Packages changed: MicroOS-release (20261007 -> 20261008) cantarell-fonts (0.303.1 -> 0.311) ffmpeg-8 (8.1.2 -> 8.1.3) gstreamer-plugins-bad harfbuzz (14.5.1 -> 14.6.0) highway mozilla-nss (3.128 -> 3.129) polkit-default-privs (1550+20260928.d1c0e7e -> 1550+20261007.d5bf5b4) qemu (11.1.1 -> 11.1.2) unzip util-linux (2.42.3 -> 2.42.4) util-linux-systemd (2.42.3 -> 2.42.4) xdg-desktop-portal xterm (410 -> 411) === Details === ==== MicroOS-release ==== Version update (20261007 -> 20261008) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== cantarell-fonts ==== Version update (0.303.1 -> 0.311) - Update to version 0.311: + Also provide a ss01 variant for the "fl" ligature, which I forgot in the last release. + Relax Python version requirements to >= 3.10 when using uv. - Changes from version 0.310: + Extend ss01 to all lowercase 'l' characters and add a feature name. + Improve autohinting of 'я' and disable autohinting for 'Ф' because it rendered badly. + Static fonts will now have PANOSE values. They're incomplete, but better than nothing. + The VF will carry a name ID 25 to help e.g. Adobe apps tell it apart from the statics. Maybe it also helps other apps. + Implement soft-dotting for more glyphs. + Remove unreachable glyphs from font, lightening them by a few bytes. + Updated translations. - Call %meson_test in %check section: there are currently no tests defined yet though. ==== ffmpeg-8 ==== Version update (8.1.2 -> 8.1.3) Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Update to release 8.1.3 * More robust parsing of formats - Delete ffmpeg-8-CVE-2026-58049.patch, ffmpeg-8-CVE-2026-64833.patch, ffmpeg-8-CVE-2026-64834.patch, ffmpeg-8-CVE-2026-65703.patch, ffmpeg-8-CVE-2026-65704.patch, ffmpeg-8-CVE-2026-65705.patch, ffmpeg-8-CVE-2026-65706.patch, ffmpeg-8-CVE-2026-66037.patch, ffmpeg-8-CVE-2026-70628.patch, ffmpeg-8-CVE-2026-70629.patch, ffmpeg-8-CVE-2026-70630.patch, ffmpeg-8-CVE-2026-70631.patch, ffmpeg-8-CVE-2026-70632.patch, ffmpeg-8-CVE-2026-75141.patch, ffmpeg-8-CVE-2026-75142.patch, ffmpeg-8-CVE-2026-75143.patch, ffmpeg-8-CVE-2026-75144.patch, ffmpeg-8-CVE-2026-75145.patch, ffmpeg-8-CVE-2026-75146.patch, ffmpeg-8-CVE-2026-75147.patch, ffmpeg-8-CVE-2026-66036-shim01.patch (merged) - Delete ffmpeg-8-CVE-2026-66036.patch (feature patch not accepted upstream for 8.x) - Enable apv encoder support, add pkgconfig(oapv) BuildRequires and pass enable-liboapv to configure. - Add 0001-avcodec-liboapvenc-fix-build-with-openapv-1.1.patch ==== gstreamer-plugins-bad ==== Subpackages: libgstphotography-1_0-0 libgstplay-1_0-0 - Add pkgconfig(libfreeaptx) BuildRequires and stop passing openaptx=disable to meson setup, build aptx support. Also drop the conditional pkgconfig(libopenaptx) BuildRequires. ==== harfbuzz ==== Version update (14.5.1 -> 14.6.0) Subpackages: libharfbuzz-gobject0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.6.0: * Fix shaping failures caused by out-of-range glyph IDs, a regression from * Update experimental beyond-64k support to the final ISO Open Font Format 5th edition. This support remains disabled by default. * Add support for the `DMAP` table. * Support `FeatureVariations` 1.1 lookup variations, including subsetting and instancing. * Update `VARC` to the revised variation-store format. The new format is incompatible with the previous one. * Various `VARC` fixes. * Fix background color and stride handling in the experimental raster library. * Improve the experimental Rust shaper (HarfRust) and font functions (`fontations`), and update HarfRust to 0.14. * Various subsetting fixes and improvements. * Various fixes for malformed fonts. * Various build and CI fixes. ==== highway ==== - Disable LTO for aarch64 as a Workaround for "error: this operation requires the SVE ISA extension" ==== mozilla-nss ==== Version update (3.128 -> 3.129) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs - update to NSS 3.129 * bmo#2068788 - emit static library names during static build. * bmo#2067434 - avoid building libcrux twice in makefile builds. * bmo#2068010 - fix non-linux arm64 makefile builds. * bmo#2017322 - set CKA_NSS_SERVER_DISTRUST_AFTER for CN=Izenpe.com. * bmo#2057185 - Document ./mach try and its Mercurial-only caveat in CLAUDE.md. * bmo#2056793 - Add tests for concurrent channel info queries during session replacement. * bmo#2056793 - take the session cache lock when reading ss->sec.ci.sid. * bmo#2066046 - Fix a race in STAN_GetNSSCertificate. * bmo#2066591 - Remove write-only blLib and libraryName statics from freebl's lowhash_vector. * bmo#2025246 - fix unknown key error type in ssl_SetAuthKeyBits. * bmo#2065879 - re-vendor HACL* and simplify run_hacl.sh. * bmo#2065879 - stop clang-formatting the vendored HACL* code. * bmo#2068191 - add --dry-run to mach try to print job list. * bmo#2029288 - avoid integer overflow in PK11_BlockData. * bmo#2066960 - fix UB in ecperf.c. * bmo#2067239 - Old coverity issues. * bmo#2067237 - MLKEM mechinfo needs keys sizes. * bmo#2066900 - pin NSPR 4.40 in CI. * bmo#2066266 - ML-KEM-1024 incorrectly allows an explicit encapsulation seed. * bmo#2066265 - Support for ML-KEM-512 in freebl and softoken. * bmo#2060316 - remove support for pre-standard Kyber. * bmo#2065423 - Build NSPR out of tree, into the dist directory. * bmo#2065423 - Write a machine-readable summary.json for each test run. * bmo#2065423 - Fail test runs on UBSan errors and on core dumps in debug builds. * bmo#2065423 - Link tests_results/latest at the newest test run. * bmo#2065423 - Resolve ssl_gtest_db.sh against QADIR. * bmo#2065423 - Generate nss.pc and nss-config into the dist directory. * bmo#2065423 - Add a --dist option to build.sh. * bmo#2065219 - Update Cryptofuzz version. * bmo#2056790 - Use PK11 digest contexts for explicit hashing in cryptohi. - rebased add-relro-linker-option.patch and nss-fips-constructor-self-tests.patch ==== polkit-default-privs ==== Version update (1550+20260928.d1c0e7e -> 1550+20261007.d5bf5b4) - Update to version 1550+20261007.d5bf5b4: * profiles: add gnome-remote-desktop use-grd-pcscd action (bsc#1276523) ==== qemu ==== Version update (11.1.1 -> 11.1.2) - Update to latest stable release (11.1.2) Full backport list here: https://lore.kernel.org/qemu-devel/20260929144512.126747-1-mjt@tls.msk.ru/ A selection of them is reported here below: target/sh4: Replace TB_FLAG_GUSA_EXCLUSIVE with CF_STEP_ATOMIC accel/tcg: Set CF_NOIRQ during cpu_exec_step_atomic linux-user/sh4: align the vdso sigreturn trampolines linux-user/sh4: fix vdso CFA for rt_sigreturn frames linux-user/sh4: use the kernel's sigreturn trampoline sequence in the vdso target/i386: Mark MOVNTI as not valid with prefixes 0x66, 0xF2, 0xF3 target/i386: Update FPU tag word for FXCH target/i386: Update FPU tag word for FSTP target/i386: Update FPU tag word for FXTRACT's old ST(0) target/i386: Fix FXCH to unconditionally clear C1 target/ppc: Stop vCPU thread before calling parent_unrealize tests/qtest/usb-hcd-xhci: test isoch endpoint type mismatch tests/qtest/usb-hcd-xhci: test isoch pacing with MFINDEX above 2^32 hw/usb/hcd-xhci: don't assert on NAK when retrying an isoch transfer hw/usb/hcd-xhci: fix interval alignment after MFINDEX passes 2^32 hw/usb/hcd-xhci: Set reentrancy guard in timer functions (CVE-2026-17588) tcg/riscv64: Set vtype before whole-register vector loads tests/tcg/s390x: Add regression test for #4449 tcg/optimize: Fix expansion/simplification of deposit tests/tcg/arm: Add regression test for #4448 tcg/optimize: Fix fold_multiply2 vs 1 accel/tcg: Fix TLB_MMIO check in tlb_plugin_lookup() accel/tcg: Use TLB_FORCE_SLOW not TLB_MMIO for system plugins hw/9pfs: mutate FID path from main thread only (CVE-2026-93834) s390x/pci: fix DMA slot leak on I/O TLB entry replacement hw/s390x/ipl: Fix incorrect PCI IPL block lengths linux-user/loongarch64: Detect vector stores in host_signal_write() linux-user: implement mlock2(2) syscall linux-user/riscv: honor zicntrúlse for base counterCSRs system/ram-discard-manager: fix offset_within_address_space in replay_by_populated_state() igvm: mark qigvm_find_param_entry as static igvm: validate and honor byte_offset in parameter directives hw/uefi: add missing uefi_str_is_valid check to uefi_vars_mm_lock_variable target/loongarch: Fix data race in CSR_ESTAT hw/riscv/virt.c: fix aclint soc/mtimer nodename target/arm/hvf: implement MDCCSR_EL0 as RAZ target/arm/whpx: fix whpx-arm post-reset CPU state target/arm/whpx: incorrect ENCODE_AA64_CP_REG parameter order target/arm/whpx: Don't try to sync ARM_CP_CONST registers hw/intc/bcm2835_ic: reject out-of-range FIQ source values qga: Change effective user/group ID in guest-ssh-* commands vhost-user-gpu: validate command buffer size in submit_3d ui/cursor: make the cursor refcount atomic hw/display/qxl: hold ssd.lock while replacing ssd.cursor hw/cxl: fix the CDAT DOE overlapping the Flex Bus DVSEC when sn= is set virtio-scsi: set dataplane_started to false upon failure virtio-balloon: fix free-page BH teardown on unrealize hw/virtio: reject inverted virtio-iommu IOVA ranges hw/net/virtio-net: strip trailing padding when caching RSC segment hw/net/virtio-net: check packet size before VLAN tag access in receive_filter() qapi/misc: Fix missed query-iothreads items hw/cxl: Fix guest-triggerable QEMU exit on reserved interleave ways virtio-gpu: clear res->blob on mapping cleanup ==== unzip ==== - Drop obsolete -fstack-protector from RPM_OPT_FLAGS (predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic) ==== util-linux ==== Version update (2.42.3 -> 2.42.4) Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - Update to version 2.42.4 (bsc#1274864, PED-16740): This release enhances previously released security fixes and adds protection against symlink attacks in the legacy mount(2)-based code in libmount. * lib/fileutils: * add safe FD-path and no-symlink helpers * fix RESOLVE_NO_SYMLINKS fallback value * libmount: * add mnt_fs_fetch_ids() and populate uniq_id for utab * use fchmodat2() for X-mount.mode= * restore the original namespace on error paths * secure the idmapped mount replacement * pin the legacy mount target and bind/move source * harden restricted mount targets and post-mount handling * fix X-mount.idmap ID names in code and man page * nsenter: close cgroup.procs fd after join to prevent authority leak [CVE-2026-78408, bsc#1278348] - Add two upstream follow-up fixes (util-linux-libcanonicalize-newline.patch, util-linux-wall-off-by-one.patch). - Fix uuidd tmpfiles installation path (bsc#1283294). - Mark two check known as failing in chroot environment. ==== util-linux-systemd ==== Version update (2.42.3 -> 2.42.4) Subpackages: lastlog2 liblastlog2-2 - Update to version 2.42.4 (bsc#1274864, PED-16740): This release enhances previously released security fixes and adds protection against symlink attacks in the legacy mount(2)-based code in libmount. * lib/fileutils: * add safe FD-path and no-symlink helpers * fix RESOLVE_NO_SYMLINKS fallback value * libmount: * add mnt_fs_fetch_ids() and populate uniq_id for utab * use fchmodat2() for X-mount.mode= * restore the original namespace on error paths * secure the idmapped mount replacement * pin the legacy mount target and bind/move source * harden restricted mount targets and post-mount handling * fix X-mount.idmap ID names in code and man page * nsenter: close cgroup.procs fd after join to prevent authority leak [CVE-2026-78408, bsc#1278348] - Add two upstream follow-up fixes (util-linux-libcanonicalize-newline.patch, util-linux-wall-off-by-one.patch). - Fix uuidd tmpfiles installation path (bsc#1283294). - Mark two check known as failing in chroot environment. ==== xdg-desktop-portal ==== - Update version dependencies according to meson.build. ==== xterm ==== Version update (410 -> 411) Subpackages: xterm-bin xterm-resize - update to 411: * add a case for DECSWT in VT520 mode * correct an index computation in VS15/VS16 logic for - emoji_width option * add ich1 to terminfo where appropriate. * drop “GTK_*” from environment filtering * fix a couple of places in terminfo which used BEL rather than ST. * add DECSCUSR 7 for the “power-up” configuration, which can be different from the documented VT520 behavior * correct a limit-check added in patch #399, which resulted in regex-based selections to be limited to the first row of a wrapped line (Redhat #2479962). * add resource brokenCopyArea, using that to control whether XCopyArea is used for indexing and scrolling, as well as inserting or deleting characters and lines. * amend check for validity of C1 controls to check both whether wide-characters have been initialized, as well as whether the current encoding is UTF-8 (Debian #687699). * call Cleanup directly when processing SIGHUP, because the process running in xterm may ignore a killpg sent to the top-level screen's process (Debian #243598).