openSUSE-SU-2026:21603-1: important: Security update for gitea-tea

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for gitea-tea
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21603-1
Rating: important
References:

  * bsc#1234598
  * bsc#1235367
  * bsc#1239493
  * bsc#1241819
  * bsc#1251471
  * bsc#1251663
  * bsc#1253576



Cross-References:

  * CVE-2024-45337
  * CVE-2024-45338
  * CVE-2025-22869
  * CVE-2025-22872
  * CVE-2025-47911
  * CVE-2025-47913
  * CVE-2025-58190



CVSS scores:

  * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2024-45338 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2024-45338 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
  * CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
  * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 7 vulnerabilities and has 7 bug fixes can now be installed.

Description:

This update for gitea-tea fixes the following issues:

Changes in gitea-tea:

- Update to 0.15.1, bringing in the 0.14.2/0.15.0/0.15.1 upstream
  changes below (bsc#1253576):
  * CVE-2025-47913: golang.org/x/crypto/ssh/agent client process
    termination on an unexpected response to a key listing or
    signing request, fixed by the vendored x/crypto bump to 0.54.0
    (fix floor is 0.43.0 per GO-2025-4116)

- update to 0.15.1:
  * f34697c5ed chore(config): replace authgate SDK with signet (#1081)
  * a613a344de fix(test): disable gpg signing in worktree test repo (#1072)
  * 6435b12202 chore(deps): pin dependencies (#1064)

- update to 0.15.0:
  * fix(context): clarify the fallback login prompt wording in #1061
  * Fix notifications --mine outside git repositories in #1056
  * feat(assignees): add set, add, and remove assignees APIs in #1045
  * fix(deps): update go dependencies in #1057
  * fix(deps): update go dependencies in #1051
  * fix(theme): don't query the terminal at start-up in #1054
  * upgrade go sdk and add test in #1048
  * feat(comments): accept -d/--description for comment body in #1043
  * Add reply to code review in #978
  * fix(http): add transport timeouts so tea fails fast on stalled
    servers in #1020
  * fix(config): write to keychain before config in #1044

- Update to version 0.14.2:
  + fix(labels): add org label for ls and pr
  + fix(oauth): pass resolved redirect_uri to token exchange
  + feat(pulls): show PR URL in detail view
  + feat(comments): add list/edit/delete subcommands to tea comment
  + feat(pulls): add --draft to create and --draft/--ready to edit
  + fix(pulls): restore standard fork-flow PR creation
  + fix(comment): don't block on stdin when body is given positionally
  + docs(login): make the git credential helper discoverable
  + fix(print): distinguish draft PRs from conflicting PRs
  + feat: add wiki CLI commands
  + fix(context): improve local repo detection logic and test


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-packagehub-504=1

Package List:

- openSUSE Leap 16.0:

  gitea-tea-0.15.1-bp160.1.1
  gitea-tea-bash-completion-0.15.1-bp160.1.1
  gitea-tea-zsh-completion-0.15.1-bp160.1.1

References:

  * https://www.suse.com/security/cve/CVE-2024-45337.html
  * https://www.suse.com/security/cve/CVE-2024-45338.html
  * https://www.suse.com/security/cve/CVE-2025-22869.html
  * https://www.suse.com/security/cve/CVE-2025-22872.html
  * https://www.suse.com/security/cve/CVE-2025-47911.html
  * https://www.suse.com/security/cve/CVE-2025-47913.html
  * https://www.suse.com/security/cve/CVE-2025-58190.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.