openSUSE-SU-2026:21585-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21585-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21585-1
Upstream
  • CVE-2024-37676
Related
Published
2026-08-17T17:00:32Z
Modified
2026-08-18T18:23:35Z
Summary
Security update for htop
Details

This update for htop fixes the following issues:

Changes in htop:

  • Update to version 3.5.3:
    • Improve the htoprc settings parser to avoid segfaults on tampered configuration files (sanitised sort keys, validated configuration invariants, NULL safety for header columns and screens)
    • Add zswap pool usage meters
    • Fix out-of-bounds access when parsing the power supply type (Linux)
    • Mark a CPU offline when it is unplugged from the middle and release its data on hot-unplug (Linux)
    • Fix a Clang MemorySanitizer-reported issue
    • Exit follow mode when a search or filter is cancelled
    • Fix blank STARTTIME and wrong ELAPSED for threads (Darwin)
    • Use strchr instead of strstr in XUtils
    • Document the CPU meter segments in the man page and add an External Libraries section covering libnl-3/libnl-genl-3
  • CVE-2024-37676: out-of-bounds access in Header_populateFromSettings reachable from a tampered htoprc; the settings parser hardening above is what upstream lists as covering it. openSUSE is assessed not affected (boo#1226729)
References

Affected packages

openSUSE:Leap 16.0 / htop

Package

Name
htop
Purl
pkg:rpm/opensuse/htop&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.5.3-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "htop":  "3.5.3-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21585-1.json"