{"schema_version":"1.7.5","id":"SUSE-SU-2026:21793-1","published":"2026-05-14T15:04:53Z","modified":"2026-05-28T18:24:08.950186514Z","related":["CVE-2026-25934","CVE-2026-26958","CVE-2026-33186","CVE-2026-4427"],"upstream":["CVE-2026-25934","CVE-2026-26958","CVE-2026-33186","CVE-2026-4427"],"summary":"Security update for alloy","details":"This update for alloy fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-4427: github.com/jackc/pgproto3/v2: improper validation of field length allows a malicious PostgreSQL server\n  to crash a client application via a DataRow message (bsc#1259919).\n- CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files\n  can lead to the consumption of corrupted files (bsc#1258099).\n- CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results\n  and lead to undefined behavior (bsc#1258609).\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260317).\n\nNon security issue:\n\n- Updated to 1.16.0\n- Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815)\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621793-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258099"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258609"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259919"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260317"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4427"}]}