openSUSE 16 Security Update : afterburn (openSUSE-SU-2026:21386-1)

critical Nessus Plugin ID 329301

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21386-1 advisory.

Update to version 5.10.0.git73.b97f772.

Security issues fixed:

- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555).
- CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651).
- CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817).
- CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding (bsc#1270886).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949).
- CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348).

Other updates and bugfixes:

- Version 5.10.0.git73.b97f772:
* build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284
* build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283
* build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277
- Version 5.10.0.git70.9cc2a7b:
* build(deps): bump openssl from 0.10.78 to 0.10.79
* providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute
* providers/hetzner: Add support for network configuration
* build(deps): bump rustls-webpki from 0.103.10 to 0.103.13
* build(deps): bump openssl from 0.10.73 to 0.10.78
* docs: Add AGENTS.md and CLAUDE.md for AI coding assistants
* build(deps): bump rand from 0.9.2 to 0.9.4
* opencode: add skills for provider scaffolding and release automation
* ibmcloud-classic: Add missing network_id to fixture
* kubevirt: Support static gateway and DNS with DHCP
* build(deps): bump rustls-webpki from 0.103.6 to 0.103.10
* fix(proxmoxve): Define DNS entries for every interface
* Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building
* Sync repo templates
* build(deps): bump bytes from 1.10.1 to 1.11.1
* util/dhcp: Fix clippy lints
* build(deps): bump actions/checkout from 4 to 6
* build(deps): bump actions/upload-artifact from 4 to 5
* kubevirt: modprobe for virtio_blk; remove dracut preload
* kubevirt: Add NoCloud network configuration support
* kubevirt: Support config drive network data
* kubevirt: Refactor the provider to follow the proxmoxve structure
* dracut: Add virtio_blk module preload to afterburn-network-kargs service
* docs: Add release notes
* cargo: Afterburn release 5.10.0
- Version 5.10.0:
* docs/release-notes: update for release 5.10.0
* cargo: update dependencies
* microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat
* docs/release-notes: Add entry for Azure SharedConfig XML parsing fix
* microsoft/azure: Fix SharedConfig parsing of XML attributes
* microsoft/azure: Mock goalstate.SharedConfig output in tests
* providers/azure: switch SSH key retrieval from certs endpoint to IMDS
* build(deps): bump the build group with 8 updates
* build(deps): bump slab from 0.4.10 to 0.4.11
* build(deps): bump actions/checkout from 4 to 5
* upcloud: implement UpCloud provider
* build(deps): bump the build group with 4 updates

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected afterburn and / or afterburn-dracut packages.

See Also

https://bugzilla.suse.com/1270175

https://bugzilla.suse.com/1270483

https://bugzilla.suse.com/1270555

https://bugzilla.suse.com/1270651

https://bugzilla.suse.com/1270787

https://bugzilla.suse.com/1270817

https://bugzilla.suse.com/1270886

https://bugzilla.suse.com/1270949

https://bugzilla.suse.com/1271348

https://www.suse.com/security/cve/CVE-2026-25541

https://www.suse.com/security/cve/CVE-2026-41676

https://www.suse.com/security/cve/CVE-2026-41677

https://www.suse.com/security/cve/CVE-2026-41678

https://www.suse.com/security/cve/CVE-2026-41681

https://www.suse.com/security/cve/CVE-2026-41898

https://www.suse.com/security/cve/CVE-2026-42327

https://www.suse.com/security/cve/CVE-2026-44662

https://www.suse.com/security/cve/CVE-2026-45784

Plugin Details

Severity: Critical

ID: 329301

File Name: openSUSE-2026-21386-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/24/2026

Updated: 7/24/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C

CVSS Score Source: CVE-2026-41677

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-41681

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:afterburn-dracut, p-cpe:/a:novell:opensuse:afterburn

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 2/3/2026

Reference Information

CVE: CVE-2026-25541, CVE-2026-41676, CVE-2026-41677, CVE-2026-41678, CVE-2026-41681, CVE-2026-41898, CVE-2026-42327, CVE-2026-44662, CVE-2026-45784