openSUSE 16 Security Update : chromium (openSUSE-SU-2026:20460-1)

high Nessus Plugin ID 305034

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:20460-1 advisory.

Changes in chromium:

- Chromium 146.0.7680.177 (boo#1261249)
* CVE-2026-5273: Use after free in CSS
* CVE-2026-5272: Heap buffer overflow in GPU
* CVE-2026-5274: Integer overflow in Codecs
* CVE-2026-5275: Heap buffer overflow in ANGLE
* CVE-2026-5276: Insufficient policy enforcement in WebUSB
* CVE-2026-5277: Integer overflow in ANGLE
* CVE-2026-5278: Use after free in Web MIDI
* CVE-2026-5279: Object corruption in V8
* CVE-2026-5280: Use after free in WebCodecs
* CVE-2026-5281: Use after free in Dawn
* CVE-2026-5282: Out of bounds read in WebCodecs
* CVE-2026-5283: Inappropriate implementation in ANGLE
* CVE-2026-5284: Use after free in Dawn
* CVE-2026-5285: Use after free in WebGL
* CVE-2026-5286: Use after free in Dawn
* CVE-2026-5287: Use after free in PDF
* CVE-2026-5288: Use after free in WebView
* CVE-2026-5289: Use after free in Navigation
* CVE-2026-5290: Use after free in Compositing
* CVE-2026-5291: Inappropriate implementation in WebGL
* CVE-2026-5292: Out of bounds read in WebCodecs

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected chromedriver and / or chromium packages.

See Also

https://bugzilla.suse.com/1261249

https://www.suse.com/security/cve/CVE-2026-5272

https://www.suse.com/security/cve/CVE-2026-5273

https://www.suse.com/security/cve/CVE-2026-5274

https://www.suse.com/security/cve/CVE-2026-5275

https://www.suse.com/security/cve/CVE-2026-5276

https://www.suse.com/security/cve/CVE-2026-5277

https://www.suse.com/security/cve/CVE-2026-5278

https://www.suse.com/security/cve/CVE-2026-5279

https://www.suse.com/security/cve/CVE-2026-5280

https://www.suse.com/security/cve/CVE-2026-5281

https://www.suse.com/security/cve/CVE-2026-5282

https://www.suse.com/security/cve/CVE-2026-5283

https://www.suse.com/security/cve/CVE-2026-5284

https://www.suse.com/security/cve/CVE-2026-5285

https://www.suse.com/security/cve/CVE-2026-5286

https://www.suse.com/security/cve/CVE-2026-5287

https://www.suse.com/security/cve/CVE-2026-5288

https://www.suse.com/security/cve/CVE-2026-5289

https://www.suse.com/security/cve/CVE-2026-5290

https://www.suse.com/security/cve/CVE-2026-5291

https://www.suse.com/security/cve/CVE-2026-5292

Plugin Details

Severity: High

ID: 305034

File Name: openSUSE-2026-20460-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 4/5/2026

Updated: 4/5/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.2

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-5282

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:chromium, p-cpe:/a:novell:opensuse:chromedriver, cpe:/o:novell:opensuse:16.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/3/2026

Vulnerability Publication Date: 3/31/2026

CISA Known Exploited Vulnerability Due Dates: 4/15/2026

Reference Information

CVE: CVE-2026-5272, CVE-2026-5273, CVE-2026-5274, CVE-2026-5275, CVE-2026-5276, CVE-2026-5277, CVE-2026-5278, CVE-2026-5279, CVE-2026-5280, CVE-2026-5281, CVE-2026-5282, CVE-2026-5283, CVE-2026-5284, CVE-2026-5285, CVE-2026-5286, CVE-2026-5287, CVE-2026-5288, CVE-2026-5289, CVE-2026-5290, CVE-2026-5291, CVE-2026-5292