openSUSE-SU-2026:21615-1: important: Security update for weechat

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for weechat
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21615-1
Rating: important

Cross-References:

  * CVE-2026-53524
  * CVE-2026-53525



Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 2 vulnerabilities can now be installed.

Description:

This update for weechat fixes the following issues:

Changes in weechat:

- Update to 4.10.0:

  Added
  * core: add command /theme (#1338)
  * core: add built-in "light" theme, applied automatically on first
    start on light-background terminals (#1338)
  * core: add themable flag on configuration options (#1338)
  * core: add options weechat.look.theme and
    weechat.look.theme_backup (#1338)
  * api: add function theme_register (#1338)
  * fset: add filter t:themable (#1338)
  * relay/api: add resource GET /api/scripts
  * relay: add option relay.network.unix_socket_permissions (#2317)
  * script: add info "script_languages"

  Changed
  * core: improve speed of /upgrade with a lot of buffers and lines
    (#2338, #2339, #2341)
  * core: improve speed of display of long words in chat area (#2336)
  * core: add condition on connected relay api clients in default
    value of option weechat.look.hotlist_add_conditions
  * core: add /mute in default command for key Alt+= (toggle filters)
  * api: change type of parameter "pos_option_name" to "const char **"
    in function config_search_with_string
  * relay/api: add field "last_read_line_id" in GET /api/buffers

  Fixed
  * core: fix infinite loop when option weechat.look.read_marker_string
    is set to a string with a width of zero (#2337)
  * core: fix option weechat.look.color_real_white not applied when
    color is "white" on 16+ colors terminals (#1742)
  * core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
  * api: fix infinite loop in function string_replace when the search
    string is empty
  * api: do not free dynamic string on error in function string_dyn_concat
  * irc: fix tag in message with list of names when joining a channel
  * fset: remove error displayed in core buffer when clicking with the
    mouse below the last option displayed
  * guile, lua, perl, python, ruby, tcl: fix conversion of dates in
    the API functions
  * irc: fix conversion of dates in received messages

  Security
  * core: fix buffer overflow in display of time in chat area with a
    custom time format (#2342)
  * core: fix integer overflow in size calculation when evaluating
    "${hide:...}" and "${base_encode:...}" (#2335)
  * core: fix possible buffer overflow in command /color alias (#2330)
  * core: fix possible buffer overflow in list of commands displayed
    by /help (#2330)
  * irc: fix heap use-after-free when a batched message causes a
    disconnection from the server (GHSA-rfmh-3r7f-jpx5)
  * irc: fix stack buffer overflow when splitting a JOIN message
    with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
  * irc: limit size of data received from the server to prevent
    memory exhaustion
  * irc: fix out-of-bounds read on incoming DCC command with a
    quoted filename ending the message (#2322)
  * logger: fix path traversal in log file name when a buffer local
    variable contains the char used internally to protect directory
    separators (#2340)
  * relay: fix use-after-free and double free on remote buffer
    (GHSA-hx59-4hq9-6vmw)
  * relay: fix authentication bypass with the "plain" password hash
    algorithm (GHSA-68ff-gq39-pqjm)
  * relay: limit size of decompressed websocket frame with
    permessage-deflate to prevent memory exhaustion
    (GHSA-v2v4-45wm-5cr3, CVE-2026-53524)
  * relay: limit size of received websocket frame and HTTP body to
    prevent memory exhaustion
  * relay: limit size of partial message received while reading an
    HTTP request to prevent memory exhaustion
  * relay: fix timing attack on password authentication
    (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
  * relay: fix out-of-bounds read in dump of data (#2324)
  * relay/api: fix memory leak in resources "handshake", "input" and
    "completion" (GHSA-wmpc-m6g9-fwj8)
  * relay: fix read of uncompressed websocket frame (#2331)
  * api, relay: fix timing attack on TOTP validation
    (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
  * xfer: replace directory separator in remote nick by underscore
    in download filename to prevent writing the file outside the
    download directory (#2321)
  * xfer: fix out-of-bounds read when receiving empty line in DCC
    chat (#2323)
  * xfer: fix out-of-bounds write in xfer file transfer resume (#2326)

- Update to 4.9.5:
  * core: fix buffer overflow in display of time in chat area with a
    custom time format (#2342)
  * irc: fix heap use-after-free when a batched message causes a
    disconnection from the server (GHSA-rfmh-3r7f-jpx5)
  * irc: fix stack buffer overflow when splitting a JOIN message with
    a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
  * relay: fix use-after-free and double free on remote buffer
    (GHSA-hx59-4hq9-6vmw)
  * relay: increase max size for decompressed websocket frame

- Update to 4.9.4:

  Changed
  * core: improve speed of display of long words in chat area (#2336)

  Fixed
  * core: fix infinite loop when option weechat.look.read_marker_string
    is set to a string with a width of zero (#2337)
  * core: fix integer overflow in size calculation when evaluating
    "${hide:...}" and "${base_encode:...}" (#2335)
  * logger: fix path traversal in log file name when a buffer local
    variable contains the char used internally to protect directory
    separators (#2340)
  * relay: fix authentication bypass with the "plain" password hash
    algorithm (GHSA-68ff-gq39-pqjm)

- Update to 4.9.3:
  * core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
  * core: fix possible buffer overflow in command /color alias (#2330)
  * core: fix possible buffer overflow in list of commands displayed
    by /help (#2330)
  * api: do not free dynamic string on error in function string_dyn_concat
  * relay/api: fix memory leak in resources "handshake", "input" and
    "completion" (GHSA-wmpc-m6g9-fwj8)
  * relay: fix read of uncompressed websocket frame (#2331)
  * xfer: fix out-of-bounds write in xfer file transfer resume (#2326)

- Update to 4.9.2:
  * api: fix infinite loop in function string_replace when the search
    string is empty
  * irc: limit size of data received from the server to prevent
    memory exhaustion
  * irc: fix out-of-bounds read on incoming DCC command with a quoted
    filename ending the message (#2322)
  * relay: limit size of received websocket frame and HTTP body to
    prevent memory exhaustion
  * relay: limit size of partial message received while reading an
    HTTP request to prevent memory exhaustion
  * relay: fix out-of-bounds read in dump of data (#2324)
  * xfer: replace directory separator in remote nick by underscore in
    download filename to prevent writing the file outside the download
    directory (#2321)
  * xfer: fix out-of-bounds read when receiving empty line in DCC
    chat (#2323)

-  Update to 4.9.1:
   * core: fix option weechat.look.color_real_white not applied when
     color is "white" on 16+ colors terminals (#1742)
   * irc: fix tag in message with list of names when joining a channel
   * relay: limit size of decompressed websocket frame with
     permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3)
   * relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc)
   * api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc)

- Update to 4.9.0:

  Added
  * typing: add option typing.look.item_text (#2305)

  Fixed
  * core: fix crash with /eval when the current buffer is closed in a
    command
  * core: fix buffer size in function util_parse_time, causing buffer
    overflow error in unit tests
  * irc: fix display of CTCP query sent multiple times to the same
    user when capability echo-message is enabled (#2309)
  * irc: fix unit of server option anti_flood from seconds to
    milliseconds in output of /server listfull
  * irc: fix creation of irc.msgbuffer option without a server name
  * irc: ignore self join if the channel is already joined (#2291)
  * relay/api: fix memory leaks in resources "ping" and "sync"
  * relay/api: fix memory leak in receive of message from remote WeeChat

- Update to 4.8.2:
  * irc: ignore self join if the channel is already joined (#2291)
  * relay/api: fix memory leaks in resources "ping" and "sync"
  * relay/api: fix memory leak in receive of message from remote WeeChat

- Update to 4.8.1:
  * core: fix buffer size in function util_parse_time, causing buffer
    overflow error in unit tests
  * irc: fix creation of irc.msgbuffer option without a server name

- Update to 4.8.0:

  Removed
  * irc: remove temporary servers and option irc.look.temporary_servers

  Changed
  * api: add support of date like ISO 8601 but with spaces and lower
    t and z in function util_parse_time (#886)
  * irc: request and perform SASL authentication when the server
    advertises SASL support with message "CAP NEW" (#2277)
  * irc: send SASL username with mechanism EXTERNAL (#2270)
  * logger: change default time format to %@%F %T.%fZ (UTC) (#886)
  * logger: use function util_parse_time to parse date/time in log
    files (#886)
  * relay/api: return an error 400 (Bad Request) when URL parameters
    "colors", "nicks", "lines" and "lines_free" have an invalid value
  * relay/api: return an error 401 (Unauthorized) when header
    "x-weechat-totp" has an invalid value
  * xfer: add buffer local variable "server" in DCC CHAT buffers
  * core, irc, relay: add tag "tls" in gnutls messages
  * irc: add tags "irc_cap" and "log3" in client capability request
    and SASL not supported messages
  * build: require Curl ≥ 7.68.0 (#2268)
  * build: require GnuTLS ≥ 3.6.3 (#2268)
  * build: require libgcrypt ≥ 1.8.0 (#2268)
  * build: require Enchant v2 (#2268)
  * build: require Lua ≥ 5.3 (#2268)

  Added
  * core: add option weechat.completion.cycle
  * core: add hdata for hooks
  * api: add functions util_parse_int, util_parse_long and
    util_parse_longlong
  * buflist: add variable ${index_displayed}

  Fixed
  * core: display an error message in case of invalid parameters in
    commands /bar, /buffer, /cursor, /print and /window
  * api: fix file descriptor leak in hook_url when a timeout occurs
    or if the hook is removed during the transfer (#2284)
  * api: fix parsing of date/times with timezone offset in function
    util_parse_time
  * irc: fix warning on creation of irc.msgbuffer option when the
    server name contains upper case letters (#2281)
  * irc: display a warning for each unknown or invalid server option
    in commands /connect and /server
  * irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and
    MODE (#2286)
  * irc: fix reset of color when multiple modes are set with
    command /mode
  * relay/api: fix crash when an invalid HTTP request is received
    from a client
  * relay/api: return HTTP error 404 instead of 400 when the buffer
    is not found in resources completion and input
  * relay/api: return HTTP error 400 in case of invalid body in
    resource ping


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-packagehub-516=1

Package List:

- openSUSE Leap 16.0:

  weechat-4.10.0-bp160.1.1
  weechat-devel-4.10.0-bp160.1.1
  weechat-lang-4.10.0-bp160.1.1
  weechat-lua-4.10.0-bp160.1.1
  weechat-perl-4.10.0-bp160.1.1
  weechat-python-4.10.0-bp160.1.1
  weechat-ruby-4.10.0-bp160.1.1
  weechat-spell-4.10.0-bp160.1.1
  weechat-tcl-4.10.0-bp160.1.1

References:

  * https://www.suse.com/security/cve/CVE-2026-53524.html
  * https://www.suse.com/security/cve/CVE-2026-53525.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.