openSUSE 16 Security Update : vexctl (openSUSE-SU-2026:21481-1)

high Nessus Plugin ID 331568

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has a package installed that is affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21481-1 advisory.

- CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234486).
- CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239186).
- CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239323).
- CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238683).
- CVE-2025-27144: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237611).
- CVE-2025-30204: github.com/golang-jwt/jwt/v4: jwt-go allows excessive memory allocation during header parsing (bsc#1240444).
- CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253802).
- CVE-2026-22772: github.com/sigstore/fulcio: bypass MetaIssuer URL validation bypass can trigger SSRF to arbitrary internal services (bsc#1256535).
- CVE-2026-24137: github.com/sigstore/sigstore/pkg/tuf: legacy TUF client allows for arbitrary file writes with target cache path traversal (bsc#1257138).

Changes for vexctl:

- Update to version 0.4.4+git20.5d61136:

* build(deps): Bump github.com/sigstore/cosign/v2
* build(deps): Bump actions/setup-go from 6.5.0 to 7.0.0
* build(deps): Bump the all group across 1 directory with 5 updates
* build(deps): Bump github.com/sigstore/rekor in the all group
* build(deps): Bump the all group with 4 updates
* build(deps): Bump github.com/google/go-containerregistry
* build(deps): Bump actions/setup-go from 6.4.0 to 6.5.0 in the all group
* build(deps): Bump the all group across 1 directory with 2 updates
* build(deps): Bump actions/checkout from 6.0.3 to 7.0.0
* build(deps): Bump chainguard-dev/actions in the all group

- Update to version 0.4.4:

* fix signature duplication
* fix lints
* housekeeping - deps update and ci cleanup
* build(deps): Bump the all group with 2 updates
* build(deps): Bump github.com/sigstore/sigstore in the all group
* build(deps): Bump golangci/golangci-lint-action in the all group

- Update to version 0.4.1+git147.b7e6ef0:

* build(deps): Bump goreleaser/goreleaser-action in the all group
* Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the all group
* Bump chainguard-dev/actions from 1.6.17 to 1.6.19 in the all group
* Bump chainguard-dev/actions from 1.6.16 to 1.6.17 in the all group
* Bump github.com/package-url/packageurl-go in the all group
* Bump the all group with 2 updates

- Update to version 0.4.1+git133.efecaf7:

* Bump github.com/secure-systems-lab/go-securesystemslib

- Update to version 0.4.1+git129.c7f3066:

* Bump github.com/google/go-containerregistry in the all group
* Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6
* Bump softprops/action-gh-release from 2.6.1 to 3.0.0
* Bump chainguard-dev/actions from 1.6.13 to 1.6.14 in the all group
* Bump actions/upload-artifact from 7.0.0 to 7.0.1 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.6.2 to 2.6.3 in the all group
* Bump kubernetes-sigs/release-actions in the all group
* Bump github.com/in-toto/in-toto-golang from 0.9.0 to 0.10.0
* Bump the all group across 1 directory with 2 updates
* Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4
* fix(add): allow add without --product flag
* Use gomod version, bump linter
* Port vexctl to intoto/attestation
* Bump the all group across 1 directory with 5 updates
* Bump google.golang.org/grpc from 1.78.0 to 1.79.3

- Update to version 0.4.1+git96.558125d:

* Bump the all group across 1 directory with 3 updates
* Bump chainguard-dev/actions from 1.6.5 to 1.6.6 in the all group
* Bump github.com/google/go-containerregistry from 0.20.7 to 0.21.0
* Bump actions/upload-artifact from 6.0.0 to 7.0.0
* Bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0
* Bump chainguard-dev/actions from 1.6.2 to 1.6.4 in the all group

- Update to version 0.4.1+git78.f951e3a:

* Bump chainguard-dev/actions from 1.6.1 to 1.6.2 in the all group

- Update to version 0.4.1+git76.10d7a2e:

* Bump chainguard-dev/actions from 1.6.0 to 1.6.1 in the all group
* Bump chainguard-dev/actions from 1.5.16 to 1.6.0 in the all group
* Bump chainguard-dev/actions from 1.5.14 to 1.5.16 in the all group
* Bump chainguard-dev/actions from 1.5.13 to 1.5.14 in the all group
* Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0
* Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.4.1
* Bump actions/setup-go from 6.1.0 to 6.2.0 in the all group
* Bump github.com/sigstore/fulcio from 1.8.4 to 1.8.5
* Bump github.com/sigstore/cosign/v2 from 2.6.1 to 2.6.2 in the all group
* Bump chainguard-dev/actions from 1.5.10 to 1.5.11 in the all group
* Bump github.com/sigstore/fulcio from 1.7.1 to 1.8.3
* Bump github.com/sigstore/sigstore
* Bump actions/upload-artifact from 5.0.0 to 6.0.0
* bump golangci-lint
* update gorelease sing to works with cosign 3.0+
* Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 in the all group
* Bump golangci/golangci-lint-action from 9.1.0 to 9.2.0 in the all group
* Bump actions/checkout from 6.0.0 to 6.0.1 in the all group
* Bump softprops/action-gh-release from 2.4.2 to 2.5.0 in the all group
* Bump chainguard-dev/actions from 1.5.9 to 1.5.10 in the all group
* Bump golangci/golangci-lint-action from 8.0.0 to 9.1.0
* Bump actions/checkout from 5.0.1 to 6.0.0
* Bump actions/setup-go from 6.0.0 to 6.1.0 in the all group
* Bump golang.org/x/crypto from 0.43.0 to 0.45.0
* Bump github.com/sigstore/rekor from 1.4.2 to 1.4.3 in the all group
* Bump actions/upload-artifact from 4.6.2 to 5.0.0
* Bump chainguard-dev/actions from 1.5.6 to 1.5.7 in the all group
* Bump sigstore/cosign-installer from 3.10.0 to 4.0.0
* Bump chainguard-dev/actions from 1.5.4 to 1.5.6 in the all group
* Bump softprops/action-gh-release from 2.3.4 to 2.4.0 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.6.0 to 2.6.1 in the all group

- Update to version 0.4.1:

* Reverse platform+os naming scheme

- Update to version 0.4.0:

* update go, goreleaser and update/clean ci
* Bump sigs.k8s.io/release-utils from 0.12.1 to 0.12.2 in the all group

- Packaging improvements:

* Update to BuildRequires: golang(API) >= 1.25 matching go.mod

- Update to version 0.3.0+git181.33bac59:

* Bump sigstore/cosign-installer from 3.9.2 to 3.10.0 in the all group
* Fix break w/cosign 2.6.0
* Bump cosign & go-vex
* Fix 2.4 linter nits
* Bump softprops/action-gh-release from 2.3.2 to 2.3.3 in the all group
* Bump github.com/spf13/cobra from 1.9.1 to 1.10.1
* Bump actions/setup-go from 5.5.0 to 6.0.0
* Bump github.com/stretchr/testify from 1.11.0 to 1.11.1 in the all group
* Bump github.com/stretchr/testify from 1.10.0 to 1.11.0
* Bump github.com/go-viper/mapstructure/v2 in the go_modules group
* Bump goreleaser/goreleaser-action from 6.3.0 to 6.4.0 in the all group
* update release-utils and fix pkg name
* Bump actions/checkout from 4.2.2 to 5.0.0
* Bump github.com/secure-systems-lab/go-securesystemslib in the all group
* Bump github.com/sigstore/rekor from 1.3.10 to 1.4.0
* Bump sigs.k8s.io/release-utils from 0.11.1 to 0.12.0
* Bump sigstore/cosign-installer from 3.9.1 to 3.9.2 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.5.2 to 2.5.3 in the all group
* Bump sigstore/cosign-installer from 3.9.0 to 3.9.1 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.5.1 to 2.5.2 in the all group
* Bump sigstore/cosign-installer from 3.8.2 to 3.9.0 in the all group
* migrate config to v2
* Bump golangci/golangci-lint-action from 6.5.2 to 8.0.0

- Update to version 0.3.0+git133.ff97560:

* Bump softprops/action-gh-release from 2.3.0 to 2.3.2 in the all group
* Bump github.com/cloudflare/circl in the go_modules group
* Bump softprops/action-gh-release from 2.2.2 to 2.3.0 in the all group
* Bump actions/setup-go from 5.4.0 to 5.5.0 in the all group
* Bump github.com/sigstore/sigstore from 1.9.3 to 1.9.4 in the all group
* Bump sigstore/cosign-installer from 3.8.1 to 3.8.2 in the all group
* Bump softprops/action-gh-release from 2.2.1 to 2.2.2 in the all group
* Bump ko-build/setup-ko from 0.8 to 0.9 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.4.3 to 2.5.0
* Bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.11.0 to 0.11.1 in the all group
* Bump github.com/golang-jwt/jwt/v4 in the go_modules group
* Bump golangci/golangci-lint-action from 6.5.1 to 6.5.2 in the all group
* Bump github.com/sigstore/sigstore from 1.8.15 to 1.9.1
* Bump golang.org/x/net from 0.35.0 to 0.36.0 in the go_modules group
* Bump golangci/golangci-lint-action from 6.5.0 to 6.5.1 in the all group
* Bump github.com/go-jose/go-jose/v3 in the go_modules group
* Bump github.com/go-jose/go-jose/v4 in the go_modules group
* Bump actions/upload-artifact from 4.6.0 to 4.6.1 in the all group
* Bump sigstore/cosign-installer from 3.8.0 to 3.8.1 in the all group
* use go1.24 and update golangci-lint
* Bump golangci/golangci-lint-action from 6.3.3 to 6.5.0 in the all group
* Bump github.com/spf13/cobra from 1.8.1 to 1.9.1
* Bump github.com/sigstore/sigstore from 1.8.12 to 1.8.14 in the all group
* Bump golangci/golangci-lint-action from 6.3.2 to 6.3.3 in the all group
* Bump goreleaser/goreleaser-action from 6.1.0 to 6.2.1 in the all group
* Bump golangci/golangci-lint-action from 6.3.0 to 6.3.2 in the all group
* Bump sigstore/cosign-installer from 3.7.0 to 3.8.0 in the all group
* Bump golangci/golangci-lint-action from 6.2.0 to 6.3.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.9.0 to 0.10.0
* Bump github.com/sigstore/rekor from 1.3.8 to 1.3.9 in the all group
* Bump actions/setup-go from 5.2.0 to 5.3.0 in the all group
* Bump golangci/golangci-lint-action from 6.1.1 to 6.2.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.8.5 to 0.9.0
* Bump go dependencies manually
* Bump ko-build/setup-ko from 0.7 to 0.8 in the all group
* Bump actions/upload-artifact from 4.5.0 to 4.6.0 in the all group
* Bump softprops/action-gh-release from 2.2.0 to 2.2.1 in the all group
* Bump actions/upload-artifact from 4.4.3 to 4.5.0 in the all group
* Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in the go_modules group
* Bump softprops/action-gh-release from 2.0.9 to 2.1.0 in the all group
* Bump goreleaser/goreleaser-action from 6.0.0 to 6.1.0 in the all group
* Bump softprops/action-gh-release from 2.0.8 to 2.0.9 in the all group
* Update verify.yaml
* Update release.yaml
* Update ci-build-test.yaml
* Bump actions/setup-go from 5.0.2 to 5.1.0 in the all group
* Bump actions/checkout from 4.2.1 to 4.2.2 in the all group
* Bump github.com/sigstore/sigstore from 1.8.9 to 1.8.10 in the all group
* Bump actions/upload-artifact from 4.4.2 to 4.4.3 in the all group
* Bump actions/upload-artifact from 4.4.1 to 4.4.2 in the all group
* Bump sigstore/cosign-installer from 3.6.0 to 3.7.0 in the all group
* Bump golangci/golangci-lint-action from 6.1.0 to 6.1.1 in the all group
* Bump github.com/sigstore/cosign/v2 from 2.4.0 to 2.4.1 in the all group
* Bump actions/checkout from 4.1.7 to 4.2.0 in the all group
* Bump sigs.k8s.io/release-utils from 0.8.4 to 0.8.5 in the all group
* upgrade to go1.23

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected vexctl package.

See Also

https://bugzilla.suse.com/1234486

https://bugzilla.suse.com/1237611

https://bugzilla.suse.com/1238683

https://bugzilla.suse.com/1239186

https://bugzilla.suse.com/1239323

https://bugzilla.suse.com/1240444

https://bugzilla.suse.com/1253802

https://bugzilla.suse.com/1256535

https://bugzilla.suse.com/1257138

https://www.suse.com/security/cve/CVE-2024-45337

https://www.suse.com/security/cve/CVE-2025-22868

https://www.suse.com/security/cve/CVE-2025-22869

https://www.suse.com/security/cve/CVE-2025-22870

https://www.suse.com/security/cve/CVE-2025-27144

https://www.suse.com/security/cve/CVE-2025-30204

https://www.suse.com/security/cve/CVE-2025-58181

https://www.suse.com/security/cve/CVE-2026-22772

https://www.suse.com/security/cve/CVE-2026-24137

Plugin Details

Severity: High

ID: 331568

File Name: openSUSE-2026-21481-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/1/2026

Updated: 8/1/2026

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.81

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-22772

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2025-27144

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:vexctl

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/30/2026

Vulnerability Publication Date: 12/11/2024

Reference Information

CVE: CVE-2024-45337, CVE-2025-22868, CVE-2025-22869, CVE-2025-22870, CVE-2025-27144, CVE-2025-30204, CVE-2025-58181, CVE-2026-22772, CVE-2026-24137