{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21010-1","published":"2026-06-22T14:30:38Z","modified":"2026-06-30T18:24:35.535933119Z","related":["CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-39821"],"upstream":["CVE-2026-33186","CVE-2026-33814","CVE-2026-34986","CVE-2026-39821"],"summary":"Security update for google-cloud-sap-agent","details":"This update for google-cloud-sap-agent fixes the following issues\n\n- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE\n  (bsc#1265764).\n- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation\n  bypass and privilege escalation (bsc#1266604).\n\nChanges for google-cloud-sap-agent:\n\n- Update to version 3.15\n\n * Remove LoggingClient error failure for hanadiskrestore and hanadiskbackup.\n * Add checks for unexpected arguments in hanadiskbackup and hanadiskrestore.\n * Update SAP Agent version to 3.15.\n * Refactor grubBootLoaderX5 to check for BLS support via grub2-mkconfig help.\n * Update all go dependencies\n * Check grub2-mkconfig for BLS support on X4 instances.\n * Add tenant SID collection to supportbundle.\n * Update golang.org/x/net dependency. This is to address (#444)\n * Fork tuned.conf to tuned-x5.conf for X5 series configurations\n * Enable configureX5 in configureinstance.\n * Create skeleton implementation and tests for X5 configureinstance support.\n * Enable detection of x5 machine types in configureinstance\n\n- Update to version 3.14 (bsc#1265991)\n\n * Update Daemon Restart method to pass the correct cancel function to the new handler.\n * Remove redundant error logging in HANA disk restore.\n * Fetch and rename Logical Volume during HANA disk restore.\n * Add usage metrics for CMEK disk restore.\n * Add multi-region and global KMS keys location checks.\n * Convert HANA SID to uppercase in hanadiskbackup and hanadiskrestore.\n * Log warning instead of erroring out on KMS key get failure.\n * Initialize GCE client in status onetime command.\n * Validate presence of KMS key in hanadiskrestore.\n * Add SID parameter to HANA backup/restore path functions.\n * Add KMS key location validation for HANA disk restore.\n * Update agent version to 3.14.\n * Fixes an issue if there is a whitespace around an argument passed in\n * Add validation to prevent using both CSEK and KMS keys in hanadiskrestore.\n * Handle disk recreation in HANA disk restore when IOPS, throughput, size, or KMS key are specified.\n * Refactor disk restore and configuration logic.\n * Add support for CMEK encryption of restored disks.\n * Remove obsolete TODOs.\n\n- Update to version 3.13\n\n * Replace strings.TrimSuffix with strings.TrimSpace in hanabackup.go\n * Improve error messages in hanabackup.go.\n * Add system state logging and logical device verification.\n * Minor version bump\n * Improve SAP instance comparison for process metrics collectors to\n prevent unnecessary restarts of collectors.\n * Delete supportbundlehandler package.\n * Remove configurehandler from sapguestactions.\n * Delete hanadiskbackuphandler from sapguestactions.\n * Remove Guest Actions and GCBDR Actions from initial daemon start.\n * Remove `gsutil` check from collection definition.\n * Delete performancediagnosticshandler package.\n * Remove unused handlers and shell command execution.\n * status feature fixes - pass secret name\n * Fix an issue in system discovery if discovering a network fails,\n particularly due to an IAM permission error.\n * Add verification for HANA data volume state after disk restore.\n * Error handling for rescanVolumegroups and improved logging.\n * Add link to What's New page in the sapagent README.\n * Add secret manager IAM checks if secret key is preset in status\n","affected":[{"package":{"name":"google-cloud-sap-agent","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/google-cloud-sap-agent&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"google-cloud-sap-agent":"3.15-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21010-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265991"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266604"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"}]}