SUSE-SU-2026:23548-1: important: Security update for google-osconfig-agent

SLE-SECURITY-UPDATES null at suse.de
Mon Sep 14 17:39:48 UTC 2026


# Security update for google-osconfig-agent

Announcement ID: SUSE-SU-2026:23548-1  
Release Date: 2026-09-10T08:34:51Z  
Rating: important  
References:

  * bsc#1272118
  * bsc#1278967
  * bsc#1279297
  * bsc#1279414

  
Cross-References:

  * CVE-2026-39821
  * CVE-2026-56852
  * CVE-2026-84303
  * CVE-2026-84304
  * CVE-2026-84445

  
CVSS scores:

  * CVE-2026-39821 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-39821 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-39821 ( NVD ):  8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
  * CVE-2026-39821 ( NVD ):  9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  * CVE-2026-56852 ( SUSE ):  6.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-56852 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-56852 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-84303 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-84303 ( SUSE ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-84303 ( NVD ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-84304 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-84304 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-84304 ( NVD ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  * CVE-2026-84445 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-84445 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

  
Affected Products:

  * SUSE Linux Micro 6.0

  
  
An update that solves five vulnerabilities can now be installed.

## Description:

This update for google-osconfig-agent fixes the following issues:

This update for google-osconfig-agent fixes the following issues:

  * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on
    truncated/invalid UTF-8 input (bsc#1272118).
  * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation
    issue allows for bypass of authorization policies via mixed-case or
    canonical-case header matches (bsc#1279297).
  * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2
    DATA frame fragmentation (bsc#1279414).
  * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing
    ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967).

Changes for google-osconfig-agent:

  * Update to version 20260908.00
  * Migrate presubmits from deb11 to deb12 (#1050)
  * Bump the go_modules group across 1 directory with 3 updates (#1047)
  * Introduce E2E v2 framework and inventory tests (#1039)
  * Remove test case for asserting JSON marshal error from task_state.go (#1045)
  * security: pin GitHub actions to commit SHAs in CodeQL workflow (#1042)
  * Add Configuration for SCALIBR (#1034)
  * add CheckState and Cleanup tests (#1008)
  * Improve unit tests for osinfo/osinfo_linux.go (#1020)
  * Bump github.com/go-git/go-git/v5 (#1036)
  * Bump cloud.google.com/go/auth from 0.18.0 to 0.22.0 (#1032)
  * Bump golang.org/x/crypto from 0.52.0 to 0.54.0 (#1028)
  * authenticate cloud build to use docker registry (#1030)
  * Migrate e2e build to internal image (#1024)
  * Upgrade google.golang.org/grpc to new version. (#1023)
  * Improve unit tests for ospatch/yum_update.go (#1012)
  * Improve unit tests for ospatch/updates.go (#1011)
  * Add unit tests for config/package_resource.go PART 2 (#1005)
  * Add unit tests for config/package_resource.go PART 1 (#1003)
  * Add unit tests for policies/local.go (#1015)
  * Add unit tests for repository_resource.go (#1002)
  * Add unit tests for installrecipe.go part 2 (#993)
  * Add unit tests for scalibr.go (#1019)
  * Add unit tests for installrecipe.go part 1 (#992)
  * Add test cases for policies/recipes/recipedb.go (#989)
  * Bump golang.org/x/crypto (#1021)
  * Add unit tests for policies/recipes/steps.go PART 3 (#976)
  * Add unit tests for policies/recipes/steps.go PART 2 (#975)
  * Bump golang.org/x/net (#1017)
  * upgrade x/net package. (#1018)
  * Add test cases for config/file_resource.go (#988)
  * Add unit tests for policies/recipes/artifacts.go (#985)
  * Add unit tests for policies/recipes/steps.go PART 1 (#974)
  * Add tests & bugfix for packages/trace.go (#939)
  * Add unit tests for agentendpoint/agentendpoint_beta.go (#983)
  * Replace yum install with yum update (#1009)
  * Bump github.com/containerd/containerd (#1013)
  * Add unit tests for policies/apt.go PART 2 (#957)
  * Add test cases for agentendpoint/task_state.go (#984)
  * Remove deprecated rhel-sap images and add new ones (#1007)
  * Add test cases for clog/clog.go (#986)
  * Use explicit upstream GitHub homepage in URL field

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Micro 6.0  
    zypper in -t patch SUSE-SLE-Micro-6.0-891

## Package List:

  * SUSE Linux Micro 6.0 (aarch64 s390x x86_64)
    * google-osconfig-agent-20260908.00-1.1
    * google-osconfig-agent-debuginfo-20260908.00-1.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-39821.html
  * https://www.suse.com/security/cve/CVE-2026-56852.html
  * https://www.suse.com/security/cve/CVE-2026-84303.html
  * https://www.suse.com/security/cve/CVE-2026-84304.html
  * https://www.suse.com/security/cve/CVE-2026-84445.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1272118
  * https://bugzilla.suse.com/show_bug.cgi?id=1278967
  * https://bugzilla.suse.com/show_bug.cgi?id=1279297
  * https://bugzilla.suse.com/show_bug.cgi?id=1279414

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260914/b27eb3ec/attachment-0001.htm>


More information about the sle-security-updates mailing list