openSUSE 16 Security Update : broot (openSUSE-SU-2026:21675-1)

low Nessus Plugin ID 341581

Language:

Synopsis

The remote openSUSE host is missing a security update.

Description

The remote openSUSE 16 host has a package installed that is affected by a vulnerability as referenced in the openSUSE- SU-2026:21675-1 advisory.

Changes in broot:

- v1.59.0 (CVE-2026-72847 boo#1275994)
* new shell_command verb attribute: run a command through a shell (sh -c / cmd /C) so &&, ; and pipes work, without leaving broot - Fix #1145
* fix invalid official Mac binary (duplicate linked dylib) with new build chain - Fix #1194
* Sixel graphics support for image preview, auto-detected: works in iterm2, Windows Terminal 1.22+ and Sixel-capable Unix terminals (foot, mlterm, xterm built with Sixel, recent WezTerm). Kitty remains the preferred protocol when available. Note: this requires broot to be compiled with sixel feature (eg cargo install broot --features sixel) - Fix #568
* High-Res images in Rio terminal (detect it to enable the Kitty image protocol) - Fix #1179
* fix iTerm2 3.6.10 and later not displaying Hi-Res images, the version being compared as text
* fix content-exact match line number off-by-one when the match starts at the first byte of a line (broot jumped to the line above)
* new :no_action internal, doing nothing, which can be used to disable a key - Fix #328
* fix: detect a duplicate broot server name instead of silently overtaking the running server - Fix #1065
* fix preview transformers extension matching not working with double extensions such as .tar.gz - Fix #1195
* strip escape sequences from displayed names to prevent OSC injections - Fix #1188
* fall back to numeric uid/gid instead of ???? when the user or group name can't be resolved, which is always the case on statically linked musl builds - Fix #1075
* fix panic on a content regex matching the empty string at the end of a line ending with a control char (eg cr/$/ on a CRLF file)
* fix Windows paths (containing backslashes) being mangled by the launcher's eval when using :cd and similar; also fixes escaping of paths containing a single quote - Fix #1100
* fix br failing on Windows/PowerShell when the temp path contains a space (e.g. a space in the Windows username) - Fix #788
* JPEG XL images are no longer previewed: the decoder had out-of-bounds bugs and the fix needs a more recent rustc (if you need it, tell me and I'll try to make it opt-in)
* rustc minimal version changed from 1.83 to 1.85, and edition 2024

- v1.58.0
* change the way possible verb completions are listed, making it more readable when there are more than what fits the screen
* fix argument of :select and :show being ignored in a --cmd sequence - Fix 1176

- v1.57.0
* help: verb 'keys' and 'description' columns now searchable - Fix #1163
* fix :print_path / :print_relative_path adding a trailing empty line when printing a multi-item staging area - Fix #1062
* Skin: attributes (bold, underlined, etc.) of the selected_line entry now applied - Fix #1156
* if no Wezterm version is found, broot now assumes it's recent enough to support kitty protocol for image - Fix #509

- v1.56.4
* fix compilation on non unix platforms (1.56.3 isn't available on those systems)

- v1.56.3
* fix control characters sometimes remaining in the terminal after broot exit
* nushell: rename br module to avoid conflict in last nushell version - Fix #1138
* :open_stay on the staging area opens every staged file through the system opener - Fix #444

- v1.56.2
* {file-root-relative} argument - Fix #1142
* fix :clear_stage (or other operations closing the stage panel) often closing broot - Fix #1143

- v1.56.1
* fix a typo in a verb in default conf

- v1.56.0
* impacted_panel verb argument, allows the effect of a verb to be on another panel (eg to scroll the preview panel without removing the focus from the tree) - Fix #1119
* focus_panel_left and focus_panel_right internals - Fix #1115
* Major Feature: merge staged files to issue a single command: when a verb argument has a space- separated or comma-separated flag, a single external command is run even when the selection is multiple - Fix #465 The default verbs.json file has an example of a zip verb building an archive from all staged files.

- v1.55.0
* activate Kitty Graphics Protocol to display Hi-Res images in iTerm2
* Tokyo Night skin ( https://github.com/Canop/broot/blob/main/resources/default-conf/skins/tokyo- night.hjson )
* matches related to several name patterns joined with and/or in a composite pattern are merged instead of having just the first one shown
* nushell integration: switch $nu.temp-path to $nu.temp-dir - #1116

- v1.54.0
* fix crash on rendering B&W images with Kitty image protocol
* don't match directories when a composite pattern has a content pattern, even negated (eg /js$/&!c/;:
it's clear the user wants to match js files not containing a semicolon)

- v1.53.0
* fix some cases of the verb not removed from the input on execution (with a risk of accidental double execution)
* add the :filesystems (short :fs) verb and state on windows (it was already present on linux and mac).
* improve the generation of preview pattern from a file tree pattern (i.e. going from /java$/&c/test to /test on opening a matching file in preview). With this change broot avoids filtering the preview when it shouldn't (eg when you searched /java$/|c/test) - See #1097
* display files whose name isn't valid UTF-8 (they were previously ignored)
* android executable is back to the official binary archive

- v1.52.0
* auto_open_staging_area preference - Fix #1090
* search content of file target of symlink - Fix #1081
* fix nushell script (swapped logic for --listen and --listen-auto)
* return non-zero exit code on error

- v1.51.0
* improved image rendering (both speed by using the zune-image library, and quality with bilinear interpolation)
* fix compilation broken by 1.50.0 on Android
* --listen-auto listens for commands on a random linux socket - Fix #1064
* when auto-completing, back-tab cycles in reverse order - Fix #1071

- v1.50.0
* big text files now only partially loaded for initial display, remaining being done in background - Fix #1052
* better support of kitty image protocol over tmux, ssh or unknown terminals, with kitty_graphics_display option and $TMUX_NEST_COUNT env variable - see PR #1034
* trash compilation feature removed: trash related features are built depending on the platform
* build chain revised. Future official releases should include a Mac binary
* fix crash on double unstage of last entry in stage panel - fix #1057
* fallback to transparent background for text preview when the skin specifies nothing

- v1.49.1
* watching made much more efficient (some deep changes won't lead to an automatic refresh which only impacts dir size)
* the name given with `--listen` is now provided to verb as the `{server-name}` verb argument

- v1.49.0
* `:toggle_watch` internal, with `:watch` shortcut, bound by default to `alt-w`. When watching is active, the tree is refreshed whenever any directory/file, even deep, is changed - Fix #730
* fallback to a transparent background for images in image preview instead of a specific color - Fix #1040 - Thanks @letmeiiiin
* fix --server socket written at a non writable location on Android/termux - Fix #1045

- v1.48.0
* Support for the 'Cmd' modifier in key shortcuts (the key is called 'Command', 'Super', 'Apple', 'Windows', depending on systems and users)
* filesystem features have been made available for Mac:
- the `:fs` screen, listing filesystems
- filesystem free space & total space displayed when size computations are requested
- device id displayed with `:toggle_device_id` (shortcut: dev)
* Fix `.config/git/ignore` not being loaded on Mac - Fix #1032 - Thanks @9999years

- v1.47.0
* text files with control chars were previously previewed as binary. They're now displayed as text with some '' when needed - Fix #977
* files with ANSI escape codes (such as the one you would obtain with `dysk --color yes > ansi.txt` can now be previewed with `:preview_tty` - Fix #1019
* first line of the tree is cropped (right aligned) when it doesn't fit

- v1.46.5
* fix `:focus some/path` called in a command sequence always opening new panel - Fix #1014

- v1.46.4
* support for keys F13 to F24 (if your system supports it)
* fix `:focus` with argument given in configuration going up one level when root is selected - Fix #1009
* fix `--max-depth` ignored when in `default_flags` - Fix #1013

- v1.46.3
* fix broot waiting for events on internals like `:quit` - Fix #1006

- v1.46.2
* fix broken nushell script (`--max-depth` again)

- v1.46.1
* fix nushell script broken by new `--max-depth` argument

- v1.46.0
* :set_max_depth <number> and :unset_max_depth
* clear cache when files are deleted in staging area
* recompute preview transform when source file changed since last preview

- v1.45.1
* Fix compilation failing without `--locked`

- v1.45.0
* Fix total search impossible to redo after refresh
* With `refresh_after: false`, a verb configuration can request that the tree isn't refreshed after its execution

- v1.44.7
* fix bad regex match position
* update resvg dependency to 0.44
* on `--server`, remove the existing socket if it already exists

- v1.44.6
* fix .ignore files ignored when not in a git repository
* update git2 dependency to 0.20

- v1.44.5
* no real change (just reverting a crate name to ease some packaging)

- v1.44.4
* fix panic in preview on syntax coloring (when a sublime syntax isn't compatible with the regex engine)

- v1.44.3
* removed default bindings on left and right keys. You may add them back by adding this to your verbs.hjson:
{ key: left, internal: back } { key: right, internal: open_stay }
* rustc minimal version changed from 1.76 to 1.79, which allows better performing image rendering
* remove dependency to onig, to allow compatibility with gcc 15

- v1.44.2
* temp files created for kitty now erased on quitting or when too many of them have been written
* no longer panics when launched with BROOT_LOG=debug but the broot.log file can't be created
* fix user and group names displayed as ???? when coming from openldap

- v1.44.1
* fix wrong position of IMEs (input method editors) popup - See #948
* improve querying the terminal for capabilities (prevent some escape chars from leaking)

- v1.44.0
* `:focus_staging_area_no_open` internal, focus the staging area if it's already open, does nothing in other case
* fix some composite patterns with several operators and no parenthesis

- v1.43.0
* 'Size' and 'Deletion date' columns in trash screen. This screen now supports the `:toggle_date`, `:toggle_size`, `:sort_by_date`, and `:sort_by_size` internals.
* new `:show` internal make the provided path visible and selected, adding lines to the tree if necessary, does nothing if the provided path is not a descendant of the current tree root (this part may change depending on feedback)

- v1.42.0
* support of `.ignore` files with the same syntax than `.gitignore`. They have priority over `.gitignore` so that a personal `.ignore` file can override a shared `.gitignore` - See https://dystroy.org/broot/tree_view/#hidden-ignored-files
* `:toggle_ignore` internal, identical to `:toggle_git_ignore`, but with a clearer name so should be preferred
* the `panels` verb filter now works in most contexts (it was previously only checked on key events)
* many dependencies updated

- v1.41.1
* allow compilation with rustc 1.76

- v1.41.0
* Major Feature: :search_again
- ctrl-s now triggers `:search_again` which either
- brings back the last used search pattern, when no filtering pattern is active
- does a total search if a filtering pattern is active and the search wasn't complete
* Major Feature: internals changing panel widths
- `set_panel_width`, taking as parameter the index of the panel and the desired width
- `move_panel_divider`, taking as parameter the index of the divider and the desired change
- `ctrl-<` is bound by default to `:move_panel_divider 0 -1`
- `ctrl->` is bound by default to `:move_panel_divider 0 1`
- See http://dystroy.org/broot/panels/#resize-panels
* Minor Changes:
- when git file infos are shown, and git ignored files aren't hidden, those files are flagged with a 'I'
- Remove .bak extension from content search exclusion list
- Update nerdfont and vscode icons
- `{initial-root}` verb argument

- v1.40.0
* Major Feature: preview transformers You can now define preview transformers to be applied before preview.
They allow for example previewing PDF or Office files, or beautifying JSON files.
Edit the `preview_transformers` array in your conf.hjson file.
See https://dystroy.org/broot/conf_file/#preview
* fix search on root
* fix some verb cycling problems

- v1.39.2
* fix UNC paths being displayed on Windows (regression at 1.39.1)

- v1.39.1
* fix high-resolution (kitty protocole) image broken in release mode
* canonicalize paths when focusing them (mostly useful when following links)
* a few minor internal optimizations

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected broot package.

See Also

https://bugzilla.suse.com/1275994

https://www.suse.com/security/cve/CVE-2026-72847

Plugin Details

Severity: Low

ID: 341581

File Name: openSUSE-2026-21675-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/30/2026

Updated: 8/30/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.76

CVSS v2

Risk Factor: Low

Base Score: 3.2

Temporal Score: 2.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-72847

CVSS v3

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2.4

Threat Score: 0.4

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:broot

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/28/2026

Vulnerability Publication Date: 8/20/2026

Reference Information

CVE: CVE-2026-72847