SUSE-SU-2026:4210-1

Advisory lineage Upstream: 7 Downstream: 0
Published: 16 Sept 2026, 11:50
Last modified:16 Sept 2026, 21:45

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Sept 2026, 11:50
Published
Vulnerability first disclosed
16 Sept 2026, 21:45
Last Modified
Vulnerability information updated

Description

Security update for alloy This update for alloy fixes the following issues: - CVE-2026-1229: github.com/cloudflare/circl: the CombinedMult function in the ecc/p384 package produces an incorrect value for specific inputs (bsc#1265542). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265845). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654). - CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264949). - CVE-2026-41606: github.com/apache/thrift: crafted nested messages in c_glib dispatch can lead to uncontrolled recursion and denial of service (bsc#1263324). - CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263289). Changes for alloy: - Update to version 1.18.0: * BREAKING: otelcol HTTP receivers default to idle_timeout='1m', read_header_timeout='1m', write_timeout='30s' to match upstream. Affects otlp, faro, jaeger, zipkin, influxdb, splunkhec, datadog and jaeger_remote_sampling. * Back off usage reporting on persistent failure * Fix Beyla glob parsing * Bump github.com/prometheus/procfs for XFS Collector fix * database_observability.mysql: Simplify denylist in-memory map * database_observability.postgres: Handle DSN with unix sockets * database_observability.postgres: Update collect intervals * database_observability: Explain-plan conditions now redact * Don't emit error log when remotecfg is unused * For a full list of changes, please refer to the CHANGELOG: https://github.com/grafana/alloy/blob/v1.18.0/CHANGELOG.md

Affected Systems

  • susealloy&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7

    < 1.18.0-150700.15.26.1

References (14)