openSUSE 16 Security Update : chromium (openSUSE-SU-2026:20372-1)

high Nessus Plugin ID 302994

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:20372-1 advisory.

Changes in chromium:

- Chromium 146.0.7680.80:
* CVE-2026-3909: Out of bounds write in Skia (boo#1259659)

- Chromium 146.0.7680.75 (released 2026-03-12) (boo#1259648)
* CVE-2026-3910: Inappropriate implementation in V8.

- Chromium 146.0.7680.71 (released 2026-03-11) (boo#1259530)
* CVE-2026-3913: Heap buffer overflow in WebML
* CVE-2026-3914: Integer overflow in WebML
* CVE-2026-3915: Heap buffer overflow in WebML
* CVE-2026-3916: Out of bounds read in Web Speech
* CVE-2026-3917: Use after free in Agents
* CVE-2026-3918: Use after free in WebMCP
* CVE-2026-3919: Use after free in Extensions
* CVE-2026-3920: Out of bounds memory access in WebML
* CVE-2026-3921: Use after free in TextEncoding
* CVE-2026-3922: Use after free in MediaStream
* CVE-2026-3923: Use after free in WebMIDI
* CVE-2026-3924: Use after free in WindowDialog
* CVE-2026-3925: Incorrect security UI in LookalikeChecks
* CVE-2026-3926: Out of bounds read in V8
* CVE-2026-3927: Incorrect security UI in PictureInPicture
* CVE-2026-3928: Insufficient policy enforcement in Extensions
* CVE-2026-3929: Side-channel information leakage in ResourceTiming
* CVE-2026-3930: Unsafe navigation in Navigation
* CVE-2026-3931: Heap buffer overflow in Skia
* CVE-2026-3932: Insufficient policy enforcement in PDF
* CVE-2026-3934: Insufficient policy enforcement in ChromeDriver
* CVE-2026-3935: Incorrect security UI in WebAppInstalls
* CVE-2026-3936: Use after free in WebView
* CVE-2026-3937: Incorrect security UI in Downloads
* CVE-2026-3938: Insufficient policy enforcement in Clipboard
* CVE-2026-3939: Insufficient policy enforcement in PDF
* CVE-2026-3940: Insufficient policy enforcement in DevTools
* CVE-2026-3941: Insufficient policy enforcement in DevTools
* CVE-2026-3942: Incorrect security UI in PictureInPicture

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected chromedriver and / or chromium packages.

See Also

https://bugzilla.suse.com/1259530

https://bugzilla.suse.com/1259648

https://bugzilla.suse.com/1259659

https://www.suse.com/security/cve/CVE-2026-3909

https://www.suse.com/security/cve/CVE-2026-3910

https://www.suse.com/security/cve/CVE-2026-3913

https://www.suse.com/security/cve/CVE-2026-3914

https://www.suse.com/security/cve/CVE-2026-3915

https://www.suse.com/security/cve/CVE-2026-3916

https://www.suse.com/security/cve/CVE-2026-3917

https://www.suse.com/security/cve/CVE-2026-3918

https://www.suse.com/security/cve/CVE-2026-3919

https://www.suse.com/security/cve/CVE-2026-3920

https://www.suse.com/security/cve/CVE-2026-3921

https://www.suse.com/security/cve/CVE-2026-3922

https://www.suse.com/security/cve/CVE-2026-3923

https://www.suse.com/security/cve/CVE-2026-3924

https://www.suse.com/security/cve/CVE-2026-3925

https://www.suse.com/security/cve/CVE-2026-3926

https://www.suse.com/security/cve/CVE-2026-3927

https://www.suse.com/security/cve/CVE-2026-3928

https://www.suse.com/security/cve/CVE-2026-3929

https://www.suse.com/security/cve/CVE-2026-3930

https://www.suse.com/security/cve/CVE-2026-3931

https://www.suse.com/security/cve/CVE-2026-3932

https://www.suse.com/security/cve/CVE-2026-3934

https://www.suse.com/security/cve/CVE-2026-3935

https://www.suse.com/security/cve/CVE-2026-3936

https://www.suse.com/security/cve/CVE-2026-3937

https://www.suse.com/security/cve/CVE-2026-3938

https://www.suse.com/security/cve/CVE-2026-3939

https://www.suse.com/security/cve/CVE-2026-3940

https://www.suse.com/security/cve/CVE-2026-3941

https://www.suse.com/security/cve/CVE-2026-3942

Plugin Details

Severity: High

ID: 302994

File Name: openSUSE-2026-20372-1.nasl

Version: 1.1

Type: local

Agent: unix

Published: 3/19/2026

Updated: 3/19/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-3910

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:chromedriver, p-cpe:/a:novell:opensuse:chromium

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/17/2026

Vulnerability Publication Date: 3/10/2026

CISA Known Exploited Vulnerability Due Dates: 3/27/2026

Reference Information

CVE: CVE-2026-3909, CVE-2026-3910, CVE-2026-3913, CVE-2026-3914, CVE-2026-3915, CVE-2026-3916, CVE-2026-3917, CVE-2026-3918, CVE-2026-3919, CVE-2026-3920, CVE-2026-3921, CVE-2026-3922, CVE-2026-3923, CVE-2026-3924, CVE-2026-3925, CVE-2026-3926, CVE-2026-3927, CVE-2026-3928, CVE-2026-3929, CVE-2026-3930, CVE-2026-3931, CVE-2026-3932, CVE-2026-3934, CVE-2026-3935, CVE-2026-3936, CVE-2026-3937, CVE-2026-3938, CVE-2026-3939, CVE-2026-3940, CVE-2026-3941, CVE-2026-3942