Packages changed: emacs-compat (31.0.0.1 -> 31.0.0.2) emacs-jinx (2.8 -> 2.10) flatpak (1.18.0 -> 1.18.1) gdm gimp glibmm2_4 (2.66.9 -> 2.66.10) harfbuzz (14.3.0 -> 14.3.1) librsvg libxmlb microos-tools (4.0+git28 -> 4.0+git29) ncurses (6.6.20260808 -> 6.6.20260815) numlockx openSUSE-release (20260818 -> 20260819) pango (1.58.0 -> 1.58.2) patterns-media postfix (3.11.5 -> 3.11.6) python-hpack (4.1.0 -> 4.2.0) qt6-tools === Details === ==== emacs-compat ==== Version update (31.0.0.1 -> 31.0.0.2) - Update to version 31.0.0.2: * compat-31: Fix extended function seconds-to-string. ==== emacs-jinx ==== Version update (2.8 -> 2.10) - Update to version 2.10: * Let-bind parse-sexp-lookup-properties to nil during Jinx tokenization. This avoids interference with the syntax-table property attached by some major modes like haskell-mode. * Rename CHANGELOG.org to NEWS.org - Changes from version 2.9: * New command jinx-remove-word to remove words from personal dictionary, file local variable, and so on. * New customizable variable jinx-save-prop-line. ==== flatpak ==== Version update (1.18.0 -> 1.18.1) Subpackages: flatpak-remote-flathub flatpak-selinux libflatpak0 system-user-flatpak - Update to version 1.18.1: + Security fixes: - Fix sandbox escape with full host filesystem read/write access via symlink attack on app data directories (GHSA-8688-9x26-hhxj) - Fix local root privilege escalation via revokefs symlink path traversal and commit tampering (GHSA-qrwq-7qwx-q9rp) - Fix arbitrary root write via symlink and path traversal in extra-data extraction (GHSA-fqx6-vh4p-42cg) - Fix arbitrary root write via path traversal in `flatpak build-init` (GHSA-8qxj-x646-phcm) - Fix arbitrary host file read via hardlink path traversal in OCI archive extraction (GHSA-9rww-v4mm-x4jg) - Fix path traversal via unvalidated architecture parameter in DeployAppstream (GHSA-v2gw-v9h5-9q4x) - Fix buffer overflow in OCI delta stream path names on 32-bit systems (GHSA-jr92-2v97-wgvc) - Fix fixed-filename writes to arbitrary locations via symlink attack on .ld.so (GHSA-99wv-m8rp-g58x) - Fix extension metadata path traversal allowing host filesystem probing and unintended mount locations (GHSA-w69g-9x8j-7p8f) - Fix anti-downgrade bypass allowing unprivileged users to downgrade system apps (GHSA-q4gr-vc25-57m5) + Bug fixes: - Fix portal flatpak-spawn environment handling regression - Fix negated permission strings for allow and share run options - Fix build failure when exporting metainfo releases.xml files - Fix crashes in the portal update monitor and OCI JSON handling - Error out if file forwarding of empty paths is attempted - Check OCI signatures from the mirrored repo in the system helper instead of fetching from the lookaside server - Apply TLS certs to OCI registry requests and propagate stream write failures to curl - Fix GI annotation for flatpak_instance_get_all - Cleanup of Bash completion - Numerous internal fixes for crashes, error handling, and hardening ==== gdm ==== Subpackages: gdm-lang gdm-schema gdm-systemd gdm-xdm-integration libgdm1 typelib-1_0-Gdm-1_0 - Add gdm-fix-tty1-mode.patch: During system startup, tty1 is left in an invalid state, preventing it from being switched away from (bsc#1250688, bsc#1272490, bsc#1252888) - Drop gdm-initial-vt-tty1.patch: Fixed by gdm-fix-tty1-mode.patch ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - Add CVE fixes: + gimp-CVE-2026-59087.patch (bsc#1274809, glgo#GNOME/gimp#16491) + gimp-CVE-2026-59088.patch (bsc#1274837, glgo#GNOME/gimp#16492) + gimp-CVE-2026-59090.patch (bsc#1274840, glgo#GNOME/gimp#16509) + gimp-CVE-2026-59091.patch (bsc#1274851, glgo#GNOME/gimp#16510) ==== glibmm2_4 ==== Version update (2.66.9 -> 2.66.10) Subpackages: libgiomm-2_4-1 libglibmm-2_4-1 - Update to version 2.66.10: + Drop G_GNUC_CONST as in GLib. + Gio: Emblem and DBus::ActionGroup: Don't derive gtkmm__Gxxx types. The underlying C classes are final types since GLib 2.89.2. + Meson build: Use Meson's pkgconfig module instead of using the * .pc.in templates. - Update to version 2.66.9+3: + Gio::DBus::ActionGroup: Improve the test whether GDBusActionGroup is final + Drop G_GNUC_CONST as in glib + Gio: Emblem and DBus::ActionGroup: Don't derive gtkmm__Gxxx types - Use source service to generate tarball. - Add mm-common and perl-XML-Parser BuildRequries: Needed now that we are using a git checkout. - Pass maintainer-mode=true to meson setup, needed since we are using a git checkout. ==== harfbuzz ==== Version update (14.3.0 -> 14.3.1) Subpackages: libharfbuzz-gobject0 libharfbuzz-icu0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.3.1: + Various fuzzing and build fixes. + Various subsetting fixes. + Fix AAT insertion at the end of the text. + Fix various rendering bugs in the experimental GPU library. + WASM shaper code can now read the user features. ==== librsvg ==== Subpackages: librsvg-2-2 typelib-1_0-Rsvg-2_0 - Disable librsvg --test reference, failing with new pango 1.58.2 ==== libxmlb ==== Subpackages: libxmlb2 libxmlb2-x86-64-v3 - Add libxmlb-tests subpackage with installed tests for gnome-desktop-testing-runner ==== microos-tools ==== Version update (4.0+git28 -> 4.0+git29) - Update to version 4.0+git29: * Move man-online to an own sub-package ==== ncurses ==== Version update (6.6.20260808 -> 6.6.20260815) Subpackages: libncurses6 ncurses-utils terminfo terminfo-base terminfo-iterm terminfo-screen - Add ncurses patch 20260815 + improve tic warnings for paired capabilities, including ich/ich1. + use xterm+tmux2 in xterm+nofkeys to match xterm patch #407 -TD + use ST in xterm+osc104 -TD + use ansi+sc -TD + modify test/dup_field.c to also demonstrate link_field(). + work around use of ^D for exiting test/ncurses except in the form test which uses ^D for movement (patch by Branden Robinson). + improve appearance of test/dup_field and test/move_field, adding a help-hint (patches by Branden Robinson). + improve formatting/style of manpages (patches by Branden Robinson). + add limit-checks in lib_screen.c and lib_ins_wch.c in case a 2-cell character is added at the right-margin (report by Miroslav Lichvar). + improve limit-check for extended names in _nc_read_termtype (report/patch by Yeo Jooho). + improve description of init_extended_color in man page (patch by Andrew Burgess). + modify test/Makefile.in to fix "make check" when ncurses is built in a non-source tree (report by Bruno Haible). ==== numlockx ==== - Implement default NumLock state, uses KBD_NUMLOCK variable in /etc/sysconfig/keyboard using /run/numlock-on set by kbdsettings.service from kbd package (numlockx-sysconfig-default.patch). ==== openSUSE-release ==== Version update (20260818 -> 20260819) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== pango ==== Version update (1.58.0 -> 1.58.2) Subpackages: libpango-1_0-0 typelib-1_0-Pango-1_0 - Update to version 1.58.2: + Require harfbuzz 11 + Require glib 2.88 + CoreText: - Support variations - Support font features from descriptions + Renderer: Keep over/under/through lines in sync + Fixes for undefined behavior ==== patterns-media ==== Subpackages: patterns-media-rest_cd_core patterns-media-rest_dvd - Media rest_dvd: recommend sudo-policy-wheel-auth-self and openSUSE-repos-Tumbleweed, as they are referenced by the Agama installer. ==== postfix ==== Version update (3.11.5 -> 3.11.6) - update to 3.11.6 This release addresses medium-impact problems that need to be fixed as some enable remote DOS or policy bypass. * Bug (introduced: Postfix 2.2, date: 20041102): missing SMTP server resets of MAIL FROM and RCPT TO command state after smtpd_end_of_data_restrictions rejected a message. This resulted in SMTP protocol state desynchronization between the remote SMTP client and the Postfix SMTP server. A crafted remote SMTP client could then send RCPT TO and DATA without MAIL FROM, and deliver a second message. Then, smtpd_end_of_data_restrictions skipped check_recipient_access constraints, because a recipient counter was > 1. * Bug (defect introduced: Postfix 3.4, date: 20180805): SMTP server command history memory exhaustion with a large number of very small BDAT requests. * Bug (defect introduced: Postfix 1.1, date: 20021116): address verification cache poisoning. A local user could use the postdrop command to submit an address verification probe with envelope or message content that Postfix rejected later, resulting in a negative address verification cache entry for that address. On systems that enable address verification, the negative address verification cache entry would force the Postfix SMTP server to reject a message that it should accept (denial of service). * Bug (defect introduced: Postfix 3.4, date: 20180805): missing SMTP server reset of RCPT TO state, after a BDAT command error. A crafted remote SMTP client could then send a DATA command without MAIL FROM or RCPT TO, and crash a Postfix SMTP daemon process with a null pointer read error. * Bug (defect introduced: Postfix 2.4, date: 20051222): null pointer read crash while parsing a malformed Dovecot AUTH server response. * Bug (defect introduced: Postfix 2.8, date: 20100914): read-after-free in the PSC_CALL_BACK_NOTIFY() macro. This had no effect on program execution, because myfree() wiped memory, and that memory was not yet reused. * Read after free (no privilege escalation) in debug logging (defect introduced: Postfix 2.2, date: 20050117). * Bug (defect introduced: Postfix 2.10, date: 20120617): uninitialized memory read in postscreen HaProxy client after remote I/O exception, causing garbage to be logged. * Latent bug (defect introduced: Postfix 2.7, date: 20090618): uninitialized memory read after dnsblog(8) returns a string that is not an IPv4 address. * Bug (defect introduced: before Postfix alpha, date 19970424): the DNS client could read up to two bytes past the end of an MX record, before discovering that the record was too short. This behavior was later copied with SRV records, potentially over-reading up to six bytes. * Bug (defect introduced: Postfix 1,1, date: 20010524): the postsuper command under-read or over-read a very short queue filename. No crash, information leak, or privilege escalation. * Bug (defect introduced: before Postfix alpha, date: 19971106): 'int' over-shift, in the queue file record-length parser. Postfix programs do not generate such records, but an attacker could cause postdrop to reject input or panic(). * Bug (defect introduced: Postfix 2.2, date: 20050117): non-transitive comparison of IPv4 addresses. * Bug (defect introduced: Postfix 1.0, date: 20000928): the fast flush server, used by the SMTP command "ETRN", and by the commands "postqueue -s site" and "postqueue -i queue_id" (and their sendmail(1) equivalents), used the wrong duplicate suppression API, resulting in unnecessary queue scans by the queue manager. * Queue hygiene: the postdrop command accepted the null record type which the rest of Postfix ignores. ==== python-hpack ==== Version update (4.1.0 -> 4.2.0) - Update to 4.2.0 (fixes boo#1275232 and CVE-2026-59980) * Support for Python 3.9 has been removed. * Support for PyPy 3.9 has been removed. * Support for Python 3.14 has been added. * Headers marked as sensitive will no longer log their value at DEBUG level. Instead a placeholder value of SENSITIVE_REDACTED is logged. * Fixed perfect match missed for headers with empty values. * Restricted variable integer decoding to uint32 to prevent run-away computation. With thanks to Hiroki Nishino. ==== qt6-tools ==== Subpackages: libQt6Designer6 libQt6UiTools6 qt6-tools-qdbus - Add patch to make documentation more reproducible (QTBUG-145807): * 0001-QDoc-Use-deterministic-tiebreaker-for-shared-notifie.patch