SUSE SLED15 / SLES15 Security Update : alloy (SUSE-SU-2026:4408-1)

high Nessus Plugin ID 362571

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED15 / SLED_SAP15 / SLES15 / SLES_SAP15 host has a package installed that is affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4408-1 advisory.

- CVE-2026-2303: go.mongodb.org/mongo-driver: mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling (bsc#1269861).
- CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277996).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276742).
- CVE-2026-45679: go.opentelemetry.io/obi: Redis error text is exported in span status messages and can lead to exfiltration of sensitive data (bsc#1267482).
- CVE-2026-45680: go.opentelemetry.io/obi: unbounded BPF internal metrics replay can exhaust CPU and cause a DoS (bsc#1267483).
- CVE-2026-45681: go.opentelemetry.io/obi: CPU-mismatch fallback uses 256-byte buffer with 8KB size and can cause OBI out-of-bounds reads to leak memory into telemetry (bsc#1267484).
- CVE-2026-45683: go.opentelemetry.io/obi: Java TLS ioctl kprobe allows a user to point OBI at kernel memory and cause that memory to be copied into telemetry (bsc#1267486).
- CVE-2026-45684: go.opentelemetry.io/obi: log enricher mishandled `writev` buffers and allows multi- segment calls to read and overwrite memory beyond the first segment (bsc#1267487).
- CVE-2026-46600: golang.org/x/net/dns/dnsmessage: Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer (bsc#1272418).
- CVE-2026-48496: opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent (bsc#1268982).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272028).
- CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278671).
- CVE-2026-71556: github.com/go-git/go-git/v5: Arbitrary file read/write via symbolic link resolution (bsc#1276982).
- CVE-2026-71557: github.com/go-git/go-git/v5: Malicious reference names may modify files outside the reference storage (bsc#1276992).
- CVE-2026-75889: arbitrary file reads due to the `prometheus.operator.servicemonitors` component allowing users who can modify `ServiceMonitor` resources in a watched namespace to specify an arbitrary local file through `bearerTokenFile` (bsc#1277429).
- CVE-2026-81521: go.mongodb.org/mongo-driver: MongoDB Go Driver: Write redirection via unvalidated database name in Client.BulkWrite (bsc#1278693).
- CVE-2026-89090: github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream: malformed EventStream response frames containing a crafted header value type byte outside the valid range can cause the host process to terminate (bsc#1280671).

Changes for alloy:

- Update to version 1.19.2.
- Update to version 1.19.1.
- Update to version 1.19.0:
* BREAKING CHANGE: prometheus.operator.servicemonitors now rejects endpoints that reference local files by default. Set allow_arbitrary_file_access = true to preserve previous behavior.
* prometheus.enrich: Support multi-label matching
* prometheus.relabel: Add opt-in TTL cache mode
* telemetry: Add new metrics for graph connections and pyroscope forwarded entries
* database_observability: Exclude system schemas from MySQL health checks and redact query text in explain_plans
- Update to version 1.18.1:
* Add nop receiver to OTel Engine

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected alloy package.

See Also

https://bugzilla.suse.com/1267482

https://bugzilla.suse.com/1267483

https://bugzilla.suse.com/1267484

https://bugzilla.suse.com/1267486

https://bugzilla.suse.com/1267487

https://bugzilla.suse.com/1268982

https://bugzilla.suse.com/1269861

https://bugzilla.suse.com/1272028

https://bugzilla.suse.com/1272418

https://bugzilla.suse.com/1276742

https://bugzilla.suse.com/1276982

https://bugzilla.suse.com/1276992

https://bugzilla.suse.com/1277429

https://bugzilla.suse.com/1277996

https://bugzilla.suse.com/1278671

https://bugzilla.suse.com/1278693

https://bugzilla.suse.com/1280671

https://www.suse.com/security/cve/CVE-2026-2303

https://www.suse.com/security/cve/CVE-2026-37236

https://www.suse.com/security/cve/CVE-2026-41178

https://www.suse.com/security/cve/CVE-2026-45679

https://www.suse.com/security/cve/CVE-2026-45680

https://www.suse.com/security/cve/CVE-2026-45681

https://www.suse.com/security/cve/CVE-2026-45683

https://www.suse.com/security/cve/CVE-2026-45684

https://www.suse.com/security/cve/CVE-2026-46600

https://www.suse.com/security/cve/CVE-2026-48496

https://www.suse.com/security/cve/CVE-2026-56852

https://www.suse.com/security/cve/CVE-2026-56854

https://www.suse.com/security/cve/CVE-2026-56855

https://www.suse.com/security/cve/CVE-2026-71556

https://www.suse.com/security/cve/CVE-2026-71557

https://www.suse.com/security/cve/CVE-2026-75889

https://www.suse.com/security/cve/CVE-2026-78662

https://www.suse.com/security/cve/CVE-2026-81521

https://www.suse.com/security/cve/CVE-2026-89090

http://www.nessus.org/u?060876d9

Plugin Details

Severity: High

ID: 362571

File Name: suse_SU-2026-4408-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/2/2026

Updated: 10/2/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.58

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2026-45684

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.2

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-89090

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:alloy

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/1/2026

Vulnerability Publication Date: 2/10/2026

Reference Information

CVE: CVE-2026-2303, CVE-2026-37236, CVE-2026-41178, CVE-2026-45679, CVE-2026-45680, CVE-2026-45681, CVE-2026-45683, CVE-2026-45684, CVE-2026-46600, CVE-2026-48496, CVE-2026-56852, CVE-2026-56854, CVE-2026-56855, CVE-2026-71556, CVE-2026-71557, CVE-2026-75889, CVE-2026-78662, CVE-2026-81521, CVE-2026-89090

SuSE: SUSE-SU-2026:4408-1