SUSE SLED15 / SLES15 Security Update : netty, netty-tcnative (SUSE-SU-2026:4391-1)

critical Nessus Plugin ID 351404

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4391-1 advisory.

- CVE-2026-59902: Netty: Memory Exhaustion in SctpMessageCompletionHandler (bsc#1275501).
- CVE-2026-59903: Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite (bsc#1275500).
- CVE-2026-62243: TLS hostname verification bypass in Netty OpenSSL client path (bsc#1276455).
- CVE-2026-62380: null byte and CRLF injection in Socks4ClientEncoder and Socks5ClientEncoder (bsc#1276456).
- CVE-2026-75595: fragmented TLS `ClientHello` causes fallback to default `SslContext` and allows for SNI routing and mTLS requirement bypass (bsc#1276420).
- CVE-2026-75596: fragmented `ClientHello`records can trigger quadratic pre-handshake reassembly in default SNI parsing (bsc#1276421).
- CVE-2026-76816: missing input validation in `MqttEncoder` allows for null-byte injection, topic hijacking, and ACL bypassing (bsc#1277243).
- CVE-2026-89044: HTTP request smuggling in Netty via improper validation of final Transfer-Encoding coding (bsc#1280048).
- CVE-2026-93488: Denial of Service via unbounded concurrent SPDY streams (bsc#1282084).
- CVE-2026-93491: Denial of Service via unbounded HttpServerCodec HTTP/1.1 pipeline queue (bsc#1282085).
- CVE-2026-93492: HTTP/2 HpackEncoder DoS with large table size (bsc#1282132).
- CVE-2026-93493: missing `nextUpdate` field in OCSP responses leads to silent validation bypass (bsc#1281431).
- CVE-2026-93494: ByteBuf Leak in StompSubframeDecoder When a Frame Body Is Never Terminated (bsc#1282506).
- CVE-2026-93558: Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service (bsc#1282140).
- CVE-2026-93560: STOMP codec content-length long-to-int truncation causes infinite decode loop DoS (bsc#1282141).
- CVE-2026-93562: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling (bsc#1282362).
- CVE-2026-93563: unbounded multi-line response accumulation in `SmtpResponseDecoder` leads to memory exhaustion and a DoS (bsc#1281432).
- CVE-2026-93564: HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (bsc#1282363).
- CVE-2026-93565: RtspDecoder Method-Token Smuggling via Trailing Control Byte (bsc#1282364).
- CVE-2026-93566: HTTP Request Smuggling due to control characters in the chunk-size line (bsc#1282366).
- CVE-2026-93567: HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host- controlled :authority (bsc#1282367).
- CVE-2026-93568: HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests (bsc#1282370).
- CVE-2026-93569: HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority (bsc#1282372).
- CVE-2026-93572: multiplication of patched preallocation limits in `RedisArrayAggregator` nested RESP headers can lead to denial of service (bsc#1281433).
- CVE-2026-93573: Incomplete validation of malformed Transfer-Encoding allows HTTP request smuggling (bsc#1282373).
- CVE-2026-93574: HTTP request smuggling via post-digit whitespace in chunk-size parsing (bsc#1282374).
- CVE-2026-93575: missing validations in the `MqttDecoder` can lead to excessive resource consumption and a DoS (bsc#1281434).
- CVE-2026-93576: netty-codec-smtp -- SMTP command-name field is not CRLF-validated (bsc#1282507).
- CVE-2026-93578: missing Extended Key Usage (EKU) check in OCSP client allows certificate revocation bypass (bsc#1281435).
- CVE-2026-93579: HTTP/2 header field values are not validated by default (bsc#1282378).

Changes for netty:

- Upgrade to upstream version 4.1.138

Changes for netty-tcnative:

- Upgrade to version 2.0.84 Final

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected netty, netty-javadoc and / or netty-tcnative packages.

See Also

https://bugzilla.suse.com/1275500

https://bugzilla.suse.com/1275501

https://bugzilla.suse.com/1276420

https://bugzilla.suse.com/1276421

https://bugzilla.suse.com/1276455

https://bugzilla.suse.com/1276456

https://bugzilla.suse.com/1277243

https://bugzilla.suse.com/1280048

https://bugzilla.suse.com/1281431

https://bugzilla.suse.com/1281432

https://bugzilla.suse.com/1281433

https://bugzilla.suse.com/1281434

https://bugzilla.suse.com/1281435

https://bugzilla.suse.com/1282084

https://bugzilla.suse.com/1282085

https://bugzilla.suse.com/1282132

https://bugzilla.suse.com/1282140

https://bugzilla.suse.com/1282141

https://bugzilla.suse.com/1282362

https://bugzilla.suse.com/1282363

https://bugzilla.suse.com/1282364

https://bugzilla.suse.com/1282366

https://bugzilla.suse.com/1282367

https://bugzilla.suse.com/1282370

https://bugzilla.suse.com/1282372

https://bugzilla.suse.com/1282373

https://bugzilla.suse.com/1282374

https://bugzilla.suse.com/1282378

https://bugzilla.suse.com/1282506

https://bugzilla.suse.com/1282507

https://www.suse.com/security/cve/CVE-2026-59902

https://www.suse.com/security/cve/CVE-2026-59903

https://www.suse.com/security/cve/CVE-2026-62243

https://www.suse.com/security/cve/CVE-2026-62380

https://www.suse.com/security/cve/CVE-2026-75595

https://www.suse.com/security/cve/CVE-2026-75596

https://www.suse.com/security/cve/CVE-2026-76816

https://www.suse.com/security/cve/CVE-2026-89044

https://www.suse.com/security/cve/CVE-2026-93488

https://www.suse.com/security/cve/CVE-2026-93491

https://www.suse.com/security/cve/CVE-2026-93492

https://www.suse.com/security/cve/CVE-2026-93493

https://www.suse.com/security/cve/CVE-2026-93494

https://www.suse.com/security/cve/CVE-2026-93558

https://www.suse.com/security/cve/CVE-2026-93560

https://www.suse.com/security/cve/CVE-2026-93562

https://www.suse.com/security/cve/CVE-2026-93563

https://www.suse.com/security/cve/CVE-2026-93564

https://www.suse.com/security/cve/CVE-2026-93565

https://www.suse.com/security/cve/CVE-2026-93566

https://www.suse.com/security/cve/CVE-2026-93567

https://www.suse.com/security/cve/CVE-2026-93568

https://www.suse.com/security/cve/CVE-2026-93569

https://www.suse.com/security/cve/CVE-2026-93572

https://www.suse.com/security/cve/CVE-2026-93573

https://www.suse.com/security/cve/CVE-2026-93574

https://www.suse.com/security/cve/CVE-2026-93575

https://www.suse.com/security/cve/CVE-2026-93576

https://www.suse.com/security/cve/CVE-2026-93578

https://www.suse.com/security/cve/CVE-2026-93579

http://www.nessus.org/u?e17a444a

Plugin Details

Severity: Critical

ID: 351404

File Name: suse_SU-2026-4391-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.3

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-75595

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.1

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:netty-javadoc, p-cpe:/a:novell:suse_linux:netty-tcnative, p-cpe:/a:novell:suse_linux:netty

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 8/17/2026

Reference Information

CVE: CVE-2026-59902, CVE-2026-59903, CVE-2026-62243, CVE-2026-62380, CVE-2026-75595, CVE-2026-75596, CVE-2026-76816, CVE-2026-89044, CVE-2026-93488, CVE-2026-93491, CVE-2026-93492, CVE-2026-93493, CVE-2026-93494, CVE-2026-93558, CVE-2026-93560, CVE-2026-93562, CVE-2026-93563, CVE-2026-93564, CVE-2026-93565, CVE-2026-93566, CVE-2026-93567, CVE-2026-93568, CVE-2026-93569, CVE-2026-93572, CVE-2026-93573, CVE-2026-93574, CVE-2026-93575, CVE-2026-93576, CVE-2026-93578, CVE-2026-93579

SuSE: SUSE-SU-2026:4391-1