLE_NODE_NAME if SYSTEM_UPGRADE_NODE_NAME is set * use correct prefix for system-agent binary (#273) * checksum validation (#271) * Add `validate` subcommand for configuration validation (#250) * Update CODEOWNERS * Pin GH Actions to commit sha * chore: bump sles to 15.7 * Extend remote plan e2e tests * Fix agent restart issue and introduce constants * chore: bump go to v1.25 * Setup e2e test infrastructure * chores(deps): Bump k8s dependencies * Define linter rules * Fix CI failures * Introduce an extended Makefile * Switch workflows to use name makefile * Replace dapper with multi stage builds * Remove dapper scripts * Add multiple improvements for ignore files * fix: remove umask command from the system-agent unit-file * fix-system-agent-umask * [1.34] bumped dependencies for 1.34 support (#242) * Bump K8s patch level to 1.33.5 and Go patch level to 1.24.6 * fix: properly handle traps after unsuccessful SUC job execution * fix: do not unconditionally reset failure-counts * fix: remove resetFailureCountOnStartup, always reset failure counts on first start * un-rc wrangler and lasso * drop windows 2019 when running PR CI - Update to version 0.3.13: * Bumped dependencies for k8s v1.33 * Add delete for plan.File * fix dispatch * fix: add retry logic for one time instruction * Get UID/GID for current user in write file_test.go * Update secrets for dispatch * fix golangci * support k8s 1.32.2 * Add GitHub App token generation and dispatch job for System Agent Upgrade workflow. * Add ResetFailureCountOnServiceRestart, if true reset plan failure count after each restart of the system-agent * Bump wharfie to v0.6.7 * Add tests and update CI * Windows updates - Update to version 0.3.9: * Properly install grep and kubectl into the SUC image (#196) * Add default fallback values (`/opt/rke2/bin`, `/opt/bin`) to the PATH if `/usr/local/bin` is read-only (#195) * use bci-base to run zypper then layer the result onto bci-micro (#194) * Change base images to `bci-micro` (#169) * Add CATTLE_AGENT_FALLBACK_PATH * Fix if statement in install.sh * bump Go version to 1.22, kube-related modules to v0.29.7 to eliminate CVEs * Update module github.com/rancher/wharfie to v0.6.6

Exploit probability Not scored
Published June 11, 2026
Required by Not available
Last source change June 17, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Micro 6.0 elemental-system-agent

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:22101-1

This update for elemental-system-agent fixes the following issue - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277). Changes for elemental-system-agent: - Update to version 0.3.16: * setup for immutable releases (#274) * align system-agent image publishing for signed releases (#270) * Bumo github.com/docker/cli to v29.2.0 and go.opentelemetry.io/otel to v1.43.0 * run go mod tidy in /test folder * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (bsc#1260277 CVE-2026-33186) * Bump github.com/docker/cli in /test * export CATTLE_NODE_NAME if SYSTEM_UPGRADE_NODE_NAME is set * use correct prefix for system-agent binary (#273) * checksum validation (#271) * Add `validate` subcommand for configuration validation (#250) * Update CODEOWNERS * Pin GH Actions to commit sha * chore: bump sles to 15.7 * Extend remote plan e2e tests * Fix agent restart issue and introduce constants * chore: bump go to v1.25 * Setup e2e test infrastructure * chores(deps): Bump k8s dependencies * Define linter rules * Fix CI failures * Introduce an extended Makefile * Switch workflows to use name makefile * Replace dapper with multi stage builds * Remove dapper scripts * Add multiple improvements for ignore files * fix: remove umask command from the system-agent unit-file * fix-system-agent-umask * [1.34] bumped dependencies for 1.34 support (#242) * Bump K8s patch level to 1.33.5 and Go patch level to 1.24.6 * fix: properly handle traps after unsuccessful SUC job execution * fix: do not unconditionally reset failure-counts * fix: remove resetFailureCountOnStartup, always reset failure counts on first start * un-rc wrangler and lasso * drop windows 2019 when running PR CI - Update to version 0.3.13: * Bumped dependencies for k8s v1.33 * Add delete for plan.File * fix dispatch * fix: add retry logic for one time instruction * Get UID/GID for current user in write file_test.go * Update secrets for dispatch * fix golangci * support k8s 1.32.2 * Add GitHub App token generation and dispatch job for System Agent Upgrade workflow. * Add ResetFailureCountOnServiceRestart, if true reset plan failure count after each restart of the system-agent * Bump wharfie to v0.6.7 * Add tests and update CI * Windows updates - Update to version 0.3.9: * Properly install grep and kubectl into the SUC image (#196) * Add default fallback values (`/opt/rke2/bin`, `/opt/bin`) to the PATH if `/usr/local/bin` is read-only (#195) * use bci-base to run zypper then layer the result onto bci-micro (#194) * Change base images to `bci-micro` (#169) * Add CATTLE_AGENT_FALLBACK_PATH * Fix if statement in install.sh * bump Go version to 1.22, kube-related modules to v0.29.7 to eliminate CVEs * Update module github.com/rancher/wharfie to v0.6.6

View original source

05 / REFERENCES

Further evidence