SUSE SLED15: libwireshark19 / libwiretap16 / libwsutil17 / wireshark / etc (SUSE-SU-2026:3501-1)

high Nessus Plugin ID 333022

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3501-1 advisory.

Update to version 4.6.7:

- CVE-2026-5299: ICMPv6 dissector crash (bsc#1263757).
- CVE-2026-5401: AFP dissector crash (bsc#1263756).
- CVE-2026-5402: TLS dissector crash and possible code execution (bsc#1263755).
- CVE-2026-5403: SBC audio codec crash (bsc#1263765).
- CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766).
- CVE-2026-5405: RDP dissector crash (bsc#1263767).
- CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754).
- CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753).
- CVE-2026-5408: BT-DHT dissector crash (bsc#1263752).
- CVE-2026-5409: Monero dissector crash (bsc#1263751).
- CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750).
- CVE-2026-5654: AMR-NB audio codec crash (bsc#1263749).
- CVE-2026-5655: SDP dissector crash (bsc#1263748).
- CVE-2026-5656: Profile import crash and possible code execution (bsc#1263809).
- CVE-2026-5657: iLBC audio codec crash (bsc#1263747).
- CVE-2026-6519: MBIM protocol dissector infinite loop (bsc#1263746).
- CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop (bsc#1263745).
- CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744).
- CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743).
- CVE-2026-6523: GNW protocol dissector infinite loop (bsc#1263742).
- CVE-2026-6524: MySQL protocol dissector crash (bsc#1263741).
- CVE-2026-6525: IEEE 802.11 protocol dissector crash (bsc#1263810).
- CVE-2026-6526: RTSP protocol dissector crash (bsc#1263740).
- CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739).
- CVE-2026-6528: TLS protocol dissector infinite loop (bsc#1263738).
- CVE-2026-6529: iLBC audio codec crash (bsc#1263737).
- CVE-2026-6530: DCP-ETSI protocol dissector crash (bsc#1263736).
- CVE-2026-6531: SANE protocol dissector infinite loop (bsc#1263735).
- CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734).
- CVE-2026-6533: Dissection engine LZ77 decompression crash (bsc#1263733).
- CVE-2026-6534: USB HID dissector infinite loop (bsc#1263732).
- CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731).
- CVE-2026-6536: DLMS/COSEM dissector infinite loop (bsc#1263730).
- CVE-2026-6537: ZigBee dissector crash (bsc#1263729).
- CVE-2026-6538: BEEP dissector crash (bsc#1263728).
- CVE-2026-6867: SMB2 protocol dissector crash (bsc#1263727).
- CVE-2026-6868: HTTP protocol dissector crash (bsc#1263762).
- CVE-2026-6869: WebSocket protocol dissector crash (bsc#1263726).
- CVE-2026-6870: GSM RP protocol dissector crash (bsc#1263725).
- CVE-2026-7375: UDS protocol dissector infinite loop (bsc#1263761).
- CVE-2026-7376: Sharkd utility crash (bsc#1263760).
- CVE-2026-7378: Sharkd utility crash (bsc#1263759).
- CVE-2026-7379: Sharkd utility memory leak (bsc#1263758).
- CVE-2026-9759: ROHC protocol dissector crash (bsc#1266670).
- CVE-2026-15163: Denial of Service via multiple protocol dissector infinite loops (bsc#1271133).
- CVE-2026-15164: Denial of Service vulnerability in ciscodump (bsc#1271134).
- CVE-2026-15165: Denial of Service via TLS ECH decryptor crash (bsc#1271135).
- CVE-2026-15166: Denial of Service via IEEE 802.11 protocol dissector crash (bsc#1271136).
- CVE-2026-15167: Denial of Service via DBS Etherwatch file parser crash (bsc#1271137).
- CVE-2026-15168: BLF file parser allows possible information disclosure (bsc#1271138).
- CVE-2026-15169: Denial of Service via UMTS FP protocol dissector crash (bsc#1271139).
- CVE-2026-15170: Denial of service via Z39.50 protocol dissector crash (bsc#1271140).
- CVE-2026-15171: Denial of service via SSH protocol dissector crash (bsc#1271141).
- CVE-2026-15172: Denial of service via FMP/NOTIFY protocol dissector crash (bsc#1271142).
- CVE-2026-15173: Denial of Service via pcapng file parser crash (bsc#1271143).
- CVE-2026-15174: Denial of Service via Catapult DCT2000 protocol dissector crash (bsc#1271144).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1263725

https://bugzilla.suse.com/1263726

https://bugzilla.suse.com/1263727

https://bugzilla.suse.com/1263728

https://bugzilla.suse.com/1263729

https://bugzilla.suse.com/1263730

https://bugzilla.suse.com/1263731

https://bugzilla.suse.com/1263732

https://bugzilla.suse.com/1263733

https://bugzilla.suse.com/1263734

https://bugzilla.suse.com/1263735

https://bugzilla.suse.com/1263736

https://bugzilla.suse.com/1263737

https://bugzilla.suse.com/1263738

https://bugzilla.suse.com/1263739

https://bugzilla.suse.com/1263740

https://bugzilla.suse.com/1263741

https://bugzilla.suse.com/1263742

https://bugzilla.suse.com/1263743

https://bugzilla.suse.com/1263744

https://bugzilla.suse.com/1263745

https://bugzilla.suse.com/1263746

https://bugzilla.suse.com/1263747

https://bugzilla.suse.com/1263748

https://bugzilla.suse.com/1263749

https://bugzilla.suse.com/1263750

https://bugzilla.suse.com/1263751

https://bugzilla.suse.com/1263752

https://bugzilla.suse.com/1263753

https://bugzilla.suse.com/1263754

https://bugzilla.suse.com/1263755

https://bugzilla.suse.com/1263756

https://bugzilla.suse.com/1263757

https://bugzilla.suse.com/1263758

https://bugzilla.suse.com/1263759

https://bugzilla.suse.com/1263760

https://bugzilla.suse.com/1263761

https://bugzilla.suse.com/1263762

https://bugzilla.suse.com/1263765

https://bugzilla.suse.com/1263766

https://bugzilla.suse.com/1263767

https://bugzilla.suse.com/1263809

https://bugzilla.suse.com/1263810

https://bugzilla.suse.com/1266670

https://bugzilla.suse.com/1271133

https://bugzilla.suse.com/1271134

https://bugzilla.suse.com/1271135

https://bugzilla.suse.com/1271136

https://bugzilla.suse.com/1271137

https://bugzilla.suse.com/1271138

https://bugzilla.suse.com/1271139

https://bugzilla.suse.com/1271140

https://bugzilla.suse.com/1271141

https://bugzilla.suse.com/1271142

https://bugzilla.suse.com/1271143

https://bugzilla.suse.com/1271144

https://www.suse.com/security/cve/CVE-2026-15163

https://www.suse.com/security/cve/CVE-2026-15164

https://www.suse.com/security/cve/CVE-2026-15165

https://www.suse.com/security/cve/CVE-2026-15166

https://www.suse.com/security/cve/CVE-2026-15167

https://www.suse.com/security/cve/CVE-2026-15168

https://www.suse.com/security/cve/CVE-2026-15169

https://www.suse.com/security/cve/CVE-2026-15170

https://www.suse.com/security/cve/CVE-2026-15171

https://www.suse.com/security/cve/CVE-2026-15172

https://www.suse.com/security/cve/CVE-2026-15173

https://www.suse.com/security/cve/CVE-2026-15174

https://www.suse.com/security/cve/CVE-2026-5299

https://www.suse.com/security/cve/CVE-2026-5401

https://www.suse.com/security/cve/CVE-2026-5402

https://www.suse.com/security/cve/CVE-2026-5403

https://www.suse.com/security/cve/CVE-2026-5404

https://www.suse.com/security/cve/CVE-2026-5405

https://www.suse.com/security/cve/CVE-2026-5406

https://www.suse.com/security/cve/CVE-2026-5407

https://www.suse.com/security/cve/CVE-2026-5408

https://www.suse.com/security/cve/CVE-2026-5409

https://www.suse.com/security/cve/CVE-2026-5653

https://www.suse.com/security/cve/CVE-2026-5654

https://www.suse.com/security/cve/CVE-2026-5655

https://www.suse.com/security/cve/CVE-2026-5656

https://www.suse.com/security/cve/CVE-2026-5657

https://www.suse.com/security/cve/CVE-2026-6519

https://www.suse.com/security/cve/CVE-2026-6520

https://www.suse.com/security/cve/CVE-2026-6521

https://www.suse.com/security/cve/CVE-2026-6522

https://www.suse.com/security/cve/CVE-2026-6523

https://www.suse.com/security/cve/CVE-2026-6524

https://www.suse.com/security/cve/CVE-2026-6525

https://www.suse.com/security/cve/CVE-2026-6526

https://www.suse.com/security/cve/CVE-2026-6527

https://www.suse.com/security/cve/CVE-2026-6528

https://www.suse.com/security/cve/CVE-2026-6529

https://www.suse.com/security/cve/CVE-2026-6530

https://www.suse.com/security/cve/CVE-2026-6531

https://www.suse.com/security/cve/CVE-2026-6532

https://www.suse.com/security/cve/CVE-2026-6533

https://www.suse.com/security/cve/CVE-2026-6534

https://www.suse.com/security/cve/CVE-2026-6535

https://www.suse.com/security/cve/CVE-2026-6536

https://www.suse.com/security/cve/CVE-2026-6537

https://www.suse.com/security/cve/CVE-2026-6538

https://www.suse.com/security/cve/CVE-2026-6867

https://www.suse.com/security/cve/CVE-2026-6868

https://www.suse.com/security/cve/CVE-2026-6869

https://www.suse.com/security/cve/CVE-2026-6870

https://www.suse.com/security/cve/CVE-2026-7375

https://www.suse.com/security/cve/CVE-2026-7376

https://www.suse.com/security/cve/CVE-2026-7378

https://www.suse.com/security/cve/CVE-2026-7379

https://www.suse.com/security/cve/CVE-2026-9759

http://www.nessus.org/u?889daf90

Plugin Details

Severity: High

ID: 333022

File Name: suse_SU-2026-3501-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/6/2026

Updated: 8/6/2026

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.04

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-7379

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-5656

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:libwireshark19, p-cpe:/a:novell:suse_linux:libwiretap16, p-cpe:/a:novell:suse_linux:libwsutil17, p-cpe:/a:novell:suse_linux:wireshark-devel, p-cpe:/a:novell:suse_linux:wireshark-ui-qt, p-cpe:/a:novell:suse_linux:wireshark

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/5/2026

Vulnerability Publication Date: 10/8/2024

Reference Information

CVE: CVE-2026-15163, CVE-2026-15164, CVE-2026-15165, CVE-2026-15166, CVE-2026-15167, CVE-2026-15168, CVE-2026-15169, CVE-2026-15170, CVE-2026-15171, CVE-2026-15172, CVE-2026-15173, CVE-2026-15174, CVE-2026-5299, CVE-2026-5401, CVE-2026-5402, CVE-2026-5403, CVE-2026-5404, CVE-2026-5405, CVE-2026-5406, CVE-2026-5407, CVE-2026-5408, CVE-2026-5409, CVE-2026-5653, CVE-2026-5654, CVE-2026-5655, CVE-2026-5656, CVE-2026-5657, CVE-2026-6519, CVE-2026-6520, CVE-2026-6521, CVE-2026-6522, CVE-2026-6523, CVE-2026-6524, CVE-2026-6525, CVE-2026-6526, CVE-2026-6527, CVE-2026-6528, CVE-2026-6529, CVE-2026-6530, CVE-2026-6531, CVE-2026-6532, CVE-2026-6533, CVE-2026-6534, CVE-2026-6535, CVE-2026-6536, CVE-2026-6537, CVE-2026-6538, CVE-2026-6867, CVE-2026-6868, CVE-2026-6869, CVE-2026-6870, CVE-2026-7375, CVE-2026-7376, CVE-2026-7378, CVE-2026-7379, CVE-2026-9759

IAVB: 2026-B-0112-S, 2026-B-0191

SuSE: SUSE-SU-2026:3501-1