Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

openSUSE: gitea-tea Reasonable Memory Leak Weak Spot 2025:0454-2

opensuse
Calendar Grey November 27, 2025
Dist Opensuse Esm H88
Two vulnerabilities have been addressed in openSUSE for gitea-tea with moderate severity affecting performance and security.
An update that fixes two vulnerabilities is now available.

Description

This update for gitea-tea fixes the following issues:

- update to 0.11.1:

* 61d4e57 Fix Pr Create crash (#823)

* 4f33146 add test for matching logins (#820)

* 08b8398 Update README.md (#819)

- CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by

`html.ParseFragment` when processing specially crafted input

(boo#1251663)

- CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic

complexity when parsing HTML documents (boo#1251471)

- update to 0.11.0:

* Fix yaml output single quote (#814)

* generate man page (#811)

* feat: add validation for object-format flag in repo create command

(#741)

* Fix release version (#815)

* update gitea sdk to v0.22 (#813)

* don't fallback login directly (#806)

* Check duplicated login name in interact mode when creating new login

(#803)

* Fix bug when output json with special chars (#801)

* add debug mode and update...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-443=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):

gitea-tea-0.11.1-bp156.14.1

- openSUSE Backports SLE-15-SP6 (noarch):

gitea-tea-bash-completion-0.11.1-bp156.14.1

gitea-tea-zsh-completion-0.11.1-bp156.14.1

References

https://www.suse.com/security/cve/CVE-2025-47911.html

https://www.suse.com/security/cve/CVE-2025-58190.html

https://bugzilla.suse.com/1251471

https://bugzilla.suse.com/1251663

Announcement ID: openSUSE-SU-2025:0443-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here