SUSE-SU-2026:2612-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262612-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2612-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2612-1
Upstream
CVE (22)
Related
Published
2026-06-24T09:01:18Z
Modified
2026-06-25T06:15:05Z
Summary
Security update for google-guest-agent
Details

This update for google-guest-agent fixes the following issues

Security issues:

  • CVE-2026-39821: Update golang.org/x/net/idna dependency (bsc#1266603).
  • CVE-2026-39827: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39828: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39829: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39830: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39831: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39832: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39833: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39834: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-39835: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-42508: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-46595: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-46597: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2026-46598: Update golang.org/x/crypto dependency (bsc#1266171).
  • CVE-2023-45288: golang.org/x/net/http2: close connections when receiving too many headers (bsc#1236533).
  • CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234563).
  • CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239334).
  • CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253889).
  • CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264).
  • CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265762).
  • CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262926).
References

Affected packages

SUSE:Linux Enterprise Micro 5.5
google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:rpm/suse/google-guest-agent&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20260529.00-150000.1.70.1

Ecosystem specific

{
    "binaries":  [
        {
            "google-guest-agent":  "20260529.00-150000.1.70.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2612-1.json"
SUSE:Linux Enterprise Module for Public Cloud 15 SP4
google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:rpm/suse/google-guest-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20260529.00-150000.1.70.1

Ecosystem specific

{
    "binaries":  [
        {
            "google-guest-agent":  "20260529.00-150000.1.70.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2612-1.json"
SUSE:Linux Enterprise Module for Public Cloud 15 SP5
google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:rpm/suse/google-guest-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20260529.00-150000.1.70.1

Ecosystem specific

{
    "binaries":  [
        {
            "google-guest-agent":  "20260529.00-150000.1.70.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2612-1.json"
SUSE:Linux Enterprise Module for Public Cloud 15 SP6
google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:rpm/suse/google-guest-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20260529.00-150000.1.70.1

Ecosystem specific

{
    "binaries":  [
        {
            "google-guest-agent":  "20260529.00-150000.1.70.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2612-1.json"
SUSE:Linux Enterprise Module for Public Cloud 15 SP7
google-guest-agent

Package

Name
google-guest-agent
Purl
pkg:rpm/suse/google-guest-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20260529.00-150000.1.70.1

Ecosystem specific

{
    "binaries":  [
        {
            "google-guest-agent":  "20260529.00-150000.1.70.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2612-1.json"