openSUSE 16: librpmbuild10 / python313-rpm / rpm / rpm-build / rpm-devel / etc (openSUSE-SU-2026:21856-1)

high Nessus Plugin ID 347917

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21856-1 advisory.

Changes in rpm:

- split imaevmsign plugin into a multibuild flavor

Changes in rpm:

- Add Requires: (rpm-plugin-selinux if selinux-policy)
- harden ndb code [bsc#1269584] [CVE-2026-44605]
- split all plugins into subpackages
* this allows for an easy way to get rid of a plugin, it's also what other distributions do
- make the imaevmsign plugin build in a multibuild flavor
- rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150]
- backport fix for add_sysuser macro [bsc#1269571]
- backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604]
- switch from rpmpgp_legacy to libpgpr
* multiple bug fixes, support for v5 and v6 signatures
- turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new rpm-imaevmsign subpackage. [jsc#PED-7246]
- Fix unexpected EOF when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215)
- Remove /var/lib/rpm migration scripting, retain an error if old location is found
- Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139)
- flush scriptlet notification messages in --runposttrans
* needed to fix leaking tmp files [bsc#1218459]
* added rpm_flushes_runposttrans provides for libzypp

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1218459

https://bugzilla.suse.com/1253139

https://bugzilla.suse.com/1259215

https://bugzilla.suse.com/1268747

https://bugzilla.suse.com/1269150

https://bugzilla.suse.com/1269571

https://bugzilla.suse.com/1269584

https://www.suse.com/security/cve/CVE-2026-44604

https://www.suse.com/security/cve/CVE-2026-44605

Plugin Details

Severity: High

ID: 347917

File Name: openSUSE-2026-21856-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.16

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-44605

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.1

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-44604

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:librpmbuild10, p-cpe:/a:novell:opensuse:python313-rpm, p-cpe:/a:novell:opensuse:rpm-build, p-cpe:/a:novell:opensuse:rpm-devel, p-cpe:/a:novell:opensuse:rpm-plugin-fapolicyd, p-cpe:/a:novell:opensuse:rpm-plugin-ima, p-cpe:/a:novell:opensuse:rpm-plugin-imaevmsign, p-cpe:/a:novell:opensuse:rpm-plugin-prioreset, p-cpe:/a:novell:opensuse:rpm-plugin-selinux, p-cpe:/a:novell:opensuse:rpm-plugin-syslog, p-cpe:/a:novell:opensuse:rpm-plugin-unshare, p-cpe:/a:novell:opensuse:rpm

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 5/28/2026

Reference Information

CVE: CVE-2026-44604, CVE-2026-44605