openSUSE 16 Security Update : kak-lsp (openSUSE-SU-2026:21560-1)

medium Nessus Plugin ID 335077

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has a package installed that is affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21560-1 advisory.

Changes in kak-lsp:

- Update to version 21.0.2:
* Fix a regression that broke compatibility with Kakoune versions older than 2026.05.21
* Add a default configuration for Hare, using hare-lsp
* Fix hangs after editing a file without a trailing newline, such as an empty file
* Use nixd instead of nil as the default language server for nix
* Fix buffer-sync corruption when .editorconfig sets insert_final_newline = false
- Refresh the vendored registry. Recording the state of the open vendored-crate CVEs against it, none of which this package is affected by:
* CVE-2026-25541 (boo#1274502): bytes is 1.12.1, above the 1.11.1 fix
* CVE-2025-3416 (boo#1242654): the openssl crate is 0.10.81, above the 0.10.72 fix; it was already 0.10.80 before this update
* CVE-2025-55159 (boo#1248048): slab is 0.4.12, above the 0.4.11 fix; only 0.4.10 was ever affected and this package never shipped it

- Update to version 20.0.0:
* v20.0.0
* Update changelog
* Fix tinymist documentation URL
* Fix tinymist preview config key. `previewFeature` only works for the vscode plugin
* Encode brackets for file paths
* feat: swift/sourcekit-lsp support
* Paal ?ye-Str?mme Copyright Waiver
* Make sure buffer synchronization works even when finaleol is missing
* workspace/executeCommand: don't panic on invalid args JSON
* servers.kak: update markdown-oxide root markers
* Inline lsp-initial-goto-position
* Fix function_casts_as_integer warning
* lsp-capabilities: remove stale default mappings
* changelog new erlang default server
* fix(ci/commit-new-release.sh): interpolate version number
* Change default language server for erlang
* lsp-inlay-hint-apply-*: fix crash when no hints avail
* Add inlay hint textedit support
* start new cycle

- Update to version 19.0.1:
* v19.0.1
* Don't print Hover: prefix if there are no diagnostics
* Changelog for regression fix
* Fix lsp-find-error incorrectly handling --previous flag
* ci/commit-new-release.sh: support jj
* start new cycle

- Update to version 18.2.0:
* v18.2.0
* Update changelog
* Remove misleading debug log in SessionRenamed hook
* Make *diagnostics* buffer one-line-per diagnostics
* test/gopls-dynamic-settings.sh: fix for recent gopls
* clippy
* controller: consume entire request before checking for user errors
* Add support vuejs
* Fix crash on invalid text edit ranges
* Send initializationOptions and workspace/didChangeConfiguration as expected by jdtls
* cargo update
* Fix type inference errors with deranged 0.4.1
* Fix symbol name prefix for breadcrumbs
* Work around breaking change in deranged crate
* Simplify recursive breadcrumbs calculation
* Language-specific SymbolKind rendering
* lsp-goto-document-symbol: remove symbol kind suffix
* start new cycle

- Update to version 18.1.3:
* v18.1.3
* Use the right language ID when [language.foo] is in effect
* Remove unused line-specs option
* Better variable name for code lens line-specs value
* lsp-object: don't send documentSymbol to servers that don't support it
* Include language server name in stderr logs
* Use rust-analyzer from PATH
* Work around lsp-rename didChange failing when using window scope
* Send texlab-specific requests only to servers that support them
* Fix dart language server command
* Add kak-lsp server PID to the closing log message
* Report more diagnostics information, in multiple lines
* Fix regression causing spurious/missing server name in hover
* Address clippy lints
* Config knob to override magic single-instance setting
* Back out Add curly underline to DiagnosticError face
* start new cycle


- Update to version 18.1.2:
* Silence errors from non-default hooks
* Fix languageId for JSX/TSX files
* Silence deprecation warning
* Add curly underline to DiagnosticError face

- Update to version 18.1.1:
* Make crash reporting optional for now
* Touch up installation instructions in readme
* Make force-exit code paths safer
* Extract function
* Rework Prevent buffer content logic from reading to much
* Don't send debug log about excessive progress reports to editor
* Make test/clangd-invalid-utf8.sh compatible with older clangd
* Fix crash when legacy language config option uses language IDs
* Set LAST_CLIENT earlier
* test/clangd-invalid-utf8.sh: fix for modern clang
* Add biome to CSS and GraphQL
* On crash, disable LSP hooks in current buffer
* Simplify sentry integration
* Work around crash on unsaved files after server restart
* Add context to crash report message
* Include formatted panic info and backtrace in crash report
* Crash reporting via sentry.io
* Make the default panic message a little less intimidating
* Generalize option change hook parsing code
* Back out Fix fake textDocument/didOpen for unsaved files
* Back out Make sure to call textDocument/didOpen when lsp_servers is set after BufCreate
* Prevent buffer content logic from reading to much
* Fix crash on <c-c> during -sync command
* Make sure to call textDocument/didOpen when lsp_servers is set after BufCreate
* Add commented config for tailwindcss-language-server
* Fix fake textDocument/didOpen for unsaved files
* Stop logging the lsp-show-error call
* Fix garbage languageId being sent on lsp-workspace-symbol
* Clean up editor command dispatch code
* Rename command sender type
* Fix corruption applying text edits to non-buffer, non-ASCII files
* Separate out function for applying text edits to in-memory data structure
* Apply clippy lints
* Update unit tests
* Consolidate error reporting
* Work around missing error on missing code lens after server restart
* Type for client name
* Rework editor-command sending
* Remove most uses of EditorMeta::session
* Remove vestiges of multi-session code
* Bravely remove obsolete command_fifo, make response_fifo handling more robust
* Fix flaky test/gopls-goto-definition.sh
* Remove unused function
* Add more details to fifo log
* Remove unused parameter
* Use a separate field for requests pending initialization resp. textDocument/didChange
* Fix hang when sync request is used in hook when LSP is disabled
* Fix lsp-did-change not being sent for lsp-code-actions-sync
* Fix lingering sync state when lsp is disabled
* Remove unused lsp-with-option command
* Stop printing panic backtrace twice
* Add badges for latest release and chat networks
* Fix stacktrace being printed on EPIPE, remove redundant error output
* Call out feedback/support channels a bit more
* Stop linking to the Wiki page for installing servers
* Only set javascriptreact/typescriptreact language ID for jsx/tsx files

- Update to version 18.1.0:
* Fix mixed-up order in tailwindcss example
* Fix bell in modeline not being cleared on ShowMessage notifications
* Fix patttern typo
* Add markdown-oxide language-server
* Add ruby-lsp language-server
* Fix stale quoting in lsp-do-send-sync
* Add log statements for raw request, handle EWOULDBLOCK/EAGAIN
* Use write instead of %val{selection} to send buffer contents
* Use a nonblocking fifo instead of pykak-style alternating fifos
* Address clippy lint
* Extend macOS workarounds to buffer synchronization
* Fail early again on missing language.foo.command field
* Also use elixir-ls on eex files
* Fail startup if session state files already exists
* Don't create session state if session is already running
* Escalate failure if kak-lsp daemon fails to start
* Don't clean up parent of session directories
* Do not briefly start kak-lsp on KakEnd if lsp-enable has never been called
* Fix typo in lsp-exit
* Rectify inconsistent quoting in recommended mappings
* Don't block when language servers are slow to exit
* Work around hang due to lost fifo on macOS
* Restyle --help output
* Fix test/clangd-diagnostic-gutter.sh flakiness
* Fix test/run not finding python on macOS
* Remove bad text edit assertion
* Braces in commented out code must match too
* The correct validation setting for CSS is `css.validate = true`
* Add CSS, HTML and JSON options, add Haskell's static-ls
* Workaround macOS waitid() not zeroing si_signo
* Fix waitid() being called unnecessarily
* Fix formatting spuriously moving cursor with vscode-html-language-server
* Fix Rust version
* Workaround HTML/CSS language servers not enabling formatting
* Workaround HTML/CSS language server crashing due to missing validProperties
* Fix crash interpreting text edit without trailing newline
* Clean up a debug log
* Remove dependency on Rust 1.80
* Fix regression causing crash when language server command fails exec()
* Don't send SIGTERM to language server, remove obsolete wait()
* Simplify sending of initialization options
* Fix regression causing hangs on restart
* Fix regression causing server configuration to be sent as initialization option
* Fix regression causing kak -p to become a zombie
* Remove set-option -add from most commented default configs
* Back out lsp-start to wait until existing server has exited
* Fix race conditions reading kak-lsp PID file
* Send SIGTERM, not SIGKILL to shut down inert language server
* Speed up language server shutdown
* lsp-exit to wait until the session directory is removed
* Remove shell calls from async request sending
* Drain fifo on exit to unblock Kakoune
* Remove unnecssary environment variable
* Refactor temporary directory cleanup logic
* lsp-start to wait until existing server has exited
* Wait for PID file creation after start
* Move fifo into a per-session directory
* Remove errant semicolon
* Remove shell calls for code-actions and highlight-references hooks
* Move hook definition out of the way
* Stop using temporary file also for textDocument/didChange and textDocument/didOpen
* typst: add default configuration
* Mohamad Makki Copyright Waiver
* Update manual installation instructions for ARM macOS

- Update to version 18.0.3:
* Update changelog for release
* Disable CI runs for a special docs branch
* Scala Metals: turn off Unicode icons until Kakoune can handle emoji width
* Simply use stdout instead of fd 3 for request sending
* Remove redundant fifo re-creation
* Elide temporary file when writing to fifo
* Fix escaping if session name starts with a dash
* Move loop-invariant set-option out of the loop
* Fix window/showMessageRequest ID deserialization
* lsp-disable: unset LSP modeline
* Fix eslint workaround
* Fix crash when language key is used in legacy kak-lsp.toml
* julia lsp configuration: move root_globs
* minor: fix typo in julia lsp config
* cargo update
* cargo clippy
* Fix crash in lsp-selection-range
* Show error instead of crashing if lsp_servers root is not an absolute path
* Block LSP requests after KakEnd to work around delay on bad config
* lsp-do-send: also block SIGINT once we have acquired the fifo
* README: update Pre-built binaries section
* Fix state transition when lsp-enable{,-window} are accidentally mixed
* Remove shell call from lsp-if-no-servers
* Remove misleading set-option -add lsp_server from default hooks
* lsp-object: fix crash on invalid param, improve docs

- Update to version 18.0.2:
* v18.0.2
* README: link to troubleshooting section
* Fix stale comment in test
* Update changelog
* Show panics in an info box
* Generate a core dump when crashing via a Rust panic
* lsp-definition: explain fallback in error message
* Fix crash in lsp-highlight-references
* Log kak-lsp daemon PID on startup
* Removed redundant error check

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected kak-lsp package.

See Also

https://bugzilla.suse.com/1242654

https://bugzilla.suse.com/1248048

https://bugzilla.suse.com/1274502

https://www.suse.com/security/cve/CVE-2025-3416

https://www.suse.com/security/cve/CVE-2025-55159

https://www.suse.com/security/cve/CVE-2026-25541

Plugin Details

Severity: Medium

ID: 335077

File Name: openSUSE-2026-21560-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.16

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-25541

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 5.5

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:kak-lsp

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/10/2026

Vulnerability Publication Date: 4/8/2025

Reference Information

CVE: CVE-2025-3416, CVE-2025-55159, CVE-2026-25541