{"id":"openSUSE-SU-2026:21585-1","summary":"Security update for htop","details":"This update for htop fixes the following issues:\n\nChanges in htop:\n\n- Update to version 3.5.3:\n  * Improve the htoprc settings parser to avoid segfaults on\n    tampered configuration files (sanitised sort keys, validated\n    configuration invariants, NULL safety for header columns and\n    screens)\n  * Add zswap pool usage meters\n  * Fix out-of-bounds access when parsing the power supply type\n    (Linux)\n  * Mark a CPU offline when it is unplugged from the middle and\n    release its data on hot-unplug (Linux)\n  * Fix a Clang MemorySanitizer-reported issue\n  * Exit follow mode when a search or filter is cancelled\n  * Fix blank STARTTIME and wrong ELAPSED for threads (Darwin)\n  * Use strchr instead of strstr in XUtils\n  * Document the CPU meter segments in the man page and add an\n    External Libraries section covering libnl-3/libnl-genl-3\n- CVE-2024-37676: out-of-bounds access in\n  Header_populateFromSettings reachable from a tampered htoprc;\n  the settings parser hardening above is what upstream lists as\n  covering it. openSUSE is assessed not affected (boo#1226729)\n","modified":"2026-08-18T18:23:35.042325642Z","published":"2026-08-17T17:00:32Z","related":["CVE-2024-37676"],"upstream":["CVE-2024-37676"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1226729"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-37676"}],"affected":[{"package":{"name":"htop","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/htop&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.3-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"htop":"3.5.3-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21585-1.json"}}],"schema_version":"1.9.0"}