|
|
Log in / Subscribe / Register

Ubuntu alert USN-8447-3 (google-guest-agent)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8447-3] Google Guest Agent vulnerabilities
Date:  Mon, 22 Jun 2026 17:57:57 +0000
Message-ID:  <E1wbiuD-0005XP-46@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8447-3 June 22, 2026 google-guest-agent vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Google Guest Agent. Software Description: - google-guest-agent: Google Compute Engine Guest Agent Details: USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides the corresponding updates for Go Cryptography code embedded in Google Guest Agent. Original advisory details: It was discovered that Go Cryptography did not properly handle SSH global request responses. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-39830) It was discovered that Go Cryptography did not properly verify user presence when using FIDO/U2F security keys. An attacker could possibly use this issue to bypass user presence verification for hardware security keys. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831) It was discovered that Go Cryptography did not properly serialize SSH agent key constraint extensions. An attacker could possibly use this issue to bypass intended key usage restrictions. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-39832) It was discovered that Go Cryptography did not properly enforce the confirm-before-use constraint in the SSH agent keyring. An attacker could possibly use this issue to use SSH keys without the required user confirmation. (CVE-2026-39833) It was discovered that Go Cryptography had an integer overflow when handling large SSH channel writes. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-39834) It was discovered that Go Cryptography did not properly check certificate authority key revocation. An attacker could possibly use this issue to bypass certificate authority revocation checks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-42508) It was discovered that Go Cryptography did not properly enforce the source- address critical option for all SSH server callback types. An attacker could possibly use this issue to bypass source address authorization restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS google-guest-agent 20250506.01-0ubuntu2.1 Ubuntu 25.10 google-guest-agent 20250506.01-0ubuntu1.2 Ubuntu 24.04 LTS google-guest-agent 20250116.00-0ubuntu1~24.04.4 Ubuntu 22.04 LTS google-guest-agent 20250116.00-0ubuntu1~22.04.3 Ubuntu 20.04 LTS google-guest-agent 20250116.00-0ubuntu1~20.04.0+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS google-guest-agent 20241011.01-0ubuntu1~18.04.0+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS google-guest-agent 20240716.00-0ubuntu1~16.04.0+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8447-3 https://ubuntu.com/security/notices/USN-8447-2 https://ubuntu.com/security/notices/USN-8447-1 CVE-2026-39830, CVE-2026-39831, CVE-2026-39834, CVE-2026-46595 Package Information: https://launchpad.net/ubuntu/+source/google-guest-agent/2... https://launchpad.net/ubuntu/+source/google-guest-agent/2... https://launchpad.net/ubuntu/+source/google-guest-agent/2... https://launchpad.net/ubuntu/+source/google-guest-agent/2...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo5dxwACgkQcpJm3tlz hgF05BAAxWvDpYfiqp5025Lsl9l6plEyWzgFGF0KrqZX2H8LyXmrUrxMWAfZ3WqF +B59o52rMmTckw8vW5vyHNTqOdIQOUMGLX3w6ljmqlRS1MLLMzx0ALjq65RK9mVP okMNI6r1BwWLtGz5cQVDoVFH8fWLESn/YYAw0ELvlVyTxg2c5Us6mfYh2zTfyJxk u8lOvVRUxXYxKSrogVmRvX6Yfz2XCIDzJ6ExddpFk9HjbwsZszvFdFrdTd/4soze hbm+a+Dcm7CnJIB9Q9BPOighBxP1M60RxOmh0hKzs7ezO6lyVm2S0CWfya1vR8DC F9fuy1n4xp/cHmXu4/dwKlmKcU7QIU7JukZalg5XQTDxvmb77btq/8Os674PGM9Y 78c4HsjboFMgbU6C3faeo2fLCxfKjMhjAGMa2WQKszFHNrId+sGz9krLvobPcjnh x4pUV3qAfb4nXYN5VgHF5sLzINkuMYfppfN9ojkcguIxQl82UJztpGfxOJx/bgoN 1J7rLufsMBzIl0u+p5MNuVmVG27fGQ9Q0QCPtdbtj8vU33vYYT225i3VWLpBmcsN lZFq94acdpXH+gs8Y73vodIs4maOO4FVJuiTLNUaySqBX2UbX+l3MaDeIt3kPa+P ujPqct+bkr13eVf6krinTYwGE/VD8bxRjdfdVUO2b+FFdmHFnkM= =6cmq -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds