Packages changed: AppStream (1.1.3 -> 1.1.5) GraphicsMagick (1.3.47 -> 1.3.48) ImageMagick (7.1.2.27 -> 7.1.2.28) Mesa (26.1.5 -> 26.1.6) Mesa-drivers (26.1.5 -> 26.1.6) MozillaFirefox (153.0 -> 153.0.1) NetworkManager PackageKit (1.3.5 -> 1.3.6) apache2-mod_php8 (8.5.8 -> 8.5.9) apparmor (5.0.1 -> 5.0.2) aws-lc (5.0.0 -> 5.4.0) bind (9.20.24 -> 9.20.26) ca-certificates (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) chrony cryptsetup (2.8.6 -> 2.8.7) evince faad2 (2.11.2.git13 -> 2.11.2.git18) freerdp (3.28.0 -> 3.30.0) fwupd (2.1.6 -> 2.1.7) gcc (15 -> 16) gcc16 (16.1.1+git8886 -> 16.1.1+git9481) gd glib2 (2.88.2 -> 2.88.3) grub2 gtk-vnc gvfs hwinfo (25.4 -> 25.5) inxi (3.3.40 -> 3.3.41) kernel-firmware-amdgpu (20260629 -> 20260717) kernel-firmware-bluetooth (20260629 -> 20260720) kernel-firmware-platform (20260629 -> 20260717) kernel-firmware-qcom (20260629 -> 20260717) kernel-source (7.1.4 -> 7.1.5) libapparmor (5.0.1 -> 5.0.2) libeconf (0.8.3 -> 0.8.4) libfastjson (1.2304.0 -> 1.2304.0+ga630254) libheif (1.23.0 -> 1.23.1) libmysofa (1.3.3 -> 1.3.5) libndp (1.8 -> 1.9) libostree (2026.1 -> 2026.2) libpng16 (1.6.57 -> 1.6.58) libssh (0.11.4 -> 0.11.5) libxmlb (0.3.27 -> 0.3.29) linux-glibc-devel (7.0 -> 7.1) microos-tools (4.0+git24 -> 4.0+git28) multipath-tools (0.14.3+212+suse.f5d32098 -> 0.15~1+230+suse.d36a6a70) net-tools (3.14~alpha~git.20251212.7011617 -> 3.14~alpha~git.20260718.4f5bfb2) nghttp2 (1.69.0 -> 1.70.0) nghttp3 (1.15.0 -> 1.18.0) ntfs-3g_ntfsprogs (2022.10.3 -> 2026.7.7) nvme-cli (3.0~b.3 -> 3.0~b.4) openSUSE-release (20260724 -> 20260802) openblas_openmp openblas_pthreads openssh (10.3p1 -> 10.4p1) openssh-askpass-gnome (10.3p1 -> 10.4p1) pam (1.7.2+git12 -> 1.7.2+git48) pam-full-src (1.7.2+git12 -> 1.7.2+git48) perl-Net-DNS (1.550.0 -> 1.560.0) permissions (1699_20260715 -> 1699_20260728) php8 (8.5.8 -> 8.5.9) python-certifi (2026.5.20 -> 2026.7.22) python-zstandard qemu (11.0.2 -> 11.0.3) qgpgme (2.1.0 -> 2.2.0) rsyslog (8.2502.0 -> 8.2606.0) salt samba (4.24.3+git.475.629de6765b9 -> 4.24.5+git.481.dba78dbdea) selinux-policy (20260715 -> 20260727) shared-mime-info (2.4 -> 2.5.1) sssd systemd (260.3 -> 261.2) tar tesseract-ocr (5.5.2 -> 5.5.3) tigervnc tumbler (4.20.1 -> 4.20.2) unbound (1.25.1 -> 1.25.2) update-bootloader (1.27 -> 1.28) util-linux (2.42.1 -> 2.42.2) util-linux-systemd (2.42.1 -> 2.42.2) vim wicked (0.6.79 -> 0.6.80) wpa_supplicant wtmpdb (0.75.0+git20251130.0d8fe7a -> 0.76.0+git20260730.89c0861) xfce4-panel (4.20.7 -> 4.20.8) xfce4-power-manager (4.20.0 -> 4.20.1) xfce4-settings (4.20.4 -> 4.20.5) yast2-auth-server (5.0.0 -> 5.0.1) zimg (3.0.6+20250919.gdf9c147 -> 3.0.6+20260720.g1ad1895) zoo zstd === Details === ==== AppStream ==== Version update (1.1.3 -> 1.1.5) Subpackages: libAppStreamQt3 libappstream5 - Update to 1.1.5 Features: * sysinfo: Implement display size detection on macOS * sysinfo: Assume a more modern display for the handset chassis template * sysinfo: Assume a more modern display for the tablet chassis template * sysinfo: Initial code to autodetect the display size on Wayland * sysinfo: Handle fractional display scaling via xdg-output * Implement support for GCVE as vulnerability database provider * qt: Sync enum mirrors with the C library * qt: Add Artifact, Checksum, Reference, Review and Agreement wrappers * qt: Wrap missing C API on existing classes * reviews: Add simple interface to fetch ODRS reviews for a component * reviews: Implement support for submitting reviews Specification: * docs: Suggest using the longest display side for maximum size constraints Bugfixes: * qt: Add back wrong const Component::addBundle for ABI compatibility * qt: Use strndup for C string-list conversion * pool: Fix bidirectional wildcard search for modalias provides * Make GResources we need outlive main thread destruction * pool: Properly implement cancellation of load operations * sysinfo: Fix display-length setter overriding the shortest edge * relation-check: Don't zero the score if a required check errored * curl: Harden downloader by restricting protocols to only HTTP(S) * curl: Allow making POST requests and changing the user agent * curl: Fix retry-loop data corruption and don't blindly retry POST requests * yaml: Fix potential crashes when encountering missing relation entry values * yaml: Adjust tests and emitter to work around libfyaml string-quoting change * yaml: Ensure version relations are consistently quoted * qt: Fix buffer overrun in stringListToCharArray - Drop patches: * 0001-yaml-Fix-potential-crashes-when-encountering-missing.patch * 0001-yaml-Adjust-tests-and-emitter-to-work-around-libfyam.patch * 0001-yaml-Ensure-version-relations-are-consistently-quote.patch * 0001-trivial-yaml-Ensure-branding-color-values-are-also-c.patch ==== GraphicsMagick ==== Version update (1.3.47 -> 1.3.48) Subpackages: libGraphicsMagick++-Q16-12 libGraphicsMagick-Q16-3 libGraphicsMagick3-config - added patches CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files [bsc#1268878] * GraphicsMagick-CVE-2026-56379.patch - version update 1.3.48 * Address ImageMagick CVE CVE-2026-42050, ImageMagick security advisory GHSA-7mxf-ff4f-jj7p, which is related to an X11 display buffer overflow. This is really a minor issue since it requires X11 keyboard input and causes no harm. * DCM: In RLE decoder, detect and report end of input. Reported-by: Tristan Madani. * DCM: Convert from ASCII numeric value to unsigned value, with error detection. Avoid problems caused by negative values. Reported-by: Tristan Madani. * display: Correct bounds checking for 'filename' length. Thanks to Petr Gajdos for a heads-up regarding the disparity. * GradientImage(): Fix 'pixel_packets' and 'indexes' addressing logic for NorthGravity. Addresses "[security] GraphicsMagick GradientImage: heap-buffer-overflow READ in NorthGravity branch reached from gm convert (magick/gradient.c:284)" from David Korczynski. Credit to Anthropic Claude and Ada Logics. * ImageToBlob(): Fix memory leak which may occur if WriteImage() fails. * LOCALE: Bound the length passed to strncpy() and string terminator. Addresses "[security] GraphicsMagick LOCALE coder: stack-buffer-overflow WRITE in ReadConfigureFile reached from gm convert (coders/locale.c:257)" from David Korczynski. Credit to Anthropic Claude and Ada Logics. * META/IPTC: Prevent reading past the end of a truncated/short IPTC profile. * MIFF: Correct scope of 'values' reallocation error handling. Addresses "[security] GraphicsMagick MIFF reader: heap-use-after-free WRITE via stale cursor on values-buffer realloc failure (coders/miff.c:1048)" from David Korczynski. Credit to Anthropic Claude and Ada Logics. * MSL: Properly log warnings and errors using LogMagickEventList() given a va_list. Reported-by: Tristan Madani. * PCD: Over-provision the per-channel Huffman decode buffers and detect any attempt to overflow them. Discovered and reported by Cipher - Causal Security (https://causalsecurity.com/). * PCX: If image has more than 256 colors, save as a DirectClass type. Addresses "[security] GraphicsMagick PCX writer: * PNG: Use only values from GetImageCharacteristics() since IsMonochromeImage() and IsGrayImage() may produce different answers. Addresses "[security] GraphicsMagick MNG re-encode: heap-buffer-overflow WRITE in ExportGrayAlphaQuantumType reached from gm convert (magick/export.c:1105)" as reported by David Korczynski via email on May 28, 2026. Credit to Anthropic Claude and Ada Logics. * SVG: Properly log warnings and errors using LogMagickEventList() given a va_list. Reported-by: Tristan Madani. * TIFF: Add many more validations and safeguards to EXIF in TIFF writer. Addresses "[security] GraphicsMagick TIFF writer: heap-buffer-overflow WRITE in AddIFDExifFields via 32-bit count*2 wrap on EXIF SHORT array (coders/tiff.c)" from David Korczynski. Credit to Anthropic Claude and Ada Logics. * TIFF: If EXIF profile string is not already NUL terminated, assure that it is NUL terminated before passing it to libtiff. Reported-by: Tristan Madani. * TIFF: In AddIFDExifFields(), address possible out of bounds read (2 bytes) beyond the end of the allocated profile buffer. Reported-by: Tristan Madani. * VIFF: Memory leak fix (ImageMagick CVE-2026-61870). * configure.ac: Fixes so Freetype and zlib may be detected if pkg-config is not available. * PICT: Remove the attempt to intuit byteCount must be a word because the approach used does not work reliably. This means that defective PICT files previously written by ImageMagick or GraphicsMagick may fail to be read. * VIFF: Fixes so remaining Khoros VIFF sample files sample files from the Encyclopedia Of Graphics File Formats which are based on integer data storage types read correctly. - deleted patches * GraphicsMagick-CVE-2026-13606.patch (upstreamed) * GraphicsMagick-CVE-2026-42050.patch (upstreamed) * GraphicsMagick-CVE-2026-61870.patch (upstreamed) - added patches CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title [bsc#1271496] * GraphicsMagick-CVE-2026-61464.patch ==== ImageMagick ==== Version update (7.1.2.27 -> 7.1.2.28) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - versn update to 7.1.2.28 * build(deps): bump ubuntu from b7f4819 to 3131b4c in /.devcontainer #8876 * build(deps): bump actions/checkout from 7.0.0 to 7.0.1 #8882 * Fixes for PTIF writer to re-enable default creation of pyramid levels #8884 * build(deps): bump the codeql-action group with 3 updates #8881 * build(deps): bump actions/attest from 4.1.1 to 4.2.0 #8880 * fix: upgrade http:// to https:// in README.md #8867 * Fix memory leak in ASHLAR coder when action fails #8865 * build(deps): bump github/codeql-action/upload-sarif #8862 * build(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0 #8863 * build(deps): bump github/codeql-action/init from 4.36.3 to 4.37.0 #8861 * Fix writing video output to stdout in Windows #8860 * build(deps): bump github/codeql-action/upload-sarif #8851 * build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 #8849 * build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3 #8850 * re-add support for libheif 1.7.0 #8841 * Fix writing video output to stdout in Windows (#8860) #7900 * beta release 3dd3215 * Make sure git is configured properly when updating the website. 2e09a16 * address remote TOCTOU issues 99d821d * eliminate compiler warning 8e835bd * map Windows file identity into st_dev/st_ino. a15976c * eliminate compiler warning c36f9ed * check image file identity da02de3 * normalize the AE metric f85632e * eliminate compiler warning 414297f * support ImageInfo properties member 560f000 * improve formatting 23cfa27 * eliminate compiler warning 2f7deb8 * initialize image info properties ee20b08 * cosmetic d87c54b * revert c5a692a * time-of-check to time-of-use check ef0eb6d * normalize AE metric de81b9a * if path attributes fail relinquish memory 9f18109 * ensure file resource identify is valid bbbf79e * premature reconstruct destruction d110964 * revert similarity image patch 60c110f * if compare:virtual-pixels is present and false then min bounds 11b86af * restore parallelism 33e5931 * include file mode when validating file identity c081559 * eliminate compiler exception 94df319 * define POSIX file type and permission macros 4fcd510 * localize defines d99edfd * define S_IWUSR ed17fb2 * https://github.com/ImageMagick/ImageMagick/issues/8856 2d68170 * reviewed and made subtle corrections to a few composite ops 55e52c4 * Corrected IsPaletteImage check. b93264e * Corrected comment. 10e4271 * https://github.com/ImageMagick/ImageMagick/issues/8858 686729b * eliminate compiler warning a73378f * eliminate compiler warning 55a6aaf * update to the latest ImageMagick documentation 60fcb88 * Restored icon. d551454 * Updated configure. 8714fef * Small memory allocation optimization. 2d4d387 * Updated configure. e0c11e3 * Use max compression for all archives. 8270efa * guarantee round-trip fidelity for IEEE‑754 doubles without printing spurious digits 676d2c3 * No longer inline the method to reduce the local stack size. d53e028 * correct cast from char to quantum 0f86975 * https://github.com/ImageMagick/ImageMagick/issues/8864 549f90b * do not divide by alpha for plus op 31c97dd * revert 5bbda08 * introduce image:frames define 7fd62c7 * eliminate compiler warning 4548c02 * FILE_READ_ATTRIBUTES is preferred over GENERIC_READ 63cc8c7 * Updated the dependencies. 873e31a * safe read/write 20dcf6d * use 1mb chunks 7618f43 * use parens in macro 7a5bc5b * eliminate compiler warning 3744060 * https://github.com/ImageMagick/ImageMagick/issues/8436 f2e478b * avoid division by 0 ec19dcd * cosmetic 62da037 * revert 3e31b7f * increase threads for PHASE metric 5a774ca * fix PDC metric fc48f7d * correct angle 836651e * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6rvv-36hw-5rgf 297c894 * Read DNG profiles when pinging the image. eeea9da * Cosmetic. 55c96d0 * configure distributed cache max clients and max unathenticated clients e9c84d9 * precompute the phase spectrum for all (u,v) frequency pairs simultaneously, 8470c17 * use virtual memory for phase spectra 4c2e04d * cosmetic 46c11a2 * spatial phase subimage search 073502f * add zlib dependency a5956e8 * restore FFT case 39fa09d * Restored logo vector files. b3c3fba * Exclude logo from the release archive. e40b4d4 * Cosmetic. 8e2561a * improve numerical stability c08cf98 * handle non-square images e5f4934 * thread phase spectra 7211f83 * eliminate compiler warning 8f527e8 * add workload factor define 6825ff5 * eliminate compiler warning 11de3d1 * adapt Fred’s spatial PHASE algorithm f94ceb9 ... changelog too long, skipping 11 lines ... * Write the x and y offset in the tga encoder when the value fit in the unsigned short range. f55e398 ==== Mesa ==== Version update (26.1.5 -> 26.1.6) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.1.6 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.6 ==== Mesa-drivers ==== Version update (26.1.5 -> 26.1.6) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Update to 26.1.6 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.6 ==== MozillaFirefox ==== Version update (153.0 -> 153.0.1) Subpackages: MozillaFirefox-branding-upstream - Mozilla Firefox 153.0.1 https://www.firefox.com/en-US/firefox/153.0.1/releasenotes/ * Fix audio playing silently on some music and audio streaming sites after pausing and resuming playback (bmo#2053586) * Fix the New Tab page background flashing a few seconds after the page loaded when a custom wallpaper was in use (bmo#2056650) * Fix a crash that could occur when a page loaded a frame using a javascript: address (bmo#2054485) * Fix a crash that could occur while typing text in an editable area of a page (bmo#2053867) * Fix a search engine you had already installed yourself being labeled as "New" when Firefox later started offering the same engine (bmo#2053710) * Improve pointer lock, used by games and other immersive web content, so that the mouse pointer is less likely to escape the Firefox window (bmo#1255338, bmo#2040628) * Fix an issue in the Inspector's Rules view where pseudo- elements could only be expanded once per selected element (bmo#2054525) * Fix View Page Source failing to load blob: documents (bmo#2054428) * Fix View Page Source timing out on documents that inherit their origin, such as frames using the srcdoc attribute (bmo#2054487) ==== NetworkManager ==== Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Add 2462.patch: nm-initrd-generator: set parent for NBFT vlan connection (bsc#1259025, glfd#NetworkManager/NetworkManager!2462). - Add NetworkManager-initrd-generator-ip-hcn.patch: handle "ip=hcn" option in nm-initrd-generator, it generates an empty connection (PED-14534). ==== PackageKit ==== Version update (1.3.5 -> 1.3.6) Subpackages: PackageKit-backend-zypp PackageKit-gstreamer-plugin PackageKit-gtk3-module libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Update to version 1.3.6 (bsc#1267250, CVE-2026-10294): + Bugfixes: - daemon: stop idle progress timer after flushing updates - tests: Actually run the daemon tests on CI using a helper - tests: daemon: Auto-answer interactive prompts from the test - tests: Refactor and reorganize tests - pk-client: Perform any state changes & teardown before g_task_return_*() - package-sack: Fix a double-free issue on PkTask - Ensure we can send SIGQUIT to spawned backends - Prevent a race between the test harness and pk_readline* for input - daemon: Do not accept symlinks as frontend socket - daemon: Return proper error codes for bad SetHints() input - Don't leak TESTDATADIR into production binaries - daemon: Whitelist ONLY_DOWNLOAD for specific transaction roles only - lib: Don't warn on generic D-Bus errors - Send SIGTERM to ask subprocesses to quit, instead of SIGQUIT - daemon: Check errno instead of kill() return values to determine why it failed - pk-client: Fix race between cancellation and TID/proxy assignment + Miscellaneous: - PkTransaction: Simplify the error quark creation - ci: Ensure D-Bus is available and running for all tests - docs: Add error-checking to PK usage example ==== apache2-mod_php8 ==== Version update (8.5.8 -> 8.5.9) - version update to 8.5.9 Core: Fixed bug GH-22290 (AST pretty printing does not correctly handle strings containing NUL). Fixed bug GH-22206 (missing return in global register detection). Lock unmodified readonly properties for modification after clone-with. BCMath: Fixed GHSA-x692-q9x7-8c3f (Out-of-bounds write in bccomp()). (CVE-2026-17544) Calendar: Fixed bug GH-22602 (gregoriantojd() and juliantojd() integer overflow with INT_MAX year). Date: Update timelib to 2022.17. Fixed bug GH-19803 (Parsing a string with a single white space does create an error). Fixed Unix timestamps in February of the year 0 are misparsed with @-notation. Fixed bug GH-11310 (__debugInfo does nothing on userland classes extending Date classes). DBA: Fixed OOB read on malformed length field in dba flatfile handler. DOM: Fixed bug GH-22570 (Stack overflow when serializing a deeply nested Dom\XMLDocument). Fixed getElementsByClassName() item() returning the wrong element on random access. Exif: Fixed bug GH-11020 (exif_read_data() emits a spurious "Illegal IFD size" warning when an IFD is not followed by a next-IFD offset). GD: Upgrade libgd. (CVE-2026-9672) Hash: Fixed bug GH-18173 (ext/hash relies on implementation-defined malloc alignment). ODBC: Fixed bug GH-22668 (Heap buffer over-read when a column value exceeds the driver-reported display size). Opcache: Fixed bug GH-22158 (Tracing JIT dispatches the observer begin handler through the wrong run_time_cache slot on megamorphic calls). Fixed bug GH-22443 (Tracing JIT SIGSEGV on megamorphic dynamic calls from an undereferenced run_time_cache map_ptr offset). Fixed bug GH-21770 (Infinite recursion in property hook getter in opcache preloaded trait). OpenSSL: Fixed timeout for supplemental read at end of a blocking stream in SSL stream wrapper. Intl: Fixed Locale::lookup() and locale_lookup() to return NULL instead of the fallback locale when a language tag cannot be canonicalized. Fixed memory leaks when calling Collator::__construct() or Spoofchecker::__construct() twice. Fixed memory leak when calling IntlListFormatter::__construct() twice. Fixed IntlChar methods leaving stale global error state after successful calls. PDO_ODBC: Fixed bug GH-20726 (Crash with ODBC connection pooling when the DSN carries no credentials). Fixed bug GH-22667 (Heap buffer over-read when a column value exceeds the driver-reported display size). Fixed bug GH-22666 (Heap buffer overflow when an output parameter value is longer than the declared maxlen). Fixed bug GH-22665 (Out-of-bounds write when the ODBC driver reports a diagnostic message length beyond the error buffer). PGSQL: Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout). (CVE-2026-17543) Phar: Fixed inconsistent handling of the magic ".phar" directory. Paths such as "/.phar" remain protected, while non-magic paths that merely start with ".phar" are handled consistently across file and directory creation, copying, ArrayAccess, stream lookup, directory iteration and extraction. Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260) PHPDBG: Fixed bug GH-17387 (Trivial crash in phpdbg lexer). Fixed fleaked lowercased lookup keys in phpdbg_resolve_opline_break. Fixed off-by-one in phpdbg_safe_class_lookup() causing class lookups to always fail during phpdbg's signal-safe interruption path. Reflection: Fixed bug GH-22324 (Ignore leading namespace separator in ReflectionParameter::__construct()). Fixed bug GH-22441 (ReflectionClass::hasProperty() and getProperty() ignore dynamic properties shadowing a private parent property). Fixed bug GH-22658 (ReflectionConstant::__toString() with a string value with null bytes truncates output). Fixed bug GH-22683 (Reflection(Class)Constant::__toString() should not warn on NAN conversions). Fixed bug GH-22681 (Reflection*::__toString() truncates on null bytes). Session: Fixed bug GH-21314 (Different session garbage collector behavior between PHP 8.3 and PHP 8.5). SPL: Fix class_parents for classes with leading slash in non-autoload mode. Ignore leading back-slash in class_parents(), class_implements(), and class_uses(). Fixed bug GH-16217 (SplFileObject::fputcsv() on an uninitialized object segfaults). Standard: Fixed bug GH-22395 (base_convert() outputs at most 64 characters). Fixed bug GH-22678 (Use-after-free in array_multisort() when the comparator mutates the array being sorted). URI: Fixed behavior of Uri\WhatWg\Url wither methods with regards to empty opaque hosts. Fixed bug GH-22628 (Percent-encoding of caret in WHATWG URL paths is not performed). Fixed bug GH-22629 (WHATWG Validation error incorrect with empty host and non-empty userinfo). Zip: Fixed bug GH-22649 (ZipArchive::setCommentName() and setCommentIndex() could crash after overwriting an entry and resetting its inherited unchanged comment). Fixed bug GH-21705 (ZipArchive::getFromIndex() ignores ZipArchive::FL_UNCHANGED for deleted entries). - modified patches * php-build-reproducible-phar.patch (refreshed) * php-systzdata-v24.patch (refreshed) - fixes CVE-2026-17543 [bsc#1273075] CVE-2026-17544 [bsc#1273076] CVE-2026-7260 [bsc#1273077] CVE-2026-9672 [bsc#1273078] ==== apparmor ==== Version update (5.0.1 -> 5.0.2) Subpackages: apparmor-abstractions apparmor-docs apparmor-parser apparmor-profiles apparmor-utils python3-apparmor - update to AppArmor 5.0.2 - several fixes in utils, parser and some profiles - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_5.0.2 for the upstream changelog - remove upstreamed patches: - curl.diff - lsblk-mr2147.diff - add nslookup.diff to fix nslookup output ==== aws-lc ==== Version update (5.0.0 -> 5.4.0) - Update to version 5.4.0: + Add AArch64 NEON runtime fallback for ML-KEM and ML-DSA + Support for EVP_AEAD_CTX_copy + Remove dead P-256 nistz asm under OPENSSL_SMALL and extend the size-check harness + Use built-in Camellia in krb5 integration patch; fix CTS doc label + add AES-KWP wrap/unwrap CASTs - Update to version 5.3.0: + Add ACVP support for multi-expansion HKDF - Update to version 5.2.0: + OPENSSL_SMALL: imply MY_ASSEMBLER_IS_TOO_OLD_FOR_512AVX on x86_64 + Documented and added feature stability tests for EVP_AEAD implementations that support concurrency through EVP_AEAD_CTX_seal/gather functions + Fix libgit2, xtrabackup, grpc tests and add OSSL3 peer cert APIs + Null-guard EVP_AEAD_CTX_cleanup for fork+shm safety + Add Symbol Versioning Support + Symbol versioning follow-ups: register peer cert APIs, fix dist_pkg_tests matrix + Add ML-KEM decapsulate CASTs to break-kat tooling + Pin required libssh2 integration to a release + openssl/target.h: Allow building for the e2k architecture + Add CTS mode, krb5 integration test + Gate s2n-bignum _alt variants under OPENSSL_SMALL + Fix SSL_OP_IGNORE_UNEXPECTED_EOF being ignored over sockets - Update to version 5.1.0: + Quote LIBCRYPTO_PATH for dynamic load test + Add SSL_CTX_set_security_callback and related APIs for OpenSSL compat + ML-DSA: import and enable x86_64 assembly backend from mldsa-native + Fix PostgreSQL integration: match upstream revoked-cert alert regex + Support SSL_OP_IGNORE_UNEXPECTED_EOF option + Stabilize libgit2 integration test + Fix SSL_CTX_add_extra_chain_cert slot routing for chains added before the leaf + Make OPENSSL_memcmp constant time + Add WASIp2 build and test support + Move TLS 1.3 KDF into the FIPS module and wire up ACVP + Define OPENSSL_INIT_NO_ATEXIT as a no-op + ML-DSA: import and enable aarch64 assembly backend from mldsa-native + Add 'version -fips' to surface FIPS module version in openssl tool + Concurrency is not generally supported for EVP_AEAD_CTX_foo functions ==== bind ==== Version update (9.20.24 -> 9.20.26) Subpackages: bind-doc bind-utils - Upgrade to release 9.20.26 Security Fixes: * Correct verification of NSEC3 signer name. (CVE-2026-10723) [bsc#1271982] * Malformed DNSKEY records could trigger an assertion. (CVE-2026-10822) [bsc#1271983] * Fix handling of RPZ CNAME expansion that returns too-long name. (CVE-2026-11331) [bsc#1271984] * Prevent excessive validation work from crafted negative responses. (CVE-2026-11605) [bsc#1271985] * Prevent cache exhaustion under sustained attack. (CVE-2026-11622) [bsc#1271986] * Stop accepting invalid signed wildcard records. (CVE-2026-11721) [bsc#1271987] * Do not assert for some specific CNAME and DNAME queries. (CVE-2026-12617) [bsc#1271988] * Prevent crash from malformed NSEC/NSEC3 response. (CVE-2026-13204) [bsc#1271989] * Fix DNSSEC validation bypass via out-of-zone NSEC Next Field. (CVE-2026-13321) [bsc#1271990] * Reclaim memory promptly when DNSSEC validations are canceled. Removed Features: * Remove the secondary validator in query.c. Bug Fixes: * Fix a bug in DNS UPDATE processing with inline-signing enabled. * Properly detect private records before copying. * Tighten referral DS acceptance. * Don't synthesize negative responses with pending NSEC. * Check that an NSEC signer is at or above the name to be validated. * Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN. * Fix a deny-answer-aliases configuration bypass issue. * Reject external referrals from forwarders. * Fix a zone transfer over TLS (XoT) issue when using the opportunistic TLS mode. * Unvalidated opt-out NSEC3 could be accepted in insecurity proof. * Check wildcard signer and NOQNAME signer match. * Fix CNAME resolution failure caused by a cached SERVFAIL response. * Reject unsupported RSA DNSKEY shapes during DNSSEC validation. * Fix a bug in GeoIP2 string matching. * Fix DNS-over-HTTPS (DoH) quota configuration issue. * Truncated reply to a TSIG query no longer stalls the resolver. * Ignore updates removing DNSKEY RRset with class ANY. * Ignore 0-byte reads in the TCP read callback. * Only print per-zone glue stats when zone-statistics is set to full. * CDS/CDNSKEY records were not removed when re-configuring the server. * Fix a crash when querying an empty non-terminal in a wildcard zone in RBTDB. * Stop reusing outgoing TCP connections the peer has already closed. * Fix DNSSEC validation failures for names under an apex DNAME. ==== ca-certificates ==== Version update (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) - Update to version 2+git20260727.241e0ff: * certbundle.run: fix case where cafile does not exist ==== chrony ==== Subpackages: chrony-pool-openSUSE - Potential incompatibility! Extend UsrEtc (/usr/etc) support to the main configuration: * Ship the vendor chrony.conf and the chrony.d pool defaults under /usr/etc instead of /etc. * chronyd.service now uses /etc/chrony.conf when it exists and falls back to /usr/etc/chrony.conf otherwise (chrony-usretc-service.patch) * Use the confdir directive for chrony.d so that files in /etc/chrony.d override same-named vendor files in /usr/etc/chrony.d * Preserve admin-modified /etc/chrony.conf and /etc/chrony.d/pool.conf across the upgrade via the standard .rpmsave migration scriptlets. * chrony.keys stays in /etc. * To add the new chrony.d overlay/fallback mechanism to existing configurations the "include" line at the end of /etc/chrony.conf needs to be replaced by the "confdir" line from the new /usr/etc/chrony.conf file. ==== cryptsetup ==== Version update (2.8.6 -> 2.8.7) Subpackages: cryptsetup-doc libcryptsetup12 - Update to 2.8.7: * Changes related to Linux kernel AF_ALG crypto userspace interface deprecation Linux kernel maintainers decided to deprecate the AF_ALG interface, which was heavily used by cryptsetup, with the plan to remove it (or severely limit it) for security reasons. Libcryptsetup uses userspace (primarily via AF_ALG) for processing LUKS keyslots and for on-disk metadata handling for other formats. Using AF_ALG ensured that the same set of algorithms is present in userspace and later in-kernel for device activation. While libcryptsetup has a concept of fallback to userspace library, it was not used in all situations. In this version, libcryptsetup can use a userspace crypto library, AF_ALG (if present), and in some situations (LUKS keyslots), fallback to a temporary dm-crypt mapping. The last option requires root privileges. This ensures that most operations will continue to work even when AF_ALG is disabled or limited. Unfortunately, removing the AF_ALG could cause severe compatibility issues if the required algorithm (or encryption mode) is not implemented in the userspace library. A typical example is the Adiantum cipher, which is implemented only in the kernel. Also, ciphers like Serpent or Twofish (in XTS mode) are missing from several userspace libraries. The cryptsetup benchmark for ciphers is no longer available if the AF_ALG interface is unavailable. * Keyring handling changes. Libcryptsetup can use the kernel keyring to transfer the volume key into the kernel, avoiding sending it as a parameter to system calls. In previous versions, the volume key could be stored in the thread keyring, which should be removed when the process exits. Unfortunately, the thread keyring can remain active in some situations (such as when allocating a loop device). This could be a problem after calling luksSuspend when the volume key could remain in memory. Instead of loading volume keys directly into the thread keyring, cryptsetup now creates an intermediary keyring linked into the thread keyring and loads volume keys there. The intermediary keyring is now removed in the libcryptsetup context destructor (usually on application exit). Note that in previous versions, volume keys persisted until the process exited (even after the context destructor was called). * Changes related to possible LUKS volume key digest collisions. LUKS on-disk metadata uses a volume key digest generated by the PBKDF2 key-derivation algorithm to verify that the decrypted volume key is valid. The use of PBKDF2 (instead of a more suitable cryptographic digest algorithm) is part of the original LUKS design. It was retained for LUKS2 for compatibility (it allows easy in-place conversion). However, PBKDF2 has several design flaws. As it is based on HMAC (Hash-based Message Authentication Code), it also inherits the weak-key HMAC issue. In HMAC, the key can be arbitrarily long. If the key is shorter than the hash internal block size, it is padded with zeroes to a full block size. This flawed padding causes any HMAC key (shorter than the specified block size) to collide with keys that have added trailing zeroes. A collision means that HMAC (and PBKDF2) has the same output for colliding keys. In LUKS, a PBKDF2 collision is not a security issue; it cannot compromise data confidentiality. Moreover, the colliding key has a different length and should be rejected by the underlying block cipher. Unfortunately, in some reencryption scenarios (e.g., a header without keyslots), a collision key could be accepted, leading to possible data corruption. Code now always validates the expected key length. This validation is now strictly implemented in LUKS metadata processing. In the long term, LUKS will need to upgrade to a better volume key digest algorithm, but that will make the format backward-incompatible. * Support Aria and Camellia ciphers in the libgcrypt cryptographic backend. * Fix pkg-config library entry for the Mbed TLS cryptographic backend. * Better document CRYPT_VOLUME_KEY_NO_SEGMENT and CRYPT_VOLUME_KEY_DIGEST_REUSE API flags. The keyslot created with the CRYPT_VOLUME_KEY_NO_SEGMENT flag must always be unbound (not assigned to the default data segment). The use of the CRYPT_VOLUME_KEY_DIGEST_REUSE flag does not make sense without the CRYPT_VOLUME_KEY_NO_SEGMENT or CRYPT_VOLUME_KEY_SET flags. * Fix several possible corner cases in OpenSSL cryptographic backend (based on AI analysis). These include checking before casting from size_t to int, checking return values for the old OpenSSL HMAC API, avoiding sending a partial buffer to the caller if the operation fails, and explicitly checking for buffer length overflow. Most of these cannot happen in the libcryptsetup context, but the cryptographic backend can be used for other projects. * Code hardening based on various AI analysis reports. Including a fix for snprintf truncation in libdevmapper code, avoiding possible leak of JSON keyslot object on error path, and a fix for reencryption temporary device name. * Fix jq (JSON commandline processor) use in testing scripts. After the security update for jq, it no longer processes JSON with trailing zeroes. Regression test scripts were updated to avoid using this scenario. * Add support for --integrity-legacy-hmac in integritysetup open command. Integritysetup open command incorrectly configured options for legacy HMAC devices. To use --integrity-legacy-hmac, it must now be used both on format and open. * Fix cryptsetup --tries option not to overflow for high values. * Remove patches upstream: - cryptsetup-Add-keyring-key-type.patch - cryptsetup-Load-volume-keys-in-intermediary-keyring-linked-in-t.patch - cryptsetup-Use-unique-intermediary-keyring-name-per-device.patch - cryptsetup-tests-revoke-keys-instead-unlinking-from-thread-keyr.patch - cryptsetup-tests-verify-VK-and-internal-keyring-cleanup-after-p.patch - cryptsetup-tests-refactor-keyring-helpers.patch - cryptsetup-tests-verify-intermediary-keyring-cleanup-after-cryp.patch ==== evince ==== Subpackages: evince-plugin-pdfdocument libevdocument3-4 libevview3-3 typelib-1_0-EvinceDocument-3_0 typelib-1_0-EvinceView-3_0 - Add evince-CVE-2026-63729.patch: Fix use-after-free in synctex_parser.c from TeX Live (bsc#1272433). ==== faad2 ==== Version update (2.11.2.git13 -> 2.11.2.git18) - Update to version 2.11.2.git18: * fix signed overflow in fixed-point sample rounding before saturation * prevent num_bits_left underflow in ps_data extension parsing * cap escape length in huffman_spectral_data_2 * fix signed overflow in estimate_current_envelope energy sum * fix ssr_gc_function signature mismatch in ssr gain control ==== freerdp ==== Version update (3.28.0 -> 3.30.0) Subpackages: libfreerdp3-3 librdtk0-0 libwinpr3-3 - Add build conditional for faad2, separate sdl package - Add pkgconfig(faad2) BuildRequires and pass -DWITH_FAAD2=ON to cmake: Support audio via optional faad2 codec. - Drop pkgconfig(gstreamer-1.0) and pkgconfig(gstreamer-plugins-base-1.0) BuildRequires, and stop passing -DWITH_GSTREAMER_1_0=ON and -DWITH_GSTREAMER_0_10=OFF to cmake, they are off by default and deprecated. - Update to version 3.30.0: + Security, bugfix and maintenance release. + CVE fixes: * CVE-XXXX-XXXXX (GHSA-m37j-jcr2-8gcc) * CVE-XXXX-XXXXX (GHSA-vv64-95pc-vj9v) * CVE-XXXX-XXXXX (GHSA-rqgv-grx4-xm6x) + Changes: * Logon info update (#13060) * Websocket regression fix (#13064) * Sdl clipbaord and bounds checks (#13065) * [core,rdstls] improve version handling (#13066) * [channels,drdynvc] fix channel unref on create request send failure (#13067) * Audin checks (#13068) * [channels,rdpsnd] tighten bounds checks (#13070) * Pcap cleanup (#13071) - Update to version 3.29.0: + Security, bugfix and maintenance release. + CVE fixes: * CVE-XXXX-XXXXX (GHSA-43hh-p3vw-hfx3) * CVE-XXXX-XXXXX (GHSA-ph3q-f9w8-7jf3) * CVE-XXXX-XXXXX (GHSA-mwwh-mhp9-q7vm) * CVE-XXXX-XXXXX (GHSA-whq8-c3v3-p8v8) * CVE-XXXX-XXXXX (GHSA-hgj8-g595-wfc6) * CVE-XXXX-XXXXX (GHSA-8v6m-2cmc-chx9) * CVE-XXXX-XXXXX (GHSA-5wr6-8m8j-3h7f) * CVE-XXXX-XXXXX (GHSA-89c6-jjrw-96h4) * CVE-XXXX-XXXXX (GHSA-8xqm-wp3f-rfp9) * CVE-XXXX-XXXXX (GHSA-jm8r-22j6-4m4v) * CVE-XXXX-XXXXX (GHSA-2c6r-4pr4-9x8m) * CVE-XXXX-XXXXX (GHSA-qmvw-52ph-q5pv) * CVE-XXXX-XXXXX (GHSA-34hq-hwjw-q8v3) * CVE-XXXX-XXXXX (GHSA-33gg-h66j-3697) * CVE-XXXX-XXXXX (GHSA-vxp3-7g6q-rq2w) * CVE-XXXX-XXXXX (GHSA-v89x-pc32-hqr7) * CVE-XXXX-XXXXX (GHSA-pfxq-3qmw-8vjx) * CVE-XXXX-XXXXX (GHSA-78jj-45vh-jpm5) * CVE-XXXX-XXXXX (GHSA-69xf-pqrw-596x) * CVE-XXXX-XXXXX (GHSA-8jj2-67pg-j6mg) * CVE-XXXX-XXXXX (GHSA-qrxx-7g3c-j6w3) * CVE-XXXX-XXXXX (GHSA-cj9v-h4hq-29jr) + Changes: * [client,sdl] Handle requested clipboard MIME formats (#13007) * [client,x11] Fix RAIL HiDef window maximize (#13010) * [channels,rdpecam] filter devices without supported formats (#13015) * [codec,planar] fix input checks (#13016) * [client] do not build wayland and windows (#13017) * [client,windows] add server response size check (#13018) * fix processImageName length check in rail get appid resp ex (#13020) * [channels,rdpecam] add data validity checks (#13021) * Scard alloc update reorder (#13022) * H264 decoder surface dimension mismatch (#13024) * [core,security] reject short server random in security_establish_keys (#13023) * Async update (#13025) * [core,rdstls] add endpoint FedAuth token authentication (#13026) * Resource limits (#13027) * Path checks (#13028) * [emu,scard] require Lc of 2 for select-by-FID in vgids_ins_select (#13030) * runtime hardening (#13032) * H264 fix (#13036) * [crypto,x509] improve hardening against embedded \0 (#13035) * [core,rail] unify RAIL_UNICODE_STRING handling (#13039) * [channels,rail] rail_server_handle_messages (#13037) * [channels,rdpecam] fix reading of config descriptor (#13042) * [codec,av1] bound decode output to decoded frame size (#13044) * Bounds check fixes (#13043) * [codec,av1] add region rects checks like with AVC modes (#13045) * Ios fixes (#13029) * Ios warn fixes (#13047) * [utils,smartcard] exclude ndr padding from returned buffer length (#13046) * Serial alloc checks (#13049) * Android build fixes (#13050) * [client,android] update build (#13051) ==== fwupd ==== Version update (2.1.6 -> 2.1.7) Subpackages: fwupd-bash-completion libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.7: + This release adds the following features: - Add "well known" AppStream IDs for common BIOS settings - Add MTD lock security attribute - Add support for "externally managed" EFI signature lists - Add systemd-pcrlock plugin and hook up to UEFI updates - Add TCG disk encryption security attribute - Enable more plugins when compiling for Android + This release fixes the following bugs: - Add wrappers for input streams for future Rust implementations - Allow overriding some methods in FwupdClient for a future refactor - Allow plain string versions for some AMD GPUs - Allow suspend-to-ram with encrypted RAM - Always test Dell dock type when connected - Avoid possible out-of-bounds read in when parsing the DFU sector - Do not abort when udisks cannot resolve a device - Do not allow force installs over D-Bus - Do not fail to start when a pre-group comment has no keys set - Fall back to copying the file descriptor contents when not sealed - Fix dropped status updates during updates - Fix FW update for Lenovo TBT5 Smart Dock 7500 - Fix fwupd-refresh.service polkit auth errors - Fix segfault parsing some logitech-hidpp bootloader records - Fix the seal self tests when building on a tmpfs - Fix update failure when the TP IC is in bootloader-only mode - Mark Coreboot VBOOT as obsoleting BootGuard verified - Move more per-class limits to the class instances to reduce RSS - Prepare modem-manager firmware after firehose detach - Reject out-of-range CCGX device mode before indexing versions - Require trusted metadata for device updates - Require trusted metadata when using OnlyTrusted - Skip modem-manager secboot status when unsupported - Use safe reads for synaptics-rmi device responses - Validate GUID-defined section offset against EFI section size + This release adds support for the following hardware: - PixArt PJP360 device ==== gcc ==== Version update (15 -> 16) - Bump GCC version to 16, leave -build flavor at 13. - Add packages for Algol 68. - Disable gccgo for loongarch64. ==== gcc16 ==== Version update (16.1.1+git8886 -> 16.1.1+git9481) Subpackages: cpp16 libasan8 libatomic1 libgcc_s1 libgccjit0 libgfortran5 libgomp1 libhwasan0 libitm1 liblsan0 libobjc4 libstdc++6 libstdc++6-pp libtsan2 libubsan1 - Update to gcc-16.1.1+git9481, GCC 16.2 RC1 - Update to gcc-16.1.1+git9423 - Build a full cross-x86_64 compiler [bsc#1272616], but not on %ix86 - Update gcc15-Wtime_t-conversion.patch - Make build recipe compatible with POSIX sh - do not pass in -fhardened ==== gd ==== Subpackages: libgd3 - added patches CVE-2026-9672: upgrade gd [bsc#1273101] * gd-CVE-2026-9672.patch ==== glib2 ==== Version update (2.88.2 -> 2.88.3) Subpackages: glib2-tools libgio-2_0-0 libgirepository-2_0-0 libglib-2_0-0 libgmodule-2_0-0 libgobject-2_0-0 libgthread-2_0-0 typelib-1_0-GIRepository-3_0 typelib-1_0-GLib-2_0 typelib-1_0-GLibUnix-2_0 typelib-1_0-GModule-2_0 typelib-1_0-GObject-2_0 typelib-1_0-Gio-2_0 - Update to version 2.88.3 (CVE-2026-15588): + Fix potential miscompilation with GCC 17 with `G_GNUC_CONST` on `get_type()` functions + Bugs fixed: - G_GNUC_CONST vs get_type comes home to roost - (CVE-2026-15588) Security report: GDBusServer pre-authentication DoS via unbounded SASL line buffering - Drop G_GNUC_CONST for *_get_type - gdbusauth: Limit length of lines read from client - gdbusauth: Unmark a new string as translatable - Several Meson/gcc fixes ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-arm64-efi-bls grub2-common grub2-snapper-plugin grub2-systemd-sleep-plugin - Fix KVM and Xen VM images taking too long to boot (bsc#1266384) * 0001-cacheinfo-fix-hit-ratio-calculation-and-statistics-o.patch * 0002-disk-fix-cache-lock-and-hit-counter-for-invalidated-.patch * 0003-disk-reduce-cache-slot-thrashing.patch - Replace patch with upstreamed version * 0001-test-Fix-f-test-on-files-over-network.patch * 0002-http-Return-HTTP-status-code-in-http_establish.patch * 0003-docs-Clarify-test-for-files-on-TFTP-and-HTTP.patch * 0004-tftp-Fix-hang-when-file-is-a-directory.patch ==== gtk-vnc ==== Subpackages: libgtk-vnc-2_0-0 libgvnc-1_0-0 libgvncpulse-1_0-0 - Replace BuildRequires on python3-devel with python3-base ==== gvfs ==== Subpackages: gvfs-backend-afc gvfs-backend-goa gvfs-backend-gphoto gvfs-backend-samba gvfs-backends gvfs-fuse - don't package capabilities in RPM but rely on permissions profiles instead (bsc#1268674). An upcoming change in rpmlint will raise badness when capabilities are directly packaged in an RPM. gvfsd-nfsd is already whitelisted in the permissions profiles and the proper capabilities will be assigned during %post. ==== hwinfo ==== Version update (25.4 -> 25.5) Subpackages: libhd25 - merge gh#openSUSE/hwinfo#187 - small adjustments to bash-completion, update spec file - 25.5 - merge gh#openSUSE/hwinfo#183 - add bash completion script for hwinfo - merge gh#openSUSE/hwinfo#186 - serial driver file name changed in /proc in current kernel, adjusting code (bsc#1271724) ==== inxi ==== Version update (3.3.40 -> 3.3.41) - Update to version 3.3.41: * A few minor errors in gpu id led to a long needed update to gpu data sources and detection logic, as well as forcing some known gpu IDs to the right generation. ==== kernel-firmware-amdgpu ==== Version update (20260629 -> 20260717) - Update to version 20260717 (git commit fb91c990e602): * amdgpu: DMCUB updates for various ASICs * amdgpu: DMCUB updates for various ASICs ==== kernel-firmware-bluetooth ==== Version update (20260629 -> 20260720) - Update to version 20260720 (git commit 18cf97993f06): * linux-firmware: Add firmware file for Intel BlazarIW * linux-firmware: Update firmware file for Intel BlazarU core * linux-firmware: Update firmware file for Intel BlazarI core * linux-firmware: Update firmware file for Intel Scorpius core - Update to version 20260703 (git commit c95059a3774b): * QCA: Add Bluetooth firmware for WCN6855 ROM 1.0 ==== kernel-firmware-platform ==== Version update (20260629 -> 20260717) - Update to version 20260717 (git commit fb91c990e602): * powervr: add firmware for Imagination Technologies BXM-4-64 GPU ==== kernel-firmware-qcom ==== Version update (20260629 -> 20260717) - Update to version 20260717 (git commit fb91c990e602): * qcom: add ADSP firmware for hawi platform * qcom: Update DSP firmware for sa8775p platform ==== kernel-source ==== Version update (7.1.4 -> 7.1.5) Subpackages: kernel-64kb kernel-default - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (git-fixes). - commit 862e13e - Linux 7.1.5 (bsc#1012628). - crypto: algif_skcipher - force synchronous processing (bsc#1012628). - iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry (bsc#1012628). - crypto: sun4i-ss - Remove insecure and unused rng_alg (bsc#1012628). - media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work (bsc#1012628). - ALSA: hda/realtek: Add quirk for TongFang X6xx45xU (bsc#1012628). - ALSA: hda: conexant: Remove mic bias threshold override (bsc#1012628). - ALSA: hda: Fix cached processing coefficient verbs (bsc#1012628). - ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7 (bsc#1012628). - media: uvcvideo: Use hw timestaming if the clock buffer is full (bsc#1012628). - media: uvcvideo: Avoid partial metadata buffers (bsc#1012628). - media: uvcvideo: Fix buffer sequence in frame gaps (bsc#1012628). - media: uvcvideo: Fix dev_sof filtering in hw timestamp (bsc#1012628). - media: uvcvideo: Do not add clock samples with small sof delta (bsc#1012628). - media: uvcvideo: Relax the constrains for interpolating the hw clock (bsc#1012628). - media: uvcvideo: Fix sequence number when no EOF (bsc#1012628). - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (bsc#1012628). - dt-bindings: power: imx93: Add MIPI PHY power domain (bsc#1012628). - serial: msm: Disable DMA for kernel console UART (bsc#1012628). - serial: max310x: implement gpio_chip::get_direction() (bsc#1012628). - serial: 8250_omap: clear rx_running on zero-length DMA completes (bsc#1012628). - rxrpc: serialize kernel accept preallocation with socket teardown (bsc#1012628). - rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc (bsc#1012628). - rxrpc: Don't move a peeked OOB message onto the pending queue (bsc#1012628). - rxrpc: Fix UAF in rxgk_issue_challenge() (bsc#1012628). - rxrpc: Fix socket notification race (bsc#1012628). - rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) (bsc#1012628). - rxrpc: Fix potential infinite loop in rxrpc_recvmsg() (bsc#1012628). - rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate (bsc#1012628). - rxrpc: Fix oob challenge leak in cleanup after notification failure (bsc#1012628). - rxrpc: Fix ACKALL packet handling (bsc#1012628). - rxrpc: Fix the reception of a reply packet before data transmission (bsc#1012628). - rxrpc: Fix leak of connection from OOB challenge (bsc#1012628). - rxrpc: Fix double unlock in rxrpc_recvmsg() (bsc#1012628). - afs: Fix netns teardown to cancel the preallocation charger (bsc#1012628). - afs: fix NULL pointer dereference in afs_get_tree() (bsc#1012628). - afs: handle CB.InitCallBackState3 requests without a server record (bsc#1012628). - afs: Fix further netns teardown to cancel the preallocation charger (bsc#1012628). - afs: Fix uncancelled rxrpc OOB message handler (bsc#1012628). - fbcon: fix NULL pointer dereference for a console without vc_data (bsc#1012628). - fbcon: Use correct type for vc_resize() return value (bsc#1012628). - soc: fsl: qe_ports_ic: Add missing cleanup on device removal (bsc#1012628). - openrisc: mm: Fix section mismatch between map_page and __set_fixmap (bsc#1012628). - clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() (bsc#1012628). - accel/amdxdna: Fix leak when pinning ubuf pages (bsc#1012628). - drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() (bsc#1012628). - drm/rockchip: dw_dp: Switch to drmm_kzalloc() (bsc#1012628). - drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() (bsc#1012628). - drm/rockchip: Test for imported buffers with drm_gem_is_imported() (bsc#1012628). - drm/tidss: Drop extra drm_mode_config_reset() call (bsc#1012628). - drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges (bsc#1012628). - accel/amdxdna: Create shared functions for AIE2 and AIE4 (bsc#1012628). - accel/amdxdna: Adjust size for copy_to_user() (bsc#1012628). - accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path (bsc#1012628). - accel/amdxdna: Fix iommu_map_sgtable() return value handling (bsc#1012628). ... changelog too long, skipping 3694 lines ... - commit 5c9ff0f ==== libapparmor ==== Version update (5.0.1 -> 5.0.2) - update to AppArmor 5.0.2 - several fixes in utils, parser and some profiles - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_5.0.2 for the upstream changelog - remove upstreamed patches: - curl.diff - lsblk-mr2147.diff - add nslookup.diff to fix nslookup output ==== libeconf ==== Version update (0.8.3 -> 0.8.4) - Update to version 0.8.4: * Described content of key_file in econf_readConfig* (#248) * Fix a missing word in README.md (#247) ==== libfastjson ==== Version update (1.2304.0 -> 1.2304.0+ga630254) - Employ a Source URL for the tarball - Modernize some macros - update to upstream git revision a630254 (boo#1272151) * fix: handle small buffered dump workspaces * docs: explain object child lookup traversal * benchmarks: address reproducibility review findings * speed up object child lookup * build: fix calloc transposed args * build: Use AC_CHECK_LIB to ensure libfastjson links against libm * Revert "build: link libfastjson against libm for modf()" * doc: clarify string buffer lifetime and thread safety * build: link libfastjson against libm for modf() * increment version number for next release cycle ==== libheif ==== Version update (1.23.0 -> 1.23.1) Subpackages: gdk-pixbuf-loader-libheif libheif-aom libheif-dav1d libheif-ffmpeg libheif-jpeg libheif-openh264 libheif-openjpeg libheif-rav1e libheif-svtenc libheif1 - Update to version 1.23.1: + FFmpeg decoder plugin gains AV1, VVC, JPEG, and JPEG 2000/HTJ2K decoding + SVT-AV1 encoder: new tune=iq and ms-ssim tune parameters + C++ API: added getters/setters for the CLLI and MDCV HDR metadata boxes + Sequence decoder now scales the alpha auxiliary track to the main image size + Fixed pixi box writing for multi-channel images + Corrected the placement of the TAI clock_type field into the top 2 bits + Empty/unset plugin directory is no longer scanned + CVE-2026-62289 (GHSA-jc8f-p23p-5hjg) Integer underflow in Fraction constructor via double clap transform application + CVE-2026-62291 (GHSA-xpw3-9rhw-482x) Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions + CVE-2026-62292 (GHSA-73p7-m7gg-w2jv) Out-of-bounds read in uncompressed unci tile range slicing + CVE-2026-62377 (GHSA-9ww4-9v47-m7pj) Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file + (GHSA-46rp-pcq2-rpmr) Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth ≤ 8 ==== libmysofa ==== Version update (1.3.3 -> 1.3.5) - Update to 1.3.5: * Harden HDF/SOFA parser against malformed input * Fixed issue with missing boundary check which lead to a stall - Changes in 1.3.4: * “fixes issues with v1.3.3” * added support for General FIR-E ==== libndp ==== Version update (1.8 -> 1.9) - Update to version 1.9: * ndptool: add support for PREF64 option * libndp: add support for PREF64 option * libndp: valid route information option length * SubmittingPatches: update mailing list - Drop libndp-CVE-2024-5564.patch: Fixed upstream. - Use modern macros, make_install and ldconfig_scriptlets. ==== libostree ==== Version update (2026.1 -> 2026.2) Subpackages: libostree-1-1 - Update to 2026.2: * Fix GVariant memory leak during opaque whiteout scanning that could cause bootc install to-disk to fail with EBUSY on unmount * Fix a crash for invalid UTF-8 ref names during pull operations * Fix Kernel argument handling was fixed to properly handle quoted values in /proc/cmdline * Correct staged deployment bootconfig merging to preserve options across re-staging ==== libpng16 ==== Version update (1.6.57 -> 1.6.58) - version update to 1.6.58: * Fixed a regression introduced in version 1.6.56 that caused `png_get_PLTE` to return stale palette data after applying gamma and background transforms in-place. ==== libssh ==== Version update (0.11.4 -> 0.11.5) Subpackages: libssh-config libssh4 - Update to 0.11.5: * Security: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction (bsc#1272162) - CVE-2026-59843: Denial of service via zero advertised channel packet size (bsc#1272164) - CVE-2026-59844: Denial of service via oversized SFTP read length (bsc#1272165) - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure (bsc#1272166) - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion (bsc#1272167) - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168) - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs (bsc#1272169) - CVE-2026-59849: Denial of service via automatic certificate authentication loop (bsc#1272170) - CVE-2026-59850: Use-after-free via data callbacks on closed channels (bsc#1272171) - Zero-initialize every ssh_string * Compatibility: - Fix compatibility with C23 / gcc16 * Bugfixes: - Fix multiple memory leaks, null checks, and error checks - Validate peer public key in DH key exchange - Avoid remote window overflow - Avoid off-by-one overflow during kbdint authentication - Avoid logging uninitialized sequence numbers - Avoid double conversion of SFTP version number - Send correct SFTP server version number - Avoid handling repeated SFTP INIT messages - Harmonize return values from SFTP server callbacks ==== libxmlb ==== Version update (0.3.27 -> 0.3.29) - Update to version 0.3.29: + Bugfixes: - Avoid stale query indexes when reloading the silo - Clear the query cache when reloading the silo - Correctly mark the silo as invalid when re-loading malformed data - Fix building the silo when shared-mime-info is installed - Changes from version 0.3.28: + New Features: - Automatically add system locales when using native-langs - Lower the Meson and GLib deps for RHEL-8 + Bugfixes: - Lazy clear opcode tokens for a ~2% speedup - Speed up negative queries by 11% by defer creating the results objects - Speed up predicates with no bindings by 9% - Speed up the no-results query by 2.5% by using a constant error ==== linux-glibc-devel ==== Version update (7.0 -> 7.1) - Update to kernel headers 7.1 ==== microos-tools ==== Version update (4.0+git24 -> 4.0+git28) - Update to version 4.0+git28: * Use zypp.conf.d dropin for ZYPP_SINGLE_RPMTRANS=1 - Update to version 4.0+git27: * Remove obsolete stuff (locale-check, salt-tmpdir) - Update to version 4.0+git26: * test: Check if autorelabel files are removed after reboot * Move cp of /.autorelabel to /etc into rd_microos_relabel ==== multipath-tools ==== Version update (0.14.3+212+suse.f5d32098 -> 0.15~1+230+suse.d36a6a70) Subpackages: kpartx libmpath0 - Update to version 0.15~1+230+suse.d36a6a70: * Even with the libudev wrapper code introduced in 0.14.0, multipathd ran into use-after-free errors in tests where multipathd was restarted frequently. Fix this by preventing thread cancellation during libudev calls. (gh#opensvc/multipath-tools#152). * libmultipath: async_checker: fix sync checker case (bsc#1272188) - Update to version 0.15~1+222+suse.cdcde840 (0.15 pre-release) * All path checkers run in asynchronous mode now by default, using a new generic asynchronous checker framework. This improves the stability of multipathd in the presence of non-responsive devices when using path checkers other than `tur` and `directio`. Use the `force_sync` parameter in `multipath.conf` to switch back to the previous, synchronous behavior, especially if you observe strong spikes of CPU load on systems with a lot of path devices. Note that the likelihood of such spikes should be strongly reduced since multipath-tools 0.10.0. Commit 6f7daba ff. * The configuration options `rr_min_io`, `rr_min_io_rq`, and `rr_weight` are now deprecated and have no effect. These options have not been supported by the kernel since version 4.6. Users should remove them from `multipath.conf`. * Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ("lba-dependent", "transitioning"). * Don't set a hardware handler for bio-based multipath devices. The kernel rejects this anyway. - Bug fixes: * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier. * kpartx: Fix an integer overflow in the GPT partition table size calculation. A crafted partition table with an extremely large number of partition entries could trigger the overflow. (bsc#1268145) * kpartx: Fix several issues in the DASD partition table reader that could be triggered by a maliciously crafted disk image. (bsc#1268144) * Fix duplicate "checker timed out" log messages when `log_checker_err` is set to `once`. (bsc#1254094) * Avoid potential buffer overflows in the iet and datacore prioritizers. * iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. (gh#opensvc/multipath-tools#145) * An overlong partition delimiter (-p option) could cause kpartx to crash. Fix it. * Man page improvements. ==== net-tools ==== Version update (3.14~alpha~git.20251212.7011617 -> 3.14~alpha~git.20260718.4f5bfb2) - Update to version 3.14~alpha~git.20260718.4f5bfb2: * Update config.in: disable AF and HW ROSE by default (obsoletes Update_config.in.patch) * netstat: Keep UTF-8 characters in process names (bsc#1254323, obsoletes net-tools-netstat-ansi-injection.patch) - Update to version 3.14~alpha~git.20260612.2ab3c5e: * netstat: Update email address * doc: describe missing headers * passes -Wunused-parameter * fix type limit warnings * Remove anchient gettext ABOUT-NLS * TODO: removed NLS, add -Wextra * INSTALLING: musl, all features, compile warning todos * netstat.8: minor edits * chore: pedantic zizmor is happy on GH actions * Unified man example format * netstat.8: warn on trustworthyness of program name * man: netstat: add two examples * Rarp: fix nullpointer on unknown hosts * netstat: safe cycles and fix comment * Sanitize cmdline (bsc#1254323, CVE-2024-58251) * Updated translations. - Add Update_config.in.patch: Update config.in: disable AF and HW ROSE by default. This is longer part of the kernel 7.1 source tree. ==== nghttp2 ==== Version update (1.69.0 -> 1.70.0) - Require the versions configure actually checks for: libnghttp3 >= 1.17.0 and libngtcp2 >= 1.23.0. Without them OBS starts the build and lets it fail in configure, instead of holding the package unresolvable until nghttp3 is in place - Update to 1.70.0: * nghttpx: add separate frontend and backend stream timeouts, plus an HTTP/2 stream write timeout * nghttpx: drop HTTP/2 and HTTP/3 connections whose frontend write rate is too low, so a peer can no longer hold a connection open by reading slowly * Rework HTTP header validation, and add the value check that was missing for the priority header field * Fix an out-of-bounds read in the base64 decoder * get_socket_error() now reports the errno of getsockopt() when that call itself fails, instead of a stale value * Update the bundled llhttp to 9.4.2 and mruby to 4.0.0, and refresh the bundled ngtcp2, neverbleed and sfparse * Large internal rework: nghttpx now carries its error paths in std::expected rather than out-parameters - Drop 0001-nghttpx-Tighten-up-CONNECT-and-HTTP-Upgrade-handling.patch, the fix is part of this release (CVE-2026-58055, bsc#1269489) - Mark the doc subpackage noarch, it ships documentation only and rpmlint rightly flagged it with no-binary - Run spec-cleaner: drop the Group tags and sort the build dependencies ==== nghttp3 ==== Version update (1.15.0 -> 1.18.0) - Update to 1.18.0: * Added nghttp3_conn_close_stream2 and the nghttp3_stream_close2 callback * Validate the header length against the estimated uncompressed length * Fix a build error with gcc-16 - Changes from 1.17.0: * Added nghttp3_conn_stream_flushed and public API to encode and decode variable-length integers * Fix header name validation - Changes from 1.16.0: * Added nghttp3_conn_get_stream_user_data * Call the nghttp3_stream_close callback for all streams * Fix a memory leak on the failure path * Ignore content-length for the extended CONNECT * Reject HTTP status codes with a leading zero * Optimize huffman decode length estimation - The library soname is unchanged at 9 ==== ntfs-3g_ntfsprogs ==== Version update (2022.10.3 -> 2026.7.7) Subpackages: ntfs-3g ntfsprogs - Update to version 2026.7.7: * (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616). * Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617). * Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618). * Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569). * Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571). * Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570). * Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572). * Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135). * Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136). - Drop patches fixed upstream: + ntfs3g-unistr-use-after-free.patch + ntfs3g-heap-overflow.patch + 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch + 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch + 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch + 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch + 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch + 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch + 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch ==== nvme-cli ==== Version update (3.0~b.3 -> 3.0~b.4) Subpackages: libnvme3-1 nvme-cli-bash-completion - Update to version 3.0~b.4: * Release v3.0-b.4 * doc: Regenerate all docs for v3.0-b.4 * libnvme/config: add epcsd supporting * libnvme/config: add support for persistent * libnvme/fabrics: remove pdc-enabled build time config * plugins/config: add create command * libnvme/config-emit: ensure config dir exists * shared/fs-util: add missing windows implementation * shared/fs-util: add sh_mkdir_from_fname and shr_dirname * shared: split platform parts into separate files * shared: update prefix for compiler attributes * doc: remove nvme-config.txt * plugins: invoke the arg parser for the remaining commands * discoverd: rename discoverd.conf to nvme-discoverd.conf * ocp: add NULL checks after memory allocation * ocp: fix __le64 usage in C9 log reading * ocp: fix use after free and memory leak related to C9 log page reads * ocp: use libnvme_alloc and libnvme_free for log buffer allocations * ocp: read telemetry log with maximum transfer size * innogrit: fix resource leak in innogrit_vsc_getcdump() * scaleflux: clamp code_type before array access in nvme_parse_evtlog() * wdc: fix out-of-bounds access in wdc_show_cloud_smart_log_normal() * micron: clean up and fix micron telemetry log reading * nbft: ensure transport buffer is null terminated in read_ssns() and read_hfi() * nvme-models: fix stream EOF state errors in __nvme_product_name and pull_class_info * ibm: fix missing break in show_ibm_smart_log() case 0x00f5 * nvme-rpmb: fix out-of-bounds allocation in read_rpmb_key() * tests: align config-convert expectation with preserved legacy json * plugins/ymtc: fix additional smart info display for YMTC PE511 * utils: check asprintf return value * util: fix memory leak in read_binary_file() * util: fix memory leak in read_binary_file() * utils: add crash handlers for option capture * nvme: avoid stale pointer in get_log_offset() * fabrics: avoid double free in build_options() * fabrics: avoid reduntant libnvmf_context_set_crypto() call * fabrics: avoid mem leak in libnvmf_context_set_crypto() * fabrics: accept fabrics arguments for disconnect * nvme: add arg parser to gen/show hostnqn * plugins/keys: report line number 1 based * plugins/keys: show error when missing trailing colon * plugins/keys: update help text for gen-tls * fabrics: add --kxchap-* arguments * nvme: add compat tls/chap key management commands * libnvme: rename DH-HMAC- prefix with KX-HMAC- * tests: add nvme keys tests cases * nvme: split keyring insert out of keys check-tls/check-dhchap * nvme: move key commands into new keys plugin * shared: add more test coverage * libnvme: return libnvmf_tid_parse{,_strict}() as int, not a pointer * libnvme/nbft: tests: Regenerate reference NBFT table dumps * nvme: preserve legacy json config for rollbacks * libnvme: reuse heap reader for NBFT security lists * libnvme: fix comments that still describe removed JSON config support * libnvme/nbft: Add sample synthetic NBFT tables * shared: move init unit test * shared: move compiler-attributes to common code * libnvme: return libnvmf_tid_from_fields() as int, not a pointer * nvme: fix to check sanitize status error * nbft-plugin: fix resource leak in show_nbft() * discoverd: parse discoverd.conf with the shared ini parser * libnvme: parse NBFT Security Profile descriptors * doc: add nvme-discoverd(8) and the design README * meson: make nvmf-autoconnect independently toggleable * discoverd: add the nvme-discoverd daemon * libnvme: harden NBFT interface references * libnvme: validate NBFT descriptor ranges * libnvme: drop test/ioctl's own freep(), use shared/cleanup.h * shared: add README * shared: add test coverage for array-util, base64, crc32 * shared: rename everything to the shr_ namespace * shared: add PTRARRAY_DEFINE() for type-checked ptrarray wrappers * shared: dedup cleanup.h boilerplate * shared: move base64, crc32, and misc utility functions * shared: fix mkdir_p() silently truncating long paths * shared: relicense to LGPL-2.1-or-later * sfx-nvme: fix resource leak in sfx_status() * nbft: fix resource leak of ssns->hfis in read_ssns() * sndk plugin: Fix vs-smart-add-log for NVMe OF * nvme: add utils dump-command-metadata command * memblaze: fix stack overflow in perf-stats-print-x * nvme: add global options config file * shared: move ini parser to common code * nvme: move args into separate header * nvme: do not include libnvme-mi on global level * nvme: change verbosity type * util/json: use stdint types * shared: add a small static utility library * wdc: free dssd_specific_ver when smart_log_ver < 3 * virtium: remove erroneous (float) cast in vt_save_smart_to_vtview_log() * nvme-print: print address instead of traddr * nvme: replace argconfig_parse with parse_args * nvme-cli: resolve hostnqn/hostid on ctx creation * libnvme/tree: free hnqn/hid in error path * sfx-nvme: fix dead assignment in sfx_dump_evtlog() * exclusion: fix uninitialized argument in libnvmf_exclusion_read() * nvme: Fix get-log xfer-len parameter handling * libnvme: generate the trivial libnvme_global_ctx bool accessors ... changelog too long, skipping 105 lines ... unpackaged files. ==== openSUSE-release ==== Version update (20260724 -> 20260802) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openblas_openmp ==== Subpackages: compatlibopenblas_openmp0 libopenblas_openmp0 - Keep building the devel libraries on the "serial" flavour with alternatives enabled, as they can be installed in parallel and there is the flexiblas integration interwined with them - Build the devel libraries on the same flavour set as default for the building architecture (pthreads in x86_64, openmp elsewhere) - On systems built without alternatives mode, ensure the various libopenblas_FLAVOUR packages conflict with each other. ==== openblas_pthreads ==== Subpackages: compatlibopenblas_pthreads0 libopenblas_pthreads0 - Keep building the devel libraries on the "serial" flavour with alternatives enabled, as they can be installed in parallel and there is the flexiblas integration interwined with them - Build the devel libraries on the same flavour set as default for the building architecture (pthreads in x86_64, openmp elsewhere) - On systems built without alternatives mode, ensure the various libopenblas_FLAVOUR packages conflict with each other. ==== openssh ==== Version update (10.3p1 -> 10.4p1) Subpackages: openssh-clients openssh-common openssh-server - Add patch submitted to upstream to fix GSSAPI* options not working after servconf refactoring (https://bugzilla.mindrot.org/show_bug.cgi?id=3974): * 0001-Fix-GSSAPI-server-option-names.diff - Rebase patches: * openssh-8.0p1-gssapi-keyex.patch * openssh-7.7p1-gssapi-new-unique.patch - Update to openssh 10.4p1: = Potentially-incompatible changes * sshd(8): configuration dump mode ("sshd -G") now writes directives in mixed case (e.g. "PubkeyAuthentication") whereas previously it emitted only lower-case names. * sshd(8): on Linux systems with the seccomp sandbox enabled, failures to enable SECCOMP or NO_NEW_PRIVS are now fatal. Previously sshd(8) would log the error but continue operation, to support systems that lacked these features. Now systems that lack these should instead disable the sandbox at configure time. * ssh(1), sshd(8): make the transport protocol stricter by disconnecting if the peer sends non-KEX messages during a post- authentication key re-exchange. Previously a malicious peer could continue sending non-key exchange messages without penalty. These would be buffered, causing memory to be wasted up until the connection terminated or the server/client hit a memory limit. Implementations that do not restrict messages sent during key exchange as per RFC4253 section 7.1 may be disconnected. Reported by Marko Jevtic. = Security * sftp(1): when downloading files on the command-line using "sftp host:/path .", a malicious server could cause the file to be downloaded to an unexpected location. This issue was identified by the Swival Security Scanner. * scp(1): when copying files between two remote destinations, do not allow a malicious server to write files to the parent directory of the intended target directory. This issue was identified by the Swival Security Scanner. * sshd(8): when using the "internal-sftp" SFTP server implementation (this is not the default), long command lines were previously truncated silently after the 9th argument. If a security-relevant option was in the 10th or later position, it would be discarded. Reported by Steve Caffrey. * sshd(8): add a documentation note to mention that the GSSAPIStrictAcceptorCheck option is ineffective when the server is joined to a Windows Active Directory. Reported by Yarin Aharoni of Safebreach. * sshd(8): DisableForwarding=yes didn't override PermitTunnel=yes as it was documented to do. Note that PermitTunnel is not enabled by default. Reported independently by Huzaifa Sidhpurwala of Redhat and Marko Jevtic. * sshd(8): avoid a potential pre-authentication denial of service when GSSAPIAuthentication was enabled (this feature is off by default). This was not mitigated by MaxAuthTries, but would be penalised by PerSourcePenalties. This was reported by Manfred Kaiser of the milCERT AT (Austrian Ministry of Defence). * sshd(8): fix a number of cases where the minimum authentication delay was not being enforced. Reported by the Orange Cyberdefense Vulnerability Team. * ssh(1): fix a possible client-side use-after-free if the server changes its host key during a key reexchange. This was reported by Zhenpeng (Leo) Lin of Depthfirst. = New features * All: add experimental support for a composite post-quantum signature scheme that combines ML-DSA 44 and Ed25519 as specified in draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not enabled by default. To use it, you'll need to add it to HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be generated using "ssh-keygen -t mldsa44-ed25519". * ssh(1), sshd(8): replace the wildcard pattern matcher with an implementation based on an NFA. This avoids exponential worst-case behaviour for the old implementation. = Bugfixes * ssh-agent(1): fix incorrect reply to "query" SSH_AGENTC_EXTENSION requests. bz3967 * sshd(8): avoid sending observably different messages for valid vs invalid users in GSSAPIAuthentication (disabled by default). * ssh(1), sshd(8): fix several bugs that incorrectly classified bulk traffic as interactive. bz3972, bz3958 * ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading resident keys from a FIDO token. Previously, downloads would abort when one was encountered. GHPR657 * ssh(1): fix a potential use-after-free on an error path if cipher_init() fails. * sshd(8): perform stricter encoding and validation of transport state passed between sshd privilege separation subprocesses. This somewhat further hardens the server against attacks on sshd-auth or sshd-session subprocesses. * ssh-agent(1): avoid possible runtime denial of service by enforcing some limits on the length of usernames in key use constraints. * sftp(1): fix two separate one-byte out-of-bounds reads, in SSH2_FXP_REALPATH and batch command processing. * sftp-server(8): disallow use of the copy-data extension to read and write to the same inode simultaneously. * ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent. GHPR679 * sftp(1), scp(1): avoid a situation where sftp_download() could get stuck in a loop if a broken server repeatedly returned zero length while reading a file. ... changelog too long, skipping 79 lines ... * fix-mac-validation-strsep-logic-bug.patch ==== openssh-askpass-gnome ==== Version update (10.3p1 -> 10.4p1) - "Update" to openssh 10.4p1: * No changes for askpass, see main package changelog for details. ==== pam ==== Version update (1.7.2+git12 -> 1.7.2+git48) - Update to version 1.7.2+git48: * pam_unix: make SHA512 the default * po: update translations using Weblate (Hebrew) * po: update translations using Weblate (Russian) * po: update translations using Weblate (Greek) * po: update translations using Weblate (Norwegian Nynorsk) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Serbian) * po: update translations using Weblate (Polish) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Hungarian) * po: add translation using Weblate (Kabyle) * po: update translations using Weblate (Indonesian) * po: update translations using Weblate (Lithuanian) * po: update translations using Weblate (Italian) * po: update translations using Weblate (Finnish) * po: update translations using Weblate (Slovenian) * po: update translations using Weblate (Spanish) * po: update translations using Weblate (Punjabi) * po: update translations using Weblate (Kazakh) * po: update translations using Weblate (Swedish) * po: update translations using Weblate (Ukrainian) * po: update translations using Weblate (Portuguese (Brazil)) * po: update translations using Weblate (Turkish) * po: update translations using Weblate (Georgian) * po: update translations using Weblate (Romanian) * po: update translations using Weblate (Czech) * po: update translations using Weblate (Korean) * Update translation files * pam_userdb: fix password comparison timing leak * meson: use an empty array for link args instead of an empty string * pam_succeed_if: prevent logging unknown user names in plaintext * pam_limits: improve 'wrong limit value' log message * pam_pwhistory: allow earlier passwords when remember count is reduced * pam_namespace: fix error handling in secure_opendir() * pam_rhosts: fix typos in pam_rhosts(8) man page * .github: add gcc-15 jobs - Obsoletes pam_userdb-fix-password-comparison-timing-leak.patch ==== pam-full-src ==== Version update (1.7.2+git12 -> 1.7.2+git48) Subpackages: pam-extra pam-manpages - Update to version 1.7.2+git48: * pam_unix: make SHA512 the default * po: update translations using Weblate (Hebrew) * po: update translations using Weblate (Russian) * po: update translations using Weblate (Greek) * po: update translations using Weblate (Norwegian Nynorsk) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Serbian) * po: update translations using Weblate (Polish) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Hungarian) * po: add translation using Weblate (Kabyle) * po: update translations using Weblate (Indonesian) * po: update translations using Weblate (Lithuanian) * po: update translations using Weblate (Italian) * po: update translations using Weblate (Finnish) * po: update translations using Weblate (Slovenian) * po: update translations using Weblate (Spanish) * po: update translations using Weblate (Punjabi) * po: update translations using Weblate (Kazakh) * po: update translations using Weblate (Swedish) * po: update translations using Weblate (Ukrainian) * po: update translations using Weblate (Portuguese (Brazil)) * po: update translations using Weblate (Turkish) * po: update translations using Weblate (Georgian) * po: update translations using Weblate (Romanian) * po: update translations using Weblate (Czech) * po: update translations using Weblate (Korean) * Update translation files * pam_userdb: fix password comparison timing leak * meson: use an empty array for link args instead of an empty string * pam_succeed_if: prevent logging unknown user names in plaintext * pam_limits: improve 'wrong limit value' log message * pam_pwhistory: allow earlier passwords when remember count is reduced * pam_namespace: fix error handling in secure_opendir() * pam_rhosts: fix typos in pam_rhosts(8) man page * .github: add gcc-15 jobs - Obsoletes pam_userdb-fix-password-comparison-timing-leak.patch ==== perl-Net-DNS ==== Version update (1.550.0 -> 1.560.0) - updated to 1.560.0 (1.56) see /usr/share/doc/packages/perl-Net-DNS/Changes Fix rt.cpan.org #180088 Documentation issue for Net::DNS::RR::RRSIG::verify() Fix rt.cpan.org #179946 Denial of Service via long DNS compression chains CVE-2026-64194 bsc#1272214 Fix rt.cpan.org #179945 Remote code injection via EDNS EXTENDED ERROR CVE-2026-64193 bsc#1272212 Fix rt.cpan.org #179692/#176900 UNIX.pm: Unreachable code warning using Apache/mod_perl ==== permissions ==== Version update (1699_20260715 -> 1699_20260728) Subpackages: permctl permissions-config - Update to version 1699_20260728: * profiles: whitelist selinux-sandbox seunshare (bsc#1268256) * profiles: drop netcfg /etc/exports - Update to version 1699_20260723: * profiles: add cap_net_admin for cloud-hypervisor (bsc#1270717) - Update to version 1699_20260722: * profiles: fix ksystemstats6 bsc# reference syntax * profiles: add noisetorch cap_sys_resource (bsc#1270715) - Update to version 1699_20260716: * profiles: reintroduce apptainer starter-suid (bsc#1268675) ==== php8 ==== Version update (8.5.8 -> 8.5.9) Subpackages: php8-ctype php8-dom php8-iconv php8-openssl php8-pdo php8-sqlite php8-tokenizer php8-xmlreader php8-xmlwriter - version update to 8.5.9 Core: Fixed bug GH-22290 (AST pretty printing does not correctly handle strings containing NUL). Fixed bug GH-22206 (missing return in global register detection). Lock unmodified readonly properties for modification after clone-with. BCMath: Fixed GHSA-x692-q9x7-8c3f (Out-of-bounds write in bccomp()). (CVE-2026-17544) Calendar: Fixed bug GH-22602 (gregoriantojd() and juliantojd() integer overflow with INT_MAX year). Date: Update timelib to 2022.17. Fixed bug GH-19803 (Parsing a string with a single white space does create an error). Fixed Unix timestamps in February of the year 0 are misparsed with @-notation. Fixed bug GH-11310 (__debugInfo does nothing on userland classes extending Date classes). DBA: Fixed OOB read on malformed length field in dba flatfile handler. DOM: Fixed bug GH-22570 (Stack overflow when serializing a deeply nested Dom\XMLDocument). Fixed getElementsByClassName() item() returning the wrong element on random access. Exif: Fixed bug GH-11020 (exif_read_data() emits a spurious "Illegal IFD size" warning when an IFD is not followed by a next-IFD offset). GD: Upgrade libgd. (CVE-2026-9672) Hash: Fixed bug GH-18173 (ext/hash relies on implementation-defined malloc alignment). ODBC: Fixed bug GH-22668 (Heap buffer over-read when a column value exceeds the driver-reported display size). Opcache: Fixed bug GH-22158 (Tracing JIT dispatches the observer begin handler through the wrong run_time_cache slot on megamorphic calls). Fixed bug GH-22443 (Tracing JIT SIGSEGV on megamorphic dynamic calls from an undereferenced run_time_cache map_ptr offset). Fixed bug GH-21770 (Infinite recursion in property hook getter in opcache preloaded trait). OpenSSL: Fixed timeout for supplemental read at end of a blocking stream in SSL stream wrapper. Intl: Fixed Locale::lookup() and locale_lookup() to return NULL instead of the fallback locale when a language tag cannot be canonicalized. Fixed memory leaks when calling Collator::__construct() or Spoofchecker::__construct() twice. Fixed memory leak when calling IntlListFormatter::__construct() twice. Fixed IntlChar methods leaving stale global error state after successful calls. PDO_ODBC: Fixed bug GH-20726 (Crash with ODBC connection pooling when the DSN carries no credentials). Fixed bug GH-22667 (Heap buffer over-read when a column value exceeds the driver-reported display size). Fixed bug GH-22666 (Heap buffer overflow when an output parameter value is longer than the declared maxlen). Fixed bug GH-22665 (Out-of-bounds write when the ODBC driver reports a diagnostic message length beyond the error buffer). PGSQL: Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout). (CVE-2026-17543) Phar: Fixed inconsistent handling of the magic ".phar" directory. Paths such as "/.phar" remain protected, while non-magic paths that merely start with ".phar" are handled consistently across file and directory creation, copying, ArrayAccess, stream lookup, directory iteration and extraction. Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260) PHPDBG: Fixed bug GH-17387 (Trivial crash in phpdbg lexer). Fixed fleaked lowercased lookup keys in phpdbg_resolve_opline_break. Fixed off-by-one in phpdbg_safe_class_lookup() causing class lookups to always fail during phpdbg's signal-safe interruption path. Reflection: Fixed bug GH-22324 (Ignore leading namespace separator in ReflectionParameter::__construct()). Fixed bug GH-22441 (ReflectionClass::hasProperty() and getProperty() ignore dynamic properties shadowing a private parent property). Fixed bug GH-22658 (ReflectionConstant::__toString() with a string value with null bytes truncates output). Fixed bug GH-22683 (Reflection(Class)Constant::__toString() should not warn on NAN conversions). Fixed bug GH-22681 (Reflection*::__toString() truncates on null bytes). Session: Fixed bug GH-21314 (Different session garbage collector behavior between PHP 8.3 and PHP 8.5). SPL: Fix class_parents for classes with leading slash in non-autoload mode. Ignore leading back-slash in class_parents(), class_implements(), and class_uses(). Fixed bug GH-16217 (SplFileObject::fputcsv() on an uninitialized object segfaults). Standard: Fixed bug GH-22395 (base_convert() outputs at most 64 characters). Fixed bug GH-22678 (Use-after-free in array_multisort() when the comparator mutates the array being sorted). URI: Fixed behavior of Uri\WhatWg\Url wither methods with regards to empty opaque hosts. Fixed bug GH-22628 (Percent-encoding of caret in WHATWG URL paths is not performed). Fixed bug GH-22629 (WHATWG Validation error incorrect with empty host and non-empty userinfo). Zip: Fixed bug GH-22649 (ZipArchive::setCommentName() and setCommentIndex() could crash after overwriting an entry and resetting its inherited unchanged comment). Fixed bug GH-21705 (ZipArchive::getFromIndex() ignores ZipArchive::FL_UNCHANGED for deleted entries). - modified patches * php-build-reproducible-phar.patch (refreshed) * php-systzdata-v24.patch (refreshed) - fixes CVE-2026-17543 [bsc#1273075] CVE-2026-17544 [bsc#1273076] CVE-2026-7260 [bsc#1273077] CVE-2026-9672 [bsc#1273078] ==== python-certifi ==== Version update (2026.5.20 -> 2026.7.22) - Update to 2026.7.22: - fix: update Requests docs link to canonical URL - Include tests in the source distribution ==== python-zstandard ==== - Really build against system libzstd again: %pyproject_wheel does not honor %py_setup_args, so since the switch to the pyproject macros the bundled zstd copy was silently linked in statically. Pass --system-zstd via pip --config-settings instead. - Add a check that the built module actually uses system libzstd, so this cannot regress silently again. - BuildRequire packaging (imported by setup.py, previously pulled in only indirectly) and drop no longer needed wheel. ==== qemu ==== Version update (11.0.2 -> 11.0.3) Subpackages: qemu-arm qemu-audio-spice qemu-block-curl qemu-block-nfs qemu-block-rbd qemu-chardev-spice qemu-guest-agent qemu-hw-display-qxl qemu-hw-display-virtio-gpu qemu-hw-display-virtio-gpu-pci qemu-hw-display-virtio-vga qemu-hw-usb-host qemu-hw-usb-redirect qemu-hw-usb-smartcard qemu-img qemu-ksm qemu-pr-helper qemu-tools qemu-ui-curses qemu-ui-gtk qemu-ui-opengl qemu-ui-spice-app qemu-ui-spice-core qemu-vgabios - (Properly, this time for real) fix bsc#1268245: * [openSUSE][RPM] spec: properly fix bsc#1268245 (this time for real!) - Update to latest stable release (11.0.3) Full backport list here: https://lore.kernel.org/qemu-devel/20260725052155.1228635-1-mjt@tls.msk.ru/ A selection of them is reported here below: target/arm: do not clear halting reason in has_work helper target/arm: teach arm_cpu_has_work about halting reasons hw/audio/intel-hda: restrict all DMA engine paths to memories hw/net/cadence: Return current Cadence GEM queue pointers hw/misc/applesmc: Fix a typo setting MSSD key replay: fix use of uninitialized pointer on error hw/display/qxl: validate monitors_config heads[] in phys2virt net: Correct padding check in qemu_receive_packet() hw/net/xilinx_axienet: Fix PHY register 17 link status reporting hw/usb/hcd-xhci-sysbus: Fix OOB heap access in xhci_sysbus_intr_raise() hw/usb/hcd-xhci: Fix guest-triggerable assert() in xhci_find_stream() usbredir: fix infinite loop and SIGFPE with zero max_packet_size usbredir: fix use-after-free on buffered bulk packet overflow tests/qtest: add xhci-pci unplug finalize regression test hw/usb/hcd-xhci-pci: break host link cycle so device_finalize() runs on unplug hw/usb/xhci: clamp interval exponent to avoid UB shift in xhci_init_epctx() accel/tcg: move jit thread manipulation into do_tb_phys_invalidate hw/display/virtio-gpu: Check pixman_image_create_bits() results hw/display/virtio-gpu: handle migration iov allocation failure hw/display/virtio-gpu: cap submit_3d command buffer allocation ui/vnc: validate SetPixelFormat field ranges ui/vnc: fix out-of-bounds write in lossy refresh dirty marking ui/gtk: Narrow DMA-BUF critical section ui/input-barrier: fix off-by-one in keycode bounds check ui/vnc: validate color shifts in SetPixelFormat ui/vnc: fix OOB write in vnc_refresh_lossy_rect net: only advertise passt in netdev help when CONFIG_PASST hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask() hw/usb/hcd-ohci: Make sure that ohci_service_ed_list() cannot loop forever hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure hw/scsi/vmw_pvscsi: add a comment to explain the endianness hw/scsi/vmw_pvscsi: translate data endianness hw/sparc64/niagara: use int64_t for vdisk size to avoid truncation hw/display/qxl: fix TOCTOU in cursor chunk data_size handling hw/misc/ivshmem: clear chardev handlers before freeing peers linux-user/alpha: populate AT_HWCAP from env->amask linux-user/alpha: add coredump support s390x/css: firm up handling of chained TIC CCWs s390x/sclpcpi: check event length field before reading from buffer s390x/sclp: prevent re-reading the sclp header hw/misc/stm32_rcc: Correct offset-to-irq calculation hw/display/sm501: Don't allow guest to set ram size larger than it is hw/display/sm501: Avoid overflow problems in bounds check calculations hw/display/sm501: Catch bad coordinates for RTL operations ... - Fix bsc#1273022: * hw/i386/pc: xen: reinstate the "xenfv" machine alias (bsc#1273022) ==== qgpgme ==== Version update (2.1.0 -> 2.2.0) - Update to 2.2.0: * Add job for querying Active Directory * Don't start dirmngr for WKD lookup if it is disabled for gpg ==== rsyslog ==== Version update (8.2502.0 -> 8.2606.0) - fix specfile for dtls module - dropped separate tarball for rsyslog-doc, now included in main sources (https://www.rsyslog.com/downloads/download-v8-stable/) - upgrade to rsyslog 8.2606 (bsc#1272414 CVE-2026-61548) * 2026-06-23: imtcp: add stream compression support * 2026-06-23: docs: add queue-full troubleshooting * 2026-06-22: mmpstrucdata: document structured-data buffer invariant * 2026-06-21: doc: refine object terminator wording * 2026-06-21: doc: clarify security release handling * 2026-06-21: doc: clarify RainerScript semicolon use * 2026-06-20: rainerscript: escape embedded NULs at C-string boundary * 2026-06-20: doc: explain service sandboxing for helpers * 2026-06-20: doc: address service sandboxing review * 2026-06-20: Apply suggested fix to tools/pmrfc3164.c from Copilot Autofix * 2026-06-19: rainerscript: fold constant comparisons * 2026-06-18: doc: clarify partial config validation * 2026-06-18: config: warn on constant boolean operands * 2026-06-17: parser: honor parseHostnameAndTag in RFC3164 parser * 2026-06-17: core: fix negated exact priority filters * 2026-06-16: rainerscript: keep random result non-negative * 2026-06-16: rainerscript: add cbool function * 2026-06-16: pmrfc3164: honor parseHostnameAndTag at runtime * 2026-06-16: msg: invalidate programname when tag changes * 2026-06-16: imfile: deliver same-file monitors independently * 2026-06-16: glbl: keep debug logfile notice informational * 2026-06-16: doc: modernize GELF forwarding tutorial * 2026-06-15: ommail: add SMTP mode test * 2026-06-15: mmjsonparse: modernize test output paths * 2026-06-14: parser: add optional trailing CR stripping * 2026-06-14: ompgsql: accept long server hostnames * 2026-06-14: dynstats: warn on duplicate bucket names * 2026-06-14: action: warn on duplicate action names * 2026-06-13: omfwd: use matching atomic mutex helper * 2026-06-08: Merge pull request #7014 from rsyslog/cursor/critical-correctness-bugs-480c * 2026-06-05: omazureeventhubs docs: fix underscored parameters * 2026-06-04: runtime: fix YAML promotion OOM ownership * 2026-06-04: omuxsock docs: correct template parameter * 2026-06-04: omhttp: own Splunk profile template names * 2026-06-04: mmjsonparse: reject boundary trailing data * 2026-06-04: mmdblookup: preserve uint64 values * 2026-06-04: mmdblookup: check uint64 fallback formatting * 2026-06-04: impstats docs: fix dotted log parameters * 2026-06-04: impstats docs: clarify parameter name guidance * 2026-06-04: imkafka: stop workers on startup failure * 2026-06-04: imkafka: refine startup stop flag handling * 2026-06-04: doc: match Sphinx duplicate CLI override handling * 2026-06-04: doc: keep stable git docs out of dev mode * 2026-06-04: doc: format stable rst_prolog metadata * 2026-06-04: doc: fix database tutorial SQL template option * 2026-06-03: regexp: avoid per-thread shutdown double-free * 2026-06-03: omkafka: fix NULL topic and add action name to onDestroy flush logs * 2026-06-03: mmsnareparse: honor searchWindow in tabbed trailing scan * 2026-06-03: mmsnareparse: cap tab trailing search by token * 2026-06-03: imfifo: guard absent module config paths * 2026-06-03: imfifo: bind instances to module config * 2026-06-03: imdiag: fix stats reporting gate * 2026-06-03: imdiag: avoid checked cond signal while locked * 2026-06-03: docker: gate collector imtcp module * 2026-06-03: docker: derive single imtcp enable switch * 2026-06-03: docker: default derived imtcp switch in collector * 2026-06-02: yamlconf: clean up include recursion guard * 2026-06-02: tls: propagate wolfSSL send-side read retry * 2026-06-02: tls: keep wolfSSL send retry local * 2026-06-02: tls: bound wolfSSL send-side read retries * 2026-06-02: sidecar: cap UDP burst buffer by total bytes * 2026-06-02: runtime: include limits.h for INT_MAX in yamlconf * 2026-06-02: runtime: guard against recursive YAML includes * 2026-06-02: runtime/queue: reset sizeOnDisk after safe recovery * 2026-06-02: rainerscript: accept optimizer NOP statements * 2026-06-02: omkafka: fix HUP deadlock when doAction holds mut_doAction (#7129) * 2026-06-02: omhttp: avoid retry-ruleset self-stall * 2026-06-02: omhiredis: fix TLS context error log * 2026-06-02: mmpstrucdata: support custom SD containers * 2026-06-02: mmjsonparse: fix find-json ownership and scan bounds * 2026-06-02: mmjsonparse: clear JSON pointer after ownership transfer * 2026-06-02: devtools: fold local review experiment into planner * 2026-06-01: translate: cover script serialization (#7152) * 2026-06-01: dev_env: include lcov in Ubuntu coverage images * 2026-06-01: ChangeLog: update 8.2606 entries * 2026-06-01: Add parse_time_localtz with documentation * 2026-05-31: runtime: join final worker after shutdown wait * 2026-05-31: runtime: harden raw message replacement growth * 2026-05-31: runtime: fix $!all-json serialization locking * 2026-05-31: ratelimit: centralize per-source enforcement * 2026-05-31: parser: fix NetAddr cleanup on mask parse errors * 2026-05-31: omclickhouse: report HTTP response errors * 2026-05-31: omclickhouse: document SQL template option * 2026-05-31: omclickhouse: clean up JSON root on OOM * 2026-05-31: action: avoid committing suspended retry batches * 2026-05-31: Keep transactional action queue messages on shutdown * 2026-05-30: rainerscript: add tocef() and cef_ext_escape() for CEF output * 2026-05-30: doc: clarify queue crash durability limits * 2026-05-30: devtools: add read-only C format check * 2026-05-29: tls: propagate send-side receive retry * 2026-05-29: tls: preserve send-side receive retry state * 2026-05-29: tls: preserve send retry without reconnect * 2026-05-29: tls: keep wolfSSL send-side retry local * 2026-05-29: tls: keep send-side read retries local * 2026-05-29: template: apply style-check formatting ... changelog too long, skipping 1049 lines ... * add 0001-imptcp-guard-regex-framing-match-at-line-start.patch ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Fix unit tests that fail due to async Tornado usage - Added: * stabilize-testsuite-773.patch ==== samba ==== Version update (4.24.3+git.475.629de6765b9 -> 4.24.5+git.481.dba78dbdea) Subpackages: libldb2 python3-ldb samba-ad-dc-libs samba-client samba-client-libs samba-dcerpc samba-gpupdate samba-ldb-ldap samba-libs samba-libs-python3 samba-python3 samba-winbind samba-winbind-libs - Update to 4.24.5 * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server; (bso#16083);(bsc#1271672). * CVE-2026-58224: CTDB: heap OOB read via unchecked packet length fields;(bso#16085);(bsc#1271673). * CVE-2026-58216: kpasswd service: 6-byte heap OOB read in packet parser;(bso#16087);(bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes;(bso#16115);(bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover;(bso#16147);(bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes; (bso#16148);(bsc#1271677). - Update to 4.24.4 * Use-after-free in handling acls with claims and conditions; (bso#16095). * Compilers may ignore overflow checks - Fix tautological- compare warnings; (bso#16092). * restrict anonymous = 2 breaks RODC functionality; (bso#14638). * warning: assignment discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers]; (bso#16006). * Require NTLMv2 session security on Windows makes trusts to Samba unusable; (bso#16067). * winbindd stuck in init_dc_connection_rpc() returning NT_STATUS_TRUSTED_DOMAIN_FAILURE; (bso#16151). * domain\user not split when provided as username in smbc_set_credentials_with_fallback(); (bso#16149). ==== selinux-policy ==== Version update (20260715 -> 20260727) Subpackages: selinux-policy-targeted - Update to version 20260727: * pwaccessd_t uses nsswitch and newidmapd connects to pwaccessd_t socket (bsc#1271860) * adjust amavis spool path regex for openSUSE (bsc#1268627) * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366) * Support vfs_snapper to work with samba_share_t (bsc#1265400) * vfs_samba uses dbus to communicate with snapper (bsc#1265400) ==== shared-mime-info ==== Version update (2.4 -> 2.5.1) - Update to version 2.5.1: + Updated translations. - Changes from version 2.5: + Add type for Git repository bundles + Add application/vnd.ms-pki.seccat + Add binary magic to PKCS#7 types + Add common file extensions to PKCS and PKIX types + Add PEM identifiers from RFC 7468 + Make application/x-x509-ca-cert a subclass of application/pkix-cert + DOS batch/cmd files: add magic, tests, and *.cmd extension + Add application/x-hwpx + Add Android App Bundles + Fix APNG detection using non-fixed acTL chunk location; add APNG test cases + Add Farbfeld image support and fix its mime + Add type for LRC lyrics + Add text/vnd.plantuml + Add text/n3 + Add text/x-gradle-kts (and remove subclass for Gradle) + Add text/x-sed ("Sed script") + Add application/x-coff + Add application/vnd.ipld.car + Add application/x-brotli and fix brotli magic bytes + Add Playstation graphics (TIM) support + Add text/scriptlet + image/x-flic: fix and improve magic, add alias and generic icon + Add image/x-aseprite (LibreSprite/Aseprite image) and improve magic + Give CSV and TSV files the spreadsheet icon + application/texinfo: use IANA registered type + application/vnd.adobe.flash.movie: add ZWS magic + /matroska: use IANA registered non-x types + application/vnd.bzip3: use IANA registered type + Add PICO-8 (.p8/.p8.rom), TIC-80, Lowres NX, and CHIP-8 source/carts + Add RWL (Leica RW2) and more RAW image mime types; fix MOS mime + Add RVZ & WIA disc image files for GameCube & Wii + AWK family: recognise GNU and New AWK; awk scripts now text/x-awk + Shell scripts now text/*, like file/libmagic + Add MP4 Base Media v[2-5] alongside v1 + Add Slint language (text/slint) with magic and test + Assign video icon to application/vnd.ms-asf + Add ZX Spectrum & clone emulation formats + Add Commodore emulation file support + Add Nero Burning ROM NRG format + Add application/x-lx-executable + Add matches and test cases for .nds/.gba + application/vnd.nintendo.nitro.rom: use IANA registered type + Split audio/x-mod into correct formats; add audio/x-dsp and audio/x-ult test + Add text/x-nsis + Add support for Alpine Linux packages (.apk) + text/x-vala: add executable subclass and shebang magic support + application/x-ruby: add text/x-ruby alias + Add AMF 3D model mime-type + Add mimetypes for Simple File Format Family (SF3) files + Add mimetype for Microsoft Developer Studio files + Add HTTP Archive (HAR) json type + Add application/vnd.cyclonedx+xml and application/vnd.cyclonedx+json + Add text/spdx and application/spdx+json + Add OpenCL C and C++ for OpenCL types + image/vnd.radiance: add image/x-hdr alias; add Radiance HDR image format + Add application/x-pcapng and *.scap glob + Add mimetype for AVCI image + Detect OpenSSH public key and private key files + Add Proxy Auto-Configuration (PAC) + Add application/buildstream+yaml + Add text/x-dockerfile + Update mimetype for Typst source files + Add Portable HalfMap images + Update nushell mime type alias to text/x-nushell + Clean up matches for OLE/CFB based Word files + Add Apple Wallet passes bundle type application/vnd.apple.pkpasses + Add application/typescript; recognize *.cjs as text/javascript + Add comment and keyword magic to C-like source code + Move magic from text/x-csrc and text/x-objcsrc to text/x-objc++src + Add *.LRF glob to MPEG-4 videos + Add PFM, PXR and SCT image formats + Recognize *.sfs, *.sqfs, and *.squashfs as application/vnd.squashfs + Remove the relationship between AppImage and SquashFS + Remove redundant "MZ" magic from application/x-executable + Remove the office document icon from application/x-object + Recognize *.lib as application/x-archive + Rename back legacy OOoXML file formats + text/calendar: add *.ifb and *.icalendar globs and the calendar icon + Add text/x-nix + Add text/x-asm + Add image/x-kiss-cel + Prefer image/vnd.fpx over image/x-fpx and improve its detection + Remove text/htmlh + Add text/x-python2 and separate text/x-cython from ... changelog too long, skipping 48 lines ... - Switch to source service for tarball, and add new sub-module. ==== sssd ==== Subpackages: libnfsidmap-sss libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap - Enable sssd-idp. This provides external Identity Provider (OAuth2/OpenID Connect) support. Also enables the krb5 idp plugin. ==== systemd ==== Version update (260.3 -> 261.2) Subpackages: libsystemd0 libudev1 systemd-boot systemd-container udev - Import commit 4925d9f07fc697efccd98a93046ff535b8832445 (merge of v261.2) For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/eff9446d505d62c075bed37d606860b38cfe51fb...4925d9f07fc697efccd98a93046ff535b8832445 - Move systemd-vmspawn from the experimental sub-package to systemd-container - Upgrade to v261 (commit eff9446d505d62c075bed37d606860b38cfe51fb) See https://github.com/openSUSE/systemd/blob/SUSE/v261/NEWS for details. ==== tar ==== Subpackages: tar-rmt - Add tar-assume-dir-size-0.patch * Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes (bsc#1271272) ==== tesseract-ocr ==== Version update (5.5.2 -> 5.5.3) Subpackages: libtesseract5 tesseract-ocr-common - Update to version 5.5.3: * Fix missing closing tags in multi-page PAGE XML output * Correct a mutex call to prevent multiple instances * Document memory ownership and lifecycle in the C API * Fix CMAKE_SYSTEM_PROCESSOR detection when cross-compiling on Apple platforms - Switch the documentation BuildRequires from asciidoc to rubygem(asciidoctor): upstream now generates the man pages with asciidoctor and silently skips them otherwise - Drop the gcc13 fallback for Leap 15.x: 15.6 is out of support and its repository has been retired from the devel project ==== tigervnc ==== Subpackages: libXvnc1 tigervnc-selinux xorg-x11-Xvnc xorg-x11-Xvnc-module - Add nettle4 compatibility [b434432] (bsc#1257934) * Add tigervnc-nettle4-compat-b434432b.patch ==== tumbler ==== Version update (4.20.1 -> 4.20.2) Subpackages: libtumbler-1-0 tumbler-folder-thumbnailer tumbler-lang tumbler-webp-thumbnailer - Update to version 4.20.2: * Update copyright year * Support new matroska mime types * Remove G_GNUC_CONST * Add missing chain up to parent class * Handle cases where there are no plugins gracefully * desktop-thumbnailer: Don't use GIOStream to get thumbnail pixbuf - Remove obsolete "bcond_with git" stuff ==== unbound ==== Version update (1.25.1 -> 1.25.2) Subpackages: libunbound8 unbound-anchor - Update to 1.25.2: * CVE-2026-14586: Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments [bsc#1271879] * CVE-2026-32665: Remote DNS-over-QUIC denial of service due to quic-size budget bypass [bsc#1271873] * CVE-2026-40691: Packet of death for DNSCrypt over TCP [bsc#1271875] * CVE-2026-41637: Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries [bsc#1271891] * CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records [bsc#1271892] * CVE-2026-44621: Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated [bsc#1271876] * CVE-2026-44687: Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN [bsc#1271893] * CVE-2026-44690: Cross-zone wildcard cache poisoning via RRSIG.labels manipulation [bsc#1271877] * CVE-2026-46582: A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path [bsc#1271894] * CVE-2026-50045: 'max-global-quota' reset by DNSSEC validation restarts [bsc#1271878] * CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out [bsc#1271882] * CVE-2026-50243: 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL [bsc#1271880] * CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones [bsc#1271881] * CVE-2026-50251: Attacker supplied 0.0.0.0/:: glue triggers defensive full-cache flush [bsc#1271883] * CVE-2026-50252: Possible cache poisoning attack by mapping source port population per thread [bsc#1271884] * CVE-2026-52863: Memory corruption could lead to crash and denial of service [bsc#1271885] * CVE-2026-54478: DNS Cookie bypass when combined with proxy-protocol use [bsc#1271895] * CVE-2026-55708: Privacy/configuration issue when adding local data in views through 'unbound-control' [bsc#1271896] * CVE-2026-55717: 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash [bsc#1271886] * CVE-2026-55973: 'dns-error-reporting: yes' leads to stack buffer overflow [bsc#1271874] * CVE-2026-55990: Packet of death for a DNSCrypt misconfigured Unbound [bsc#1271887] * CVE-2026-55991: Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 [bsc#1271888] * CVE-2026-56416: Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name [bsc#1271889] * CVE-2026-56444: Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration [bsc#1271890] ==== update-bootloader ==== Version update (1.27 -> 1.28) - merge gh#openSUSE/update-bootloader#197 - fix test suite - adjust two tests - updated test results - fix command line parser (bsc#1271602) - add test case - update test result - fix and reenable ksh tests: ksh uses alts now - update ksh test results - 1.28 ==== util-linux ==== Version update (2.42.1 -> 2.42.2) Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ==== util-linux-systemd ==== Version update (2.42.1 -> 2.42.2) Subpackages: lastlog2 liblastlog2-2 - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ==== vim ==== Subpackages: vim-data vim-data-common xxd - Guard suse.vimrc against missing syntax without vim-data ==== wicked ==== Version update (0.6.79 -> 0.6.80) Subpackages: wicked-service - Update to version 0.6.80 - Immutable Mode: conditionally install configs, scripts and extensions in /usr, document the /usr vs /etc config split in the manual pages, and render via new util/templatepp.gawk preprocessor (gh#openSUSE/wicked#1075,gh#openSUSE/wicked#1076) - xpath: fix gcc-15.x assignment discards 'const' warning (gh#openSUSE/wicked#1074) - nanny: use opaque id for managed-netif dbus path (gh#openSUSE/wicked#1070) - netlink: remove libnl-route dependency (gh#openSUSE/wicked#1068) - spec: guard the sle_version macro (gh#openSUSE/wicked#1067) - service: drop rcwicked* links on 16.x (jsc#PED-266,gh#openSUSE/wicked#1066) - client: add iaid show,get --iaid-format option (gh#openSUSE/wicked#1064) - ovs: suppress harmless ovs-vsctl discover call errors (gh#openSUSE/wicked#1063) - teamd: fix TEAM_LACP_ACTIVE default to true (gh#openSUSE/wicked#1062) - policy: cleanup managed objectmodel, fsm-policy match and transform processing (gh#openSUSE/wicked#1055,gh#openSUSE/wicked#1056,gh#openSUSE/wicked#1057, gh#openSUSE/wicked#1059,gh#openSUSE/wicked#1060) ==== wpa_supplicant ==== - Add mesh-Reject-AMPE-MIC-element-with-length-AES_BLOCK_S.patch https://w1.fi/security/2026-4/ ==== wtmpdb ==== Version update (0.75.0+git20251130.0d8fe7a -> 0.76.0+git20260730.89c0861) Subpackages: libwtmpdb0 - Update to version 0.76.0+git20260730.89c0861: * Release version 0.76.0 * CI: get rid of obsolete actions * Use _cleanup_, adjust formating * rotate: keep open entries after last boot * wtmpdb: use different variable for (const) char * * Update mkdir_p to fix error code for last call * ignore absence of systemd * ignore absense of dbus ==== xfce4-panel ==== Version update (4.20.7 -> 4.20.8) Subpackages: libxfce4panel-2_0-4 xfce4-panel-lang xfce4-panel-restore-defaults - Update to version 4.20.8 * wayland: Set layer-shell namespace * wayland: Restart panel when gtk-layer-shell is in unrecoverable state * Use XfwMonitor to match monitor by name * Refactor XfwScreen management a bit * clock: Deduce update interval from date and time formats * Fix autotools build * Set translation domain for plugins * Remove G_GNUC_CONST (complement) * Remove G_GNUC_CONST * libxfce4panel: Do not emit signals if construct() has not been called * I18n: Update po/LINGUAS list * Fix -Wdiscarded-qualifiers compiler warning for autotools builds * build: Replace wrong define guard with libxfce4ui version check * panel: Use same code to cleanup plugin config everywhere * icons: Fix non-zero page opacity * panel: Set itembar clip when allocating window * I18n: Update po/LINGUAS list * actions: Fix variable used out of scope * pager: Fix workspace switch for Compiz when scrolling over pager * build: Do not display full path in generated headers * Translation Updates ==== xfce4-power-manager ==== Version update (4.20.0 -> 4.20.1) Subpackages: xfce4-power-manager-lang xfce4-power-manager-plugin - Update to version 4.20.1: * Update copyright year * Remove undesired 'n' in logs * settings: Update sleep mode allowed values * settings: Remove sleep mode combobox tooltips * settings: Add shutdown as sleep mode when inactive * backlight-helper: Fix brightness control device selection logic * Translation Updates - Remove obsolete 0001-relax-x11-version.patch ==== xfce4-settings ==== Version update (4.20.4 -> 4.20.5) Subpackages: xfce4-settings-color xfce4-settings-lang - Update to version 4.20.5: * Fix -Wdiscarded-qualifiers compiler warning * Remove G_GNUC_CONST * wayland: Set mode dimensions to 1x1 if width or height <= 0 * Revert "dialogs/display-settings: Fix possible arithmetic exception" * dialogs/display-settings: Fix possible arithmetic exception * Add missing chain up to parent class * display-settings: Release main object early to avoid use-after-free * display-settings: Handle source memory management * I18n: Update po/LINGUAS list * wayland: display-settings: Fall back to output name when EDID is duplicated * xfsettingsd: Add some debug traces to gtk-settings helper * gtk-settings-module: handle g_value_transform() failures * Special-case gtk-xft-hintstyle * Include an allowlist of xfconf props to sync to GtkSettings * Fix incorrect TitleCase to kebab-case in gtk-settings-module.c * Translation Updates ==== yast2-auth-server ==== Version update (5.0.0 -> 5.0.1) - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.1 ==== zimg ==== Version update (3.0.6+20250919.gdf9c147 -> 3.0.6+20260720.g1ad1895) - Update to version 3.0.6+20260720.g1ad1895: * colorspace: add chromatic adaptation support, disabled by default (new zfilter_graph_builder_params field, required by VapourSynth R78) * colorspace: add BT.1361 transfer characteristics, simplify the xvYCC EOTF, add FMA and F16C feature checks, fix the hash function and an assertion on 240M->709 gamma * depth: add NEON-optimized error diffusion dithering * resize: fix integer weight rounding compensation and impose a maximum tap count on Lanczos * Fix out-of-bounds accesses in several SIMD code paths: the AVX2 u16 permute resizer load, AVX2 and NEON ordered dither reads, NEON error diffusion read, NEON float-to-half write, NEON byte-to-word left-shift read and the AVX2 unresize buffer size calculation * unresize: special-case the LU decomposition of a 1x1 matrix and use double epsilon * common: fix matrix row offset tracking after compaction * graph: fix the 64-byte alignment check, rename factory to observer * Update the bundled graphengine * Test-only, MSVC/Windows and example-code changes omitted here ==== zoo ==== - Add zoo-64bit-header-check.patch, taken from Debian, to fix the archive header consistency check on 64-bit platforms: * zoo_start and zoo_minus are a 32-bit value and its two's complement, so they stopped cancelling out once long became 64 bits wide and the check misfired on valid archives * extracting or packing an archive printed a spurious "Archive header failed consistency check" warning * deleting a member from an archive treated the same check as fatal and aborted, making zoo D unusable on 64-bit ==== zstd ==== Subpackages: libzstd1 - Cleanup .spec file