gpp_maybe
Security update for elemental-toolkit
SUSE-SLE-Micro-6.0-749
This update for elemental-toolkit fixes the following issue - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260277). Changes for elemental-toolkit: - Update to version 2.1.6: * Bump golang.org/x/net to v0.55.0 (bsc#1267168) * Bump golang.org/x/crypto to v0.52.0 (bsc#1266187) * Update orange flavor * Install hugo from the OS repositories * Bump actions/upload-artifact to v7 * Bump actions/cache to v5 * Bump golangci/golangci-lint-action to v9 * Bump github.com/spf13/cobra library * Bump github.com/jaypipes/ghw library * Bump github.com/bramvdbogaerde/go-scp library * Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186) * Bump github.com/ulikunitz/xz library * Do not clean cache on PRs from forks
-
Release DateJun 10 2026
-
ReferencesBugzilla: 1260277, 1266187, 1267168
CVEs: CVE-2026-39832, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33186, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Micro 6.0 aarch64
-
Packages
SUSE Linux Micro 6.0 x86_64
-
Packages