{"id":"openSUSE-SU-2026:20749-1","summary":"Security update for tree-sitter","details":"This update for tree-sitter fixes the following issues\n\nSecurity issues:\n\n- CVE-2026-34941: wasmtime: crafted input string can lead to an out-of-bound read (bsc#1261871).\n- CVE-2026-34942: wasmtime: unaligned pointers can lead to a denial of service (bsc#1261894).\n- CVE-2026-34943: wasmtime: lifting `flags` component value can lead to a denial of service (bsc#1261954).\n- CVE-2026-34944: wasmtime: out-of-bounds read during WebAssembly compilation can lead to a denial of service\n  (bsc#1261963).\n- CVE-2026-34945: wasmtime: incorrectly translated table.size could lead to disclosing data (bsc#1262007).\n- CVE-2026-34946: wasmtime: denial of service due to WebAssembly compilation error (bsc#1261974).\n- CVE-2026-34987: wasmtime: winch compiler backend may allow a sandbox-escaping memory access (bsc#1262032).\n- CVE-2026-34988: wasmtime: pooling allocator instances can cause data leakage (bsc#1261968).\n- CVE-2026-35186: wasmtime: translating the table.grow operator can cause a masked return value (bsc#1262036).\n- CVE-2026-35195: wasmtime: transcoding strings can lead to an out of bound write or a crash (bsc#1262040).\n\nChanges for tree-sitter:\n\n- update to 0.26.8:\n\n * fix(generate): allow disabling qjs-rt feature from CLI by @WillLillis in\n #5448\n * fix(lib): document invariants that must be upheld for TSInputEdit by\n @WillLillis in #5452\n * fix(cli): correct typo in parse command's help text by @WillLillis in #5465\n * perf(cli): misc. improvements by @tree-sitter-ci-bot[bot] in #5476\n * Fix wasm loading of languages w/ multiple reserved word sets by\n @tree-sitter-ci-bot[bot] in #5477\n * generate: avoid panicking when a supertype only has hidden external token\n children by @tree-sitter-ci-bot[bot] in #5478\n","modified":"2026-05-19T18:23:49.202321836Z","published":"2026-05-14T08:07:53Z","related":["CVE-2026-34941","CVE-2026-34942","CVE-2026-34943","CVE-2026-34944","CVE-2026-34945","CVE-2026-34946","CVE-2026-34987","CVE-2026-34988","CVE-2026-35186","CVE-2026-35195"],"upstream":["CVE-2026-34941","CVE-2026-34942","CVE-2026-34943","CVE-2026-34944","CVE-2026-34945","CVE-2026-34946","CVE-2026-34987","CVE-2026-34988","CVE-2026-35186","CVE-2026-35195"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261839"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261871"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261894"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261954"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261963"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261968"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261974"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262007"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262032"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34941"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34942"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34944"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34946"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35195"}],"schema_version":"1.7.5"}