SUSE SLES15: Multiple Vulnerabilities (SUSE-RU-2026:3712-1)

high Nessus Plugin ID 350285

Synopsis

The remote SUSE host is missing a security update.

Description

The remote SUSE Linux SLES15 host has packages installed that are affected by a vulnerability as referenced in the SUSE- RU-2026:3712-1 advisory.

Release Notes Highlights:

- Update to SUSE Multi-Linux Manager 5.1.5
* Added known issue for missing BasicConstraints Critical flag
* Added a note about disk-check parameters semantics change
* Added a note about enabling FIPS mode after installing SUSE Multi-Linux Manager.
* Monitoring: Upgrade Grafana to 12.4.5
* Enabled the support on FIPS enabled host
* Security Fixes:
CVE-2026-33382, CVE-2025-12141, CVE-2026-41607, CVE-2026-39821 CVE-2026-39882, CVE-2026-33244, CVE-2026-13149, CVE-2026-33814 CVE-2026-39821
* Bugs mentioned:
bsc#1243168, bsc#1244141, bsc#1245944, bsc#1247004, bsc#1253505 bsc#1254201, bsc#1257102, bsc#1257295, bsc#1258500, bsc#1258567 bsc#1259225, bsc#1259254, bsc#1259594, bsc#1259720, bsc#1260342 bsc#1260396, bsc#1261195, bsc#1262012, bsc#1262168, bsc#1262664 bsc#1263822, bsc#1263823, bsc#1265334, bsc#1266481, bsc#1267619 bsc#1267871, bsc#1268006, bsc#1268151, bsc#1268229, bsc#1268309 bsc#1268325, bsc#1268567, bsc#1268570, bsc#1268673, bsc#1269192 bsc#1269267, bsc#1269408, bsc#1265827, bsc#1270040, bsc#1271331 bsc#1262187, bsc#1263272, bsc#1266615, bsc#1267416, bsc#1269917 bsc#1274571

Container images and uyuni-tools changes:


server-attestation-image:

- Version 5.1.16
* Add org.uyuni.version LABEL to the image

server-hub-xmlrpc-api-image:

- Version 5.1.15
* Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.5

server-image:

- Version 5.1.16
* Configure Java strong SecureRandom to use the NSS FIPS provider on FIPS-enabled hosts so DB connections (SCRAM-SHA-256) work under FIPS

server-migration-14-16-image:

- Version 5.1.15
* Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.5

server-postgresql-image:

- Version 5.1.15
* Automatically set the log timezone for TZ env (bsc#1267871)
* Grant access to uyuni-server-attestation container (bsc#1269267)
* Enable hostname filtering in pg_hba.conf

server-saline-image:

- Version 5.1.15
* Add org.uyuni.version LABEL to the image

uyuni-tools:

Security issues fixed:

- Version 5.1.31-0:
* CVE-2026-39821: Drop the direct dependency on golang.org/x/net (bsc#1266481)

Other bugs fixed and changes:

- Version 5.1.32-0:
* Use common container name to prevent pg auth errors (bsc#1275217)
- Version 5.1.30-0
* Strip text from x509 certs before creating the secret (bsc#1259720)
* Fix the traefik enpoints names (bsc#1267619)
* Set the timezone on the database container too (bsc#1267871)
* Disable SSL on internal DB connection
* Internal SANs for db and reportdb are no longer required
* Generate the same certificate for server and reportdb
* Make uyuni-server service dependent on uyuni-db (bsc#1263823)


The following packages are underlying build dependencies and system components used by the containers:


salt:

- Use AsyncHTTPClient in salt.utils.http (bsc#1268325)
- Decode binary pillars for salt-ssh to avoid exceptions (bsc#1263822)

spacewalk-admin:

- Version 5.1.9-0
* Use db_ssl_enabled value consistently

spacewalk-backend:

- Version 5.1.18-0
* Use db_ssl_enabled value consistently

spacewalk-certs-tools:

- Version 5.1.12-0
* Set Basic Constraints extension as 'critical' according to RFC 5280 for self signed CA certificates (bsc#1274571)

spacewalk-java:

- Version 5.1.30-0
* Add Ubuntu 26.04 LTS
- Version 5.1.29-0
* Fix mainframe foreign systems showing wrong OS (bsc#1260342)
* Make setting of column filters in ListTag idempotent (bsc#1269192)
* Optimized channel model generation logic to improve page load performance during peripheral channel selection (bsc#1259225)
* Do not attempt to delete a certificate that does not exist (bsc#1268151)
* Remote Report DB connection should always use SSL (bsc#1268229)
* Make sure the image upload directory exists
* Add primary FQDN to pillar (bsc#1247004)
* Use db_ssl_enabled value consistently
* Fix user role selection when org admin role is enabled (bsc#1259254)
* Fix inventory refresh triggering from unrelated inotify events (bsc#1268309)
* Prevent inventory refresh before ansible package is installed (bsc#1244141)
* Fix CLM not propagating new AppStream module versions to cloned channels (bsc#1254201)
* Fix hubsync package download checksum lookup (bsc#1270040)
* Add delay to package clean to not interfere with repo-sync (bsc#1258500)

spacewalk-search:

- Version 5.1.8-0
* Use db_ssl_enabled value consistently
* Fix Fine Grained search for hyphenated hostnames (bsc#1257102)

spacewalk-utils:

- Version 5.1.11-0
* Add Ubuntu 26.04 LTS
- Version 5.1.10-0
* Taskotop now handles timezone (bsc#1267871)

spacewalk-web:

- Version 5.1.22-0
* Improve product selection checkboxes in the setup UI
* Show partial selection state for product trees more accurately
* Use db_ssl_enabled value consistently

susemanager:

- Version 5.1.19-0
* Add Ubuntu 26.04 LTS
- Version 5.1.18-0
* Add bootstrap repository definition for SLE and Leap 16.1

susemanager-build-keys:

- Add Liberty v3 backup / reserve key Added: RPM-GPG-KEY-SUSE_Liberty_Linux_v3 (BB9FD340DA090344)

susemanager-docs_en:

- Documented SLES 15 SP7 to SLES 16.0 major upgrade via product migration in Client Configuration Guide
- Added a common workflow to setup crypto policies in the server container (bsc#1253505)
- Added mass migration using UI to Client Configuration Guide (bsc#1259594)
- Enhanced proxy migration procedure (bsc#1269408)
- Added procedure for allowing uploading of large files to Specialized Guides (bsc#1268673)
- Enhanced Prometheus formula with command to generate password hash in Specialized Guides (bsc#1268570)
- Document Ansible Playbook variable editing (bsc#1260396)
- Convert broken `[role]``text`` double-backtick literals in `en/modules` to standard single-backtick literals for Weblate AI translation compatibility
- Document use_bundle_build custom info key for KIWI builds (bsc#1243168)
- Updated SSO / SAML integration with Keycloak in Administration Guide (bsc#1261195)
- Move Prometheus as the first section in Monitoring Formulas
- Add information about optional TLS Grafana configuration (bsc#1268567)
- Reorganized the documentation around reporting database
- Adjusted the note about *.rpmnew and *.rpmsave files usage (bsc#1245944)
- Removed obsolete file from Salt guide (bsc#1268006)
- Added OS versions currently suported with OVAL in the product (bsc#1262664)
- Added instructions to migrate from wicked to NetworkManager to Administration Guide (bsc#1257295)
- Added migration steps for SL Micro 6.1 as base OS to Retail Branch Server 4.3 migration guide (bsc#1262168)
- Clarified Jinja templating in Client Configuration Guide (bsc#1262012)
- Added information about recreating missing Cobbler entries by resaving the Saltboot Group formula to Retail Guide (bsc#1265334)
- Updated Hub online synchronization documentation in Specialized Guides
- Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD

susemanager-schema:

- Version 5.1.20-0
* Use db_ssl_enabled value consistently
* Fix user role selection when org admin role is enabled (bsc#1259254)
* Make inventory path not nullable in rhnActionInventory (bsc1268309)
* Make clone channel appstreams idempotent (bsc#1254201)

susemanager-sls:

- Version 5.1.26-0
* Install ansible and ansible-core depending on their availability
* Handle release package for SLE16 correctly depending on the transactional flag
* Fix cleanup timeout when deleting minions (bsc#1258567)
* Use primary FQDN to contact Build Host (bsc#1247004)
* Use db_ssl_enabled value consistently
* Prevent inventory refresh before ansible package is installed (bsc#1244141)

susemanager-sync-data:

- Version 5.1.11-0
* Add Ubuntu 26.04 LTS

How to apply this update:

1. Log in as root user to the SUSE Multi-Linux Manager Server.
2. Upgrade mgradm and mgrctl.
3. If you are in a disconnected environment, upgrade the image packages.
4. Reboot the system.
5. Run `mgradm upgrade podman` which will use the default image tags.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1243168

https://bugzilla.suse.com/1244141

https://bugzilla.suse.com/1245944

https://bugzilla.suse.com/1247004

https://bugzilla.suse.com/1253505

https://bugzilla.suse.com/1254201

https://bugzilla.suse.com/1257102

https://bugzilla.suse.com/1257295

https://bugzilla.suse.com/1258500

https://bugzilla.suse.com/1258567

https://bugzilla.suse.com/1259225

https://bugzilla.suse.com/1259254

https://bugzilla.suse.com/1259594

https://bugzilla.suse.com/1259720

https://bugzilla.suse.com/1260342

https://bugzilla.suse.com/1260396

https://bugzilla.suse.com/1261195

https://bugzilla.suse.com/1262012

https://bugzilla.suse.com/1262168

https://bugzilla.suse.com/1262664

https://bugzilla.suse.com/1263822

https://bugzilla.suse.com/1263823

https://bugzilla.suse.com/1265334

https://bugzilla.suse.com/1266481

https://bugzilla.suse.com/1267619

https://bugzilla.suse.com/1267871

https://bugzilla.suse.com/1268006

https://bugzilla.suse.com/1268151

https://bugzilla.suse.com/1268229

https://bugzilla.suse.com/1268309

https://bugzilla.suse.com/1268325

https://bugzilla.suse.com/1268567

https://bugzilla.suse.com/1268570

https://bugzilla.suse.com/1268673

https://bugzilla.suse.com/1269192

https://bugzilla.suse.com/1269267

https://bugzilla.suse.com/1269408

https://bugzilla.suse.com/1270040

https://bugzilla.suse.com/1274571

https://bugzilla.suse.com/1274984

https://bugzilla.suse.com/1275217

https://lists.suse.com/pipermail/sle-updates/2026-August/049455.html

https://www.suse.com/security/cve/CVE-2026-39821

Plugin Details

Severity: High

ID: 350285

File Name: suse_RU-2026-3712-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/25/2026

Updated: 9/25/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.83

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-39821

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:mgradm-bash-completion, p-cpe:/a:novell:suse_linux:mgradm-lang, p-cpe:/a:novell:suse_linux:mgradm-zsh-completion, p-cpe:/a:novell:suse_linux:mgradm, p-cpe:/a:novell:suse_linux:mgrctl-bash-completion, p-cpe:/a:novell:suse_linux:mgrctl-lang, p-cpe:/a:novell:suse_linux:mgrctl-zsh-completion, p-cpe:/a:novell:suse_linux:mgrctl, p-cpe:/a:novell:suse_linux:mgrpxy-bash-completion, p-cpe:/a:novell:suse_linux:mgrpxy-lang, p-cpe:/a:novell:suse_linux:mgrpxy-zsh-completion, p-cpe:/a:novell:suse_linux:mgrpxy, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-proxy-squid-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-aarch64-server-saline-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-ppc64le-server-saline-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-proxy-httpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-proxy-squid-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-proxy-ssh-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-s390x-server-saline-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-proxy-squid-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-attestation-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-postgresql-image, p-cpe:/a:novell:suse_linux:suse-multi-linux-manager-5.1-x86_64-server-saline-image

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/24/2026

Vulnerability Publication Date: 5/12/2026

Reference Information

CVE: CVE-2026-39821

SuSE: SUSE-RU-2026:3712-1