Alerts This Week
Warning Icon 1 815
Alerts This Week
Warning Icon 1 815

SUSE amazon-ssm-agent Important DoS Resource Vulnerabilities 2026-22157-1

suse
Calendar Grey June 23, 2026
Dist Suse Esm H88
Important security update for Amazon SSM Agent addresses 21 vulnerabilities including DoS and resource issues through patches.
An update that solves 21 vulnerabilities and contains one feature can now be installed.

Summary

## This update for amazon-ssm-agent fixes the following issues Update to version 3.3.4624.0: * CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239342). * CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238702). * CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253611). * CVE-2026-1229: the CombinedMult function in the ecc/p384 package produces an incorrect value for specific inputs (bsc#1265474). * CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files can lead to the consumption of corrupted files (bsc#1258095).

References

* bsc#1238702

* bsc#1239342

* bsc#1253611

* bsc#1258095

* bsc#1264952

* bsc#1265474

* bsc#1266200

* bsc#1266781

* bsc#1267332

* jsc#PED-14843

Cross-

* CVE-2025-22869

* CVE-2025-22870

* CVE-2025-47913

* CVE-2026-1229

* CVE-2026-25934

* CVE-2026-39821

* CVE-2026-39827

* CVE-2026-39828

* CVE-2026-39829

* CVE-2026-39830

* CVE-2026-39831

* CVE-2026-39832

* CVE-2026-39833

* CVE-2026-39834

* CVE-2026-39835

* CVE-2026-41506

* CVE-2026-42508

* CVE-2026-44740

* CVE-2026-46595

* CVE-2026-46597

* CVE-2026-46598

CVSS scores:

* CVE-2025-22869 ( SUSE ): 8.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22157-1
Release Date: 2026-06-17T16:32:56Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here