openSUSE 16: git-cliff / git-cliff-bash-completion / git-cliff-fish-completion / etc (openSUSE-SU-2026:21584-1)

medium Nessus Plugin ID 335942

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21584-1 advisory.

Changes in git-cliff:

- Update to version 2.13.1:
* Support more configuration file locations
* Add per-commit statistics
* Expose determined bump type in release context
* Add configurable commit processing order
* Add environment variable for offline execution
* Migrate logging to tracing
* Add caching where applicable
- CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (boo#1274523)

- Update to version 2.12.0:
* Add offline flag
* Add --skip-tags cli argument
* Implement commit processing summary
* Bug Fixes
- includes changes from 2.11.0:
* Support failing on unmatched commits
* Add support for azure devops
* Improve repository/directory path resolution
* Add split_regex, replace_regex, find_regex filters
* Bug Fixes
- includes changes from 2.10.1:
* Add 'integrations' feature flag for enabling all integrations
* Bug Fixes
* CVE-2025-55159: lab: incorrect bounds check in get_disjoint_mut function can lead to undefined behavior or potential crash due to out-of-bounds access (boo#1248065)

- Update to version 2.10.0:
* (config) Support using include and exclude paths in the config (#1173) - (7c2f922)
* (parser) Support regex matching on JSON arrays with scalar elements (#1163) - (dc458ea)
* (template) Support adding commit statistics to the changelog (#1151) - (05a50d7)
* (config) [breaking] Use empty header and footer as default (#1161) (#1172) - (3e9311e)
* (config) Check if commit.footers is defined in detailed example (#1170) - (078545f)
* (fixtures) Update expected.md after config change (#1176) - (76d3e81)
* (generation) Ensure skip_tags condition is evaluated first (#1190) - (318be66)
* (repo) Use the correct order while diffing paths (#1188) - (ff6c310)
* (ci) Apply security best practices (#1180) - (a32deca)
* (config) Implement FromStr instead of Config::parse_from_str() (#1185) - (692345e)
* (test) Standardize unit tests for commit module (#1147) - (0446d6a)
* (context) Add example usage for statistics (#1162) - (4f7379a)
* (quickstart) Remove repetitive words (#1200) - (434f9ee)
* (readme) Fix twitter badge (#1164) - (68bd85e)
* (readme) Polish badges (#1159) - (941cc2b)
* (remote) Fix inconsistency in remote integration documentation (#1165) - (deb29dc)
* (website) Add highlights for 2.10.0 (#1225) - (a3fe8c9)
* (website) Add installation instructions for gentoo-linux (#1203) - (07fe6bf)
* (formatting) Use spaces instead of tabs (#1184) - (0027300)
* (fixture) Add test fixture for overriding the conventional scope (#1166) - (cb84a08)
* (build) Bump MSRV to 1.85.1 - (d8279d4)
* (cd) Use macos-15 runner - (c156fc5)
* (cd) Re-enable sccache for maturin - (871c3c9)
* (crate) Remove Rust nightly requirement - (4f3e5af)
* (fixture) Update test-regex-json-array fixture (#1178) - (95f4056)
* (format) Format module imports for readability (#1183) - (6db7d49)
* (git) Add .git-blame-ignore-revs - (5b64131)
* (npm) Bump git-cliff to 2.9.1 (#1156) - (e13b158)
* (website) Update the node version - (566c2a1)
* Check if commit.footers is defined in detailed example (#1170) (078545f)
* (breaking) Use empty header and footer as default (#1161) (#1172) (3e9311e)
* Update expected.md after config change (#1176) (76d3e81)
* Use the correct order while diffing paths (#1188) (ff6c310)
* Ensure skip_tags condition is evaluated first (#1190) (318be66)
* Polish badges (#1159) (941cc2b)
* Fix twitter badge (#1164) (68bd85e)
* Fix inconsistency in remote integration documentation (#1165) (deb29dc)
* Add example usage for statistics (#1162) (4f7379a)
* Remove repetitive words (#1200) (434f9ee)
* Add installation instructions for gentoo-linux (#1203) (07fe6bf)
* Add highlights for 2.10.0 (#1225) (a3fe8c9)
* Support regex matching on JSON arrays with scalar elements (#1163) (dc458ea)
* Support using include and exclude paths in the config (#1173) (7c2f922)
* Support adding commit statistics to the changelog (#1151) (05a50d7)
* Bump git-cliff to 2.9.1 (#1156) (e13b158)
* Re-enable sccache for maturin (871c3c9)
* Update test-regex-json-array fixture (#1178) (95f4056)
* Format module imports for readability (#1183) (6db7d49)
* Use macos-15 runner (c156fc5)
* Update the node version (566c2a1)
* Remove Rust nightly requirement (4f3e5af)
* Bump MSRV to 1.85.1 (d8279d4)
* Add .git-blame-ignore-revs (5b64131)
* Standardize unit tests for commit module (#1147) (0446d6a)
* Resolve mismatched lifetime syntax warnings (#1167) (9970402)
* Implement FromStr instead of Config::parse_from_str() (#1185) (692345e)
* Apply security best practices (#1180) (a32deca)
* Use spaces instead of tabs (#1184) (0027300)
* Add test fixture for overriding the conventional scope (#1166) (cb84a08)

- Update to version 2.9.1:
* CI/CD fixes only

- Update to version 2.9.0:
* chore(release): prepare for v2.9.0
* docs(website): add highlights for 2.9.0 (#1153)
* chore(deps-dev): bump typescript in /website in the patch group (#1139)
* chore(docs): fix some typos (#1149)
* fix(template): correctly serialize JSON for the commit fields (#1145)
* docs(security): extend security policy (#1142)
* chore(deps): bump the minor group in /website with 2 updates (#1116)
* refactor(lint): apply clippy suggestions
* feat(context): add release commit range (#1138)
* fix(submodules): fix submodules handling when using custom range (#1136)
* docs(config): fix typo on commit.links (#1132)
* chore(deps): upgrade dependencies (#1129)
* chore(project): migrate to Rust 2024 edition (#1128)
* feat(changelog): support recursing into submodules (#1082)
* feat(remote): fetch commits from non-default branches using remotes (#1086)
* feat(git): support disabling sorting commits topologically (#804) (#1121)
* refactor(config): initialize config structs with default values (#1090)
* chore(dependabot): make dependency updates less noisy
* chore(dependabot): check dependency updates weekly
* fix(bump): check the next version against tag_pattern regex (#1070)
* feat(config): support configuring with a remote URL (#1083)
* fix(fixtures): evaluate the rc of git-cliff correctly (#1104)
* fix(bump): accept lowercase values for bump_type config (#1101)
* docs(readme): add blog posts from the community (#1102)
* fix(fixtures): use the correct syntax while checking fixture results (#1099)
* docs(website): remove references of tj-actions (#1097)
* feat(config): add `require_conventional` option (#1061)
* docs(release): fix Docker Hub URL
* refactor(lint): use IOError::other (#1074)
* doc(config): update comments for all configuration options (#1057)
* docs(quickstart): clarify git-cliff command (#1051)
* fix(git): handle worktrees while retrieving the path of repository (#1054)
* chore(npm): update yarn.lock
* fix(remote): fix detection of GitLab merge request sha if commits were squashed (#1043)
* fix(deps): make glob dependency mandatory (#1035)

- Update to version 2.8.0:
* cli: Support initializing config with a custom filename
* config: Discover the configuration file when run in a sub directory
* git: Improve the set commit range error
* monorepo: Automatically set include-path for current directory
* remote: Support enabling native TLS
* repo: Allow running from sub directories
* config: Allow environment overwrites when using builtin config
* fixtures: Update the arguments for custom GitLab API fixture test
* monorepo: Do not set include-path if workdir is set
* remote: Fix detection of GitLab merge request sha
* lib: Add changelog modifier callback to run function
* lint: Use a shared lint config for the workspace
* lint: Apply clippy suggestions
* docker: Fix typo in comment
* highlights: Add link to the Nix flake
* jujutsu: Update links to the upstream documentation
* lib: Allow doc lint
* license: Update copyright years
* tips: Extend the merge commit filter example
* website: Add highlights for 2.8.0
* fixture: Add fixture for include-path
* build: Bump MSRV to 1.83.0
* lint: Allow false positive lint

- Update to version 2.7.0:
* refactor(clippy): apply clippy suggestions
* chore(deps): bump dependencies
* chore(integration): remove experimental feature disclaimer
* feat(config): allow overriding the remote API URL via config
* docs(git): improve docs for commit_preprocessors and commit_parsers
* feat(jujutsu): add jujustu support
* perf(test): don't create regex inside a loop
* chore(log): add trace log about which command is being run
* fix(remote): preserve first time contributors
* test(git): find upstream remote when using ssh
* docs(readme): add blog post about git-cliff
* chore(config): add the 'other' parser to the default config
* fix(changelog): fix missing commit fields in context
* refactor(clippy): apply clippy suggestions
* test(repo): expand unit tests of the repo module
* fix(changelog): include the root commit when `--latest` is used with one tag
* chore(deps): bump clap from 4.5.18 to 4.5.19
* feat(args): add color to the help text
* chore(release): prepare for v2.6.1
* refactor(clippy): apply doc_markdown and ignored_unit_patterns lint
* chore(fixtures): build binaries using dev profile
* refactor(clippy): apply if_not_else lint
* fix(remote): avoid setting multiple remotes
* chore(deps): bump thiserror from 1.0.63 to 1.0.64
* refactor(clippy): apply assigning_clones lint
* refactor(clippy): apply single_match_else lint
* refactor(clippy): apply needless_pass_by_value lint
* chore(release): prepare for v2.6.0
* feat(config): add changelog.render_always option
* chore(deps): bump dependencies
* fix(changelog): do not change the tag date if tag already exists
* feat(config): allow configuring output file from config
* docs(args): fix copy-paste mistake where gitea mentioned gitlab
* fix(commit): trim the trailing newline for git2 commits
* fix(bump): suppress template warning when `--bumped-version` is used
* refactor(clippy): apply explicit_iter_loop lint
* refactor(clippy): apply manual_is_variant_and lint
* chore(deps): bump clap_complete from 4.5.23 to 4.5.28
* chore(deps-dev): bump typescript from 5.5.4 to 5.6.2 in /website in the minor group
* chore(deps): bump pretty_assertions from 1.4.0 to 1.4.1
* fix(changelog): correctly set the tag message for the latest release
* refactor(clippy): apply case_sensitive_file_extension_comparisons lint
* refactor(clippy): apply clippy suggestions
* refactor(clippy): apply option_as_ref_cloned lint
* refactor(template)!: add name parameter to the constructor
* fix(core): avoid the unnecessary loop when no remote feature is activated
* feat(core): add `remote` to commit and deprecate fields
* refactor(clippy): apply semicolon_if_nothing_returned clippy lint
* refactor(clippy): apply unnested_or_patterns clippy lint
* docs(contributing): mention fetching the tags for running tests successfully
* fix(args): support using use_branch_tags from both config and args
* feat(changelog): support generating changelog for different branches
* chore(examples): improve example templates
* chore(lib): fix typos in code comments
* chore(deps): bump prism-react-renderer from 2.3.1 to 2.4.0 in /website in the minor group
* fix(template): resolve parsing issues with `raw`/`endraw` in Jinja
* fix(changelog): don't change the context when provided via `--from-context`

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected git-cliff, git-cliff-bash-completion, git-cliff-fish-completion and / or git-cliff-zsh-completion packages.

See Also

https://bugzilla.suse.com/1248065

https://bugzilla.suse.com/1274523

https://www.suse.com/security/cve/CVE-2025-55159

https://www.suse.com/security/cve/CVE-2026-25541

Plugin Details

Severity: Medium

ID: 335942

File Name: openSUSE-2026-21584-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/17/2026

Updated: 8/17/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.75

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-25541

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 5.5

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:git-cliff-bash-completion, p-cpe:/a:novell:opensuse:git-cliff-fish-completion, p-cpe:/a:novell:opensuse:git-cliff-zsh-completion, p-cpe:/a:novell:opensuse:git-cliff

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/14/2026

Vulnerability Publication Date: 8/11/2025

Reference Information

CVE: CVE-2025-55159, CVE-2026-25541