View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0009881 | Kali Linux | Kali Package Bug | public | 2026-10-02 08:43 | 2026-10-02 08:43 |
| Reporter | logopk | Assigned To | |||
| Priority | normal | Severity | minor | Reproducibility | have not tried |
| Status | new | Resolution | open | ||
| Summary | 0009881: OpenVAS 23.45.1-1 with current NVT feed fails to run Notus checks: Invalid URL (null) | ||||
| Description | Package openvas-scanner 23.45.1-1 Distribution: Kali Linux Rolling
Description I am experiencing a problem with Notus-based local security checks when scanning a Debian 13 (Trixie) host using SSH credentials. The Kali packages are fully upgraded according to APT. The installed versions are the current candidates offered by my configured Kali Rolling repository. The target is correctly identified as Debian 13, SSH authentication succeeds, and the target has 717 installed packages according to dpkg-query. However, the scan does not successfully perform the Notus-based Debian package checks. The relevant OpenVAS log messages are: attack_network_init: INIT MQTT: SUCCESS parse_server: Invalid URL (null). It must be in format: nasl_notus: Unable to get the response The last two messages recur during the scan. Current configuration and observations /etc/openvas/openvas.conf contains: The current /var/lib/openvas/plugins/notus.inc uses the direct notus() function when that function is available. In the installed OpenVAS 23.45.1 source, the direct NASL Notus request uses openvasd_server, whereas the installed Kali configuration uses the Python Notus scanner and MQTT. This suggests a possible incompatibility between the current NVT feed and the OpenVAS/Notus components packaged by Kali. I have not established the definitive root cause. Steps to reproduce Install or update GVM using the packages available from Kali Rolling. Expected result OpenVAS should successfully communicate with the configured Notus backend and perform Debian 13 package-based vulnerability checks. Actual result OpenVAS logs Invalid URL (null) and nasl_notus: Unable to get the response. The expected Notus-based Debian package checks do not appear to complete successfully. Request Please investigate whether the current NVT feed is compatible with Kali's packaged OpenVAS 23.45.1-1 and Python Notus 22.7.2-3 stack, and whether a package update, feed compatibility adjustment, or documented configuration change is required. I can provide relevant logs and further diagnostic output if needed. Thank You Peter Error Message from yesterday's log: lib misc:WARNING:2026-10-01 17h30.02 utc:390300:b691f5ad-12c0-4e4a-9e8c-837b1df6cb8d: parse_server: Invalid URL (null). It must be in format: schema://host:port. E.g. http://localhost:8080 Additional diagnostic tests (unsuccessful) The current notus.inc calls the built-in notus() function whenever it is available. In my setup, this results in the Invalid URL (null) error because openvasd is not installed and openvasd_server is not configured. For diagnostic purposes, I temporarily changed the condition to if (FALSE) to bypass the direct notus() call and allow execution to reach the legacy fallback code, including update_table_driven_lsc_data() if available. However, this did not resolve the issue. During a subsequent scan, no relevant MQTT messages appeared when monitoring Mosquitto with mosquitto_sub, and the Notus service showed no corresponding processing activity. The ssh/login/release_notus knowledge-base entry remained FALSE, although the target was correctly identified as Debian 13 (ssh/login/release = DEB13). I restored the original notus.inc after the test. No permanent feed modifications remain. | ||||
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2026-10-02 08:43 | logopk | New Issue |