{"id":"openSUSE-SU-2026:21560-1","summary":"Security update for kak-lsp","details":"This update for kak-lsp fixes the following issues:\n\nChanges in kak-lsp:\n\n- Update to version 21.0.2:\n  * Fix a regression that broke compatibility with Kakoune versions\n    older than 2026.05.21\n  * Add a default configuration for Hare, using hare-lsp\n  * Fix hangs after editing a file without a trailing newline, such\n    as an empty file\n  * Use nixd instead of nil as the default language server for nix\n  * Fix buffer-sync corruption when .editorconfig sets\n    insert_final_newline = false\n- Refresh the vendored registry. Recording the state of the open\n  vendored-crate CVEs against it, none of which this package is\n  affected by:\n  * CVE-2026-25541 (boo#1274502): bytes is 1.12.1, above the 1.11.1\n    fix\n  * CVE-2025-3416 (boo#1242654): the openssl crate is 0.10.81, above\n    the 0.10.72 fix; it was already 0.10.80 before this update\n  * CVE-2025-55159 (boo#1248048): slab is 0.4.12, above the 0.4.11\n    fix; only 0.4.10 was ever affected and this package never\n    shipped it\n\n- Update to version 20.0.0:\n  * v20.0.0\n  * Update changelog\n  * Fix tinymist documentation URL\n  * Fix tinymist preview config key. `previewFeature` only works for the vscode plugin\n  * Encode brackets for file paths\n  * feat: swift/sourcekit-lsp support\n  * Paal �ye-Str�mme Copyright Waiver\n  * Make sure buffer synchronization works even when finaleol is missing\n  * workspace/executeCommand: don't panic on invalid args JSON\n  * servers.kak: update markdown-oxide root markers\n  * Inline lsp-initial-goto-position\n  * Fix function_casts_as_integer warning\n  * lsp-capabilities: remove stale default mappings\n  * changelog new erlang default server\n  * fix(ci/commit-new-release.sh): interpolate version number\n  * Change default language server for erlang\n  * lsp-inlay-hint-apply-*: fix crash when no hints avail\n  * Add inlay hint textedit support\n  * start new cycle\n\n- Update to version 19.0.1:\n  * v19.0.1\n  * Don't print Hover: prefix if there are no diagnostics\n  * Changelog for regression fix\n  * Fix lsp-find-error incorrectly handling --previous flag\n  * ci/commit-new-release.sh: support jj\n  * start new cycle\n\n- Update to version 18.2.0:\n  * v18.2.0\n  * Update changelog\n  * Remove misleading debug log in SessionRenamed hook\n  * Make *diagnostics* buffer one-line-per diagnostics\n  * test/gopls-dynamic-settings.sh: fix for recent gopls\n  * clippy\n  * controller: consume entire request before checking for user errors\n  * Add support vuejs\n  * Fix crash on invalid text edit ranges\n  * Send initializationOptions and workspace/didChangeConfiguration as expected by jdtls\n  * cargo update\n  * Fix type inference errors with deranged 0.4.1\n  * Fix symbol name prefix for breadcrumbs\n  * Work around breaking change in deranged crate\n  * Simplify recursive breadcrumbs calculation\n  * Language-specific SymbolKind rendering\n  * lsp-goto-document-symbol: remove symbol kind suffix\n  * start new cycle\n\n- Update to version 18.1.3:\n  * v18.1.3\n  * Use the right language ID when [language.foo] is in effect\n  * Remove unused line-specs option\n  * Better variable name for code lens line-specs value\n  * lsp-object: don't send documentSymbol to servers that don't support it\n  * Include language server name in stderr logs\n  * Use rust-analyzer from PATH\n  * Work around lsp-rename didChange failing when using window scope\n  * Send texlab-specific requests only to servers that support them\n  * Fix dart language server command\n  * Add kak-lsp server PID to the closing log message\n  * Report more diagnostics information, in multiple lines\n  * Fix regression causing spurious/missing server name in hover\n  * Address clippy lints\n  * Config knob to override magic single-instance setting\n  * Back out \"Add curly underline to DiagnosticError face\"\n  * start new cycle\n\n\n- Update to version 18.1.2:\n  * Silence errors from non-default hooks\n  * Fix languageId for JSX/TSX files\n  * Silence deprecation warning\n  * Add curly underline to DiagnosticError face\n\n- Update to version 18.1.1:\n  * Make crash reporting optional for now\n  * Touch up installation instructions in readme\n  * Make force-exit code paths safer\n  * Extract function\n  * Rework \"Prevent buffer content logic from reading to much\"\n  * Don't send debug log about excessive progress reports to editor\n  * Make test/clangd-invalid-utf8.sh compatible with older clangd\n  * Fix crash when legacy \"language\" config option uses language IDs\n  * Set LAST_CLIENT earlier\n  * test/clangd-invalid-utf8.sh: fix for modern clang\n  * Add biome to CSS and GraphQL\n  * On crash, disable LSP hooks in current buffer\n  * Simplify sentry integration\n  * Work around crash on unsaved files after server restart\n  * Add context to crash report message\n  * Include formatted panic info and backtrace in crash report\n  * Crash reporting via sentry.io\n  * Make the default panic message a little less intimidating\n  * Generalize option change hook parsing code\n  * Back out \"Fix fake textDocument/didOpen for unsaved files\"\n  * Back out \"Make sure to call textDocument/didOpen when lsp_servers is set after BufCreate\"\n  * Prevent buffer content logic from reading to much\n  * Fix crash on \u003cc-c\u003e during -sync command\n  * Make sure to call textDocument/didOpen when lsp_servers is set after BufCreate\n  * Add commented config for tailwindcss-language-server\n  * Fix fake textDocument/didOpen for unsaved files\n  * Stop logging the lsp-show-error call\n  * Fix garbage languageId being sent on lsp-workspace-symbol\n  * Clean up editor command dispatch code\n  * Rename command sender type\n  * Fix corruption applying text edits to non-buffer, non-ASCII files\n  * Separate out function for applying text edits to in-memory data structure\n  * Apply clippy lints\n  * Update unit tests\n  * Consolidate error reporting\n  * Work around missing error on missing code lens after server restart\n  * Type for client name\n  * Rework editor-command sending\n  * Remove most uses of EditorMeta::session\n  * Remove vestiges of multi-session code\n  * Bravely remove obsolete command_fifo, make response_fifo handling more robust\n  * Fix flaky test/gopls-goto-definition.sh\n  * Remove unused function\n  * Add more details to fifo log\n  * Remove unused parameter\n  * Use a separate field for requests pending initialization resp. textDocument/didChange\n  * Fix hang when sync request is used in hook when LSP is disabled\n  * Fix lsp-did-change not being sent for lsp-code-actions-sync\n  * Fix lingering sync state when lsp is disabled\n  * Remove unused lsp-with-option command\n  * Stop printing panic backtrace twice\n  * Add badges for latest release and chat networks\n  * Fix stacktrace being printed on EPIPE, remove redundant error output\n  * Call out feedback/support channels a bit more\n  * Stop linking to the Wiki page for installing servers\n  * Only set javascriptreact/typescriptreact language ID for jsx/tsx files\n\n- Update to version 18.1.0:\n  * Fix mixed-up order in tailwindcss example\n  * Fix bell in modeline not being cleared on ShowMessage notifications\n  * Fix patttern typo\n  * Add markdown-oxide language-server\n  * Add ruby-lsp language-server\n  * Fix stale quoting in lsp-do-send-sync\n  * Add log statements for raw request, handle EWOULDBLOCK/EAGAIN\n  * Use write instead of %val{selection} to send buffer contents\n  * Use a nonblocking fifo instead of pykak-style alternating fifos\n  * Address clippy lint\n  * Extend macOS workarounds to buffer synchronization\n  * Fail early again on missing language.foo.command field\n  * Also use elixir-ls on eex files\n  * Fail startup if session state files already exists\n  * Don't create session state if session is already running\n  * Escalate failure if kak-lsp daemon fails to start\n  * Don't clean up parent of session directories\n  * Do not briefly start kak-lsp on KakEnd if lsp-enable has never been called\n  * Fix typo in lsp-exit\n  * Rectify inconsistent quoting in recommended mappings\n  * Don't block when language servers are slow to exit\n  * Work around hang due to lost fifo on macOS\n  * Restyle --help output\n  * Fix test/clangd-diagnostic-gutter.sh flakiness\n  * Fix test/run not finding python on macOS\n  * Remove bad text edit assertion\n  * Braces in commented out code must match too\n  * The correct validation setting for CSS is `css.validate = true`\n  * Add CSS, HTML and JSON options, add Haskell's static-ls\n  * Workaround macOS waitid() not zeroing si_signo\n  * Fix waitid() being called unnecessarily\n  * Fix formatting spuriously moving cursor with vscode-html-language-server\n  * Fix Rust version\n  * Workaround HTML/CSS language servers not enabling formatting\n  * Workaround HTML/CSS language server crashing due to missing validProperties\n  * Fix crash interpreting text edit without trailing newline\n  * Clean up a debug log\n  * Remove dependency on Rust 1.80\n  * Fix regression causing crash when language server command fails exec()\n  * Don't send SIGTERM to language server, remove obsolete wait()\n  * Simplify sending of initialization options\n  * Fix regression causing hangs on restart\n  * Fix regression causing server configuration to be sent as initialization option\n  * Fix regression causing \"kak -p\" to become a zombie\n  * Remove \"set-option -add\" from most commented default configs\n  * Back out \"lsp-start to wait until existing server has exited\"\n  * Fix race conditions reading kak-lsp PID file\n  * Send SIGTERM, not SIGKILL to shut down inert language server\n  * Speed up language server shutdown\n  * lsp-exit to wait until the session directory is removed\n  * Remove shell calls from async request sending\n  * Drain fifo on exit to unblock Kakoune\n  * Remove unnecssary environment variable\n  * Refactor temporary directory cleanup logic\n  * lsp-start to wait until existing server has exited\n  * Wait for PID file creation after start\n  * Move fifo into a per-session directory\n  * Remove errant semicolon\n  * Remove shell calls for code-actions and highlight-references hooks\n  * Move hook definition out of the way\n  * Stop using temporary file also for textDocument/didChange and textDocument/didOpen\n  * typst: add default configuration\n  * Mohamad Makki Copyright Waiver\n  * Update manual installation instructions for ARM macOS\n\n- Update to version 18.0.3:\n  * Update changelog for release\n  * Disable CI runs for a special \"docs\" branch\n  * Scala Metals: turn off Unicode icons until Kakoune can handle emoji width\n  * Simply use stdout instead of fd 3 for request sending\n  * Remove redundant fifo re-creation\n  * Elide temporary file when writing to fifo\n  * Fix escaping if session name starts with a dash\n  * Move loop-invariant set-option out of the loop\n  * Fix window/showMessageRequest ID deserialization\n  * lsp-disable: unset LSP modeline\n  * Fix eslint workaround\n  * Fix crash when \"language\" key is used in legacy kak-lsp.toml\n  * julia lsp configuration: move root_globs\n  * minor: fix typo in julia lsp config\n  * cargo update\n  * cargo clippy\n  * Fix crash in lsp-selection-range\n  * Show error instead of crashing if lsp_servers root is not an absolute path\n  * Block LSP requests after KakEnd to work around delay on bad config\n  * lsp-do-send: also block SIGINT once we have acquired the fifo\n  * README: update \"Pre-built binaries\" section\n  * Fix state transition when lsp-enable{,-window} are accidentally mixed\n  * Remove shell call from lsp-if-no-servers\n  * Remove misleading \"set-option -add lsp_server\" from default hooks\n  * lsp-object: fix crash on invalid param, improve docs\n\n- Update to version 18.0.2:\n  * v18.0.2\n  * README: link to troubleshooting section\n  * Fix stale comment in test\n  * Update changelog\n  * Show panics in an info box\n  * Generate a core dump when crashing via a Rust panic\n  * lsp-definition: explain fallback in error message\n  * Fix crash in lsp-highlight-references\n  * Log kak-lsp daemon PID on startup\n  * Removed redundant error check\n","modified":"2026-08-12T18:23:54.601459071Z","published":"2026-08-10T16:06:46Z","related":["CVE-2025-3416","CVE-2025-55159","CVE-2026-25541"],"upstream":["CVE-2025-3416","CVE-2025-55159","CVE-2026-25541"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1242654"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-3416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55159"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25541"}],"affected":[{"package":{"name":"kak-lsp","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/kak-lsp&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"21.0.2-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"kak-lsp":"21.0.2-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21560-1.json"}}],"schema_version":"1.9.0"}