SUSE-SU-2026:22101-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622101-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22101-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:22101-1
Upstream
Related
Published
2026-06-11T10:08:55Z
Modified
2026-06-17T18:24:07Z
Summary
Security update for elemental-system-agent
Details

This update for elemental-system-agent fixes the following issue

  • CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277).

Changes for elemental-system-agent:

  • Update to version 0.3.16:
  • setup for immutable releases (#274)
  • align system-agent image publishing for signed releases (#270)
  • Bumo github.com/docker/cli to v29.2.0 and go.opentelemetry.io/otel to v1.43.0
  • run go mod tidy in /test folder
  • Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (bsc#1260277 CVE-2026-33186)
  • Bump github.com/docker/cli in /test
  • export CATTLE_NODE_NAME if SYSTEM_UPGRADE_NODE_NAME is set
  • use correct prefix for system-agent binary (#273)
  • checksum validation (#271)
  • Add validate subcommand for configuration validation (#250)
  • Update CODEOWNERS
  • Pin GH Actions to commit sha
  • chore: bump sles to 15.7
  • Extend remote plan e2e tests
  • Fix agent restart issue and introduce constants
  • chore: bump go to v1.25
  • Setup e2e test infrastructure
  • chores(deps): Bump k8s dependencies
  • Define linter rules
  • Fix CI failures
  • Introduce an extended Makefile
  • Switch workflows to use name makefile
  • Replace dapper with multi stage builds
  • Remove dapper scripts
  • Add multiple improvements for ignore files
  • fix: remove umask command from the system-agent unit-file
  • fix-system-agent-umask
  • [1.34] bumped dependencies for 1.34 support (#242)
  • Bump K8s patch level to 1.33.5 and Go patch level to 1.24.6
  • fix: properly handle traps after unsuccessful SUC job execution
  • fix: do not unconditionally reset failure-counts
  • fix: remove resetFailureCountOnStartup, always reset failure counts on first start
  • un-rc wrangler and lasso
  • drop windows 2019 when running PR CI
  • Update to version 0.3.13:
  • Bumped dependencies for k8s v1.33
  • Add delete for plan.File
  • fix dispatch
  • fix: add retry logic for one time instruction
  • Get UID/GID for current user in write file_test.go
  • Update secrets for dispatch
  • fix golangci
  • support k8s 1.32.2
  • Add GitHub App token generation and dispatch job for System Agent Upgrade workflow.
  • Add ResetFailureCountOnServiceRestart, if true reset plan failure count after each restart of the system-agent
  • Bump wharfie to v0.6.7
  • Add tests and update CI
  • Windows updates
  • Update to version 0.3.9:
  • Properly install grep and kubectl into the SUC image (#196)
  • Add default fallback values (/opt/rke2/bin, /opt/bin) to the PATH if /usr/local/bin is read-only (#195)
  • use bci-base to run zypper then layer the result onto bci-micro (#194)
  • Change base images to bci-micro (#169)
  • Add CATTLE_AGENT_FALLBACK_PATH
  • Fix if statement in install.sh
  • bump Go version to 1.22, kube-related modules to v0.29.7 to eliminate CVEs
  • Update module github.com/rancher/wharfie to v0.6.6
References

Affected packages

SUSE:Linux Micro 6.0 / elemental-system-agent

Package

Name
elemental-system-agent
Purl
pkg:rpm/suse/elemental-system-agent&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.3.16-1.1

Ecosystem specific

{
    "binaries":  [
        {
            "elemental-system-agent":  "0.3.16-1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22101-1.json"