{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20924-1","published":"2026-06-08T15:15:01Z","modified":"2026-06-10T18:24:15.182560289Z","related":["CVE-2026-33186"],"upstream":["CVE-2026-33186"],"summary":"Security update for elemental-system-agent","details":"This update for elemental-system-agent fixes the following issue\n\n- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-\n  header (bsc#1260277).\n\nChanges:\n\n- Update to version 0.3.16:\n * setup for immutable releases (#274)\n * align system-agent image publishing for signed releases (#270)\n * Bumo github.com/docker/cli to v29.2.0 and go.opentelemetry.io/otel to v1.43.0\n * run go mod tidy in /test folder\n * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (bsc#1260277 CVE-2026-33186)\n * Bump github.com/docker/cli in /test\n * export CATTLE_NODE_NAME if SYSTEM_UPGRADE_NODE_NAME is set\n * use correct prefix for system-agent binary (#273)\n * checksum validation (#271)\n * Add `validate` subcommand for configuration validation (#250)\n * Update CODEOWNERS\n * Pin GH Actions to commit sha\n * chore: bump sles to 15.7\n * Extend remote plan e2e tests\n * Fix agent restart issue and introduce constants\n * chore: bump go to v1.25\n * Setup e2e test infrastructure\n * chores(deps): Bump k8s dependencies\n * Define linter rules\n * Fix CI failures\n * Introduce an extended Makefile\n * Switch workflows to use name makefile\n * Replace dapper with multi stage builds\n * Remove dapper scripts\n * Add multiple improvements for ignore files\n * fix: remove umask command from the system-agent unit-file\n * fix-system-agent-umask\n * [1.34] bumped dependencies for 1.34 support (#242)\n * Bump K8s patch level to 1.33.5 and Go patch level to 1.24.6\n * fix: properly handle traps after unsuccessful SUC job execution\n * fix: do not unconditionally reset failure-counts\n * fix: remove resetFailureCountOnStartup, always reset failure counts on first start\n * un-rc wrangler and lasso\n * drop windows 2019 when running PR CI\n","affected":[{"package":{"name":"elemental-system-agent","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/elemental-system-agent&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.16-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"elemental-system-agent":"0.3.16-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20924-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"}]}