SUSE SLED15: jackson-annotations / jackson-core / jackson-databind / etc (SUSE-SU-2026:4394-1)

high Nessus Plugin ID 351412

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4394-1 advisory.

- CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to Potential Processing Time Issues (bsc#1273856).
- CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit accumulation (bsc#1273857).
- CVE-2026-68495: Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639).
- CVE-2026-68496: Ensure maxNameLength limit enforced for Smile parser (bsc#1282640).
- CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641).
- CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
- CVE-2026-89425: `UTF8DataInputJsonParser._reportInvalidToken()`lacks `maxErrorTokenLength` limit, which allows for unbounded `StringBuilder` growth and can lead to a DoS when malformed tokens are processed (bsc#1282505).

Changes for jackson-annotations:

- Update to 2.18.11

Changes for jackson-bom:

- Update to 2.18.11

Changes for jackson-core:

- Update to 2.18.11
* #1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645, CVE-2026-89407)
* #1698: UTF8DataInputJsonParser does not honor maxErrorTokenLength when reporting an unrecognized token (bsc#1282505, CVE-2026-89425)
* #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
* #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser (bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856, CVE-2026-18401)

Changes for jackson-databind:

- Update to 2.18.11
* #6185: Bracket unresolved IPv6 host name in InetSocketAddress serialization
* #6203: Prevent unbounded growth of type id cache in TypeDeserializer (bsc#1282491, CVE-2026-91776)
* #6204: Avoid quadratic forward-reference resolution in Collection/Map deserializers (bsc#1282492, CVE-2026-91777)
* #6099: Resolve classes without initialization in TypeFactory.findClass()
* #6116: Reject non-ASCII digits in InetAddress literal validation
* #6127: Add StreamReadConstraints number len constraint to javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration (bsc#1280125, CVE-2026-68497)
* #6129: Limit the supported URL schemes for java.nio.file.Path deserialization (bsc#1277883, CVE-2026-19032)
* #6156: Add java.lang.Comparable in set of unsafe polymorphic base types (bsc#1278008, CVE-2026-83557)
* #6165: Apply number length limits to BigDecimal/BigInteger/ /Double/Float Map keys

Changes for jackson-dataformat-xml:

- Update to 2.18.11
* Fix build to avoid past-JDK-8 bytecode generation
* #891: Enforce StreamReadConstraints.maxNestingDepth in FromXmlParser

Changes for jackson-dataformats-binary:

- Update to 2.18.11
* #783: (protobuf) Support StreamReadConstraints.maxDocumentLength in ProtobufParser
* #785: (avro) Support StreamReadConstraints.maxDocumentLength and maxTokenCount in Avro parser
* #803: (ion) Support StreamReadConstraints.maxNestingDepth in Ion parser (partial fix for #358)
* #805: (ion) Support StreamReadConstraints.maxDocumentLength in Ion parser (partial fix for #358)
* #725: (cbor) Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639, CVE-2026-68495)
* #726: (smile) Ensure maxNameLength limit enforced for Smile parser (bsc#1282640, CVE-2026-68496)
* #727: (cbor) CBORParser.nextFieldName(SerializableString) confuses 5-bit length marker 23 with 24 ('1-byte length suffix follows')
* #728: (cbor) CBORParser.nextFieldName(SerializableString) consumes Object entry slot twice on fast-path miss, truncating definite-length Objects
* #733: (cbor) Long `String`s not added to 'stringref' reference table, breaking following references
* #735: (cbor) 'stringref' property-name paths pass 5-bit length marker instead of actual length to shouldReferenceString()
* #736: (cbor) Long Object property names added to 'stringref' reference table twice

Changes for jackson-modules-base:

- Update to 2.18.11

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1273856

https://bugzilla.suse.com/1273857

https://bugzilla.suse.com/1277883

https://bugzilla.suse.com/1278008

https://bugzilla.suse.com/1280125

https://bugzilla.suse.com/1282491

https://bugzilla.suse.com/1282492

https://bugzilla.suse.com/1282505

https://bugzilla.suse.com/1282639

https://bugzilla.suse.com/1282640

https://bugzilla.suse.com/1282641

https://bugzilla.suse.com/1282645

https://www.suse.com/security/cve/CVE-2026-18401

https://www.suse.com/security/cve/CVE-2026-19032

https://www.suse.com/security/cve/CVE-2026-68494

https://www.suse.com/security/cve/CVE-2026-68495

https://www.suse.com/security/cve/CVE-2026-68496

https://www.suse.com/security/cve/CVE-2026-68497

https://www.suse.com/security/cve/CVE-2026-68498

https://www.suse.com/security/cve/CVE-2026-83557

https://www.suse.com/security/cve/CVE-2026-89407

https://www.suse.com/security/cve/CVE-2026-89425

https://www.suse.com/security/cve/CVE-2026-91776

https://www.suse.com/security/cve/CVE-2026-91777

http://www.nessus.org/u?95430b8d

Plugin Details

Severity: High

ID: 351412

File Name: suse_SU-2026-4394-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

Percentile: 95.86

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-83557

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-68494

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:jackson-annotations, p-cpe:/a:novell:suse_linux:jackson-core, p-cpe:/a:novell:suse_linux:jackson-databind, p-cpe:/a:novell:suse_linux:jackson-dataformat-cbor, p-cpe:/a:novell:suse_linux:jackson-dataformat-xml

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 2/28/2026

Reference Information

CVE: CVE-2026-18401, CVE-2026-19032, CVE-2026-68494, CVE-2026-68495, CVE-2026-68496, CVE-2026-68497, CVE-2026-68498, CVE-2026-83557, CVE-2026-89407, CVE-2026-89425, CVE-2026-91776, CVE-2026-91777

SuSE: SUSE-SU-2026:4394-1