SUSE SLED15 / SLES15 Security Update : cosign (SUSE-SU-2026:4392-1)

high Nessus Plugin ID 351406

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4392-1 advisory.

- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272117).
- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278614).
- CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).
- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279215).
- Verification bypass via public key in legacy bundle (bsc#1282542).

Changes for cosign:

- update to 3.1.3:
* Auto-detect default digest algorithm for public keys
* fix(pkcs11key): return an error instead of panicking when no key pair matches
* Supporting OCI Signing with X.509 Certificate Chain
* fix: prevent shell completions for various options not taking filenames
* fix(blob): compare file checksums case-insensitively in
* Verification bypass via public key in legacy bundle (GHSA- fx35-mq7g-6g98, bsc#1282542)

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected cosign, cosign-bash-completion and / or cosign-zsh-completion packages.

See Also

https://bugzilla.suse.com/1272117

https://bugzilla.suse.com/1275025

https://bugzilla.suse.com/1278614

https://bugzilla.suse.com/1279215

https://bugzilla.suse.com/1282542

https://www.suse.com/security/cve/CVE-2026-56852

https://www.suse.com/security/cve/CVE-2026-56854

https://www.suse.com/security/cve/CVE-2026-56855

https://www.suse.com/security/cve/CVE-2026-56864

https://www.suse.com/security/cve/CVE-2026-78662

https://www.suse.com/security/cve/CVE-2026-84304

http://www.nessus.org/u?4db62552

Plugin Details

Severity: High

ID: 351406

File Name: suse_SU-2026-4392-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-56854

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2026-78662

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-84304

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:cosign-bash-completion, p-cpe:/a:novell:suse_linux:cosign-zsh-completion, p-cpe:/a:novell:suse_linux:cosign

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 7/16/2026

Reference Information

CVE: CVE-2026-56852, CVE-2026-56854, CVE-2026-56855, CVE-2026-56864, CVE-2026-78662, CVE-2026-84304

SuSE: SUSE-SU-2026:4392-1