{"id":"openSUSE-SU-2026:21166-1","summary":"Security update for nano","details":"This update for nano fixes the following issues:\n\nChanges in nano:\n\n- Update to version 9.1:\n  * When searching, the viewport is placed snug left where\n    possible.\n  * The ability to read and write files in old Mac format (a lone\n    carriage return as line ending) was removed.\n  * The ^T toggle between WhereIs and GotoLine was dropped.\n  * Fix backups that were missing or had a wrong timestamp when\n    --backup is active.\n  * On a crash or kill, a .save file is no longer chmodded or\n    chowned to the base file's permissions and owner.\n  * The history code now creates the ~/.local directory with\n    limited access rights (boo#1263437; the referenced\n    CVE-2026-40556 was rejected upstream).\n  * M-Ins and M-Del have become rebindable.\n\n- GNU nano 9.0:\n  * When the cursor almost goes offscreen to the right, all lines\n    are now scrolled sideways together, by just the amount needed\n    to keep the cursor in view.\n    Use --solosidescroll or 'set solosidescroll' to get back the\n    old, jerky, single-line horizontal scrolling.\n  * The viewport can be scrolled sideways (in steps of one\n    tabsize) with M-\u003c and M-\u003e.  See `man nanorc` if M-\u003c and M-\u003e\n    should switch between buffers (as they did earlier).\n  * M-Left, M-Right, M-Up, and M-Down have become rebindable.\n  * Stopping the recording of a macro immediately after starting\n    it cancels the recording and leaves an existing macro in place.\n  * Feature toggles no longer break a chain of ^K cuts or M-6\n    copies, except the M-K cut-from-cursor toggle.\n  * With --mouse and --indicator, one can click in the scrollbar\n    area to roughly navigate within the buffer.\n  * CVE-2026-6843: format string vulnerability leads to denial of\n    service (boo#1262643)\n  * create the ~/.local directory with limited access rights\n    (CVE-2026-6842 boo#1263022, CVE-2026-40556 boo#1263437)\n\n- GNU nano 8.7.1:\n  * fix build against glibc-2.43 (boo#1258260)\n\n- GNU nano 8.7:\n  * At the Execute prompt, preceding the command with two pipe\n    symbols allows implementing a copy-to-clipboard feature in\n    nanorc on terminals that support OSC 52. See doc/sample.nanorc\n","modified":"2026-06-30T09:15:07.746855861Z","published":"2026-06-29T08:14:36Z","related":["CVE-2026-40556","CVE-2026-6842","CVE-2026-6843"],"upstream":["CVE-2026-40556","CVE-2026-6842","CVE-2026-6843"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258260"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262643"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263022"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40556"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6842"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6843"}],"affected":[{"package":{"name":"nano","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/nano&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"nano-lang":"9.1-bp160.1.1","nano":"9.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21166-1.json"}}],"schema_version":"1.7.5"}