SUSE SLED15 / SLES15 Security Update : netty, netty-tcnative (SUSE-SU-2026:3482-1)

high Nessus Plugin ID 332130

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3482-1 advisory.

Upgrade netty to upstream version 4.1.136 and netty-tcnative to version 2.0.80 Final.

Security issues fixed

- CVE-2026-44891: memory exhaustion in `io.netty:netty-codec-stomp` (bsc#1271435).
- CVE-2026-55831: resource exhaustion/DoS in `io.netty:netty-codec-http` (bsc#1271960).
- CVE-2026-55833: zip bomb in `io.netty:netty-codec-http` (bsc#1271961).
- CVE-2026-55851: memory exhaustion in `io.netty:netty-codec-haproxy` (bsc#1272253).
- CVE-2026-56745: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272254).
- CVE-2026-56746: improper access control in `io.netty:netty-codec-http` (CORS) (bsc#1272255).
- CVE-2026-56817: insecure defaults in XML parsing in `io.netty:netty-codec-xml` (bsc#1272257).
- CVE-2026-56818: memory leak in `io.netty:netty-codec-redis` (bsc#1272603).
- CVE-2026-56819: memory leak in `io.netty:netty-codec-http2` (bsc#1272258).
- CVE-2026-56820: improper certificate validation in `io.netty:netty-handler-ssl-ocsp` (bsc#1272259).
- CVE-2026-56821: improper certificate revocation check in `io.netty:netty-handler-ssl-ocsp` (bsc#1272299).
- CVE-2026-56822: time-of-check/time-of-use in `io.netty:netty-handler-ssl-ocsp` (bsc#1272300).
- CVE-2026-59898: protocol version confusion in `io.netty:netty-codec-http` (websocket) (bsc#1272302).
- CVE-2026-59899: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272301).
- CVE-2026-59900: improper header neutralization in `io.netty:netty-codec-http2` (bsc#1272303).
- CVE-2026-59901: infinite loop in `io.netty:netty-codec-compression` (bzip2) (bsc#1272304).
- CVE-2026-59919: improper CR/LF neutralization in `io.netty:netty-codec-haproxy` (bsc#1272305).
- CVE-2026-59920: improper CR/LF neutrolization in `io.netty:netty-codec-stomp` (bsc#1272306).
- CVE-2026-59921: improper CR/LF neutralization in `io.netty:netty-codec-http` (multipart) (bsc#1272307).
- Memory leak in `io.netty:netty-codec-dns` (bsc#1272519).
- Uncontrolled resource consumption in `io.netty:netty-codec-xml` (bsc#1272518).

Other updates and bugfixes:

- Upgrade to upstream version 4.1.136:
- SingleThreadEventExecutor: document Throwable safety contract on run()
- Make HTTP/2 frame hashCode consistent with equals
- Add BlockHound exception for DnsQueryIdSpace (#16896)
- FlowControlHandler: Fix autoRead behavior
- Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize
- MQTT: Fix MQTT decoder size check after variable header replay
- MQTT: Make the decodeProperties early-REPLAY check actually fire
- Reject control characters at the boundary of HTTP method names (#16723)
- Update to latest tcnative release
- Fix HTTP 2 PUSH_PROMISE stream association validation
- Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder
- Add opt-in validation of mandatory pseudo-header fields for HTTP/2
- Strictly validate MQTT UTF-8 Encoded String (#16939)
- Stop DateFormatter trailing token from running past the parse end
- IpFilter: Deprecate constructor which use accept by default
- Add RFC 10008 QUERY Method support (#16966)
- Correctly release and fail queued traffic-shaping writes on close (#16959)
- FlowControlHandler: respect auto-read when toggled while dequeueing
- IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout (#16982)
- Fix typo in AbstractSniHandler Javadoc
- Reconcile AbstractCoalescingBufferQueue readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames
- Reject control characters at the boundary of the HTTP version token (#16971)
- Reset UTF-8 decode state on CR in StompSubframeDecoder
- HTTP2: Pass the correct number of arguments when logging goaway + FastLz: Guard decompression against truncated input (#17000) + Fix propagation of startTls for client SslContext handler + Reject non-token characters in HTTP/2 header names + Update lz4-java to 1.11.1 + Pin github actions to reduce risk (#17043) + Merge branches from forks (#17063)

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected netty, netty-javadoc and / or netty-tcnative packages.

See Also

https://bugzilla.suse.com/1271435

https://bugzilla.suse.com/1271960

https://bugzilla.suse.com/1271961

https://bugzilla.suse.com/1272253

https://bugzilla.suse.com/1272254

https://bugzilla.suse.com/1272255

https://bugzilla.suse.com/1272257

https://bugzilla.suse.com/1272258

https://bugzilla.suse.com/1272259

https://bugzilla.suse.com/1272299

https://bugzilla.suse.com/1272300

https://bugzilla.suse.com/1272301

https://bugzilla.suse.com/1272302

https://bugzilla.suse.com/1272303

https://bugzilla.suse.com/1272304

https://bugzilla.suse.com/1272305

https://bugzilla.suse.com/1272306

https://bugzilla.suse.com/1272307

https://bugzilla.suse.com/1272518

https://bugzilla.suse.com/1272519

https://bugzilla.suse.com/1272603

https://www.suse.com/security/cve/CVE-2026-44891

https://www.suse.com/security/cve/CVE-2026-55831

https://www.suse.com/security/cve/CVE-2026-55833

https://www.suse.com/security/cve/CVE-2026-55851

https://www.suse.com/security/cve/CVE-2026-56745

https://www.suse.com/security/cve/CVE-2026-56746

https://www.suse.com/security/cve/CVE-2026-56817

https://www.suse.com/security/cve/CVE-2026-56818

https://www.suse.com/security/cve/CVE-2026-56819

https://www.suse.com/security/cve/CVE-2026-56820

https://www.suse.com/security/cve/CVE-2026-56821

https://www.suse.com/security/cve/CVE-2026-56822

https://www.suse.com/security/cve/CVE-2026-59898

https://www.suse.com/security/cve/CVE-2026-59899

https://www.suse.com/security/cve/CVE-2026-59900

https://www.suse.com/security/cve/CVE-2026-59901

https://www.suse.com/security/cve/CVE-2026-59919

https://www.suse.com/security/cve/CVE-2026-59920

https://www.suse.com/security/cve/CVE-2026-59921

http://www.nessus.org/u?298d5f37

Plugin Details

Severity: High

ID: 332130

File Name: suse_SU-2026-3482-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/5/2026

Updated: 8/5/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 96.31

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-56817

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-59901

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:netty-javadoc, p-cpe:/a:novell:suse_linux:netty-tcnative, p-cpe:/a:novell:suse_linux:netty

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/4/2026

Vulnerability Publication Date: 7/14/2026

Reference Information

CVE: CVE-2026-44891, CVE-2026-55831, CVE-2026-55833, CVE-2026-55851, CVE-2026-56745, CVE-2026-56746, CVE-2026-56817, CVE-2026-56818, CVE-2026-56819, CVE-2026-56820, CVE-2026-56821, CVE-2026-56822, CVE-2026-59898, CVE-2026-59899, CVE-2026-59900, CVE-2026-59901, CVE-2026-59919, CVE-2026-59920, CVE-2026-59921

SuSE: SUSE-SU-2026:3482-1