openSUSE 16: libBasicUsageEnvironment2 / libUsageEnvironment3 / libgroupsock33 / etc (openSUSE-SU-2026:21863-1)

high Nessus Plugin ID 347914

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21863-1 advisory.

Changes in live555:

- Update to version 2026.08.25:
* Fixed a bug in VorbisAudioRTPSource that could have caused a malicious SDP description to crash a RTP client.

- update to 2026.08.14:
* Fixed a bug that could cause a problem with subclassed variants of H.264 or H.265 RTP sinks.
* Fixed old code in GroupsockHelper.cpp that was using hardcoded numeric error numbers
* Fixed a memory leak that could occur when parsing a SDP description that contains two or more
* When adding protection against the use of 'stolen' RTSP session ids we forgot to do so for every SETUP command. This release fixes that.
* Fixed a typo in RTSPCommon.cpp: smtpe -> smpte.
* Updated the RTSP server implementation to return a Unsupported Transport error if a SETUP request does not include a Transport: header.
* Added -std=c++20 to the CPLUSPLUS_FLAGS line in each config.* file, so that std::atomic_flag::test will compile with compilers that support
* Made the parsing of MP3 audio files more robust to protect against malformed MP3 data.
* Minor change to testProgs/testRTSPClient.cpp to make compiling on Mac OS X happier.

- Update to version 2026.06.01:
* Updated the RTSPServer implementation of the SETUP command to make it more robust if subclassed code reimplements lookupServerMediaSession() as an asynchronous operation.

- update to 2026.05.30:
* Updated the RTSPServer implementation some more to make it more robust if subclassed code reimplements lookpServerMediaSession() as an asynchronous operation.
* Added an (integer) index to identify each server's 'client connection', and changed the fClientConnections table to be indexed by this id.
* In the RTSPServer implementation, removed the fOurClientConnection member variable.
This had been left over from when the RTSP SETUP command had been implemented as a single, synchronous function.
Now that SETUP is implemented using multiple functions, possibly asynchronously (depending upon how lookpServerMediaSession() is implemented), this member variable was potentially dangerous if more than one SETUP is performed concurrently on the same client connection, or on separate client connections.

- update to 2026.05.28:
* fix use-after-free memory corruption introduced in fix for CVE-2026-41470

- Update to version 2026.04.22 (CVE-2026-41470, boo#1265856):
* Added extra checking to the handling of the RTSP server's PLAY, PAUSE, TEARDOWN, and SET_PARAMETER commands, to ensure that, if the session is authenticated, then a proper authentication check is done before these commands are handled.
This protects against the use of a 'stolen' RTSP session id to send these commands. (Note, however, that if the session is not authenticated (i.e., no username,password is needed), then no such protection is possible.)
- Changes from version 2026-04-01:
* Updated the way that the RTSP server generates successive RTSP 'session ids' to make it less likely that an attacker could guess a session id.
* Updated the RTSP server implementation to make it possible for a client to request both interleaved (i.e., RTP/RTCP-over-TCP) and non-interleaved (i.e., RTP/RTCP-over-UDP) delivery within the same session.

- Update to version 2026.03.23 (boo#1279932):
* CVE-2026-38998: Fixed a bug in the RTSP server code that caused it to improperly handle non-interleaved SETUPs that were sent for a session where interleaving (i.e., RTP/RTCP-over-TCP) had already been SETUP. (This could cause a 'use-after-free' error.
* For changes between 2024.08.01 to today, please refer to https://download.live555.com/changelog.txt

- update to 2024-08-01:
* Updated ServerMediaSession::generateSDPDescription() to treat time_t as (long long).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1265856

https://bugzilla.suse.com/1279932

https://www.suse.com/security/cve/CVE-2026-38998

https://www.suse.com/security/cve/CVE-2026-41470

Plugin Details

Severity: High

ID: 347914

File Name: openSUSE-2026-21863-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.65

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-38998

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.2

Threat Score: 4.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-41470

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:libbasicusageenvironment2, p-cpe:/a:novell:opensuse:libgroupsock33, p-cpe:/a:novell:opensuse:liblivemedia120, p-cpe:/a:novell:opensuse:libusageenvironment3, p-cpe:/a:novell:opensuse:live555-devel, p-cpe:/a:novell:opensuse:live555

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 5/19/2026

Reference Information

CVE: CVE-2026-38998, CVE-2026-41470