Packages changed: bind chrony expat (2.8.4 -> 2.8.5) google-noto-fonts (20260901 -> 20261001) hwdata (0.411 -> 0.412) libpng16 (1.6.58 -> 1.6.59) libstorage-ng (4.5.355 -> 4.5.359) libupnp (22.1.7 -> 22.1.8) perl-XML-Twig (3.540.0 -> 3.550.0) python-urllib3 (2.7.0 -> 2.8.0) selinux-policy (20260928 -> 20261002) === Details === ==== bind ==== Subpackages: bind-doc bind-utils - Update named.root - remove nonsensical prep code. it was reading SOURCE0 as a gzip. the code anyway already follows SOURCE_DATE_EPOCH for reproducibility. ==== chrony ==== Subpackages: chrony-pool-openSUSE - (bsc#1273873): Replace chrony-usretc-service.patch with chrony-usretc-config-fallback.patch to let chronyd itself fall back to /usr/etc/chrony.conf when /etc/chrony.conf is absent and no -f is given. - Rework chrony-service-ordering.patch (bsc#1145193, bsc#1279495): * chronyd.service: drop the time-sync.target coupling (Wants= and Before=); chronyd is Type=notify, so readiness only means the daemon started, not that the clock is synced. * chronyd.service: also drop "Wants=network.target", keeping just After=nss-lookup.target and After=network.target. * chrony-wait.service: add After=/Wants=network-online.target so it no longer times out before the network is up. - Default OPTIONS to "-s" in the chronyd sysconfig to seed the clock from the RTC (or driftfile) at start-up; override in /etc/sysconfig/chronyd. ==== expat ==== Version update (2.8.4 -> 2.8.5) Subpackages: libexpat1 - security update: * CVE-2026-102633: expat: Denial of Service via integer overflow in expat_realloc (bsc#1283493) - Added patch expat-CVE-2026-102633.patch - update to 2.8.5 (bsc#1282347, CVE-2026-93990): * Security fixes: * CVE-2026-93990: reject high surrogates not followed by a low surrogate during UTF-16 decoding; malformed UTF-16 could be smuggled into the application (CVSS 9.8) * Bug fixes: * Fix an OOM-related memory leak on a failed overflow check * Fix memory alignment for architectures with 128bit pointers * Mark XML_SetHashSalt deprecated ==== google-noto-fonts ==== Version update (20260901 -> 20261001) Subpackages: google-noto-sans-arabic-fonts google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Update to 20261001: * Sans Devanagari: - Remove incorrectly localized Nepali fixes (#62) - Improve rendering of U+0908 - Improve rendering of certain Nepali conjuncts - Improve Rakar U+094D and U+0930 for the Marathi language - Adjust some glyphs for Santali ==== hwdata ==== Version update (0.411 -> 0.412) - Update to 0.412: * pci.ids refreshed to the 2026.10.01 snapshot, 247 lines added and 19 removed * Six new vendor ids: 0168 Chengdu ZeoberCom (23 CPCI/PCI interface cards), 1ca5 Corerise Electronics (Comay SBC208 SCSI controller), 2159 AIC Semiconductor Shanghai, 215a Suzhou Ruixin (5 devices), and 215e SmarCo HT Tech and 2165 Dnotitia * AIC Semiconductor moved off the wrong vendor id a69c onto 2159, keeping its AIC8800M80X2P network controller * AMD entries renamed and added: Granite Ridge and Raphael now carry the Radeon 610M name, and GB100 [B200], GB203 [GeForce RTX 5070], GB20B [RTX Spark N1X], TB500 RP x16/x8/x4/x2/x1 and GR100/GR102 are new * Broadcom/LSI gained two SAS9300-16e Fibre Channel ids; the 1107 WCN785x entry is renamed NCM8x5/WCN785x * usb.ids, pnp.ids, iab.txt and oui.txt are unchanged ==== libpng16 ==== Version update (1.6.58 -> 1.6.59) Subpackages: libpng16-16 libpng16-16-x86-64-v3 - version update to 1.6.59: * Fixed CVE-2026-46675 (medium severity): Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression. (Reported independently by Ze Sheng and .) * Fixed a regression introduced in version 1.6.47 that caused libpng to reject hIST chunks in their correct position, after PLTE. (Contributed by Yuki Sekiguchi.) * Prevented a double free of `png_struct` members after an allocation failure. (Contributed by Anthony Hurtado.) * Applied fixes and updates to the CMake build. * Adopted the REUSE Specification for licensing the CI files. - fixes CVE-2026-46675 [bsc#1283183] ==== libstorage-ng ==== Version update (4.5.355 -> 4.5.359) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Dutch) (bsc#1149754) - 4.5.359 - Translated using Weblate (Catalan) (bsc#1149754) - 4.5.358 - Translated using Weblate (Japanese) (bsc#1149754) - 4.5.357 - merge gh#openSUSE/libstorage-ng#1097 - updated pot and po files - 4.5.356 ==== libupnp ==== Version update (22.1.7 -> 22.1.8) Subpackages: libixml22 libupnp22 - Update to release 22.1.8 * Cap the MX header of an incoming SSDP M-SEARCH request at 5 seconds [GHSA-8pj8-vmhq-qwvj] * Fix denial of service of the miniserver worker threads by connections that send nothing [GHSA-hwrm-c56x-fj22] * Fix a path traversal in the web server on Windows [GHSA-f8rh-7wq7-v4m7] ==== perl-XML-Twig ==== Version update (3.540.0 -> 3.550.0) - updated to 3.550.0 (3.55) see /usr/share/doc/packages/perl-XML-Twig/Changes 3.55 2026-10-01 minor maintenance release - added Scalar::Util as a dependency - improved some tests - minor bug fixes see https://github.com/mirod/xmltwig/issues/47 bsc#1282902 see https://github.com/mirod/xmltwig/issues/46 ==== python-urllib3 ==== Version update (2.7.0 -> 2.8.0) - Update to 2.8.0: [#] Security - The TLS configuration for HTTPS proxies could be ignored or overridden. (bsc#1283908, CVE-2026-97687) - ``HTTPResponse.stream()`` and ``read_chunked()`` could buffer a chunk-size line of unbounded length in memory. (bsc#1283910, CVE-2026-97689) - Chunked Deflate streaming could enter an infinite loop. (bsc#1283909, CVE-2026-97688) [#]# caution urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. Configure proxy CA certificates and client certificates in ``proxy_ssl_context``, and proxy identity checks with ``proxy_assert_hostname`` or ``proxy_assert_fingerprint``. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. [#] Deprecations & Removals - Deprecated using an empty collection as the ``Retry`` option ``allowed_methods`` to retry any verb. [#] Features - Added ``Url.auth_decoded`` and ``Url.auth_decoded_joined`` convenience properties to the result of ``parse_url()``. - Added ``basic_auth_encoding`` and ``proxy_basic_auth_encoding`` parameters to ``urllib3.util.make_headers()``. [#] Bugfixes - Fixed response header handling to replace obsolete folded header lines (`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as ``Set-Cookie``. - Fixed usage of ``proxy_ssl_context`` with ``ProxyManager`` when ``use_forwarding_for_https=True``. Passing ``ssl_context`` instead of ``proxy_ssl_context`` for HTTPS proxies in this configuration now emits a ``FutureWarning`` and will raise an error in v3.0. - Changed behavior of the default ``ConnectionPool.pool`` initialization. ``LifoQueue`` is now resolved from the ``queue`` module after the ``ConnectionPool`` is instantiated instead of using the default cached ``QueueCls`` class property. This is done because sometimes the ``queue.LifoQueue`` is monkey-patched late in the program, such as by gevent. - Raised ``UnrewindableBodyError`` instead of ``ValueError`` when retrying a request whose body had ``tell()`` but not ``seek()``. - Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. - Fixed ``HTTPResponse.drain_conn()`` to discard unread response data in 64 KiB chunks (same as the default ``amt`` when doing ``HTTPResponse.stream(...)``). - Fixed ``is_ipaddress()`` to detect non-standard IPv4 forms accepted by ``socket.connect``, such as hex (``0x7f000001``), octal (``0177.0.0.1``), and decimal integers (``2130706433``), ensuring SSL certificate verification uses the correct mode for these addresses. - Fixed ``HTTPConnectionPool.urlopen`` raising a misleading ``FullPoolError`` instead of ``ValueError`` when called with an invalid ``timeout`` argument on a pool created with ``block=True``. - Fixed port-zero handling to preserve explicit ``:0`` values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, ``connection_from_url()``, and HTTP/2 request authority. - Fixed a bug where ``PoolManager`` passed the ``assert_hostname`` and ``assert_fingerprint`` parameters to HTTP connection pools. - Fixed ``HTTPConnectionPool.urlopen()`` and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. - Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. - Fixed ``HTTPSConnection.connect()`` overriding ``ProxyConfig.ssl_context``'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy. ``HTTPSConnection`` no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ``ssl_context`` as a fallback when an HTTPS proxy forwards an HTTP target. - Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. - Fixed an ``AttributeError`` on Python built with OpenSSL 4+, where ``ssl.PROTOCOL_TLSv1`` no longer exists. - Fixed ``urllib3.contrib.pyopenssl`` to use cryptography APIs when reading a certificate subject and loading encrypted private keys, avoiding ``DeprecationWarning`` raised by pyOpenSSL 26.3.0+. - Fixed handling of HTTP 303 redirects for requests with chunked or file-like bodies. - Fixed ``assert_fingerprint()`` to raise ``SSLError`` instead of ``binascii.Error`` when a fingerprint has a supported length but ... changelog too long, skipping 9 lines ... - Fixed flaky tests. ==== selinux-policy ==== Version update (20260928 -> 20261002) Subpackages: selinux-policy-targeted - Update to version 20261002: * Allow gnome-remote-desktop use kerberos * Allow gnome-remote-desktop read password files * Add new interfaces for rhc-worker-playbook * Allow virtqemud getattr fuse filesystem conditionally * Allow cloud-init the setgid capability * Allow bootupd read proc dirs * Allow bootupd read /proc/swaps * Allow login_userdomain dbus chat with power-profiles-daemon * Allow icecast create and use unix dgram sockets * Allow systemd-coredump send a null signal to unconfined services * Allow samba_dcerpcd_t signull smbd_t * Make post-te statement extraction tolerant of leading whitespace * Allow login/pam_systemd started by kmscon to access env vars * Allow sshd-session tcp connect to all reserved ports * Allow sshd-session connect to vnc port * Allow sshd-session transition on passwd execution * Allow dhcpc-hook get init status * Allow kmscon read systemd_ssh_issue PID files * Rearrange kmscon policy to comply with formatting rules * Allow kmscon signal init * Allow systemd-timedated read network sysctls * Add CI check for whitespace on pull requests * Remove commented-out interface calls * Fix whitespace across all policy modules * Move systemd_read_userdbd_runtime_sock_files() to another optional block * Use udev_manage_pid_lnk_files() instead of direct reference - Syncing with upstream rawhide selinux-policy up to: * f52a7800ecaecff7a39f95cd1b89b686daf6729b