Synopsis
The remote SUSE host is missing one or more security updates.
Description
The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4394-1 advisory.
- CVE-2026-18401: Number Length Constraint Bypass in Async Parser Can Lead to Potential Processing Time Issues (bsc#1273856).
- CVE-2026-68494: Async parser maxNumberLength bypass via chunked digit accumulation (bsc#1273857).
- CVE-2026-68495: Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639).
- CVE-2026-68496: Ensure maxNameLength limit enforced for Smile parser (bsc#1282640).
- CVE-2026-68498: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641).
- CVE-2026-89407: Optimize NumberInput.looksLikeValidNumber (bsc#1282645).
- CVE-2026-89425: `UTF8DataInputJsonParser._reportInvalidToken()`lacks `maxErrorTokenLength` limit, which allows for unbounded `StringBuilder` growth and can lead to a DoS when malformed tokens are processed (bsc#1282505).
Changes for jackson-annotations:
- Update to 2.18.11
Changes for jackson-bom:
- Update to 2.18.11
Changes for jackson-core:
- Update to 2.18.11
* #1649: Optimize NumberInput.looksLikeValidNumber (bsc#1282645, CVE-2026-89407)
* #1698: UTF8DataInputJsonParser does not honor maxErrorTokenLength when reporting an unrecognized token (bsc#1282505, CVE-2026-89425)
* #1642: Fix maxDocumentLength bypass in async parser single-feedInput() case [GHSA-2c4j-63jj-9fqr]
* #1643: Enforce maxNameLength incrementally in ReaderBasedJsonParser (bsc#1282641, CVE-2026-68498) of async parser (bsc#1273857, CVE-2026-68494) non-blocking (async) parser (bsc#1273856, CVE-2026-18401)
Changes for jackson-databind:
- Update to 2.18.11
* #6185: Bracket unresolved IPv6 host name in InetSocketAddress serialization
* #6203: Prevent unbounded growth of type id cache in TypeDeserializer (bsc#1282491, CVE-2026-91776)
* #6204: Avoid quadratic forward-reference resolution in Collection/Map deserializers (bsc#1282492, CVE-2026-91777)
* #6099: Resolve classes without initialization in TypeFactory.findClass()
* #6116: Reject non-ASCII digits in InetAddress literal validation
* #6127: Add StreamReadConstraints number len constraint to javax.xml.datatype.XMLGregorianCalendar and javax.xml.datatype.Duration (bsc#1280125, CVE-2026-68497)
* #6129: Limit the supported URL schemes for java.nio.file.Path deserialization (bsc#1277883, CVE-2026-19032)
* #6156: Add java.lang.Comparable in set of unsafe polymorphic base types (bsc#1278008, CVE-2026-83557)
* #6165: Apply number length limits to BigDecimal/BigInteger/ /Double/Float Map keys
Changes for jackson-dataformat-xml:
- Update to 2.18.11
* Fix build to avoid past-JDK-8 bytecode generation
* #891: Enforce StreamReadConstraints.maxNestingDepth in FromXmlParser
Changes for jackson-dataformats-binary:
- Update to 2.18.11
* #783: (protobuf) Support StreamReadConstraints.maxDocumentLength in ProtobufParser
* #785: (avro) Support StreamReadConstraints.maxDocumentLength and maxTokenCount in Avro parser
* #803: (ion) Support StreamReadConstraints.maxNestingDepth in Ion parser (partial fix for #358)
* #805: (ion) Support StreamReadConstraints.maxDocumentLength in Ion parser (partial fix for #358)
* #725: (cbor) Ensure maxNameLength limit enforced for CBOR parser (bsc#1282639, CVE-2026-68495)
* #726: (smile) Ensure maxNameLength limit enforced for Smile parser (bsc#1282640, CVE-2026-68496)
* #727: (cbor) CBORParser.nextFieldName(SerializableString) confuses 5-bit length marker 23 with 24 ('1-byte length suffix follows')
* #728: (cbor) CBORParser.nextFieldName(SerializableString) consumes Object entry slot twice on fast-path miss, truncating definite-length Objects
* #733: (cbor) Long `String`s not added to 'stringref' reference table, breaking following references
* #735: (cbor) 'stringref' property-name paths pass 5-bit length marker instead of actual length to shouldReferenceString()
* #736: (cbor) Long Object property names added to 'stringref' reference table twice
Changes for jackson-modules-base:
- Update to 2.18.11
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected packages.
Plugin Details
File Name: suse_SU-2026-4394-1.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:jackson-annotations, p-cpe:/a:novell:suse_linux:jackson-core, p-cpe:/a:novell:suse_linux:jackson-databind, p-cpe:/a:novell:suse_linux:jackson-dataformat-cbor, p-cpe:/a:novell:suse_linux:jackson-dataformat-xml
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 9/29/2026
Vulnerability Publication Date: 2/28/2026
Reference Information
CVE: CVE-2026-18401, CVE-2026-19032, CVE-2026-68494, CVE-2026-68495, CVE-2026-68496, CVE-2026-68497, CVE-2026-68498, CVE-2026-83557, CVE-2026-89407, CVE-2026-89425, CVE-2026-91776, CVE-2026-91777
SuSE: SUSE-SU-2026:4394-1