openSUSE 16: weechat / weechat-devel / weechat-lang / weechat-lua / weechat-perl / etc (openSUSE-SU-2026:21615-1)

high Nessus Plugin ID 339034

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21615-1 advisory.

Changes in weechat:

- Update to 4.10.0:

Added
* core: add command /theme (#1338)
* core: add built-in light theme, applied automatically on first start on light-background terminals (#1338)
* core: add themable flag on configuration options (#1338)
* core: add options weechat.look.theme and weechat.look.theme_backup (#1338)
* api: add function theme_register (#1338)
* fset: add filter t:themable (#1338)
* relay/api: add resource GET /api/scripts
* relay: add option relay.network.unix_socket_permissions (#2317)
* script: add info script_languages

Changed
* core: improve speed of /upgrade with a lot of buffers and lines (#2338, #2339, #2341)
* core: improve speed of display of long words in chat area (#2336)
* core: add condition on connected relay api clients in default value of option weechat.look.hotlist_add_conditions
* core: add /mute in default command for key Alt+= (toggle filters)
* api: change type of parameter pos_option_name to const char ** in function config_search_with_string
* relay/api: add field last_read_line_id in GET /api/buffers

Fixed
* core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
* core: fix option weechat.look.color_real_white not applied when color is white on 16+ colors terminals (#1742)
* core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
* api: fix infinite loop in function string_replace when the search string is empty
* api: do not free dynamic string on error in function string_dyn_concat
* irc: fix tag in message with list of names when joining a channel
* fset: remove error displayed in core buffer when clicking with the mouse below the last option displayed
* guile, lua, perl, python, ruby, tcl: fix conversion of dates in the API functions
* irc: fix conversion of dates in received messages

Security
* core: fix buffer overflow in display of time in chat area with a custom time format (#2342)
* core: fix integer overflow in size calculation when evaluating ${hide:...} and ${base_encode:...} (#2335)
* core: fix possible buffer overflow in command /color alias (#2330)
* core: fix possible buffer overflow in list of commands displayed by /help (#2330)
* irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
* irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
* irc: limit size of data received from the server to prevent memory exhaustion
* irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message (#2322)
* logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
* relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
* relay: fix authentication bypass with the plain password hash algorithm (GHSA-68ff-gq39-pqjm)
* relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3, CVE-2026-53524)
* relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
* relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
* relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
* relay: fix out-of-bounds read in dump of data (#2324)
* relay/api: fix memory leak in resources handshake, input and completion (GHSA-wmpc-m6g9-fwj8)
* relay: fix read of uncompressed websocket frame (#2331)
* api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
* xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory (#2321)
* xfer: fix out-of-bounds read when receiving empty line in DCC chat (#2323)
* xfer: fix out-of-bounds write in xfer file transfer resume (#2326)

- Update to 4.9.5:
* core: fix buffer overflow in display of time in chat area with a custom time format (#2342)
* irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
* irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
* relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
* relay: increase max size for decompressed websocket frame

- Update to 4.9.4:

Changed
* core: improve speed of display of long words in chat area (#2336)

Fixed
* core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
* core: fix integer overflow in size calculation when evaluating ${hide:...} and ${base_encode:...} (#2335)
* logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
* relay: fix authentication bypass with the plain password hash algorithm (GHSA-68ff-gq39-pqjm)

- Update to 4.9.3:
* core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
* core: fix possible buffer overflow in command /color alias (#2330)
* core: fix possible buffer overflow in list of commands displayed by /help (#2330)
* api: do not free dynamic string on error in function string_dyn_concat
* relay/api: fix memory leak in resources handshake, input and completion (GHSA-wmpc-m6g9-fwj8)
* relay: fix read of uncompressed websocket frame (#2331)
* xfer: fix out-of-bounds write in xfer file transfer resume (#2326)

- Update to 4.9.2:
* api: fix infinite loop in function string_replace when the search string is empty
* irc: limit size of data received from the server to prevent memory exhaustion
* irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message (#2322)
* relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
* relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
* relay: fix out-of-bounds read in dump of data (#2324)
* xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory (#2321)
* xfer: fix out-of-bounds read when receiving empty line in DCC chat (#2323)

- Update to 4.9.1:
* core: fix option weechat.look.color_real_white not applied when color is white on 16+ colors terminals (#1742)
* irc: fix tag in message with list of names when joining a channel
* relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3)
* relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc)
* api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc)

- Update to 4.9.0:

Added
* typing: add option typing.look.item_text (#2305)

Fixed
* core: fix crash with /eval when the current buffer is closed in a command
* core: fix buffer size in function util_parse_time, causing buffer overflow error in unit tests
* irc: fix display of CTCP query sent multiple times to the same user when capability echo-message is enabled (#2309)
* irc: fix unit of server option anti_flood from seconds to milliseconds in output of /server listfull
* irc: fix creation of irc.msgbuffer option without a server name
* irc: ignore self join if the channel is already joined (#2291)
* relay/api: fix memory leaks in resources ping and sync
* relay/api: fix memory leak in receive of message from remote WeeChat

- Update to 4.8.2:
* irc: ignore self join if the channel is already joined (#2291)
* relay/api: fix memory leaks in resources ping and sync
* relay/api: fix memory leak in receive of message from remote WeeChat

- Update to 4.8.1:
* core: fix buffer size in function util_parse_time, causing buffer overflow error in unit tests
* irc: fix creation of irc.msgbuffer option without a server name

- Update to 4.8.0:

Removed
* irc: remove temporary servers and option irc.look.temporary_servers

Changed
* api: add support of date like ISO 8601 but with spaces and lower t and z in function util_parse_time (#886)
* irc: request and perform SASL authentication when the server advertises SASL support with message CAP NEW (#2277)
* irc: send SASL username with mechanism EXTERNAL (#2270)
* logger: change default time format to %@%F %T.%fZ (UTC) (#886)
* logger: use function util_parse_time to parse date/time in log files (#886)
* relay/api: return an error 400 (Bad Request) when URL parameters colors, nicks, lines and lines_free have an invalid value
* relay/api: return an error 401 (Unauthorized) when header x-weechat-totp has an invalid value
* xfer: add buffer local variable server in DCC CHAT buffers
* core, irc, relay: add tag tls in gnutls messages
* irc: add tags irc_cap and log3 in client capability request and SASL not supported messages
* build: require Curl 7.68.0 (#2268)
* build: require GnuTLS 3.6.3 (#2268)
* build: require libgcrypt 1.8.0 (#2268)
* build: require Enchant v2 (#2268)
* build: require Lua 5.3 (#2268)

Added
* core: add option weechat.completion.cycle
* core: add hdata for hooks
* api: add functions util_parse_int, util_parse_long and util_parse_longlong
* buflist: add variable ${index_displayed}

Fixed
* core: display an error message in case of invalid parameters in commands /bar, /buffer, /cursor, /print and /window
* api: fix file descriptor leak in hook_url when a timeout occurs or if the hook is removed during the transfer (#2284)
* api: fix parsing of date/times with timezone offset in function util_parse_time
* irc: fix warning on creation of irc.msgbuffer option when the server name contains upper case letters (#2281)
* irc: display a warning for each unknown or invalid server option in commands /connect and /server
* irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and MODE (#2286)
* irc: fix reset of color when multiple modes are set with command /mode
* relay/api: fix crash when an invalid HTTP request is received from a client
* relay/api: return HTTP error 404 instead of 400 when the buffer is not found in resources completion and input
* relay/api: return HTTP error 400 in case of invalid body in resource ping

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://www.suse.com/security/cve/CVE-2026-53524

https://www.suse.com/security/cve/CVE-2026-53525

Plugin Details

Severity: High

ID: 339034

File Name: openSUSE-2026-21615-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/23/2026

Updated: 8/23/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.52

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:C

CVSS Score Source: CVE-2026-53525

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:weechat-devel, p-cpe:/a:novell:opensuse:weechat-lang, p-cpe:/a:novell:opensuse:weechat-lua, p-cpe:/a:novell:opensuse:weechat-perl, p-cpe:/a:novell:opensuse:weechat-python, p-cpe:/a:novell:opensuse:weechat-ruby, p-cpe:/a:novell:opensuse:weechat-spell, p-cpe:/a:novell:opensuse:weechat-tcl, p-cpe:/a:novell:opensuse:weechat

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/20/2026

Vulnerability Publication Date: 8/2/2026

Reference Information

CVE: CVE-2026-53524, CVE-2026-53525