openSUSE 16 Security Update : zk (openSUSE-SU-2026:21567-1)

medium Nessus Plugin ID 335082

Synopsis

The remote openSUSE host is missing a security update.

Description

The remote openSUSE 16 host has a package installed that is affected by a vulnerability as referenced in the openSUSE- SU-2026:21567-1 advisory.

Changes in zk:

- Update to version 0.15.6:
* Parse links to notes in frontmatter
* Set filters for lsp completion items from the config
* Set a note's modification time in frontmatter and allow for custom key naming for both creation and modification keys
* Indexing made significantly more performant
* Support filtering by date and time with <date> <time> instead of <date>T<time> only
* Exclude globs now prune matching directories from indexing, improving speed of indexing

- Update to version 0.15.5:
* List, edit and filter for broken links with --broken-links
* Update strftime package, supporting %g and %G formats in the {{format-date}} helper
* Option to append links to selected text, instead of replacing
* Paths with ~ and env variables no longer error when passed to
--notebook-dir and --working-dir
* Guard LSP against unnecessary erroring on missing textDocument/definition capabilities

- Update to version 0.15.4:
* fix jump to definition follows wrong link
* zk config --list <object> (by @andrebauer, 484)
* Ignore commented links for LSP diagnostics. Use an AST to parse files, fixing
* other similar edge cases.
* Links in markdown footnotes now included in :ZkLinks
* Indexing notebook now 35% and 74% faster for full and incremental indexing
* respectively
* Stop crashing lsp server when server received textDocument/completion request with out of range parameters.
* lsp: Provide completion after [[ on lines with multi-byte characters
* Prevent crash in LookForward when the parameters is out of characters number.

- Update to version 0.15.2
* Find notes with missing backlinks using zk list --missing-backlink
* LSP diagnostic for missing backlinks when other notes link to current note without reciprocal links
* Code action to add missing backlinks
* LSP diagnostic for self-referential links
* Release tarballs now output the program version
* Config path can be set with $ZK_CONFIG_DIR
* bump deps: golang.org/x/crypto v0.45.0 fixes CVE-2025-58181

- Update to version 0.15.0
* fixed LSP crashes when editing code fences and/or working in text files with code fences
* new feature to set a group path by name, in that any directory with the same name can share the same group rules, no matter how deep in the notebook. See references below.

- Update to version 0.14.2
* Path in .zk/config.toml for the default note template now accepts UNIX ~/paths
* Find notes without tags with zk list --tagless
* fix: LSP ignores magnet links as links to notes
* fix: Note titles with double quoted words no longer break json output
* fix: Grammar in error output
* fix: Group rules could not be nested

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected zk package.

See Also

https://bugzilla.suse.com/1253784

https://www.suse.com/security/cve/CVE-2025-58181

Plugin Details

Severity: Medium

ID: 335082

File Name: openSUSE-2026-21567-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2025-58181

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:zk

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/11/2026

Vulnerability Publication Date: 11/19/2025

Reference Information

CVE: CVE-2025-58181