SUSE alert openSUSE-SU-2026:21166-1 (nano)
| From: | null@suse.de | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:21166-1: moderate: Security update for nano | |
| Date: | Tue, 30 Jun 2026 09:48:42 +0200 | |
| Message-ID: | <20260630074842.901FFFF75@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE security update: security update for nano ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21166-1 Rating: moderate References: * bsc#1258260 * bsc#1262643 * bsc#1263022 * bsc#1263437 Cross-References: * CVE-2026-40556 * CVE-2026-6842 * CVE-2026-6843 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for nano fixes the following issues: Changes in nano: - Update to version 9.1: * When searching, the viewport is placed snug left where possible. * The ability to read and write files in old Mac format (a lone carriage return as line ending) was removed. * The ^T toggle between WhereIs and GotoLine was dropped. * Fix backups that were missing or had a wrong timestamp when --backup is active. * On a crash or kill, a .save file is no longer chmodded or chowned to the base file's permissions and owner. * The history code now creates the ~/.local directory with limited access rights (boo#1263437; the referenced CVE-2026-40556 was rejected upstream). * M-Ins and M-Del have become rebindable. - GNU nano 9.0: * When the cursor almost goes offscreen to the right, all lines are now scrolled sideways together, by just the amount needed to keep the cursor in view. Use --solosidescroll or 'set solosidescroll' to get back the old, jerky, single-line horizontal scrolling. * The viewport can be scrolled sideways (in steps of one tabsize) with M-< and M->. See `man nanorc` if M-< and M-> should switch between buffers (as they did earlier). * M-Left, M-Right, M-Up, and M-Down have become rebindable. * Stopping the recording of a macro immediately after starting it cancels the recording and leaves an existing macro in place. * Feature toggles no longer break a chain of ^K cuts or M-6 copies, except the M-K cut-from-cursor toggle. * With --mouse and --indicator, one can click in the scrollbar area to roughly navigate within the buffer. * CVE-2026-6843: format string vulnerability leads to denial of service (boo#1262643) * create the ~/.local directory with limited access rights (CVE-2026-6842 boo#1263022, CVE-2026-40556 boo#1263437) - GNU nano 8.7.1: * fix build against glibc-2.43 (boo#1258260) - GNU nano 8.7: * At the Execute prompt, preceding the command with two pipe symbols allows implementing a copy-to-clipboard feature in nanorc on terminals that support OSC 52. See doc/sample.nanorc Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-361=1 Package List: - openSUSE Leap 16.0: nano-9.1-bp160.1.1 nano-lang-9.1-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-40556.html * https://www.suse.com/security/cve/CVE-2026-6842.html * https://www.suse.com/security/cve/CVE-2026-6843.html
