SUSE SLES15: helm / helm-bash-completion / helm-fish-completion / etc (SUSE-SU-2026:4417-1)

high Nessus Plugin ID 362806

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4417-1 advisory.

- CVE-2026-85731: oras.land/oras-go/v2: arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (bsc#1281104).
- CVE-2026-85732: oras.land/oras-go/v2: blind SSRF via unvalidated Link header URL in pagination allows internal network probing (bsc#1281112).

Changes for helm:

- Update to version 3.22.0:
* chore(deps): bump the k8s-io group across 1 directory with 6 updates
* bump version to 3.22 (#32606)
* fix: set [pull,push] scope when helm push to a registry(use token auth) (backport) (#32362)
* chore(deps): bump the k8s-io group with 7 updates (#32573)
* chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#32563)
* chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#32554)
* chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#32542)
* [dev-v3 backport] deps: bump google.golang.org/[email protected] for GO-2026-6061 (#32536)
* fix: bump go.opentelemetry.io/[email protected] for GO-2026-5158 (#32535)
* chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6
* fix(provenance): migrate to ProtonMail/go-crypto to resolve GO-2026-5932
* chore(deps): bump the k8s-io group with 7 updates
* chore(deps): bump github/codeql-action/upload-sarif (#32449)
* chore(deps): bump github/codeql-action/analyze from 4.37.1 to 4.37.2
* chore(deps): bump github/codeql-action/autobuild from 4.37.1 to 4.37.2
* chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.2
* chore(deps): bump github/codeql-action/autobuild from 4.37.0 to 4.37.1 (#32381)
* chore(deps): bump github/codeql-action/upload-sarif (#32382)
* ci: auto-label PRs targeting dev-v3 (#32340)
* chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#32331)
* chore(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 (#32332)
* chore(deps): bump github/codeql-action/analyze from 3.26.6 to 4.37.0 (#32357)
* chore(deps): bump github/codeql-action/upload-sarif (#32360)
* chore(deps): bump github/codeql-action/init from 3.26.6 to 4.37.0 (#32359)
* chore(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#32356)
* chore(deps): bump golangci/golangci-lint-action from 6.1.1 to 9.3.0 (#32354)
* chore(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3 (#32353)
* chore(deps): bump golang.org/x/text from 0.38.0 to 0.40.0 (#32310)
* chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#32308)
* chore(deps): bump golang.org/x/term from 0.44.0 to 0.45.0 (#32306)
* fix(engine): prevent Files.Lines panic on empty file
* fix: drop containerd v1 dep to resolve govulncheck CVEs
* chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33
* chore(deps): bump github.com/cyphar/filepath-securejoin
* chore(deps): bump the k8s-io group with 2 updates
* chore(deps): bump the k8s-io group across 1 directory with 2 updates
* fix(registry): keep credentials on plain-HTTP fallback with oras-go v2.6.1
* chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1
* chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0
* chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0
* chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0
* ci: bump golangci-lint to v2.11.3 for go 1.26
* chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3
* chore(deps): bump github.com/distribution/distribution/v3
* chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32
* chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0
* chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13
* chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0
* fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026
* chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0
* chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0
* [v3] Bump to version v3.21 (#32103)
* [v3 backport] Fix rollback for missing resources
* fix(action): avoid nil REST client getter panic when installing CRDs

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected helm, helm-bash-completion, helm-fish-completion and / or helm-zsh-completion packages.

See Also

https://bugzilla.suse.com/1281104

https://bugzilla.suse.com/1281112

https://www.suse.com/security/cve/CVE-2026-85731

https://www.suse.com/security/cve/CVE-2026-85732

http://www.nessus.org/u?ebeac31a

Plugin Details

Severity: High

ID: 362806

File Name: suse_SU-2026-4417-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/3/2026

Updated: 10/3/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.22

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-85731

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:helm-bash-completion, p-cpe:/a:novell:suse_linux:helm-fish-completion, p-cpe:/a:novell:suse_linux:helm-zsh-completion, p-cpe:/a:novell:suse_linux:helm

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/2/2026

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-85731, CVE-2026-85732

SuSE: SUSE-SU-2026:4417-1