SUSE-SU-2026:22066-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622066-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22066-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:22066-1
Upstream
CVE (9)
Related
Published
2026-06-10T08:12:23Z
Modified
2026-06-13T18:24:17Z
Summary
Security update for elemental-operator
Details

This update for elemental-operator fixes the following issue

  • CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277).

Changes for elemental-operator:

  • Fix substitution
  • Fix reference in labels
  • Adapt labels to pass OBS container checks
  • Update to version 1.6.11:
  • Bump unit test environment artifacts
  • Bump test environment tools in Makefile
  • Bump actions
  • Refresh auto-generated code (make run)
  • Bump controller generator to version 0.19
  • Bump golangci/golangci-lint-action
  • Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186)
  • Update spec and Dockerfiles to use go1.25
  • Bump golang.org/x/net to v0.55.0, includes fixes for:
  • bsc#1266789 bsc#1265921 bsc#1267197 bsc#1267168 bsc#1251679
  • Update year in header
  • Remove labeler workflow
References

Affected packages

SUSE:Linux Micro 6.0 / elemental-operator

Package

Name
elemental-operator
Purl
pkg:rpm/suse/elemental-operator&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.11-1.1

Ecosystem specific

{
    "binaries":  [
        {
            "elemental-register":  "1.6.11-1.1",
            "elemental-support":  "1.6.11-1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22066-1.json"