This update for flannel fixes the following issues:
- Update to version 0.28.4:
* fix go version (don't set patch version) (#2428)
* Bump flannel-cni-plugin to v1.9.1-flannel1 (#2427)
* Bump the other-go-modules group across 1 directory with 3 updates
(#2425)
* Bump the tencent group with 2 updates (#2417)
* Bump the etcd group with 4 updates (#2398), includes fix for
CVE-2026-33413 (boo#1260853) and CVE-2026-33343 (boo#1260847)
* Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 (#2420)
* Bump go to 1.25 (#2424)
* Bump actions/upload-pages-artifact from 4.0.0 to 5.0.0
* Bump docker/build-push-action from 7.0.0 to 7.1.0
* Bump docker/login-action from 4.0.0 to 4.1.0
* Verify the kubectl sha256sum
* Secure makefile (#2414)
* Improve the security of Dockerfile
* Bump github/codeql-action from 4.34.1 to 4.35.1 (#2409)
* Bump actions/deploy-pages from 4.0.5 to 5.0.0
* lease: only...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-149=1
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
flannel-0.28.4-bp157.2.6.1
- openSUSE Backports SLE-15-SP7 (noarch):
flannel-k8s-yaml-0.28.4-bp157.2.6.1
https://www.suse.com/security/cve/CVE-2026-33343.html
https://www.suse.com/security/cve/CVE-2026-33413.html
https://bugzilla.suse.com/1260847
https://bugzilla.suse.com/1260853
Get the latest Linux and open source security news straight to your inbox.