{"id":"SUSE-SU-2026:4388-1","summary":"Security update for amazon-cloudwatch-agent","details":"This update for amazon-cloudwatch-agent fixes the following issues:\n\n- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization\n  policies via mixed-case or canonical-case header matches (bsc#1279334).\n- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279235).\n- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS\n  servers (bsc#1279393).\n\nChanges for amazon-cloudwatch-agent:\n\n- Update to version 1.300072.0\n \n * [DatabaseInsights] Enable PostgreSQL execution plan collection\n by @AshuSrv in (#2225)\n * [DatabaseInsights] Add workload detection for PostgreSQL database\n servers by @Paamicky in (#2220)\n * [ApplicationSignals] Preserve jvm.gc.name attribute in GC runtime\n metrics to differentiate collector types by @ezhang6811 in (#2218)\n * [DatabaseInsights] Split PostgreSQL per-resource metrics to a dedicated\n 60s receiver to reduce collection overhead by @EduVencovsky in (#2232)\n * [Agent] Bump grpc and golang.org/x/net dependencies\n by @dependabot in (#2217) and @movence in (#2242)\n * [Agent] Fix AKS cloud.resource_id derivation to use the cluster\n resource group by @jefchien in (#2237)\n  \n- Lock github.com/prometheus/common at v0.62.0\n  \n- Update to version 1.300071.0\n \n * [OpenTelemetry] Add file tailing and Windows Events support\n by @jefchien in (#2206) and (#2193)\n * [OpenTelemetry] Add resource_attributes support by @movence in (#2207)\n * [Agent] Add set-env ctl action to persist agent environment variables\n by @sky333999 in (#2211)\n * [Agent] Add platform-aware default configs for OpenTelemetry (host,\n Kubernetes, ECS) by @jefchien in (#2179)\n * [Agent] Add Microsoft Azure support for VMs and AKS by @movence in (#2183)\n * [OpenTelemetry] Add root-level cluster_name and standardize collection_interval\n by @Paamicky in (#2189)\n * [Agent] Retain custom environment variables in env-config.json between\n translation by @jefchien in (#2131)\n * [DatabaseInsights] Add severity parsing and fix multiline/timestamp for\n PostgreSQL server logs by @JayPolanco in (#2209)\n * [Logs] Fix throttling deadlock in cloudwatchlogs output plugin when destinations\n are removed by @lorespiz in (#2190)\n * [Logs] Fix force-flush timer permanently stalling on low-volume log streams\n by @musa-asad in (#2166)\n * [Logs] Add journald log collection support by @Paamicky in (#2121)\n * [OpenTelemetry] Add new opentelemetry section in JSON configuration to support\n sending telemetry to CloudWatch OTLP endpoints by @mitali-salvi in (#2152)\n * [DatabaseInsights] Add support for self-managed PostgreSQL metrics and logs\n collection by @JayPolanco in (#2172)\n * [ApplicationSignals] Fix Service Events logs and metrics pipelines\n to use shared AWS credential chain by @jefchien in (#2151)\n","modified":"2026-09-30T12:00:04.600856100Z","published":"2026-09-29T11:44:51Z","related":["CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"upstream":["CVE-2026-84303","CVE-2026-84304","CVE-2026-84445"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264388-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279235"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279334"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84304"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-84445"}],"affected":[{"package":{"name":"amazon-cloudwatch-agent","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP4","purl":"pkg:rpm/suse/amazon-cloudwatch-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.300072.0-150400.9.13.1"}]}],"ecosystem_specific":{"binaries":[{"amazon-cloudwatch-agent":"1.300072.0-150400.9.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4388-1.json"}},{"package":{"name":"amazon-cloudwatch-agent","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP5","purl":"pkg:rpm/suse/amazon-cloudwatch-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.300072.0-150400.9.13.1"}]}],"ecosystem_specific":{"binaries":[{"amazon-cloudwatch-agent":"1.300072.0-150400.9.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4388-1.json"}},{"package":{"name":"amazon-cloudwatch-agent","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP6","purl":"pkg:rpm/suse/amazon-cloudwatch-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.300072.0-150400.9.13.1"}]}],"ecosystem_specific":{"binaries":[{"amazon-cloudwatch-agent":"1.300072.0-150400.9.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4388-1.json"}},{"package":{"name":"amazon-cloudwatch-agent","ecosystem":"SUSE:Linux Enterprise Module for Public Cloud 15 SP7","purl":"pkg:rpm/suse/amazon-cloudwatch-agent&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.300072.0-150400.9.13.1"}]}],"ecosystem_specific":{"binaries":[{"amazon-cloudwatch-agent":"1.300072.0-150400.9.13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4388-1.json"}}],"schema_version":"1.9.0"}