Packages changed: 7zip (26.01 -> 26.02) AppStream (1.1.2 -> 1.1.3) GraphicsMagick ImageMagick Mesa (26.1.4 -> 26.1.5) Mesa-drivers (26.1.4 -> 26.1.5) MozillaFirefox (152.0.4 -> 153.0) PackageKit acl (2.3.2 -> 2.4.0) akonadi-import-wizard aurorae6 (6.7.2 -> 6.7.3) autoyast2 (5.0.8 -> 5.0.10) avahi avahi-glib2 blog (2.46 -> 2.47) bluedevil6 (6.7.2 -> 6.7.3) breeze6 (6.7.2 -> 6.7.3) breeze6-gtk (6.7.2 -> 6.7.3) brltty btrfsprogs (7.0 -> 7.1) ca-certificates (2+git20260420.2a8e251 -> 2+git20260717.2e3a23b) dav1d (1.5.3 -> 1.5.4) discover6 (6.7.2 -> 6.7.3) dracut (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) drkonqi6 (6.7.2 -> 6.7.3) e2fsprogs findutils (4.10.0 -> 4.11.0) firewalld (2.1.2 -> 2.3.2) flatpak-kcm6 (6.7.2 -> 6.7.3) gawk (5.4.0 -> 5.4.1) glslang (16.3.0 -> 16.4.0) gnome-sudoku (50.2.1 -> 50.3) gnutls google-noto-fonts (20241201 -> 20260701) gpsd grub2 gstreamer-devtools (1.28.4 -> 1.28.5) gstreamer-plugins-libav (1.28.4 -> 1.28.5) gtk4 (4.22.4+11 -> 4.22.4+29) inkscape (1.4.4+git0.dcaf3e7d9e -> 1.4.4+git2.3454cb1dab) inn ipxe (1.21.1+git20250827.61b4585e2 -> 2.0.0+git20260710.58ee55b3c) java-25-openjdk (25.0.3.0 -> 25.0.4.0) kactivitymanagerd6 (6.7.2 -> 6.7.3) kaddressbook kcalutils kde-cli-tools6 (6.7.2 -> 6.7.3) kde-gtk-config6 (6.7.2 -> 6.7.3) kdecoration6 (6.7.2 -> 6.7.3) kdeplasma6-addons (6.7.2 -> 6.7.3) kernel-source (7.1.3 -> 7.1.4) kf6-attica (6.27.0 -> 6.28.0) kf6-baloo (6.27.0 -> 6.28.0) kf6-bluez-qt (6.27.0 -> 6.28.0) kf6-breeze-icons (6.27.0 -> 6.28.0) kf6-frameworkintegration (6.27.0 -> 6.28.0) kf6-karchive (6.27.0 -> 6.28.0) kf6-kauth (6.27.0 -> 6.28.0) kf6-kbookmarks (6.27.0 -> 6.28.0) kf6-kcalendarcore (6.27.0 -> 6.28.0) kf6-kcmutils (6.27.0 -> 6.28.0) kf6-kcodecs (6.27.0 -> 6.28.0) kf6-kcolorscheme (6.27.0 -> 6.28.0) kf6-kcompletion (6.27.0 -> 6.28.0) kf6-kconfig (6.27.0 -> 6.28.0) kf6-kconfigwidgets (6.27.0 -> 6.28.0) kf6-kcontacts (6.27.0 -> 6.28.0) kf6-kcoreaddons (6.27.0 -> 6.28.0) kf6-kcrash (6.27.0 -> 6.28.0) kf6-kdav (6.27.0 -> 6.28.0) kf6-kdbusaddons (6.27.0 -> 6.28.0) kf6-kdeclarative (6.27.0 -> 6.28.0) kf6-kded (6.27.0 -> 6.28.0) kf6-kdesu (6.27.0 -> 6.28.0) kf6-kdnssd (6.27.0 -> 6.28.0) kf6-kdoctools (6.27.0 -> 6.28.0) kf6-kfilemetadata (6.27.0 -> 6.28.0) kf6-kglobalaccel (6.27.0 -> 6.28.0) kf6-kguiaddons (6.27.0 -> 6.28.0) kf6-kholidays (6.27.0 -> 6.28.0) kf6-ki18n (6.27.0 -> 6.28.0) kf6-kiconthemes (6.27.0 -> 6.28.0) kf6-kidletime (6.27.0 -> 6.28.0) kf6-kimageformats (6.27.0 -> 6.28.0) kf6-kio (6.27.0 -> 6.28.0) kf6-kirigami (6.27.0 -> 6.28.0) kf6-kitemmodels (6.27.0 -> 6.28.0) kf6-kitemviews (6.27.0 -> 6.28.0) kf6-kjobwidgets (6.27.0 -> 6.28.0) kf6-knewstuff (6.27.0 -> 6.28.0) kf6-knotifications (6.27.0 -> 6.28.0) kf6-knotifyconfig (6.27.0 -> 6.28.0) kf6-kpackage (6.27.0 -> 6.28.0) kf6-kparts (6.27.0 -> 6.28.0) kf6-kplotting (6.27.0 -> 6.28.0) kf6-kpty (6.27.0 -> 6.28.0) kf6-kquickcharts (6.27.0 -> 6.28.0) kf6-krunner (6.27.0 -> 6.28.0) kf6-kservice (6.27.0 -> 6.28.0) kf6-kstatusnotifieritem (6.27.0 -> 6.28.0) kf6-ksvg (6.27.0 -> 6.28.0) kf6-ktexteditor (6.27.0 -> 6.28.0) kf6-ktexttemplate (6.27.0 -> 6.28.0) kf6-ktextwidgets (6.27.0 -> 6.28.0) kf6-kunitconversion (6.27.0 -> 6.28.0) kf6-kuserfeedback (6.27.0 -> 6.28.0) kf6-kwallet (6.27.0 -> 6.28.0) kf6-kwidgetsaddons (6.27.0 -> 6.28.0) kf6-kwindowsystem (6.27.0 -> 6.28.0) kf6-kxmlgui (6.27.0 -> 6.28.0) kf6-modemmanager-qt (6.27.0 -> 6.28.0) kf6-networkmanager-qt (6.27.0 -> 6.28.0) kf6-prison (6.27.0 -> 6.28.0) kf6-purpose (6.27.0 -> 6.28.0) kf6-qqc2-desktop-style (6.27.0 -> 6.28.0) kf6-solid (6.27.0 -> 6.28.0) kf6-sonnet (6.27.0 -> 6.28.0) kf6-syndication (6.27.0 -> 6.28.0) kf6-syntax-highlighting (6.27.0 -> 6.28.0) kf6-threadweaver (6.27.0 -> 6.28.0) kgamma6 (6.7.2 -> 6.7.3) kglobalacceld6 (6.7.2 -> 6.7.3) kinfocenter6 (6.7.2 -> 6.7.3) kirigami-addons6 (1.12.1 -> 1.13.0) kmenuedit6 (6.7.2 -> 6.7.3) knighttime6 (6.7.2 -> 6.7.3) kpipewire6 (6.7.2 -> 6.7.3) kscreen6 (6.7.2 -> 6.7.3) kscreenlocker6 (6.7.2 -> 6.7.3) ksshaskpass6 (6.7.2 -> 6.7.3) ksystemstats6 (6.7.2 -> 6.7.3) kwayland-integration6 (6.7.2 -> 6.7.3) kwayland6 (6.7.2 -> 6.7.3) kwin6 (6.7.2 -> 6.7.3) kwin6-x11 (6.7.2 -> 6.7.3) layer-shell-qt6 (6.7.2 -> 6.7.3) libdrm libgit2 (1.9.4 -> 1.9.6) libkscreen6 (6.7.2 -> 6.7.3) libksysguard6 (6.7.2 -> 6.7.3) libplasma6 (6.7.2 -> 6.7.3) libseccomp libsoup libtool (2.5.4 -> 2.6.2) libupnp (2.0.2 -> 22.0.4) libyui (4.7.6 -> 4.7.7) libyui-ncurses (4.7.6 -> 4.7.7) libyui-ncurses-pkg (4.7.6 -> 4.7.7) libyui-qt (4.7.6 -> 4.7.7) libyui-qt-graph (4.7.6 -> 4.7.7) libyui-qt-pkg (4.7.6 -> 4.7.7) libzypp (17.38.13 -> 17.38.14) milou6 (6.7.2 -> 6.7.3) mozilla-nss (3.124 -> 3.125) ngtcp2 (1.22.1 -> 1.24.0) ntfs-3g_ntfsprogs ocean-sound-theme6 (6.7.2 -> 6.7.3) open-iscsi open-vm-tools openSUSE-release (20260714 -> 20260724) openssl-3 pam_kwallet6 (6.7.2 -> 6.7.3) patterns-base perl (5.42.1 -> 5.44.0) perl-Cpanel-JSON-XS (4.420.0 -> 4.430.0) perl-HTTP-Date (6.70.0 -> 6.80.0) permissions (1699_20260707 -> 1699_20260715) pipewire (1.6.7 -> 1.6.8) plasma5support6 (6.7.2 -> 6.7.3) plasma6-activities (6.7.2 -> 6.7.3) plasma6-activities-stats (6.7.2 -> 6.7.3) plasma6-browser-integration (6.7.2 -> 6.7.3) plasma6-desktop (6.7.2 -> 6.7.3) plasma6-disks (6.7.2 -> 6.7.3) plasma6-integration (6.7.2 -> 6.7.3) plasma6-nm (6.7.2 -> 6.7.3) plasma6-openSUSE plasma6-pa (6.7.2 -> 6.7.3) plasma6-print-manager (6.7.2 -> 6.7.3) plasma6-systemmonitor (6.7.2 -> 6.7.3) plasma6-thunderbolt (6.7.2 -> 6.7.3) plasma6-workspace (6.7.2 -> 6.7.3) policycoreutils polkit polkit-kde-agent-6 (6.7.2 -> 6.7.3) poppler (26.06.0 -> 26.07.0) poppler-qt6 (26.06.0 -> 26.07.0) powerdevil6 (6.7.2 -> 6.7.3) python-click (8.4.1 -> 8.4.2) python-numpy (2.4.4 -> 2.4.6) python-pyasn1 (0.6.3 -> 0.6.4) python313 (3.13.13 -> 3.13.14) python313-core (3.13.13 -> 3.13.14) qemu qqc2-breeze-style6 (6.7.2 -> 6.7.3) rsyslog ruby4.0 (4.0.5 -> 4.0.6) salt sddm sddm-kcm6 (6.7.2 -> 6.7.3) sddm-qt6 selinux-policy (20260702 -> 20260715) shaderc (2026.2 -> 2026.3) spectacle (6.7.2 -> 6.7.3) sqlite3 srt (1.5.5 -> 1.5.6) sso-mib (0.10.0 -> 0.10.1) suse-module-tools (16.1.5 -> 16.1.6) swtpm systemsettings6 (6.7.2 -> 6.7.3) tar thunar (4.20.8 -> 4.20.9) unison (2.53.8 -> 2.54.0) unrar_wrapper vim virtiofsd (1.13.2 -> 1.14.0) wacomtablet-kcm6 (6.7.2 -> 6.7.3) wayland (1.25.0 -> 1.26.0) webkitgtk3 (2.52.4 -> 2.52.5) webkitgtk4 (2.52.4 -> 2.52.5) wget xclock (1.2.0 -> 1.2.1) xdg-desktop-portal-kde6 (6.7.2 -> 6.7.3) xfce4-power-manager xmodmap (1.0.11 -> 1.0.12) xorg-x11-server (21.1.21 -> 21.1.24) yast2-add-on (5.0.0 -> 5.0.2) yast2-installation (5.0.19 -> 5.0.21) yast2-packager (5.0.11 -> 5.0.13) === Details === ==== 7zip ==== Version update (26.01 -> 26.02) - Update to 26.02: * Some bugs and vulnerabilities were fixed. * CVE-2026-14266 / ZDI-26-444 : 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability ==== AppStream ==== Version update (1.1.2 -> 1.1.3) Subpackages: libAppStreamQt3 libappstream5 - Add upstream changes: * 0001-yaml-Fix-potential-crashes-when-encountering-missing.patch * 0001-yaml-Adjust-tests-and-emitter-to-work-around-libfyam.patch * 0001-yaml-Ensure-version-relations-are-consistently-quote.patch * 0001-trivial-yaml-Ensure-branding-color-values-are-also-c.patch - Drop patch, no longer needed: * 0001-Disable-failing-test-with-old-libfyaml.patch - Update to 1.1.3 Features: * Officially support & read JXL images for icons, validate permitted filetypes * meson: Allow disabling command-line tools * news-convert: Recognize "=" as release block header * news-convert: Handle extra linebreaks better and add support for issue-blocks * compose: Create content hashes with Blake3 instead of MD5 * Update static data for category and license additions * validator: Tags without namespace are an error Specification: * docs: Convert to Docbook 5 Bugfixes: * yaml: Ensure certain values are always explicitly emitted as strings * Never emit usertags that are missing a namespace * compose: add bounds checks when parsing malformed translation files * Explicitly add fcfreetype.h include to asc-font.c * compose: Unref icon_policy in asc_compose_finalize * compose: Free array from asc_result_get_component_ids_with_hints Miscellaneous: * yaml: Improve string quoting heuristics * meson: Drop -Winline from maintainer flags - Drop patch, merged upstream: * 0001-Explicitly-add-fcfreetype.h-include-to-asc-font.c.patch - Drop no longer needed patch: * support-meson0.59.patch ==== GraphicsMagick ==== Subpackages: libGraphicsMagick++-Q16-12 libGraphicsMagick-Q16-3 libGraphicsMagick3-config - added patches CVE-2026-61870: Memory leak in VIFF encoder when allocation fails [bsc#1271293] * GraphicsMagick-CVE-2026-61870.patch ==== ImageMagick ==== Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - remove logo.eps (propriatery licence) ==== Mesa ==== Version update (26.1.4 -> 26.1.5) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.1.5 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.5 - fixed hardware supplements for libvulkan_intel/libvulkan_radeon (boo#1271268) ==== Mesa-drivers ==== Version update (26.1.4 -> 26.1.5) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Update to 26.1.5 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.5 - fixed hardware supplements for libvulkan_intel/libvulkan_radeon (boo#1271268) ==== MozillaFirefox ==== Version update (152.0.4 -> 153.0) Subpackages: MozillaFirefox-branding-upstream - Mozilla Firefox 153.0 https://www.firefox.com/en-US/firefox/153.0/releasenotes/ MFSA 2026-68 (bsc#1271649) * CVE-2026-16349 (bmo#2034682) Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 (bmo#2042033) Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 (bmo#2043188) Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 (bmo#2045468) Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 (bmo#2046416) Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 (bmo#2047689) JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 (bmo#2047802) Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 (bmo#2049149) Privilege escalation in the DOM: Workers component * CVE-2026-16366 (bmo#2049181) Privilege escalation in the DOM: Navigation component * CVE-2026-16353 (bmo#2049523) Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 (bmo#2050626) Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 (bmo#2050627) Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 (bmo#2051015) Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 (bmo#2051854) Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 (bmo#2052207) JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 (bmo#2052562) Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 (bmo#2053326) Incorrect boundary conditions in the Graphics component * CVE-2026-16370 (bmo#1996495) Mitigation bypass in the DOM: Networking component * CVE-2026-16371 (bmo#2008369) Privilege escalation in the DOM: Navigation component * CVE-2026-16372 (bmo#2013800) Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 (bmo#2021964) Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 (bmo#2027519) Information disclosure in the Framework component in DevTools * CVE-2026-16375 (bmo#2032140) Site isolation issue in the Networking: HTTP component * CVE-2026-16376 (bmo#2035733) Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 (bmo#2037770) Mitigation bypass in the PDF Viewer component * CVE-2026-16378 (bmo#2038868) Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 (bmo#2039452) Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 (bmo#2040119) Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 (bmo#2040386) Mitigation bypass in the Networking component * CVE-2026-16381 (bmo#2041001) Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 (bmo#2041864) Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 (bmo#2041902) Mitigation bypass in the DOM: Networking component * CVE-2026-16384 (bmo#2041911) Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 (bmo#2041912) Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 (bmo#2041916) Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 (bmo#2043200) Site isolation issue in the Networking component * CVE-2026-16388 (bmo#2043845) Sandbox escape in the DOM: Networking component * CVE-2026-16389 (bmo#2043887) Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 (bmo#2044527) Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 (bmo#2044536) Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 (bmo#2044606) JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 (bmo#2045410) Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 (bmo#2045424) Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 (bmo#2046748) Mitigation bypass in the DOM: Security component ... changelog too long, skipping 101 lines ... (bmo#2048383) ==== PackageKit ==== Subpackages: PackageKit-backend-zypp PackageKit-gstreamer-plugin PackageKit-gtk3-module libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Add PackageKit-zypp-respect-libzypp-package-locks.patch: zypp: respect libzypp package locks (bsc#1263252, gh#PackageKit/PackageKit/commit/1263252). ==== acl ==== Version update (2.3.2 -> 2.4.0) Subpackages: libacl1 - Update to version 2.4.0: Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent that. ==== akonadi-import-wizard ==== Subpackages: libKPim6ImportWizard6 - Add upstream change: * 0001-Add-missing-find_package-KF6I18n.patch ==== aurorae6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== autoyast2 ==== Version update (5.0.8 -> 5.0.10) Subpackages: autoyast2-installation - jsc#PED-14507 - Removed remaining reference to update-desktop-files embedded deeper inside from spec file - 5.0.10 - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.9 ==== avahi ==== Subpackages: libavahi-client3 libavahi-common3 libavahi-core7 - Add avahi-CVE-2025-59529.patch: limit the number of simple clients (bsc#1255451 CVE-2025-59529). ==== avahi-glib2 ==== - Add avahi-CVE-2025-59529.patch: limit the number of simple clients (bsc#1255451 CVE-2025-59529). ==== blog ==== Version update (2.46 -> 2.47) Subpackages: libblogger2 - Update to version 2.47 This addresses several race conditions, file descriptor leaks, and architectural issues regarding virtual terminal (VT) handling in blogd. * VT Encapsulation: Extracted all kernel-specific terminal ioctls and macros (e.g., KD_GRAPHICS, KD_TEXT) into a dedicated vt.c module. Added clean abstractions like vt_is_graphics(), vt_is_text(), and vt_set_text_mode() to decouple blogd.c and console.c from kernel headers. * List Management & FD Leaks: Fixed dynamic VT allocation in console.c. By resetting the console pointer to NULL before consalloc() and explicitly searching the doubly linked list for the target device ID afterward, we ensure the exact newly allocated terminal node is referenced. This fixes incorrect node assignments and prevents file descriptor leaks. * Smart VT Switching: Optimized the password prompt logic. If the currently active VT is a text console, the prompt is displayed there directly without unnecessary context switches. If the active VT is running a GUI (X11/Wayland), it safely switches to a newly allocated text VT and returns afterward. * EBUSY Race Condition: The child process now explicitly closes the temporary VT file descriptor before initiating the vt_switch back to the original console. This allows the parent process to safely perform vt_disallocate without encountering EBUSY kernel errors. * Timeout Handling: Replaced the infinite wait loop in request_tty() (tty.c) with a safe 2000ms timeout via can_read(). This prevents the daemon from hanging indefinitely on locked terminals and allowed the removal of error-prone alarm() signal hacks. * Lifecycle Management: Ensured newly allocated dynamic VTs are properly initialized via consinitIO() and reliably deallocated upon daemon exit (lcons_shutdown). Fix epoll EEXIST crash and prevent infinite waits on busy terminals This also addresses two critical edge cases that could cause the blogd daemon to either crash or hang during concurrent or blocked prompt requests. Key changes: * epoll.c: Prevent an `EEXIST` crash in `epoll_addition()`. If a file descriptor is already registered in the watch list, the daemon now gracefully updates it using `EPOLL_CTL_MOD` instead of blindly calling `EPOLL_CTL_ADD`. This makes the socket handling robust against rapid, overlapping client requests. * console.c: Add a 2-second deadline (`alarm(2)`) around the `request_tty()` call inside the password-prompt child process. Previously, if a terminal was exclusively locked (e.g. by an X11 server returning EPERM), the child would fall into an infinite inotify wait-loop. With the timeout, the child now dies cleanly, allowing the parent's reaping logic to properly cancel the prompt and send an ANSWER_ENQ (abort) to the waiting client. ==== bluedevil6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== breeze6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: breeze6-cursors breeze6-decoration breeze6-style - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * breezehelper: Fix asymmetric separators on immutable tabs ==== breeze6-gtk ==== Version update (6.7.2 -> 6.7.3) Subpackages: gtk2-metatheme-breeze6 gtk3-metatheme-breeze6 gtk4-metatheme-breeze6 metatheme-breeze6-common - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== brltty ==== Subpackages: brltty-driver-at-spi2 brltty-driver-brlapi brltty-driver-speech-dispatcher brltty-driver-xwindow libbrlapi0_8 python3-brlapi system-user-brltty xbrlapi - Remove OCaml bindings on 32bit architectures ==== btrfsprogs ==== Version update (7.0 -> 7.1) Subpackages: btrfsprogs-bash-completion btrfsprogs-udev-rules libbtrfs0 libbtrfsutil1 - update to 7.1 * mkfs: * use GET_CSUMS ioctl (if provided by kernel, 7.2) to reuse existing checksums for --rootdir, works with --reflink to avoid reading file data * fix last block handling for reflink * fix handling of incompressible data extents * fix --rootdir size estimation when using hardlinks * fi mkswapfile: add option to specify page size, useful on ARM64 * check: add option to skip qgroup verification to speed up check * in experimental build, use V2 of tree search ioctl, this can use larger buffer * preliminary fscrypt support * enhance filesystem opening modes with more fine-grained support of partially damaged trees and allow to skip non-essential trees * other: * stability and error handling fixes * CI updates * updated tests * documentation updates ==== ca-certificates ==== Version update (2+git20260420.2a8e251 -> 2+git20260717.2e3a23b) - Update to version 2+git20260717.2e3a23b: * Fix for 458d37d, logic got wrong - Update to version 2+git20260708.2380cdb: * Remove duplicate I from help text * Blacken test_update_ca_certificates * Replace backticks in shell scripts * Unify quoting in shell scripts * Refactor to POSIX sh * Reduce slashes in shell paths * Unify indentation style in shell scripts * CI: remove black format check and update actions * CI: create /etc/ca-certificates in the container ==== dav1d ==== Version update (1.5.3 -> 1.5.4) - Update to version 1.5.4 * Switch to external checkasm * Add Armv9.3-A GCS (Guarded Control Stack) support * AArch64: optimize ipred_v, ipred_h and ipred_smooth_* 8bpc functions, and reduce .text size * ARM32: optimize prep_neon * RISC-V: ipred_(dc, h, v, pal) optimizations for 8 and 16bpc, generate_grain_y for 8bpc, and optimizations (prep/put_8tap, 6-tap and copy paths) * Schedule tile tasks for all passes at once, improving threading * Precompute the quantization matrix tables at build time * Move loop-invariant computations out of hot loops ==== discover6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: discover6-backend-flatpak discover6-backend-fwupd discover6-backend-packagekit discover6-notifier - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== dracut ==== Version update (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) - Update to version 110+suse.45.geaec47e4: * fix(systemd-networkd): escape values from DHCP options (bsc#1264833, GHSA-x37p-6hhc-6628) * feat(base): add escape function implementing printf %q * fix(systemd-networkd): get DHCP options values from networkctl * fix(kernel-modules): include xhci-pci-prom21 for early USB ==== drkonqi6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * launcher: do not participate in session management * don't start launcher when not in a graphical session (kde#522477) * excavator: do not try to excavate coredump files that do not exist ==== e2fsprogs ==== Subpackages: libcom_err2 libext2fs2 - Drop obsolete BuildRoot tag and no-op %defattr lines - Package NOTICE as %license unconditionally - Fix scope of the systemd guard around %preun ==== findutils ==== Version update (4.10.0 -> 4.11.0) - Update to 4.11.0. Announcement: https://savannah.gnu.org/news/?id=10912 Most prominent change in behavior: As announced since the release of 4.7.0 (2019) and mandated by POSIX 2024, the behaviour of the -mount option changed: while it was a mere alias for the -xdev option to prevent descending into directories of another device, the -mount option now makes find(1) ignore files on another device, i.e., 'find -mount' will skip the entry of active mount points already. Example, assuming the PROC filesystem is mounted on '/proc': $ find / -mount -path /proc -print $ find / -xdev -path /proc -print /proc - findutils-avoid-crash-system-loop.patch: Remove now-upstream patch. - findutils-xautofs.patch: Refresh. ==== firewalld ==== Version update (2.1.2 -> 2.3.2) Subpackages: firewalld-bash-completion python313-firewall * Fix CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903) [+ 0003-CVE-2026-4948-fix-dbus-setter-authorization.patch] - Update to New Version 2.3.2 * doc(policy): add examples to man page * doc(policies): correct word is asymmetric * fix(doc): dbus: remove links to nonexistent IDs * fix(policy): allow forward ports with ingress zone and egress HOST * fix(server): load firewall rules before claiming dbus * fix(nftables): ipset: add entries from GLib loop when idle * fix(systemd): Requires dbus * fix(nftables): use current pkttype keywords * fix(systemd): use ProtectHome=tmpfs * fix(policy): allow-host-ipv6: allow MLD packets * fix(icmpv6): validate router codes * fix(icmpv6): validate neighbor codes * fix(icmpv6): validate redirect codes * docs(zone): update default zone target description to mention that ICMP is accepted * docs(zone): grammar fixes * docs(zone): mention that the ACCEPT target allows forwarding out of the zone * docs(zone): remove references to specific zone names in description of target attribute * docs: use US spelling of behavior - Update to New Version 2.3.0 -Update to New Version 2.3.0 It also includes all bug fixes since v2.3.0. * feat(policy): add disable flag * feat(client): policy: add disable flag * feat(cli): policy: add disable flag * feat(policy): increase maximum name length to 128 * feat(cli): policy: support setting disable on sets * feat(policy): set: add gateway ==== flatpak-kcm6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * kcm_app-permissions.json: fix BugReportUrl ==== gawk ==== Version update (5.4.0 -> 5.4.1) - update to 5.4.1: * Fix a performance problem in PMA with backing store files 1G or more in size * Fix a bug in gensub() when using MinRX * Unary plus and minus now force their operands to be numeric * Add man page and documentation for the intdiv extension * Enable and update the Georgian translation (ka.po) * Parse time division by zero is no longer a fatal error, but rather a lint warning. Division by zero at runtime remains fatal * Some subtle issues with respect to formatting numeric fields have been fixed * small bug fixes ==== glslang ==== Version update (16.3.0 -> 16.4.0) - Update to release 16.4.0 * Implement `GLSL_EXT_structured_descriptor_heap` with SPIR-V layout generation, heap offset access, buffer references, matrix layout decorations, and correct `readonly`/`writeonly` qualifier propagation for buffer and image descriptors * Fix descriptor heap-bound buffer access to use typed pointers * Omit `NonUniform` decoration when using descriptor heaps, as the SPIR-V spec does not require it * Add `--relax-set-binding-limits` option to allow large `layout(set)` and `layout(binding)` values for descriptor heap-style workflows with sparse set spaces * Reject combined image samplers with `descriptor_heap` * Fix `GL_KHR_compute_shader_derivatives` regressions on shaders using the `GL_NV` variant * Update compute shader derivative rules to allow texture operations with implicit derivatives without extensions, falling back to LoD 0 * New extensions: `GL_EXT_ocp_microscaling_types`, `GL_NV_cooperative_matrix_decode_vector`, `GL_EXT_opacity_micromap_ray_query_mode` and basic support for `GL_NV_desktop_lowp_mediump` ==== gnome-sudoku ==== Version update (50.2.1 -> 50.3) - Update to version 50.3: + Fix game not being cleared up on quit when completed + Fix earmark warnings strike-through not being automatically applied ==== gnutls ==== Subpackages: libgnutls-dane0 libgnutls30 - FIPS: Add NIST SP800-56Brev2 6.4.2.2 check: * Partial public-key validation for RSA OAEP (bsc#1262397) * Add gnutls-FIPS-RSA-OAEP-PK-validation.patch - FIPS: Perform the integrity checks for libleancrypto-fips and libleancrypto with the HMACs provided by the library (bsc#1262399) * Add gnutls-FIPS-HMAC-leancrypto.patch - FIPS: Remove GNUTLS_MAC_SHA1 FIPS self-test (bsc#1262400) * Add gnutls-FIPS-Remove-SHA1-self-test.patch ==== google-noto-fonts ==== Version update (20241201 -> 20260701) Subpackages: google-noto-sans-arabic-fonts google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Drop stale file - Update Source in the spec file to include the download URL - Update to 20260701 * Various updates to the font collection, Too many changes to list * New fonts : - Todhri Fonts (google-noto-serif-todhri-fonts) - Hentaigana Fonts (google-noto-serif-hentaigana-fonts) - Sunuwar Fonts (google-noto-sans-sunuwar-fonts) ==== gpsd ==== - Fix for gpsprof gnuplot command injection via attacker-controlled GPS metadata (CVE-2026-58459 [bsc#1271191]) + 4c06658.patch + 5581ba1.patch + 1a6bb7b.patch ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-arm64-efi-bls grub2-common grub2-snapper-plugin grub2-systemd-sleep-plugin - Backport merged upstream patch * 0001-lvm-allocate-metadata-buffer-from-raw-contents.patch - Drop local patch * grub2-lvm-allocate-metadata-buffer-from-raw-contents.patch - Backport merged upstream patch * 0001-net-http-Check-result-of-grub_netbuff_put-in-http_re.patch * 0002-efinet-Add-structures-for-PXE-messages.patch * 0003-efinet-bootp-add-net_dhcp6-command-supporting-dhcpv6.patch * 0004-grub.texi-Add-net_dhcp6-document.patch * 0005-bootp-Process-DHCPACK-packet-during-HTTP-Boot.patch * 0006-efinet-Configure-network-from-UEFI-device-path.patch * 0007-efinet-Set-DNS-server-from-UEFI-protocol.patch * 0008-kern-efi-efi-Print-URI-and-DNS-device-path-info.patch * 0009-kern-efi-efi-Correct-endianness-in-IPv6-device-path.patch * 0010-bootp-Fix-logical-operator-in-DHCP-option-overload-c.patch - Drop local patch * 0003-bootp-New-net_bootp6-command.patch * 0004-efinet-UEFI-IPv6-PXE-support.patch * 0005-grub.texi-Add-net_bootp6-doument.patch * 0006-bootp-Add-processing-DHCPACK-packet-from-HTTP-Boot.patch * 0007-efinet-Setting-network-from-UEFI-device-path.patch * 0008-efinet-Setting-DNS-server-from-UEFI-protocol.patch - Refreshed patch * 0001-add-support-for-UEFI-network-protocols.patch * grub2-bsc1220338-key_protector-implement-the-blocklist.patch ==== gstreamer-devtools ==== Version update (1.28.4 -> 1.28.5) - Update to version 1.28.5: + No changes, stable versionbump only. ==== gstreamer-plugins-libav ==== Version update (1.28.4 -> 1.28.5) - Update to version 1.28.5: + No changes, stable bump only ==== gtk4 ==== Version update (4.22.4+11 -> 4.22.4+29) Subpackages: gtk4-schema gtk4-tools libgtk-4-1 typelib-1_0-Gtk-4_0 - Update to version 4.22.4+29: + gl: Actually report partial damage + gtkapplication-wayland: Add a missing NULL check when forgetting a window + Fix the build with pango main + Revert "filechooserutils: Stop using pixbufs" + gskvulkanimage: fix building on 32-bit + Updated translations. ==== inkscape ==== Version update (1.4.4+git0.dcaf3e7d9e -> 1.4.4+git2.3454cb1dab) Subpackages: inkscape-extensions-extra inkscape-extensions-gimp - Update to version 1.4.4+git2.3454cb1dab: * update translations - Add fix_build_with_poppler_26.07.patch: + Fix support for poppler >= 26.07 https://gitlab.com/inkscape/inkscape/-/merge_requests/8034 - Adjust _Service: strip +git0 when we're actually on the tag. ==== inn ==== - Properly set %verify(not mode) for files that have their permissions set/adjusted by set_permissions. ==== ipxe ==== Version update (1.21.1+git20250827.61b4585e2 -> 2.0.0+git20260710.58ee55b3c) - Packaging cleanups: - Drop unused fix-i586.patch and the no_aarch64_cc machinery - Version the qemu-ipxe Provides/Obsoletes - Add license files to the qemu subpackage - Single-source the QEMU NIC list in %build - Merge the config/general.h sed calls - Drop obsolete %defattr - Remove unused ipxe.efi directory creation - _service: use mode="manual" instead of the deprecated mode="disabled" - Add ipxe-rpmlintrc to filter the bogus no-binary error - Disable serial. We have -nographic for that, and having both enabled causes the output to be mangled (bsc#1271154). - Update to version 2.0.0+git20260710.58ee55b3c: * [image] Make text-based image data usable by string functions * [xferbuf] Provide an image-backed data transfer buffer * [libc] Add strchrnul() * [hermon] Check for failure from pci_ioremap() * [tls] Retain a reference in the key schedule to the bound identity * [tls] Reject incorrect server names before completing validation * [tls] Guard against resuming from an empty resumption master secret * [tls] Poison initial resumption master secret * [tls] Poison initial key derivation function master secret * [tls] Track and check key schedule state * [tls] Guard against a premature server Finished * [tls] Send closure alert only when we are initiating the closure * [tls] Handle key exchange within key schedule * [cloud] Use "param" command to provide Google metadata request header * [tls] Restructure to use a single key derivation function master secret * [tls] Treat session secret as "resumption master secret" * [virtio] Allow for long delays in processing transmit queue submissions * [virtio] Fix queue size calculations * [tls] Move handshake digest within the scope of the key schedule * [tls] Clarify TLS key schedule function names * [crypto] Define a structure for holding hybrid MD5+SHA1 HMAC keys * [crypto] Make maximum TLS version a configurable option * [crypto] Re-add missing digestInfo prefix for MD5+SHA1 * [build] Use dynamic keyboard map by default in UEFI builds * [crypto] Allow for the construction of fixed-size HMAC keys * [s390x] Add time source based on the architectural Time-of-Day clock * [s390x] Add support for the PRNO TRNG as an entropy source * [s390x] Provide a mechanism for checking installed CPU facilities * [crypto] Remove redundant DHE algorithm * [tls] Use generic key exchange algorithm abstraction for DHE * [crypto] Allocate FFDHE temporary space on demand * [crypto] Allow construction of shared public key to return an error * [crypto] Correct maximum length of FFDHE prime modulus * [crypto] Generalise implementation of Merkle-Damgård hash algorithms * [aqc1xx] Free outstanding receive I/O buffers on close * [aqc1xx] Set netdev->dma for operation with an IOMMU * [http] Remove knowledge of MD5 digest context internal structure * [bnxt] Prevent out-of-bounds memory access * [tls] Centralise pseudorandom data generation * [crypto] Allow for input keying material to overlap output * [crypto] Use private data field for public-key algorithms * [crypto] Allow cipher_setiv() to return an error * [crypto] Use private data field for cipher algorithms * [crypto] Use private data field for digest algorithms * [crypto] Generalise notion of uncompressed elliptic curve points * [crypto] Use private data field for elliptic curve algorithms * [crypto] Use verbs in key exchange method names * [tls] Accept only explicitly supported FFDHE groups * [crypto] Add TLS named groups for FFDHE key exchange algorithms * [tls] Allow for the existence of anonymous named groups * [tls] Prefer X25519 as a key exchange mechanism * [crypto] Provide a mechanism to check FFDHE group parameters * [crypto] Use private data field for key exchange algorithms * [crypto] Add RFC 3526 FFDHE key exchange algorithms * [crypto] Use inline assembly for bigint_grow() and bigint_shrink() * [s390x] Use XOR-in-place to zero small fixed-length blocks * [tls] Rename "named curve" to "named group" * [virtio] Ignore capabilities that describe inaccessible PCI BARs * [settings] Allow system time to be modified via builtin/unixtime * [settings] Allow for writable built-in settings * [scsi] Use data-transfer buffers for data-in and data-out * [s390x] Add optimised TCP/IP checksumming * [ci] Add s390x self-tests * [s390x] Add support for the IBM s390x CPU architecture * [test] Fix RFC 1071 checksum calculation for big-endian targets * [linux] Fix console output on big-endian targets * [efi] Fix parsing of EFI signature lists on big-endian targets * [peerdist] Fix segment identifier constant on big-endian targets * [build] Fix building for big-endian targets * [crypto] Use generic implementations of slow-path big integer functions * [iscsi] Ensure SCSI sense data is present before parsing * [crypto] Add RFC 7919 FFDHE key exchange algorithms * [test] Allow for large values in key exchange self-tests * [test] Verify test vector lengths for key exchange self-tests * [crypto] Remove redundant ECDHE algorithm * [crypto] Remove elliptic curve abstraction for X25519 * [tls] Use generic key exchange algorithm abstraction for ECDHE * [crypto] Provide Weierstrass curves as generic key exchange algorithms * [crypto] Provide X25519 as a generic key exchange algorithm * [crypto] Add a generic concept of a key exchange algorithm * [nfs] Fix off-by-one heap overflow in nfs_uri_symlink() * [linux] Disable implicit linking against libatomic * [tg3] Use updated DMA APIs * [loong64] Port the RISC-V optimised TCP/IP checksum implementation * [riscv] Simplify TCP/IP checksum calculation * [ci] Update action versions to silence GitHub warnings ... changelog too long, skipping 313 lines ... * [libc] Add wcsnlen() ==== java-25-openjdk ==== Version update (25.0.3.0 -> 25.0.4.0) Subpackages: java-25-openjdk-headless - Update to upstream tag jdk-25.0.4+7 (July 2026 CPU) * CVEs + CVE-2026-46968 (bsc#1272224) + CVE-2026-46917 (bsc#1272223) + CVE-2026-47010 (bsc#1272225) + CVE-2026-47021 (bsc#1272227) + CVE-2026-47027 (bsc#1272228) + CVE-2026-60147 (bsc#1272237) + CVE-2026-47059 (bsc#1272235) + CVE-2026-47063 (bsc#1272236) + CVE-2026-41254 (bsc#1264994) * Changes + JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail + JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails + JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails + JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel + JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F + JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'. + JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04 + JDK-8213530: Test java/awt/Modal/ToFront/ /DialogToFrontModeless1Test.java fails on Linux + JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails + JDK-8225787: java/awt/Window/GetScreenLocation/ /GetScreenLocationTest.java fails on Ubuntu + JDK-8241066: Shenandoah: fix or cleanup SH::do_full_collection + JDK-8261743: Shenandoah: enable String deduplication with compact heuristics + JDK-8264851: Shenandoah: Rework control loop mechanics to use timed waits + JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process" + JDK-8279196: Test: jdk/jfr/event/gc/stacktrace/ /TestG1OldAllocationPendingStackTrace.java timed out + JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages + JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!" + JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder + JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder + JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux + JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/ /TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE + JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer) + JDK-8325482: Test that distinct seeds produce distinct traces for compiler stress flags + JDK-8335355: Shenandoah: Fix race condition in gc/shenandoah/ /mxbeans/TestPauseNotifications.java + JDK-8339526: C2: store incorrectly removed for clone() transformed to series of loads/stores + JDK-8340182: Java HttpClient does not follow default retry limit of 3 retries + JDK-8341735: Rewrite the build/AbsPathsInImage.java test to not load the entire file at once + JDK-8344345: test/hotspot/gtest/x86/x86-asmtest.py has trailing whitespaces + JDK-8345631: TestRegionSamplingLogging.java [#]generational-rotation intermittent fails + JDK-8347167: Reduce allocation in com.sun.net.httpserver.Headers::normalize + JDK-8347938: Add Support for the Latest ML-KEM and ML-DSA Private Key Encodings + JDK-8351010: Test java/io/File/GetXSpace.java failed: / usable space 56380809216 > free space 14912244940 + JDK-8352914: Shenandoah: Change definition of ShenandoahSharedValue to int32_t to leverage platform atomics + JDK-8353115: GenShen: mixed evacuation candidate regions need accurate live_data + JDK-8354650: [PPC64] Try to reduce register definitions + JDK-8355339: Test java/io/File/GetCanonicalPath.java failed: The specified network name is no longer available + JDK-8357086: os::xxx functions returning memory size should return size_t + JDK-8358600: Template-Framework Library: Template for TestFramework test class + JDK-8358772: Template-Framework Library: Primitive Types + JDK-8359083: Test jdkCheckHtml.java should report SkippedException rather than report fails when miss tidy + JDK-8359223: HttpClient: Remove leftovers from the SecurityManager cleanup + JDK-8359412: Template-Framework Library: Operations and Expressions + JDK-8359433: The final modifier on Windows L&F internal UI ... changelog too long, skipping 361 lines ... + JDK-8386551: Windows build broken because of MSys2/Make update ==== kactivitymanagerd6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kaddressbook ==== Subpackages: kaddressbook-doc libKPim6AddressbookImportExport6 - Add upstream change: * 0001-Explicitely-check-KF6I18n-dependency-ourselves-using.patch ==== kcalutils ==== Subpackages: libKPim6CalendarUtils6 - Add missing kcalutils-devel dependencies ==== kde-cli-tools6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kde-gtk-config6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: kde-gtk-config6-gtk3 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kdecoration6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libkdecorations3-6 libkdecorations3private2 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kdeplasma6-addons ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * applets/colorpicker: allow space for all previews (kde#522377) * applets/quicklaunch: avoid infinite regression on edge change * Fix colorpicker button sizing (kde#522377) * [Vietnamese Lunar Calendar] Force using Vietnamese translation (kde#521787) * MediaFrame: Set proper sourceSize to both Image instances (kde#521534) * kdeds/kameleon: Disable kameleon by default (kde#521793) ==== kernel-source ==== Version update (7.1.3 -> 7.1.4) Subpackages: kernel-64kb kernel-default - Update patches.kernel.org/7.1.2-002-fuse-re-lock-request-before-replacing-page-cach.patch (bsc#1012628 CVE-2026-53388). - Update patches.kernel.org/7.1.2-005-iio-light-veml6075-add-bounds-check-to-veml6075.patch (bsc#1012628 CVE-2026-53387). - Update patches.kernel.org/7.1.2-006-iio-adc-ti-ads1298-add-bounds-check-to-pga_sett.patch (bsc#1012628 CVE-2026-53386). - Update patches.kernel.org/7.1.2-008-vc_screen-fix-null-ptr-deref-in-vcs_notifier-du.patch (bsc#1012628 CVE-2026-53385). - Update patches.kernel.org/7.1.2-010-serial-8250_dw-unregister-8250-port-if-clk_noti.patch (bsc#1012628 CVE-2026-53384). - Update patches.kernel.org/7.1.2-012-ksmbd-reject-non-VALID-session-in-compound-requ.patch (bsc#1012628 CVE-2026-53383). - Update patches.kernel.org/7.1.2-013-media-vidtv-fix-NULL-pointer-dereference-in-vid.patch (bsc#1012628 CVE-2026-53382). - Update patches.kernel.org/7.1.2-014-virtiofs-fix-UAF-on-submount-umount.patch (bsc#1012628 CVE-2026-53381). - Update patches.kernel.org/7.1.3-001-KVM-x86-Fix-shadow-paging-use-after-free-due-to.patch (bsc#1012628 CVE-2026-53359 bsc#1270059). - Update patches.kernel.org/7.1.3-006-batman-adv-tp_meter-avoid-divide-by-zero-for-de.patch (bsc#1012628 CVE-2026-63836). - Update patches.kernel.org/7.1.3-018-batman-adv-v-prevent-OGM-aggregation-on-disable.patch (bsc#1012628 CVE-2026-63835). - Update patches.kernel.org/7.1.3-019-batman-adv-tp_meter-restrict-number-of-unacked-.patch (bsc#1012628 CVE-2026-63834). - Update patches.kernel.org/7.1.3-028-ipv6-account-for-fraggap-on-the-paged-allocatio.patch (bsc#1012628 CVE-2026-53362 bsc#1269493). - Update patches.kernel.org/7.1.3-029-ipv4-account-for-fraggap-on-the-paged-allocatio.patch (bsc#1012628 CVE-2026-53366 bsc#1271366). - Update patches.kernel.org/7.1.3-030-ntfs3-reject-direct-userspace-writes-to-reserve.patch (bsc#1012628 CVE-2026-63833). - Update patches.kernel.org/7.1.3-031-wifi-mt76-add-wcid-publish-check-in-mt76_sta_ad.patch (bsc#1012628 CVE-2026-63832). - Update patches.kernel.org/7.1.3-032-mac802154-llsec-add-skb_cow_data-before-in-plac.patch (bsc#1012628 CVE-2026-63831). - Update patches.kernel.org/7.1.3-033-net-skmsg-preserve-sg.copy-across-SG-transforms.patch (bsc#1012628 CVE-2026-63830). - Update patches.kernel.org/7.1.3-034-net-ip_gre-require-CAP_NET_ADMIN-in-the-device-.patch (bsc#1012628 CVE-2026-63829). - Update patches.kernel.org/7.1.3-036-apparmor-mediate-the-implicit-connect-of-TCP-fa.patch (bsc#1012628 CVE-2026-63828). - Update patches.kernel.org/7.1.3-037-apparmor-fix-use-after-free-in-rawdata-dedup-lo.patch (bko#221513 bsc#1012628 CVE-2026-63827). - Update patches.kernel.org/7.1.3-039-fbdev-fix-use-after-free-in-store_modes.patch (bsc#1012628 CVE-2026-63826). - Update patches.kernel.org/7.1.3-045-gcov-use-atomic-counter-updates-to-fix-concurre.patch (bsc#1012628 CVE-2026-63825). - Update patches.kernel.org/7.1.3-046-KEYS-fix-overflow-in-keyctl_pkey_params_get_2.patch (bsc#1012628 CVE-2026-63824). - Update patches.kernel.org/7.1.3-047-keys-Pin-request_key_auth-payload-in-instantiat.patch (bsc#1012628 CVE-2026-63823). - Update patches.kernel.org/7.1.3-052-wifi-ath11k-fix-warning-when-unbinding.patch (bsc#1012628 CVE-2026-63822). - Update patches.kernel.org/7.1.3-056-wifi-rtw88-usb-fix-memory-leaks-on-USB-write-fa.patch (bsc#1012628 CVE-2026-63821). - Update patches.kernel.org/7.1.3-060-f2fs-fix-missing-read-bio-submission-on-large-f.patch (bsc#1012628 CVE-2026-63820). - Update patches.kernel.org/7.1.3-063-f2fs-fix-to-do-sanity-check-on-f2fs_get_node_fo.patch (bsc#1012628 CVE-2026-63819). - Update patches.kernel.org/7.1.3-064-f2fs-validate-orphan-inode-entry-count.patch (bsc#1012628 CVE-2026-63818). - Update patches.kernel.org/7.1.3-065-f2fs-validate-compress-cache-inode-only-when-en.patch (bsc#1012628 CVE-2026-63817). - Update patches.kernel.org/7.1.3-066-f2fs-atomic-fix-UAF-issue-on-f2fs_inode_info.at.patch (bsc#1012628 CVE-2026-63816). - Update patches.kernel.org/7.1.3-068-f2fs-bound-i_inline_xattr_size-for-non-inline-x.patch (bsc#1012628 CVE-2026-63815). ... changelog too long, skipping 1114 lines ... - commit 342bd0e ==== kf6-attica ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Attica6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-baloo ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-baloo-file kf6-baloo-imports kf6-baloo-kioslaves kf6-baloo-tools libKF6Baloo6 libKF6Baloo6-lang libKF6BalooEngine6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * CI: Update clang-format job * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-bluez-qt ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-bluez-qt-imports libKF6BluezQt6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-breeze-icons ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6BreezeIcons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Inject version macros to all public headers * Remove duplicated ECMSetupVersion include * Update dependency version to 6.28.0 * Avoid oversized Xcode script input lists * Don't include quiet packages in feature_summary * Update version to 6.28.0 ==== kf6-frameworkintegration ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-frameworkintegration-plugin libKF6Style6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-karchive ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Archive6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kauth ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kauth-lang libKF6AuthCore6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Port to KWaylandExtras::exportToplevel * Update version to 6.28.0 ==== kf6-kbookmarks ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Bookmarks6 libKF6BookmarksWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcalendarcore ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Write custom properties as TEXT or STRING based on their type * Update dependency version to 6.28.0 * Add Android platform calendar plugin * Update version to 6.28.0 ==== kf6-kcmutils ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kcmutils-imports libKF6KCMUtils6 libKF6KCMUtilsCore6 libKF6KCMUtilsQuick6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * KF6KCMUtilsQuick: inject version macros to all public headers * Update dependency version to 6.28.0 * kquickconfigmodule.h: remove unused QQmlComponent include * kcmloadtest: remove unused include * Update version to 6.28.0 ==== kf6-kcodecs ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Codecs6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * [KEncodingProber] Remove some unreachable Reset methods * [KEncodingProber] Reduce scope of some variables * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcolorscheme ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ColorScheme6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcompletion ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Completion6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kconfig ==== Version update (6.27.0 -> 6.28.0) Subpackages: kconf_update6 kf6-kconfig-imports libKF6ConfigCore6 libKF6ConfigGui6 libKF6ConfigQml6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * ksharedconfig: only free the shared config at exit under AddressSanitizer * ksharedconfig: free the per-thread shared config at application exit * Do not launch desktop helper processes on iOS and Android * Do not launch desktop helper processes on iOS * Update version to 6.28.0 ==== kf6-kconfigwidgets ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ConfigWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcontacts ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Contacts6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * CMake config file: search static-build-only dependencies only on condition * Update version to 6.28.0 ==== kf6-kcoreaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kcoreaddons-imports libKF6CoreAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * KMemoryInfo: add basic GNU/Hurd support * KDirWatch_UnitTest: fix memory leaks * KFileSystemType: add custom determineFileSystemTypeImpl for Hurd * Switch to ECMGenerateExportHeader generating C++ standard attributes * aboutdata: Also fill componentName from AppStream data * Expose basic KSandbox properties to QML * Find AppStream files on Android * fix Clang-Tidy: Method 'test_locking' can be made static * fix Clang-Tidy: Static member accessed through instance * fix Clang-Tidy: Method 'test_fileStaleFiles' can be made static * aboutdata: Fix retrieving untranslated release notes * Update version to 6.28.0 ==== kf6-kcrash ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Crash6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kdav ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6DAV6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Fix caldavprotocol color argb formatting * Update version to 6.28.0 ==== kf6-kdbusaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kdbusaddons-tools libKF6DBusAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kdeclarative ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kdeclarative-imports libKF6CalendarEvents6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kded ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Disable startup notification for kded * Update version to 6.28.0 ==== kf6-kdesu ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Su6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kdnssd ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Correctly track Avahi service types * Add basic service browser example * Update version to 6.28.0 ==== kf6-kdoctools ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6DocTools6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kfilemetadata ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6FileMetaData3 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * OSS-Fuzz: serialize AFL fuzzer builds * Integrate KFileMetaData into OSS-Fuzz * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kglobalaccel ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6GlobalAccel6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kguiaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kguiaddons-imports libKF6GuiAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Use iOS-compatible platform and URL handling * Update version to 6.28.0 ==== kf6-kholidays ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kholidays-imports libKF6Holidays6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * holiday_et_am - fix region name * holidays: Add Ethiopian holidays (et_en, et_am) * Updated Croatian holidays as of 2026. * fix occurrence of Mother's Day and Father's Day in Slovakia * Update version to 6.28.0 ==== kf6-ki18n ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-ki18n-imports libKF6I18n6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * KTranscript: Use Q_APPLICATION_STATIC for impl (kde#520512) * fix: use system locale as fallback for macOS app bundle * klocalizedcontext: correctly place deprecation attribute after class keyword * Update version to 6.28.0 ==== kf6-kiconthemes ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kiconthemes-imports libKF6IconThemes6 libKF6IconWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Disable desktop-only KIconThemes tools and plugin on iOS * Update version to 6.28.0 ==== kf6-kidletime ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kidletime-plugins libKF6IdleTime6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Fully port to ecm_qt_declare_logging_category * Fix debug category name kf5idletime_wayland It's not a kf5 * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kimageformats ==== Version update (6.27.0 -> 6.28.0) - Add upstream change (kde#523105) * 0001-HEIF-keep-reader-callback-table-alive.patch - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * EXR: added support for additional metadata * Update dependency version to 6.28.0 * JP2: limits the maximum number of channels to the global value defined * ossfuzz: replace INITGUID with __ANSI__ * JXR: remove INITGUID define * ossfuzz: update libaom and libavif * HEIF: use heif_reader for random access devices * avif: If we only have single image, return false at jumpToNextImage (kde#521200) * Added limit to maximum number of channels * Improve buffer memory management * Update version to 6.28.0 ==== kf6-kio ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6KIO6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Too many changes since 6.27.0, only listing bugfixes: * mkdirjob: add setOwnership to set uid/gid (kde#517067) * deletejob: report files removed before a partial failure (kde#424545) * kfileitem: do not read .directory on slow filesystems in iconName (kde#519189) * widgets/kfileitem: center small icons in grid view (kde#520659) ==== kf6-kirigami ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kirigami-imports libKirigamiPlatform6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Action: only enable alternateShortcut when the action is enabled * FormEntry: fix binding loop * Update dependency version to 6.28.0 * FormEntry: always be hoverEnabled * forms: Dont put items at fractional positions * AbstractApplicationWindow: Fix applications that use an header item (kde#521552) * primitives: Base Icon's node size on icon size, not item size (kde#391315) * AlignedSize: fix docs * controls/private/DefaultChipBackground.qml: remove wrong colorSet * Update version to 6.28.0 ==== kf6-kitemmodels ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kitemmodels-imports libKF6ItemModels6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kitemviews ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ItemViews6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kjobwidgets ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6JobWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-knewstuff ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-knewstuff-imports libKF6NewStuffCore6 libKF6NewStuffWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-knotifications ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-knotifications-imports libKF6Notifications6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * android: Modernize JNI code * Update version to 6.28.0 ==== kf6-knotifyconfig ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6NotifyConfig6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kpackage ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Package6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kparts ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Parts6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Dont copy kaboutdata into khelpmenu * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kplotting ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kpty ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Pty6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kquickcharts ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-krunner ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Runner6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * KRunner::ResultsModel: remove unneeded QIcon include * Update version to 6.28.0 ==== kf6-kservice ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Service6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * services/kservicegroup: include storageId in sorting key (kde#516802) * Update version to 6.28.0 ==== kf6-kstatusnotifieritem ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6StatusNotifierItem6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-ksvg ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-ksvg-imports libKF6Svg6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * KF6Svg: drop publically unused KF6::ConfigCore from public link interface * KSvg::ImageSet: remove unneeded KSharedConfig include * Update version to 6.28.0 ==== kf6-ktexteditor ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6TextEditor6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Fix typo in settings (kde#https://bugs.kde.org/522337) * vi-mode: Fix reversed mouse selection range (kde#454417) * vi-mode: Fix command range for mouse selection (kde#454312) * vi-mode: Implement read-only registers: search and command * Update dependency version to 6.28.0 * vi-mode: Fix register for last inserted text * vi-mode: Simplify validation of register characters * Change setting wording * Word cursor movement: Only stop at underscores in camel cursor * vi-mode: Shorten names for VI modes on the status bar * vi-mode: Allow count for multiple undo/redo * add editor color theme preview icon to config page combo boxes * show preview icons for editor color themes * themeconfig: Set file type instead of highlighting mode * Update version to 6.28.0 ==== kf6-ktexttemplate ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6TextTemplate6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-ktextwidgets ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kunitconversion ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6UnitConversion6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * ADD: Wh (watt-hour) energy conversion * Update version to 6.28.0 ==== kf6-kuserfeedback ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kuserfeedback-imports kf6-kuserfeedback-lang libKF6UserFeedbackCore6 libKF6UserFeedbackWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Inject version macros to all public headers * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kwallet ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kwallet-tools kwalletd6 libKF6Wallet6 libKF6WalletBackend6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * fix(ksecretd): reject invalid UTF-8 in `SetSecret`/`CreateItem` instead of silent corruption * Update version to 6.28.0 ==== kf6-kwidgetsaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6WidgetsAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * KJobWidgets: place deprecation attribute standard-type-clang-compatible * Update dependency version to 6.28.0 * Exclude KMimeTypeEditor from iOS builds * Update version to 6.28.0 ==== kf6-kwindowsystem ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kwindowsystem-imports libKF6WindowSystem6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * platforms/xcb: Handle Xwayland restarts better * platforms/xcb: Manage atoms with a shared pointer * Update dependency version to 6.28.0 * Restore guard for null window in exportWindow (kde#521241) * Provide a future based API to export a window * Update version to 6.28.0 ==== kf6-kxmlgui ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6XmlGui6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Support modifier-only shortcuts in KShortcutsEditor (kde#518302) * Refactor internal KShortcutsEditor bits to support shortcut patterns * don't call moveValuesTo on invalid source (kde#520556) * Update version to 6.28.0 ==== kf6-modemmanager-qt ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ModemManagerQt6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-networkmanager-qt ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-networkmanager-qt-imports libKF6NetworkManagerQt6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-prison ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-prison-imports libKF6Prison6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Fix documentation syntax * Update dependency version to 6.28.0 * Add support for rendering ITF and Codabar barcodes * Update version to 6.28.0 ==== kf6-purpose ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-purpose-services libKF6Purpose6 libKF6PurposeWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Fix constraints not being evaluated correctly (kde#521138) * Update version to 6.28.0 ==== kf6-qqc2-desktop-style ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * ComboBox: Fix width calculation in some situations (kde#522453) * Update dependency version to 6.28.0 * Set implicitWidth for ComboBox popups * Update version to 6.28.0 ==== kf6-solid ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-solid-tools libKF6Solid6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * windows: do not query drives without a reachable volume * Allow discovery of Samba shares under BSD. * fix: add missing ARM CPU part numbers from util-linux lscpu-arm.c * QDoc fixes * Update version to 6.28.0 ==== kf6-sonnet ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-sonnet-imports libKF6SonnetCore6 libKF6SonnetUi6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-syndication ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Syndication6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-syntax-highlighting ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-syntax-highlighting-imports libKF6SyntaxHighlighting6 - Add upstream fix: * 0001-Fix-listening-for-language-changes-just-react-on-the.patch - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Invalidate cached translations when language changes * Powershell: fix parentheses matching in command substitution with function calls (kde#519774) * Powershell: fix Numeric Suffix when the previous line ends with number * Update dependency version to 6.28.0 * make build reproducable * adapt refs to fixed scope highlighting * Fixes formatting for scopes containing types like 'std::char' or 'std::str::Bytes' which contain 'str' and 'char' * systemd unit: update to systemd v261 * YAML: fix some bad indentation detection, add Timestamp and fix some defects * Fish: end keyword of function as Keyword instead of Control Flow * Fish: use the "Function Doc" style for strings with --description followed by spaces (kde#521369) * Theme: Add preview icon * Zsh: remove String Transl. which does not exist in zsh * Bash: fix String Transl. highlingting (was a String DoubleQ) * Bash: fix context pop of brace command substitution (${ cmd}/${|cmd}) (kde#521069) * Update version to 6.28.0 ==== kf6-threadweaver ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kgamma6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kglobalacceld6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKGlobalAccelD6-0 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kinfocenter6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kirigami-addons6 ==== Version update (1.12.1 -> 1.13.0) Subpackages: libKirigamiAddonsComponents6 libKirigamiAddonsStatefulApp6 libKirigamiApp6 - Update to 1.13.0 * Fix reference error in about page program icon * Avoid unneeded KCoreAddons version include * FormComboBoxDelegate: Forward more ComboBox APIs * Add a button to reset a time picker back to the current time * Enable KCrash integration on Android * AboutPage: Sync with Kirigami changes to program icon * Replace image in qml-check-i18n job * FormDelegateBackground: Use Kirigami.Units.cornerRadius * Do not explicitly link against Qt6::QuickEffect in onboarding module * Add explicit linkage against Qt6::QuickEffects for apps using the onboarding module * Add org.kde.kirigamiaddons.onboarding module documentation * Fix org.kde.kirigamiaddons.onboarding issues on Android/iOS * Make KCrash and Linux sandbox integration optional on iOS * FormSpinBoxDelegate: Alias more properties and signals * Add new org.kde.kirigamiaddons.onboarding module * KirigamiAppDefaults: Clean up ifdefs * Require Qt 6.9 for unconditional use of the SafeArea API * Form*FieldDelegate: Fix text property not yet updated on signal trigger * Form*FieldDelegate: Add more aliases to input field * FormCard: Fix implicitWidth * Add missing QML module dependencies to Qt.labs.qmlmodels ==== kmenuedit6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== knighttime6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKNightTime0 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kpipewire6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: kpipewire6-imports libKPipeWire6 libKPipeWireDmaBuf6 libKPipeWireRecord6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Restore binary compatibility ==== kscreen6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Take locale into account when formatting refresh rate ==== kscreenlocker6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKScreenLocker6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== ksshaskpass6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== ksystemstats6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Fix crashes in KSysGuard::SensorObject::id() * Guard ksystemstats_intel_helper against path traversal - Drop patches, now upstream: * 0001-Guard-ksystemstats_intel_helper-against-path-travers.patch ==== kwayland-integration6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kwayland6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKWaylandClient6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kwin6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libkwin6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * wayland: Implement wl_fixes v2 * wayland/tools: Make generated globals set "withdrawn" callbacks * workspace: remove sleep inhibitor if the dpms animation is canceled (kde#523001) * pointer_input: fix waking up screens that temporarily disconnect during dpms (kde#518271) * vulkan/vulkan_device: use a graphics queue instead of transfer * opengl/eglcontext: always bind the desired EGL API before context creation (kde#521742) * backends/drm: allow triple buffering on Nvidia again * autotests: Rework how EI events are drained * effects: Forward tablet events to OffscreenQuickView (kde#468396,kde#522677) * core/drmdevice: also print the error when opening a render node fails * autotests/integration/drm_test: filter out broken VM drivers * autotests/integration/drm_test: fix cases not currently tested in CI * autotests/integration: use framebuffer IDs for comparing buffers * opengl/icc_shader: don't use GL_TEXTURE_1D * plugins/overview: fix middle click with touchpads (kde#522015) * compositor: also set dmabuf feedback if buffer import fails * core/gpumanager: fix the Vulkan device check * libinput: Fix Device::serializeMatrix (kde#521464) * dpmsinputeventfilter: also wake screens on laptop lid open (kde#466748) * backends/drm: apply the amdgpu workaround in both matchPipeline methods * backends/drm: match color pipelines already in importScanoutBuffer (kde#522075) * compositor: attempt direct scanout before preparing rendering * plugins/screencast: in testCreateDmaBuf, also create a framebuffer * wayland/alphamodifier: track the per-surface object * Avoid updating shape when an override-redirect window is moved ==== kwin6-x11 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libkwin-x11-6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== layer-shell-qt6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libLayerShellQtInterface6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libdrm ==== Subpackages: libdrm2 libdrm_amdgpu1 libdrm_nouveau2 libdrm_radeon1 - add upstream signing key and validate source signature ==== libgit2 ==== Version update (1.9.4 -> 1.9.6) - update to 1.9.6: * load_known_hosts: do not fail if homedir is invalid - includes changes from 1.9.5: * Fix for blame error handling on hunk creation failures * CVE-2026-53586: give auth callback current host (boo#1271694) * CVE-2026-53587: heap out-of-bounds read in set_data (boo#1271695) * CVE-2026-53585: Unbounded Memory Allocation via Delta Object Result-Size Header (boo#1271696) * CVE-2026-53584: submodule: check paths for escaping (boo#1271697) * CVE-2026-53583: inverted IP SubjectAltName comparison in OpenSSL backend (boo#1271698) ==== libkscreen6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKF6Screen8 libKF6ScreenDpms8 libkscreen6-plugin - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libksysguard6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: ksysguardsystemstats6-data libKSysGuardSystemStats2 libksysguard6-imports libksysguard6-plugins - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libplasma6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasma7 libplasma6-components libplasma6-desktoptheme - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libseccomp ==== - Skip tests/52-basic-load.py under qemu emulation ==== libsoup ==== Subpackages: libsoup-3_0-0 typelib-1_0-Soup-3_0 - Rename libsoup-CVE-2026-0716.patch to libsoup-CVE-2026-12478.patch to reflect the new CVE assignment (bsc#1271401 CVE-2026-12478). - Add fix-samsung-tv-playback.patch: Update the content length decimal value when encoding is set to SOUP_ENCODING_CONTENT_LENGTH - Refresh patches with quilt. ==== libtool ==== Version update (2.5.4 -> 2.6.2) - update to version 2.6.2 - Add a new tool, libtool-next-version, to guide users through updating library versions. - Add tagging for Objective-C and Objective-C++, OBJC and OBJCXX. - Increase 5 digit limit on revision value for libraries to 19 digits, which is referencing Unix epoch time in nanoseconds. - Add configuration options to choose whether to use '-nostdlib' to let the compiler frontend decide what standard libraries to link when building C++ shared libraries and modules, --enable-cxx-stdlib and - -disable-cxx-stdlib. - Allow statically linking GCC and Clang compiler support libraries into shared libraries. - Add linking clang_rt static archives compiler internal libraries by their absolute path. - Pass '--target' architecture flag for Clang. - Pass 'resource-dir=*' flag for Clang. - Recognise explicit shared library arguments when linking dependency libraries to a shared library, like exists when linking a program. ==== libupnp ==== Version update (2.0.2 -> 22.0.4) - Update to release 22.0.4 * Raise default SOAP content-length limit from 16K to 64K bytes. * Avoid potential double-unlocking of `GlobalHndRWLock` in function `UpnpSetContentLength`. * Stop resolving DNS during URI/GENA callback parsing [CWE-400 class issue]. * Removed deprecated function `UpnpSetContentLength`. ==== libyui ==== Version update (4.7.6 -> 4.7.7) - Fix build against GCC 16 (boo#1243674#c5, boo#1256972): + ncurses: Fix wchar_t stream insertion + Qt: Fix deprecated enum conversion in YQWizard + ncurses-pkg: remove unused-but-set variable 'idx' + ncurses-pkg: Replace deprecated SolvAttr provides and requires + qt-pkg: remove unused-but-set variables - 4.7.7 - Remove the -std=gnu++17 workaround in favor of the upcoming clean fix (boo#1256972) ==== libyui-ncurses ==== Version update (4.7.6 -> 4.7.7) - Fix build against GCC 16 (boo#1243674#c5, boo#1256972): + ncurses: Fix wchar_t stream insertion + Qt: Fix deprecated enum conversion in YQWizard + ncurses-pkg: remove unused-but-set variable 'idx' + ncurses-pkg: Replace deprecated SolvAttr provides and requires + qt-pkg: remove unused-but-set variables - 4.7.7 - Remove the -std=gnu++17 workaround in favor of the upcoming clean fix (boo#1256972) ==== libyui-ncurses-pkg ==== Version update (4.7.6 -> 4.7.7) - Fix build against GCC 16 (boo#1243674#c5, boo#1256972): + ncurses: Fix wchar_t stream insertion + Qt: Fix deprecated enum conversion in YQWizard + ncurses-pkg: remove unused-but-set variable 'idx' + ncurses-pkg: Replace deprecated SolvAttr provides and requires + qt-pkg: remove unused-but-set variables - 4.7.7 - Remove the -std=gnu++17 workaround in favor of the upcoming clean fix (boo#1256972) ==== libyui-qt ==== Version update (4.7.6 -> 4.7.7) - Fix build against GCC 16 (boo#1243674#c5, boo#1256972): + ncurses: Fix wchar_t stream insertion + Qt: Fix deprecated enum conversion in YQWizard + ncurses-pkg: remove unused-but-set variable 'idx' + ncurses-pkg: Replace deprecated SolvAttr provides and requires + qt-pkg: remove unused-but-set variables - 4.7.7 - Remove the -std=gnu++17 workaround in favor of the upcoming clean fix (boo#1256972) ==== libyui-qt-graph ==== Version update (4.7.6 -> 4.7.7) - Fix build against GCC 16 (boo#1243674#c5, boo#1256972): + ncurses: Fix wchar_t stream insertion + Qt: Fix deprecated enum conversion in YQWizard + ncurses-pkg: remove unused-but-set variable 'idx' + ncurses-pkg: Replace deprecated SolvAttr provides and requires + qt-pkg: remove unused-but-set variables - 4.7.7 - Remove the -std=gnu++17 workaround in favor of the upcoming clean fix (boo#1256972) ==== libyui-qt-pkg ==== Version update (4.7.6 -> 4.7.7) - Fix build against GCC 16 (boo#1243674#c5, boo#1256972): + ncurses: Fix wchar_t stream insertion + Qt: Fix deprecated enum conversion in YQWizard + ncurses-pkg: remove unused-but-set variable 'idx' + ncurses-pkg: Replace deprecated SolvAttr provides and requires + qt-pkg: remove unused-but-set variables - 4.7.7 - Remove the -std=gnu++17 workaround in favor of the upcoming clean fix (boo#1256972) ==== libzypp ==== Version update (17.38.13 -> 17.38.14) - zypp.conf: add solver.NoUpdateProvide (default: false) option. In general, packages that obsolete another package are treated as update candidates for the obsoleted package. However, SUSE-specific update rules prefer candidates that also explicitly 'provide' the obsoleted package. Sometimes it is necessary or helpful to disable this rule. (may help in bsc#1261038) - Use HttpHeader class for defining host specific http headers (bsc#1268321) - Compile and link with -fPIE to build on sparc64 (fixes #742) - version 17.38.14 (35) ==== milou6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== mozilla-nss ==== Version update (3.124 -> 3.125) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.125 * no public releasenotes yet ==== ngtcp2 ==== Version update (1.22.1 -> 1.24.0) Subpackages: libngtcp2-16 libngtcp2_crypto_gnutls8 libngtcp2_crypto_ossl0 - Update to 1.24.0: * crypto: Add openssl libs to cryptotest * Add --disable-crypto configure option * crypto: Add ngtcp2_crypto_ossl_free * examples: Avoid the deprecated nghttp3 APIs * lib: Add recv_stop_sending callback * lib: Add ngtcp2_conn_set_max_stream_data_thresh * lib: Tweak ngtcp2_conn_set_max_stream_data_thresh * Remove max stream data thresh * Rewrite window filter from scratch * lib: Tweak app-limited detection * lib: Simplify app-limited conditions * Bump openssl to v4.0.1 * Bump boringssl * Bump aws-lc to v5.1.0 * Bump picotls * Bump wolfssl to v5.9.2-stable - Update to 1.23.0: * log: Faster logging * Use ULL consistently * Transit to closing state when sending application close * Specify QualifierOrder * Provide generic ngtcp2_max and ngtcp2_min * Add ngtcp2_secure_clear * Clear sensitive secrets and keys after use * Add const version * crypto: Add tests for token validation * Add const and remove duplicated code * Remove stale function declarations * crypto: Deal with overflow when computing token timeout * build(deps): bump actions/github-script from 8 to 9 * Revert "fix: prevent max_idle_timeout multiplication overflow in transport params decode" * Deal with large max_idle_timeout that could overflow in computation * Fix qlog params set stack overflow * Log enhancement * Bump LibreSSL to v4.3.1 by @nak3 in #2161 * pq: Adopt designated initializers * Add missing initialization for fields that are not used for CRYPTO * rst: Rename TCP centric variable names * bbr: Cap maximum drain rounds * GHA: Avoid azure Ubuntu mirror * Bump openssl to v4.0.0 * Bump boringssl * Bump picotls * Bump wolfssl to v5.9.1-stable * Bump aws-lc to v1.73.0 * Bump wolfssl to v5.9.1-stable in interop Dockerfile * lib: Apply absolute upper bound against CRYPTO data offset * Adopt sphinx version-add and version-deprecated directives * ppe: Robust ngtcp2_ppe_padding_size * ppe: Ensure packet protection sample with ngtcp2_ppe_dgram_padding_size * cubic: Add missing is_cwnd_limited reset after exiting slow start * Make bitwise operations robust * Make all private hex constants unsigned * lib: Ensure that unidirectional stream shutdown flags properly set * More unsigned hex integer literals * Fix strict aliasing issue in ngtcp2_get_varint * Net cleanup * Bump boringssl * Bump picotls * Bump libressl to v4.3.2 * Consider static const if possible ==== ntfs-3g_ntfsprogs ==== Subpackages: libntfs-3g89 ntfs-3g ntfsprogs - Adding patch bundle from upstream (download.tuxera.com/opensource) re:cve_2026-04 for v2022.10.3 * bsc#1271104 -> 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch * bsc#1271102 -> 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch * bsc#1271103 -> 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch * bsc#1271105 -> 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch * bsc#1271107 -> 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch * bsc#1271106 -> 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch * bsc#1271108 -> 7_ntfs-3g_2022.10.3-CVE-2026-46572.patch - This file is identical to 3_...42617.patch * bsc#1271109 -> 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch * bsc#1271110 -> 9_ntfs-3g_2022.10.3-CVE-2026-56136.patch - This file is identical to 3_...42617.patch ==== ocean-sound-theme6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== open-iscsi ==== Subpackages: iscsiuio libopeniscsiusr0 - Update to version 2.1.12.suse+0.8f77cf16: * Preparing for version 2.1.12 (#536) * Fix security issues recently discovered by Keith at Linneman Labs (#535) (CVE-2026-44943 and CVE-2026-44944) * iscsi-init.service: Use iscsi-gen-initiatorname * iscsi-gen-initiatorname use @IQN_PREFIX@ as default * avoid possible double free of found in idbm_rec_update_param (#528) * iscsi: validate interface IP against target address family (#527) ==== open-vm-tools ==== Subpackages: libvmtools0 open-vm-tools-desktop - Remove all dependencies on update-desktop-files - open-vm-tools (PED-15231) Remove BuildRequires: update-desktop-files and %suse_update_desktop_file vmware-user-autostart from the spec file. ==== openSUSE-release ==== Version update (20260714 -> 20260724) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openssl-3 ==== Subpackages: libopenssl3 - Security fix: (bsc#1271712) * "HollowByte" DoS via attacker-controlled memory allocation. * Grow the init_buf incrementally as we receive data. * Add openssl-HollowByte.patch ==== pam_kwallet6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: pam_kwallet6-common - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== patterns-base ==== Subpackages: patterns-base-apparmor patterns-base-base patterns-base-basesystem patterns-base-basic_desktop patterns-base-console patterns-base-enhanced_base patterns-base-minimal_base patterns-base-selinux patterns-base-sw_management patterns-base-x11 patterns-base-x11_enhanced - Suggest sudo-rpm to give the solver a hint to prefer sudo.rpm over alternative dropins [bsc#1267899] ==== perl ==== Version update (5.42.1 -> 5.44.0) Subpackages: perl-base - update to 5.44.0 * support named parameters in signatures * support aliased refs in mult-var foreach * enhanced /xx regexp pattern modifier * unicode 17.0 is supported * use of getentropy() for PRNG initialization * refreshed patches: perl-HiRes.t-timeout.diff ==== perl-Cpanel-JSON-XS ==== Version update (4.420.0 -> 4.430.0) - updated to 4.430.0 (4.43) see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes 4.43 2026-07-18 (rurban) - Fix canonical sort: compare by UTF-16 code units per RFC 8785 (GH #248, leont) - Fix canonical sort on Perl 5.8-5.18: utf16_cmp now always attempts UTF-8 decoding instead of checking SvUTF8 flag, since older Perls may store valid UTF-8 hash keys without the flag set. - Fix quadmath encode dropping ".0" for large floats (GH #246, reported by Tux). The .0 guard condition that suppressed appending for NV values > UV_MAX was incorrect on high-precision FP (quadmath, 128-bit long double on arm64) where %g uses fixed-point notation for values like 1.01e30. Guarded with #if NV_DIG < 31 to skip only on double/80-bit-ld where %g naturally uses %e for large values. ==== perl-HTTP-Date ==== Version update (6.70.0 -> 6.80.0) - updated to 6.80.0 (6.08) see /usr/share/doc/packages/perl-HTTP-Date/Changes 6.08 2026-07-09 02:04:21Z - [SECURITY] Reject input longer than 64 characters in parse_date() to prevent quadratic regex backtracking (a denial of service) on hostile date strings. Fixes CVE-2026-14741. (Olaf Alders) bsc#1271705 ==== permissions ==== Version update (1699_20260707 -> 1699_20260715) Subpackages: permctl permissions-config - Update to version 1699_20260715: * profiles: add cap_net_raw for ttl (bsc#1270714) ==== pipewire ==== Version update (1.6.7 -> 1.6.8) Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-jack pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Update to version 1.6.8: * This is a bugfix release that is API and ABI compatible with the previous 1.6.x releases. * Highlights - Fix a data race in JACK that could cause lost MIDI events in ardour. - Fix some unbounded memory allocations. - Various small fixes. * PipeWire - Avoid some graph recalcs, which fixes a bug when suspending a node while it is active. * Modules - Do Content-Length and allocation check in RAOP to avoid OOM errors. - Fix a potential memory leak in the error path of client-node. (#5348 (closed)) * SPA - Fix filter-graph dynamic graph updates. - Avoid 100% when unplugging a card. - Fix filter-graph volumes when the filter is loaded inside a node with hardware volume. (#5344 (closed)) - Add normalize and latency options to the SOFA filter. (#5322) * Bluetooth - Fix a potential leak when transport fails to start. * Pulse-server - Avoid stack exhaustion via unbounded alloca. * JACK - Fix a data race in jack_port_get_buffer() when called from concurrent threads, like in ardour. (#5324 (closed)) * GStreamer - Skip invalid crop metadata. - Avoid crash because metadata listener was registered twice. ==== plasma5support6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasma5Support6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-activities ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasmaActivities7 plasma6-activities-imports - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-activities-stats ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasmaActivitiesStats1 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-browser-integration ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-desktop ==== Version update (6.7.2 -> 6.7.3) Subpackages: plasma6-desktop-emojier plasma6-kimpanel-ibus - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * kcms/mouse: actually disable if there is only one device * applets/kicker: fix runner list keyboard navigation * kcms/libkwindevices: Fix serializeMatrix serializing in the wrong order ==== plasma6-disks ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-integration ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * qt6: Skip loading palettes when widget style changes ==== plasma6-nm ==== Version update (6.7.2 -> 6.7.3) Subpackages: plasma6-nm-openconnect plasma6-nm-openvpn plasma6-nm-pptp plasma6-nm-vpnc - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-openSUSE ==== Subpackages: plasma6-branding-openSUSE plasma6-sddm-theme-openSUSE plasma6-theme-openSUSE - Update to 6.7.3 ==== plasma6-pa ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-print-manager ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * kcm: Use Kirigami.StyleHints.showFramedBackground for ScrollView ==== plasma6-systemmonitor ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-thunderbolt ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - No code changes since 6.7.2 ==== plasma6-workspace ==== Version update (6.7.2 -> 6.7.3) Subpackages: plasma6-session plasma6-session-x11 plasma6-workspace-libs sddm-qt6-branding-openSUSE - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * applets/kicker: Fix counting of m_queryingModels in RunnerModel * runners/services: handle malformed .desktop file names better * applets/kicker: return empty url for systemmodel * components/calendar: fix use-after-free of shared calendar event plugins (kde#520465) * kcm_soundtheme: fix preview sounds not playing (kde#521699) * libkworkspace: make sure outputOrderChanged() is always triggered (kde#518058) * klipper: fix spacing on shortcuts configuration page * kcm_nightlight.json, kcm_notifications.json: fix BugReportUrl * startkde: Log the global theme that gets applied * applets/digital-clock: fix timezone offset (kde#522037) * Klipper: Fix spacing on the action configuration page ==== policycoreutils ==== Subpackages: policycoreutils-python-utils python313-policycoreutils - Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645) - can be dropped once "policycoreutils/scripts/fixfiles: drop /tmp cleanup" is in the upstream release - Add patch: 1271645-drop-tmp-cleanup.patch ==== polkit ==== Subpackages: libpolkit-agent-1-0 libpolkit-gobject-1-0 pkexec typelib-1_0-Polkit-1_0 - pkexec: add provides pkexec-rpm to be able to give the solver a hint that this is the real pkexec.rpm [bsc#1267899] ==== polkit-kde-agent-6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== poppler ==== Version update (26.06.0 -> 26.07.0) Subpackages: libpoppler-cpp3 libpoppler-glib8 poppler-tools - Update to version 26.07.0: + core: * Remove deprecated DCT and JPX decoders. * Fix signature regression in some cases. * Fix added annotations getting lost in some cases. * GPG based signature improvements. * Internal code improvements. * Fix crashes in malformed documents. + utils: pdfinfo: sanitize output. + cpp: Add render_hint::ignore_paper_color to allow transparent paper. + glib: construct PopplerPage::mutex (fixes crash on macOS). + qt5: Fix crash in some signature operations. + qt6: Fix crash in some signature operations. - Bump poppler_sover to 162 following upstream changes. ==== poppler-qt6 ==== Version update (26.06.0 -> 26.07.0) - Update to version 26.07.0: + core: * Remove deprecated DCT and JPX decoders. * Fix signature regression in some cases. * Fix added annotations getting lost in some cases. * GPG based signature improvements. * Internal code improvements. * Fix crashes in malformed documents. + utils: pdfinfo: sanitize output. + cpp: Add render_hint::ignore_paper_color to allow transparent paper. + glib: construct PopplerPage::mutex (fixes crash on macOS). + qt5: Fix crash in some signature operations. + qt6: Fix crash in some signature operations. - Bump poppler_sover to 162 following upstream changes. ==== powerdevil6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * BrightnessItem: only do slider->Upower when dragging the slider ==== python-click ==== Version update (8.4.1 -> 8.4.2) - Update to 8.4.2 * Fix Fish shell completion broken in 8.4.0 by #3126. Newlines and tabs in option help text are now escaped, keeping the original completion format while still supporting multi-line help. * Deprecated commands and options with empty or missing help text no longer render a stray leading space before the (DEPRECATED) label. * A Group with invoke_without_command=True marks its subcommand as optional in the usage help, showing [COMMAND] instead of COMMAND. * echo_via_pager flushes after each write, so passing a generator streams output to the pager incrementally instead of staying hidden until the pipe buffer fills. * Fix CLI usage symopsis for optional arguments producing double square brackets whose type already brackets their metavar. * version_option() resolves a package_name that does not match an installed distribution as an import (top-level module) name via importlib.metadata.packages_distributions(). ==== python-numpy ==== Version update (2.4.4 -> 2.4.6) - Update to 2.4.6 * Return rank 0 for empty matrices in matrix_rank * fix heap buffer overflow in timedelta to string casts * fix memory leak in np.zeros when fill-zero loop raises * Don’t call INCREF/DECREF on descr in NpyStringAcquireAllocator ==== python-pyasn1 ==== Version update (0.6.3 -> 0.6.4) - Update to 0.6.4 (fixes CVE-2026-59884 (bsc#1271464), CVE-2026-59885 (bsc#1271465), CVE-2026-59886 (bsc#1271466)) * CVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time complexity in the OBJECT IDENTIFIER and RELATIVE-OID decoders. A small crafted substrate encoding many arcs could consume excessive CPU. Arcs are now accumulated in linear time; decoded values are unchanged * CVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag IDs to 20 octets (140 bits), matching the OID arc limit introduced in 0.6.2. Unbounded tag IDs allowed a crafted substrate to consume excessive CPU and memory; longer tag IDs are now rejected with PyAsn1Error. Also fixed Tag and TagSet repr() failing on huge tag IDs due to the integer-to-string conversion limit * CVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and CPU consumption in Real.__float__() for values with large base-10 exponents. Conversion no longer materializes huge intermediate integers; values too large to represent as a Python float raise OverflowError promptly, and prettyPrint() renders them as '' as before. Also fixed base-10 mantissa normalization to use exact integer arithmetic; mantissas larger than 2**53 could previously lose precision through float division * Pinned PyPI publish GitHub Action to an immutable commit ==== python313 ==== Version update (3.13.13 -> 3.13.14) Subpackages: python313-curses python313-dbm python313-tk - CVE-2026-11940: fix the symlink escape via tarfile hardlink-extraction fallback (bsc#1268977) CVE-2026-11940-tarfile-escape.patch - CVE-2025-15367: reject control characters in POP3 commands (bsc#1257041) CVE-2025-15366-pop3-ctrl-chars.patch - CVE-2025-15366: reject control characters in IMAP commands (bsc#1257044, gh#python/cpython!143922) CVE-2025-15366-imap-ctrl-chars.patch - Update to 3.13.14: - Security - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. - gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328) - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter. - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) - Core and Builtins - gh-151112: Fix a crash in the compiler that could occur when running out of memory. - gh-151126: Fix a crash, when there’s no memory left on a device, which happened in: - code compilation - _winapi.CreateProcess() - Now these places raise proper MemoryError errors. - gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. - gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. - gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. ... changelog too long, skipping 232 lines ... - CVE-2026-6100-use-after-free-decompression.patch ==== python313-core ==== Version update (3.13.13 -> 3.13.14) Subpackages: libpython3_13-1_0 python313-base python313-devel - CVE-2026-11940: fix the symlink escape via tarfile hardlink-extraction fallback (bsc#1268977) CVE-2026-11940-tarfile-escape.patch - CVE-2025-15367: reject control characters in POP3 commands (bsc#1257041) CVE-2025-15366-pop3-ctrl-chars.patch - CVE-2025-15366: reject control characters in IMAP commands (bsc#1257044, gh#python/cpython!143922) CVE-2025-15366-imap-ctrl-chars.patch - Update to 3.13.14: - Security - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. - gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328) - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter. - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) - Core and Builtins - gh-151112: Fix a crash in the compiler that could occur when running out of memory. - gh-151126: Fix a crash, when there’s no memory left on a device, which happened in: - code compilation - _winapi.CreateProcess() - Now these places raise proper MemoryError errors. - gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. - gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. - gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. ... changelog too long, skipping 232 lines ... - CVE-2026-6100-use-after-free-decompression.patch ==== qemu ==== Subpackages: qemu-arm qemu-audio-spice qemu-block-curl qemu-block-nfs qemu-block-rbd qemu-chardev-spice qemu-guest-agent qemu-hw-display-qxl qemu-hw-display-virtio-gpu qemu-hw-display-virtio-gpu-pci qemu-hw-display-virtio-vga qemu-hw-usb-host qemu-hw-usb-redirect qemu-hw-usb-smartcard qemu-img qemu-ksm qemu-pr-helper qemu-tools qemu-ui-curses qemu-ui-gtk qemu-ui-opengl qemu-ui-spice-app qemu-ui-spice-core qemu-vgabios - Properly fix bsc#1268245: * [openSUSE][RPM] spec: fix missing unversioned ppc64 linker (bsc#1268245) ==== qqc2-breeze-style6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== rsyslog ==== - added new rsyslog (imdtls/omdtls) DTLS modules (jsc#PED-16623) - added a devel subpackage, with requires (jsc#PED-16301) ==== ruby4.0 ==== Version update (4.0.5 -> 4.0.6) Subpackages: libruby4_0-4_0 - Update to 4.0.6 - Bug #22070: Thread.each_caller_location(1, 1) segfaults when called from a cfunc - Bug #22075: heap-use-after-free in rb_vm_ci_lookup under parallel Ractors - Bug #22076: defined? returns nil for protected methods defined in a module even when callable - Bug #22072: [BUG] should have cvar cache entry - Bug #22074: YJIT misaligns locals when there are > 256 local variables - Bug #22064: GC compaction breaks compare-by-identity sets - Bug #22084: invokesuper from define_method in Ractor can call wrong super method or crash - Bug #22092: Array#sum takes slow path, does not perform compensated summation of Float elements when init argument is a Float - Bug #14635: Float#round(n) returns a wrong result when n is big - Bug #22079: Float#ceil gives incorrect result - Bug #22096: Freeing a mutex locked by a fiber inside fiber scheduler can crash - Bug #21996: Crash when modifying instance variables during inspect or Marshal dump - Bug #22101: ASAN heap-use-after-free in rb_data_free after TypedData dfree frees dynamic rb_data_type_t - Bug #22103: Constant-folded /o regexp crashes with dupstring of a Regexp - Bug #21991: $! stays as the first exception in Ruby Box - Feature #21881: Split the root box into the (newer) root box and the master of copied user boxes - Bug #22120: Segfault caused by ar_find_entry_hint() not checking for conversion to st_table - Bug #22129: error_highlight raises NotImplementedError for ArgumentErrors that get wrapped - Bug #21864: Inconsistencies in type coercion error messages for integers - Bug #21882: IO::Buffer#locked leaves the buffer locked when the block raises - Bug #22127: parse.y regexp crash on invalid encoding - Bug #22126: Stack underflow for partial DCE and loops - Bug #22124: void value missed in parse.y - Bug #22104: Segfault in PRISM while Bootsnap compiles aws-sdk client_api.rb - Bug #21685: Unnecessary context-switching, especially bad on multi-core machines. - Bug #22099: Keyword-only method silently accepts a positional argument - Bug #22183: parse.y interpolation inside lambda literal - Bug #22181: SEGV in branch peephole optimization due to label/insn struct aliasing - Bug #22133: Ruby's default SIGINT handling ignores Thread.handle_interrupt masking. - Bug #22189: Enumerator::Lazy#to_enum does not accept method names as strings - Bug #22191: Signal.trap(:EXIT) exception only shown if at_exit also raises ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Stabilize testsuite tests and fix AllEventsHandler - Switch apache2ctl to apachectl for SUSE OSes (bsc#1252286) - Support attrlist in ldap.managed (bsc#1257151) - Added: * stabilize-testsuite-tests-and-fix-alleventshandler-7.patch * switch-apache2ctl-to-apachectl-for-suse-oses-bsc-125.patch * support-attrlist-in-ldap.managed-746.patch ==== sddm ==== Subpackages: sddm-branding-openSUSE sddm-greeter-qt5 - Introduce patch to make the default session configurable beyond xsessions/default.desktop and migrate to it: * 0001-Introduce-DefaultSession-option-in-sddm.conf.patch * 0002-Migrate-from-default.desktop-to-General-DefaultSessi.patch - Drop then unnecessary hunk from 0001-Read-the-DISPLAYMANAGER_AUTOLOGIN-value-from-sysconf.patch - Rebase 0003-Leave-duplicate-symlinks-out-of-the-SessionModel.patch ==== sddm-kcm6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== sddm-qt6 ==== Subpackages: sddm-greeter-qt6 - Introduce patch to make the default session configurable beyond xsessions/default.desktop and migrate to it: * 0001-Introduce-DefaultSession-option-in-sddm.conf.patch * 0002-Migrate-from-default.desktop-to-General-DefaultSessi.patch - Drop then unnecessary hunk from 0001-Read-the-DISPLAYMANAGER_AUTOLOGIN-value-from-sysconf.patch - Rebase 0003-Leave-duplicate-symlinks-out-of-the-SessionModel.patch ==== selinux-policy ==== Version update (20260702 -> 20260715) Subpackages: selinux-policy-targeted - fix cleanoldsepoldir.sh to properly handle migration markers when /var/lib/selinux doesn't exists (backported from SLFO_Main codebase) - Update to version 20260715: * Allow snapper_sdbootutil_plugin_t status and stop unit files(bsc#1271391) * Allow sdbootutil_t read and write snapperd_t pipes (bsc#1271391) - Update to version 20260713: * Fix wrong gen_requires in snapper_read_data_files (bsc#1271282) ==== shaderc ==== Version update (2026.2 -> 2026.3) - Update to release 2026.3 * HLSL compilation (i.e. sources for Direct3D) is deprecated and will be removed in a future version. ==== spectacle ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Fix lack of mouse release events when making windows transparent to input after double click (kde#513715) ==== sqlite3 ==== Subpackages: libsqlite3-0 sqlite3-tcl - Add sqlite3-tools and sqlite3-tools-tcl subpackages * Most other distributions have included a separate -tools package with these for a while, but we seemingly haven't been packaging them at all in openSUSE. * New tools include the ones packaged by debian trixie (showdb, showjournal, showstat4, showwal, sqldiff, and sqlite3_analyzer) along with sqlite3_rsync, which is recommended in sqlite3 docs * All tools are in -tools subpackage except for sqlite3_analyzer which is in -tools-tcl ==== srt ==== Version update (1.5.5 -> 1.5.6) - Update to version 1.5.6: + Security Notice: This release includes important security updates that address two significant CVE vulnerabilities affecting previous versions of the library. Users are strongly encouraged to upgrade to this version as soon as possible to benefit from these fixes and reduce exposure to the associated security risks. + The resolved CVEs are listed below: - CVE-2026-55869: Heap-Based Buffer Overflow in KMREQ Handling - CVE-2026-55868: Encryption State Machine Downgrade + Security Improvements: - Implemented security improvements for KMREQ buffer validation. This fix addresses a vulnerability where received message sizes were not verified against the destination buffer size during the copy process. The update enforces word-aligned validation to prevent overflows when copying to internal arrays. - Added strict validation of KMRSP wire length to prevent stack overflows. - Resolved an OOB read in LOSSREPORT range parsing. The logic previously read a "HI" sequence number word following a "LO" marker without verifying if the "HI" word existed in the wire payload. - Fixed an OOB read vulnerability in DROPREQ payload parsing. The handler now verifies that the wire payload meets the minimum 8-byte length requirement (two 32-bit sequence numbers) before attempting to process the request, preventing reads beyond the packet slot. - Introduced a guard in CRcvBuffer::dropMessage to reject requested drop ranges that extend beyond the end of the receiver buffer. + Important Bug Fixes: - Streamlined the library cleanup sequence by removing redundant post-cleaning of closed sockets. Architecture logic dictates that the Garbage Collector (GC) thread is the primary owner of socket deletion. Once the GC thread is joined, all sockets are considered deleted; further post-checks are unnecessary and avoid potential undefined behavior in cases where the library state might be corrupted. - Fixed a segmentation fault (SEGV) occurring during global or static initialization when ENABLE_HEAVY_LOGGING was active. + Build System Enhancements: - Transitioned the CI/CD pipeline to a robust Linux configuration matrix, serving as the modern replacement for Travis CI. The new system includes various platform and compiler combinations and incorporates specific fixes for MinGW builds and C++11 syntax compatibility. + Documentation Updates: Corrected a typographical error in the documentation regarding the separator used for searchParameters. ==== sso-mib ==== Version update (0.10.0 -> 0.10.1) - Import version 0.10.1 Fix bug to avoid activating broker on app creation ==== suse-module-tools ==== Version update (16.1.5 -> 16.1.6) Subpackages: suse-module-tools-scriptlets - Update to version 16.1.6: * Add 65-md-raid-properties.rules (bsc#1261555, jsc#PED-16120) Always set serialize_policy sysfs attribute to 1 for RAID1 arrays ==== swtpm ==== Subpackages: swtpm-selinux - Drop tunable in require to avoid policy loading issues with toolchain 3.11 (bsc#1271417). Can be dropped, once this is accepted upstream: https://github.com/stefanberger/swtpm/pull/1139 - Add patch: 1271417-drop-tunable-requires.patch ==== systemsettings6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== tar ==== Subpackages: tar-rmt - Add tar-acl_-prefix.patch: Avoid acl_ prefix for functions The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. ==== thunar ==== Version update (4.20.8 -> 4.20.9) Subpackages: libthunarx-3-0 thunar-lang - Update to 4.20.9 * Prevent use-after-free in list-view (#1861) * Fix use-after-free in tree-view-model (#1860) * Fix -Wdiscarded-qualifiers compiler warnings (#1859) * Remove G_GNUC_CONST qualifiers * Check/Update view-type on reload (#1799) * Prevent Criticals in some use-cases (#1799) * Prevent crash on reload when unmounted (#1799) * Fix crash when open unknown gvfs location (#1834) * Prevent use-after-free on re-login (#1831) * Keep a global ref. to job operation history (#1823) * Disconnect from 'action_mgr' on finalize (#1816) * Translation Updates ==== unison ==== Version update (2.53.8 -> 2.54.0) - Update to version 2.54.0 * Drop support for versions before 2.52.0 ==== unrar_wrapper ==== - Add missing python3-base BR (bsc#1270341). ==== vim ==== Subpackages: vim-data vim-data-common xxd - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). - Add vim-9.2.0780-modelinestrict-allow-wrap.patch: allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Upstream patch 9.2.0350 added the 'modelinestrict' option, enabled by default, whose hardcoded whitelist omits these two purely visual window-local options, so 'nowrap' in a modeline was silently ignored while every other setting on the same line was applied. - Update vim-7.3-name_vimrc.patch: point SYS_VIMRC_FILE at $VIMRUNTIME/suse.vimrc rather than /etc/vimrc, which we no longer own (bsc#1268162). - Update suse.vimrc: source /etc/vimrc at the end of the file, so that a local system vimrc still overrides the distribution defaults. - Drop vim-8.2.2411-globalvimrc.patch: its main.c fallback to suse.vimrc fired only when do_source() of /etc/vimrc returned FAIL, which an empty /etc/vimrc does not. A stale or empty /etc/vimrc therefore suppressed the distribution defaults entirely, losing 'syntax on', the cursor position restore and 'nomodeline' (bsc#1268162). - Build gvim against GTK 3 instead of GTK 4 (bsc#1270238). The GTK 4 clipboard code spins a nested main loop around gdk_clipboard_read_async(), which deadlocks gvim on paste, and its mime type negotiation does not interoperate with Qt clipboard owners. - -enable-gui=gtk4 also forces with_x=no in vim's configure, so gvim lost +X11, +xterm_clipboard, +xsmp and the CUT_BUFFER0 fallback. GTK 3 keeps native Wayland support: * Replace BuildRequires pkgconfig(gtk4) with pkgconfig(gtk+-3.0). * Pass --enable-gui=gtk3 and --with-x=yes in GUI_OPTIONS. ==== virtiofsd ==== Version update (1.13.2 -> 1.14.0) - Update to version 1.14.0: * Bump version to v1.14.0 * passthrough: only clear capabilities on regular files * Track the file type on HandleData * read_dir: add tests for u64 cookie fallback path * read_dir: handle u64 directory cookies that exceed i64::MAX * passthrough: add negotiation modes to --security-label * passthrough: add negotiation modes to --posix-acl * vhost_user: exit gracefully on queue processing errors * vhost_user: extract process_message() from queue processing loops * deps: bump vhost 0.15->0.16, vhost-user-backend 0.21->0.22 * passthrough: remove redundant inode lookups in open_inode() * server: do not reject oversized readdir requests * server: reject malformed extension lengths with a minimal local check * passthrough: avoid panic in setxattr on non-UTF-8 names * Support multiple supplementary groups * Update rust-vmm dependencies * seccomp: Don't allow newfstatat syscall on sparc64 * README: --announce-submounts is enabled by default * sandbox: only canonicalize shared_dir for chroot * sandbox: fix pivot_root to relative paths - Add explicit handling of (and checking that is has actually been handled) bsc#1257912 (CVE-2026-25727). Patch added: * update-time-0.3.47.patch - Service file cleanup and refactoring - Update to version 1.13.3: * Bump version to v1.13.3 * Allow readv() seccomp * Allow pwritev() seccomp * Extend traits methods to support ReadvFlag * Replace preadv64() with preadv2() * Update pwritev2() flags * Add Intellij IDEA configuration to .gitignore ==== wacomtablet-kcm6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== wayland ==== Version update (1.25.0 -> 1.26.0) Subpackages: libwayland-client0 libwayland-cursor0 libwayland-egl1 libwayland-server0 - Update to release 1.26 * A new wl_pointer.warp event, to notify a new pointer position without an end-user-initiated motion event. * A new wl_fixes.ack_global_remove request, to address races related to global remove events. * A new wl_display_remove_socket_fd() function to remove sockets previously added via wl_display_add_socket_fd(). * WAYLAND_DEBUG timestamps now use the "HH:MM:ss.xxxxxx" format, making them easier to read and compare with other logs. - Drop pre-Leap-16.x build logic ==== webkitgtk3 ==== Version update (2.52.4 -> 2.52.5) Subpackages: libjavascriptcoregtk-4_1-0 libwebkit2gtk-4_1-0 typelib-1_0-JavaScriptCore-4_1 typelib-1_0-WebKit2-4_1 webkit2gtk-4_1-injected-bundles - Update to version 2.52.5 (bsc#1271638): + Fire scrollend event for instant programmatic scrolls. + Increase network idle connection timeout to 115 seconds. + Add User-Agent quirk for HBO Max. + Fix the build with system malloc. + Fix several crashes and rendering issues. + Security fixes: CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745. - Drop webkitgtk-ppc64le-build-fix.patch: Applied upstream. ==== webkitgtk4 ==== Version update (2.52.4 -> 2.52.5) Subpackages: libjavascriptcoregtk-6_0-1 libwebkitgtk-6_0-4 typelib-1_0-JavaScriptCore-6_0 typelib-1_0-WebKit-6_0 webkitgtk-6_0-injected-bundles - Update to version 2.52.5 (bsc#1271638): + Fire scrollend event for instant programmatic scrolls. + Increase network idle connection timeout to 115 seconds. + Add User-Agent quirk for HBO Max. + Fix the build with system malloc. + Fix several crashes and rendering issues. + Security fixes: CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745. - Drop webkitgtk-ppc64le-build-fix.patch: Applied upstream. ==== wget ==== - Fix metalink regression from CVE-2026-58469 fix See: commit 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf from https://gitlab.com/gnuwget/wget [bsc#1272219, CVE-2026-58469] * CVE-2026-58469.patch - ftp validate PASV/LPSV response address against control connection peer [bsc#1271320, CVE-2026-15146] * CVE-2026-15146.patch ==== xclock ==== Version update (1.2.0 -> 1.2.1) - Update to version 1.2.1 * This release fixes the build on systems like NetBSD that support setlocale() but not uselocale(), and adds example app-defaults files for the new shapes configurations introduced in the 1.2.0 release. ==== xdg-desktop-portal-kde6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Disable background portal on X11 (kde#522864) * appchooser: Unconfuse url vs filename (kde#521748) ==== xfce4-power-manager ==== Subpackages: xfce4-power-manager-lang xfce4-power-manager-plugin - Suggest pkexec-rpm to tell solver we prefer the original one [bsc#1267899] ==== xmodmap ==== Version update (1.0.11 -> 1.0.12) - Update to version 1.0.12: * Accept --help and --version as aliases to -help and -version. * Avoid -Wuse-after-free warning from GCC 15 in handle.c. * Handle possible NULL return from copy_to_scratch() in parse_keysym. * Improve man page formatting and text. * Assume target platforms have strncasecmp now (Unix98/SUSv2). * Add support for building with Meson. - Switch to meson build system ==== xorg-x11-server ==== Version update (21.1.21 -> 21.1.24) Subpackages: xorg-x11-server-Xvfb xorg-x11-server-extra - Update to version 21.1.24 - Replaced xorg-server-21.1.21.tar.xz with xorg-server-21.1.24.tar.xz - Dropped patches now included upstream: * bsc1260922_CVE-2026-33999_xkb-fix-buffer-re-use-in-_XkbSetCompatMap.patch (bsc#1260922, CVE-2026-33999) * bsc1260923_CVE-2026-34000_xkb-Fix-bounds-check-in-_CheckSetGeom.patch (bsc#1260923, CVE-2026-34000) * bsc1260924_CVE-2026-34001_miext-sync-Fix-use-after-free-in-miSyncTriggerFence.patch (bsc#1260924, CVE-2026-34001) * bsc1260925_CVE-2026-34002_0001-xkb-Fix-out-of-bounds-read-in-CheckModifierMap.patch (bsc#1260925, CVE-2026-34002) * bsc1260925_CVE-2026-34002_0002-xkb-Add-more-_XkbCheckRequestBounds.patch (bsc#1260925, CVE-2026-34002) * bsc1260926_CVE-2026-34003_0001-xkb-Add-additional-bound-checking-in-CheckKeyTypes.patch (bsc#1260926, CVE-2026-34003) * bsc1266294_CVE-2026-XXXX1_0007-dix-increase-XLFDMAXFONTNAMELEN-to-match-libXfont2-s.patch (bsc#1266294, CVE-2026-XXXX1) * bsc1266295_CVE-2026-XXXX2_0001-sync-fix-deletion-of-counters-and-fences.patch (bsc#1266295, CVE-2026-XXXX2) * bsc1266296_CVE-2026-XXXX3_0003-xkb-reject-key-types-with-num_levels-exceeding-XkbMa.patch (bsc#1266296, CVE-2026-XXXX3) * bsc1266297_CVE-2026-XXXX4_0004-xkb-clamp-nMaps-to-mapWidths-buffer-size-in-CheckKey.patch (bsc#1266297, CVE-2026-XXXX4) * bsc1266299_CVE-2026-XXXX6_0002-sync-restart-trigger-list-iteration-in-SyncChangeCou.patch (bsc#1266299, CVE-2026-XXXX6) * bsc1266300_CVE-2026-XXXX7_0005-glx-fix-reversed-length-check-in-ChangeDrawableAttri.patch (bsc#1266300, CVE-2026-XXXX7) * bsc1266301_CVE-2026-XXXX8_0006-saver-re-fetch-screen-private-after-CheckScreenPriva.patch (bsc#1266301, CVE-2026-XXXX8) * bsc1266302_CVE-2026-XXXX9_0001-dri2-Use-booleans-for-fake-front-buffer-tracking-in-.patch (bsc#1266302, CVE-2026-XXXX9) * bsc1266302_CVE-2026-XXXX9_0002-dri2-Deduplicate-attachments-in-do_get_buffer.patch (bsc#1266302, CVE-2026-XXXX9) * bsc1268893_CVE-2026-55999_0002-fb-mi-glamor-reject-glyphs-with-negative-dimensions.patch (bsc#1268893, CVE-2026-55999) * bsc1268893_CVE-2026-55999_0003-glamor-reject-fonts-with-per-glyph-metrics-exceeding.patch (bsc#1268893, CVE-2026-55999) * U_GLX-Free-the-tag-of-the-old-context-later.patch (bsc#1268894, CVE-2026-56000) * bsc1268894_CVE-2026-56000_0001-glx-free-old-context-tag-before-allocating-new-one-i.patch (bsc#1268894, CVE-2026-56000) ==== yast2-add-on ==== Version update (5.0.0 -> 5.0.2) - fix invalid entry in changelog ( needed to submit jsc#PED-14507) - 5.0.2 - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.1 ==== yast2-installation ==== Version update (5.0.19 -> 5.0.21) - jsc#PED-14507 - Removed remaining reference to update-desktop-files embedded deeper inside from spec file - 5.0.21 - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.20 ==== yast2-packager ==== Version update (5.0.11 -> 5.0.13) - Cleaned the changelog entries formatting - jsc#PED-14507 - Removed remaining reference to update-desktop-files embedded deeper inside from spec file - 5.0.13 - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.12