Описание
Security update for amazon-ssm-agent
This update for amazon-ssm-agent fixes the following issues:
- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278681).
- CVE-2026-71556: github.com/go-git/go-git/v5: arbitrary file read/write via symbolic link resolution (bsc#1276981).
- CVE-2026-71557: github.com/go-git/go-git/v5: malicious reference names may modify files outside the reference storage (bsc#1276994).
Changes for amazon-ssm-agent:
- Update to version 3.3.5390.0
- Bump github.com/gorilla/websocket from v1.4.2 to v1.5.3
- Bump golang.org/x/crypto from v0.53.0 to v0.56.0
- Bump golang.org/x/net from v0.56.0 to v0.57.0
- Bump golang.org/x/sys from v0.46.0 to v0.47.0
- Upgrade GoLang version from 1.25 to 1.26
- Mint control-channel token after dial to fix AZ-fault token expiry
- Resume patch documents interrupted by an external shutdown
- Use systemctl for systemd in aws: configureDocker on Amazon Linux
- Update greengrass component version to 1.3.5
- Update to version 3.3.5226.0
- Add bounds check for HeaderLength in AgentMessage Deserialize
- Bump github.com/go-git/go-git/v5 to v5.19.2
- Bump golang.org/x/sync to v0.21.0
- Detect Azure Linux and potential future unregistered Linux platforms
- Fix Windows session command parsing by removing shlex
- Fix shell injection in Windows domainjoin plugin parameters
- Prevent control channel deadlock on ProcessorBufferFull
- Revert migration from aws-sdk-go v1 to aws-sdk-go-v2 change
- Update the logic for loading RegistrationInfo
- Upgrade Go version to 1.25.13
- Update to version 3.3.5068.0
- Migrate from aws-sdk-go v1 to aws-sdk-go-v2
- Fix flaky registration/connection channel tests
- Sync AWS SDK fork in extra/ with multicloud vendor changes
- Harden function create file with permissions in a single syscall
- Upgrade Go version to 1.25.12
- Bump golang.org/x/net@v0.55.0 to golang.org/x/net@v0.56.0
- Fix loopback bypass in remote-host port forwarding denylist
- Update to version 3.3.4851.0
- Add ECS/EKS credential endpoints and loopback to port-forward denylist
- Canonicalize IP addresses before port-forwarding denylist check
- Pass the ActiveDirectory domain password via stdin using -y /dev/stdin instead of the -w flag
- Fix false StuckAtInProgress timeout for associations with rate >= 2h
- Fix non-interactive session big file transfer issues
- Prevent ssm-user race condition with flock-based serialization
- Send AWS::EC2::Instance as source type when registered with provider EC2
- Validate process name in orphan worker detection
- Update to version 3.3.4793.0
- Add multicloud support enabling SSM Agent registration with Azure cloud providers
- Add support for the upcoming public key in the agent code
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1276981
- SUSE Bug 1276994
- SUSE Bug 1278681
- SUSE CVE CVE-2026-56854 page
- SUSE CVE CVE-2026-56855 page
- SUSE CVE CVE-2026-71556 page
- SUSE CVE CVE-2026-71557 page
- SUSE CVE CVE-2026-78662 page
Описание
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.
Затронутые продукты
Ссылки
- CVE-2026-56854
- SUSE Bug 1278446
- SUSE Bug 1280553
Описание
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Затронутые продукты
Ссылки
- CVE-2026-56855
- SUSE Bug 1278446
- SUSE Bug 1280553
Описание
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.
Затронутые продукты
Ссылки
- CVE-2026-71556
- SUSE Bug 1276977
Описание
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.
Затронутые продукты
Ссылки
- CVE-2026-71557
- SUSE Bug 1276986
Описание
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Затронутые продукты
Ссылки
- CVE-2026-78662
- SUSE Bug 1278446
- SUSE Bug 1280553