openSUSE 16: libwireshark18 / libwiretap15 / libwsutil16 / wireshark / etc (openSUSE-SU-2026:22014-1)

critical Nessus Plugin ID 362892

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:22014-1 advisory.

Update to Wireshark 4.4.18:

- CVE-2026-19694: TTX Logger file parser crash (bsc#1275279).
- CVE-2026-19695: Gammu DCT3 trace file parser crash (bsc#1275280).
- CVE-2026-19696: Ixia IxVeriWave and Vector Informatik BLF file parser crashes on Windows (bsc#1275281).
- CVE-2026-76879: C12.22 protocol dissector crash (bsc#1275828).
- CVE-2026-76880: RRC protocol dissector crash (bsc#1275829).
- CVE-2026-76881: CMS protocol dissector crash (bsc#1275831).
- CVE-2026-76882: Bluetooth Attribute Protocol dissector crash (bsc#1275832).
- CVE-2026-76883: Catapult DCT2000 file parser crash (bsc#1275833).
- CVE-2026-76884: ERF file parser crash (bsc#1275834).
- CVE-2026-76885: Tektronix K12xx file parser crash (bsc#1275835).
- CVE-2026-76886: C12.22 protocol dissector crash (bsc#1275836).
- CVE-2026-76887: Dissection engine reassembly crash (bsc#1275838).
- CVE-2026-76888: RDP protocol dissector crash (bsc#1275839).
- CVE-2026-76889: UMTS FP protocol dissector crash (bsc#1275840).
- CVE-2026-76890: Sharkd utility crash (bsc#1275841).
- CVE-2026-76891: Sharkd utility crash (bsc#1275844).
- CVE-2026-76917: Bluetooth AVRCP Profile (bsc#1275842).
- CVE-2026-76918: SSH protocol dissector crash (bsc#1275843).
- CVE-2026-76919: ESS protocol dissector crash (bsc#1275845).
- CVE-2026-76920: 3gpp phone log file parser crash (bsc#1275846).
- CVE-2026-76921: CMS protocol dissector crash (bsc#1275847).
- CVE-2026-76922: Bluetooth BR/EDR FHS protocol dissector crash (bsc#1275848).
- CVE-2026-76923: Bluetooth HFP Profile protocol dissector crash (bsc#1275849).
- CVE-2026-76924: Kerberos protocol dissector crash (bsc#1275850).
- CVE-2026-76926: BUSMASTER file parser abnormal exit (bsc#1275851).
- CVE-2026-76927: H.245 protocol dissector crash (bsc#1275852).
- CVE-2026-76928: X.509IF protocol dissector crash (bsc#1275853).
- CVE-2026-76929: Pcapng file parser crash (bsc#1275854).

Many more features, bug fixes and updated protocol support as listed in:
https://www.wireshark.org/docs/relnotes/wireshark-4.4.18.html

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1275279

https://bugzilla.suse.com/1275280

https://bugzilla.suse.com/1275281

https://bugzilla.suse.com/1275828

https://bugzilla.suse.com/1275829

https://bugzilla.suse.com/1275831

https://bugzilla.suse.com/1275832

https://bugzilla.suse.com/1275833

https://bugzilla.suse.com/1275834

https://bugzilla.suse.com/1275835

https://bugzilla.suse.com/1275836

https://bugzilla.suse.com/1275838

https://bugzilla.suse.com/1275839

https://bugzilla.suse.com/1275840

https://bugzilla.suse.com/1275841

https://bugzilla.suse.com/1275842

https://bugzilla.suse.com/1275843

https://bugzilla.suse.com/1275844

https://bugzilla.suse.com/1275845

https://bugzilla.suse.com/1275846

https://bugzilla.suse.com/1275847

https://bugzilla.suse.com/1275848

https://bugzilla.suse.com/1275849

https://bugzilla.suse.com/1275850

https://bugzilla.suse.com/1275851

https://bugzilla.suse.com/1275852

https://bugzilla.suse.com/1275853

https://bugzilla.suse.com/1275854

https://www.suse.com/security/cve/CVE-2026-19694

https://www.suse.com/security/cve/CVE-2026-19695

https://www.suse.com/security/cve/CVE-2026-19696

https://www.suse.com/security/cve/CVE-2026-76879

https://www.suse.com/security/cve/CVE-2026-76880

https://www.suse.com/security/cve/CVE-2026-76881

https://www.suse.com/security/cve/CVE-2026-76882

https://www.suse.com/security/cve/CVE-2026-76883

https://www.suse.com/security/cve/CVE-2026-76884

https://www.suse.com/security/cve/CVE-2026-76885

https://www.suse.com/security/cve/CVE-2026-76886

https://www.suse.com/security/cve/CVE-2026-76887

https://www.suse.com/security/cve/CVE-2026-76888

https://www.suse.com/security/cve/CVE-2026-76889

https://www.suse.com/security/cve/CVE-2026-76890

https://www.suse.com/security/cve/CVE-2026-76891

https://www.suse.com/security/cve/CVE-2026-76917

https://www.suse.com/security/cve/CVE-2026-76918

https://www.suse.com/security/cve/CVE-2026-76919

https://www.suse.com/security/cve/CVE-2026-76920

https://www.suse.com/security/cve/CVE-2026-76921

https://www.suse.com/security/cve/CVE-2026-76922

https://www.suse.com/security/cve/CVE-2026-76923

https://www.suse.com/security/cve/CVE-2026-76924

https://www.suse.com/security/cve/CVE-2026-76926

https://www.suse.com/security/cve/CVE-2026-76927

https://www.suse.com/security/cve/CVE-2026-76928

https://www.suse.com/security/cve/CVE-2026-76929

Plugin Details

Severity: Critical

ID: 362892

File Name: openSUSE-2026-22014-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/4/2026

Updated: 10/4/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.21

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-76929

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2026-76886

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:libwireshark18, p-cpe:/a:novell:opensuse:libwiretap15, p-cpe:/a:novell:opensuse:libwsutil16, p-cpe:/a:novell:opensuse:wireshark-devel, p-cpe:/a:novell:opensuse:wireshark-ui-qt, p-cpe:/a:novell:opensuse:wireshark

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/2/2026

Vulnerability Publication Date: 10/8/2024

Reference Information

CVE: CVE-2026-19694, CVE-2026-19695, CVE-2026-19696, CVE-2026-76879, CVE-2026-76880, CVE-2026-76881, CVE-2026-76882, CVE-2026-76883, CVE-2026-76884, CVE-2026-76885, CVE-2026-76886, CVE-2026-76887, CVE-2026-76888, CVE-2026-76889, CVE-2026-76890, CVE-2026-76891, CVE-2026-76917, CVE-2026-76918, CVE-2026-76919, CVE-2026-76920, CVE-2026-76921, CVE-2026-76922, CVE-2026-76923, CVE-2026-76924, CVE-2026-76926, CVE-2026-76927, CVE-2026-76928, CVE-2026-76929

IAVB: 2026-B-0239-S