SUSE SLES15 Security Update : containerized-data-importer (SUSE-SU-2026:4209-1)

high Nessus Plugin ID 346799

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4209-1 advisory.

- CVE-2025-58058: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory (bsc#1248946).
- CVE-2026-25680: golang.org/x/net/html: denial of service when parsing arbitrary HTML (bsc#1267176).
- CVE-2026-25681: golang.org/x/net/html: incorrect handling of character references in DOCTYPE nodes (bsc#1267176).
- CVE-2026-27136: golang.org/x/net/html: duplicate attributes can cause XSS (bsc#1267176).
- CVE-2026-42502: golang.org/x/net/html: incorrect handling of HTML elements in foreign content (bsc#1267176).
- CVE-2026-42506: golang.org/x/net/html: incorrect handling of namespaced elements in foreign content (bsc#1267176).
- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265799).
- CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262952).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266639).
- CVE-2026-39827: golang.org/x/crypto/ssh: newChannel leak after Reject() (bsc#1266179).
- CVE-2026-39828: golang.org/x/crypto/ssh: bypass of certificate restrictions (bsc#1266179).
- CVE-2026-39829: golang.org/x/crypto/ssh: pathological RSA/DSA parameters may cause DoS (bsc#1266179).
- CVE-2026-39830: golang.org/x/crypto/ssh: client can cause server deadlock on unexpected responses (bsc#1266179).
- CVE-2026-39831: golang.org/x/crypto/ssh: bypass of FIDO/U2F security keys physical interaction (bsc#1266179).
- CVE-2026-39832: golang.org/x/crypto/ssh: remote agent constraint extensions dropped (bsc#1266179).
- CVE-2026-39833: golang.org/x/crypto/ssh: lifetime without confirm constraint (bsc#1266179).
- CVE-2026-39834: golang.org/x/crypto/ssh: infinite loop on large channel writes (bsc#1266179).
- CVE-2026-39835: golang.org/x/crypto/ssh: server panic during CheckHostKey/Authenticate (bsc#1266179).
- CVE-2026-42508: golang.org/x/crypto/ssh: failure to enforce @revoked status (bsc#1266179).
- CVE-2026-46595: golang.org/x/crypto/ssh: VerifiedPublicKeyCallback permissions skip enforcement (bsc#1266179).
- CVE-2026-46597: golang.org/x/crypto/ssh: byte arithmetic causes underflow and panic (bsc#1266179).
- CVE-2026-46598: golang.org/x/crypto/ssh: pathological inputs can lead to client panic (bsc#1266179).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276687).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272064).
- CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1278621).
- CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278621).
- CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278621).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected containerized-data-importer-manifests package.

See Also

https://bugzilla.suse.com/1248946

https://bugzilla.suse.com/1262952

https://bugzilla.suse.com/1265799

https://bugzilla.suse.com/1266179

https://bugzilla.suse.com/1266639

https://bugzilla.suse.com/1267176

https://bugzilla.suse.com/1272064

https://bugzilla.suse.com/1276687

https://bugzilla.suse.com/1278621

https://www.suse.com/security/cve/CVE-2025-58058

https://www.suse.com/security/cve/CVE-2026-25680

https://www.suse.com/security/cve/CVE-2026-25681

https://www.suse.com/security/cve/CVE-2026-27136

https://www.suse.com/security/cve/CVE-2026-33814

https://www.suse.com/security/cve/CVE-2026-34986

https://www.suse.com/security/cve/CVE-2026-39821

https://www.suse.com/security/cve/CVE-2026-39827

https://www.suse.com/security/cve/CVE-2026-39828

https://www.suse.com/security/cve/CVE-2026-39829

https://www.suse.com/security/cve/CVE-2026-39830

https://www.suse.com/security/cve/CVE-2026-39831

https://www.suse.com/security/cve/CVE-2026-39832

https://www.suse.com/security/cve/CVE-2026-39833

https://www.suse.com/security/cve/CVE-2026-39834

https://www.suse.com/security/cve/CVE-2026-39835

https://www.suse.com/security/cve/CVE-2026-41178

https://www.suse.com/security/cve/CVE-2026-42502

https://www.suse.com/security/cve/CVE-2026-42506

https://www.suse.com/security/cve/CVE-2026-42508

https://www.suse.com/security/cve/CVE-2026-46595

https://www.suse.com/security/cve/CVE-2026-46597

https://www.suse.com/security/cve/CVE-2026-46598

https://www.suse.com/security/cve/CVE-2026-56852

https://www.suse.com/security/cve/CVE-2026-56854

https://www.suse.com/security/cve/CVE-2026-56855

https://www.suse.com/security/cve/CVE-2026-78662

http://www.nessus.org/u?6fe187cf

Plugin Details

Severity: High

ID: 346799

File Name: suse_SU-2026-4209-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/17/2026

Updated: 9/17/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.74

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-33814

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:containerized-data-importer-manifests

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 8/28/2025

Reference Information

CVE: CVE-2025-58058, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-33814, CVE-2026-34986, CVE-2026-39821, CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-41178, CVE-2026-42502, CVE-2026-42506, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598, CVE-2026-56852, CVE-2026-56854, CVE-2026-56855, CVE-2026-78662

SuSE: SUSE-SU-2026:4209-1