{"id":"openSUSE-SU-2026:21882-1","summary":"Security update for google-osconfig-agent","details":"This update for google-osconfig-agent fixes the following issues:\n\n- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS\n  via oversized inputs (bsc#1276722).\n- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118).\n- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the\n  crypto/ssh library (bsc#1278597).\n- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization\n  policies via mixed-case or canonical-case header matches (bsc#1279297).\n- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414).\n- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS\n  servers (bsc#1278967).\n\nChanges for google-osconfig-agent:\n\n- Update to version 20260911.00\n * Add support for all possible SCALIBR os extractor for linux (#1052)\n * Migrate presubmits from deb11 to deb12 (#1050)\n * Bump the go_modules group across 1 directory with 3 updates (#1047)\n * Introduce E2E v2 framework and inventory tests (#1039)\n * Remove test case for asserting JSON marshal error from task_state.go (#1045)\n * security: pin GitHub actions to commit SHAs in CodeQL workflow (#1042)\n * Add Configuration for SCALIBR (#1034)\n * add CheckState and Cleanup tests (#1008)\n * Improve unit tests for osinfo/osinfo_linux.go (#1020)\n * Bump github.com/go-git/go-git/v5 (#1036)\n * Bump cloud.google.com/go/auth from 0.18.0 to 0.22.0 (#1032)\n * Bump golang.org/x/crypto from 0.52.0 to 0.54.0 (#1028)\n * authenticate cloud build to use docker registry (#1030)\n * Migrate e2e build to internal image (#1024)\n * Upgrade google.golang.org/grpc to new version. (#1023)\n * Improve unit tests for ospatch/yum_update.go (#1012)\n * Improve unit tests for ospatch/updates.go (#1011)\n * Add unit tests for config/package_resource.go PART 2 (#1005)\n * Add unit tests for config/package_resource.go PART 1 (#1003)\n * Add unit tests for policies/local.go (#1015)\n * Add unit tests for repository_resource.go (#1002)\n * Add unit tests for installrecipe.go part 2 (#993)\n * Add unit tests for scalibr.go (#1019)\n * Add unit tests for installrecipe.go part 1 (#992)\n * Add test cases for policies/recipes/recipedb.go (#989)\n * Bump golang.org/x/crypto (#1021)\n * Add unit tests for policies/recipes/steps.go PART 3 (#976)\n * Add unit tests for policies/recipes/steps.go PART 2 (#975)\n * Bump golang.org/x/net (#1017)\n * upgrade x/net package. (#1018)\n * Add test cases for config/file_resource.go (#988)\n * Add unit tests for policies/recipes/artifacts.go (#985)\n * Add unit tests for policies/recipes/steps.go PART 1 (#974)\n * Add tests & bugfix for packages/trace.go (#939)\n * Add unit tests for agentendpoint/agentendpoint_beta.go (#983)\n * Replace yum install with yum update (#1009)\n * Bump github.com/containerd/containerd (#1013)\n * Add unit tests for policies/apt.go PART 2 (#957)\n * Add test cases for agentendpoint/task_state.go (#984)\n * Remove deprecated rhel-sap images and add new ones (#1007)\n * Add test cases for clog/clog.go (#986)\n","modified":"2026-09-25T18:24:22.119730744Z","published":"2026-09-19T22:39:23Z","related":["CVE-2026-41178","CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-78662","CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"upstream":["CVE-2026-41178","CVE-2026-56852","CVE-2026-56854","CVE-2026-56855","CVE-2026-78662","CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272118"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278597"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278967"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279297"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279414"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84445"}],"affected":[{"package":{"name":"google-osconfig-agent","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/google-osconfig-agent&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20260911.00-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"google-osconfig-agent":"20260911.00-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21882-1.json"}}],"schema_version":"1.9.0"}