Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21592-1 advisory.
Update to go1.25.13 (released 2026-08-13, bsc#1244485).
Security issues fixed:
- CVE-2026-33818: encoding/asn1: unenforced recursion limit can lead to stack exhaustion when parsing deeply-nested, recursive structures (bsc#1275034).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609).
- CVE-2026-56853: net/http: missing timeout when doing unencrypted HTTP/2 check can lead to a denial of service (bsc#1275028).
- CVE-2026-56858: html/template: improper Javascript regexp context tracking allows for XSS attacks (bsc#1275033).
- CVE-2026-56859: encoding/xml: missing recursion depth guard during decode operation can lead to stack exhaustion and a denial of service (bsc#1275026).
- CVE-2026-56860: net/url: quadratic time complexity in `resolvePath` when processing certain input can lead to high memory allocation overhead and a denial of service (bsc#1275029).
- CVE-2026-56862: crypto/tls: no limit set for handshake messages sent post-handshake allows for denial of service (bsc#1275032).
- CVE-2026-56864: x/mod/sumdb: unauthenticated hashes accepted in `Lookup` allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content (bsc#1275025).
- CVE-2026-56865: x/mod/sumdb/tlog: improper transparency log tile verification allows for bypass on crafted input and can lead to malicious module content to be accepted (bsc#1275024).
Changes for go1.25.13:
- go#79875 cmd/compile: prove misscompilation in slicemask folding leaves garbage in upper bits
- go#80098 cmd/compile: internal compiler error invalid heap allocated var without Heapaddr
- go#80364 os: Root's MkdirAll can't create paths ending in forward slashes
- go#80366 os: TestRootMultiReadFile fails on netbsd/arm64 after CL 797880
- go#80368 os: TestRootConsistencyRemoveAll fails on Plan 9 after CL 797880
- go#80393 runtime: arm64 found pointer to free object with safe code
- go#80440 runtime: uninitialized register due to wrong ABI in mach_vm_region_trampoline leads to libc following garbage stack data as a pointer
- go#80477 cmd/compile: riscv64 miscompiles struct copy, corrupting a []byte slice field
- go#80500 runtime: js/wasm: found bad pointer in Go heap -- link-layout-constant value recorded as a pointer in the write-barrier buffer
- go#80578 cmd/compile: regalloc uses unreliable type data (like v.Type.IsSigned()) to choose the restore of spills
- go#80605 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement
- go#80614 cmd/compile: mips64le misscompile OffPtr by a const which doesn't fit 32bits resulting in panic
- go#80616 cmd/compile: mips/mips64, multiply/divide results spilled from HI/LO corrupted w/ big stack frames
- go#80618 cmd/compile: prove bug causes invalid indirect call
- go#80737 runtime: fpTracebackPartialExpand SIGSEGV under high panic load
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected go1.25 and / or go1.25-race packages.
Plugin Details
File Name: openSUSE-2026-21592-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:go1.25-race, p-cpe:/a:novell:opensuse:go1.25
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 8/19/2026
Vulnerability Publication Date: 5/12/2026