UbuntuUpdates.org

Package "google-guest-agent"

Name: google-guest-agent

Description:

Google Compute Engine Guest Agent

Latest version: 20250116.00-0ubuntu2.2
Release: plucky (25.04)
Level: security
Repository: main
Homepage: https://github.com/GoogleCloudPlatform/guest-agent

Links


Download "google-guest-agent"


Other versions of "google-guest-agent" in Plucky

Repository Area Version
base main 20250116.00-0ubuntu2
updates main 20250116.00-0ubuntu2.2

Changelog

Version: 20250116.00-0ubuntu2.2 2026-01-13 10:07:48 UTC

  google-guest-agent (20250116.00-0ubuntu2.2) plucky-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/extra/vendor/golang.org/x/crypto was patched
      with a backport of e79546e28b85ea53dd37afe1c4102746ef553b9c in file
      ssh/ssh_gss.go.
    - debian/extra/vendor adding patches-applied and README.txt for
      track/documentation propose about patches applied in vendored sources.
    - CVE-2025-58181

 -- Nishit Majithia <email address hidden> Fri, 09 Jan 2026 16:38:21 +0530

Source diff to previous version
CVE-2025-58181 SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause u

Version: 20250116.00-0ubuntu2.1 2025-11-03 13:07:15 UTC

  google-guest-agent (20250116.00-0ubuntu2.1) plucky-security; urgency=medium

  * SECURITY UPDATE: Authorization bypass in SSH protocol
    - debian/extra/vendor/golang.org/x/crypto/ssh/server.go: Change
      maxCachedPubKeys to 1 and change limit checks. Based on:
      https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909
    - CVE-2024-45337

 -- Hlib Korzhynskyy <email address hidden> Fri, 24 Oct 2025 10:09:10 -0230

CVE-2024-45337 Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an au



About   -   Send Feedback to @ubuntu_updates