Описание
Security update for weechat
This update for weechat fixes the following issues:
Changes in weechat:
-
Update to 4.10.0:
Added
- core: add command /theme (#1338)
- core: add built-in "light" theme, applied automatically on first start on light-background terminals (#1338)
- core: add themable flag on configuration options (#1338)
- core: add options weechat.look.theme and weechat.look.theme_backup (#1338)
- api: add function theme_register (#1338)
- fset: add filter t:themable (#1338)
- relay/api: add resource GET /api/scripts
- relay: add option relay.network.unix_socket_permissions (#2317)
- script: add info "script_languages"
Changed
- core: improve speed of /upgrade with a lot of buffers and lines (#2338, #2339, #2341)
- core: improve speed of display of long words in chat area (#2336)
- core: add condition on connected relay api clients in default value of option weechat.look.hotlist_add_conditions
- core: add /mute in default command for key Alt+= (toggle filters)
- api: change type of parameter "pos_option_name" to "const char **" in function config_search_with_string
- relay/api: add field "last_read_line_id" in GET /api/buffers
Fixed
- core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
- core: fix option weechat.look.color_real_white not applied when color is "white" on 16+ colors terminals (#1742)
- core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
- api: fix infinite loop in function string_replace when the search string is empty
- api: do not free dynamic string on error in function string_dyn_concat
- irc: fix tag in message with list of names when joining a channel
- fset: remove error displayed in core buffer when clicking with the mouse below the last option displayed
- guile, lua, perl, python, ruby, tcl: fix conversion of dates in the API functions
- irc: fix conversion of dates in received messages
Security
- core: fix buffer overflow in display of time in chat area with a custom time format (#2342)
- core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}" (#2335)
- core: fix possible buffer overflow in command /color alias (#2330)
- core: fix possible buffer overflow in list of commands displayed by /help (#2330)
- irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
- irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
- irc: limit size of data received from the server to prevent memory exhaustion
- irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message (#2322)
- logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
- relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
- relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)
- relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3, CVE-2026-53524)
- relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
- relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
- relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
- relay: fix out-of-bounds read in dump of data (#2324)
- relay/api: fix memory leak in resources "handshake", "input" and "completion" (GHSA-wmpc-m6g9-fwj8)
- relay: fix read of uncompressed websocket frame (#2331)
- api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc, CVE-2026-53525)
- xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory (#2321)
- xfer: fix out-of-bounds read when receiving empty line in DCC chat (#2323)
- xfer: fix out-of-bounds write in xfer file transfer resume (#2326)
-
Update to 4.9.5:
- core: fix buffer overflow in display of time in chat area with a custom time format (#2342)
- irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
- irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
- relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
- relay: increase max size for decompressed websocket frame
-
Update to 4.9.4:
Changed
- core: improve speed of display of long words in chat area (#2336)
Fixed
- core: fix infinite loop when option weechat.look.read_marker_string is set to a string with a width of zero (#2337)
- core: fix integer overflow in size calculation when evaluating "${hide:...}" and "${base_encode:...}" (#2335)
- logger: fix path traversal in log file name when a buffer local variable contains the char used internally to protect directory separators (#2340)
- relay: fix authentication bypass with the "plain" password hash algorithm (GHSA-68ff-gq39-pqjm)
-
Update to 4.9.3:
- core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
- core: fix possible buffer overflow in command /color alias (#2330)
- core: fix possible buffer overflow in list of commands displayed by /help (#2330)
- api: do not free dynamic string on error in function string_dyn_concat
- relay/api: fix memory leak in resources "handshake", "input" and "completion" (GHSA-wmpc-m6g9-fwj8)
- relay: fix read of uncompressed websocket frame (#2331)
- xfer: fix out-of-bounds write in xfer file transfer resume (#2326)
-
Update to 4.9.2:
- api: fix infinite loop in function string_replace when the search string is empty
- irc: limit size of data received from the server to prevent memory exhaustion
- irc: fix out-of-bounds read on incoming DCC command with a quoted filename ending the message (#2322)
- relay: limit size of received websocket frame and HTTP body to prevent memory exhaustion
- relay: limit size of partial message received while reading an HTTP request to prevent memory exhaustion
- relay: fix out-of-bounds read in dump of data (#2324)
- xfer: replace directory separator in remote nick by underscore in download filename to prevent writing the file outside the download directory (#2321)
- xfer: fix out-of-bounds read when receiving empty line in DCC chat (#2323)
-
Update to 4.9.1:
- core: fix option weechat.look.color_real_white not applied when color is "white" on 16+ colors terminals (#1742)
- irc: fix tag in message with list of names when joining a channel
- relay: limit size of decompressed websocket frame with permessage-deflate to prevent memory exhaustion (GHSA-v2v4-45wm-5cr3)
- relay: fix timing attack on password authentication (GHSA-vhv8-g2r9-cwcc)
- api, relay: fix timing attack on TOTP validation (GHSA-vhv8-g2r9-cwcc)
-
Update to 4.9.0:
Added
- typing: add option typing.look.item_text (#2305)
Fixed
- core: fix crash with /eval when the current buffer is closed in a command
- core: fix buffer size in function util_parse_time, causing buffer overflow error in unit tests
- irc: fix display of CTCP query sent multiple times to the same user when capability echo-message is enabled (#2309)
- irc: fix unit of server option anti_flood from seconds to milliseconds in output of /server listfull
- irc: fix creation of irc.msgbuffer option without a server name
- irc: ignore self join if the channel is already joined (#2291)
- relay/api: fix memory leaks in resources "ping" and "sync"
- relay/api: fix memory leak in receive of message from remote WeeChat
-
Update to 4.8.2:
- irc: ignore self join if the channel is already joined (#2291)
- relay/api: fix memory leaks in resources "ping" and "sync"
- relay/api: fix memory leak in receive of message from remote WeeChat
-
Update to 4.8.1:
- core: fix buffer size in function util_parse_time, causing buffer overflow error in unit tests
- irc: fix creation of irc.msgbuffer option without a server name
-
Update to 4.8.0:
Removed
- irc: remove temporary servers and option irc.look.temporary_servers
Changed
- api: add support of date like ISO 8601 but with spaces and lower t and z in function util_parse_time (#886)
- irc: request and perform SASL authentication when the server advertises SASL support with message "CAP NEW" (#2277)
- irc: send SASL username with mechanism EXTERNAL (#2270)
- logger: change default time format to %@%F %T.%fZ (UTC) (#886)
- logger: use function util_parse_time to parse date/time in log files (#886)
- relay/api: return an error 400 (Bad Request) when URL parameters "colors", "nicks", "lines" and "lines_free" have an invalid value
- relay/api: return an error 401 (Unauthorized) when header "x-weechat-totp" has an invalid value
- xfer: add buffer local variable "server" in DCC CHAT buffers
- core, irc, relay: add tag "tls" in gnutls messages
- irc: add tags "irc_cap" and "log3" in client capability request and SASL not supported messages
- build: require Curl ≥ 7.68.0 (#2268)
- build: require GnuTLS ≥ 3.6.3 (#2268)
- build: require libgcrypt ≥ 1.8.0 (#2268)
- build: require Enchant v2 (#2268)
- build: require Lua ≥ 5.3 (#2268)
Added
- core: add option weechat.completion.cycle
- core: add hdata for hooks
- api: add functions util_parse_int, util_parse_long and util_parse_longlong
- buflist: add variable ${index_displayed}
Fixed
- core: display an error message in case of invalid parameters in commands /bar, /buffer, /cursor, /print and /window
- api: fix file descriptor leak in hook_url when a timeout occurs or if the hook is removed during the transfer (#2284)
- api: fix parsing of date/times with timezone offset in function util_parse_time
- irc: fix warning on creation of irc.msgbuffer option when the server name contains upper case letters (#2281)
- irc: display a warning for each unknown or invalid server option in commands /connect and /server
- irc: fix colors in messages 367 (ban mask), 728 (quiet mask) and MODE (#2286)
- irc: fix reset of color when multiple modes are set with command /mode
- relay/api: fix crash when an invalid HTTP request is received from a client
- relay/api: return HTTP error 404 instead of 400 when the buffer is not found in resources completion and input
- relay/api: return HTTP error 400 in case of invalid body in resource ping
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE CVE CVE-2026-53524 page
- SUSE CVE CVE-2026-53525 page
Описание
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a small compressed WebSocket frame (~100 bytes) that decompresses to gigabytes, exhausting all server memory and crashing the entire WeeChat process. The api protocol enables permessage-deflate and requires authentication before WebSocket upgrade. Version 4.9.1 patches the issue.
Затронутые продукты
Ссылки
- CVE-2026-53524
Описание
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
Затронутые продукты
Ссылки
- CVE-2026-53525