Packages changed: PackageKit (1.3.6 -> 1.4.0) coreutils (9.11 -> 9.12) coreutils-systemd (9.11 -> 9.12) cppcheck (2.21.0 -> 2.22.0) cups-filters2 emacs-compat (31.0.0.2 -> 31.1.0.0) feh (3.11.1 -> 3.13.1) flatpak (1.18.2 -> 1.18.3) freerdp (3.31.0 -> 3.31.1) gimp gucharmap (17.0.2 -> 18.0.0) gzip (1.14 -> 1.15) harfbuzz (14.4.0 -> 14.5.0) hplip (3.26.4 -> 3.26.6) kernel-source (7.2.6 -> 7.2.7) libgsf (1.14.58 -> 1.14.59) libheif (1.23.4 -> 1.23.5) libinput (1.31.3 -> 1.32) libreoffice librsvg (2.62.3 -> 2.62.4) libsolv (0.7.39 -> 0.7.40) libsrtp2 (2.8.0 -> 2.8.1) libssh libstorage-ng (4.5.353 -> 4.5.354) libupnp (22.1.0 -> 22.1.2) libvirt libzio (1.15 -> 1.17) libzypp (17.38.15 -> 17.38.16) lightdm (1.32.0 -> 1.33.1) lightdm-gtk-greeter (2.0.8 -> 2.0.9) lpsolve (5.5.2.0 -> 5.5.2.14) lzlib man meson (1.12.0 -> 1.12.1) mozjs140 ncurses (6.6.20260912 -> 6.6.20260919) nvidia-open-driver-G07-signed (595.99.02_k7.2.6_1 -> 595.99.02_k7.2.7_1) nvidia-open-driver-G07-signed-cuda (615.71.09_k7.2.6_1 -> 615.71.09_k7.2.7_1) openSUSE-release (20260921 -> 20260924) p11-kit (0.26.2 -> 0.26.5) publicsuffix (20260902 -> 20260921) python-pip python-tornado6 (6.5.8 -> 6.5.10) rsync (3.4.3 -> 3.5.1) seahorse (47.0.1+6 -> 47.0.1+113) selinux-policy (20260914 -> 20260923) syslogd sysvinit (3.14 -> 3.18) tesseract-ocr thin-provisioning-tools (1.3.3 -> 1.3.4) util-linux (2.42.2 -> 2.42.3) util-linux-systemd (2.42.2 -> 2.42.3) wsdd xscreensaver (6.15 -> 6.16) xwaylandvideobridge (0.5.2 -> 0.5.3) yast2-trans (84.87.20260906.c2bec94659 -> 84.87.20260916.f55042cfcf) === Details === ==== PackageKit ==== Version update (1.3.6 -> 1.4.0) Subpackages: PackageKit-backend-zypp PackageKit-gstreamer-plugin PackageKit-gtk3-module libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Update to version 1.4.0: + Backends: - zypp: respect libzypp package locks - Drop unmaintained DNF backend - Various changes/fixes for alpm, dnf5 and eopkg + Bugfixes: - pkgcli: Skip blocked updates in full upgrade too - python: Use a raw string for regex - lib: Tighten the pk-client-helper mainloop spin fix - lib: Prevent mainloop spin in pk-debconf-helper by dispatching on POLLHUP and POLLERR - lib: Close gaps in the public header include guards - Pass daemon config on the command line, so test binaries are identical to production - Refactor, so daemon run in test-mode never touches the host's state - offline-update: Never let a Trigger call disarm or replace an armed trigger - Drop dead error macros for nonexistent types - spawn: Reject stdin-protocol delimiters in caller-supplied strings - Validate a distro-ID in UpgradeSystem for invalid characters + Miscellaneous: - Move the Python backend module to the top level - Flatten the client library into lib/ - Install headers into $includedir/packagekit - Autoformat the source code in (almost) its original style - Add security policy - Drop PackageKit-CVE-2026-19816.patch, PackageKit-zypp-respect-libzypp-package-locks.patch and PackageKit-alias-dnf-to-dnf5.patch: fixed upstream - Rebase PackageKit-remove-polkit-rules.patch - No longer pass -Dlocal_checkout=false to meson: option is no longer supported. - Add PackageKit-CVE-2026-19816.patch: dnf5: Never execute repo-remove for simulated transactions (bsc#1280033, CVE-2026-19816). ==== coreutils ==== Version update (9.11 -> 9.12) - coreutils-9.12-env-quote-fix.patch: Add post-release upstream patch to revert env(1) behavior, i.e., only quote when outputting to terminals. - coreutils-i18n.patch: Sync with Fedora. * src/linebuffer.h: Remove unnecessary hunk. Avoid false-positives in French locale: * tests/Coreutils.pm: Adjust test name length for "-mb" suffix. * tests/pr/pr-tests.pl: Skip "neg-page" test. * tests/sort/sort.pl: Skip "invalid-parallel" test. - Update to 9.12: Bug fixes * 'chcon', 'chgrp', 'chmod', 'chown', 'du', 'ls' which traverse hierarchies with - R, no longer fail merely because files may be being removed in parallel. [This bug was present in "the beginning".] * 'comm - -' no longer closes standard input twice. Previously it would mistakenly exit with a nonzero status. [This bug was present in "the beginning".] * 'cp', 'install', and 'mv' now fall back to a standard copy if a --reflink=auto clone fails due to EDQUOT, ENOMEM, or ENOSPC. E.g., with XFS, a clone can exhaust metadata space in an allocation group, while a standard copy works. [bug introduced in coreutils-9.2] * 'cut -d' with multiple multi-byte delimiter options specified will correctly match the last delimiter specified. [bug introduced with multi-byte support in coreutils-9.11] * 'date -d '1-2-3' "+%_D"' no longer propagates flags like _ and - to the year component of the %D date specifier, keeping consistent component formatting. [bug introduced in coreutils-8.31] * 'du --max-depth=N' now exits with a nonzero exit status and an error message if N is negative. Previously it behaved as if N were zero. [bug introduced in coreutils-9.4] * 'factor' avoids a buffer over-read (CWE-126) for certain values. [bug introduced in coreutils-9.8] * 'head' and 'tail' now quote names in file headers when needed. [This bug was present in "the beginning".] * 'ls --color' no longer reads freed memory when LS_COLORS sets "ln=target" and later becomes unparsable, e.g., LS_COLORS='ln=target:x'. [This bug was present in "the beginning".] * 'mv' now warns when copying extended attributes fails with ENOTSUP, e.g., when moving files to a file system that does not support them. [bug introduced in coreutils-7.3] * 'numfmt', 'printf', and 'seq' on Solaris, no longer output an extraneous e+00 when using a large precision like "%.5119f". [This bug was present in "the beginning".] * 'pinky -l' no longer no longer prints output in the incorrect order when standard output is fully buffered, e.g., when redirected to a file. [bug introduced in coreutils-9.10] * 'pr' now exits gracefully upon exceeding internal accounting limits, like when processing large tab stops. [This bug was present in "the beginning".] * 'ptx -G' no longer loops forever when the output width is smaller than twice the gap size, as with 'ptx -G -w4', or when a long reference leaves that little room, as with 'ptx -G -r'. [This bug was present in "the beginning".] * 'ptx -W' no longer loops forever with a word regular expression that can match the empty string, like: echo ab | ptx -W 'a*'. [This bug was present in "the beginning".] * 'shred' no longer blocks when opening a FIFO that has no readers. [This bug was present in "the beginning".] * 'stty' no longer fails when the system uses speed encodings that are variations of the requested speed. [bug introduced in coreutils-9.8] * 'tee' no longer loops infinitely after writing all output if a write call sets errno to EAGAIN. [bug introduced in coreutils-9.11] * 'tee' no longer treats short writes as errors. [bug introduced in coreutils-9.11] * 'test' no longer treats '-a' and '-o' as operators when given as strings to a binary operator. E.g., 'test -a -a -a' exits successfully instead of exiting with an error. [This bug was present in "the beginning".] * 'truncate --reference=R' no longer hangs when R is a FIFO with no readers. [bug introduced in coreutils-8.17] * 'unexpand -t' no longer overflows a heap buffer, for tab values > SIZE_MAX/16, or with multi-byte blank characters longer than the tab value. [bugs introduced in coreutils-9.11] * 'uniq -w' no longer overruns the read buffer in multibyte locales. [bug introduced in coreutils-9.5] * 'wc' no longer reads past the end of a lookup table in legacy multibyte locales like SHIFT-JIS where a single byte can decode to a wide character. [bug introduced in coreutils-9.5] * Messages from Gnulib are no longer mistranslated in non-English locales. [bug introduced in coreutils-9.6] New Features * 'env' now supports --env0-from=FILE to read NUL-delimited environment entries from a file. With -i, entries are preserved exactly, allowing full round-tripping of environments containing duplicate or nonstandard entries. * 'stat' and 'tail' now know about the "failfs" and "nullfs" file system types. stat -f -c%T now reports the file system type, and tail -f uses inotify for these file systems. * uname adds the -A,--all-labeled option to label all output, one item per line. Changes in behavior * 'env' and 'printenv' now quote printed environment variables honoring the QUOTING_STYLE environment variable, defaulting to shell-escape style. This avoids printing arbitrary data to the terminal and allows the output to be sourced by a POSIX shell. * 'ls' -w,--width no longer includes '\n' in the width of a line. I.e., the width or $COLUMNS is interpreted to be an _inclusive_ maximum. * 'stat' now uses shell quoting when required, to more robustly escape file names. Previously it only quoted file names with the %N format. ... changelog too long, skipping 47 lines ... - Refresh all other patches. ==== coreutils-systemd ==== Version update (9.11 -> 9.12) - coreutils-9.12-env-quote-fix.patch: Add post-release upstream patch to revert env(1) behavior, i.e., only quote when outputting to terminals. - coreutils-i18n.patch: Sync with Fedora. * src/linebuffer.h: Remove unnecessary hunk. Avoid false-positives in French locale: * tests/Coreutils.pm: Adjust test name length for "-mb" suffix. * tests/pr/pr-tests.pl: Skip "neg-page" test. * tests/sort/sort.pl: Skip "invalid-parallel" test. - Update to 9.12: Bug fixes * 'chcon', 'chgrp', 'chmod', 'chown', 'du', 'ls' which traverse hierarchies with - R, no longer fail merely because files may be being removed in parallel. [This bug was present in "the beginning".] * 'comm - -' no longer closes standard input twice. Previously it would mistakenly exit with a nonzero status. [This bug was present in "the beginning".] * 'cp', 'install', and 'mv' now fall back to a standard copy if a --reflink=auto clone fails due to EDQUOT, ENOMEM, or ENOSPC. E.g., with XFS, a clone can exhaust metadata space in an allocation group, while a standard copy works. [bug introduced in coreutils-9.2] * 'cut -d' with multiple multi-byte delimiter options specified will correctly match the last delimiter specified. [bug introduced with multi-byte support in coreutils-9.11] * 'date -d '1-2-3' "+%_D"' no longer propagates flags like _ and - to the year component of the %D date specifier, keeping consistent component formatting. [bug introduced in coreutils-8.31] * 'du --max-depth=N' now exits with a nonzero exit status and an error message if N is negative. Previously it behaved as if N were zero. [bug introduced in coreutils-9.4] * 'factor' avoids a buffer over-read (CWE-126) for certain values. [bug introduced in coreutils-9.8] * 'head' and 'tail' now quote names in file headers when needed. [This bug was present in "the beginning".] * 'ls --color' no longer reads freed memory when LS_COLORS sets "ln=target" and later becomes unparsable, e.g., LS_COLORS='ln=target:x'. [This bug was present in "the beginning".] * 'mv' now warns when copying extended attributes fails with ENOTSUP, e.g., when moving files to a file system that does not support them. [bug introduced in coreutils-7.3] * 'numfmt', 'printf', and 'seq' on Solaris, no longer output an extraneous e+00 when using a large precision like "%.5119f". [This bug was present in "the beginning".] * 'pinky -l' no longer no longer prints output in the incorrect order when standard output is fully buffered, e.g., when redirected to a file. [bug introduced in coreutils-9.10] * 'pr' now exits gracefully upon exceeding internal accounting limits, like when processing large tab stops. [This bug was present in "the beginning".] * 'ptx -G' no longer loops forever when the output width is smaller than twice the gap size, as with 'ptx -G -w4', or when a long reference leaves that little room, as with 'ptx -G -r'. [This bug was present in "the beginning".] * 'ptx -W' no longer loops forever with a word regular expression that can match the empty string, like: echo ab | ptx -W 'a*'. [This bug was present in "the beginning".] * 'shred' no longer blocks when opening a FIFO that has no readers. [This bug was present in "the beginning".] * 'stty' no longer fails when the system uses speed encodings that are variations of the requested speed. [bug introduced in coreutils-9.8] * 'tee' no longer loops infinitely after writing all output if a write call sets errno to EAGAIN. [bug introduced in coreutils-9.11] * 'tee' no longer treats short writes as errors. [bug introduced in coreutils-9.11] * 'test' no longer treats '-a' and '-o' as operators when given as strings to a binary operator. E.g., 'test -a -a -a' exits successfully instead of exiting with an error. [This bug was present in "the beginning".] * 'truncate --reference=R' no longer hangs when R is a FIFO with no readers. [bug introduced in coreutils-8.17] * 'unexpand -t' no longer overflows a heap buffer, for tab values > SIZE_MAX/16, or with multi-byte blank characters longer than the tab value. [bugs introduced in coreutils-9.11] * 'uniq -w' no longer overruns the read buffer in multibyte locales. [bug introduced in coreutils-9.5] * 'wc' no longer reads past the end of a lookup table in legacy multibyte locales like SHIFT-JIS where a single byte can decode to a wide character. [bug introduced in coreutils-9.5] * Messages from Gnulib are no longer mistranslated in non-English locales. [bug introduced in coreutils-9.6] New Features * 'env' now supports --env0-from=FILE to read NUL-delimited environment entries from a file. With -i, entries are preserved exactly, allowing full round-tripping of environments containing duplicate or nonstandard entries. * 'stat' and 'tail' now know about the "failfs" and "nullfs" file system types. stat -f -c%T now reports the file system type, and tail -f uses inotify for these file systems. * uname adds the -A,--all-labeled option to label all output, one item per line. Changes in behavior * 'env' and 'printenv' now quote printed environment variables honoring the QUOTING_STYLE environment variable, defaulting to shell-escape style. This avoids printing arbitrary data to the terminal and allows the output to be sourced by a POSIX shell. * 'ls' -w,--width no longer includes '\n' in the width of a line. I.e., the width or $COLUMNS is interpreted to be an _inclusive_ maximum. * 'stat' now uses shell quoting when required, to more robustly escape file names. Previously it only quoted file names with the %N format. ... changelog too long, skipping 47 lines ... - Refresh all other patches. ==== cppcheck ==== Version update (2.21.0 -> 2.22.0) - update to version 2.22.0 * Warn when feof() is used as a while loop condition (wrongfeofUsage). * ftell() result is unspecified when file is opened in mode "t". * Detect when an STL algorithm such as std::copy, std::equal, std::transform, etc. accesses more elements through an iterator than are available in the container (algorithmOutOfBounds). * Detect switch cases that cannot be selected when the switch condition has a known value (unreachableSwitchCase). * Support C++23 'if consteval' / 'if !consteval'. ==== cups-filters2 ==== - disable-universal-cups-filter : do not use a single, universal CUPS filter executable for all filter functions, see https://github.com/OpenPrinting/cups-filters/discussions/727 which reads (excerpts) "drivers with ... filter chains ... made universal fail ... 2 filters ... which come from ... driver package, but universal only supports ... one single driver filter" ==== emacs-compat ==== Version update (31.0.0.2 -> 31.1.0.0) - Update to version 31.1.0.0: * Synchronize version with the Emacs 31.1 release. * compat-31: set version to 31.1 (was 31.0.50). * Document both any and member-if in the manual. - Enable %check (upstream ERT suite). - Spec cleanup ==== feh ==== Version update (3.11.1 -> 3.13.1) Subpackages: feh-zsh-completion - Update _feh zsh completion URL - Update to 3.13.1: * Improve --scale-down in tiling WMs (no flicker on newly loaded images) * Switch default font to bundled NotoSans Medium; keep yudit.ttf for existing themes * Reject unescaped %f/%n in --action/--info (use %F/%N) to prevent command injection via untrusted filenames * Display embedded cover art for audio/mpeg files * Support non-ASCII caption input and DOS-style filelists * Fix Xwayland menu focus and --draw-exif clobbering --draw-info * Handle XOpenIM/XCreateIC failures; fix zoom_fit centering * Do not skip URLs when using --sort mtime - Rebase feh-makefile_optflags.patch, feh-makefile_app.patch and feh-add_jxl_support.patch - Enable the upstream non-X test suite - Add OFL-1.1 for bundled NotoSans-Medium.ttf - Spec cleanup ==== flatpak ==== Version update (1.18.2 -> 1.18.3) Subpackages: flatpak-remote-flathub flatpak-selinux flatpak-zsh-completion libflatpak0 system-user-flatpak - Update to version 1.18.3: + Bug fixes: - Update Meson wrap subprojects for projects that are normally taken from the host system: . bubblewrap 0.12.0 (CVE-2026-87766) . xdg-dbus-proxy 0.1.8 (CVE-2026-93676) - Fix regressions in 1.18.2 when building apps/runtimes, especially on SELinux systems or when the runtime is not installed per-user - Fix subsandbox startup (`flatpak-spawn`) when run from an app that was configured with `--no-talk-name` or `--system-no-talk-name` - Fix a crash when a bundle is installed with explicit key bytes - Documentation updates (code of conduct, contributor guidelines) ==== freerdp ==== Version update (3.31.0 -> 3.31.1) Subpackages: libfreerdp3-3 librdtk0-0 libwinpr3-3 - Update to version 3.31.1: + After the last huge CVE and security fix releases finally a simple papercut fix release. + Most notable user visible changes: - xfreerdp image clipboard now better handles conversion of host images to bitmap (CF_DIB the default windows exchange format) - Improved keyboard mapping for sdl-freerdp (some more exotic keys are properly mapped now) - xfreerdp RAILS: better transparency support with windows 11 - Fix C23 macro definitions for GCC ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - Add gimp-fix-invalid-XWD-guards.patch: Fix invalid guards for XWD parameters which is used to fix CVE-2026-80101. (glgo#GNOME/gimp!3007, bsc#1279839) ==== gucharmap ==== Version update (17.0.2 -> 18.0.0) Subpackages: libgucharmap_2_90-7 - Update to version 18.0.0: + unicode: Update to unicode 18.0.0 + Updated translations. ==== gzip ==== Version update (1.14 -> 1.15) - Update to version 1.15: * Bug fixes: - gzip no longer can mistakenly remove the wrong file if some other process simultaneously renames a gzip destination's ancestor. [bug present since the beginning] - gzip -d no longer rejects PKZIP signatures, local header, and data descriptors. These can appear in well-formed streamed zip files. [bug present since the beginning] - gzip diagnostics now quote file names containing unusual characters. [bug present since the beginning] - A use of uninitialized memory on some malformed inputs has been fixed. [bug present since the beginning] - A buffer overflow has been fixed when decompressing an .lzh file after decompressing a .Z file. [bug present since the beginning] - When decompressing an .lzh file, the output is no longer corrupted when an internal bit buffer is not properly cleared. [bug present since the beginning] - When decompressing an .lzh file after another .lzh file, the output is no longer corrupted by the previous file's decoding table. [bug present since the beginning] - gzip --synchronous no longer fails to synchronize unreadable parent directories on platforms like GNU/Linux that have O_PATH, or to synchronize any parent directories on platforms like FreeBSD that have O_SEARCH but not O_PATH. [bug introduced in gzip-1.7] - On old-fashioned or limited platforms lacking mktemp, gzexe, zdiff and znew no longer have a race when creating a temporary file. [bug present since the beginning] + Changes in behavior: - gzip no longer insists on the "C" locale; instead, it follows the typical practice of using the locale specified by the environment. This change, which is needed for file name quoting, can affect the format of floating-point numbers output by gzip's -l and -v options. Diagnostics are still in English, though. - gzip -l now reports "-Inf%" instead of "0.0%" for the infinite compression ratio of an empty file. - znew's -P option is now ignored, with a warning. It was present only to improve performance, and its implementation had too many bugs to be worth supporting. - Add fix-aarch64-build.patch: build: avoid failure to build on linux aarch64. - Drop CVE-2026-41991.patch, CVE-2026-41992.patch and gzip-1.14-s390x-errno.patch: Fixed upstream. - Rebase patches with quilt. ==== harfbuzz ==== Version update (14.4.0 -> 14.5.0) Subpackages: libharfbuzz-gobject0 libharfbuzz-icu0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.5.0: + Update Unicode 18.0 data and script support, including script values for Jurchen, Proto-Cuneiform, and Seal, and the corresponding shaping support. + Add support for VARC table subsetting, including pruning auxiliary data, remapping glyph IDs, and guarding the feature in lean builds. + Add rendering work budgets to the draw and paint APIs and share them across the raster, vector, GPU, and Cairo renderers so nested outline work remains bounded. + Improve performance in set iteration, lookup traversal, and the repacker, and add coverage for new benchmarks and fuzzing seeds + Fix various correctness and robustness issues across the CFF, Graphite, DirectWrite, and repacker code paths, including memory leaks, overflow checks, bounds issues, and malformed-font handling. + Various build, portability, and CI fixes. ==== hplip ==== Version update (3.26.4 -> 3.26.6) Subpackages: hplip-base hplip-common hplip-cups hplip-driver-hpcups hplip-sane libhplip0 - hpmud.rules: use SYSTEMD_WANTS for firmware upload to USB printers (boo#1274562) * add hpmud.rules-use-SYSTEMD_WANTS-rather-than-RUN.patch - Fix download of propietary plugin for 3.26.6 * add pluginhandler.py-add-fallback-location-for-3.26.6.patch - Update to HPLIP 3.26.6 - Fix hplip CVEs (bsc#1282051): * CVE-2026-91097 (bsc#1281303) * CVE-2026-91098 (bsc#1281304) * CVE-2026-91099 (bsc#1281305) * CVE-2026-91100 (bsc#1281306) * CVE-2026-91101 (bsc#1281307) * CVE-2026-91102 (bsc#1281308) * CVE-2026-91103 (bsc#1281309) * CVE-2026-91105 (bsc#1281310) * CVE-2026-91104 (bsc#1281313) * CVE-2026-91106 (bsc#1281314) - Add support for the following new printers: * HP ScanJet Enterprise Flow N9000 sn1 * HP ScanJet Enterprise Flow 9000 s1 * HP ScanJet Pro 4200 s1 * HP LaserJet Pro 4006dn printer * HP LaserJet Pro 4006dw printer * HP LaserJet Pro 4006n printer * HP LaserJet Pro 4002d printer * HP LaserJet Pro 4007dw printer * HP LaserJet Pro 4007n printer * HP LaserJet Pro 4008d * HP LaserJet Pro 4008dn * HP LaserJet Pro 4008dw * HP LaserJet Pro MFP 4112dw printer * HP LaserJet Pro MFP 4112fdn printer * HP LaserJet Pro MFP 4112fdw printer * HP LaserJet Pro MFP 4113dw printer * HP LaserJet Pro MFP 4113dwg printer * HP LaserJet Pro MFP 4113fdn printer * HP LaserJet Pro MFP 4113fdng printer * HP LaserJet Pro MFP 4113fdw printer * HP LaserJet Pro MFP 4113fdwg printer * HP LaserJet Pro MFP 4114dw * HP LaserJet Pro MFP 4114fdn * HP LaserJet Pro MFP 4114fdw - Remove hp-pkservice - Add compat-fix-shlex.quote-Python-2.7-incompatibility.patch ==== kernel-source ==== Version update (7.2.6 -> 7.2.7) Subpackages: kernel-64kb kernel-default - Update patches.kernel.org/7.2.4-001-drm-amd-display-Skip-Update-HDCP-Config-In-Tran.patch (bsc#1012628 CVE-2026-89773 bsc#1280700). - Update patches.kernel.org/7.2.4-009-btrfs-write-protect-folios-during-data-writebac.patch (bsc#1012628 CVE-2026-89772 bsc#1280699). - Update patches.kernel.org/7.2.4-010-ring-buffer-Fix-subbuf-resize-race-with-ring-bu.patch (bsc#1012628 CVE-2026-89771 bsc#1280712). - Update patches.kernel.org/7.2.4-014-iomap-don-t-free-integrity-payload-that-doesn-t.patch (bsc#1012628 CVE-2026-89770 bsc#1280710). - Update patches.kernel.org/7.2.4-017-clocksource-drivers-nxp-pit-Fix-IRQ-leak-on-cpu.patch (bsc#1012628 CVE-2026-89769 bsc#1280708). - Update patches.kernel.org/7.2.4-019-fs-fix-user-path-of-nested-backing-files.patch (bsc#1012628 CVE-2026-89768 bsc#1280734). - Update patches.kernel.org/7.2.4-020-ovl-fix-double-end_creating-on-the-casefold-mis.patch (bsc#1012628 CVE-2026-89767 bsc#1280730). - Update patches.kernel.org/7.2.4-021-pidfd-hold-exec_update_lock-around-namespace-io.patch (bsc#1012628 CVE-2026-89766 bsc#1280725). - Update patches.kernel.org/7.2.4-024-timers-itimer-Zero-init-old-itimerval-before-co.patch (bsc#1012628 CVE-2026-89765 bsc#1281182). - Update patches.kernel.org/7.2.4-032-rust-devres-fix-race-between-concurrent-revoker.patch (bsc#1012628 CVE-2026-89764 bsc#1280818). - Update patches.kernel.org/7.2.4-041-KEYS-trusted-Fix-TPM-teardown-ordering.patch (bsc#1012628 CVE-2026-89763 bsc#1280820). - Update patches.kernel.org/7.2.4-042-apparmor-fix-cred-UAF-caused-by-begin_current_l.patch (bsc#1012628 CVE-2026-89762 bsc#1280749). - Update patches.kernel.org/7.2.4-043-apparmor-fix-out-of-bounds-write-when-null-term.patch (bsc#1012628 CVE-2026-89761 bsc#1280745). - Update patches.kernel.org/7.2.4-045-mm-swap-don-t-free-a-hibernation-slot-that-is-i.patch (bsc#1012628 CVE-2026-89760 bsc#1280740). - Update patches.kernel.org/7.2.4-053-mm-kmemleak-avoid-soft-lockup-when-scanning-tas.patch (bsc#1012628 CVE-2026-89759 bsc#1280821). - Update patches.kernel.org/7.2.4-055-mm-mempolicy-skip-non-present-PMDs-when-queuein.patch (bsc#1012628 CVE-2026-89758 bsc#1280757). - Update patches.kernel.org/7.2.4-056-mm-mglru-fix-and-remove-redundant-unevictable-f.patch (bsc#1012628 CVE-2026-89757 bsc#1280763). - Update patches.kernel.org/7.2.4-057-mm-migrate-report-RCU-tasks-quiescent-states-in.patch (bsc#1012628 CVE-2026-89756 bsc#1280756). - Update patches.kernel.org/7.2.4-059-mm-migrate_device-clear-stale-mapping-after-fre.patch (bsc#1012628 CVE-2026-89755 bsc#1280770). - Update patches.kernel.org/7.2.4-063-mm-pagewalk-fix-stale-walk-action-escaping-walk.patch (bsc#1012628 CVE-2026-89754 bsc#1280769). - Update patches.kernel.org/7.2.4-069-mm-vmscan-report-RCU-tasks-quiescent-states-in-.patch (bsc#1012628 CVE-2026-89753 bsc#1281178). - Update patches.kernel.org/7.2.4-074-mm-memcg-stop-reclaim-when-a-limit-update-is-su.patch (bsc#1012628 CVE-2026-89752 bsc#1281176). - Update patches.kernel.org/7.2.4-084-x86-tdx-Fix-off-by-one-in-port-I-O-handling.patch (bsc#1012628 CVE-2026-89751 bsc#1280822). - Update patches.kernel.org/7.2.4-088-tracing-user_events-Clear-copied-tracing-state-.patch (bsc#1012628 CVE-2026-89750 bsc#1281172). - Update patches.kernel.org/7.2.4-089-tracing-Fix-crash-passing-ERR_PTR-to-kthread_st.patch (bsc#1012628 CVE-2026-89749 bsc#1281166). - Update patches.kernel.org/7.2.4-091-tracing-Fix-retry-exhaustion-in-simple-ring-buf.patch (bsc#1012628 CVE-2026-89748 bsc#1281024). - Update patches.kernel.org/7.2.4-092-tracing-Fix-use-after-free-in-trace_pipe-read-o.patch (bsc#1012628 CVE-2026-89747 bsc#1281025). - Update patches.kernel.org/7.2.4-093-tracing-Fix-use-after-free-with-same-name-named.patch (bsc#1012628 CVE-2026-89746 bsc#1281026). - Update patches.kernel.org/7.2.4-095-debugfs-Fix-lockdown-check-for-mmap_prepare.patch (bsc#1012628 CVE-2026-89745 bsc#1281209). - Update patches.kernel.org/7.2.4-096-device-property-fix-infinite-loop-in-fwnode_for.patch (bsc#1012628 CVE-2026-89744 bsc#1281029). - Update patches.kernel.org/7.2.4-097-misc-nsm-bound-the-device-reported-response-len.patch (bsc#1012628 CVE-2026-89743 bsc#1281028). - Update patches.kernel.org/7.2.4-099-rapidio-mport_cdev-fix-use-after-free-in-dma_re.patch (bsc#1012628 CVE-2026-89742 bsc#1281027). - Update patches.kernel.org/7.2.4-100-Revert-media-v4l2-dev-fix-error-handling-in-__v.patch (bsc#1012628 CVE-2026-89741 bsc#1281030). ... changelog too long, skipping 3942 lines ... - commit 125ac6f ==== libgsf ==== Version update (1.14.58 -> 1.14.59) Subpackages: gsf-office-thumbnailer libgsf-1-114 - Update to version 1.14.59: * Fix some OLE2 edge cases + Plug leak + Improve thread safety of GSF_CLASS_FULL + Fix zip read for corrupted stream + Fix ole2 leaks + Protect ole2 loader from crazy recursion. ==== libheif ==== Version update (1.23.4 -> 1.23.5) Subpackages: gdk-pixbuf-loader-libheif libheif-aom libheif-dav1d libheif-ffmpeg libheif-jpeg libheif-openh264 libheif-openjpeg libheif-rav1e libheif-svtenc libheif1 - update to 1.23.5: * (GHSA-v8qw-hwjv-44hw) Memory exhaustion through a mismatch between the container and the bitstream image size. A crafted image can declare a small size in its ispe property while the bitstream declares a much larger coded frame. The container-level checks used the ispe size, so the oversized bitstream reached the decoder, which allocated a frame buffer for the in-band size before libheif rejected the mismatch. The advisory demonstrated this for AV1 with the libaom backend (a 351-byte AVIF declaring 64x64 but coding up to 27648x27648, allocating hundreds of MB to more than 10 GB), but the same class affects every codec whose real frame size lives in the bitstream. The coded size is now checked against max_image_size_pixels in the codec- independent decode path, before any bytes reach a decoder plugin: all AV1 sequence headers, all HEVC/AVC/VVC SPS NAL units (including those carried in the item data, not only the ones in the configuration record), the JPEG SOF marker and the JPEG 2000 SIZ reference grid are scanned for the largest coded size. (high) * (GHSA-qwpf-5wf7-r996) Heap use-after-free and double free when encoding an image that carries a TAI timestamp, including transcoding a file with an itai property. ImageDescription shallow-copied its raw heif_tai_timestamp_packet pointer, and a temporary in ImageItem::encode_to_bitstream_and_boxes() freed the packet while the item and the source image still held it. The timestamp is now stored by value. (medium) * (GHSA-9c75-9g8r-4728) Memory amplification through a JPEG 2000 pclr box declaring zero palette columns. The entry-count bound was skipped for zero columns, so an 11-byte box allocated 65,535 empty palette entries, and nested j2kH containers could repeat this within the child and nesting limits: a 3 KB file reached about 330 MB RSS, none of it charged to max_total_memory. Zero columns are rejected (ISO/IEC 15444-1 requires 1 to 255), the byte bound is unconditional, and the palette storage is charged to the memory limits. (medium) * (GHSA-r7gr-2xm2-23wf) Heap out-of-bounds read in alpha compositing for uncompressed (unci) images whose colour planes have different bit depths. Op_flatten_alpha_plane read every plane through the sample type of the first colour plane, so an 8-bit blue plane next to 16-bit red and green planes was read with a halved stride past its end, and the bytes ended up in the composited output. ColorState now tracks one bit depth per plane, and the operator declines mixed sample widths at planning time. (medium) * (GHSA-q492-cfcm-895h) The OpenJPEG decoder plugin's pre-decode size check bounded the JPEG 2000 window span (x1-x0)*(y1-y0) but not the absolute reference-grid coordinates, so a codestream with a 17-pixel window on a grid near the 32-bit boundary reached opj_decode(). Against OpenJPEG 2.3.1 this produced a heap-buffer-overflow write inside OpenJPEG (the class of CVE-2020-6851); OpenJPEG 2.5.4 rejects the input. The reference-grid area is now bounded as well. (low) * (GHSA-qfj5-c4pq-q998) Heap out-of-bounds read in the uncompressed encoder when an application attached a separate alpha plane to an image with an interleaved chroma format. The interleaved encoders took their component list from the chroma format (three entries) but decided whether to write alpha from the presence of an alpha plane, and indexed the list at [3]. heif_image_add_plane() now rejects a separate alpha plane on interleaved images, and the encoders derive both decisions from the chroma format. Only reachable through the public API; decoding never produces such an image. (low) * (GHSA-7pwf-qh74-p35w) The caller's heif_security_limits were not applied when parsing a mini box (the MIAF minimized image format) or the av1C/hvcC blob embedded in it; the built-in defaults were used instead. An application that tightened the limits got no enforcement of its max_memory_block_size or max_total_memory on such files. The allocations are bounded by the bytes present in the box, so this could not amplify memory use. (low) ==== libinput ==== Version update (1.31.3 -> 1.32) Subpackages: libinput-udev libinput10 - Update to release 1.32 * Circular scrolling on circular touchpads (e.g. Panasonic CF-SV1) * New convenience features, e.g. dragging on a touchpad automatically enables a drag lock if the finger near the edge. * On touchpads, disable-while-typing no longer cancels ongoing interactions. * For tablets, we now allow the physical eraser button to be mapped to any button. * `libinput record` now allows a `--no-events` flag. - Delete kill-env.diff (no longer needed, %python3_fix_shebang_path already takes care of it) ==== libreoffice ==== Subpackages: libreoffice-base libreoffice-calc libreoffice-draw libreoffice-filters-optional libreoffice-gnome libreoffice-gtk3 libreoffice-icon-themes libreoffice-impress libreoffice-l10n-en libreoffice-mailmerge libreoffice-math libreoffice-pyuno libreoffice-qt6 libreoffice-writer libreofficekit - Add dbaccess-no-firebird-default-crash.patch: fix the SIGSEGV in the Base "Create Database" wizard. The wizard hardcodes Firebird as the default entry of the data source type list, but Tumbleweed has no firebird package so we build with --disable-firebird-sdbc and the entry does not exist. The list then has no selection at all and FillItemSet() indexes m_aURLPrefixes with -1. Fall back to the first available type and bounds-check the index. - Delete unused files: * b7cae45ad2c23551fd6ccb8ae2c1f59e-numbertext_0.9.5.oxt * dtoa-20180411.tgz - Rework external library handling into one %enable_X/%bundle_X/ %support_X/%version_X macro block per library, with everything else (Source/Provides/BuildRequires/configure flags) derived from it instead of repeating %if 0%{?suse_version} checks. No change to which libraries are bundled vs. system. ==== librsvg ==== Version update (2.62.3 -> 2.62.4) Subpackages: librsvg-2-2 typelib-1_0-Rsvg-2_0 - Update to version 2.62.4: + librsvg crate version 2.62.4 + librsvg-rebind crate version 0.3.0 + Fix use-after-free when there are duplicate XML entities in nested Xinclude documents. + Dependency updates: lopdf for RUSTSEC-2026-0187, crossbeam-epoch for RUSTSEC-2026-0204. ==== libsolv ==== Version update (0.7.39 -> 0.7.40) Subpackages: libsolv-tools-base libsolv1 ruby-solv - improve SUSE product link dependency generation if there are multiple release packages for the same product [bsc#1279541] - fix possible segfault in the SUSE namespace dependency generation - bump version to 0.7.39 ==== libsrtp2 ==== Version update (2.8.0 -> 2.8.1) - Update to release 2.8.1 * Add API to require cryptex * Treat cryptex and enc xtn hdr as an invalid combination ==== libssh ==== Subpackages: libssh-config libssh4 - Fix: libssh ignores explicit username in URL if User specified in SSH config (bsc#1279934) * options: do not let config override explicitly-set options * tests: cover config-vs-app-set option precedence * Add patches: - libssh-options-do-not-let-config-override-explicitly-set-options.patch - libssh-tests-cover-config-vs-app-set-option-precedence.patch ==== libstorage-ng ==== Version update (4.5.353 -> 4.5.354) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Danish) (bsc#1149754) - 4.5.354 ==== libupnp ==== Version update (22.1.0 -> 22.1.2) Subpackages: libixml22 libupnp22 - Update to release 22.1.2 * Fix quadratic-time DOM construction in ixmlParseBufferEx() [GHSA-xr5m-v53v-jfq9] - Update to release 22.1.1 * Fix unauthenticated remote crash in SOAP QueryStateVariable handling. [GHSA-7mx2-6v7x-xhv7] ==== libvirt ==== Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - spec: Skip vishtest test in qemu emulation ==== libzio ==== Version update (1.15 -> 1.17) - Update to version 1.17 * Mention lzip in manual page as well * Implement lzlib support as well * Add Debian package build tree - Update to version 1.16 e2k arch support: makecontext() is unavailable on e2k arch since makecontext_e2k() allocates additional stacks so freecontext_e2k() is required where the given ucp.uc_stack gets either freed or reused. ==== libzypp ==== Version update (17.38.15 -> 17.38.16) - BuildRequires: %{libsolv_devel_package} >= 0.7.40 (bsc#1279541) This fix resolves issues in online migrations to SLES 16.1. - version 17.38.16 (35) ==== lightdm ==== Version update (1.32.0 -> 1.33.1) Subpackages: liblightdm-gobject-1-0 lightdm-bash-completion - Update to 1.33.1: * Fix user switching (assume CanMultiSession after logind dropped the property) * Add a Qt6 client library (Qt5 remains available) * Honor the VNC server command; try IPv6 first for VNC bind * Do not reuse a local X server if the hostname has changed * Allow Wayland sessions on seat0 without VTs * Support PAM modules that change the home directory * Do not disconnect signals on cancel before the session ends * Suppress log errors for missing PAM modules * Fix memory leaks in session_child_run - Drop lightdm-1.32.0-qt6-library.patch (now upstream; also unblocks GCC 16 / C++17, boo#1261691) - Rebase remaining patches for 1.33.1 ==== lightdm-gtk-greeter ==== Version update (2.0.8 -> 2.0.9) Subpackages: lightdm-gtk-greeter-lang - Update to version 2.0.9: * Trim whitespace from username input * Add Cinnamon and LXQt session badges * Add Alt+Delete shortcut for the reboot dialog * New config options: default-session, highlight-logged-user, keyboard-layouts and round-user-image * Add usage examples to the sample configuration * Updated translations - Enable kill-on-sigterm for GTK 3.16+ SIGTERM handling - Drop unused exo-tools BuildRequires - Raise liblightdm-gobject floor to 1.19.2 - Replace obsolete packageand/otherproviders with boolean deps ==== lpsolve ==== Version update (5.5.2.0 -> 5.5.2.14) - Update to 5.5.2.14 (upstream moved from SourceForge to GitHub): * Fix a rare case of a variable value returned as a very small negative number instead of 0 - Switch from the lpsolve_bundled_colamd-5.5.2.0.tar.xz fork tarball to upstream sources (lp_solve-5.5.2.14-repackaged.tar.gz) with the non-free colamd/colamd.{c,h} removed; rebase the bundled COLAMD to 3.0.4 (BSD-3-Clause) and add Provides: bundled(colamd) = 3.0.4 - Add Fedora's patches: * lp_solve-5.5.2.14-Respect-CC-CFLAGS-and-LDFLAGS.patch * lp_solve-5.5.2.11-Link-a-tool-to-a-shared-library.patch * lp_solve-5.5.2.11-Rebase-COLAMD-to-3.0.4.patch * lp_solve-5.5.2.11-Port-lp_MDO-to-colamd-3.0.4.patch - Add lp_solve-5.5.2.14-versioned-soname.patch to build the shared library with a versioned SONAME (liblpsolve55.so.0) - Link the lp_solve tool against the shared library instead of statically duplicating its objects - Correct the license tag to LGPL-2.1-or-later AND GPL-2.0-or-later WITH Bison-exception-2.2 AND BSD-3-Clause - Add %check: solver smoke test plus building and running demo/demo.c - Modernize spec file ==== lzlib ==== - Add baselibs.conf so that libzio can depend on lzlib - Make build recipe POSIX sh compatible ==== man ==== - Enable multi compression with libzio ==== meson ==== Version update (1.12.0 -> 1.12.1) Subpackages: meson-vim - Update to version 1.12.1: + gnome: Fix dependency between gir and sources + Handle invalid CMake skip compiler test values + python module: support pypy without distutils + build: ExtractedObjects are non-recursive by default + Add LLVM 23 version suffixes + compilers: move -fpermissive from CPPCompiler to individual superclass - Drop 16167.patch: fixed upstream ==== mozjs140 ==== - Drop mozjs140-CVE-2026-32776.patch, mozjs140-CVE-2026-32777.patch, mozjs140-CVE-2026-32778.patch, and mozjs140-CVE-2025-70103.patch. These were added by mistake and are not needed, since the relevant sources are not build for the JS interpreter. ==== ncurses ==== Version update (6.6.20260912 -> 6.6.20260919) Subpackages: libncurses6 ncurses-utils terminfo terminfo-base terminfo-iterm terminfo-screen - Add ncurses patch 20260919 + revise content/formatting/style of man pages (patches by Branden Robinson) + add overline to ghostty (report by Jared Finder) + review ghostty -TD + add overline to rlogin-color -TD + add null pointer check for stdscr in endwin() when saving keypad mode (patch by Branden Robinson). + remove an adjustment to stdscr in doupdate() when restoring keypad mode (OpenSUSE boo#1281268). ==== nvidia-open-driver-G07-signed ==== Version update (595.99.02_k7.2.6_1 -> 595.99.02_k7.2.7_1) Subpackages: nvidia-open-driver-G07-signed-kmp-64kb nvidia-open-driver-G07-signed-kmp-default - kernel-7.3.0-opengpu-615.71.09.patch * fix build against Linux 7.3.0 (RC) (boo#1278022) - Fixing-build-against-SLE16.1-Kernel.patch - re-disabled CXL support for now again following NVIDIA's advice (bsc#1280057) ==== nvidia-open-driver-G07-signed-cuda ==== Version update (615.71.09_k7.2.6_1 -> 615.71.09_k7.2.7_1) Subpackages: nvidia-open-driver-G07-signed-cuda-kmp-64kb nvidia-open-driver-G07-signed-cuda-kmp-default - kernel-7.3.0-opengpu-615.71.09.patch * fix build against Linux 7.3.0 (RC) (boo#1278022) - Fixing-build-against-SLE16.1-Kernel.patch - re-disabled CXL support for now again following NVIDIA's advice (bsc#1280057) ==== openSUSE-release ==== Version update (20260921 -> 20260924) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== p11-kit ==== Version update (0.26.2 -> 0.26.5) Subpackages: libp11-kit0 p11-kit-server p11-kit-tools - Update to 0.26.5: * CVE-2026-18938: guard against overflow when decoding nested attributes (bsc#1280702) - Update to 0.26.4: * Build fix [PR#773] * Update translations [PR#743, PR#772] - Update to 0.26.3: * CVE-2026-13757: server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit (bsc#1269664) * fixed confusing error message when trying to store an existing cert with trust anchor [PR#770] * fixed assert when parsing p11-kit files with value (") [PR#762] * fixed numerous memory management issues [PR#751, PR#753, PR#754, PR#756, PR#758, PR#763, PR#764, PR#765, PR#766, PR#769] * Build and test fixes [PR#746, PR#747, PR#752, PR#755, PR#757, PR#760, PR#761] ==== publicsuffix ==== Version update (20260902 -> 20260921) - Update to version 20260921 (public_suffix_list.dat snapshot taken from upstream commit of 2026-09-21): * Add Databricks Apps zones under databricksapps.com and databricksapps.us to PRIVATE section (#3255) * Add surge.sh to PRIVATE section (#3287) * Add hosted-by-files.com to PRIVATE section (#3267) * Add *.compute.herokuapp.com (Heroku) (#3208) * Add cloud.run and ai.studio (Google) (#2959) * Add Azure App Service delegated zones under azurewebsites.net, including the wildcard * .p.azurewebsites.net (#3147) * Add opencloud.me (#3174) * Add ia.bo social ccTLD subdomain for Bolivia (#3214) * Remove alpha-myqnapcloud.com and dev-myqnapcloud.com (#3254) ==== python-pip ==== - Remove the usage of ensurepip to build the package, uses the source pip instead. ==== python-tornado6 ==== Version update (6.5.8 -> 6.5.10) - update to 6.5.10: - tornado.web: The allowed_symlink_directory argument of StaticFileHandler may now be a list of directories instead of just a single directory. This feature has been adjusted to improve compatibility with Jupyter, which would fail to load with Tornado 6.5.9. - 6.5.9: [#] Security fixes - .StaticFileHandler no longer follows symlinks outside of the static root directory. Applications that wish to continue the previous behavior may set the new argument allowed_symlink_directory to the directory (an ancestor of the static root) that should be used for symlink validation. Thanks to Yasha-ops and iaohkut-from-NightWolf-Team for reporting this issue. - curl_httpclient has a new max_body_size argument (default 100MB, same as for simple_httpclient). This limit is enforced on all requests, whether or not streaming_callback is used. curl_httpclient now also controls its memory usage when decompressing response bodies. Thanks to afldl, iaohkut-from-NightWolf-Team, and aoto-tech for reporting this issue. - simple_httpclient now correctly applies the max_body_size limit to responses using HTTP/1.0 format (no Content-Length or Transfer-Encoding). Previously it silently truncated such responses at max_buffer_size instead. Thanks to afldl for reporting this issue. - simple_httpclient now rejects responses that use more than 10 100 Continue responses, which could previously cause stack overflow errors. Thanks to afldl for reporting this issue. - The limit ParseBodyConfig.urlencoded.max_argument is now applied to URL arguments in addition to POST bodies. Thanks to iaohkut-from-NightWolf-Team, afldl, and manus-pi for reporting this issue. - Add patch run-multi-process-in-fresh-process.patch: * Run test_multi_process in a fresh subprocess to avoid a warning. ==== rsync ==== Version update (3.4.3 -> 3.5.1) - Update to 3.5.1 - Protocol: - The protocol number was changed to 33. - Bug fixes: - Fixed several path-handling regressions from 3.5.0. Explicit sender paths can again traverse symlinked ancestors without weakening confinement of paths found during recursive scans. Local and remote-shell `--files-from` paths are handled as operator-supplied paths rather than paths beneath the transfer root. - Fixed access to `/dev/stdin`, `/dev/stdout`, `/dev/stderr` and `/dev/fd/N` when they refer to pipes or descriptors inside user namespaces. Reading batch data from a FIFO or process substitution works again. - Restored `--max-alloc=0` as a spelling for the parser's maximum allocation limit rather than disabling that limit. - Fixed restricted-root paths in `rrsync` and detection of an inetd connection when a daemon is started with a local socket on standard input, as can happen under ADB without a PTY. - Allowed `--contimeout` for daemon connections made through `--rsh` without applying it to ordinary remote-shell transfers. - Tightened validation of partial-directory state and alternate-destination paths on the receiver. An alternate-destination leaf symlink is no longer followed as a basis file. - Fixed undefined shifts in the bundled zlib code and a FreeBSD amd64 build failure involving the assembly and SIMD objects. - Enhancements: - Added support for internationalised domain names when the required library is available at build time. - Added the number of 4 KiB logical blocks touched to `--stats`. This counts distinct logical file regions written by the receiver, not physical disk blocks or disk I/O. It is reported when both peers negotiate protocol 33. - Build and tests: - `install-strip` now honours `STRIP` including during cross-compilation. - Updated platform tests and fleet-test coverage for the 3.5.0 fixes. - Activate IDN (internationalised domain name) support by adding BuildRequires: libidn2-devel - Drop rsync-fix-protected-regultar-test.patch (already upstream) - Fix test suit protected-regular test * Added rsync-fix-protected-regultar-test.patch - explicitly require python-rpm-macros to not rely on any indirect requires. Fixes build on SLE 16.0 - Update to 3.5.0 - Security update (bsc#1269060, rsync 3.5.0 security backports): - CVE-2026-53783, bsc#1269041: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) - CVE-2026-53784, bsc#1269042: Daemon module-root chdir escape under "use chroot = no" - CVE-2026-53785, bsc#1269043: --relative implied-parent creation escapes the destination tree - CVE-2026-53786, bsc#1269044: Daemon --filter merge file bypasses the module filter list - CVE-2026-53788, bsc#1269046: Daemon name-converter accepts newline-bearing names into its line protocol - CVE-2026-53789, bsc#1269047: Malicious sender expands --delete scope by reclassifying an implied parent - CVE-2026-53790, bsc#1269048: Command / argument injection via unquoted peer- or host-controlled values - CVE-2026-53791, bsc#1269049: PROXY-protocol mode lets a direct client spoof the daemon's source address - CVE-2026-53792, bsc#1269050: Receiver-supplied zero checksum block length drives sender matching negative - CVE-2026-53793, bsc#1269051: Chroot "/./" inner-module escape via a parent-component symlink - CVE-2026-53794, bsc#1269052: Remote peer disables the per-allocation sanity cap via --max-alloc=0 - CVE-2026-53795, bsc#1269053: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement - CVE-2026-53796, bsc#1269054: Non-daemon receiver destination-chdir symlink race (TOCTOU) - CVE-2026-53797, bsc#1269055: Sender source-tree parent-component symlink race -> out-of-tree disclosure - CVE-2026-53798, bsc#1269045: Daemon name-converter empty response maps an unknown name to uid/gid 0 - CVE-2026-53799, bsc#1269056: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) - CVE-2026-53800, bsc#1269057: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree - CVE-2026-53801, bsc#1269058: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure - CVE-2026-53802, bsc#1269039: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files - CVE-2026-53803, bsc#1269040: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths - CVE-2026-70463, bsc#1273430: "auth users" ignores documented comma-only parsing, silently skipping a deny/read-only rule - CVE-2026-70462, bsc#1273431: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (signed overflow, and a non-positive value) - CVE-2026-70461, bsc#1273432: Peer-driven one-byte heap out-of-bounds write in add_implied_include() - CVE-2026-70460, bsc#1273433: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-module symlink - CVE-2026-70459, bsc#1273434: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root - CVE-2026-70458, bsc#1273435: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H - CVE-2026-70457, bsc#1273436: Attacker-chosen-offset write in parse_size_arg() error formatting - CVE-2026-70456, bsc#1273437: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs - CVE-2026-70454, bsc#1273439: rsync-ssl establishes an unauthenticated TLS connection (no CA verification; no stunnel hostname binding) - CVE-2026-70453, bsc#1273440: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain - CVE-2026-70464, bsc#1273429: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module - CVE-2026-70455, bsc#1273438: Peer-controlled Zstandard worker exhaustion on an rsync daemon - CVE-2026-70452, bsc#1273441: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block - Rejected CVEs (duplicates, resolved to canonical CVEs above): - CVE-2026-44507, bsc#1271931: duplicate of CVE-2026-43617 - CVE-2026-44508, bsc#1271932: duplicate of CVE-2026-43618 - CVE-2026-44509, bsc#1271933: duplicate of CVE-2026-43619 - CVE-2026-44510, bsc#1271934: duplicate of CVE-2026-43620 - Security update: - CVE-2025-10158, bsc#1254441: Out of bounds array access via negative index - CVE-2026-41035, bsc#1262223: count of entries mismatch can lead to a use-after-free - CVE-2026-43617, bsc#1264515: Authorization Bypass via Hostname Resolution - CVE-2026-29518, bsc#1264512: Integer Overflow Information Disclosure - CVE-2026-43619, bsc#1264514: Symlink Race Condition via Path-Based Syscalls - CVE-2026-43620, bsc#1264513: Out-of-Bounds Array Read via recv_files() - CVE-2026-45232, bsc#1265296: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing - SECURITY FIXES: - This release fixes 33 security issues found during a focused audit of rsync's path handling and daemon protocol, a companion daemon-protocol fuzzing pass, and reports from external researchers -- plus several robustness hardenings. ... changelog too long, skipping 443 lines ... don't assume python3 is the binary name. use sys.executable. ==== seahorse ==== Version update (47.0.1+6 -> 47.0.1+113) Subpackages: gnome-shell-search-provider-seahorse - Update to version 47.0.1+113: * flatpak: Don't use comments in JSON * css: Don't use shade() * ssh: Notify the rest of the UI after comment change * Fix search provider * passphrase-prompt: Mark the repeat password entry invalid on mismatch * import-dialog: Mark the error label as a source of an error message * prefs-keyservers: Mark the URL entry invalid on the a11y layer * prefs-keyservers: Add tooltip to the remove button * add-keyserver: Use appropriate "win" action prefix * common: Remove PgpSettings * Stop using separate PgpSettings * app-settings: Add 'default-key' and 'keyservers' keys * keyserver-dropdown: Use correct changed signal * Updated translations. - Drop 260.patch: Merged upstream. - Update to version 47.0.1+89: * data: Compile schemas for unit tests * data: Update the screenshot * Updated translations. - Replace 258.patch and 259.patch with 260.patch following upstream changes. - Add patches from upstream: + 258.patch: Add keys from org.gnome.crypto.pgp schema + 259.patch: data: Compile schemas for unit tests - Drop gcr3-data BuildRequires and Requires, no longer needed. - Update to version 47.0.1+81: * ssh: Notify "loaded" property * pgp: Allow build with gpgme >= 2.0.0 * gpg_check: Set LC_ALL to C * pgp: Introduce PGP key algorithm & usage enums * pgp: Split off SeahorseGpgmKeyGenType enum * pgp: Split off key creation logic from generate dialog * gpg_check: Check for supported pubkey algorithms * build-aux: Refactor gpg_check.py * pgp: Separate logic for key creation parameters * gkr: Clear details group before re-adding items * pgp: Re-implement adding a photo * pkcs11: Show new gcr certificate extensions in cert widget * Drop version parsing functions * Remove unused seahorse_util_write_file_private() * metainfo: Add Matrix channel as contact link * metainfo: Add supported input methods * metainfo: Change component type to desktop-application * data: Rename appdata to metainfo * Automatically load CSS * Drop unnecessary "Application" suffix * po: Cleanup POTFILES.skip a bit * po: Damned Lies workaround should be in .skip not .in * Remove obsolete entries from POTFILES.in * gkr: Hide rows if empty * pgp: Port KeyserverSync dialog to AdwDialog * Rework SeahorseObject as a SeahorseItem interface * pkcs11: Actually use issuer part for issuer row * pgp: Move KeyserverResults to KeyserverSearch dialog * pgp: Port KeyserverSearch to AdwDialog * pkcs11: Fix byte strings in CertificateWidget * ssh: Don't allow creation of DSA keys anymore * po: Update POTFILES.in/skip after GTK4 port * Port to GTK4 and gcr4 * appdata: Fix developer id * Updated translations. - Drop seahorse-47.0.1-gpgme-2.patch: Fixed upstream. - Drop appstream-glib, pkgconfig(gcr-3), pkgconfig(gcr-ui-3), pkgconfig(gtk+-3.0) and pkgconfig(libhandy-1) BuildRequires: No longer needed nor used. - Add AppStream, gcr3-data, pkgconfig(gck-2), pkgconfig(gcr-4), pkgconfig(gtk4) and pkgconfig(libadwaita-1) BuildRequires: New dependencies following upstreams port to gtk4 and libadwaita. Also add gcr3-data Requires: Still needed for its schema files. ==== selinux-policy ==== Version update (20260914 -> 20260923) Subpackages: selinux-policy-targeted - Update to version 20260923: * Add common criteria banner labels (bsc#1282303) - Fail cleanoldsepoldir.service with a warning instead of an error when snapper is not installed, as snapper is not installed by default in public cloud images (bsc#1271814) ==== syslogd ==== Subpackages: klogd syslog-service - Add keyring but there is still no signed 1.5.1 source tar ball ==== sysvinit ==== Version update (3.14 -> 3.18) - Update to sysvinit 3.18 * This release fixes builds with man pages when language-specific directories are not available. * Removed unused "check" command from Makefile. * Fix version number in init.c and changelog. * Remove shell script which has a license conflict from contrib directory. * Clean up of inittab manual page (typos and syntax) by Bjarni Ingi Gislason. * Clean up of init manual page (typos and syntax) by Bjarni Ingi Gislason. * Improved systemd to sysv unit-to-script conversion. Provided by avivdaum. * Remove some debug/status messages when reading the /etc/inittab.d/ directory. * Document how init reads the inittab.d directory in the inittab manual page. * Removed unused variable/code from sulogin * Some manual page clean-up for init to fix typos and formatting. * Small change to optimize getting string length in a loop in init. * Small fixes for formatting and typos in runlevel manual page. - Update to startpar 0.67 * This release introduces no feature changes, but does clean up compiler issues with GCC 15 and newer. Following the compiler's C standards we now use stdbool.h instead of defining our own boolean type. ==== tesseract-ocr ==== Subpackages: libtesseract5 tesseract-ocr-common - CVE-2026-88047: stack buffer overflow in Classify::ReadNormProtos on crafted traineddata (boo#1280925) * tesseract-CVE-2026-88047.patch - CVE-2026-88048: heap out-of-bounds write/read in FullyConnected::Forward via dimension mismatch (boo#1280929) * tesseract-CVE-2026-88048.patch - CVE-2026-88049: heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch (boo#1280930) * tesseract-CVE-2026-88049.patch - CVE-2026-88050: out-of-bounds write in UnicharCompress via unvalidated recoder code values (boo#1280931) * tesseract-CVE-2026-88050.patch - CVE-2026-88051: heap out-of-bounds write in GenericVector::read via reserved/size_used_ mismatch (boo#1280932) * tesseract-CVE-2026-88051.patch - CVE-2026-88052: heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynchronization (boo#1280933) * tesseract-CVE-2026-88052.patch - CVE-2026-88053: heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in crafted traineddata (boo#1280934) * tesseract-CVE-2026-88053.patch - CVE-2026-88054: denial of service via empty-stack dereference at model load (boo#1280935) * tesseract-CVE-2026-88054.patch - CVE-2026-73067 (boo#1275623): heap out-of-bounds read in SquishedDawg on crafted model, already fixed in the shipped 5.5.3 (DAWG edge-structure validation). ==== thin-provisioning-tools ==== Version update (1.3.3 -> 1.3.4) - Update to version 1.3.4: * thin_dump: fix panics when btree nodes point beyond the end of the metadata device * thin_check, cache_check and the other tools: fix overflows in IoEngine block range tracking and offset calculation, which caused panics or reads at the wrong offset on damaged metadata * fix an integer overflow in space map boundary checks * remove redundant leaf insertions in LeafWalker * update bundled dependencies to their latest compatible releases - Drop thin-provisioning-tools-tests-clap-single-alias.patch: merged upstream, which now also requires clap 4.6. - Refresh the vendored Rust crates: 48 changed version, zlib-rs added, windows_i686_gnullvm dropped. - Re-derive License from the crates actually linked into the shipped binary: unchanged. zlib-rs is vendored but stays unlinked, since flate2 still defaults to miniz_oxide, so no Zlib obligation is taken on. ==== util-linux ==== Version update (2.42.2 -> 2.42.3) Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - Update to version 2.42.3: * Security fixes: * CVE-2026-76642 - mount(8) post-mount hooks execute after helper failure. When an external mount. helper exits nonzero, post-mount hooks (X-mount.idmap, X-mount.owner/group/mode) still execute as if the mount had succeeded, allowing privileged operations on the pre-existing target filesystem (bsc#1274864, bsc#1278349). * CVE-2026-78410 - mount(8) TOCTOU race on source path. In restricted (SUID, non-root) mode, the source path is canonicalized with realpath() as euid=0, following symlinks through user-writable directories. Additionally, open_tree() follows symlinks in intermediate path components. A local attacker can redirect a privileged mount or post-mount ownership change to an arbitrary path (bsc#1274864, bsc#1278347). * CVE-2026-78409 - mount(8) X-mount.subdir symlink escape. The open_tree() call used to open a subdirectory on a detached mount follows symlinks in intermediate path components, allowing escape from the detached tree (bsc#1274864, bsc#1278346). * CVE-2026-78408 - nsenter(1), unshare(1) file descriptor leak. File descriptors in nsenter and unshare were not created with O_CLOEXEC, potentially leaking them across exec. Added O_CLOEXEC as defense in depth (bsc#1274864, bsc#1278348). * wall(1), write(1) - hostname escape sequence injection. The CVE-2024-28085 fix sanitized only message bodies; the banner headers still interpolated the system hostname without sanitization. An unprivileged user can inject terminal escape sequences via a user namespace hostname. Additional fix for CVE-2024-28085. Reported-by: Skyler Ferrante * agetty: fix spurious issue file reprinting on reload * col: * guard c_width sign before size_t cast in BS branch * fix cur_col underflow on backspace over a wide char * disk-utils: fix memory leak in execute function * hexdump: stop after stdout write errors * libblkid: * befs fix possible load of misaligned address * befs fix possible too large shift * dos fix 32-bit overflow in partition start/size [coverity CID 503517, 503518] * (iso9660) fix out-of-bounds read of root dir record * libfdisk: fix OOM on GPT with huge partition entries array * libmount: * skip post-mount hooks after failed mount helper [CVE-2026-76642] * pin source path with openat2() for restricted users [CVE-2026-78410] * restrict source path canonicalization for non-root users [CVE-2026-78410] * fix X-mount.subdir symlink following on detached tree [CVE-2026-78409] * reuse existing act fd in mnt_update_start on ro retry * properly end act file in mnt_free_update * don't ignore "/" target in mount --all when target prefix is set * lscpu: * remove mmu reference not available in stable/v2.42 * add NULL guards for RISC-V ISA functions [coverity CID 503785] * mbsalign: check remaining buffer space before writing hex escapes * more: fix out-of-bounds write in get_line() on invalid multibyte input * nsenter, unshare: add O_CLOEXEC to all open() calls [CVE-2026-78408] * pg: fix out-of-bounds access past wbuf on a trailing tab * unshare: Fix --map-auto regression * wall, write: sanitize hostname in banner header - Refresh Add-documentation-on-blacklisted-modules-to-mount-8-.patch. ==== util-linux-systemd ==== Version update (2.42.2 -> 2.42.3) Subpackages: lastlog2 liblastlog2-2 - Update to version 2.42.3: * Security fixes: * CVE-2026-76642 - mount(8) post-mount hooks execute after helper failure. When an external mount. helper exits nonzero, post-mount hooks (X-mount.idmap, X-mount.owner/group/mode) still execute as if the mount had succeeded, allowing privileged operations on the pre-existing target filesystem (bsc#1274864, bsc#1278349). * CVE-2026-78410 - mount(8) TOCTOU race on source path. In restricted (SUID, non-root) mode, the source path is canonicalized with realpath() as euid=0, following symlinks through user-writable directories. Additionally, open_tree() follows symlinks in intermediate path components. A local attacker can redirect a privileged mount or post-mount ownership change to an arbitrary path (bsc#1274864, bsc#1278347). * CVE-2026-78409 - mount(8) X-mount.subdir symlink escape. The open_tree() call used to open a subdirectory on a detached mount follows symlinks in intermediate path components, allowing escape from the detached tree (bsc#1274864, bsc#1278346). * CVE-2026-78408 - nsenter(1), unshare(1) file descriptor leak. File descriptors in nsenter and unshare were not created with O_CLOEXEC, potentially leaking them across exec. Added O_CLOEXEC as defense in depth (bsc#1274864, bsc#1278348). * wall(1), write(1) - hostname escape sequence injection. The CVE-2024-28085 fix sanitized only message bodies; the banner headers still interpolated the system hostname without sanitization. An unprivileged user can inject terminal escape sequences via a user namespace hostname. Additional fix for CVE-2024-28085. Reported-by: Skyler Ferrante * agetty: fix spurious issue file reprinting on reload * col: * guard c_width sign before size_t cast in BS branch * fix cur_col underflow on backspace over a wide char * disk-utils: fix memory leak in execute function * hexdump: stop after stdout write errors * libblkid: * befs fix possible load of misaligned address * befs fix possible too large shift * dos fix 32-bit overflow in partition start/size [coverity CID 503517, 503518] * (iso9660) fix out-of-bounds read of root dir record * libfdisk: fix OOM on GPT with huge partition entries array * libmount: * skip post-mount hooks after failed mount helper [CVE-2026-76642] * pin source path with openat2() for restricted users [CVE-2026-78410] * restrict source path canonicalization for non-root users [CVE-2026-78410] * fix X-mount.subdir symlink following on detached tree [CVE-2026-78409] * reuse existing act fd in mnt_update_start on ro retry * properly end act file in mnt_free_update * don't ignore "/" target in mount --all when target prefix is set * lscpu: * remove mmu reference not available in stable/v2.42 * add NULL guards for RISC-V ISA functions [coverity CID 503785] * mbsalign: check remaining buffer space before writing hex escapes * more: fix out-of-bounds write in get_line() on invalid multibyte input * nsenter, unshare: add O_CLOEXEC to all open() calls [CVE-2026-78408] * pg: fix out-of-bounds access past wbuf on a trailing tab * unshare: Fix --map-auto regression * wall, write: sanitize hostname in banner header - Refresh Add-documentation-on-blacklisted-modules-to-mount-8-.patch. ==== wsdd ==== - Do not chroot into /run/wsdd (boo#1282139): CPython imports parts of the standard library lazily, so the first such import after the chroot fails with ModuleNotFoundError and the daemon exits. Also drop the CAP_SYS_CHROOT ambient capability that only existed for it. The runtime directory still comes from the tmpfiles entry and the remaining systemd hardening is kept. ==== xscreensaver ==== Version update (6.15 -> 6.16) Subpackages: xscreensaver-data xscreensaver-lang - Update to 6.16: * New hacks: floppy, graphstat, amigajuggler and polarnight. * New display modes in hypertorus. * X11: Updates for systemd inhibitors on KDE Plasma 6.5. - Drop xscreensaver-systemd.patch: adopted upstream. - Rebase xscreensaver-screenfade.patch. - Add floppy, graphstat, amigajuggler and polarnight to xscreensaver-data-extra.list. - Spec cleanup: drop Group, add gcc/make BuildRequires, and require pkgconfig(libsystemd) >= 221. ==== xwaylandvideobridge ==== Version update (0.5.2 -> 0.5.3) - Update to version 0.5.3: * Fix deprecation warnings * Shrink the idle window * Fixup comments * clear WM_TAKE_FOCUS from window flags * Move the WM_TAKE_FOCUS removal to syncWindowId() * Request autostart through the Background portal in Flatpak * Show the bridge in the application menu * Tidy up translatable strings * Fix build with KPipeWire older than 6.7 * Document how to install the bridge ==== yast2-trans ==== Version update (84.87.20260906.c2bec94659 -> 84.87.20260916.f55042cfcf) Subpackages: yast2-trans-af yast2-trans-ar yast2-trans-bg yast2-trans-bn yast2-trans-bs yast2-trans-ca yast2-trans-cs yast2-trans-cy yast2-trans-da yast2-trans-de yast2-trans-el yast2-trans-en_GB yast2-trans-es yast2-trans-et yast2-trans-fa yast2-trans-fi yast2-trans-fr yast2-trans-gl yast2-trans-gu yast2-trans-hi yast2-trans-hr yast2-trans-hu yast2-trans-id yast2-trans-it yast2-trans-ja yast2-trans-jv yast2-trans-ka yast2-trans-km yast2-trans-ko yast2-trans-lo yast2-trans-lt yast2-trans-mk yast2-trans-mr yast2-trans-nb yast2-trans-nl yast2-trans-pa yast2-trans-pl yast2-trans-pt yast2-trans-pt_BR yast2-trans-ro yast2-trans-ru yast2-trans-si yast2-trans-sk yast2-trans-sl yast2-trans-sr yast2-trans-sv yast2-trans-ta yast2-trans-th yast2-trans-tr yast2-trans-uk yast2-trans-vi yast2-trans-wa yast2-trans-xh yast2-trans-zh_CN yast2-trans-zh_TW yast2-trans-zu - Update to version 84.87.20260916.f55042cfcf: * Translated using Weblate (Danish) * Translated using Weblate (Danish)