{"id":"openSUSE-SU-2026:21884-1","summary":"Security update for amazon-ssm-agent","details":"This update for amazon-ssm-agent fixes the following issues:\n\n- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the\n  crypto/ssh library (bsc#1278681).\n- CVE-2026-71556: github.com/go-git/go-git/v5: arbitrary file read/write via symbolic link resolution (bsc#1276981).\n- CVE-2026-71557: github.com/go-git/go-git/v5: malicious reference names may modify files outside the reference storage\n  (bsc#1276994).\n\nChanges for amazon-ssm-agent:\n\n- Update to version 3.3.5390.0\n * Bump github.com/gorilla/websocket from v1.4.2 to v1.5.3\n * Bump golang.org/x/crypto from v0.53.0 to v0.56.0\n * Bump golang.org/x/net from v0.56.0 to v0.57.0\n * Bump golang.org/x/sys from v0.46.0 to v0.47.0\n * Upgrade GoLang version from 1.25 to 1.26\n * Mint control-channel token after dial to fix AZ-fault token expiry\n * Resume patch documents interrupted by an external shutdown\n * Use systemctl for systemd in aws: configureDocker on Amazon Linux\n * Update greengrass component version to 1.3.5\n\n- Update to version 3.3.5226.0\n * Add bounds check for HeaderLength in AgentMessage Deserialize\n * Bump github.com/go-git/go-git/v5 to v5.19.2\n * Bump golang.org/x/sync to v0.21.0\n * Detect Azure Linux and potential future unregistered Linux platforms\n * Fix Windows session command parsing by removing shlex\n * Fix shell injection in Windows domainjoin plugin parameters\n * Prevent control channel deadlock on ProcessorBufferFull\n * Revert migration from aws-sdk-go v1 to aws-sdk-go-v2 change\n * Update the logic for loading RegistrationInfo\n * Upgrade Go version to 1.25.13\n\n- Update to version 3.3.5068.0\n\n * Migrate from aws-sdk-go v1 to aws-sdk-go-v2\n * Fix flaky registration/connection channel tests\n * Sync AWS SDK fork in extra/ with multicloud vendor changes\n * Harden function create file with permissions in a single syscall\n * Upgrade Go version to 1.25.12\n * Bump golang.org/x/net@v0.55.0 to golang.org/x/net@v0.56.0\n * Fix loopback bypass in remote-host port forwarding denylist\n\n- Update to version 3.3.4851.0\n\n * Add ECS/EKS credential endpoints and loopback to port-forward denylist\n * Canonicalize IP addresses before port-forwarding denylist check\n * Pass the ActiveDirectory domain password via stdin using -y /dev/stdin\n instead of the -w flag\n * Fix false StuckAtInProgress timeout for associations with rate \u003e= 2h\n * Fix non-interactive session big file transfer issues\n * Prevent ssm-user race condition with flock-based serialization\n * Send AWS::EC2::Instance as source type when registered with provider EC2\n * Validate process name in orphan worker detection\n\n- Update to version 3.3.4793.0\n\n * Add multicloud support enabling SSM Agent registration with\n Azure cloud providers\n * Add support for the upcoming public key in the agent code\n","modified":"2026-09-25T18:23:10.832163688Z","published":"2026-09-20T03:28:14Z","related":["CVE-2026-56854","CVE-2026-56855","CVE-2026-71556","CVE-2026-71557","CVE-2026-78662"],"upstream":["CVE-2026-56854","CVE-2026-56855","CVE-2026-71556","CVE-2026-71557","CVE-2026-78662"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276981"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276994"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-71556"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-71557"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78662"}],"affected":[{"package":{"name":"amazon-ssm-agent","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/amazon-ssm-agent&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.5390.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"amazon-ssm-agent":"3.3.5390.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21884-1.json"}}],"schema_version":"1.9.0"}