openSUSE 16: helm / helm-bash-completion / helm-fish-completion / etc (openSUSE-SU-2026:21983-1)

high Nessus Plugin ID 362531

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21983-1 advisory.

- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265758).
- CVE-2026-35204: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary file write via specially crafted plugin (bsc#1261939).
- CVE-2026-35205: github.com/helm/helm: helm.sh/helm/v4: Helm: Arbitrary code execution due to insufficient plugin provenance verification (bsc#1261935).
- CVE-2026-35206: github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart (bsc#1261938).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510).
- CVE-2026-41888: github.com/distribution/distribution/v3: tag deletion bypasses the storage.delete.enabled configuration (bsc#1265428).
- CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127).
- CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660).
- CVE-2026-50163: oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks (bsc#1276327).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997).
- CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1281426).
- CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1281426).
- CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025).
- CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024).
- CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1281426).
- CVE-2026-81871: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration (bsc#1281468).
- CVE-2026-81872: go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker- driven log emission (bsc#1281469).
- CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network probing (bsc#1281112).
- gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected helm, helm-bash-completion, helm-fish-completion and / or helm-zsh-completion packages.

See Also

https://bugzilla.suse.com/1261935

https://bugzilla.suse.com/1261938

https://bugzilla.suse.com/1261939

https://bugzilla.suse.com/1265428

https://bugzilla.suse.com/1265758

https://bugzilla.suse.com/1270127

https://bugzilla.suse.com/1271660

https://bugzilla.suse.com/1271997

https://bugzilla.suse.com/1275024

https://bugzilla.suse.com/1275025

https://bugzilla.suse.com/1276327

https://bugzilla.suse.com/1276510

https://bugzilla.suse.com/1276514

https://bugzilla.suse.com/1281112

https://bugzilla.suse.com/1281426

https://bugzilla.suse.com/1281468

https://bugzilla.suse.com/1281469

https://www.suse.com/security/cve/CVE-2026-33814

https://www.suse.com/security/cve/CVE-2026-35204

https://www.suse.com/security/cve/CVE-2026-35205

https://www.suse.com/security/cve/CVE-2026-35206

https://www.suse.com/security/cve/CVE-2026-41178

https://www.suse.com/security/cve/CVE-2026-41888

https://www.suse.com/security/cve/CVE-2026-48978

https://www.suse.com/security/cve/CVE-2026-50151

https://www.suse.com/security/cve/CVE-2026-50163

https://www.suse.com/security/cve/CVE-2026-56852

https://www.suse.com/security/cve/CVE-2026-56854

https://www.suse.com/security/cve/CVE-2026-56855

https://www.suse.com/security/cve/CVE-2026-56864

https://www.suse.com/security/cve/CVE-2026-56865

https://www.suse.com/security/cve/CVE-2026-78662

https://www.suse.com/security/cve/CVE-2026-81871

https://www.suse.com/security/cve/CVE-2026-81872

https://www.suse.com/security/cve/CVE-2026-85732

Plugin Details

Severity: High

ID: 362531

File Name: openSUSE-2026-21983-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.14

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-35205

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-35204

CVSS v4

Risk Factor: High

Base Score: 8.4

Threat Score: 7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:helm-bash-completion, p-cpe:/a:novell:opensuse:helm-fish-completion, p-cpe:/a:novell:opensuse:helm-zsh-completion, p-cpe:/a:novell:opensuse:helm

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/30/2026

Vulnerability Publication Date: 4/9/2026

Reference Information

CVE: CVE-2026-33814, CVE-2026-35204, CVE-2026-35205, CVE-2026-35206, CVE-2026-41178, CVE-2026-41888, CVE-2026-48978, CVE-2026-50151, CVE-2026-50163, CVE-2026-56852, CVE-2026-56854, CVE-2026-56855, CVE-2026-56864, CVE-2026-56865, CVE-2026-78662, CVE-2026-81871, CVE-2026-81872, CVE-2026-85732