FlawAtlas
Search the atlas
SUSE-SU-2026:2665-1 Not scored

Security update for google-osconfig-agent

This update for google-osconfig-agent fixes the following issues: - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260264). - CVE-2026-39821: Update golang.org/x/net/idna dependency (bsc#1266603). - CVE-2026-39827: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39828: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39829: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39830: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39831: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39832: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39833: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39834: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39835: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-42508: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-46595: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-46597: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-46598: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-33814: Update golang.org/x/net dependency (bsc#1265762). - CVE-2026-41506: Update github.com/go-git/go-git/v5 dependency (bsc#1264923). - CVE-2026-34986: Update github.com/go-jose/go-jose/v4 dependency (bsc#1262926). Other bugfixes: - Re-enable binary stripping and debuginfo (bsc#1210938).

Exploit probability Not scored
Published June 26, 2026
Required by Not available
Last source change June 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Public Cloud 12 google-osconfig-agent

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2665-1

This update for google-osconfig-agent fixes the following issues: - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260264). - CVE-2026-39821: Update golang.org/x/net/idna dependency (bsc#1266603). - CVE-2026-39827: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39828: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39829: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39830: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39831: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39832: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39833: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39834: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-39835: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-42508: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-46595: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-46597: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-46598: Update golang.org/x/crypto dependency (bsc#1266171). - CVE-2026-33814: Update golang.org/x/net dependency (bsc#1265762). - CVE-2026-41506: Update github.com/go-git/go-git/v5 dependency (bsc#1264923). - CVE-2026-34986: Update github.com/go-jose/go-jose/v4 dependency (bsc#1262926). Other bugfixes: - Re-enable binary stripping and debuginfo (bsc#1210938).

View original source

05 / REFERENCES

Further evidence