openSUSE 16: containerized-data-importer1.65-api / etc (openSUSE-SU-2026:21824-1)

high Nessus Plugin ID 344999

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21824-1 advisory.

- CVE-2025-22869: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322).
- CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238699).
- CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241838).
- CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (bsc#1251495).
- CVE-2025-47913: client process termination when receiving an unexpected message type in response to a key listing or (bsc#1253506).
- CVE-2025-47914: non validated message size can cause a panic due to an out of bounds read (bsc#1253967).
- CVE-2025-58058: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory (bsc#1248946).
- CVE-2025-58181: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253784).
- CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input (bsc#1251689).
- CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html:
multiple issues when parsing HTML files (bsc#1267176).
- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260295).
- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265799).
- CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262952).
- CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262269).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266639).
- CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597, CVE-2026-46598: multiple issues in golang.org/x/crypto/ssh (bsc#1266179).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276687).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272064).
- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278621).
- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279315).
- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279234).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1238699

https://bugzilla.suse.com/1239322

https://bugzilla.suse.com/1241838

https://bugzilla.suse.com/1248946

https://bugzilla.suse.com/1251495

https://bugzilla.suse.com/1251689

https://bugzilla.suse.com/1253506

https://bugzilla.suse.com/1253784

https://bugzilla.suse.com/1253967

https://bugzilla.suse.com/1260295

https://bugzilla.suse.com/1262269

https://bugzilla.suse.com/1262952

https://bugzilla.suse.com/1265799

https://bugzilla.suse.com/1266179

https://bugzilla.suse.com/1266639

https://bugzilla.suse.com/1267176

https://bugzilla.suse.com/1272064

https://bugzilla.suse.com/1276687

https://bugzilla.suse.com/1278621

https://bugzilla.suse.com/1279234

https://bugzilla.suse.com/1279315

https://www.suse.com/security/cve/CVE-2025-22869

https://www.suse.com/security/cve/CVE-2025-22870

https://www.suse.com/security/cve/CVE-2025-22872

https://www.suse.com/security/cve/CVE-2025-47911

https://www.suse.com/security/cve/CVE-2025-47913

https://www.suse.com/security/cve/CVE-2025-47914

https://www.suse.com/security/cve/CVE-2025-58058

https://www.suse.com/security/cve/CVE-2025-58181

https://www.suse.com/security/cve/CVE-2025-58190

https://www.suse.com/security/cve/CVE-2026-25680

https://www.suse.com/security/cve/CVE-2026-25681

https://www.suse.com/security/cve/CVE-2026-27136

https://www.suse.com/security/cve/CVE-2026-33186

https://www.suse.com/security/cve/CVE-2026-33814

https://www.suse.com/security/cve/CVE-2026-34986

https://www.suse.com/security/cve/CVE-2026-35469

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-39827

https://www.suse.com/security/cve/CVE-2026-39828

https://www.suse.com/security/cve/CVE-2026-39829

https://www.suse.com/security/cve/CVE-2026-39830

https://www.suse.com/security/cve/CVE-2026-39831

https://www.suse.com/security/cve/CVE-2026-39832

https://www.suse.com/security/cve/CVE-2026-39833

https://www.suse.com/security/cve/CVE-2026-39834

https://www.suse.com/security/cve/CVE-2026-39835

https://www.suse.com/security/cve/CVE-2026-41178

https://www.suse.com/security/cve/CVE-2026-42502

https://www.suse.com/security/cve/CVE-2026-42506

https://www.suse.com/security/cve/CVE-2026-42508

https://www.suse.com/security/cve/CVE-2026-46595

https://www.suse.com/security/cve/CVE-2026-46597

https://www.suse.com/security/cve/CVE-2026-46598

https://www.suse.com/security/cve/CVE-2026-56852

https://www.suse.com/security/cve/CVE-2026-56854

https://www.suse.com/security/cve/CVE-2026-56855

https://www.suse.com/security/cve/CVE-2026-78662

https://www.suse.com/security/cve/CVE-2026-84303

https://www.suse.com/security/cve/CVE-2026-84304

Plugin Details

Severity: High

ID: 344999

File Name: openSUSE-2026-21824-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/12/2026

Updated: 9/12/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-33814

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-84304

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-api, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-cloner, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-controller, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-importer, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-manifests, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-operator, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-uploadproxy, p-cpe:/a:novell:opensuse:containerized-data-importer1.65-uploadserver, p-cpe:/a:novell:opensuse:obs-service-cdi1.65_containers_meta

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/9/2026

Vulnerability Publication Date: 2/26/2025

Reference Information

CVE: CVE-2025-22869, CVE-2025-22870, CVE-2025-22872, CVE-2025-47911, CVE-2025-47913, CVE-2025-47914, CVE-2025-58058, CVE-2025-58181, CVE-2025-58190, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33186, CVE-2026-33814, CVE-2026-34986, CVE-2026-35469, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-41178, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598, CVE-2026-56852, CVE-2026-56854, CVE-2026-56855, CVE-2026-78662, CVE-2026-84303, CVE-2026-84304