Security update for tree-sitter
| Announcement ID: | SUSE-SU-2026:21789-1 |
|---|---|
| Release Date: | 2026-05-14T08:13:06Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves 10 vulnerabilities and has two fixes can now be installed.
Description:
This update for tree-sitter fixes the following issues
Security issues:
- CVE-2026-34941: wasmtime: crafted input string can lead to an out-of-bound read (bsc#1261871).
- CVE-2026-34942: wasmtime: unaligned pointers can lead to a denial of service (bsc#1261894).
- CVE-2026-34943: wasmtime: lifting
flagscomponent value can lead to a denial of service (bsc#1261954). - CVE-2026-34944: wasmtime: out-of-bounds read during WebAssembly compilation can lead to a denial of service (bsc#1261963).
- CVE-2026-34945: wasmtime: incorrectly translated table.size could lead to disclosing data (bsc#1262007).
- CVE-2026-34946: wasmtime: denial of service due to WebAssembly compilation error (bsc#1261974).
- CVE-2026-34987: wasmtime: winch compiler backend may allow a sandbox-escaping memory access (bsc#1262032).
- CVE-2026-34988: wasmtime: pooling allocator instances can cause data leakage (bsc#1261968).
- CVE-2026-35186: wasmtime: translating the table.grow operator can cause a masked return value (bsc#1262036).
- CVE-2026-35195: wasmtime: transcoding strings can lead to an out of bound write or a crash (bsc#1262040).
Changes for tree-sitter:
-
update to 0.26.8:
-
fix(generate): allow disabling qjs-rt feature from CLI by @WillLillis in #5448
- fix(lib): document invariants that must be upheld for TSInputEdit by @WillLillis in #5452
- fix(cli): correct typo in parse command's help text by @WillLillis in #5465
- perf(cli): misc. improvements by @tree-sitter-ci-bot[bot] in #5476
- Fix wasm loading of languages w/ multiple reserved word sets by @tree-sitter-ci-bot[bot] in #5477
- generate: avoid panicking when a supertype only has hidden external token children by @tree-sitter-ci-bot[bot] in #5478
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-743=1 -
SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-743=1
Package List:
-
SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
- tree-sitter-debuginfo-0.26.8-160000.1.1
- libtree-sitter0_26-debuginfo-0.26.8-160000.1.1
- tree-sitter-devel-0.26.8-160000.1.1
- libtree-sitter0_26-0.26.8-160000.1.1
- tree-sitter-debugsource-0.26.8-160000.1.1
-
SUSE Linux Enterprise Server 16.0 (x86_64)
- libtree-sitter0_26-x86-64-v3-0.26.8-160000.1.1
- libtree-sitter0_26-x86-64-v3-debuginfo-0.26.8-160000.1.1
-
SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
- tree-sitter-debuginfo-0.26.8-160000.1.1
- libtree-sitter0_26-debuginfo-0.26.8-160000.1.1
- tree-sitter-devel-0.26.8-160000.1.1
- libtree-sitter0_26-0.26.8-160000.1.1
- tree-sitter-debugsource-0.26.8-160000.1.1
-
SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64)
- libtree-sitter0_26-x86-64-v3-0.26.8-160000.1.1
- libtree-sitter0_26-x86-64-v3-debuginfo-0.26.8-160000.1.1
References:
- https://www.suse.com/security/cve/CVE-2026-34941.html
- https://www.suse.com/security/cve/CVE-2026-34942.html
- https://www.suse.com/security/cve/CVE-2026-34943.html
- https://www.suse.com/security/cve/CVE-2026-34944.html
- https://www.suse.com/security/cve/CVE-2026-34945.html
- https://www.suse.com/security/cve/CVE-2026-34946.html
- https://www.suse.com/security/cve/CVE-2026-34987.html
- https://www.suse.com/security/cve/CVE-2026-34988.html
- https://www.suse.com/security/cve/CVE-2026-35186.html
- https://www.suse.com/security/cve/CVE-2026-35195.html
- https://bugzilla.suse.com/show_bug.cgi?id=1259205
- https://bugzilla.suse.com/show_bug.cgi?id=1261839
- https://bugzilla.suse.com/show_bug.cgi?id=1261871
- https://bugzilla.suse.com/show_bug.cgi?id=1261894
- https://bugzilla.suse.com/show_bug.cgi?id=1261954
- https://bugzilla.suse.com/show_bug.cgi?id=1261963
- https://bugzilla.suse.com/show_bug.cgi?id=1261968
- https://bugzilla.suse.com/show_bug.cgi?id=1261974
- https://bugzilla.suse.com/show_bug.cgi?id=1262007
- https://bugzilla.suse.com/show_bug.cgi?id=1262032
- https://bugzilla.suse.com/show_bug.cgi?id=1262036
- https://bugzilla.suse.com/show_bug.cgi?id=1262040