{"id":"openSUSE-SU-2026:21870-1","summary":"Security update for openai-codex","details":"This update for openai-codex fixes the following issues:\n\nChanges in openai-codex:\n\nUpdate to version 0.154.0:\n\n  * Experimental worktree support for isolated checkouts of new\n    or forked sessions, with browse and resume\n  * Answer questions inline while Codex keeps working, keeping\n    the main draft\n  * Vim R replace mode with undo and dot-repeat; /copy keeps\n    formatting and covers status and session fields\n  * Plugin tools refresh after external upgrades, MCP OAuth\n    refresh is coordinated, helpers no longer run before trust\n    is established; resume and fork keep saved permissions\n  * Drop the deprecated codex mcp-server entry point, now codex mcp\n- Regenerate vendor.tar.zst: rmcp 3.1.3 -\u003e 3.2.0 plus routine\n  bumps; webrtc/gstreamer/cpal stay out of the codex-cli link\n  graph, so the License tag is unchanged\n- Legal-Review-Notice: linked-crate count 876/878 -\u003e 880/882 on\n  aarch64/x86_64; the vendored dependency licence set is unchanged\n- cargo-audit reports the same five advisories as 0.151.0, none\n  new and none fixable by re-vendoring\n\nUpdate to version 0.153.4:\n\n  * GPT-6-Astra is listed in the bundled model picker and is the\n    bundled default when no model is configured\n  * Astra's async-question guidance now applies only when\n    request_user_input_async is available in the session\n\nUpdate to version 0.153.3:\n\n  * GPT-6-Astra is available in the Amazon Bedrock model picker\n    for Mantle and Runtime global/US routes\n  * Astra's async-question guidance now names\n    request_user_input_async and notes that it accepts text only\n\n- Keep vendor.tar.zst: 0.153.4 has the same Cargo.lock as 0.153.2,\n  so the linked crate set, the License tag and the\n  Legal-Review-Notice counts are unchanged\n\n- Update to version 0.153.2:\n\n  * Correct the GPT-6-Astra Fast tier description to \"2x speed\"\n    instead of \"1.5x\"; display text only, request handling is\n    unchanged\n    \n- Update to version 0.153.1:\n\n  * GPT-6-Astra can be configured through the API without changing\n    the default model or listing it in the model picker\n    \n- Build against the system bzip2, libzstd, oniguruma and sqlite\n  instead of the copies bzip2-sys, zstd-sys, onig_sys and\n  libsqlite3-sys otherwise compile in; drop their bundled()\n  Provides and add pkgconfig(bzip2), pkgconfig(libzstd),\n  pkgconfig(oniguruma) \u003e= 6.9.3 and pkgconfig(sqlite3) \u003e= 3.34.1\n  * oniguruma and sqlite have no usable manifest switch, so %build\n    and %check export RUSTONIG_SYSTEM_LIBONIG and\n    LIBSQLITE3_SYS_USE_PKG_CONFIG instead, and %install now fails\n    the build unless all four are DT_NEEDED of codex\n  * aws-lc stays bundled: aws-lc-sys has no system-library mode\n  \n- Keep vendor.tar.zst: 0.153.2 has the same Cargo.lock as 0.153.0,\n  so the linked crate set, the License tag and the\n  Legal-Review-Notice counts are unchanged\n\n- Update to version 0.153.0:\n\n  * Vim mode gains undo (u) and redo (Ctrl+R), preserving whole\n    drafts including pasted content and attachments\n  * The plugin CLI lists, installs and removes plugins from remote\n    marketplaces\n  * tui.auto_recap = false turns off automatic recaps while keeping\n    /recap available\n  * TUI history shows complete patches, input sent to background\n    terminals and individual completed commands\n  * TUI sessions reconnect after an app-server connection drops,\n    keeping drafts and holding queued submissions for review\n  * Guardian review history survives compaction, restarts and\n    forks; Full Access skips Guardian review for confirmation-only\n    actions\n  * Remembered MCP tool approvals are scoped to the selected\n    app account\n  * tui.disable_paste_burst replaces the top-level setting, which\n    stays supported as a fallback\n  * New disabled-by-default\n    features.context_management.experimental_mode\n    \n- Regenerate vendor.tar.zst: the 14 crates 0.153.0 adds to the\n  lockfile are all Windows-only, so the linked third-party set,\n  the License tag and the bundled() versions are unchanged; the\n  Legal-Review-Notice counts move only by one added first-party\n  workspace member\n\n- Update to version 0.152.1:\n\n  * Guardian approval review honours Node REPL policies supplied\n    through model metadata; the bundled policy is now only the\n    fallback\n  * Switching models mid-session is refused when the destination\n    changes the Guardian parent-fallback node REPL policy\n\n- Update to version 0.152.0:\n\n  * Vim mode gains \"/\" and \"?\" search within drafts, with match\n    highlighting and n/N repeat navigation\n  * Rate-limit banners offer actions for checking usage, managing\n    credits, resetting limits and managing plans\n  * TUI and \"codex exec\" show credential-refresh progress,\n    including Amazon Bedrock reauthentication\n  * MCP server names may contain \":\", \"@\", \"/\" and \".\"\n  * Individual MCP tools honour an output_token_limit setting\n  * App-server clients can configure thread/shellCommand timeouts\n    longer than one hour\n  * Cloud task requests reject untrusted backend URLs and refuse\n    redirects, protecting saved credentials\n  * The planning tool is now disabled by default; re-enable with\n    tools.update_plan.enabled = true\n  * Vim-enabled composers start fresh drafts in Insert mode again\n  \n- cargo-audit reports five advisories on the vendored lockfile, all\n  pre-existing and unchanged since 0.151.0; audit a bare Cargo.lock\n  because upstream's codex-rs/.cargo/audit.toml hides four of them:\n  \n  * CVE-2026-25800 (RUSTSEC-2026-0185, quinn-proto 0.11.14): not\n    affected, reqwest gates dep:quinn behind its \"http3\" feature,\n    which the workspace leaves off, so it is never linked\n  * RUSTSEC-2026-0194 and -0195 (quick-xml 0.39.4) and\n    RUSTSEC-2026-0118 and -0119 (hickory-proto 0.25.2), DoS with no\n    CVE assigned: linked, but each fix is a semver-incompatible\n    bump of an intermediate crate, or not released at all\n    \n- Legal-Review-Notice: linked-crate count 874/876 -\u003e 875/877 on\n  aarch64/x86_64, from one new first-party workspace crate\n  (codex-guardian-context). The vendored dependency set, the\n  bundled() versions and the License tag are unchanged from 0.151.0\n\n- Update to version 0.151.0:\n\n  * Configurable grace period for discovering tools from optional\n    MCP servers\n  * Extensions can inspect or replace MCP tool results before they\n    reach the model\n  * Plugin catalogs combine per-repository configuration and report\n    invalid project marketplaces without hiding valid plugins\n  * Preserve restored permission profiles across TUI turns; /cd can\n    no longer weaken sandbox restrictions\n  * Stale Guardian classifications no longer authorize actions after\n    a permission-state change\n  * Remote sandbox enforcement uses the executor's actual home\n    directory, OS and path conventions\n  * Keep tool availability and reasoning effort correct when\n    switching models or falling back to another one\n  * Nested subagent token usage counts toward root goal budgets\n  \n- Vendored dependency set is unchanged from 0.150.1 (1193 crates,\n  none added or removed), so the License tally and the bundled()\n  versions still hold.\n","modified":"2026-09-17T18:23:34.299920645Z","published":"2026-09-16T20:01:13Z","related":["CVE-2026-25800"],"upstream":["CVE-2026-25800"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25800"}],"affected":[{"package":{"name":"openai-codex","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/openai-codex&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.154.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"openai-codex":"0.154.0-bp160.1.1","openai-codex-bash-completion":"0.154.0-bp160.1.1","openai-codex-fish-completion":"0.154.0-bp160.1.1","openai-codex-zsh-completion":"0.154.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21870-1.json"}}],"schema_version":"1.9.0"}