Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21999-1 advisory.
Changes in rclone:
- Update to version 1.75.1: (boo#1279548)
- Security
- archive
- Fix zip slip path traversal in untrusted zip files GHSA-66hp-wgxq-6f5q CVE-PENDING (Nick Craig-Wood)
- Hide any archive entry which escapes the directory being listed GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Reject unsafe entry names when mounting squashfs images GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Fix zip subdirectory root matching sibling directories GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Fix zip entry named . hiding every other file GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- Fix directory not found for archive paths containing ./ or // GHSA-66hp-wgxq-6f5q (Nick Craig-Wood)
- build
- Fix multiple CVEs by upgrading to go1.26.6 (Nick Craig-Wood)
- CVE-2026-56860: net/url: quadratic complexity in resolvePath
- CVE-2026-56858: html/template: JavaScript regexp context tracking
- CVE-2026-56862: crypto/tls: limit handshake messages accepted post-handshake
- CVE-2026-56853: net/http: apply ReadHeaderTimeout to unencrypted HTTP/2 check
- CVE-2026-56859: encoding/xml: recursion depth guard during decode
- CVE-2026-33818: encoding/asn1: enforce maximum recursion depth
- CVE-2026-46600: net: panic parsing an invalid SVCB or HTTPS RR in dnsmessage
- CVE-2026-39821: net/http: reject ASCII-only Punycode-encoded labels in idna
- Update golang.org/x/crypto to v0.56.0 to fix multiple CVEs (Nick Craig-Wood)
- CVE-2026-56854: ssh: source-address critical option not enforced for non-public-key auth callbacks
- CVE-2026-78662: ssh: a malicious peer could flood an undecided channel's incoming requests, deadlocking the connection
- CVE-2026-56855: ssh: a malicious peer could send crafted messages on an established channel, deadlocking the connection
- Update golang.org/x/image to v0.45.0 to fix CVE-2026-46603 (Nick Craig-Wood)
- CVE-2026-46603: excessive memory allocation during VP8L decoding
- fs: Confine directory listing entries that escape the root GHSA-3vxh-3pcx-9m8q GHSA-38xv-hf3p-h7mq CVE-PENDING (Nick Craig-Wood)
- fshttp: Don't send --header values to other hosts on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood)
- http: Don't leak configured headers to other hosts or over plaintext on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood)
- lib/rest: Check HTTPS downgrades against the original request on redirect GHSA-486v-q2wf-fp2r CVE-PENDING (Nick Craig-Wood)
- local
- Fix dir metadata escaping the root through a planted symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)
- Fix btime escaping the root via a planted symlink GHSA-f8g7-2xjc-7mfh CVE-PENDING (Nick Craig-Wood)
- Fix panic on Range request past the end of a symlink GHSA-p6m2-r3w9-mpxw CVE-PENDING (Nick Craig-Wood)
- serve docker
- Reject volume names that escape the base directory GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)
- Reject volume names resolving to the base directory itself GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)
- Re-derive volume mountpoint from name when restoring state GHSA-p6vx-hf7p-98j6 (Nick Craig-Wood)
- serve ftp: Fix auth-proxy sessions sharing credentials by username GHSA-c476-6w5q-jw77 CVE-PENDING (Nick Craig-Wood)
- serve s3
- Fix memory exhaustion from client-declared multipart part size GHSA-2p48-j3qc-rx9f CVE-PENDING (Nick Craig-Wood)
- Reject bogus multipart part sizes in the reorder buffer GHSA-2p48-j3qc-rx9f (Nick Craig-Wood)
- Fix auth proxy accepting any request signed with an empty secret GHSA-xwwr-4h3p-r22c CVE-PENDING (Nick Craig-Wood)
- NB the auth proxy protocol for serve s3 has changed - the proxy program is now given the access key ID as user and must return the secret as _secret_access_key
- Fix each server accepting the --auth-key credentials of all the others (Nick Craig-Wood)
- Fix misleading anonymous access log when using an auth proxy via rc GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood)
- serve sftp: Fix auth proxy configured via rc being silently ignored GHSA-p569-5gjg-9cmj CVE-PENDING (Nick Craig-Wood)
- Bug Fixes
- accounting
- Fix memory leak on long-running rcd (nielash)
- Fix memory leak from stats groups on long-running rcd (nielash)
- Fix bwlimit burst overflow (Rayan Salhab)
- bisync
- Fix memory leak when running via the rc (nielash)
- Fix failed transfers of empty files being recorded as synced (Nick Craig-Wood)
- build: Make go1.26 the minimum required version as needed by golang.org/x/crypto v0.56.0 (Nick Craig-Wood)
- config: Redact env var config values in logs (Pastalikek65)
- doc fixes (Anton Karpov, CAOShurong, Dean Chen, Nick Craig-Wood, Recoordinate, Rodrigo Rodrigues, Shantanav Mukherjee, shaurya)
- lib/batcher: Prevent commits racing shutdown (Loi Nguyen)
- lib/transform: Fix panic in truncate_keep_extension (VXNCXNX)
- multipart: Fix chunked uploads storing truncated objects when the source ends early (Nick Craig-Wood)
- operations: Fix silent truncation of streaming uploads whose source ends early (Nick Craig-Wood)
- serve
- Fix VFS instance leaks on server startup failures and shutdown (Hakan SMAL)
- Pass the client IP address to the auth proxy (am-at-enrollvb)
- serve http: Prevent scrolling to the top on page reload (Sune M?lgaard)
- serve nfs: Fix EIO when creating symlinks with --vfs-links (SillyZir)
- serve s3
- Fix failed uploads deleting or corrupting the object at the key (Nick Craig-Wood)
- Fix crash when a multipart upload is aborted while a part is uploading (Nick Craig-Wood)
- Fix modtime not being set when only mtime metadata is supplied on PUT (Nick Craig-Wood)
- Upload all multipart uploads via the VFS so they obey
--bwlimit and show in stats (Nick Craig-Wood)
- Reserve the .rclone_temp_ prefix for temporary objects (Nick Craig-Wood)
- Clean up abandoned multipart uploads after
--multipart-expiry (Nick Craig-Wood)
- vfscache
- Fix reader deadlock when the item size drops below the read offset (Dave)
- Fix log message growing without bound on repeated write errors (Vijay Misal)
- walk: Stop directory traversal when the context is cancelled (Rahman Yilmaz)
- VFS
- Synchronize poll updates with shutdown (Loi Nguyen)
- Make poll shutdown lifecycle deterministic (Loi Nguyen)
- Crypt
- Fix hash mismatches with no_data_encryption on backends which check upload hashes (Nick Craig-Wood)
- Fix directory names which look like versioned file names (TowyTowy)
- Warn about directories with legacy version-like encrypted names (Nick Craig-Wood)
- Azure Blob
- Fix Entra ID server-side copy source authentication (Edward Klesel)
- Fix spurious vfs cache corruption errors during chunked reads (Nick Craig-Wood)
- Azurefiles
- Fix zero padded files being created when the source ends early (Nick Craig-Wood)
- Box
- Fix truncated files being uploaded successfully when the source ends early (Rohit Behera)
- Compress
- Fix corrupted objects being created when the source ends early (Nick Craig-Wood)
- Drive
- Don't list trashed files when removing a directory into the trash (alliasgher)
- Dropbox
- Preserve Paper export paths on lookup (Loi Nguyen)
- Fix context cancellation (e.g. --max-duration limit) not stopping in-flight requests (debaditya)
- Fix chunked uploads of truncated files never finishing (Nick Craig-Wood)
- Don't retry chunked upload requests when the upload has been cancelled (Nick Craig-Wood)
- Decode received shared-file names (Sanjay Kanth A)
- Fix ChangeNotify when the root's case differs from Dropbox's (Loi Nguyen)
- Filelu
- Fix truncated files being uploaded successfully when the source ends early (Nick Craig-Wood)
- Fix duplicate root path during multipart folder creation (kingston125)
- Huaweidrive
- Fix truncated files being uploaded successfully when the source ends early (Rohit Behera)
- Iclouddrive
- Fix uploads into an app container failing with 412 (Christian De Santis)
- Internetarchive
- Fix corrupted files being created when the source ends early (Nick Craig-Wood)
- Internxt
- Persist rotated token returned by the user info call (0rangeSeaW0lf)
- Onedrive
- Fix 403 Forbidden for configuration personal onedrive (machsix)
- Fall back to manual drive ID entry when drive listing fails (SillyZir)
- Don't retry multipart upload chunk on 404 (upload session not found) (water)
- Overview
- Fix internal error: no overview data found on 32 bit architectures (Nick Craig-Wood)
- Pikpak
- Fix truncated files being created when the source ends early (Nick Craig-Wood)
- Fix truncated single part uploads reported as ok when source ends early (Nick Craig-Wood)
- Protondrive
- Fix files uploaded with v1.75.0 not being readable in the Proton apps (Nick Craig-Wood)
- Fix corrupted uploads after a retried upload error (Nick Craig-Wood)
- Quatrix
- Fix chunk upload retries and fix memory leak (Nick Craig-Wood)
- S3
- Update Mega endpoints (Nick Craig-Wood)
- Treat UploadPart success without ETag as retryable error (CAOShurong)
- Fix server side copy failing with --s3-no-head-object (Anatoly Tarnavsky)
- Sia
- Fix corrupted files being created when the source ends early (Nick Craig-Wood)
- Smb
- Reuse the upload connection for SetModTime (alliasgher)
- WebDAV
- Fix SetModTime failing and hashes missing on Nextcloud (Nick Craig-Wood)
- Yandex
- Fix truncated files being uploaded successfully when the source ends early (Rohit Behera)
- Update to version 1.75.0:
- New S3 Providers
- Scality (RING / ARTESCA)
- Zero Services (ZERO-Z3)
- Security
- archive: Don't crash on malformed squashfs images GHSA-6jcg-q3wp-x2f4 CVE-PENDING (Nick Craig-Wood)
- ftp: Fix ftp command injection when encoding doesn't include CRLF GHSA-8c48-q9wj-3w37 CVE-PENDING (Nick Craig-Wood)
- lib/http: Use TLS on all --addr listeners when --cert and
--key are set GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)
- lib/proxy: Fix unbounded HTTP CONNECT headers causing OOM GHSA-xhf4-832v-7xcr CVE-PENDING (Nick Craig-Wood)
- local: Stop source file names escaping the destination directory GHSA-7p4m-qxvv-g567 CVE-PENDING (Nick Craig-Wood)
- rc
- Don't expose pprof debug handlers on an unauthenticated server GHSA-mfvx-7rcj-9m5g CVE-PENDING (Nick Craig-Wood)
- Require authentication to list the remotes with --rc-serve GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)
- Fix leaking stack traces on panics GHSA-gwfq-86j8-7qhv (Nick Craig-Wood)
- s3
- Fix redirect credential leaks, reject HTTPS->HTTP and strip secrets GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)
- Strip S3 Express session token on cross-host redirects GHSA-8mxv-9xhp-86h4 (Nick Craig-Wood)
- serve ftp: Use constant time comparison for password check GHSA-mfvx-7rcj-9m5g (Nick Craig-Wood)
- serve restic: Fix path traversal above the served directory GHSA-45pq-889g-fcgh CVE-PENDING (Nick Craig-Wood)
- serve sftp: Don't crash the whole server on a bad request GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)
- sftp: Fix command injection via crafted filenames on PowerShell remotes GHSA-2m8m-jhrm-w6j2 CVE-PENDING (Nick Craig-Wood)
- vfs: Don't crash the process if a backend panics on a background goroutine GHSA-6jcg-q3wp-x2f4 (Nick Craig-Wood)
- webdav
- Fix HTTPS to HTTP redirects leaking credentials GHSA-h4mf-4v27-hggj (Nick Craig-Wood)
- Tus: fix potential nil pointer crash GHSA-3x6r-wxxg-53vv (Nick Craig-Wood)
- Update google.golang.org/grpc to fix multiple security problems (Nick Craig-Wood)
- New Features
- build: Update all dependencies (Nick Craig-Wood)
- config
- Add config unset command to remove options from a remote (Nick Craig-Wood)
- Add tier to config wizard (dougal)
- docker serve
- Add timeout to volume restore so slow remotes don't block startup (Nick Craig-Wood)
- Restore volumes concurrently so one slow remote doesn't block others (Nick Craig-Wood)
- Make Create idempotent to avoid volume already exists after restart (Nick Craig-Wood)
- doc fixes (blackflytech, dougal, Giridhar, KTibow, mathieulongtin, Nick Craig-Wood, p1, Socialpranker, S?ren Lindberg, yashanil98)
- filter
- Support nested {} alternates in glob filters (maximilize)
- Add --files-from0 to support NUL-delimited input (Gaurav)
- fserrors: Make http2 server sent GOAWAY a retriable error (phatlc)
- fshttp
- Add --dump errors to dump only failed HTTP transactions (Nick Craig-Wood)
- Add --dump trace to log connection level events via httptrace (Nick Craig-Wood)
- gui
- Serve static files with gzip/deflate compression (Leon Brocard)
- Respect explicit --rc-allow-origin instead of always deriving it from the bind address (Kyue)
- Update embedded release to 1.1.11 (Nick Craig-Wood)
- mount2: Add --allow-idmap to advertise FUSE_ALLOW_IDMAP (Valerij Fredriksen)
- nfsmount: Call mount_nfs directly on OpenBSD so -T is accepted (Socialpranker)
- rc
- Respond with 202 if prefer-async header is passed (FTCHD)
- Add config/oauthstop and config/oauthstatus to control oauth listener (FTCHD)
- Include OAuth authorization URL in rc config/oauthstatus response (Hakan SMAL)
- Allow setting rc config and filter options as flat parameters (Hakan SMAL)
- serve
- Support custom http response headers (kkocdko)
- Update serve remote control to accept nested as well as flat options (Hakan SMAL)
- serve dlna: Bound SOAP request bodies (Acts1631)
- serve nfs
- Allow NFS clients to mount subpaths of the served remote (Nick Craig-Wood)
- Advertise AUTH_UNIX so the *BSD NFS clients can mount (Socialpranker)
- serve s3: Stream multipart uploads to the backend instead of buffering in memory (Nick Craig-Wood)
- serve sftp
- Implement [email protected] to report disk usage (Nick Craig-Wood)
- Use the requested atime when setting file times (Nick Craig-Wood)
- serve webdav: Add gzip compression for compressible responses (Leon Brocard)
- serve http: Add --disable-dir-list flag (Leon Brocard)
- Bug Fixes
- archive/squashfs: Fix reading images with no fragment or xattr table (maximilize)
- chunkedreader: Fix spurious errors when a parallel stream is closed early (Nick Craig-Wood)
- config
- Fix config_template_file and config_template being ignored via config/create (hexbinoct)
- Fix normalization when obscuring passwords (Nick Craig-Wood)
- docker serve: Fix plugin timeout on restart when volumes have active mounts (Nick Craig-Wood)
- fs: Fix passwords and tokens appearing in the debug log during rclone config (Nick Craig-Wood)
- gui: Fix cross-origin API requests when bound to a wildcard address (FTCHD)
- hash: Fix xxh128 hasher size (Yuhang Cao)
- log: Fix side effects when importing rclone as a library (Sven Rebhan)
- march
- Fix unnecessarily listing dst directory when src listing finished (Nick Craig-Wood)
- Fix goroutine leak on completed async rc jobs (Yash Anil)
- nfsmount: Fix mount_nfs options incompatible with OpenBSD (Socialpranker)
- rc
- Fix operations/stat for directories with large parent dirs (Nick Craig-Wood)
- Fix _filter and _config parameters being ignored by mount/* commands (Hakan SMAL)
- serve: Fix auth proxy using stale config parameters when making a backend (Nick Craig-Wood)
- serve s3
- Fix aborted multipart uploads appearing as ghosts (Nick Craig-Wood)
- Fix streamed multipart uploads not being atomic (Nick Craig-Wood)
- Fix OOM and InvalidPart errors with concurrent multipart uploads (Nick Craig-Wood)
- sync: Fix --fix-case rename on backends that need upload before overwrite (Nick Craig-Wood)
- Mount
- Support flat VFS and Mount options in mount RC command (Hakan SMAL)
- VFS
- Fix IO error by recreating the cache file if it has been removed (Nick Craig-Wood)
- Fix invalid seek position error when cache files larger than the remote (Nick Craig-Wood)
- Fix vfs cache writeback timer not being stopped when
--transfers reached (Nick Craig-Wood)
- Fix crash when multiple mounts or servers share the same VFS (Nick Craig-Wood)
- Local
- Add --local-fatal-if-no-space flag (ferrumclaudepilgrim)
- Don't resolve relative roots to absolute paths (Nick Craig-Wood)
- Archive
- Fix squashfs listings failing with invalid argument after update (Nick Craig-Wood)
- Azure Blob
- Fix MD5 being dropped on range reads causing vfs cache re-downloads (Nick Craig-Wood)
- Add use_arrow_list flag for experimental Apache Arrow listing (Nick Craig-Wood)
- List very large containers in parallel with list_parallelism (Nick Craig-Wood)
- Azurefiles
- Fix incorrect modtime after uploading a file or setting its modtime (Nick Craig-Wood)
- Improve modtime precision from 1s to 100ns (Nick Craig-Wood)
- Combine
- Don't return an error message as the remote name for a bad object (Nick Craig-Wood)
- Drime
- Remove stale mux_status field from Item (Nick Craig-Wood)
- Drive
- Warn in config wizard before using the shared client_id (Nick Craig-Wood)
- Detect shortcut loops to avoid infinite recursion (Nick Craig-Wood)
- Dropbox
- Add support for impersonate_admin (Gaurav)
- Add --dropbox-skip-shared-folders and
--dropbox-skip-unowned-folders (Gaurav)
- Make Rmdir use one less API call (Socialpranker)
- Use much less memory when uploading small files (Nick Craig-Wood)
- Remove an unnecessary API call when uploading small files (Nick Craig-Wood)
- Filen
- Fix incorrect modtime after updating a file or setting its modtime (Nick Craig-Wood)
- Filescom
- Fix missing MD5 hash after uploading a file (Nick Craig-Wood)
- FTP
- Fix incorrect modtime after uploading a file or setting its modtime (Nick Craig-Wood)
- Googlephotos
- Warn in config wizard before using the shared client_id (Nick Craig-Wood)
- Hasher
- Fix Update not storing hashes in bolt DB after file replacement (Nick Craig-Wood)
- Hdfs
- Fix incorrect modtime after uploading a file or setting its modtime (Nick Craig-Wood)
- Hidrive
- Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood)
- HTTP
- Don't list parent directory when pointing at a single file (Nick Craig-Wood)
- Add Prefer to CORS Access-Control-Allow-Headers header (sijie-Z)
- Iclouddrive
- Fix cannot unmarshal number error when listing photo albums (Nick Craig-Wood)
- Fix 2FA failing with 409 even when the code is valid (Punya Jain)
- Imagekit
- Fix Open with a RangeOption returning the wrong data (Nick Craig-Wood)
- Add mtime to the available metadata (Nick Craig-Wood)
- Internxt
- Add Move and DirMove methods for server-side file and directory operations (jzunigax2)
- Handle file size limit errors during uploads (jzunigax2)
- Surface re-login error when re-auth fails in NewFs (0rangeSeaW0lf)
- Jottacloud
- Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood)
- Linkbox
- Retry bot protection HTML challenge responses instead of failing (Nick Craig-Wood)
- Mailru
- Fix incorrect modtime after updating a file or setting its modtime (Nick Craig-Wood)
- Mega
- Fix files reappearing in listings after being renamed (Nick Craig-Wood)
- Fix moved files disappearing from listings between remotes (Nick Craig-Wood)
- Netstorage
- Fix missing MD5 hash after uploading a file (Nick Craig-Wood)
- Onedrive
- Add support for no admin mode (TaterLi)
- Treat non-2xx preauth download as error (ifloppy)
- Download malware-flagged files via Graph Prefer header (ifloppy)
- Opendrive
- Fix uploaded objects returning the wrong hash and modtime (Nick Craig-Wood)
- Oracleobjectstorage
- Fix crash when downloading objects with unknown length (Nick Craig-Wood)
- Add --oos-decompress flag to download gzip-encoded files (Nick Craig-Wood)
- Pixeldrain
- Fix incorrect modtime and missing hash after uploading a file (Nick Craig-Wood)
- Protondrive
- Implement proper retry logic (tomholford)
- Fix gopenpgp: invalid data: user ID signature with wrong type on custom-domain account (Nick Craig-Wood)
- Fix long hangs on permanent validation failures (Nick Craig-Wood)
- Fix incorrect modtime after uploading a file (Nick Craig-Wood)
- Putio
- Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood)
- Fix sync deletions failing with 400 TRASH_LOCK_TIMEOUT errors (Nick Craig-Wood)
- Quatrix
- Fix incorrect modtime after uploading a file (Nick Craig-Wood)
- S3
- Add Zero Services (ZERO-Z3) provider (Zero Services GmbH)
- Add Scality (RING / ARTESCA) provider (Dzmitry Nianakhau)
- Seafile
- Fix rclone sync files with identical size again and again (TowyTowy)
- SFTP
- Add --sftp-pin-host-key - Trust On First Use host key pinning (Nick Craig-Wood)
- Add --sftp-encoding support (Puneet Dixit)
- Don't retry permanent connection errors (Nick Craig-Wood)
- Allow silencing no hostkey validation warning (Noah Zalev)
- Fix cmd shell execution of paths containing variable-expansion or newline characters (Nick Craig-Wood)
- Shade
- Retry server errors instead of failing the transfer (Nick Craig-Wood)
- Fix uploads failing with EOF when completing multipart uploads (Nick Craig-Wood)
- Smb
- Fix Kerberos credentials being reloaded for every connection (Nick Craig-Wood)
- Fix TCP connection leak when connection setup fails (Nick Craig-Wood)
- Fix server-side move of directories with special characters in the name (Nick Craig-Wood)
- Fix spurious Directory already exists errors when moving directories (Nick Craig-Wood)
- Ulozto
- Fix server side moves between differently rooted remotes losing files (Nick Craig-Wood)
- WebDAV
- Fix incorrect modtime after setting a file's modtime (Nick Craig-Wood)
- Yandex
- Fix 500 errors by waiting for uploads to complete before setting modtime (Nick Craig-Wood)
- Fix missing MD5 hash after uploading a file (Nick Craig-Wood)
- Fix modtime randomly reverting to the upload time after upload (Nick Craig-Wood)
- Add --yandex-upload-wait to fix 500 errors when uploading (Nick Craig-Wood)
- Zoho
- Honour Retry-After header on 429 (Erol Ozcan)
- Add --zoho-tpslimit and --zoho-tpslimit-burst (Erol Ozcan)
- Log throttling once per episode at NOTICE (Erol Ozcan)
- Rate limit repeated listings of the same folder (Erol Ozcan)
- Fix flaky folder list limiter test under concurrent listings (Nick Craig-Wood)
- Fix large file overwrite creating a duplicate instead of replacing (Erol Ozcan)
- Treat R008 unauthorized as directory not found (Erol Ozcan)
- Preserve root_folder_id on reconnect and allow setting it (Erol Ozcan)
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected rclone, rclone-bash-completion and / or rclone-zsh-completion packages.
Plugin Details
File Name: openSUSE-2026-21999-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:rclone-bash-completion, p-cpe:/a:novell:opensuse:rclone-zsh-completion, p-cpe:/a:novell:opensuse:rclone
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 9/28/2026
Vulnerability Publication Date: 5/12/2026
Reference Information
CVE: CVE-2026-33818, CVE-2026-39821, CVE-2026-46600, CVE-2026-46603, CVE-2026-56853, CVE-2026-56854, CVE-2026-56855, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-78662