{"id":"SUSE-SU-2026:2438-1","summary":"Security update for alloy","details":"This update for alloy fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-4427: github.com/jackc/pgproto3/v2: improper validation of field length allows a malicious PostgreSQL server\n  to crash a client application via a DataRow message (bsc#1259919).\n- CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files\n  can lead to the consumption of corrupted files (bsc#1258099).\n- CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results\n  and lead to undefined behavior (bsc#1258609).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260317).\n- CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of\n  service (bsc#1262955).\n- CVE-2026-41602: github.com/apache/thrift: TFramedTransport frame size headers can lead to a uint32 integer overflow\n  (bsc#1263530).\n\nNon security issue:\n\n- Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815).\n- Update to version 1.16.1\n * Bug Fixes\n logging: Fix startup deadlock when components log before\n logging config is evaluated\n Update to Beyla 3.9.8\n Migrate from Docker to Moby\n- Use latest openSUSE Tumbleweed image for building web UI assets\n- Install nvm to set node version specified upstream\n- update to 1.16.0:\n * Features\n - Add clustering for loki.source.kubernetes_events (#6027)\n (3dbf587) (@petewall)\n - Add otelcol.auth.google client auth provider (#5526)\n (da99a66) (@dashpole, @clayton-cornell)\n - beyla.ebpf: Bump to v3.7.0 (#5966) (5126c2e) (@marctc)\n - database_observability: Add support for GCP Cloud SQL\n metadata (#5875) (5d23245) (@cristiangreco, @clayton-cornell)\n - database_observability: Make targets optional (#5924)\n (54664b2) (@matthewnolf)\n - database_observability: Update default excluded schemas and\n users (#6080) (b386fff) (@cristiangreco)\n - faro.receiver: Add sourcemap fetching from remote locations\n (#4614) (b6cb5da) (@Oxel40)\n - helm: Add support for global.image.pullPolicy (#6069)\n (2e2ce72) (@petewall)\n - helm: Allow configuring image pull policy for config reloader\n (#5923) (991539b) (@kalleep)\n - loki.secretfilter: Add label_timed_out option to mark\n timed-out log lines (#5898) (2ad8834) (@kleimkuhler)\n - loki.secretfilter: Add secrets_redacted_by_category_total\n metric combining rule and origin (#5855) (053a2f7)\n (@kleimkuhler)\n - loki.secretfilter: Change secretfilter to use go-re2 regex\n library instead of stdlib (#5909) (c16a660) (@mikefat)\n - loki.secretfilter: Remove redundant\n secrets_redacted_by_rule_total and secrets_redacted_by_origin\n metrics (#5970) (b16decb) (@kleimkuhler)\n - Oracle exporter can scrape more than one DB (#6008) (6fbad38)\n (@ptodev)\n - prometheus.exporter.cloudwatch: Upgrade YACE and drop\n aws-sdk-go v1 support (#5936) (f1c036d) (@x1unix)\n - prometheus.exporter.mysql: Update to mysqld_exporter 0.19.0\n (#5836) (4f49b57) (@cristiangreco)\n - prometheus.remote_write: Sync WAL with upstream Prometheus\n (#5907) (e74a91b) (@x1unix)\n - pyroscope: Add support for extra async-profiler CLI arguments\n (#5472) (9251e33) (@ivanape)\n - pyroscope: Replace Parca gRPC debuginfo upload with Pyroscope\n Connect API (#5891) (e7ea34a) (@korniltsev-grafanista)\n - pyroscope: Update debuginfo client for HTTP/1.1 upload API\n (#6037) (879d8e5) (@korniltsev-grafanista)\n - Change service stop command from 'sc' to 'net' (#5906)\n (450973d) (@mateuszdrab)\n - database_observability.mysql: Refactor explain plan loop\n batch size (#5894) (f0fcd6b) (@cristiangreco)\n - database_observability.postgres: Cleanup embedded exporter\n collectors on reconnection (#6079) (f30d9ae) (@cristiangreco)\n - database_observability.postgres: Fix EXPLAIN param count when\n placeholders repeat (#6082) (b612b81) (@rgeyer)\n - database_observability: Drop schema_detection from logs\n (#6076) (b0105cb) (@cristiangreco)\n - database_observability: Ensure connection_info_monitor\n goroutine exits on Stop (#5874) (1e3334b) (@cristiangreco)\n - deps: Update module github.com/aws/aws-sdk-go-v2/service/s3\n to v1.97.3 [SECURITY] (#6004) (38f4346)\n - deps: Update module github.com/go-git/go-git/v5 to v5.17.1\n [SECURITY] (#5934) (a5154af)\n - deps: Update module github.com/go-git/go-git/v5 to v5.18.0\n [SECURITY] (#6090) (0e59d64)\n - deps: Update module github.com/nwaples/rardecode/v2 to v2.2.0\n [SECURITY] (b44d51a) (@jharvey10)\n - deps: Update module\n go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp\n to v1.43.0 [SECURITY] (#6016) (d92c5c0)\n go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp\n to v1.43.0 [SECURITY] (#6017) (e655bbc)\n - deps: Update module go.opentelemetry.io/otel/sdk to v1.43.0\n [SECURITY] (#6018) (94006e8)\n - deps: Update some minor go dep versions (#5896) (4ddd0ed)\n (@jharvey10)\n - go: Update alloy builder image to Go 1.25.9 (#6012) (d2ae8b8)\n (@x1unix)\n - go: Upgrade to Go 1.25.9 (#6019) (d777ed1) (@x1unix,\n @kalleep)\n - Helm: RBAC template handles empty rule arrays (#4860)\n (c9430e9) (@naptalie, @dehaansa, @kalleep)\n - loki.process: Eliminate per-stream goroutines in multiline\n stage (#6036) (c089e2e) (@kgeckhart)\n - loki.process: Prevent stage.structured_metadata from adding\n the same metadata several times (#5965) (0ec8a26) (@kalleep,\n @thampiotr)\n - loki.process: Wrap template in a custom type and move\n validation to syntax.Validator (#5910) (700dd7d) (@kalleep)\n - prometheus.exporter.postgres: Close DB connections on update\n (#6021) (8da97cf) (@kalleep)\n - prometheus.scrape: Update scrape_native_histograms to be\n updated at runtime (#6087) (18b205c) (@kalleep)\n - pyroscope.ebpf: Fix deadlock on LRU eviction in irsymcache\n (#5911) (03ca563) (@luweglarz)\n - pyroscope.ebpf: Move Pyroscope ebpf metrics registration\n after component error handling (#5540) (a3c57c0) (@crbednarz,\n @marcsanmi)\n - pyroscope: Set user agent on debuginfo connect-go client\n (#6022) (38ad1ef) (@korniltsev-grafanista)\n - ui: Large arguments are downloaded as files instead of\n rendered (#5268) (26c67b3) (@ptodev)\n - Update go-m1cpu v0.1.7 -\u003e v0.2.1 to fix M5 chip crash (#6034)\n (7fa0cbc) (@ymotongpoo)\n - windows-installer: Increase service restart on failure delays\n (#5969) (add15b1) (@rknightion)\n- add script to package webassets inside a podman container, to not\n endanger or pollute the host system with npm\n- update to 1.15.1:\n goroutine exits on Stop\n * CVE-2026-34986: Fix panic in JWE decryption (bsc#1262955)\n- update to 1.15.0:\n * BREAKING CHANGES\n - otelcol: Upgrade to OTel Collector v0.147.0\n - Renamed undocumented metrics that was previously prefixed\n with \u003ccomponent_id\u003e\u003cmetric_name\u003e to\n loki_source_awsfirehose\u003cmetric_name\u003e\n * Security\n CVE-2026-26958: Update filippo.io/edwards25519 to version 1.1.1\n (bsc#1258609).\n - alloy-mixin: Add filters, groupBy, and multi-select dashboard\n variables\n - beyla.ebpf: Add support for Prometheus native histograms\n - beyla.ebpf: Bump Beyla to v3.6\n - converters: Support converting Promtail limits_config\n - database_observability.mysql: Add filtering of query samples\n and wait events by minimum duration\n - database_observability.mysql: Embed prometheus exporter\n within db-o11y component\n - database_observability.postgres: Add configurable limit to\n pg_stat_statements query\n - database_observability.postgres: Embed prometheus exporter\n - database_observability: Promote components to stable\n - Expose Functionality to Handle syslogs with Empty MSG Field\n - loki.process: Support structured metadata as source type of\n stage.labels for loki.process\n - loki.secretfilter: Add sampling for secretfilter entries\n - loki.source.gcplog: Add alloy config for MaxOutstandingBytes\n and MaxOutstandingMessages\n - loki.write: Add loki pipeline latency metric\n - mixin: Update loki dashboard\n - otelcol.receiver.datadog: Expose intake proxy and\n trace_id_cache_size settings\n - prometheus.exporter.cloudwatch: Use aws-sdk-go-v2 by default\n - pyroscope.ebpf: Add comm, pid labels and kernel frame options\n- update to 1.14.1:\n - Correctly handle the deprecated topic field in\n otelcol.receiver.kafka configuration\n - loki.process: Protect against json that does not look like\n docker json format\n - loki.source.file: Keep positions for compressed files when\n reading is finished\n - prometheus.scrape: Update arguments and targets even if\n scrape_native_histograms and extra_metrics are updated\n- update to 1.14.0:\n - loki.secretfilter: Some config options are removed entirely:\n partial_mask (replaced with redact_percent), allowlist (now\n controlled with custom gitleaks config), enable_entropy,\n include_generic, types (now controlled with custom gitleaks\n config).\n - otelcol.receiver.prometheus: otelcol.receiver.prometheus no\n longer sets start times of OTLP metrics.\n * Security:\n- update to 1.13.2:\n - Expose missing otelcol.processor.tail_sampling options\n - mixin: Add zipped dashboards as a release artifact\n - profiler: Backport Go 1.26 gopclntab textStart fix\n - prometheus.exporter.postgres: Update version of the exporter\n fork to fix pg_settings\n - pyroscope.ebpf: Backport dotnet nibble map fix\n- update to 1.13.1:\n - timeout before starting new ones\n- update to 1.13.0:\n - otelcol: Upgrade to OTel Collector v0.142.0\n - otelcol.receiver.kafka: The global topic attribute has been\n deleted; use the topics attributes inside the logs, metrics,\n and traces blocks instead.\n - otelcol.exporter \u003e sending_queue \u003e batch \u003e min_size changed\n from 8192 to 2000 and max_size changed from 0 to 3000\n - Add a virtual_node_peer_attributes and\n virtual_node_extra_label arguments to\n otelcol.connector.servicegraph\n - Add an otelcol.processor.metric_start_time component\n - Add job level period, length, and add_cloudwatch_timestamp\n options and labels_snake_case to CW exporter\n - Add missing configuration parameter\n deployment_name_from_replicaset to k8sattributes processor\n - Add parcas symbols upload to pyroscope.ebpf\n - Add sharding for loki.write\n - Add unexposed otel engine and extension to codebase and\n change build structure\n - beyla.ebpf: Add meta_cache_address to\n beyla.ebpf.attributes.kubernetes\n - beyla.ebpf: Upgrade Beyla to v2.8.5\n - Change the defaults for sending_queue \u003e batch block inside\n otelcol.exporter components\n - cluster: Support DNS discovery mode prefixes in\n --cluster.join-addresses flag\n - converter: Update promtail converter to use file_match block\n for loki.source.file\n - database_observability: Add health check collector for\n postgres component\n - database_observability: Expose exclude_schemas and\n exclude_databases settings\n - database_observability: Support Azure cloud provider config\n data\n - database_observability.mysql: Support excluding schemas in\n all collectors\n - database_observability.postgres: Support excluding DBs in all\n collectors\n","modified":"2026-06-18T08:15:04.393246448Z","published":"2026-06-17T14:45:01Z","related":["CVE-2026-25934","CVE-2026-26958","CVE-2026-33186","CVE-2026-34986","CVE-2026-41602","CVE-2026-4427"],"upstream":["CVE-2026-25934","CVE-2026-26958","CVE-2026-33186","CVE-2026-34986","CVE-2026-41602","CVE-2026-4427"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262438-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258099"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258609"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259919"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4427"}],"affected":[{"package":{"name":"alloy","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/alloy&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.16.1-150700.15.20.1"}]}],"ecosystem_specific":{"binaries":[{"alloy":"1.16.1-150700.15.20.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2438-1.json"}}],"schema_version":"1.7.5"}