openSUSE security update: security update for weechat
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21615-1
Rating: important
Cross-References:
* CVE-2026-53524
* CVE-2026-53525
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 2 vulnerabilities can now be installed.
Description:
This update for weechat fixes the following issues:
Changes in weechat:
- Update to 4.10.0:
Added
* core: add command /theme (#1338)
* core: add built-in "light" theme, applied automatically on first
start on light-background terminals (#1338)
* core: add themable flag on configuration options (#1338)
* core: add options weechat.look.theme and
weechat.look.theme_backup (#1338)
* api: add function theme_register (#1338)
* fset: add filter t:themable (#1338)
* relay/api: add resource GET /api/scripts
* relay: add option relay.network.unix_socket_permissions (#2317)
* script: add info "script_languages"
Changed
* core: improve speed of /upgrade with a lot of buffers and lines
(#2338, #2339, #2341)
* core: improve speed of display of long words in chat area (#2336)
* core: add condition on connected relay api clients in default
value of option weechat.look.hotlist_add_conditions
* core: add /mute in default command for key Alt+= (toggle filters)
* api: change type of parameter "pos_option_name" to "const char **"
in function config_search_with_string
* relay/api: add field "last_read_line_id" in GET /api/buffers
Fixed
* core: fix infinite loop when option weechat.look.read_marker_string
is set to a string with a width of zero (#2337)
* core: fix option weechat.look.color_real_white not applied when
color is "white" on 16+ colors terminals (#1742)
* core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
* api: fix infinite loop in function string_replace when the search
string is empty
* api: do not free dynamic string on error in function string_dyn_concat
* irc: fix tag in message with list of names when joining a channel
* fset: remove error displayed in core buffer when clicking with the
mouse below the last option displayed
* guile, lua, perl, python, ruby, tcl: fix conversion of dates in
the API functions
* irc: fix conversion of dates in received messages
Security
* core: fix buffer overflow in display of time in chat area with a
custom time format (#2342)
* core: fix integer overflow in size calculation when evaluating
"${hide:...}" and "${base_encode:...}" (#2335)
* core: fix possible buffer overflow in command /color alias (#2330)
* core: fix possible buffer overflow in list of commands displayed
by /help (#2330)
* irc: fix heap use-after-free when a batched message causes a
disconnection from the server (GHSA-rfmh-3r7f-jpx5)
* irc: fix stack buffer overflow when splitting a JOIN message
with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
* irc: limit size of data received from the server to prevent
memory exhaustion
* irc: fix out-of-bounds read on incoming DCC command with a
quoted filename ending the message (#2322)
* logger: fix path traversal in log file name when a buffer local
variable contains the char used internally to protect directory
separators (#2340)
* relay: fix use-after-free and double free on remote buffer
(GHSA-hx59-4hq9-6vmw)
* relay: fix authentication bypass with the "plain" password hash
algorithm (GHSA-68ff-gq39-pqjm)
* relay: limit size of decompressed websocket frame with
permessage-deflate to prevent memory exhaustion
(GHSA-v2v4-45wm-5cr3, CVE-2026-53524)
* relay: limit size of received websocket frame and HTTP body to
prevent memory exhaustion
* relay: limit size of partial message received while reading an
HTTP request to prevent memory exhaustion
* relay: fix timing attack on password authentication
(GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
* relay: fix out-of-bounds read in dump of data (#2324)
* relay/api: fix memory leak in resources "handshake", "input" and
"completion" (GHSA-wmpc-m6g9-fwj8)
* relay: fix read of uncompressed websocket frame (#2331)
* api, relay: fix timing attack on TOTP validation
(GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
* xfer: replace directory separator in remote nick by underscore
in download filename to prevent writing the file outside the
download directory (#2321)
* xfer: fix out-of-bounds read when receiving empty line in DCC
chat (#2323)
* xfer: fix out-of-bounds write in xfer file transfer resume (#2326)
- Update to 4.9.5:
* core: fix buffer overflow in display of time in chat area with a
custom time format (#2342)
* irc: fix heap use-after-free when a batched message causes a
disconnection from the server (GHSA-rfmh-3r7f-jpx5)
* irc: fix stack buffer overflow when splitting a JOIN message with
a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
* relay: fix use-after-free and double free on remote buffer
(GHSA-hx59-4hq9-6vmw)
* relay: increase max size for decompressed websocket frame
- Update to 4.9.4:
Changed
* core: improve speed of display of long words in chat area (#2336)
Fixed
* core: fix infinite loop when option weechat.look.read_marker_string
is set to a string with a width of zero (#2337)
* core: fix integer overflow in size calculation when evaluating
"${hide:...}" and "${base_encode:...}" (#2335)
* logger: fix path traversal in log file name when a buffer local
variable contains the char used internally to protect directory
separators (#2340)
* relay: fix authentication bypass with the "plain" password hash
algorithm (GHSA-68ff-gq39-pqjm)
- Update to 4.9.3:
* core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
* core: fix possible buffer overflow in command /color alias (#2330)
* core: fix possible buffer overflow in list of commands displayed
by /help (#2330)
* api: do not free dynamic string on error in function string_dyn_concat
* relay/api: fix memory leak in resources "handshake", "input" and
"completion" (GHSA-wmpc-m6g9-fwj8)
* relay: fix read of uncompressed websocket frame (#2331)
* xfer: fix out-of-bounds write in xfer file transfer resume (#2326)
- Update to 4.9.2:
* api: fix infinite loop in function string_replace when the search
string is empty
* irc: limit size of data received from the server to prevent
memory exhaustion
* irc: fix out-of-bounds read on incoming DCC command with a quoted
filename ending the message (#2322)
* relay: limit size of received websocket frame and HTTP body to
prevent memory exhaustion
* relay: limit size of partial message received while reading an
HTTP request to prevent memory exhaustion
* relay: fix out-of-bounds read in dump of data (#2324)
* xfer: replace directory separator in remote nick by underscore in
download filename to prevent writing the file outside the download
directory (#2321)
* xfer: fix out-of-bounds read when receiving empty line in DCC
chat (#2323)
- Update to 4.9.1:
* core: fix option weechat.look.color_real_white not applied when
color is "white" on 16+ colors terminals (#1742)
* irc: fix tag in message with list of names when joining a channel
* relay: limit size of decompressed websocket frame with
permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3)
* relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc)
* api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc)
- Update to 4.9.0:
Added
* typing: add option typing.look.item_text (#2305)
Fixed
* core: fix crash with /eval when the current buffer is closed in a
command
* core: fix buffer size in function util_parse_time, causing buffer
overflow error in unit tests
* irc: fix display of CTCP query sent multiple times to the same
user when capability echo-message is enabled (#2309)
* irc: fix unit of server option anti_flood from seconds to
milliseconds in output of /server listfull
* irc: fix creation of irc.msgbuffer option without a server name
* irc: ignore self join if the channel is already joined (#2291)
* relay/api: fix memory leaks in resources "ping" and "sync"
* relay/api: fix memory leak in receive of message from remote WeeChat
- Update to 4.8.2:
* irc: ignore self join if the channel is already joined (#2291)
* relay/api: fix memory leaks in resources "ping" and "sync"
* relay/api: fix memory leak in receive of message from remote WeeChat
- Update to 4.8.1:
* core: fix buffer size in function util_parse_time, causing buffer
overflow error in unit tests
* irc: fix creation of irc.msgbuffer option without a server name
- Update to 4.8.0:
Removed
* irc: remove temporary servers and option irc.look.temporary_servers
Changed
* api: add support of date like ISO 8601 but with spaces and lower
t and z in function util_parse_time (#886)
* irc: request and perform SASL authentication when the server
advertises SASL support with message "CAP NEW" (#2277)
* irc: send SASL username with mechanism EXTERNAL (#2270)
* logger: change default time format to %@%F %T.%fZ (UTC) (#886)
* logger: use function util_parse_time to parse date/time in log
files (#886)
* relay/api: return an error 400 (Bad Request) when URL parameters
"colors", "nicks", "lines" and "lines_free" have an invalid value
* relay/api: return an error 401 (Unauthorized) when header
"x-weechat-totp" has an invalid value
* xfer: add buffer local variable "server" in DCC CHAT buffers
* core, irc, relay: add tag "tls" in gnutls messages
* irc: add tags "irc_cap" and "log3" in client capability request
and SASL not supported messages
* build: require Curl ≥ 7.68.0 (#2268)
* build: require GnuTLS ≥ 3.6.3 (#2268)
* build: require libgcrypt ≥ 1.8.0 (#2268)
* build: require Enchant v2 (#2268)
* build: require Lua ≥ 5.3 (#2268)
Added
* core: add option weechat.completion.cycle
* core: add hdata for hooks
* api: add functions util_parse_int, util_parse_long and
util_parse_longlong
* buflist: add variable ${index_displayed}
Fixed
* core: display an error message in case of invalid parameters in
commands /bar, /buffer, /cursor, /print and /window
* api: fix file descriptor leak in hook_url when a timeout occurs
or if the hook is removed during the transfer (#2284)
* api: fix parsing of date/times with timezone offset in function
util_parse_time
* irc: fix warning on creation of irc.msgbuffer option when the
server name contains upper case letters (#2281)
* irc: display a warning for each unknown or invalid server option
in commands /connect and /server
* irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and
MODE (#2286)
* irc: fix reset of color when multiple modes are set with
command /mode
* relay/api: fix crash when an invalid HTTP request is received
from a client
* relay/api: return HTTP error 404 instead of 400 when the buffer
is not found in resources completion and input
* relay/api: return HTTP error 400 in case of invalid body in
resource ping
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-516=1
Package List:
- openSUSE Leap 16.0:
weechat-4.10.0-bp160.1.1
weechat-devel-4.10.0-bp160.1.1
weechat-lang-4.10.0-bp160.1.1
weechat-lua-4.10.0-bp160.1.1
weechat-perl-4.10.0-bp160.1.1
weechat-python-4.10.0-bp160.1.1
weechat-ruby-4.10.0-bp160.1.1
weechat-spell-4.10.0-bp160.1.1
weechat-tcl-4.10.0-bp160.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-53524.html
* https://www.suse.com/security/cve/CVE-2026-53525.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.