Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21884-1

Опубликовано: 20 сент. 2026
Источник: suse-cvrf

Описание

Security update for amazon-ssm-agent

This update for amazon-ssm-agent fixes the following issues:

  • CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278681).
  • CVE-2026-71556: github.com/go-git/go-git/v5: arbitrary file read/write via symbolic link resolution (bsc#1276981).
  • CVE-2026-71557: github.com/go-git/go-git/v5: malicious reference names may modify files outside the reference storage (bsc#1276994).

Changes for amazon-ssm-agent:

  • Update to version 3.3.5390.0
  • Bump github.com/gorilla/websocket from v1.4.2 to v1.5.3
  • Bump golang.org/x/crypto from v0.53.0 to v0.56.0
  • Bump golang.org/x/net from v0.56.0 to v0.57.0
  • Bump golang.org/x/sys from v0.46.0 to v0.47.0
  • Upgrade GoLang version from 1.25 to 1.26
  • Mint control-channel token after dial to fix AZ-fault token expiry
  • Resume patch documents interrupted by an external shutdown
  • Use systemctl for systemd in aws: configureDocker on Amazon Linux
  • Update greengrass component version to 1.3.5
  • Update to version 3.3.5226.0
  • Add bounds check for HeaderLength in AgentMessage Deserialize
  • Bump github.com/go-git/go-git/v5 to v5.19.2
  • Bump golang.org/x/sync to v0.21.0
  • Detect Azure Linux and potential future unregistered Linux platforms
  • Fix Windows session command parsing by removing shlex
  • Fix shell injection in Windows domainjoin plugin parameters
  • Prevent control channel deadlock on ProcessorBufferFull
  • Revert migration from aws-sdk-go v1 to aws-sdk-go-v2 change
  • Update the logic for loading RegistrationInfo
  • Upgrade Go version to 1.25.13
  • Update to version 3.3.5068.0
  • Migrate from aws-sdk-go v1 to aws-sdk-go-v2
  • Fix flaky registration/connection channel tests
  • Sync AWS SDK fork in extra/ with multicloud vendor changes
  • Harden function create file with permissions in a single syscall
  • Upgrade Go version to 1.25.12
  • Bump golang.org/x/net@v0.55.0 to golang.org/x/net@v0.56.0
  • Fix loopback bypass in remote-host port forwarding denylist
  • Update to version 3.3.4851.0
  • Add ECS/EKS credential endpoints and loopback to port-forward denylist
  • Canonicalize IP addresses before port-forwarding denylist check
  • Pass the ActiveDirectory domain password via stdin using -y /dev/stdin instead of the -w flag
  • Fix false StuckAtInProgress timeout for associations with rate >= 2h
  • Fix non-interactive session big file transfer issues
  • Prevent ssm-user race condition with flock-based serialization
  • Send AWS::EC2::Instance as source type when registered with provider EC2
  • Validate process name in orphan worker detection
  • Update to version 3.3.4793.0
  • Add multicloud support enabling SSM Agent registration with Azure cloud providers
  • Add support for the upcoming public key in the agent code

Список пакетов

openSUSE Leap 16.0
amazon-ssm-agent-3.3.5390.0-160000.1.1

Описание

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.


Затронутые продукты
openSUSE Leap 16.0:amazon-ssm-agent-3.3.5390.0-160000.1.1

Ссылки

Описание

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.


Затронутые продукты
openSUSE Leap 16.0:amazon-ssm-agent-3.3.5390.0-160000.1.1

Ссылки

Описание

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.


Затронутые продукты
openSUSE Leap 16.0:amazon-ssm-agent-3.3.5390.0-160000.1.1

Ссылки

Описание

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.


Затронутые продукты
openSUSE Leap 16.0:amazon-ssm-agent-3.3.5390.0-160000.1.1

Ссылки

Описание

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.


Затронутые продукты
openSUSE Leap 16.0:amazon-ssm-agent-3.3.5390.0-160000.1.1

Ссылки
Уязвимость openSUSE-SU-2026:21884-1