openSUSE 16: bouncycastle / bouncycastle-javadoc / bouncycastle-jmail / etc (openSUSE-SU-2026:21538-1)

critical Nessus Plugin ID 333511

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21538-1 advisory.

Update to 1.85.

Security issues fixed:

- CVE-2026-8763: Name Constraints bypass via trailing dot in rfc822Name and URI (bsc#1272700).
- CVE-2026-12185: BKS/UBER keystore allocates from untrusted lengths before integrity check (bsc#1272701).
- CVE-2026-12802: CMS AuthEnvelopedData fails to enforce tag-length on decryption (bsc#1272702).
- CVE-2026-12803: KCCMBlockCipher MAC does not bind nonce when AAD is absent (bsc#1272703).
- CVE-2026-12816: IESEngine stream-mode MAC forgery via length-dependent KDF split (bsc#1272704).
- CVE-2026-12817: OpenPGP AEAD decryption skips final tag on chunk-aligned data (bsc#1272705).
- CVE-2026-12852: MLS wire decoder allocates attacker-declared opaque length before bounds check (bsc#1272707).
- CVE-2026-12860: RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path (bsc#1272708).
- CVE-2026-13506: Lazy ASN.1 sequence forcing resets nesting-depth guard (bsc#1272709).
- CVE-2026-13586: PKCS#12 MAC and bag-decryption KDF iteration-count bound (bsc#1272710).
- CVE-2026-14682: Possible OOM from unbounded up-front allocation on a definite-length read (bsc#1272711).
- CVE-2026-15055: PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input (bsc#1272712).
- CVE-2026-58059: Quadratic-time escaping when stringifying X.500 distinguished names (bsc#1272713).
- CVE-2026-58060: HSS public-key level count unbounded, enabling huge allocation on verify (bsc#1272714).
- CVE-2026-58061: CCM-family modes write plaintext to caller buffer before tag check (bsc#1272715).
- CVE-2026-58062: Stapled OCSP response accepted without binding to the checked certificate (bsc#1272716).
- CVE-2026-58063: BCFKS keystore load honours unbounded KDF cost from untrusted file (bsc#1272717).
- CVE-2026-59638: JSSE hostname verifier CN-fallback enabled by default despite documented opt-in (bsc#1272718).
- CVE-2026-59639: CMS verifySignatures returns true for SignedData with zero signers (bsc#1272719).
- CVE-2026-59640: OpenPGP CFB quick-check oracle active on symmetric/session-key paths (bsc#1272720).
- CVE-2026-59641: S/MIME validator trusts signer-asserted signingTime for path validation (bsc#1272721).
- CVE-2026-59642: CMS AuthenticatedData content not bound to MAC when authAttrs present (bsc#1272722).
- CVE-2026-59643: OpenPGP inline-signature policy failures silently ignored (bsc#1272723).
- CVE-2026-59644: MLS hash-ratchet honours arbitrary 32-bit generation counter from sender (bsc#1272724).
- CVE-2026-59645: OER parser recurses without depth limit on self-referential IEEE 1609.2 schema (bsc#1272725).
- CVE-2026-59646: DTLS handshake reassembler allocates buffer from unchecked 24-bit length (bsc#1272726).
- CVE-2026-59647: CRMF/CMP password-MAC honours unbounded iteration count (bsc#1272727).
- CVE-2026-59648: OpenPGP Argon2 S2K honours attacker-chosen memory and passes (bsc#1272728).
- CVE-2026-59649: OpenPGP user-attribute subpacket length bounded only by JVM max memory (bsc#1272729).
- CVE-2026-59650: MTI/A0 DH agreement exponentiates unvalidated peer value (bsc#1272730).
- CVE-2026-59651: BKS keystore accepts legacy version with 16-bit integrity MAC key (bsc#1272731).
- CVE-2026-59652: LDAP filter injection in legacy jdk1.4 LDAPStoreHelper (bsc#1272732).

Additional notes:

- The standardised PQC algorithms ML-KEM, ML-DSA, SLH-DSA, FrodoKEM, and CMCE have been repackaged under `org.bouncycastle.crypto` and the versions under `org.bouncycastle.crypto.pqc` have been deprecated.
These deprecated versions will be removed in BC 1.86.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1272700

https://bugzilla.suse.com/1272701

https://bugzilla.suse.com/1272702

https://bugzilla.suse.com/1272703

https://bugzilla.suse.com/1272704

https://bugzilla.suse.com/1272705

https://bugzilla.suse.com/1272707

https://bugzilla.suse.com/1272708

https://bugzilla.suse.com/1272709

https://bugzilla.suse.com/1272710

https://bugzilla.suse.com/1272711

https://bugzilla.suse.com/1272712

https://bugzilla.suse.com/1272713

https://bugzilla.suse.com/1272714

https://bugzilla.suse.com/1272715

https://bugzilla.suse.com/1272716

https://bugzilla.suse.com/1272717

https://bugzilla.suse.com/1272718

https://bugzilla.suse.com/1272719

https://bugzilla.suse.com/1272720

https://bugzilla.suse.com/1272721

https://bugzilla.suse.com/1272722

https://bugzilla.suse.com/1272723

https://bugzilla.suse.com/1272724

https://bugzilla.suse.com/1272725

https://bugzilla.suse.com/1272726

https://bugzilla.suse.com/1272727

https://bugzilla.suse.com/1272728

https://bugzilla.suse.com/1272729

https://bugzilla.suse.com/1272730

https://bugzilla.suse.com/1272731

https://bugzilla.suse.com/1272732

https://www.suse.com/security/cve/CVE-2026-12185

https://www.suse.com/security/cve/CVE-2026-12802

https://www.suse.com/security/cve/CVE-2026-12803

https://www.suse.com/security/cve/CVE-2026-12816

https://www.suse.com/security/cve/CVE-2026-12817

https://www.suse.com/security/cve/CVE-2026-12852

https://www.suse.com/security/cve/CVE-2026-12860

https://www.suse.com/security/cve/CVE-2026-13506

https://www.suse.com/security/cve/CVE-2026-13586

https://www.suse.com/security/cve/CVE-2026-14682

https://www.suse.com/security/cve/CVE-2026-15055

https://www.suse.com/security/cve/CVE-2026-58059

https://www.suse.com/security/cve/CVE-2026-58060

https://www.suse.com/security/cve/CVE-2026-58061

https://www.suse.com/security/cve/CVE-2026-58062

https://www.suse.com/security/cve/CVE-2026-58063

https://www.suse.com/security/cve/CVE-2026-59638

https://www.suse.com/security/cve/CVE-2026-59639

https://www.suse.com/security/cve/CVE-2026-59640

https://www.suse.com/security/cve/CVE-2026-59641

https://www.suse.com/security/cve/CVE-2026-59642

https://www.suse.com/security/cve/CVE-2026-59643

https://www.suse.com/security/cve/CVE-2026-59644

https://www.suse.com/security/cve/CVE-2026-59645

https://www.suse.com/security/cve/CVE-2026-59646

https://www.suse.com/security/cve/CVE-2026-59647

https://www.suse.com/security/cve/CVE-2026-59648

https://www.suse.com/security/cve/CVE-2026-59649

https://www.suse.com/security/cve/CVE-2026-59650

https://www.suse.com/security/cve/CVE-2026-59651

https://www.suse.com/security/cve/CVE-2026-59652

https://www.suse.com/security/cve/CVE-2026-8763

Plugin Details

Severity: Critical

ID: 333511

File Name: openSUSE-2026-21538-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/8/2026

Updated: 8/8/2026

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.4

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-8763

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:bouncycastle-javadoc, p-cpe:/a:novell:opensuse:bouncycastle-jmail, p-cpe:/a:novell:opensuse:bouncycastle-mail, p-cpe:/a:novell:opensuse:bouncycastle-pg, p-cpe:/a:novell:opensuse:bouncycastle-pkix, p-cpe:/a:novell:opensuse:bouncycastle-tls, p-cpe:/a:novell:opensuse:bouncycastle-util, p-cpe:/a:novell:opensuse:bouncycastle

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 8/3/2026

Reference Information

CVE: CVE-2026-12185, CVE-2026-12802, CVE-2026-12803, CVE-2026-12816, CVE-2026-12817, CVE-2026-12852, CVE-2026-12860, CVE-2026-13506, CVE-2026-13586, CVE-2026-14682, CVE-2026-15055, CVE-2026-58059, CVE-2026-58060, CVE-2026-58061, CVE-2026-58062, CVE-2026-58063, CVE-2026-59638, CVE-2026-59639, CVE-2026-59640, CVE-2026-59641, CVE-2026-59642, CVE-2026-59643, CVE-2026-59644, CVE-2026-59645, CVE-2026-59646, CVE-2026-59647, CVE-2026-59648, CVE-2026-59649, CVE-2026-59650, CVE-2026-59651, CVE-2026-59652, CVE-2026-8763