openSUSE 16 Security Update : go1.26 (openSUSE-SU-2026:21593-1)

high Nessus Plugin ID 338686

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21593-1 advisory.

Update to go1.26.6 (released 2026-08-13, bsc#1255111).

Security issues fixed:

- CVE-2026-33818: encoding/asn1: unenforced recursion limit can lead to stack exhaustion when parsing deeply-nested, recursive structures (bsc#1275034).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609).
- CVE-2026-56853: net/http: missing timeout when doing unencrypted HTTP/2 check can lead to a denial of service (bsc#1275028).
- CVE-2026-56858: html/template: improper Javascript regexp context tracking allows for XSS attacks (bsc#1275033).
- CVE-2026-56859: encoding/xml: missing recursion depth guard during decode operation can lead to stack exhaustion and a denial of service (bsc#1275026).
- CVE-2026-56860: net/url: quadratic time complexity in `resolvePath` when processing certain input can lead to high memory allocation overhead and a denial of service (bsc#1275029).
- CVE-2026-56862: crypto/tls: no limit set for handshake messages sent post-handshake allows for denial of service (bsc#1275032).
- CVE-2026-56864: x/mod/sumdb: unauthenticated hashes accepted in `Lookup` allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content (bsc#1275025).
- CVE-2026-56865: x/mod/sumdb/tlog: improper transparency log tile verification allows for bypass on crafted input and can lead to malicious module content to be accepted (bsc#1275024).

Changes for go1.26.6:

- go#79876 cmd/compile: prove misscompilation in slicemask folding leaves garbage in the upper bits
- go#80099 cmd/compile: internal compiler error invalid heap allocated var without Heapaddr
- go#80131 cmd/link: peCreateExportFile generates invalid .def file when output name has trailing dot (c-shared on Windows)
- go#80365 os: Root's MkdirAll can't create paths ending in forward slashes
- go#80367 os: TestRootMultiReadFile fails on netbsd/arm64 after CL 797880
- go#80369 os: TestRootConsistencyRemoveAll fails on Plan 9 after CL 797880
- go#80394 runtime: arm64 found pointer to free object with safe code
- go#80441 runtime: uninitialized register due to wrong ABI in mach_vm_region_trampoline leads to libc following garbage stack data as a pointer
- go#80478 cmd/compile: riscv64 miscompiles struct copy, corrupting a []byte slice field
- go#80499 runtime: js/wasm: found bad pointer in Go heap -- link-layout-constant value recorded as a pointer in the write-barrier buffer
- go#80579 cmd/compile: regalloc uses unreliable type data (like v.Type.IsSigned()) to choose the restore of spills
- go#80606 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement
- go#80609 net, x/net/dns/dnsmessage: panic when parsing invalid SVCB record
- go#80615 cmd/compile: mips64le misscompile OffPtr by a const which doesn't fit 32bits resulting in panic
- go#80617 cmd/compile: mips/mips64, multiply/divide results spilled from HI/LO corrupted w/ big stack frames
- go#80619 cmd/compile: prove bug causes invalid indirect call
- go#80715 runtime: fpTracebackPartialExpand SIGSEGV under high panic load

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected go1.26 and / or go1.26-race packages.

See Also

https://bugzilla.suse.com/1255111

https://bugzilla.suse.com/1266609

https://bugzilla.suse.com/1275024

https://bugzilla.suse.com/1275025

https://bugzilla.suse.com/1275026

https://bugzilla.suse.com/1275028

https://bugzilla.suse.com/1275029

https://bugzilla.suse.com/1275032

https://bugzilla.suse.com/1275033

https://bugzilla.suse.com/1275034

https://www.suse.com/security/cve/CVE-2026-33818

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-56853

https://www.suse.com/security/cve/CVE-2026-56858

https://www.suse.com/security/cve/CVE-2026-56859

https://www.suse.com/security/cve/CVE-2026-56860

https://www.suse.com/security/cve/CVE-2026-56862

https://www.suse.com/security/cve/CVE-2026-56864

https://www.suse.com/security/cve/CVE-2026-56865

Plugin Details

Severity: High

ID: 338686

File Name: openSUSE-2026-21593-1.nasl

Version: 1.2

Type: Local

Agent: unix

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.17

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-39821

CVSS v3

Risk Factor: High

Base Score: 8.4

Temporal Score: 7.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-56865

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:go1.26-race, p-cpe:/a:novell:opensuse:go1.26

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/19/2026

Vulnerability Publication Date: 5/12/2026

Reference Information

CVE: CVE-2026-33818, CVE-2026-39821, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865

IAVB: 2026-B-0234