openSUSE-SU-2026:21884-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21884-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21884-1
Upstream
CVE (5)
Related
Published
2026-09-20T03:28:14Z
Modified
2026-09-25T18:23:10Z
Summary
Security update for amazon-ssm-agent
Details

This update for amazon-ssm-agent fixes the following issues:

  • CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278681).
  • CVE-2026-71556: github.com/go-git/go-git/v5: arbitrary file read/write via symbolic link resolution (bsc#1276981).
  • CVE-2026-71557: github.com/go-git/go-git/v5: malicious reference names may modify files outside the reference storage (bsc#1276994).

Changes for amazon-ssm-agent:

  • Update to version 3.3.5390.0
  • Bump github.com/gorilla/websocket from v1.4.2 to v1.5.3
  • Bump golang.org/x/crypto from v0.53.0 to v0.56.0
  • Bump golang.org/x/net from v0.56.0 to v0.57.0
  • Bump golang.org/x/sys from v0.46.0 to v0.47.0
  • Upgrade GoLang version from 1.25 to 1.26
  • Mint control-channel token after dial to fix AZ-fault token expiry
  • Resume patch documents interrupted by an external shutdown
  • Use systemctl for systemd in aws: configureDocker on Amazon Linux
  • Update greengrass component version to 1.3.5
  • Update to version 3.3.5226.0
  • Add bounds check for HeaderLength in AgentMessage Deserialize
  • Bump github.com/go-git/go-git/v5 to v5.19.2
  • Bump golang.org/x/sync to v0.21.0
  • Detect Azure Linux and potential future unregistered Linux platforms
  • Fix Windows session command parsing by removing shlex
  • Fix shell injection in Windows domainjoin plugin parameters
  • Prevent control channel deadlock on ProcessorBufferFull
  • Revert migration from aws-sdk-go v1 to aws-sdk-go-v2 change
  • Update the logic for loading RegistrationInfo
  • Upgrade Go version to 1.25.13
  • Update to version 3.3.5068.0
  • Migrate from aws-sdk-go v1 to aws-sdk-go-v2
  • Fix flaky registration/connection channel tests
  • Sync AWS SDK fork in extra/ with multicloud vendor changes
  • Harden function create file with permissions in a single syscall
  • Upgrade Go version to 1.25.12
  • Bump golang.org/x/net@v0.55.0 to golang.org/x/net@v0.56.0
  • Fix loopback bypass in remote-host port forwarding denylist
  • Update to version 3.3.4851.0
  • Add ECS/EKS credential endpoints and loopback to port-forward denylist
  • Canonicalize IP addresses before port-forwarding denylist check
  • Pass the ActiveDirectory domain password via stdin using -y /dev/stdin instead of the -w flag
  • Fix false StuckAtInProgress timeout for associations with rate >= 2h
  • Fix non-interactive session big file transfer issues
  • Prevent ssm-user race condition with flock-based serialization
  • Send AWS::EC2::Instance as source type when registered with provider EC2
  • Validate process name in orphan worker detection
  • Update to version 3.3.4793.0
  • Add multicloud support enabling SSM Agent registration with Azure cloud providers
  • Add support for the upcoming public key in the agent code
References

Affected packages

openSUSE:Leap 16.0 / amazon-ssm-agent

Package

Name
amazon-ssm-agent
Purl
pkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.3.5390.0-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "amazon-ssm-agent": "3.3.5390.0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21884-1.json"