Packages changed: GraphicsMagick ImageMagick (7.1.2.29 -> 7.1.2.30) Mesa (26.2.1 -> 26.2.2) Mesa-drivers (26.2.1 -> 26.2.2) NetworkManager SDL3 (3.4.14 -> 3.4.16) apache2-mod_php8 (8.5.9 -> 8.5.10) appstream-glib (0.8.3 -> 0.8.4) boost-base boost-extra bubblewrap (0.11.2 -> 0.12.0) cairomm (1.18.0 -> 1.18.1) chrony clamav cpio cups-filters curl (8.21.0 -> 8.22.0) dmidecode dracut (112+suse.34.g35e16b7 -> 112+suse.47.gec0b378) emacs evolution-data-server exiv2 (0.28.8 -> 0.28.9) ffmpeg-8 gcc16 gdm (50.2 -> 50.3) gegl (0.4.70 -> 0.4.72) gimp glibc (2.43 -> 2.44) gnome-sudoku (50.3 -> 50.4) google-noto-fonts (20260801 -> 20260901) gpg2 (2.5.21 -> 2.5.22) gpgme (2.1.2 -> 2.2.0) gpgmepp (2.1.0 -> 2.2.0) grub2 gstreamer-plugins-bad gtk3 (3.24.52 -> 3.24.52+git59.b30343717d) gtk4 (4.22.4+29 -> 4.22.4+35) harfbuzz (14.3.1 -> 14.4.0) hwdata (0.410 -> 0.411) ibus ibus_gtk4 imlib2 (1.12.6 -> 1.12.7) iproute2 (7.1 -> 7.2) kernel-firmware-amdgpu (20260717 -> 20260829) kernel-firmware-ath10k (20260610 -> 20260809) kernel-firmware-ath12k (20260610 -> 20260813) kernel-firmware-bluetooth (20260720 -> 20260828) kernel-firmware-i915 (20260706 -> 20260806) kernel-firmware-intel (20260610 -> 20260728) kernel-firmware-iwlwifi (20260610 -> 20260820) kernel-firmware-media (20260706 -> 20260813) kernel-firmware-mediatek (20260629 -> 20260825) kernel-firmware-network (20260610 -> 20260813) kernel-firmware-qcom (20260717 -> 20260828) kernel-firmware-qlogic (20260610 -> 20260731) kernel-firmware-realtek (20260629 -> 20260731) kernel-firmware-sound (20260706 -> 20260825) kernel-firmware-ueagle (20260610 -> 20260703) kernel-source (7.2.2 -> 7.2.3) kquickimageeditor6 (0.6.2.1 -> 0.7.0.1) libbpf libcloudproviders (0.4.0 -> 0.4.1) libcupsfilters libfastjson (1.2304.0+ga630254 -> 1.2609.0) libfido2 libgcrypt (1.12.2 -> 1.12.3) libheif (1.23.1 -> 1.23.4) libjpeg-turbo libksba (1.8.0 -> 1.8.1) liblouis (3.38.0 -> 3.39.0) libnftnl (1.3.1 -> 1.3.2) libphonenumber (9.0.36 -> 9.0.38) libreoffice (26.2.5.2 -> 26.8.0.3) libvirt (12.6.0 -> 12.7.0) libxml2 (2.15.3 -> 2.15.4) libzypp (17.38.14 -> 17.38.15) lightdm-gtk-greeter-branding-openSUSE localsearch (3.11.1 -> 3.11.2) m4 mariadb-connector-c mozilla-nspr (4.39 -> 4.40) mozilla-nss (3.126.1 -> 3.127) mozjs140 (140.14.0 -> 140.15.0) nautilus (50.2.2 -> 50.3.1) nftables (1.1.6 -> 1.1.7) openSUSE-release (20260830 -> 20260908) openssl-3 osinfo-db (20251212 -> 20260812) ovmf patterns-kde (20260428 -> 20260830) pcre2 (10.47 -> 10.48) perl-Cpanel-JSON-XS (4.430.0 -> 4.440.0) perl-MIME-tools (5.517.0 -> 5.518.0) perl-Net-DNS (1.560.0 -> 1.570.0) perl-URI (5.350.0 -> 5.360.0) php8 (8.5.9 -> 8.5.10) publicsuffix (20260819 -> 20260902) python-dnspython python-idna (3.18 -> 3.19) python-numpy (2.5.2 -> 2.5.3) qca-qt6 (2.3.10 -> 2.3.12) qemu (11.0.3 -> 11.1.1) qt6-tools raspberrypi-firmware re2c (4.5.1 -> 4.6) rpcbind rsyslog (8.2606.0 -> 8.2608.0) salt sdbootutil (1+git20260825.c7a5a97 -> 1+git20260903.f91f636) sdl2-compat (2.32.70 -> 2.32.72) sg3_utils (1.48+35.c49e7c08 -> 1.48+36.936c7ae) strace suitesparse (7.13.0 -> 7.14.0) suse-module-tools (16.1.6 -> 16.1.7) tcl tree-sitter wireless-regdb (20260530 -> 20260903) wireplumber (0.5.15 -> 0.5.17) xdp-tools xwaylandvideobridge (0.5.0 -> 0.5.2) yast2-bootloader (5.0.33 -> 5.0.42) zvbi (0.2.44 -> 0.2.45) zypper (1.14.98 -> 1.14.101) === Details === ==== GraphicsMagick ==== Subpackages: libGraphicsMagick++-Q16-12 libGraphicsMagick-Q16-3 libGraphicsMagick3-config - added patches CVE-2025-55154: integer overflow when performing magnified size calculations in ReadOneMNGIMage can lead to out-of-bounds write [bsc#1248078] * GraphicsMagick-CVE-2025-55154.patch ==== ImageMagick ==== Version update (7.1.2.29 -> 7.1.2.30) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - version update to 7.1.2.30 * Fix inline SVG style precedence #8920 * Preserve page offsets in PCX images #8921 * Added initial support for the aseprite format #8783 * https://github.com/ImageMagick/ImageMagick/issues/8893 c0bfa48 * Corrected method call. ac68a7c * Fix YCbCr TIFF images to always convert to RGB via the generic reader. 6a40f26 * Moved the workflow to the Website repository. b17cb9c * check for supported inline image formats e1394ac * fix exception tag 8f88a9a * correct exception tag 4d3d052 * deny inline implicit image formats 71489bb * eliminate compiler exception 3d7013b * get properties that might exceed 4096 characters a5c0521 * initialize buffer to null a8a11a2 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wxw6-98rj-hjfr 19bce64 * https://github.com/ImageMagick/ImageMagick/issues/8901 4d9720f * Return error when WebPDemuxGetFrame fails. 48c6d95 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr 5bff96a * Corrected types. b20cdc8 * Updated configure. d4847a3 * Added new ASE coder. 6de67df * Make sure we also include the static.h header file. 9f277ec * latest autoconf/automake update 91df48a * symetric divide of real and imaginary components by magnitude 2b3ca93 * phase similarity now matches Fred’s phase script b7794a3 * https://github.com/ImageMagick/ImageMagick/security/code-scanning/135 12174d4 * https://github.com/ImageMagick/ImageMagick/issues/8890 8d1fdcb * use log of guassian for the correlation surface 5c4be46 * Removed variable that is only set but never read. f6f439a * Updated the dependencies. 2c19028 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g a44ef50 * rename() does not work across partitions 332aa87 * Explicitly checks for read() and write() errors 15aafab * earlier check for authorized path 083a4b4 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc 1d3e989 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4w-pvxj-fpjc ae2ed8c * Don’t call SetImageExtent when pinging an Aseprite image. b8731aa * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x8g2-7r3w-h44p fb0b4ff * Updated the dependencies. cbe23fb * Correct the media type of the image that is added to the wand. 26b7e6d * Fixed double free in non cairo builds (https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x) 326451a * Removed unused code. 35318d3 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp 6ac0755 * Don’t throw a fatal exception when hitting a recursion depth (GHSA-27m9-54jx-fgvq). 907b748 * Use AcquireCriticalMemory instead. 74ec09f * Report errors or return null instead of exiting the process. a6b9e7f * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x c83153d * https://github.com/ImageMagick/ImageMagick/issues/8918 31a418a * Use omp_set_max_active_levels on MSYS2 build instead. d7924bc * latest autoconf/automake updates 05371c0 * Code cleanup and a bug fix. f9070c0 * Updated configure. 86e0ac6 * latest automake/autoconf update 6b1062f * Create an SBOM for the Windows release artifacts. 8ee86fa * Use UTC timestamp instead. 0e0a477 * Correct filename. 7d45ed0 ==== Mesa ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== Mesa-drivers ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== NetworkManager ==== Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Add NetworkManager-CVE-2026-10805.patch: dhclient: reject unsafe characters in URLs and hostnames (bsc#1267696, CVE-2026-10805, glfd#NetworkManager/NetworkManager!2426). - Add NetworkManager-CVE-2026-19685.patch: core: 802.1x: reject ca-path for private connections (bsc#1276764, CVE-2026-19685, glfd#NetworkManager/NetworkManager!2513). ==== SDL3 ==== Version update (3.4.14 -> 3.4.16) - Update to release 3.4.16 * Fixed loading BMP files with < 8 bits per pixel and odd widths * Fixed the depth format sample count support check in the GPU API * Removed WM_TAKE_FOCUS from WM_PROTOCOLS for X11 windows * Report SDL_PenInputFlags in SDL_PenProximityEvent * Fixed vertical high-resolution mouse wheel scaling on evdev * Fixed joystick stick calibration on Nintendo Joy-Con controllers ==== apache2-mod_php8 ==== Version update (8.5.9 -> 8.5.10) - version update to 8.5.10 Core: Fixed bug GH-22782 (Const expr FCC crashes under preloading). Fixed bug GH-23088 (Stack overflow when comparing deeply nested arrays). Date: Fixed leak on double DatePeriod::__construct() call. DOM: Fixed bug GH-23116 (Stack overflow when normalizing a deeply nested DOMDocument). Fixed bug GH-23117 (Stack overflow when normalizing a deeply nested Dom\XMLDocument). Fixed bug GH-22825 (DOMElement::setAttribute() fails silently when the DTD declares a default value for the attribute). Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes with DOMNode::isEqualNode()). Exif: Fixed exif_read_data() allocating a HEIF meta box larger than the file it came from. Intl: Fixed IntlListFormatter::__construct() leaving stale global error state after successful calls. Opcache: Fixed GH-22693 (DT_TEXTREL in JIT-generated TLS access on x86_64). Fixed bug GH-22763 (JIT fails to clear ZREG_TYPE_ONLY after setting reg). Fixed bug GH-22857 (Function JIT emits wrong code for FETCH_OBJ_FUNC_ARG on a property hook getter, losing register-held variables). Fixed bug GH-22916 (Preserve parent regs in zend_jit_deoptimizer_start()). OpenSSL: Fix missing error check on invalid alpn protocols. MBString: Fixed bug GH-22779 (mb_strrpos() returns the wrong position for a negative offset in a non-UTF-8 encoding). Fixed bug GH-21036 (mb_ereg_search_getregs() crashes after mb_eregi() invalidates the regex cache). PCRE: Fixed bug GH-21134 (Crash with \C + UTF-8). Using \C in UTF-8 patterns is now forbidden. PDO_ODBC: Fixed bug GH-23016 (NULL values in long columns come back as garbage binary strings). PDO_PGSQL: Fixed several lazy fetch (PDO::ATTR_PREFETCH => 0) defects: an infinite loop when cleaning up a fetch left in a COPY, a use-after-free when a statement with emulated or disabled prepares is destroyed, a connection left busy for the next fetch, and rows delivered from a result another statement took over. Reflection: Fixed bug GH-22905 (Reflection exception messages truncate on null bytes). Fixed ReflectionProperty::isLazy() and skipLazyInitialization() using the parent slot when a child class hooks an inherited property. Fixed segfault in ReflectionMethod::createFromMethodName() on an uninstantiable subclass. Session: Fix corruption in mod_mm. Fixed bug GH-23043 (broken session id code can cause zend_mm_heap corrupted). SimpleXML: Fixed integer element offsets that cannot resolve aliasing an existing element. Fixed segfault when comparing uninitialized SimpleXMLElement instances. Sockets: Fixed socket_set_option() validation error messages for UDP_SEGMENT and SO_LINGER options. Fixed various memory related issues in ext/sockets. SQLite: Fix leak when trying to close db if blob stream is still open. Standard: Fixed bug GH-23111 (Stack overflow in array_walk_recursive() with deeply nested arrays). Fixed bug GH-23113 (Stack overflow in array_replace_recursive() with deeply nested arrays). Fixed bug GH-23115 (Stack overflow in compact() with deeply nested arrays). Streams: Fixed bug GH-15836 (Use-after-free when a user stream filter accesses $this->stream during the close flush). XSL: Fixed use-after-free when a DOMDocument subclass __clone() retains the stylesheet copy made by XSLTProcessor::importStylesheet(). - Removed php-fix-build-gcc16.patch (fixed upstream) ==== appstream-glib ==== Version update (0.8.3 -> 0.8.4) Subpackages: libappstream-glib8 - Update to version 0.8.4: + New Features: - Add symbol and sample text for Amharic and Inuktitut - Add symbol text for N'Ko and Yi script + Bugfixes: - Fix building the silo when shared-mime-info >= 2.5.1 is installed - Fix RISC-V test failure ==== boost-base ==== Subpackages: boost-license1_91_0 libboost_filesystem1_91_0 libboost_iostreams1_91_0 libboost_locale1_91_0 libboost_log1_91_0 libboost_thread1_91_0 - Also install the CMake package config for the header-only Boost.System during the base build: since CMake 4 removed the FindBoost module, find_package(Boost COMPONENTS system) falls through to BoostConfig.cmake, which requires a per-component boost_system-config.cmake that the top-level b2 install no longer generates now that the compatibility stub library is gone. Package it in libboost_headers-devel. ==== boost-extra ==== - Also install the CMake package config for the header-only Boost.System during the base build: since CMake 4 removed the FindBoost module, find_package(Boost COMPONENTS system) falls through to BoostConfig.cmake, which requires a per-component boost_system-config.cmake that the top-level b2 install no longer generates now that the compatibility stub library is gone. Package it in libboost_headers-devel. ==== bubblewrap ==== Version update (0.11.2 -> 0.12.0) - update to 0.12.0: * The flag --not-a-security-boundary was added. If this is enabled then failure of some sandbox setup steps (like remounting a submount) are not fatal. * The license has been updated from LGPL 2.0 (or later) to LGPL 2.1 (or later). * This version removes the support for building a setuid bubblewrap. Changes in this version made it difficult to support and basically all modern linux distributions now support unprivileged user namespaces to some extent. * The assume_kernel build option was added, if specified no backwards compatiblity for kernels older than this is built in (and will result in hard failures at runtime). Currently specifying 5.6.0 or later will disable the fallback implementation of openat2(RESOLVE_IN_ROOT). * Bubblewrap now correctly resolves absolute symlinks during the sandbox setup by using openat2 with RESOLVE_IN_ROOT (or a fallback implementation). This fixes a security issue (GHSA-pxhw-h44j-8pfx) where file or directories created during sandbox setup could follow parent symlinks out of the sandbox. ==== cairomm ==== Version update (1.18.0 -> 1.18.1) - Update to version 1.18.1: + Fix memory leak in Context::pop_group() + Updated documentation. + Meson build system fixes ==== chrony ==== Subpackages: chrony-pool-openSUSE - Create /var/lib/chrony via tmpfiles ==== clamav ==== Subpackages: libclamav12 libclammspack0 libfreshclam4 - Put libclamunrar into an optional subpackage, because it has a NonFree license. - Improve macro usage for the library subpackages. - Add clamav-libcheck-workarounds.patch to work around missing macros in libcheck-0.10.0 on SLE-12-SP5. ==== cpio ==== Subpackages: cpio-mt - Adjust doc mtime for reproducible cpio.info (boo#1047218) - Change cpio-use_new_ascii_format.patch to get the doc change into the package ==== cups-filters ==== Subpackages: cups-filters-cups-browsed - cups-filters-1.28.17-CVE-2026-64611.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/4b343522823403df01f6753082df83f07d18c217 backported to cups-filters 1.28.17 to fix CVE-2026-64611 "Infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4 "user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop" (bsc#1273145) - cups-filters-1.28.17-CVE-2026-64612.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 backported to cups-filters 1.28.17 to fix CVE-2026-64612 "Malformed PNG aborts CUPS image filter process (missing libpng setjmp recovery)" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch "authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG" (bsc#1273146) ==== curl ==== Version update (8.21.0 -> 8.22.0) Subpackages: libcurl4 - Update to 8.22.0: * Security fixes: - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476) - CVE-2026-18924: HTTP/2 server push UAF (bsc#1277477) - CVE-2026-19931: Negotiate ambient user conn reuse (bsc#1277478) - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479) - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480) - CVE-2026-80255: secure cookie attribute bypass with tab (bsc#1277482) - CVE-2026-82209: curl: domain-scoped PSL domain cookie (bsc#1278173) * Changes: - gssapi: add support for Apple GSS Framework - hardening: add API guards - RFC 9421 HTTP Message Signatures support - spnego: block NTLM fallback in SPNEGO negotiation - TLS: drop support for TLS-SRP - vquic: add option to use Apple fast UDP * Bugfixes: - altsvc: continue after unknown parameters - asyn-thrdd: retry link-local ipv6 if missing scope id - autotools: minor fixes and improvements - cd2nroff: fix backslashes for 4-space indent lines - cd2nroff: stricter checks for asterisks for italics - cfilters: fix event-based connection shutdown - conncache: apply multi limits to transfers using a shared pool - connect: only set connect timer on first socket - connection reuse: check SSL configs when doing a scheme upgrade - cookie: cookies set for an exact PSL domain is host-only - cookie: improve TAB handling - cookie: refuse to load cookies set against a PSL domain - FTP: fix TLS session reuse on the data connection - hostip: only cache negative resolves for authoritative answers - http digest: tie peer/credentials on input - http2: make server push transfers inherit share from parent - ldap: reject control characters in URL-decoded filter values - ldap: support empty username and password - md5: replace magic numbers with `MD5_DIGEST_LEN` - mime.c: avoid integer overflow in base64 size calculation - mprintf: acknowledge %F - ngtcp2+openssL: fix early data - ngtcp2: avoid NULL deref in cf_ngtcp2_send - openssl+sectrust: fix session reuse - openssl+sectrust: move session verified set into result check - openssl: avoid conn reuse if provider is used - openssl: avoid strlen() on the data from OpenSSL - openssl: prefer modern API flavors for `EVP_MD_CTX` new/free - openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` - url: fix handling of empty user in NTLM matching - url: fix negotiate/ntlm connection reuse - urlapi: allow URLs to not have userauth (hostname) - urlapi: clear password buffer on error path - vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config * Rebase libcurl-ocloexec.patch ==== dmidecode ==== - Display slot information for EDSFF (jsc#NVIDIA-68) * dmidecode-Display-slot-information-for-EDSFF.patch ==== dracut ==== Version update (112+suse.34.g35e16b7 -> 112+suse.47.gec0b378) - Update to version 112+suse.47.gec0b378: * fix(base): check first argument in load_fstype() * fix(url-lib): check error if curl fails in subshell * fix(dracut-systemd): actually make rd.break=pre-trigger stop before pre-trigger * fix(lvm): unset DM_VG_NAME and DM_LV_NAME in each iteration * fix(lvm): drop stray leading and trailing spaces from generated cmdline * fix(lvm): install the LVM system ID file again * fix(lvm): deduplicate rd.lvm.lv= arguments in cmdline() * fix(lvm): check all host devices in cmdline() * fix(iscsi): sanitize netroot= value passed to initqueue scripts - CVE-2026-6893: root code execution via dhcp options command injection (bsc#1268322, follow-up fixes recently merged) * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset - Maintain configuration in OBS ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Include libdir site-lisp for native modules in load-path by default. boo#1277717 - Add workaround for race in process-tests.el on s390x - Add upstream patch 0001-speedbar-window-now-run-speedbar-before-delete-hook-.patch * 'speedbar-window' now run 'speedbar-before-delete-hook' ==== evolution-data-server ==== Subpackages: libcamel-1_2-67 libebackend-1_2-11 libebook-1_2-21 libebook-contacts-1_2-5 libecal-2_0-3 libedata-book-1_2-27 libedata-cal-2_0-2 libedataserver-1_2-27 libedataserverui-1_2-4 - Move %{_libexecdir}/evolution-data-server/evolution-data-server (without installed-tests) back to the main package (boo#1277935). ==== exiv2 ==== Version update (0.28.8 -> 0.28.9) - update to 0.28.9 (bsc#1277579, CVE-2026-68547, bsc#1277579, CVE-2026-68546, bsc#1277791, CVE-2026-49275): * https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j * https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q * https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp * https://github.com/Exiv2/exiv2/security/advisories/GHSA-pwvq-9w4q-786w ==== ffmpeg-8 ==== Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Enable decoders in ffmpeg-8-mini that need no extra build dependencies. This makes it possible for some packages to run testsuites with e.g. WAV files. - Add ffmpeg-8-CVE-2026-75147.patch: Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU size in the keyframe search loop. (CVE-2026-75147, bsc#1276413) - Add ffmpeg-8-CVE-2026-75146.patch: Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative fragment index. (CVE-2026-75146, bsc#1276412) - Add ffmpeg-8-CVE-2026-75145.patch: Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow the OBU size to (long). (CVE-2026-75145, bsc#1276411) - Add ffmpeg-8-CVE-2026-75144.patch: Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data units larger than the RTP payload buffer. (CVE-2026-75144, bsc#1276410) - Add ffmpeg-8-CVE-2026-75143.patch: Backport 1c10bcc2 from upstream, avformat/librist: honor the caller buffer size in librist_read. (CVE-2026-75143, bsc#1276409) - Add ffmpeg-8-CVE-2026-75142.patch: Backport 9d786e4b from upstream, avformat/mpegenc: reject stream counts that overflow the system header. (CVE-2026-75142, bsc#1276408) - Add ffmpeg-8-CVE-2026-75141.patch: Backport acf5d7cd from upstream, avformat/hevc: reject hvcC NAL arrays that overflow the 16-bit count. (CVE-2026-75141, bsc#1276407) - Add ffmpeg-8-CVE-2026-70632.patch: Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 output wider than the plane. (CVE-2026-70632, bsc#1274289) - Add ffmpeg-8-CVE-2026-70631.patch: Backport 3c287af3 from upstream, avcodec/tiff: reject inflate output shorter than the strip. (CVE-2026-70631, bsc#1274287) - Add ffmpeg-8-CVE-2026-70630.patch: Backport c22667d0 from upstream, avcodec/screenpresso: reject deflate output shorter than the frame. (CVE-2026-70630, bsc#1274282) - Add ffmpeg-8-CVE-2026-70629.patch: Backport a5fe21a1 from upstream, avcodec/rscc: do not leave uninitilized data when the input is too short. (CVE-2026-70629, bsc#1274270) - Add ffmpeg-8-CVE-2026-70628.patch: Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid signed overflow in the capacity check. (CVE-2026-70628, bsc#1274268) - Add ffmpeg-8-CVE-2026-66037.patch: Backport f15e730c from upstream, avformat/iamf_parse: check count_label against the available bytes. (CVE-2026-66037, bsc#1272764) - Add ffmpeg-8-CVE-2026-66036.patch: Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support dynamic frame sizes. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-66036-shim01.patch Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject unsupported frame parameter changes. This patch is for facilitate ffmpeg-CVE-2026-66036.patch. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-65706.patch: Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the temp row buffer for the widest plane. (CVE-2026-65706, bsc#1272762) - Add ffmpeg-8-CVE-2026-65705.patch: Backport 30a52276 from upstream, avfilter/vf_floodfill: remove unneeded variables. (CVE-2026-65705, bsc#1272761) - Add ffmpeg-8-CVE-2026-65704.patch: Backport 52f7983f from upstream, avformat/ty: don't let the Series2 AC3 trim underflow the packet size. (CVE-2026-65704, bsc#1272760) - Add ffmpeg-8-CVE-2026-65703.patch: Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference frame before reallocating on size change. (CVE-2026-65703, bsc#1272759) - Add ffmpeg-8-CVE-2026-64834.patch: Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF objects smaller than their header. (CVE-2026-64834, bsc#1272757) - Add ffmpeg-8-CVE-2026-64833.patch: Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS core_size against the packet size in the HD path. (CVE-2026-64833, bsc#1272755) - Add ffmpeg-8-CVE-2026-58049.patch: Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit DLTA accesses stay within the row. (CVE-2026-58049, bsc#1269550) - Rename the ffmpeg BRPM back to ffmpeg-8 to make room for ffmpeg-9 to fill the role. [boo#1271606] - Rename the ffmpeg-8 BRPM to ffmpeg. [boo#1271606] ==== gcc16 ==== Subpackages: cpp16 libasan8 libatomic1 libgcc_s1 libgccjit0 libgfortran5 libgomp1 libhwasan0 libitm1 liblsan0 libobjc4 libstdc++6 libstdc++6-pp libtsan2 libubsan1 - Add gcc16-pr124811.patch to fix build reproducability when PCH is used - Add gcc16-znver6-cpuid.patch to fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390, make sure to configure s390x with - -disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ==== gdm ==== Version update (50.2 -> 50.3) Subpackages: gdm-schema gdm-systemd gdm-xdm-integration libgdm1 typelib-1_0-Gdm-1_0 - Update to version 50.3: + Fixed pam_gdm regression where a previous security fix caused authentication to fail on systemd, which intentionally leaves the kernel keyring buffer unterminated + Fixed potential use-after-free where gdm-session-settings did not keep a reference to the user, which could be freed by the manager while it was still emitting signals + Fixed connection reference leaks and a use-after-free crash in session worker connection teardown that could bring down the whole user session during screen lock/unlock + Updated translations. ==== gegl ==== Version update (0.4.70 -> 0.4.72) Subpackages: gegl-0_4 libgegl-0_4-0 typelib-1_0-Gegl-0_4 - Drop gegl-CVE-2026-18300.patch: This was applied upstream several versions back. Our original patch was a backport, and we still had an extra bit of code from that left over that still applied and nobody noticed since quilt rebases it so nicely for us. - Update to version 0.4.72: + Build: - Build with pure MSVC as well as wasm - Improvements to defcheck, - Minimum meson version bumped to 0.60 - More CI integration, harmonized with gimp/babl + Core: - Use G_{BEGIN|END}_DECLS in all header declarations - gegl_param_color_cmp, new function - Avoid crashes in gegl_path + Buffer: - Refactoring, comments and documentation comments in GeglBufferIterator - Avoid duplicate, aliasing stack allocations + OpenCL: - Update headers to OpenCL 3.0 - Use gmodule for loading, also on windows - Buffer access code refactored, unifying destruction code paths - Move kernels to operations part of directory hierarchy - Warn on console on initialization errors + Ops: - General: make more consistent use of title case (changing strings, affecting translations) - Factor out common deps for ops in meson - rgbe_load: bail if x or y dimension larger than max scanline width, also further robustness for corrupt files - exp_combine: use public rather than private APIs, qsort rather than g_sort_array - waterpixels, normal-map, gblur-1d: fix crashes due to stack allocations in loop - introspect: fix warnings in console - ff-load, ff-save: disable by default - rawbayer-load (in workshop, not built by default): avoid code execution - normal-map: fix scratch buffer allocations - sdl3-display: SDL3 variant of display op - workshop/sharpen: new operation implementing the classic GIMP sharpen filter - Add pkgconfig(sdl3) BuildRequires: New dependency. - Rebase gegl-CVE-2026-18300.patch with quilt. - Add gegl-CVE-2026-18300.patch: libs/rgbe: fix >200kb report from ZDI (bsc#1276229, CVE-2026-18300) ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - Replace gimp-CVE-2026-66757.patch with the upstream backport. - Add gimp-CVE-2026-66757-2.patch: fix allocation of SGI tables (glgo#GNOME/gimp!2984). ==== glibc ==== Version update (2.43 -> 2.44) Subpackages: glibc-devel glibc-extra glibc-gconv-modules-extra glibc-locale glibc-locale-base - dt-d-rule.patch: Makerules: Make the .dt to .d conversion safe against concurrent sub-makes - math-sinh-worst-case-results.patch: math: Fix sinh worst-case results for |x| > 36.736801 (BZ #34441) - math-x86-64-tanh-floatn-aliases.patch: Fix x86_64 tanh _FloatN aliases binding to the FMA variant (BZ #34465) - elf-honor-skip-ifunc-for-ifunc-relocations.patch: elf: Honour skip_ifunc for cross-object IFUNC relocations (BZ #34428) - For the cross-x86_64 flavor also build the -m32 glibc - Enable cross-x86_64 - Update to glibc 2.44 * System-wide tunables can be applied using /etc/tunables.conf and running ldconfig * A new tunable, glibc.elf.thp, is added to map read-only segments with Transparent Huge Pages (THP) if THP is not disabled in the kernel * The THP page size in malloc is capped to MAX_THP_PAGESIZE * Additional optimized and correctly rounded mathematical functions have been imported from the CORE-MATH project * Many additional improvements to existing functions have been synchronized from the CORE-MATH project * For C++26, the assert macro is now variadic * The SVID error handling for cosh and sinh was moved to compatibility symbols * Static PIE is now supported for arm-*-linux-gnueabi * On AArch64 targets that support the Guarded Control Stack extension all GCS operations (including status, write on shadow stack, and push to shadow stack) are locked after enabling GCS with ENFORCED or OVERRIDE GCS policy * On AArch64 targets, log, exp, sin, cas, sinh, cosh, asinh, acosh, atanh single and double precision special cases have been vectorized for SVE and AdvSIMD, and vector variants of powr have been added * On RISC-V targets, vector extension optimized variants of memcmp, memccpy, memchr, memcpy, memmove, stpncpy, strcmp, strchr, strcpy, strncmp, strncpy, strlen, and strrchr have been added * On PowerPC, memchr optimized for Power10 has been re-added * Pre-built ld.so.cache files can be installed with ldconfig * A new locale has been added: hrx_BR (Hunsrik language spoken in Brazil) * Although malloc and related functions currently return pointers aligned to alignof (max_align_t), the documentation now says future versions of glibc may relax alignment requirements for small allocations * GLIBC-SA-2026-0013: Potential stack-based buffer clash during tilde expansion in wordexp (CVE-2026-6791) * GLIBC-SA-2026-0014: wordexp with WRDE_APPEND may result in an invalid call to free() (CVE-2026-6368) - resolv-count-resource-records.patch, resolv-check-hostname.patch, ldbl-128ibm-ceill-floorl-roundl-truncl.patch, getlogin-utmp-fallback.patch, nss-malloc-failure-checks.patch, nss-database-for-fork.patch, malloc-sys-kernel-mm.patch, tests-aarch64-makefile-deps-bti.patch, aarch64-lock-gcs-startup.patch, elf-strlen-redir-ifunc.patch, riscv-redir-memcpy-generic.patch, tst-rseq-linux-7.patch, sys-mount-cloexec-flag.patch, sys-mount-open-tree-macros.patch, ibm139x-pending-char-state.patch, ungetwc-byte-stream.patch, scanf-mc-buffer-overflow.patch, fma-shift-ub.patch, struct-reserved-members.patch, iconv-translit-intermediate-errors.patch, arm-vfp-plt-trampoline.patch, resolv-sprintrrf-unkown-types.patch, resolv-sprintrrf-inet-ntop-check.patch, resolv-sprintrrf-buffer-overreads.patch: Removed ==== gnome-sudoku ==== Version update (50.3 -> 50.4) - Update to version 50.4: + Partly fix numbers sometimes leaving artifacts on removal + Updated translations. ==== google-noto-fonts ==== Version update (20260801 -> 20260901) Subpackages: google-noto-sans-arabic-fonts google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Update to 20260901: * Serif Toto: - Improve the Kerning of BREATHY EO - Reverts the change to the dot under TOTO LETTER WA * Sans Miao: Add 9 Miao glyph variants for the Lipo language ==== gpg2 ==== Version update (2.5.21 -> 2.5.22) Subpackages: dirmngr - Update to 2.5.22: * gpg: New option "primary" for the --card-edit "generate" command. This option is useful create only the primary key on the first slot of an OpenPGP card * gpgsm: Emit issuer and serial no. when the certificate is not found * A range of bug fixes ==== gpgme ==== Version update (2.1.2 -> 2.2.0) Subpackages: libgpgme45 - Update to 2.2.0: * gpgme_verify_result_t now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Handle the new SIGINFO status line * Ignore TRUST_ status lines if no NEWSIG was seen ==== gpgmepp ==== Version update (2.1.0 -> 2.2.0) - Update to 2.2.0: * Signature now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Added missing getters for the number of notations of a signature and the numbers of created signatures and of invalid signing keys of a signing result ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-arm64-efi-bls grub2-common grub2-snapper-plugin grub2-systemd-sleep-plugin - Backport merged upstream patch * 0001-fs-btrfs-mark-Btrfs-on-disk-structs-as-GRUB_PACKED.patch * 0002-fs-btrfs-add-btrfs-info-command.patch * 0003-fs-btrfs-add-btrfs-list-subvols-command.patch * 0004-fs-btrfs-add-btrfs-get-default-subvol-command.patch - Patch rebased * grub2-btrfs-01-add-ability-to-boot-from-subvolumes.patch * grub2-btrfs-06-subvol-mount.patch * grub2-btrfs-10-config-directory.patch - Drop local patch * grub2-btrfs-09-get-default-subvolume.patch ==== gstreamer-plugins-bad ==== Subpackages: libgstadaptivedemux-1_0-0 libgstanalytics-1_0-0 libgstbadaudio-1_0-0 libgstbasecamerabinsrc-1_0-0 libgstcodecparsers-1_0-0 libgstcodecs-1_0-0 libgstcuda-1_0-0 libgsthip-1_0-0 libgstinsertbin-1_0-0 libgstisoff-1_0-0 libgstmpegts-1_0-0 libgstmse-1_0-0 libgstphotography-1_0-0 libgstplay-1_0-0 libgstsctp-1_0-0 libgsturidownloader-1_0-0 libgstva-1_0-0 libgstvulkan-1_0-0 libgstwayland-1_0-0 libgstwebrtc-1_0-0 libgstwebrtcnice-1_0-0 - Disable msdk plugin, currently broken, and in practice abandoned upstream. It is also ranked as 0, so to even attempt to use it, users have to manually enable it via the command line. ==== gtk3 ==== Version update (3.24.52 -> 3.24.52+git59.b30343717d) Subpackages: gtk3-data gtk3-immodule-amharic gtk3-immodule-inuktitut gtk3-immodule-thai gtk3-immodule-tigrigna gtk3-immodule-vietnamese gtk3-schema gtk3-tools libgtk-3-0 typelib-1_0-Gtk-3_0 - Update to version 3.24.52+git59.b30343717d: + filechooser: Avoid converting CSS font size twice + a11y: Do not emit false focus changes for a notebook tab on page changes + Window: Free empty string set to gtk-menu-bar-accel + wayland: Align decoration layout fallback with GtkSettings + filechooserwidget: stop the location and load timeouts in dispose - Update to version 3.24.52+git48.b9cc75f19f: + menu: Avoid scrolling too far + gtkapplication: Fix gtk_application_dbus_register return value + gtk/window: NULL check settings before disconnecting handler + gtkwindow: Clear active state on disappearing pointer + gdk/wayland: Remove unused field in _GdkWaylandSelection + gdk/wayland: Make primary selection and clipboard updates less racy + gdk/wayland: Clear dnd targets + gdk/wayland: Set clipboard targets atomically + Focus does not return to the main window when closing File Chooser + gdk/wayland: Add support for wl_fixes.ack_global_remove + x11: Fix wrong display when getting xatom - Drop gtk3-fix-xi2-xatom.patch:fixed upstream. ==== gtk4 ==== Version update (4.22.4+29 -> 4.22.4+35) Subpackages: gtk4-schema gtk4-tools libgtk-4-1 typelib-1_0-Gtk-4_0 - Update to version 4.22.4+35: + css: Fix invalidation for text decorations + gtkapplication-wayland: Add a missing NULL check when forgetting a window + Updated translations. ==== harfbuzz ==== Version update (14.3.1 -> 14.4.0) Subpackages: libharfbuzz-gobject0 libharfbuzz-icu0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.4.0: + Glyph positions and extents now saturate instead of overflowing. + Arabic Windows-1256 fallback shaping is now enabled on all platforms. + Fix cluster values and a dropped glyph advance in the Graphite shaper. + Fix `avar` axis value mapping in fonts that repeat the boundary entries. + Fix `avar` version 2 partial instancing. + Fix `COLR` sweep gradient truncation and unbounded memory use. + Faster subsetting, especially for large `GSUB`/`GPOS` and `CFF` tables. + Faster extraction of the experimental glyph dependency graph. + Various shaping speedups. + Various fixes for crashes and hangs with malformed fonts. + Various fixes to the experimental raster, vector, and GPU libraries. + Various improvements to the HarfRust integration shaper. + The DirectWrite backend no longer uses the C++ runtime. + Various build, portability, and fuzzing fixes. + New API: +hb_set_intersects() ==== hwdata ==== Version update (0.410 -> 0.411) - Update to version 0.411: * Update pci and vendor ids ==== ibus ==== Subpackages: ibus-dict-emoji ibus-gtk ibus-gtk3 libibus-1_0-5 typelib-1_0-IBus-1_0 - Backport patches to fix crashes with GNOME 51 (boo#1279542): + 1a331e695d84fc6bae8f2d11c52d4776df49647b.patch + 5bbe88a1936246185a65f76e58cc85871401e59a.patch ==== ibus_gtk4 ==== - Backport patches to fix crashes with GNOME 51 (boo#1279542): + 1a331e695d84fc6bae8f2d11c52d4776df49647b.patch + 5bbe88a1936246185a65f76e58cc85871401e59a.patch ==== imlib2 ==== Version update (1.12.6 -> 1.12.7) Subpackages: imlib2-loaders libImlib2-1 - Add imlib2-jpeg-arm32.patch: loader_jpeg: silence -Wcast-align error on 32-bit ARM architectures. - Update to version 1.12.7: + AVIF saver: Fix saving images with alpha + BMP loader: Fix alpha detection + JXL loader: Change runners from max 4 to ncores/2 + JXL loader: Refactor runners handling + PNM loader: add support for 16-bit (high depth) PGM/PPM/PAM + Spec file: Add a %conf section + TIFF saver: Fix saving images with alpha + ico: validate palette size for indexed images + id3: reject external APIC picture links + j2k: limit decoded image dimensions + loaders: limit decompressed temporary output + png: validate APNG IHDR length + scale: add bicubic scaling via uscaler + scale: support flips with uscaler + y4m: read high-bit-depth grayscale samples safely + Updated tests. - Add imlib-ico-loader.patch: Fix ico loader: planes and bpp are defined as uint16 in the spec, thus apply LE_16 macros on it (boo#1278182). ==== iproute2 ==== Version update (7.1 -> 7.2) - Update to release 7.2 * dpll: Added frequency monitoring support * dpll: monitor: add -t/--timestamp and --tshort options * rdma: netns can now be specified by PID * bridge: vlan: Added support for neigh_forward_grat * netshaper: Added bw-min and weight parameter support * netshaper: Added group command for creating scheduling hierarchies * iplink: bridge: Added stp_mode support * devlink: Added dump support for resource show - Ditch libnetlink-devel. This was never really a public API, and mipv6d (its original user back in 2014) has long had its own copy of libnetlink. ==== kernel-firmware-amdgpu ==== Version update (20260717 -> 20260829) - Update to version 20260829 (git commit 458e40fdbb4d): * amdgpu: DMCUB updates for various ASICs - Update to version 20260828 (git commit b6bdea3726dc): * amdgpu: add VCN 5.3.0 firmware - Update to version 20260821 (git commit 8c7fac62c0d1): * amdgpu: add VPE 2.0.0 firmware * amdgpu: add SDMA 6.1.4 firmware * amdgpu: add DCN 4.2 firmware * amdgpu: add PSP 15.0.9 firmware * amdgpu: add PSP 15.0.0 firmware * amdgpu: add GC 11.7.1 firmware * amdgpu: add GC 11.7.0 firmware * amdgpu: DMCUB update for DCN314 - Update to version 20260814 (git commit 2398c20fc656): * amdgpu: DMCUB updates for various ASICs - Update to version 20260813 (git commit 984503d80fd6): * Revert "amdgpu: update GC 10.3.6 firmware" * amdgpu: update vangogh firmware * amdgpu: update VPE 6.1.1 firmware * amdgpu: update VCN 4.0.6 firmware * amdgpu: update PSP 14.0.1 firmware * amdgpu: update GC 11.5.1 firmware * amdgpu: update VPE 6.1.0 firmware * amdgpu: update VCN 4.0.5 firmware * amdgpu: update PSP 14.0.0 firmware * amdgpu: update GC 11.5.0 firmware * amdgpu: update renoir firmware * amdgpu: update yellow carp firmware * amdgpu: update raven2 firmware * amdgpu: update raven firmware * amdgpu: update VCN 3.1.2 firmware * amdgpu: update PSP 13.0.5 firmware * amdgpu: update GC 10.3.6 firmware * amdgpu: update picasso firmware * amdgpu: update PSP 13.0.11 firmware * amdgpu: update GC 11.0.4 firmware * amdgpu: update VCN 4.0.2 firmware * amdgpu: update PSP 13.0.4 firmware * amdgpu: update GC 11.0.1 firmware * amdgpu: update VCN 5.0.0 firmware * amdgpu: update SMU 14.0.3 firmware * amdgpu: update PSP 14.0.3 firmware * amdgpu: update GC 12.0.1 firmware * amdgpu: update SMU 14.0.2 firmware * amdgpu: update PSP 14.0.2 firmware * amdgpu: update GC 12.0.0 firmware * amdgpu: update vcn 4.0.4 firmware * amdgpu: update SMU 13.0.7 firmware * amdgpu: update PSP 13.0.7 firmware * amdgpu: update GC 11.0.2 firmware * amdgpu: update SMU 13.0.10 firmware * amdgpu: update SDMA 6.0.3 firmware * amdgpu: update PSP 13.0.10 firmware * amdgpu: update GC 11.0.3 firmware * amdgpu: update VCN 4.0.0 firmware * amdgpu: update SMU 13.0.0 firmware * amdgpu: update PSP 13.0.0 firmware * amdgpu: update GC 11.0.0 firmware * amdgpu: update beige goby firmware * amdgpu: update dimgrey cavefish firmware * amdgpu: update navy flounder firmware * amdgpu: update sienna cichlid firmware * amdgpu: update navi14 firmware * amdgpu: update navi12 firmware * amdgpu: update navi10 firmware * amdgpu: add PSP 13.0.15 firmware * amdgpu: update VCN 5.0.1 firmware * amdgpu: update PSP 13.0.12 firmware * amdgpu: update GC 9.5.0 firmware * amdgpu: update PSP 13.0.14 firmware * amdgpu: update GC 9.4.4 firmware * amdgpu: update PSP 14.0.5 firmware * amdgpu: update GC 11.5.3 firmware * amdgpu: update VPE 6.1.3 firmware * amdgpu: update PSP 14.0.4 firmware * amdgpu: update GC 11.5.2 firmware * amdgpu: update green sardine firmware * amdgpu: update arcturus firmware * amdgpu: update VCN 4.0.3 firmware * amdgpu: update PSP 13.0.6 firmware * amdgpu: update GC 9.4.3 firmware * amdgpu: update aldebaran firmware - Update to version 20260728 (git commit 543b8f5f987c): * amdgpu: DMCUB updates for various ASICs ==== kernel-firmware-ath10k ==== Version update (20260610 -> 20260809) - Update to version 20260809 (git commit 6f221d80d2fa): * ath10k: WCN3990 hw1.0: update board-2.bin ==== kernel-firmware-ath12k ==== Version update (20260610 -> 20260813) - Update to version 20260813 (git commit 984503d80fd6): * ath12k: QCC2072 hw1.0: update to WLAN.COL.1.0.c2-00228-QCACOLSWPL_V1_TO_SILICON-1 ==== kernel-firmware-bluetooth ==== Version update (20260720 -> 20260828) - Update to version 20260828 (git commit b6bdea3726dc): * linux-firmware: Update firmware file for Intel BlazarIW core * linux-firmware: Update firmware file for Intel BlazarU core * linux-firmware: Update firmware file for Intel Scorpius core - Update to version 20260825 (git commit 0305399a8783): * QCA: Update Bluetooth WCN3988 firmware 2.1.5.c5-00042 to 2.1.5.c5-00060 - Update to version 20260821 (git commit 8c7fac62c0d1): * qca: Update Bluetooth QCC2072 UART interface firmware from 1.1.0-00295 to 1.1.0-00340 ==== kernel-firmware-i915 ==== Version update (20260706 -> 20260806) - Update to version 20260806 (git commit 16d815da3637): * xe: Update GUC to v70.72.1 for BMG, LNL, PTL, NVL-S ==== kernel-firmware-intel ==== Version update (20260610 -> 20260728) - Update to version 20260728 (git commit 543b8f5f987c): * intel_vpu: Update NPU firmware ==== kernel-firmware-iwlwifi ==== Version update (20260610 -> 20260820) - Update to version 20260820 (git commit f2ab551dea14): * iwlwifi: add Bz/Sc FW for core24.70-49 release * iwlwifi: Add Hr/Gf firmware for core24.70-49 release * iwlwifi: update ty/So/Ma firmwares for core24.70-49 release * iwlwifi: update cc/Qu/QuZ firmwares for core24.70-49 release - Update to version 20260703 (git commit c95059a3774b): * iwlwifi: add Bz/Sc FW for core24.60-33 release * iwlwifi: Add Hr/Gf firmware for core24.60-33 release * iwlwifi: update ty/So/Ma firmwares for core24.60-33 release * iwlwifi: update cc/Qu/QuZ firmwares for core24.60-33 release ==== kernel-firmware-media ==== Version update (20260706 -> 20260813) - Update to version 20260813 (git commit 984503d80fd6): * qcom: vpu: add Gen2 firmware binary for Eliza - Update to version 20260731 (git commit a968c5c2962e): * qcom: venus-5.4: fix vp9 decoder assertion failure ==== kernel-firmware-mediatek ==== Version update (20260629 -> 20260825) - Update to version 20260825 (git commit 0305399a8783): * mediatek MT7925: update bluetooth firmware to 20260813113236 * linux-firmware: update firmware for MT7925 WiFi device - Update to version 20260813 (git commit 984503d80fd6): * linux-firmware: update firmware for MT7922 WiFi device - Update to version 20260805 (git commit 31883adc3365): * mediatek MT7922: update bluetooth firmware to 20260724143815 ==== kernel-firmware-network ==== Version update (20260610 -> 20260813) - Update to version 20260813 (git commit 984503d80fd6): * morsemicro: add firmware for mm8108 support - Update to version 20260806 (git commit 16d815da3637): * linux-firmware: Update firmware for an8811hb 2.5G ethernet phy - Update to version 20260805 (git commit 31883adc3365): * airoha: update AN7583 NPU firmwares to version 0.5 ==== kernel-firmware-qcom ==== Version update (20260717 -> 20260828) - Update to version 20260828 (git commit b6bdea3726dc): * qcom: update CDSP firmware for x1e80100 platform * qcom: add QUPv3 firmware for nord * qcom: add HPASS firmware for nord platform * qcom/sa8775p: update signature on cdsp1 firmware - Update to version 20260820 (git commit f2ab551dea14): * qcom: add NSP firmware for nord platform * WHENCE: Move qcom qcdxkmsuc8[23]80.mbn firmwares to Adreno section - Update to version 20260813 (git commit 984503d80fd6): * qcom: add CDSP firmware for eliza platform - Update to version 20260803 (git commit 73b4d58aba76): * qcom: Add gpu firmwares for Eliza chipset - Update to version 20260728 (git commit 543b8f5f987c): * qcom: Update qdsp6sw firmware for shikra platform * qcom: Update DSP firmware for qcs8300 platform ==== kernel-firmware-qlogic ==== Version update (20260610 -> 20260731) - Update to version 20260731 (git commit a968c5c2962e): * qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters ==== kernel-firmware-realtek ==== Version update (20260629 -> 20260731) - Update to version 20260731 (git commit a968c5c2962e): * rtw89: 8922d: add fw 0.35.113.2 - Update to version 20260728 (git commit 543b8f5f987c): * rtw88: add firmware v41.0.0 for RTL8723B ==== kernel-firmware-sound ==== Version update (20260706 -> 20260825) - Update to version 20260825 (git commit 0305399a8783): * cirrus: cs35l54: Add Cirrus CS35L54 firmware mappings for an HP laptop * linux-firmware: Upload firmware for tas2573 stereo * intel: avs: Add AudioDSP base firmware for LKF platforms * intel: avs: Update AudioDSP firmware for APL-based platforms * intel: avs: Update AudioDSP firmware for SKL-based platforms * intel: catpt: Update AudioDSP firmware for BDW platforms - Update to version 20260820 (git commit f2ab551dea14): * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Samsung laptops * cirrus: cs42l45: Add new SSIDs for Dell laptops * cirrus: cs35l56: Add firmware for Cirrus Amps for an ASUS laptop * cirrus: cs35l56: Add Cirrus CS35L56 firmware mappings for some Dell laptops - Update to version 20260813 (git commit 984503d80fd6): * cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for some Dell laptops - Update to version 20260803 (git commit 73b4d58aba76): * linux-firmware: Add firmware for new project - Update to version 20260731 (git commit a968c5c2962e): * cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops - Update to version 20260728 (git commit 543b8f5f987c): * linux-firmware: Add firmware for new soundwire projects ==== kernel-firmware-ueagle ==== Version update (20260610 -> 20260703) - Update to version 20260703 (git commit c95059a3774b): * ueagle-atm: sadly drop unlicensed files ==== kernel-source ==== Version update (7.2.2 -> 7.2.3) Subpackages: kernel-64kb kernel-default - Update patches.kernel.org/7.2.1-083-ptp-vmclock-prevent-read-only-mappings-from-bec.patch (bsc#1012628 CVE-2026-80724 bsc#1277850). - Update patches.kernel.org/7.2.2-001-inet-frags-strip-GSO-state-from-fragments-befor.patch (bsc#1012628 CVE-2026-80590 bsc#1277275). suse-add-cves - commit 263d925 - Update config files. - commit a590eb7 - Update config files. - commit f305596 - Linux 7.2.3 (bsc#1012628). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (bsc#1012628). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (bsc#1012628). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (bsc#1012628). - USB: serial: spcp8x5: drop broken carrier detect support (bsc#1012628). - USB: serial: option: fix slab OOB read in interrupt URB callback (bsc#1012628). - ALSA: usb-audio: Complete cleanup after system-resume errors (bsc#1012628). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (bsc#1012628). - ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB (bsc#1012628). - usb: core: Strengthen error handling in hub_hub_status() (bsc#1012628). - usb: core: Add lock to usb_wakeup_notification() (bsc#1012628). - KVM: s390: vsie: zero stale crypto bits (bsc#1012628). - crypto: qce - Remove unsafe/deprecated algorithms (bsc#1012628). - crypto: mxs-dcp - fix source scatterlist length access (bsc#1012628). - crypto: iaa - fall back to software for multi-entry scatterlists (bsc#1012628). - crypto: qce - fix CCM AAD buffer underallocation (bsc#1012628). - crypto: krb5 - use kfree_sensitive() for derived key buffers (bsc#1012628). - crypto: atmel-tdes - use scatterlist length before DMA mapping (bsc#1012628). - crypto: sun8i-ss - Remove crypto_rng interface (bsc#1012628). - crypto: sun8i-ce - Remove crypto_rng interface (bsc#1012628). - crypto: qcom-rng - Allow zero as a random number (bsc#1012628). - crypto: qcom-rng - Remove crypto_rng interface (bsc#1012628). - crypto: qcom-rng - Enable clock in hwrng case (bsc#1012628). - crypto: virtio - bound the akcipher result length (bsc#1012628). - kunit: irq: Continue increasing hrtimer interval for longer (bsc#1012628). - mm/swap: reject swapon() on filesystem-level encrypted files (bsc#1012628). - netfilter: nf_tables: don't queue packet path object notifications (bsc#1012628). - netfilter: nft_set_pipapo_avx2: add missing vzeroupper (bsc#1012628). - vxlan: keep the last remote linked during FDB flush (bsc#1012628). - batman-adv: reject unrepresentable multicast TVLV offsets (bsc#1012628). - ipv6: seg6: clear IPv4 control block on IPIP decapsulation (bsc#1012628). - net/packet: defer vmalloc TX_RING free until skbs finish (bsc#1012628). - vlan: fix skb_under_panic and races when toggling HW VLAN offload (bsc#1012628). - net: bridge: mcast: fix use-after-free of a master VLAN's multicast context (bsc#1012628). - xfrm: bound nat keepalive state collection (bsc#1012628). - xfrm: fix xfrm_state_construct() auth-trunc leak (bsc#1012628). - xfrm: ah6: validate routing header segments_left (bsc#1012628). - xfrm: avoid lock inversion in nat keepalive work (bsc#1012628). - xfrm: drop ESP-in-TCP packets with no ingress device (bsc#1012628). - tcp: clamp route advmss to TCP_MIN_MSS (bsc#1012628). - xfrm: espintcp: fix UAF during close (bsc#1012628). - net: advertise TCP MSS from the configured MTU, not the learned PMTU (bsc#1012628). - net/tcp-ao: fix use-after-free of current_key on reconnect to another peer (bsc#1012628). - tcp: fix AO info use-after-free in tcp_ao_connect_init() (bsc#1012628). - net/tcp: fix TCP-AO key deletion in VRFs (bsc#1012628). - gtp: serialize PDP context updates (bsc#1012628). - tls: device: fix out-of-bounds write in tls_append_frag() (bsc#1012628). - KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y (bsc#1012628). - KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable (bsc#1012628). - KVM: SEV: Extract loading of guest-provided VMSA to a separate helper (bsc#1012628). - KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests (bsc#1012628). - KVM: SEV: Drop FOLL_WRITE for encrypted region registration (bsc#1012628). - KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts (bsc#1012628). ... changelog too long, skipping 49 lines ... - commit dcfc956 ==== kquickimageeditor6 ==== Version update (0.6.2.1 -> 0.7.0.1) Subpackages: kquickimageeditor6-imports libKQuickImageEditor1 - Update to 0.7.0.1: * Fix build on ARM with SVE - Update to 0.7.0: * Removed OpenCV dependency by replacing the stack blur with a Qt Concurrency and Highway SIMD library based implementation. * Added color adjustment API. * Added repainted signal to AnnotationDocument. AnnotationDocument periodically repaints annotationsImage and canvasBaseImage. * AnnotationDocument::renderToImage always returns the latest image. If necessary, it will wait for repaints to finish before returning. * Annotation shadows don't jitter as much while being drawn or resized. * Added hasSelectionChanged and optionsChanged signals to SelectedItemWrapper. * For more details see https://mail.kde.org/pipermail/kde-announce/2026-August/000524.html - Add %check ==== libbpf ==== - Use make macros with -C ==== libcloudproviders ==== Version update (0.4.0 -> 0.4.1) - Update to version 0.4.1: + Complete the documentation to fix the validation test. ==== libcupsfilters ==== Subpackages: libcupsfilters2 - libcupsfilters-2.1.1-CVE-2026-64611.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/4b343522823403df01f6753082df83f07d18c217 backported to libcupsfilters 2.1.1 to fix CVE-2026-64611 "Infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4 "user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop" (bsc#1273145) - libcupsfilters-2.1.1-CVE-2026-64612.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 backported to libcupsfilters 2.1.1 to fix CVE-2026-64612 "Malformed PNG aborts CUPS image filter process (missing libpng setjmp recovery)" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch "authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG" (bsc#1273146) ==== libfastjson ==== Version update (1.2304.0+ga630254 -> 1.2609.0) - Update to 1.2609.0: * Speed up object member lookup by traversing child pages directly * Fix buffered JSON dumping with zero-sized and small caller- provided workspaces * Ensure correct linking with libm on glibc 2.42 and later * Correct transposed calloc() arguments that trigger warnings with newer compilers * Clarify string-buffer lifetime and thread-safety guarantees in the API documentation * Expand correctness tests, fuzzing, and cross-platform CI coverage ==== libfido2 ==== Subpackages: libfido2-1 libfido2-udev - Drop USE_HIDAPI, as it produces a race condition (bsc#1234010) ==== libgcrypt ==== Version update (1.12.2 -> 1.12.3) - Update to 1.12.3: * Validate hash algorithm for use with RSA modulus * Validate parameters of Balloon KDF * Validate parallelism of Argon2 KDF * Fix parsing quoted parts and CRLF/LFCR in s-expression * Support BUFLEN check for GCRYMPI_FMT_SSH * Fix RSA PSS verify message length checking * Avoid a NULL ptr deref due to a unsupported genkey flag for ECC * Assert 32 KiB input cap in gcm_ctr_encrypt * Fix assertion failure in OCB when a buffered block becomes block 65536 * Fix OOB read in IMIT MAC verify of GOST28147 * Fix CMAC block-count truncation for 64 GiB writes * Fix AEAD spurious byte-counter carry for 4 GiB adds * Validate all KEM input lengths * Add length check of DATALEN when parsing s-expression * Only accept canonical value for S with EdDSA * Only accept canonical signatures for RSA * Fix an assertion failure for invalid small-order Ed25519 public keys * Validate length of supplied receiver public-key length in DHKEM decapsulation * Use a more strict value for the PKCS#1 minimal frame length. * Use just strong random for the Dilithium signature nonce and the Kyber encapsulation coins * Allow internal users to skip fast random poll for ciphers and hashes * Speedup sntrup761 by defer reduction in polynomial multiplication, reading random with a single call, and reducing freeze helpers w/o division * Avoid byte-wise load/store on RISC-V with Zicclsm * Use unaligned vector memory access on RSIV-V when supported * Add Intel SM4 instructions accelerated AVX512 and AVX2 implementation * Add Intel SM3 extension implementation * Add Intel SHA512 extension implementation * kyber: Accept and return a seed using the gcry_pk_genkey API * Add curve "ietf25" as alternative to "Curve25519" with exact RFC-8410 semantics. The name "X25519" was already used as an alias, thus this new name. * Add straight-line speculation hardening for function ends * Fix constant time memequal check for SM2 * Add post-quantum algorithm benchmarking to bench-slope * Due to the minor API updates and but with no newer branch released the SO name has been updated. - update upstream signing key ==== libheif ==== Version update (1.23.1 -> 1.23.4) Subpackages: gdk-pixbuf-loader-libheif libheif-aom libheif-dav1d libheif-ffmpeg libheif-jpeg libheif-openh264 libheif-openjpeg libheif-rav1e libheif-svtenc libheif1 - Update to version 1.23.4: * CVE-2026-XXXXX: The max_items security limit was not enforced for the child boxes of iinf, so a file could declare an unbounded number of items. * CVE-2026-XXXXX: Unbounded recursion in the reference-cycle check crashed the parser on a long chain of derived items, without bound when the item-count limit is disabled. * CVE-2026-XXXXX: Permanent decoder deadlock through a lock-order inversion in parallel grid tile decoding (enabled by default). * CVE-2026-XXXXX: Heap out-of-bounds read in the encoder pluginsi for images whose luma and chroma bit depths differ. * CVE-2026-XXXXX: Unreclaimable memory leak in heif_track_get_next_raw_sequence_sample(). * CVE-2026-XXXXX: Heap out-of-bounds read in the WebCodecs decoder plugin - includes fixes from 1.23.3: * CVE-2026-XXXXX: Heap buffer overflow (write) in the uncompressed (unci) mixed-interleave decoder when the two chroma components declare different bit depths. * CVE-2026-XXXXX: Permanent decoder deadlock through a reference cycle between an image and its alpha auxiliary image. * CVE-2026-XXXXX: Heap out-of-bounds read in the YCbCr 4:2:0 to 16-bit interleaved RGB conversion when the chroma planes have a lower bit depth than luma * CVE-2026-XXXXX: Heap buffer overflow in the SVT-AV1 encoder plugin when encoding a high-bit-depth alpha channel, and a double free on its send-picture error path. * CVE-2026-84451: Incomplete fix: the tile range check of the unci decoder (without icef) could still overflow, allowing an out-of-bounds read * CVE-2026-XXXXX: Heap out-of-bounds read when converting odd- height 4:2:0 frames of an uncompressed (uncv) image sequence to RGB. * CVE-2026-XXXXX: Out-of-bounds read in the RGB to YCbCr identity- matrix color conversion when the R, G, and B planes have different bit depths * CVE-2026-84450: A clap property combined with an oversized ispe reached an assert() in the Fraction arithmetic and aborted the process (incomplete fix). An error is returned instead. * Fix Several smaller findings * Fix Undefined behavior (negative shift) in the HDR bit-depth up-conversion for target bit depths above 16. Such conversions are now rejected. * A number of bug fixes - Update to version 1.23.2: * CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl items. (boo#CVE-2026-84383) * Out-of-bounds read and write in derived-item and pixel-plane handling. Through iden and auxl item chains, a crafted file could attach pixel planes whose size differs from the image geometry; crop, scale, and plane-extraction code then indexed those planes with the wrong size. A working code-execution exploit was confirmed. Plane sizes are now validated wherever they are consumed. (boo#1279444) * CVE-2026-84384: brotli/zlib decompression of mime metadata and unci image data had no effective output-size limit, so a decompression bomb could exhaust memory. Decompressed output is now bounded by the security limits. (boo#1279445) * CVE-2026-84447: Chains of derived-image references (grid, iovl, iden) bypassed decode caching and memory limits, causing CPU and memory amplification. (boo#1279446) * CVE-2026-84446: Sequence sample-timing initialization could produce non-terminating decode loops and unbounded memory, bypassing max_sequence_frames. (boo#1279447) * CVE-2026-84444: Out-of-bounds write in the unci encoder when heif_context_add_image_tile() is given a tile whose planes do not match its declared size. (boo#1279448) * CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API when mask_data_len does not match the region geometry. (boo#1279449) * C++ exceptions such as std::bad_alloc can no longer escape the C API read/decode entry points; they are returned as a heif_error instead of aborting the process * assert()s in the pixel-image plane allocation were replaced by runtime errors * stts/ctts tables describing more samples than the track can have are rejected * pclr (JPEG 2000 palette) box: the number of palette entries is bounded by the box size * BitReader::skip_bytes() is now constant time (fixes a fuzzer timeout on bogus alignment values) * iden items now validate the decoded image size like all other items * The uncompressed (unci) encoder rejects images without pixel planes * meta, mini, and moov boxes with size 0 (extending to the end of the file) are now parsed correctly * Fixed an integer overflow when probing the file size * Fixed undefined behavior (signed shift) when reading the NAL unit length in the OpenH264 decoder * heif_region_item_add_region_inline_mask_data() now requires non-zero width and height and the mask_data_len must equal the expected (width * height + 7) / 8; otherwise it returns an error instead of storing the mask * heif_image_add_plane() returns an error instead of aborting for bit depths outside 1..128 or interleaved component counts outside 1..255 ==== libjpeg-turbo ==== Subpackages: libjpeg8 libturbojpeg0 - do not skip djpeg12-shared-3x2-float-prog-cmp, use correct parameters instead ==== libksba ==== Version update (1.8.0 -> 1.8.1) - Update to 1.8.1: * Fix CMS parser to avoid possible infinite loop - drop libksba-nobetasuffix.patch, not needed when autoreconf is not run. Also don't run it. - Fix fgrep deprecation warnings in ksba-config --libs output boo#1203092 add libksba-1.8.1-fgrep-warning.patch, sent upstream ==== liblouis ==== Version update (3.38.0 -> 3.39.0) Subpackages: liblouis-data liblouis20 python3-louis - Update to version 3.39.0: + A lot of dedicated work by Bue, Tiago, Clive, Leonard, Anthony, Andrey, Dimitar, Danil Kostenkov, Dmitriy Lazarev, Christian Comaschi and Seeing Hands went into this release, and as always Bert did a lot of the work that holds it all together. It adds braille for Haitian Creole and for Māori, the latter following the policy of the Braille Authority of New Zealand Aotearoa Trust, which also brings new tables for English text in New Zealand. The Portuguese grade 1 table has been thoroughly overhauled, the English grade 3 table gained more than 5000 new hyphenation patterns, and the Russian tables gained mathematical braille definitions as well as the last of the grade 1 contractions. The Bulgarian, Italian and Biblical Hebrew tables all back-translate considerably better than before, and the UEB grade 2 shortforms have been cleaned up, which also makes the compiled table smaller. On the technical side several memory safety issues were fixed, building with clang and MSVC on Windows works again, and the ~spacing~ parameter of the translation functions has been deprecated. ==== libnftnl ==== Version update (1.3.1 -> 1.3.2) - Update to release 1.3.2 * Support for connlimit stateful objects * Now validates geneve class and type attribute size in setter and validates that the kernel does not provide too long geneve data attributes. * Do not print userdata content through snprintf API. * Enhancements for the snprint API to display data according to size and byteorder, this includes new functions nftnl_{expr,set_elem}_set_imm() to decorate the data. * More improvements for the snprintf() API for set elements: no colon is printed if data is not provided, print object names in maps and print flags only if non-zero. ==== libphonenumber ==== Version update (9.0.36 -> 9.0.38) - update to 9.0.38: * Updated phone metadata for region code(s): GM, HK, IN, JO, PG, SN, TZ, ZW * Updated geocoding data for country calling code(s): 55 (en), 61 (en), 91 (en), 220 (en), 221 (en), 263 (en) * Updated carrier data for country calling code(s): 221 (en), 254 (en), 255 (en), 373 (en), 675 (en), 852 (en, zh), 962 (en) - update to 9.0.37: * Updated alternate formatting data for country calling code(s): 34, 90 * Updated phone metadata for region code(s): AR, BD, CL, ES, FJ, GM, GY, IL, MZ, NO, PE, SJ, SY, TG, TR, UG * Updated short number metadata for region code(s): ES * Updated geocoding data for country calling code(s): 220 (en), 963 (en) * Updated carrier data for country calling code(s): 47 (en), 56 (en), 90 (en), 220 (en), 228 (en), 234 (en), 254 (en), 256 (en), 592 (en), 963 (en), 972 (en) * Updated / refreshed time zone meta data ==== libreoffice ==== Version update (26.2.5.2 -> 26.8.0.3) Subpackages: libreoffice-base libreoffice-calc libreoffice-draw libreoffice-filters-optional libreoffice-gnome libreoffice-gtk3 libreoffice-icon-themes libreoffice-impress libreoffice-l10n-en libreoffice-mailmerge libreoffice-math libreoffice-pyuno libreoffice-qt6 libreoffice-writer libreofficekit - Update to 26.8.0.3: * Release notes: https://wiki.documentfoundation.org/Releases/26.8.0/RC3 - Update bundled pdfium to 7681 and skia to m147 as required by the new download.lst. - Add box2d-detection.patch: configure derived the box2d version from pkg-config only, which fails with the box2d 2.4.1 we ship as it installs no box2d.pc. - Drop Qt 5 support in SLFO and Tumbleweed (related: boo#1277445) ==== libvirt ==== Version update (12.6.0 -> 12.7.0) Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - Update to libvirt 12.7.0 - CVE-2026-18917, CVE-2026-77158, CVE-2026-77159 - Many incremental improvements and bug fixes, see https://libvirt.org/news.html#v12-7-0-2026-09-01 ==== libxml2 ==== Version update (2.15.3 -> 2.15.4) Subpackages: libxml2-16 libxml2-tools - Update to version 2.15.4: + Security: - xmlregexp: Prevent out-of-bounds read in NXT macro - fix: add missing overflow checks in dict.c, uri.c, and valid.c - xmlregexp: Calc string length after null checking - xpointer: Check overflow in xmlXPtrEvalXPtrPart - xmlIO: Check for int overflow before calling writecallback - fix(xinclude): propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree + Improvements: - Improve bound checks for xmlcatalog and xmllint arguments (out-of-bound) - Fix memory leak in static Windows library (memory-leak) - xmlreader: Copy DTD in xmlTextReaderDumpCopy - parser: Fix double free in xmlIOParseDTD (double-free) - parser: fix division-by-zero when maxAmpl is set to 0 - parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak) - catalog: Make sure to reset catalog resolve cache - xmlAddChild: unlink node before free for text nodes (memory-leak) - Normalize entity values in attr in xmlNodeGetContent - Handle whitespace for date/time/duration types - catalog: Fix NULL deref for nextCatalog without 'catalog' attribute (null-deref) - Drop libxml2-CVE-2026-11979.patch: Fixed upstream. ==== libzypp ==== Version update (17.38.14 -> 17.38.15) - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. - Iniparser: each new file starts in the unnamed section (bsc#1272534) - Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - version 17.38.15 (35) ==== lightdm-gtk-greeter-branding-openSUSE ==== - Set default NumLock state as it is defined in KBD_NUMLOCK variable in /etc/sysconfig/keyboard using /run/numlock-on set by kbdsettings.service from kbd package and numlockx default. ==== localsearch ==== Version update (3.11.1 -> 3.11.2) - Update to version 3.11.2: + Fix possible crash after a directory is deleted + Fix extraction errors with some EPUB files + Fix "localsearch status -f" when extractor is active + Prevent possible main thread stalls when handling many errors + Fix possible situations where files are needlessly re-extracted + Updated translations. ==== m4 ==== - posix-spawn-faction.patch: Fix check for posix_spawn_file_actions_addchdir ==== mariadb-connector-c ==== - ead038d.patch: fix regresssion in mysql_stmt_bind_result (bsc#1273612) ==== mozilla-nspr ==== Version update (4.39 -> 4.40) - update to version 4.40 * no upstream release notes found ==== mozilla-nss ==== Version update (3.126.1 -> 3.127) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.127 * bmo#2060720 - Round ECH ClientHelloInner padding up to a multiple of 32 * bmo#2063071 - make selfserv listen on IPv6 wildcard on dual-stack hosts * bmo#2059176 - EC_DerivePublicKey() failure is not propagated in sftk_mkPrivKey() * bmo#2052210 - Generate additional test message for Thunderbird (HTML with remote image) * bmo#1869493 - Heap-buffer overflow in AES Keywrap * bmo#2054609 - remove cipher suite order exception from bug 946147 * bmo#2061107 - restore pkcs12.h for source compatibility * bmo#2056291 - remove support for pre-v1.0 PKCS#12 * bmo#2054719 - fix content type tag for CMS AuthEnvelopedData plaintext * bmo#2060118 - remove DH_GenParam support * bmo#2053831 - clang format * bmo#2054714 - avoid leaking stale ECH outer extensions across HRR * bmo#2053831 - Drop CKF_VERIFY flag from CKM_HKDF_DATA derivation in ECH GREASE * bmo#2053831 - Adjust PK11_Derive and TLS 1.3 derivation templates for CKM_HKDF_DATA and CKO_DATA compliance * bmo#2053831 - Use CKF_HKDF_SALT_DATA in tls13_HkdfExtract for CKO_DATA keys per PKCS#11 v3.2 * bmo#2057184 - Enable -Wunused-but-set-variable/-global in werror.py * bmo#2056846 - Remove unused policy string callback to fix - Wunused-but-set-global * bmo#2052709 - Convert NSS 3.126 release notes to Markdown * bmo#2052709 - Rename doc/rst to doc/src and update references * bmo#2052709 - Apply markdownlint to the converted Markdown docs * bmo#2052709 - Fix Markdown documentation build warnings * bmo#2052709 - Convert documentation from reStructuredText to Markdown (automated) ==== mozjs140 ==== Version update (140.14.0 -> 140.15.0) - Update to version 140.15.0: + See https://www.firefox.com/en-US/firefox/140.15.0/releasenotes/ ==== nautilus ==== Version update (50.2.2 -> 50.3.1) Subpackages: gnome-shell-search-provider-nautilus libnautilus-extension4 - Update to version 50.3.1: + Bugfixes: Fix a possible crash when changing app defaults after closing the app chooser + Cleanups: Attempt using any sushi version - Update to version 50.3: + Bugfixes: - Mark network address entry invalid on the a11y layer when appropriate - Correctly position related apps in the app chooser - Fix thumbnail not being updated while loading is some cases - Show the correct starred status and normal features of properties in Recents - Fix Escape not closing the app chooser dialog when the entry is focused - Fix a bug where copied files are not selected after the operation has ended - Fix memory trimming on window closure + Updated translations. ==== nftables ==== Version update (1.1.6 -> 1.1.7) Subpackages: libnftables1 python313-nftables - Update to release 1.1.7 * Fix spurious EEXIST error when using the create element command with large batches. * Improve error reporting for syntax errors by printing expected tokens. * Set element support for multi-statements, e.g. counter + quota. * Connlimit support with maps. * Support for using bitmask datatypes as set key, e.g. tcp flags. - Delete support-reproducible-build.patch (merged) ==== openSUSE-release ==== Version update (20260830 -> 20260908) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openssl-3 ==== Subpackages: libopenssl3 - Security fix: * CVE-2026-75803: openssl: AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() (bsc#1275837) * Add openssl-CVE-2026-75803.patch - Security fixes in August 2026 release: (bsc#1274774) * CVE-2026-14456: Unbounded Memory Growth in QUIC Server Incoming Channel Queue (bsc#1274791) * CVE-2026-14457: RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate (bsc#1274792) * CVE-2026-18798: QUIC Server May Trigger Double Free When Processing INITIAL Packet (bsc#1274777) * CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343) * CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795) * CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788) * CVE-2026-63073: Untrusted Sender DN Used as Format String in CMP Response Validation (bsc#1274796) * CVE-2026-63074: CMP Indefinite Cache Growth of ExtraCerts (bsc#1274797) * CVE-2026-63075: QUIC ACK-only Packet Retention Can Cause Memory Exhaustion (bsc#1274798) * CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790) * Add patches: openssl-CVE-2026-14456.patch openssl-CVE-2026-14457.patch openssl-CVE-2026-18798.patch openssl-CVE-2026-34181.patch openssl-CVE-2026-54874.patch openssl-CVE-2026-63072.patch openssl-CVE-2026-63073.patch openssl-CVE-2026-63074.patch openssl-CVE-2026-63075.patch openssl-CVE-2026-63076.patch ==== osinfo-db ==== Version update (20251212 -> 20260812) - Update to database version 20260812 (jsc#PED-14625) osinfo-db-20251212.tar.xz - Drop patches contained in new tarball Add-optional-recommended-attribute-to-firmware.patch add-win-2k19-media-info.patch add-sles16-support.patch (see bsc#1268781) - Update add-sles16.1-support.patch ==== ovmf ==== Subpackages: qemu-uefi-aarch64 - Remove ovmf-UefiCpuPkg-Disable-EFI-memory-attributes-protocol.patch (bsc#1240771) because GRUB2 already supports the EFI Memory Attributes Protocol. ==== patterns-kde ==== Version update (20260428 -> 20260830) Subpackages: patterns-kde-kde patterns-kde-kde_edutainment patterns-kde-kde_games patterns-kde-kde_ide patterns-kde-kde_imaging patterns-kde-kde_internet patterns-kde-kde_multimedia patterns-kde-kde_office patterns-kde-kde_pim patterns-kde-kde_plasma patterns-kde-kde_utilities patterns-kde-kde_utilities_opt patterns-kde-kde_yast - Drop Leap 15 recommends from spec file - Recommend libreoffice-qt6 when installing the KDE Office pattern rather than libreoffice-qt5 (boo#1277445) ==== pcre2 ==== Version update (10.47 -> 10.48) Subpackages: libpcre2-16-0 libpcre2-32-0 libpcre2-8-0 libpcre2-posix3 - Update to 10.48: * GHSA-2p8c-ff85-vh9x: If pcre2_jit_compile() is called with options for some match modes, and then pcre2_match() is used to perform a match for a different match mode, an out-of-bounds read can occur if the match is attempted against invalid UTF input. (boo#1277708) * GHSA-q8g2-wprr-34m9: If pcre2_convert() is called on untrusted input on platforms with 32-bit size_t, an out-of-bounds heap write can occur (boo#1277707) * GHSA-3r4p-g7gg-ppmf: Fixed an out-of-bounds write in DFA matching when using a heap limit; also fixed possible integer overflows which could cause under-allocation of the workspace. (boo#1277713) * GHSA-fmgr-6ggq-9859: Added bounds checks for several integer overflows while compiling patterns on 32-bit CPUs, which could cause under-allocation followed by out-of-bounds writes. (boo#1277709) * GHSA-9qww-pwc4-77qq: Applied lower buffer bound to prevent two out-of-bounds reads while scanning backwards through invalid UTF data with PCRE2_MATCH_INVALID_UTF. (boo#1277710) * Fix a JIT-specific matching bug affecting prefix scanning on patterns with repeats * Fix a JIT-specific matching bug in variable-length lookbehinds * Miscompiled Unicode character classes combining characters at or below U+00FF with characters at U+0100 and U+8000 or above * Incorrect JIT character advancement with PCRE2_MATCH_INVALID_UTF in UTF-8 and UTF-16 modes, which could skip adjacent characters * Update Unicode support to Unicode 17.0 * Fix a leak and later invalid free when calling the fast-path pcre2_jit_match() function with a match data object previously used with pcre2_match() and PCRE2_COPY_MATCHED_SUBJECT. (boo#1277711) * GHSA-q7rw-r7qq-2hx6: Fix exposure of two uninitialised bytes from malloc() via pcre2_serialize_encode() (boo#1277712) - Fix (all) rpmlint warnings ==== perl-Cpanel-JSON-XS ==== Version update (4.430.0 -> 4.440.0) - updated to 4.440.0 (4.44) see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes 4.44 2026-09-02 (rurban) - Fix canonical sort infinite loop (GH #252 amelchio): malformed UTF-8 keys (e.g. Latin-1 byte strings mixed with Unicode) made utf16_cmp treat the decoder's (STRLEN)-1 malformed sentinel as a length, wrapping the buffer pointer. Now checked as 0 or > remaining length. ==== perl-MIME-tools ==== Version update (5.517.0 -> 5.518.0) - updated to 5.518.0 (5.518) see /usr/share/doc/packages/perl-MIME-tools/ChangeLog 5.518 2026-08-26 Dianne Skoll * VERSION 5.518 RELEASED * Add tests for encoded "boundary=XXX" parameters and set the ambiguous-parse flag if any are found. Patch courtesy of Dominik Csapak MIME::tools chooses to decode encoded boundary parameters. MUA behaviors differ; Claws-Mail decodes them while Thunderbird does not. * Don't ignore invalid whitespace after "boundary=XXX" parameter. Patch courtesy of Dominik Csapak * Ignore comments between tokens. A header parameter can be written foo(comment)=bar and it's the same as foo=bar. Patch courtesy of Dominik Csapak ==== perl-Net-DNS ==== Version update (1.560.0 -> 1.570.0) - updated to 1.570.0 (1.57) see /usr/share/doc/packages/perl-Net-DNS/Changes Resync with IANA DNS parameters registry. EDNS: Add support for MQTYPE-QUERY option. Fix rt.cpan.org #181125 Unbounded recursion when re-encoding message with misplaced TSIG CVE-2026-81928 bsc#1278084 Fix rt.cpan.org #180773 UNIX resolver can fail in taint mode ==== perl-URI ==== Version update (5.350.0 -> 5.360.0) - updated to 5.360.0 (5.36) see /usr/share/doc/packages/perl-URI/Changes 5.36 2026-08-19 19:37:22Z - Apply Unicode NFC normalization in URI::_idna nameprep so IDNA host encoding matches other clients instead of emitting a non-standard, non-round-tripping A-label [CVE-2026-19953] (reported by Naseeb Dangi, @naseeb0) (GH#191) ==== php8 ==== Version update (8.5.9 -> 8.5.10) Subpackages: php8-ctype php8-dom php8-iconv php8-openssl php8-pdo php8-sqlite php8-tokenizer php8-xmlreader php8-xmlwriter - version update to 8.5.10 Core: Fixed bug GH-22782 (Const expr FCC crashes under preloading). Fixed bug GH-23088 (Stack overflow when comparing deeply nested arrays). Date: Fixed leak on double DatePeriod::__construct() call. DOM: Fixed bug GH-23116 (Stack overflow when normalizing a deeply nested DOMDocument). Fixed bug GH-23117 (Stack overflow when normalizing a deeply nested Dom\XMLDocument). Fixed bug GH-22825 (DOMElement::setAttribute() fails silently when the DTD declares a default value for the attribute). Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes with DOMNode::isEqualNode()). Exif: Fixed exif_read_data() allocating a HEIF meta box larger than the file it came from. Intl: Fixed IntlListFormatter::__construct() leaving stale global error state after successful calls. Opcache: Fixed GH-22693 (DT_TEXTREL in JIT-generated TLS access on x86_64). Fixed bug GH-22763 (JIT fails to clear ZREG_TYPE_ONLY after setting reg). Fixed bug GH-22857 (Function JIT emits wrong code for FETCH_OBJ_FUNC_ARG on a property hook getter, losing register-held variables). Fixed bug GH-22916 (Preserve parent regs in zend_jit_deoptimizer_start()). OpenSSL: Fix missing error check on invalid alpn protocols. MBString: Fixed bug GH-22779 (mb_strrpos() returns the wrong position for a negative offset in a non-UTF-8 encoding). Fixed bug GH-21036 (mb_ereg_search_getregs() crashes after mb_eregi() invalidates the regex cache). PCRE: Fixed bug GH-21134 (Crash with \C + UTF-8). Using \C in UTF-8 patterns is now forbidden. PDO_ODBC: Fixed bug GH-23016 (NULL values in long columns come back as garbage binary strings). PDO_PGSQL: Fixed several lazy fetch (PDO::ATTR_PREFETCH => 0) defects: an infinite loop when cleaning up a fetch left in a COPY, a use-after-free when a statement with emulated or disabled prepares is destroyed, a connection left busy for the next fetch, and rows delivered from a result another statement took over. Reflection: Fixed bug GH-22905 (Reflection exception messages truncate on null bytes). Fixed ReflectionProperty::isLazy() and skipLazyInitialization() using the parent slot when a child class hooks an inherited property. Fixed segfault in ReflectionMethod::createFromMethodName() on an uninstantiable subclass. Session: Fix corruption in mod_mm. Fixed bug GH-23043 (broken session id code can cause zend_mm_heap corrupted). SimpleXML: Fixed integer element offsets that cannot resolve aliasing an existing element. Fixed segfault when comparing uninitialized SimpleXMLElement instances. Sockets: Fixed socket_set_option() validation error messages for UDP_SEGMENT and SO_LINGER options. Fixed various memory related issues in ext/sockets. SQLite: Fix leak when trying to close db if blob stream is still open. Standard: Fixed bug GH-23111 (Stack overflow in array_walk_recursive() with deeply nested arrays). Fixed bug GH-23113 (Stack overflow in array_replace_recursive() with deeply nested arrays). Fixed bug GH-23115 (Stack overflow in compact() with deeply nested arrays). Streams: Fixed bug GH-15836 (Use-after-free when a user stream filter accesses $this->stream during the close flush). XSL: Fixed use-after-free when a DOMDocument subclass __clone() retains the stylesheet copy made by XSLTProcessor::importStylesheet(). - Removed php-fix-build-gcc16.patch (fixed upstream) ==== publicsuffix ==== Version update (20260819 -> 20260902) - Update to version 20260902 (public_suffix_list.dat snapshot taken from upstream commit of 2026-09-02): * Add builtwithrocket.new and rocketpreview.app to PRIVATE section (#2948) * Add canva-code.cn (#2980) * Add tmp.now to PRIVATE section (Vercel) (#3193) * Add eth.limo and eth.link gateways (#3199) * Remove demo.datacenter.fi and paas.datacenter.fi (#3197) * Remove XnBay Technology entries (#3176) ==== python-dnspython ==== - Skip tests failing with idna 1.19 ==== python-idna ==== Version update (3.18 -> 3.19) - update to 3.19: * Restore the `std3_rules` option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that `uts46_remap()` defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again. * Performance improvements to UTS #46 mapping, particularly for ASCII-only domains. * Test on free-threaded CPython with the GIL disabled and document thread safety. * Expose the Unicode version of the generated tables as `idna.unicode_version`, and show it in `idna --version`. * Add `code`, `text`, `codepoint` and `position` attributes to `IDNAError` so that the failed rule and the offending character can be identified without parsing the exception message. * The deprecated `transitional` argument to `encode()` and `uts46_remap()` is now completely ignored, and gives a deprecation warning for the latter. * Reject A-labels that are not the canonical Punycode encoding of their U-label. * Fix CONTEXTJ violations raising `IDNAError` instead of `InvalidCodepointContext`. * Consistently raise `IDNAError` for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec. * Add property-based tests, extended fuzzing targets, coverage * measurement, and CI checks that the data tables match the generator output. * Various code quality and tooling improvements. ==== python-numpy ==== Version update (2.5.2 -> 2.5.3) - update to 2.5.3: * Casting a fixed-width byte string array (``np.bytes_``) to ``StringDType`` now raises ``TypeError`` when the bytes are not valid UTF-8. Previously the invalid bytes were stored as-is and later caused undefined behavior in string operations. * ``MaskedArray._fill_value`` would become stale when ufuncs that change dtype left the result holding a fill_value typed for the old dtype. The mismatch was silent until something later called ``_check_fill_value``, such as ``.view()``, and then a ``TypeError`` would be raised. Now, when the copied fill_value is no longer valid for the new dtype, fall back to the default fill_value for that dtype instead of propagating the stale value. This may raise a ``ComplexWarning`` if the fill_value is complex and the new dtype is real. ==== qca-qt6 ==== Version update (2.3.10 -> 2.3.12) Subpackages: libqca-qt6-2 qca-qt6-plugins - Update to version 2.3.12: * Update rootcerts.pem * Increase version number * CI: gitlab-templates/linux.yml is gone * qca-ossl: do not dereference a DH key that failed to generate * qca-ossl: load the default OpenSSL provider explicitly (kde#482819) * CI: Add build with openssl4 * Update rootcerts.pem * CI: A bit of janitoring * Increase version number * Define QCA_FULL_INCLUDE_INSTALL_DIR after USE_RELATIVE_PATHS has been processed * Compile with openssl4 * CI: Remove fedora 34 build * Remove FreeBSD Qt5 build ==== qemu ==== Version update (11.0.3 -> 11.1.1) Subpackages: qemu-arm qemu-audio-spice qemu-block-curl qemu-block-nfs qemu-block-rbd qemu-chardev-spice qemu-guest-agent qemu-hw-display-qxl qemu-hw-display-virtio-gpu qemu-hw-display-virtio-gpu-pci qemu-hw-display-virtio-vga qemu-hw-usb-host qemu-hw-usb-redirect qemu-hw-usb-smartcard qemu-img qemu-ksm qemu-pr-helper qemu-tools qemu-ui-curses qemu-ui-gtk qemu-ui-opengl qemu-ui-spice-app qemu-ui-spice-core qemu-vgabios - Bugfixes (bsc#1277435, bsc#1263864): * file-posix: Tolerate unaligned hole at middle (bsc#1277435) * target/ppc/kvm: Use host compatibility mode for nested guests (bsc#1263864) * target/ppc/kvm: Add support for querying host compatibility mode (bsc#1263864) * linux-headers: Update to include KVM_CAP_PPC_COMPAT_CAPS (bsc#1263864) - Improve riscv64 handling: * [openSUSE][RPM] build all firmware on riscv64 and fix user tests * [openSUSE][RPM] spec: stub out all iotests when running under user emulation (e.g., for riscv64) - Fix broken build on aarch64: * [openSUSE][RPM] spec: disable GCS linker validation on aarch64 - Update to latest stable release (11.1.1) Full backport list here: https://lore.kernel.org/qemu-devel/20260827155607.639070-1-mjt@tls.msk.ru/ A selection of them is reported here below: target/riscv/tcg: sret in virtual user mode raises virtual instruction exception target/riscv: Allow UXL to be 3 in mstatus on rv128 target/riscv: Restore register dump zero padding tests/qtest: remove trace output from k230 watchdog test target/riscv: enforce even register constraints for Zdinx fcvt pairs target/riscv: reject FMV.X.W/FMV.W.X under Zfinx target/riscv: honor zicbo* envcfg gating in linux-user mode disas/riscv: Fix typo in th.lbib format disas/riscv: Fix isa decoding of rev8 disas/riscv: Fix rv32 encoding of zext.h target/riscv: allow menvcfg/henvcfg LPE and SSE bits on RV32 hw/riscv/riscv-iommu: preserve requested perm in spa_fetch() hw/riscv/riscv-iommu: fix U-bit check to apply only to leaf S/VS-stage PTEs disas/riscv: Decode unsigned vector immediates as unsigned disas/riscv: Use signed type for vector immediates disas/riscv: Fix 6-bit immediate extraction disas/riscv: Fix th.srri decoding tests/qtest: Add seed CSR zero extension test target/riscv: Fix seed CSR sign extension target/riscv: do not count ECALL in minstret target/riscv: Fix memory leak in riscv_trigger_unrealize() target/riscv: use SXL instead of MXL for read_sstatus target/riscv: Fix PC sync in trans_sspopchk for CFI exception handling whpx: i386: inject back db whpx: i386: work around Hyper-V FP state oddities whpx: i386: synchronise PAT too whpx: i386: enable fast hypercall output hw/i386: fw_cfg: do not set VMX feature control on WHPX whpx: i386: fix xsaves enablement in legacy probing path hw/watchdog: Add lower bound check for watchdogNumber tests/tcg/aarch64: Add regression test for whilewr/whilerw target/arm: Fix SVE2 WHILEWR/WHILERW zero diff boundary case tcg: Export tcg_gen_ussub_i{32,64,tl} hw/intc/arm_gicv3: Have GIC kconfig select GICv3 for HVF and WHPX hw/intc: Fix arm kvm gicv3 selection tcg: Defer tb_flush when initial thread region alloc fails tcg: Return success from tcg_region_alloc tcg: Return success from tcg_region_alloc__locked target/loongarch: check FPE before reading fcc in bceqz/bcnez meson: make linker warnings non-fatal on Linux serial: clear transmit retry callback on unrealize ... - Revisit the fix for bsc#1232712: * hw/display/xenfb: always register vfb and allocate console early (bsc#1232712) - Switch to ipxe-qemu: * [openSUSE][RPM] spec: stop building edk2-basetools and ipxe - Upgrade to version 11.1.0 The full list of changes are available at: https://wiki.qemu.org/ChangeLog/11.1 Highlights include: * Universal Flash Storage (UFS) emulation support for Write Booster (device-level caching) and Host-Initiated Defragmentation (HID) based on UFS 4.1 specification * vhost-host-user support for offloading real-time clock handling from the hypervisor when using virtio-rtc * GUI: improvements to virtual console handling/specifying of different character encoding and GTK/VNC improvements as well * ARM: support for new architectural CPU features (too many to list here, see full changelog) * ARM: support for new imx8mp-evk machine type (based on i.MX 8MM Evaluation kit) * ARM: 'virt' board support for specifying cache topology, 'hvf' accelerator now supports nested virtualization and vGIC * HPPA: updated to SeaBIOS-hppa v25 firmware, TLB insert fixes for HP-UX 9 * PowerPC: MPIPL support for PowerNV to preserve memory after an unexpected reset, as well as support for emulating a nest MMU * RISC-V: ISA exstention support for big-endian, Zbr/xbr0p93, Zvfbfa, fractional LMUL on vector SHA instructions, KVM support for Zicbop and BFloat16 extensions, and more * RISC-V: new board support for K230, support for Tenstorrent mvendorid, and other misc. fixes/features * s390x: KVM support for ASTFLE facility 2 (for nested) * and lots more... ==== qt6-tools ==== Subpackages: libQt6Designer6 libQt6UiTools6 qt6-tools-qdbus - Add 0003-CMake-Add-LLVM-23-to-supported-QDoc-Clang-versions.patch. ==== raspberrypi-firmware ==== - Prevent -52 error message during wifi scan (bsc#1215134). ==== re2c ==== Version update (4.5.1 -> 4.6) - Update to version 4.6 * Added support for Zig labeled continue optimization. (#580). * Updated C/C++ examples to use re2c features available in version 4.0 or higher. ==== rpcbind ==== - Fix stack-based buffer overflow in rpcinfo's rpcbdump() short-mode version-list formatting (bsc#1272340, CVE-2026-16461) * add 0001-rpcinfo-fix-stack-buffer-overflow-in-rpcbdump-short-.patch ==== rsyslog ==== Version update (8.2606.0 -> 8.2608.0) - upgrade to rsyslog 8.2608.0 - dropped patches: * 0001-imptcp-guard-regex-framing-match-at-line-start.patch * 2026-08-18: imbeats: rearm listener after failed TLS accept * 2026-08-18: msg: serialize turbo snapshot duplication * 2026-08-18: omfile: harden dynafile default containment * 2026-08-18: fixup! omfwd: support PKCS#11 URIs with ossl TLS * 2026-07-02: omfwd: support PKCS#11 URIs with ossl TLS * 2026-07-21: mmkubernetes: reload SA token proactively and on HTTP 401 * 2026-08-17: devtools: remove Cubic from local validation * 2026-08-14: mmnormalize: share turbo $! snapshot across MsgDup by refcount * 2026-08-11: tcpsrv: synchronize session table slots * 2026-08-11: imrelp: preserve errno across stop signal * 2026-08-12: examples.rst: Missing space in template * 2026-08-10: mmnormalize: merge debug metadata * 2026-08-08: normalizers: complete debug test gating * 2026-08-08: normalizers: complete debug integration * 2026-08-07: mmnormalize, pmnormalize: add liblognorm debugging * 2026-08-07: msg: ignore null values in msgSetPropViaJSON() instead of crashing * 2026-08-07: runtime: make error-message flag atomic * 2026-07-24: fuzz: exercise RFC 3164 and RFC 5424 parsers * 2026-08-05: build: unify indentation in AC_CONFIG_FILES list * 2026-07-25: imfile: fix delay.message microsecond conversion * 2026-07-24: diskqueue: reject symlinked persisted segments * 2026-06-23: omfile: control symlink following * 2026-07-25: mmnormalize: make HUP reload worker-safe * 2026-07-24: docs(agents): add Cursor Cloud environment setup notes * 2026-07-22: imbeats: harden Lumberjack input resource handling * 2026-07-23: stringbuf: harden empty string replacement * 2026-07-20: imptcp: guard regex framing match at line start (bsc#1271910) * 2026-07-21: rainerscript: free cnfstmtNewAct nvlst once, at the done: label * 2026-07-21: queue: preserve DA child work during shutdown * 2026-07-21: imtcp: release completed zlib decoder state * 2026-07-09: doc: clarify JSON array rendering * 2026-07-21: Potential fixes for 5 code quality findings (#7397) * 2026-07-20: ratelimit: optimize port-based per-source keys * 2026-07-20: imtcp: make zstd window budget configurable * 2026-07-19: imtcp: use snake case for zstd window tracking * 2026-07-17: imtcp: bound aggregate zstd decoder window memory * 2026-07-20: statsobj: guard Prometheus escape writes * 2026-07-18: config: do not instantiate actions disabled via config.enabled="off" * 2026-07-15: queue: document DA engine internals * 2026-07-14: msg: enforce source-property helper contract * 2026-07-10: ratelimit: remove per-source key policy hot lock * 2026-07-08: ratelimit: speed source-key shortcuts * 2026-07-15: queue: clarify DA transfer worker role * 2026-07-18: compat_queue: add missing STAILQ_FOREACH/STAILQ_NEXT fallback * 2026-07-18: rainerscript: warn on constant AND/OR operand at parse time * 2026-07-18: configure: include in the STAILQ detection test * 2026-07-17: mmnormalize: share Turbo CEE root path check * 2026-07-17: mmnormalize: fall back after Turbo materialization failure * 2026-07-17: mmnormalize: preserve turbo results across message boundaries * 2026-07-17: benchmarks: harden comparison and helper inputs * 2026-07-16: segdisk: optimize CRC accounting and add benchmarks * 2026-07-15: imjournal: stop invalidation reopen busy-loop * 2026-07-14: queue: harden segmented DA lifecycle invariants * 2026-07-14: queue: harden DA portability and startup cleanup * 2026-07-14: queue: address segmented DA review findings * 2026-07-14: queue: stabilize DA shutdown and reload state * 2026-07-14: queue: clarify lazy marker and legacy state paths * 2026-07-14: queue: gate idle cleanup on durable intent * 2026-07-14: queue: document empty DA marker replacement * 2026-07-14: queue: preserve classic state on transient load errors * 2026-07-14: queue: make idle cleanup restoration crash safe * 2026-07-14: queue: fail classic DA startup on real errors * 2026-07-14: queue: clarify dirty DA configuration handling * 2026-07-14: queue: separate DA idle and worker timeouts * 2026-07-14: queue: document DA auto-upgrade boundary * 2026-07-14: queue: publish fresh DA markers on first spill * 2026-07-14: queue: constrain classic DA startup fallback * 2026-07-14: queue: clarify disabled DA idle timeout * 2026-07-14: queue: preserve classic DA startup fallback * 2026-07-14: doc: describe segmented disk-assisted queues * 2026-07-14: queue: add segmented disk-assisted engine * 2026-07-14: queue: retain adopted recovery frontier * 2026-07-14: queue: address segmented disk review findings * 2026-07-13: queue: wake workers before capacity waits * 2026-07-13: queue: make segmented deletion resumable * 2026-07-13: queue: initialize missing state in empty spool dirs * 2026-07-13: queue: reject invalid segmented codec field types * 2026-07-13: queue: avoid sanitized generation wrap * 2026-07-13: queue: expose segmented disk durability test hooks * 2026-07-13: queue: make segmented disk recovery lazy * 2026-07-09: queue: rework experimental segmented disk backend * 2026-07-08: imjournal: warn when failing to get the MESSAGE field * 2026-07-08: omawslogshlc: add CloudWatch Logs HLC output module * 2026-07-08: core: add systemd READY delay opt-in * 2026-06-02: core/imfile: synchronize sd_notify READY=1 with module startup * 2026-07-07: ratelimit: shard per-source state * 2026-07-06: docs: validate marked config samples * 2026-07-07: ratelimit: shard named config registry * 2026-07-06: runtime: harden ratelimit per-source reload * 2026-07-06: queue: align legacy action batch default * 2026-07-06: runtime: relax worker-count log reads * 2026-07-06: core: relax selected atomic flag reads * 2026-07-06: omkafka: relax poll stop flag atomics * 2026-07-06: doc: add documentation for imfile delay.message parameter * 2026-06-04: core: add generic output rate limiting * 2026-07-05: omelasticsearch: apply TLS options during detection ... changelog too long, skipping 63 lines ... * 2026-06-08: diag.sh: fix content-pattern-check and assert-first-column-sum-greater-than ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Fix "mount.swap" activation on UUID and add "resolve_canonical" arg - Added: * fix-mount.swap-activation-when-using-uuid-and-introd.patch - Fix test_tcp for pytest >=8 - Added: * fix-test_tcp-for-pytest-8-779.patch - Fix file handlers leaking on using SyncWrapper (bsc#1272939) - Added: * fix-file-handlers-leaking-on-using-syncwrapper-bsc-1.patch ==== sdbootutil ==== Version update (1+git20260825.c7a5a97 -> 1+git20260903.f91f636) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper - Update to version 1+git20260903.f91f636: * Include FIDO2 unlocked devices for ordering (bsc#1234010) * Test in parallel for speed up * Add --repair parameter to cleanup * Fix shellcheck complain * Report entries with missing files * Avoid duplicate entries in non-snapper systems * Add initial tests for sdbootutil * Report the error if bootctl clean fails - Update to version 1+git20260901.41540d5: * No warn if a component is not in the event log * Add status command * Select the new sdbootutil if available * Skip blank lines in measure-pcr-generator.sh * Do not change crypttab for unrelated entries * Report the bad PCR when update-prediction fail * Do not write the recovery PIN in the journal * Improves non snapshot system support * Update help message for --measure-pcr * Report when PCR 7 is dropped because shim update * Add --strict parameter for --pcr policy * Report dropped PCRs via a warn * Adjust the limits for PolicyOR issues * Avoid update predictions if the service is up * Keep the exit status of sdbootutil call - Update to version 1+git20260827.786f9a8: * Do not accept empty passwords * jeos-firstboot-enroll: report errors also in the journal * Restore old crypttab via the exit trap * Update CLAUDE data * Detect half created openssl keys * check_enrolled report when something was written in the LUKS2 header * Improve a bit the disk-encryption-tool keyslot detection * Avoid leak of env var secrets * Wipe the d-e-t key in the enroll service and jeos module * Remove the correct keyslot left by d-e-t * Differentiate tpm2 and tpm2+pin for unattended unlock * Use is_same_device in detect_tracked_device and drop greps * Refactor check to avoid shellcheck complain * Parse the entry file in a sigle place * Validate the entry with the new kernel name * Refactor enrollment interface and deprecate the old one * New kernels will have different hash * Warn If no crypttab entry found * Extend is_same_device * jeos-firstboot-enroll: validate the passwords * sdbootutil-enroll: report when no encryption method is provided * Write recovery pin after enrollment in jeos module * Write recovery pin after enrollment * Improve error detection in sdbootutil-enroll * Increase keyctl timeout * Merge require_unlock and set_unlock_method * Be sure that the terminal check works with snapper * Renerate initrd when new measure-pcr keys are created * Separate ask-* parameters * Fix reading credential and keyctl password * Get the device password for each enrolling mechanism * Drop elements from crypttab if the enrollment fails * Validate the enrollment for each method * Add warning when enrolling FIDO2 token ==== sdl2-compat ==== Version update (2.32.70 -> 2.32.72) - Update to release 2.32.72 * Fixed a crash during the menu transition in Super Mario War. * Fixed menu rendering in The Ur-Quan Masters. * Fixed loading screen flickering in Payday 2. * Fixed the pointer position in Augustus when screen scaling is enabled. * Fixed an out of bounds exception in the OBS plugin "input-overlay" when using the new Steam Controller. ==== sg3_utils ==== Version update (1.48+35.c49e7c08 -> 1.48+36.936c7ae) Subpackages: libsgutils2-1_48-2 - Update to version 1.48+36.936c7ae: * sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) ==== strace ==== - Remove unused sysvinit-tools and time - Don't require mpers support ==== suitesparse ==== Version update (7.13.0 -> 7.14.0) Subpackages: libamd3 libcamd3 libccolamd3 libcholmod5 libcolamd3 libsuitesparseconfig7 libumfpack6 - Update to 7.14.0 * GraphBLAS 10.5.0: faster resize, post-iso check revised, and a bug fix ==== suse-module-tools ==== Version update (16.1.6 -> 16.1.7) Subpackages: suse-module-tools-scriptlets - Update to version 16.1.7: * If no initrd is found rebuild it (gh#openSUSE/suse-module-tools#133) ==== tcl ==== - Split the test suite into a multibuild "test" flavour: the main build no longer runs it (%check measured 326s of a 471s build on aarch64) and no longer pulls in the timezone build dependency; the test flavour builds only a src.rpm - Do not build the test flavour in the Factory rings and staging, which set %_with_ringdisabled - Modernise the spec: drop the obsolete BuildRoot, Group, defattr and PreReq tags, brace all macros, use %autosetup and %make_build - Point URL, Source0 and the description at tcl-lang.org; the tcl.tk domain no longer resolves at all - Run the full test suite: drop the 31-entry known-failures whitelist, every id of which passes again (47159 tests, 43939 passed, 3220 skipped, 0 failed on aarch64); only the riscv64 and qemu-only entries are kept - Fail the build on a crashed or aborted test run, which previously passed silently: the pipeline reported tee's exit status, and tests/all.tcl returns 0 even on failures unless ERROR_ON_FAILURES is set - Drop the dead s390 test guard; only s390x still exists - Drop the ppc64 tcl-64bit and tcl-devel-64bit Obsoletes, added in 2009 for the SLE10-era biarch packages - Drop the %post scriptlet removing a /usr/lib/tcl8.6 compat symlink from the pre-2005 layout; no tcl 8.6 package has ever created it ==== tree-sitter ==== - Revendored to the latest versions of dependencies (including bytes-1.12.1 to fix bsc#1274132, CVE-2026-25541). ==== wireless-regdb ==== Version update (20260530 -> 20260903) - Update to version 20260903: * wireless-regdb: update regulatory database based on preceding changes * wireless-regdb: allow 320MHz channel width for Hong Kong (HK) * wireless-regdb: Update 2.4 and 5 GHz rules for South Africa (ZA) * wireless-regdb: Remove DFS flag from 60 GHz band for Togo (TG) ==== wireplumber ==== Version update (0.5.15 -> 0.5.17) Subpackages: libwireplumber-0_5-0 wireplumber-bash-completion - Update to version 0.5.17: * Highlights: - This release fixes a significant regression introduced in version 0.5.16. Users are strongly encouraged to upgrade to this release and avoid using 0.5.16. * Fixes: - Fixed factory-created device, node and link objects to stop sharing ownership with their registry global, fixing a regression from the WpClientContext introduced in 0.5.16 that broke proper object destruction in the monitor scripts. - Improved default-nodes to also rank on the object.serial of a node's device and on the node's own object.serial, so that route priorities are only compared between nodes of the same card, and the election no longer changes for no apparent reason when all other keys are equal. - Fixed m-lua-scripting to include the offending Lua type name in POD build errors - Update to version 0.5.16: * Additions & Enhancements: - Added WpClientContext, a second PipeWire connection running on its own thread that hosts WirePlumber's in-process media objects (loopback and filter-chain modules, LocalNode(), SpaDevice()), so that slow Lua event hooks on the main thread no longer stall their control path; the export core is retired in favor of this new client context - Added new WpDynamicRules class for matching rules with conditions, and updated filter-graph.lua to use it, allowing filter-graphs to be loaded and unloaded dynamically depending on whether other objects exist or not - Added wp_impl_module_unload() and LocalModule:unload(), giving scripts control to unload implemented modules at any time - Added a volume-set action to module-mpris to allow adjusting the volume of a remote MPRIS2 player from Lua - Added --yes flag to wpctl reset to skip the confirmation prompt - Added device.form-factor ALSA node property for use in ALSA rules, and made HDMI node descriptions include the name of the connected display when available - Refactored the Bluetooth monitor to use event hooks for handling devices and nodes, matching the design already used by the v4l2 and libcamera monitors - Overhauled the documentation: filled in every stub and missing Lua API and C API page, added a getting started guide, new wireplumber(1) and wpexec(1) man pages, and removed stale pages describing features renamed or removed in the 0.4 to 0.5 transition * Fixes: - Fixed monitors to always activate all device and node features, and made monitors wait for successful device activation before storing the devices and nodes as a managed objects - Fixed find-preferred-profile to skip a configured preferred profile that is not available, instead of leaving no profile selected - Fixed permission-manager to not include destroyed globals when rebuilding the permissions array on objects-changed, fixing some pipewire warnings in the log - Fixed a memory leak in WpSpaDevice by only collecting params from our own requests - Fixed filter-graph to correctly apply graphs defined for the same node across multiple configuration files - Fixed several nil-related crashes and correctness issues in Lua scripts - Improved apply-access to directly attach an already-active permission manager to the client instead of wastefully re-running activation on it - Improved state-stream change detection to avoid spurious state writes from volume rounding and from unset or empty properties - Fixed default-nodes to ignore smart filters when selecting the best default node - Removed the node.filter.forward-format setting and its script, which only worked with 0.4 and never really worked with 0.5 ==== xdp-tools ==== - Use pkgconfig, %autosetup and %ldconfig_scriptlets ==== xwaylandvideobridge ==== Version update (0.5.0 -> 0.5.2) - Update to version 0.5.2: * CI: Flatpak: Formatting * CI: Flatpak: Disable tests for KDE modules * CI: Flatpak: Sort finish arguments * Fix redirection counting never reaching zero * Don't hold a fullscreen screen-spanning window while idle * Clang format. * Start a session on the redirect itself. * Fix Messages.sh. * Fix deprecation warning. - Changes in 0.5.1: * Fix the Icon in the Flatpak * CI - Flatpak - Update Runtime to 6.11 * Make the bridge window frameless so it can't eat clicks - Add BuildRequires cmake(KF6DBusAddons) >= %{kf6_version} ==== yast2-bootloader ==== Version update (5.0.33 -> 5.0.42) - revert "do not suggest grub2-bls if there are other systems" as it breaks upgrades scenario (bsc#1258861) - 5.0.42 - remove remaining occurrences of trusted boot to fix crash when writting sysconfig for systemd-boot and grub2-bls (bsc#1274932) - 5.0.41 - propose secure boot only for ECKD DASD (bsc#1270367) - 5.0.40 - Reducing error level for not available shim package while using systemd-boot (bsc#1265870). - 5.0.39 - jsc#PED-7975 and bsc#1262249 - dropped trusted boot - 5.0.38 AutoYaST/systemd-boot export/import: Using string for secure_boot setting in export file (bsc#1260385). - 5.0.37 - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.36 - Propose always secure boot with zipl on DASD (jsc#/PED-13734) - Do not suggest grub2-bls if there is another e.g. windows system installed (bsc#1257528, bsc#1257510). - 5.0.34 ==== zvbi ==== Version update (0.2.44 -> 0.2.45) - update to 0.2.45: * Update Swedish translations. * Update Cyrillic characters for Bulgarian/Russian/Ukranian. * Fix missing subtitles, revert C4_ERASE_PAGE patch from libzvbi 0.2.42. * Apply security updates. ==== zypper ==== Version update (1.14.98 -> 1.14.101) Subpackages: zypper-log zypper-needs-restarting - Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. - version 1.14.101 - Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) - version 1.14.100 - info: check for missing positional args before systemSetup (bsc#1274091) - Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. - BuildRequires: libzypp-devel >= 17.38.0. Code uses some of the new libzypp log and string tools. - version 1.14.99