openSUSE 16 Security Update : sccache (openSUSE-SU-2026:21982-1)

critical Nessus Plugin ID 362529

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has a package installed that is affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21982-1 advisory.

- CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243868).
- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274146).
- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257923).
- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270206).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270559).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270693).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270736).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270869).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270512).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust- openssl crate (bsc#1270938).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270948).
- CVE-2026-66746: rouille: HTTP Response Splitting via Unvalidated Response Header Values (bsc#1273881).
- CVE-2026-66754: rouille: remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL (bsc#1273884).
- CVE-2026-67181: rouille: HTTP Request Smuggling via Transfer-Encoding Desynchronization (bsc#1273886).
- CVE-2026-67182: rouille: HTTP Request Smuggling Enables Front-End Access Control Bypass (bsc#1273888).
- CVE-2026-93599: rustls-webpki: panic via empty BIT STRING (bsc#1282211).
- CVE-2026-93600: rustls-webpki: name constraints URI validation bypass (bsc#1282211).
- CVE-2026-93601: rustls-webpki: name constraint bypass (bsc#1282211).
- CVE-2026-93602: rustls-webpki: CRL revocation check bypass (bsc#1282211).

Changes for sccache:

Update to version 0.18.0~2:
* Add experimental concurrent cache support
* chore: Remove dependency status badge (#2856)
* Don't hand the jobserver to children that can't use it
* dist: refuse to trim rlibs from crates that also emit a cdylib
* fix(cache): avoid duplicate multilevel reads
* Strip basedirs from the compiler arguments too
* tests/integration: replace MinIO with Silo
* ci: dump sccache logs on integration failures
* multilevel: a chain with any writable level is writable
* Fix parsing of #line directives
* Release 0.18.0
* daemonize: use an allow-list approach to inherited FDs
* gcc, clang: make the assembler part of the cache key
* support cl.exe /openmp:llvm
* support all current /fsanitize*, /fsanitize-coverage*, and /fno-sanitize* args
* support MSVC /feature argument
* msvc: support lots of flags (#2832)
* Update shlex dependency to version 2 (#2836)
* gcc: mark flags as TooHard if need to cache something else (#2833)
* clang: support more CLI options (#2834)
* msvc: support arm64EC and fastfail flags (#2830)
* chore: fix typo in comment (#2829)
* nvcc: accept the --diag-error/--diag-suppress/--diag-warn family (#2816)
* cache: allow skipping capability checks (#2822)
* Bump opendal to 0.58.1 and fix fallout (fixes local GCS cache usage) (#2715)
* nvcc (Windows): protect escaped quotes in dryrun lines before flattening backslashes (#2811)
* Add an agent (#2812)
* Add support for d20bforceinline. (#2807)
* feat: add Microsoft Entra ID (passwordless) auth for the Azure Blob backend (#2802)
* Bump MSRV to 1.91.0 (#2793)
* Fix `nvcc` dryrun parsing for CUDA 13.3 (#2722)
* test: Fixed hardcoded binary path in test
* Release 0.17.0
* tests: pin libc in the dist test crate
* doc: clarify server-side outputs and drop 'recommended mode' claim
* doc: document SCCACHE_CLIENT_SIDE env var
* doc: document client-side and direct modes in Architecture.md
* Fix description of Unix socket-based Redis connection
* server: remove redundant async block in start_compile_task
* server: simplify bind() request loops with ? instead of manual match arms
* Add support for arg files in Rust (#2782)
* feat: support S3 SSE-KMS with AWS-managed and customer-managed keys (#2770)
* abort compile tasks and associated subprocesses when a client disconnects
* treat -ivfsoverlay as a preprocessor-only argument
* gcc: refine response-file tokenizer visibility and whitespace handling
* integration: convert cmake 4.x modules XFAIL test to a passing test
* gcc/clang: cache and distribute builds using quoted @response files
* fix: Fix ToolchainPackager cfg gate to build on ppc64le/s390x
* fix: make gcc diagnostics color output work the same as for rustc
* implement client-side mode
* split handle_compile_response so that the compilation result can be handled separately
* implement IpcStorage -- Storage backend over IPC
* extend wire protocol with storage RPCs
* implement AddAssign for ServerStats and related types
* add Storage::get_path for direct file access
* implement get_raw/put_raw on MultiLevelStorage
* add client_side_mode config flag (SCCACHE_CLIENT_SIDE)
* Extract new_client_runtime() helper to DRY up client runtime creation
* Clarify single-threaded runtime rationale comment (grammar)
* fix: use single-threaded tokio runtime in sccache dist-client
* fix: use single-threaded tokio runtime in sccache client
* fix: handle disabled cache backend features in multilevel chain
* Fix ldd output parsing: remove .exists() check that failed on systems where the symlink source path does not exist locally (e.g. aarch64)
* Fix cfg guard for PanicToolchainPackager to also cover non-x86_64 Linux architectures (e.g. aarch64)
* Release 0.16.0
* fix: strip SCCACHE_BASEDIRS from escaped-backslash paths on Windows (#2736)
* Ignore empty-set environment values (#2639)
* feat: all backends support making them as read-only (#2705)
* Enable RE on Linux-aarch64 (#2668)
* Slightly improve logging (#2734)
* chore: encode jwt key and cert digest with base64 in logs (#2712)
* chore: make clippy happy (#2727)
* feat: avoid sccache wrapper when resolving compiler (#2720)
* Fall back to direct cache write if tempfile creation on the same fs fails (#2369)
* remove too noisy bench
* feat(nvcc): support argument: `--dependency-output` (#2708)
* fix: add newline when printing dist-status to stdout
* Revert Classify .s files as AssemblerToPreprocess so #include/#ifdef are hon...
* Don't wait depfiles for gcc/clang preprocessed inputs
* Classify .s files as AssemblerToPreprocess so #include/#ifdef are honored
* prepare release 0.15.0
* Add cargo-binstall metadata for prebuilt binary installation
* Fix coverage
* fix: handle directories in dep-info source file hashing
* docs(Rust.md): Add caveats from README
* Add retry for dists docker image build
* ci: set crt-static for riscv64 musl targets
* feat: Add loongarch64 support
* feat: Implement multi-tier caching with fallback and backfilling (#2581)
* msvc: add support for Y-, YI, Zf flags
* Group tests logging in CI
* Add failing test for cmake-modules + cmake 4 version
* Unfold ninja output in the test
* Add a comment for maintaining integration tests
* Move cmake-modules to integration tests
* fix: exclude CARGO_ENCODED_RUSTFLAGS from env var hash (#2651)
* chore(deps): update rust crate quinn-proto to v0.11.14
* Fix sync GCS initialization
* clippy: fix from_iter_instead_of_collect lint
* fix: add Win32_Security feature to windows-sys dependency
* build(deps): bump actions/download-artifact from 5 to 8
* msvc: Append the default .pdb extension for the /Fd argument (#2621)
* build(deps): bump actions/upload-artifact from 4 to 7
* clippy: fix ref_option lint
* ci: install grcov from prebuilt binary instead of cargo install
* ci: use default toolchain to install grcov
* ci: fix artifact_failure action when target dir does not exist
* Remove benchmark normalize_win_path_utf8 (#2634)
* Revert actions: add security audit workflow (#2594) (#2603)
* partial c++20 module support (#2516)
* clippy: fix ptr_as_ptr lint (#2611)
* Add support for `d1nodatetime` & `await:strict` MSVC flags (#2617)
* chore: switch thirtyfour_sync to thirtyfour (#2613)
* clippy: fix manual_string_new lint (#2609)
* clippy: fix unnecessary_semicolon lint (#2615)
* clippy: fix explicit_into_iter_loop lint (#2616)
* Avoid double-caching when ccache is installed in PATH (#2524)
* clippy: fix cloned_instead_of_copied lint (#2605)
* clippy: fix semicolon_if_nothing_returned lint (#2601)
* Move PreprocessorCacheModeConfig to src/config.rs (#2604)
* clippy: fix cloned_ref_to_slice_refs lint (#2602)
* prepare the new release (#2600)
* chore: update to toml 0.9 (#2599)
* ci: Add coverage to integration tests, report it to Codecov.io (#2598)
* Preparation for multilevel caching (#2597)
* Add sccache-dist to flake.nix (#2579)
* fixup! cargo fmt
* fixup! rustfmt update
* Extract FileObjectSource, CacheRead and CacheWrite to cache_io.rs
* chore: update to nix 0.30
* Add a helper method to get a correct backend name
* Add cos feature gate to RemoteStorage
* Simplify profiles for integration tests
* clippy: fix implicit_clone lint (#2584)
* actions: add security audit workflow (#2594)
* docs: fix examples showing an xz-compress toolchain archive (#2587)
* add benches for normalize_win_path strip_basedirs (#2588)
* snap: update to core24 (#2570)
* Add .rustfmt.toml for consistent style between `rustfmt` and `cargo fmt` (#2582)
* add comments about auth token requirements (#2583)
* chore: update to tokio-serde 0.9 (#2585)
* ci: update freebsd to 15.0 (#2586)
* distributed compilation support for asm & preprocessor outputs (#2557)
* remove unused declaration (#2577)
* Extract LazyDiskCache to a separated file (#2573)
* Revert ci: show diff for toml_format (#2578)
* Open Add SCCACHE_BASEDIRS support
* ci: show diff for toml_format
* chore: update to syslog 7
* refactor: use matrix to reduce deduplication
* fix: remove outdated `analysis` mode
* Unbreak the s390x CI
* ci: add macos-15-intel for prebuilt binary (#2555)
* Integration tests (#2564)
* Fix code review.
* Impl for COS.
* build(deps): bump opendal from 0.54.0 to 0.55.0
* Move integration tests related stuff to subdir
* Add Objective C Header for consistency
* github action: fix the syntax - fails in the ci
* sccache: prepare a new release
* msvc: add msbuild support test
* msvc: fix detect_showincludes_prefix with MSBuild
* chore: update to gzp 2
* build(deps): bump rsa from 0.9.6 to 0.9.10
* codspeed: evaluate the memory benchmarking
* remove too quick benchmarks
* codspeed: move to simulation mode
* Add realistic LRU cache access pattern benchmarks
* Add compression characteristics benchmarks
* Add build workflow simulation benchmarks
* Add hash computation scenario benchmarks
* Add batch cache entry benchmarks
* Add cache artifact serialization benchmarks
* Add /etc/ld.so.conf.d (if present) to compiler package
* Assembly language support
* fix(ci): pin serde_json to avoid zmij dependency
* fix(ci): update zmij to fix s390x cross-compilation
* Fix the run of the CI
* run the benchmark in the ci
* add benchmarks
* dedup some code
* Fix hash logging prefix
* Add support for C preprocessor output
* Add GCC pipe flag support
* Improve save-temps gcc flags detection
* MSVC: support forward slash as an output dir marker
* add clang -fplugin=x regression test
* canbeconcatenated is not accounted for in cmp
* Reversed the order for looking `rustc`, added comment
* Fix failing test_rlib_dep_reader_call for omit CARGO_HOME
* fix: don't hash -parallel-jobs in Clang
* docs: add installation steps for nix (#2523)
* Support clang -fexperimental-assignment-tracking option (#2517)
* add a nix flake (#2518)
* Switch from the unmaintained daemonize crate to a maintained fork
* chore: update to fs-err 3
* Fix grammar of error message
* Add server name info to stderr of remote jobs that ran, but failed
* Remove another pointless destructuring
* try to unbreak the ci
* fix s390x build error
* Add riscv64 support
* fix: make aarch64-pc-windows-msvc also zip not tar.gz
* Free up disk space in CI
* MSVC on Windows only
* Avoid 'No space left on device' errors in CI
* GitHub dropped macos-13 runners
* Proper function pointer to int cast
* Avoid unused structs with dist-server disabled
* no check cfg (#2507)
* chore: switch once_cell crate to standard library (#2499)
* Avoid unreliable assert_cmd::cargo::cargo_bin (#2489)
* Fix build on macOS which doesn't have separate 32-bit dirent (#2492)
* Fix Clippy warnings (#2490)
* docs: bump MSRV to 1.85.0
* msvc: handle '/FoRelease\' command-line argument
* chore: drop tower dependency
* chore: update to itertools 0.14
* Use generator in CMAKE_MSVC_DEBUG_INFORMATION_FORMAT in README
* Update directories to 6.0
* Configuration.md - note logging env variables
* chore: update to env_logger 0.11
* deps: update blake3
* prepare version 0.12.0
* Update README with winget installation instructions
* Skip CARGO_BUILD_JOBS in hash keys
* build(deps): bump object from 0.36.7 to 0.37.1
* Adjust tests after the rust update
* Fix CI by adding cargo-features and updating coverage test to use modern -Cinstrument-coverage
* Fix more clippy warnings
* bump rustc in the ci too
* Fix rustc 1.85 clippy warnings
* bump to rustc 1.85 / edition 2024. mandatory for reqsign-core and run rustfmt with the version
* fix clippy warnings
* bump opendal to 0.54.0 & reqsign to 0.18.0
* github action: when creating a release, make it as draft before (#2458)
* prepare version 0.11.0 (#2457)
* document SCCACHE_LOG_MILLIS (#2456)
* logging: add a option to log milliseconds (Closes: #2454) (#2455)
* feat: handle human size prefixes (#2405)
* fix: in stats, Compare values AND keys to have a fully deterministic order (#2403)
* Add --diagnostic-width to test for args ignored in hash
* Ignore --diagnostic-width argument when computing hash
* build(deps): bump actions/checkout from 4 to 5
* build(deps): bump actions/download-artifact from 4 to 5
* build(deps): bump actions/github-script from 7 to 8
* Fix rustfmt
* Fix comments on request
* Fix clippy and rustfmt
* Add test for count toolchain and use Determenistic for create tar archive
* Fix mtime for reproducable toolchains
* build(deps): bump chrono from 0.4.41 to 0.4.42
* fix typo in an environment variable name
* Fix documentation of azure configuration
* Account for clippy-driver having extra prefix `rustc`
* Fix build on Android (in Termux)
* add support for s390x build
* chore: replace retry crate with backon
* Remove or replace Windows 2019 CI config
* Needs another result unwrapping, it seems
* Test: invoking symlink compiler to sccache invokes compiler
* Add a comment about the problem with symlinks and current_exe()
* Fix symbolic links to sccache on linux
* Allow the CI configuration to disable clang++ for CUDA testing
* Don't run tests using clang++ as CUDA compiler on Windows
* add description to sccache-dist commands
* Display a more user-friendly error when compiling on Linux/arm64
* Clarify documentation about the hash (aka cache key)
* Remove stray ')'
* Remove documentation for removed limitations of preprocessor cache mode
* Fix preprocessor cache mode when the compiler outputs a dep file
* Partially revert Don't cache dep file (#2322)
* Do not disable preprocessor cache mode if there is a dep file
* Fix preprocessor cache mode with distributed builds (#2173)
* Change self of generate_hash_key() from Box<Self> to &mut Self
* Remove a few IMO pointless indirections / aliases
* Remove workaround for #2173
* Add test for bug #2173
* chore: fix some minor issues in comments
* build(deps): bump chrono from 0.4.40 to 0.4.41
* build(deps): bump memchr from 2.7.1 to 2.7.5
* check if we can use a specific version of rust to build grcov
* Move comment that hadn't moved with its corresponding code
* Rework direct mode documentation some more
* Explain what preprocessor cache mode really does
* Reword and correct the preprocessor cache mode documentation
* chore: Remove not working mozilla code
* Add support for -fsanitize-ignorelist
* github storage: adjust the doc
* github storage: ACTIONS_CACHE_URL => ACTIONS_RESULTS_URL
* github storage: force version 2
* Update codecov badge in README.md
* Expand tests for dist-server
* ci: Consolidate testing, coverage
* ci: Update ubuntu-20.04 runners to ubuntu-22.04
* chore: fix some comments
* Give the --dist-status user some information about when a retry will happen.
* Add support for Xclang flag '-mrelax-all'
* Add support for Xclang flag '-mconstructor-aliases'
* feat(utils): Add support for object >= 0.33
* fix(tests): Remove executable bit from oauth.rs
* build(deps): bump openssl from 0.10.64 to 0.10.72
* build(deps): bump tokio from 1.41.0 to 1.43.1
* Improve the CARGO_INCREMENTAL checking (#2364)
* build(deps): bump chrono from 0.4.38 to 0.4.40
* build(deps): bump clap from 4.4.18 to 4.5.13
* build(deps): bump ring from 0.17.7 to 0.17.13
* Bail on `nvcc -time` and `nvcc -fdevice-time-trace` flags
* test hip with librandomize_readdir
* Add randomize_readdir test utility
* fix non-strict HIP device lib order
* Create config during testing to collect coverage data
* Extend coverage to distributed tests
* chore: replace num_cpus crate with available_parallelism in standard library (#2342)
* Update CI coverage: grcov/codecov

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected sccache package.

See Also

https://bugzilla.suse.com/1243868

https://bugzilla.suse.com/1257923

https://bugzilla.suse.com/1270206

https://bugzilla.suse.com/1270512

https://bugzilla.suse.com/1270559

https://bugzilla.suse.com/1270693

https://bugzilla.suse.com/1270736

https://bugzilla.suse.com/1270869

https://bugzilla.suse.com/1270938

https://bugzilla.suse.com/1270948

https://bugzilla.suse.com/1273881

https://bugzilla.suse.com/1273884

https://bugzilla.suse.com/1273886

https://bugzilla.suse.com/1273888

https://bugzilla.suse.com/1274146

https://bugzilla.suse.com/1282211

https://www.suse.com/security/cve/CVE-2024-12224

https://www.suse.com/security/cve/CVE-2026-25541

https://www.suse.com/security/cve/CVE-2026-25727

https://www.suse.com/security/cve/CVE-2026-41676

https://www.suse.com/security/cve/CVE-2026-41677

https://www.suse.com/security/cve/CVE-2026-41678

https://www.suse.com/security/cve/CVE-2026-41681

https://www.suse.com/security/cve/CVE-2026-41898

https://www.suse.com/security/cve/CVE-2026-42327

https://www.suse.com/security/cve/CVE-2026-44662

https://www.suse.com/security/cve/CVE-2026-45784

https://www.suse.com/security/cve/CVE-2026-66746

https://www.suse.com/security/cve/CVE-2026-66754

https://www.suse.com/security/cve/CVE-2026-67181

https://www.suse.com/security/cve/CVE-2026-67182

https://www.suse.com/security/cve/CVE-2026-93599

https://www.suse.com/security/cve/CVE-2026-93600

https://www.suse.com/security/cve/CVE-2026-93601

https://www.suse.com/security/cve/CVE-2026-93602

Plugin Details

Severity: Critical

ID: 362529

File Name: openSUSE-2026-21982-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-12224

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-41677

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-41681

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:sccache

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 12/9/2024

Reference Information

CVE: CVE-2024-12224, CVE-2026-25541, CVE-2026-25727, CVE-2026-41676, CVE-2026-41677, CVE-2026-41678, CVE-2026-41681, CVE-2026-41898, CVE-2026-42327, CVE-2026-44662, CVE-2026-45784, CVE-2026-66746, CVE-2026-66754, CVE-2026-67181, CVE-2026-67182, CVE-2026-93599, CVE-2026-93600, CVE-2026-93601, CVE-2026-93602