SUSE SLES11: kernel-default / kernel-default-base / kernel-ec2 / kernel-ec2-base / etc (SUSE-SU-2026:4190-1)

high Nessus Plugin ID 346220

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES11 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4190-1 advisory.

The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues:

The following security issues were fixed:

- CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369).
- CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).
- CVE-2026-53059: dm mirror log: clear log bits up to BITS_PER_LONG boundary (bsc#1269655).
- CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306).
- CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385).
- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888).
- CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161).
- CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869).
- CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1267369

https://bugzilla.suse.com/1269159

https://bugzilla.suse.com/1269306

https://bugzilla.suse.com/1269655

https://bugzilla.suse.com/1272385

https://bugzilla.suse.com/1273869

https://bugzilla.suse.com/1274888

https://bugzilla.suse.com/1275161

https://bugzilla.suse.com/1278294

https://www.suse.com/security/cve/CVE-2026-46116

https://www.suse.com/security/cve/CVE-2026-52955

https://www.suse.com/security/cve/CVE-2026-53059

https://www.suse.com/security/cve/CVE-2026-53163

https://www.suse.com/security/cve/CVE-2026-63887

https://www.suse.com/security/cve/CVE-2026-68121

https://www.suse.com/security/cve/CVE-2026-68202

https://www.suse.com/security/cve/CVE-2026-72389

https://www.suse.com/security/cve/CVE-2026-80580

http://www.nessus.org/u?eac15b20

Plugin Details

Severity: High

ID: 346220

File Name: suse_SU-2026-4190-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/16/2026

Updated: 9/16/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53059

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:11, p-cpe:/a:novell:suse_linux:kernel-default-base, p-cpe:/a:novell:suse_linux:kernel-default, p-cpe:/a:novell:suse_linux:kernel-ec2-base, p-cpe:/a:novell:suse_linux:kernel-ec2, p-cpe:/a:novell:suse_linux:kernel-source, p-cpe:/a:novell:suse_linux:kernel-trace-base, p-cpe:/a:novell:suse_linux:kernel-trace, p-cpe:/a:novell:suse_linux:kernel-xen-base, p-cpe:/a:novell:suse_linux:kernel-xen

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2026

Vulnerability Publication Date: 5/26/2026

Reference Information

CVE: CVE-2026-46116, CVE-2026-52955, CVE-2026-53059, CVE-2026-53163, CVE-2026-63887, CVE-2026-68121, CVE-2026-68202, CVE-2026-72389, CVE-2026-80580

SuSE: SUSE-SU-2026:4190-1