Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE Leap 16.0 Elemental-Register Key Security Flaw CVE-2026-33186

opensuse
Calendar Grey June 9, 2026
Dist Opensuse Esm H88
This update resolves a critical authorization bypass in elemental-register for openSUSE Leap 16.0
An update that solves one vulnerability and has 6 bug fixes can now be installed.

Description

This update for elemental-register fixes the following issue

- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo-

header (bsc#1260277).

Changes:

- Update to v1.9.2:

* 71d1fb9c Local node labels (#984)

* ce6acda9 Bump golang.org/x/net to v0.55.0 includes fixes for:

- bsc#1266789 bsc#1265921 bsc#1267197 bsc#1267168 bsc#1251679

* 060958b7 Bump golangci/golangci-lint-action

* 3b4b6699 use a real UUID for the machine registration ID

* d33faa01 Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186)

* 6dceb411 Deterministic endpoints for MachineRegistrations (#975)

- Update to v1.9.1:

* b42116d4 Ensure the machine inventory selector keeps looking for a match

- Update to v1.9.0:

- Update to v1.9.0-rc1:

* 9952ebe1 Update libraries based on dependency scan

* 5e128c5d Adapt OBS packages to a 1.9 version to coexist with 1.8 version

* f88219af Fix cluster api version in test environment

* ad937279 Run...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

elemental-register-1.9.2-160000.1.1

elemental-support-1.9.2-160000.1.1

References

* bsc#1251679

* bsc#1260277

* bsc#1265921

* bsc#1266789

* bsc#1267168

* bsc#1267197

References:

* https://www.suse.com/security/cve/CVE-2026-33186.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20920-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here