Synopsis
The remote SUSE host is missing one or more security updates.
Description
The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4417-1 advisory.
- CVE-2026-85731: oras.land/oras-go/v2: arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (bsc#1281104).
- CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network probing (bsc#1281112).
Changes for helm:
- Update to version 3.22.0:
* chore(deps): bump the k8s-io group across 1 directory with 6 updates
* bump version to 3.22 (#32606)
* fix: set [pull,push] scope when helm push to a registry(use token auth) (backport) (#32362)
* chore(deps): bump the k8s-io group with 7 updates (#32573)
* chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#32563)
* chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#32554)
* chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#32542)
* [dev-v3 backport] deps: bump google.golang.org/[email protected] for GO-2026-6061 (#32536)
* fix: bump go.opentelemetry.io/[email protected] for GO-2026-5158 (#32535)
* chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6
* fix(provenance): migrate to ProtonMail/go-crypto to resolve GO-2026-5932
* chore(deps): bump the k8s-io group with 7 updates
* chore(deps): bump github/codeql-action/upload-sarif (#32449)
* chore(deps): bump github/codeql-action/analyze from 4.37.1 to 4.37.2
* chore(deps): bump github/codeql-action/autobuild from 4.37.1 to 4.37.2
* chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.2
* chore(deps): bump github/codeql-action/autobuild from 4.37.0 to 4.37.1 (#32381)
* chore(deps): bump github/codeql-action/upload-sarif (#32382)
* ci: auto-label PRs targeting dev-v3 (#32340)
* chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#32331)
* chore(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 (#32332)
* chore(deps): bump github/codeql-action/analyze from 3.26.6 to 4.37.0 (#32357)
* chore(deps): bump github/codeql-action/upload-sarif (#32360)
* chore(deps): bump github/codeql-action/init from 3.26.6 to 4.37.0 (#32359)
* chore(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#32356)
* chore(deps): bump golangci/golangci-lint-action from 6.1.1 to 9.3.0 (#32354)
* chore(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3 (#32353)
* chore(deps): bump golang.org/x/text from 0.38.0 to 0.40.0 (#32310)
* chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#32308)
* chore(deps): bump golang.org/x/term from 0.44.0 to 0.45.0 (#32306)
* fix(engine): prevent Files.Lines panic on empty file
* fix: drop containerd v1 dep to resolve govulncheck CVEs
* chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33
* chore(deps): bump github.com/cyphar/filepath-securejoin
* chore(deps): bump the k8s-io group with 2 updates
* chore(deps): bump the k8s-io group across 1 directory with 2 updates
* fix(registry): keep credentials on plain-HTTP fallback with oras-go v2.6.1
* chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1
* chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0
* chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0
* chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0
* ci: bump golangci-lint to v2.11.3 for go 1.26
* chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3
* chore(deps): bump github.com/distribution/distribution/v3
* chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32
* chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0
* chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13
* chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0
* fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026
* chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0
* chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0
* [v3] Bump to version v3.21 (#32103)
* [v3 backport] Fix rollback for missing resources
* fix(action): avoid nil REST client getter panic when installing CRDs
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected helm, helm-bash-completion, helm-fish-completion and / or helm-zsh-completion packages.
Plugin Details
File Name: suse_SU-2026-4417-1.nasl
Agent: unix
Supported Sensors: Continuous Assessment, Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:helm-bash-completion, p-cpe:/a:novell:suse_linux:helm-fish-completion, p-cpe:/a:novell:suse_linux:helm-zsh-completion, p-cpe:/a:novell:suse_linux:helm
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 10/2/2026
Vulnerability Publication Date: 9/16/2026