Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21386-1 advisory.
Update to version 5.10.0.git73.b97f772.
Security issues fixed:
- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555).
- CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651).
- CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817).
- CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding (bsc#1270886).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949).
- CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348).
Other updates and bugfixes:
- Version 5.10.0.git73.b97f772:
* build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284
* build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283
* build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277
- Version 5.10.0.git70.9cc2a7b:
* build(deps): bump openssl from 0.10.78 to 0.10.79
* providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute
* providers/hetzner: Add support for network configuration
* build(deps): bump rustls-webpki from 0.103.10 to 0.103.13
* build(deps): bump openssl from 0.10.73 to 0.10.78
* docs: Add AGENTS.md and CLAUDE.md for AI coding assistants
* build(deps): bump rand from 0.9.2 to 0.9.4
* opencode: add skills for provider scaffolding and release automation
* ibmcloud-classic: Add missing network_id to fixture
* kubevirt: Support static gateway and DNS with DHCP
* build(deps): bump rustls-webpki from 0.103.6 to 0.103.10
* fix(proxmoxve): Define DNS entries for every interface
* Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building
* Sync repo templates
* build(deps): bump bytes from 1.10.1 to 1.11.1
* util/dhcp: Fix clippy lints
* build(deps): bump actions/checkout from 4 to 6
* build(deps): bump actions/upload-artifact from 4 to 5
* kubevirt: modprobe for virtio_blk; remove dracut preload
* kubevirt: Add NoCloud network configuration support
* kubevirt: Support config drive network data
* kubevirt: Refactor the provider to follow the proxmoxve structure
* dracut: Add virtio_blk module preload to afterburn-network-kargs service
* docs: Add release notes
* cargo: Afterburn release 5.10.0
- Version 5.10.0:
* docs/release-notes: update for release 5.10.0
* cargo: update dependencies
* microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat
* docs/release-notes: Add entry for Azure SharedConfig XML parsing fix
* microsoft/azure: Fix SharedConfig parsing of XML attributes
* microsoft/azure: Mock goalstate.SharedConfig output in tests
* providers/azure: switch SSH key retrieval from certs endpoint to IMDS
* build(deps): bump the build group with 8 updates
* build(deps): bump slab from 0.4.10 to 0.4.11
* build(deps): bump actions/checkout from 4 to 5
* upcloud: implement UpCloud provider
* build(deps): bump the build group with 4 updates
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected afterburn and / or afterburn-dracut packages.
Plugin Details
File Name: openSUSE-2026-21386-1.nasl
Agent: unix
Supported Sensors: Continuous Assessment, Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C
Threat Vector: CVSS:4.0/E:P
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:afterburn-dracut, p-cpe:/a:novell:opensuse:afterburn
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 7/20/2026
Vulnerability Publication Date: 2/3/2026