openSUSE 16: cockpit / cockpit-bridge / cockpit-devel / cockpit-firewalld / etc (openSUSE-SU-2026:21399-1)

critical Nessus Plugin ID 329307

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21399-1 advisory.

Security issues fixed:

- CVE-2025-13465: lodash: prototype pollution in the _.unset and _.omit functions can lead to deletion of methods from global prototypes (bsc#1257325).
- CVE-2026-4631: SSH command-line argument injection can lead to unauthenticated remote code execution (bsc#1261829).
- CVE-2026-25547: brace-expansion: unbounded brace range expansion can lead to excessive CPU and memory consumption and may crash a Node.js process (bsc#1257836 bsc#1257838 bsc#1257840).
- CVE-2026-26996: minimatch: ReDoS when glob pattern contains many consecutive wildcards followed by a literal character that doesn't appear in the test string (bsc#1258637 bsc#1258640 bsc#1258641).
- CVE-2026-27904: minimatch: nested *() extglobs can lead to regular expressions with exponential backtracking complexity and a ReDoS (bsc#1259010 bsc#1259013 bsc#1259015).

Non security issues fixed:

- cockpit webUI - 'Software updates - install all updates' got an unexpected internal error (bsc#1259210).
- cockpit-machines does not work out of the box, missing libvirt daemon (bsc#1236149).

Changes for cockpit:

- Update to 364.

- Update to 361 (jsc#PED-15706/jsc#CPT-183):

* Remove all Mount actions in Anaconda mode
* Dependency updates

- Update to 360:
* ws: be more explicit when handling hostnames on cli bsc#1261829/CVE-2026-4631
* ws: support loading a custom login page

- Update to 358:

* Networking: Add Wi-Fi support
* Cockpit Client updated to GTK 4
* Bugfixes and translation updates

- Update to 357:

* lib: Use browser context menu on shift
* bridge: support Python 3.14 on old kernels (RHEL 8)

- Update to 356:

* systemd: Allow editing timers created by Cockpit
* Convert license headers to SPDX format

- Update to 355:

* ws: Remove obsolete pam_cockpit_cert module
* shell: add StartTransientUnit as a sudo alternative

Changes for cockpit-machines:

- Update to 354.

- Update to 352:

- Improvements to the Add disk and Create Volume dialogs.

- Update suse_version requirement to function with the planned bump (jsc#PED-15820).
- Drop explict dependency on libvirt (bsc#1258040, bsc#1236149).

- Update to 348:

* Translation updates
* Convert license headers to SPDX format
* Now requires cockpit-devel 356 due to the replacement of xterm/addon-canvas with xterm/addon-webgl

- Update to 347:
* Bug fixes and translation updates

- Fix esbuild for ppc64le (bsc#1257698).

Changes for cockpit-packages:

- Update to version 5:

* Support transactional systems
* Improve error/success messages
* Translation updates

- Patch esbuild to use native runtime on ppc64 (bsc#1257698).

Changes for cockpit-podman:

- Update to 128.
- Fix esbuild for ppc64le (bsc#1257698).

Changes for cockpit-repos:

- Update to 4.8.
- Patch esbuild to use native runtime on ppc64 (bsc#1257698).

Changes for cockpit-subscriptions:

- Update to version 16.2 (bsc#1257033).
- Patch esbuild to use native runtime on ppc64 (bsc#1257698).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1236149

https://bugzilla.suse.com/1257033

https://bugzilla.suse.com/1257325

https://bugzilla.suse.com/1257698

https://bugzilla.suse.com/1257836

https://bugzilla.suse.com/1257838

https://bugzilla.suse.com/1257840

https://bugzilla.suse.com/1258040

https://bugzilla.suse.com/1258637

https://bugzilla.suse.com/1258640

https://bugzilla.suse.com/1258641

https://bugzilla.suse.com/1259010

https://bugzilla.suse.com/1259013

https://bugzilla.suse.com/1259015

https://bugzilla.suse.com/1259210

https://bugzilla.suse.com/1259774

https://bugzilla.suse.com/1261829

https://www.suse.com/security/cve/CVE-2025-13465

https://www.suse.com/security/cve/CVE-2026-25547

https://www.suse.com/security/cve/CVE-2026-26996

https://www.suse.com/security/cve/CVE-2026-27904

https://www.suse.com/security/cve/CVE-2026-4631

https://www.suse.com/security/cve/CVE-2026-4802

Plugin Details

Severity: Critical

ID: 329307

File Name: openSUSE-2026-21399-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/24/2026

Updated: 7/24/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.06

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2025-13465

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 8.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

CVSS Score Source: CVE-2026-25547

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:cockpit-bridge, p-cpe:/a:novell:opensuse:cockpit-devel, p-cpe:/a:novell:opensuse:cockpit-firewalld, p-cpe:/a:novell:opensuse:cockpit-kdump, p-cpe:/a:novell:opensuse:cockpit-machines, p-cpe:/a:novell:opensuse:cockpit-networkmanager, p-cpe:/a:novell:opensuse:cockpit-packagekit, p-cpe:/a:novell:opensuse:cockpit-packages, p-cpe:/a:novell:opensuse:cockpit-podman, p-cpe:/a:novell:opensuse:cockpit-repos, p-cpe:/a:novell:opensuse:cockpit-selinux, p-cpe:/a:novell:opensuse:cockpit-storaged, p-cpe:/a:novell:opensuse:cockpit-subscriptions, p-cpe:/a:novell:opensuse:cockpit-system, p-cpe:/a:novell:opensuse:cockpit-ws-selinux, p-cpe:/a:novell:opensuse:cockpit-ws, p-cpe:/a:novell:opensuse:cockpit

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/21/2026

Vulnerability Publication Date: 1/21/2026

Reference Information

CVE: CVE-2025-13465, CVE-2026-25547, CVE-2026-26996, CVE-2026-27904, CVE-2026-4631, CVE-2026-4802