Security update for alloy
| Announcement ID: | SUSE-SU-2026:21793-1 |
|---|---|
| Release Date: | 2026-05-14T15:06:27Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves four vulnerabilities and contains one feature can now be installed.
Description:
This update for alloy fixes the following issues
Security issues:
- CVE-2026-4427: github.com/jackc/pgproto3/v2: improper validation of field length allows a malicious PostgreSQL server to crash a client application via a DataRow message (bsc#1259919).
- CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for .pack and .idx files can lead to the consumption of corrupted files (bsc#1258099).
- CVE-2026-26958: filippo.io/edwards25519: failure to initialize receiver in MultiScalarMult can produce invalid results and lead to undefined behavior (bsc#1258609).
- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2: path pseudo- header (bsc#1260317).
Non security issue:
- Updated to 1.16.0
- Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815)
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-747=1 -
SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-747=1
Package List:
-
SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
- alloy-1.16.0-160000.1.1
- alloy-debuginfo-1.16.0-160000.1.1
-
SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
- alloy-1.16.0-160000.1.1
- alloy-debuginfo-1.16.0-160000.1.1
References:
- https://www.suse.com/security/cve/CVE-2026-25934.html
- https://www.suse.com/security/cve/CVE-2026-26958.html
- https://www.suse.com/security/cve/CVE-2026-33186.html
- https://www.suse.com/security/cve/CVE-2026-4427.html
- https://bugzilla.suse.com/show_bug.cgi?id=1258099
- https://bugzilla.suse.com/show_bug.cgi?id=1258609
- https://bugzilla.suse.com/show_bug.cgi?id=1259919
- https://bugzilla.suse.com/show_bug.cgi?id=1260317
- https://jira.suse.com/browse/PED-14815