## This update for google-guest-agent fixes the following issues: Update to version 20260430.00 * Update THIRD_PARTY_LICENSES to be package specific location. (#608) * Update dependencies and go version to 1.26.2 (#607) (bsc#1265762, CVE-2026-33814) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) (bsc#1260264, CVE-2026-33186) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593)
* bsc#1210938
* bsc#1239334
* bsc#1239944
* bsc#1243254
* bsc#1243505
* bsc#1245759
* bsc#1253889
* bsc#1257010
* bsc#1260264
* bsc#1262926
* bsc#1265762
Cross-
* CVE-2025-22868
* CVE-2025-22869
* CVE-2025-58181
* CVE-2026-33186
* CVE-2026-33814
* CVE-2026-34986
CVSS scores:
* CVE-2025-22868 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22868 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22869 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Get the latest Linux and open source security news straight to your inbox.