Packages changed: MicroOS-release (20261005 -> 20261007) aardvark-dns (2.0.0 -> 2.1.0) bluez glibc kernel-source (7.2.8 -> 7.2.9) libcontainers-common (20260521 -> 20260915) netavark (2.0.0 -> 2.1.0) passt (20260612.a9c61ff -> 20261002.cba3570) podman (6.0.2 -> 6.1.2) python-Mako (1.4.1 -> 1.4.3) python-dbus-python python-idna (3.19 -> 3.20) python-pycairo (1.29.1 -> 1.29.2) rebootmgr (3.3+git20250722.adf0149 -> 4.0+git20261005.1e5481c) samba (4.24.6+git.488.e38f6c96c62 -> 4.25.0+git.473.e78e78fbf4) selinux-policy (20261002 -> 20261006) vim === Details === ==== MicroOS-release ==== Version update (20261005 -> 20261007) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== aardvark-dns ==== Version update (2.0.0 -> 2.1.0) - Update to version 2.1.0: * Dependency updates ==== bluez ==== Subpackages: bluez-cups libbluetooth3 - Add a2dp-fix-loading-of-remote-SEP-from-cache.patch Without this, Pipewire forces AVDTP Discover on every reconnect, causing codec negotiation failures on some LE Audio headsets. * Upstream issue: https://github.com/bluez/bluez/issues/2321 * Upstream commit: https://github.com/bluez/bluez/commit/b7d71e5067856b0daf2f1f73b3fc95483236610e ==== glibc ==== Subpackages: glibc-locale glibc-locale-base - resolv-search-list-trunc.patch: resolv: Fix assertion failure on search list truncation (CVE-2026-8674, bsc#1281297, BZ #31026) - elf-origin-open-normalized.patch: elf: Open the normalized $ORIGIN rpath in AT_SECURE programs (CVE-2026-86805, bsc#1282509, BZ #34360) - power8-strncasecmp-overread.patch: powerpc: Fix one byte overread in strncasecmp (CVE-2026-97399, bsc#1283147, BZ #34683) - realloc-mmap-non-mremap.patch: realloc: Fix mmap non-mremap reallocation case (BZ #34697) ==== kernel-source ==== Version update (7.2.8 -> 7.2.9) - Update patches.kernel.org/7.2.6-0018-smb-server-fix-tree-connection-leak-in-smb2_tr.patch (bsc#1012628 CVE-2026-98162 bsc#1283790). - Update patches.kernel.org/7.2.6-0022-nvdimm-pmem-keep-PREFLUSH-before-data-writes.patch (bsc#1012628 CVE-2026-98161 bsc#1283791). - Update patches.kernel.org/7.2.6-0235-staging-rtl8723bs-fix-mismatched-free-of-HalDa.patch (bsc#1012628 CVE-2026-98160 bsc#1283276). - Update patches.kernel.org/7.2.6-0392-firmware-arm_scmi-Publish-channel-state-before.patch (bsc#1012628 CVE-2026-93093 bsc#1284062). - Update patches.kernel.org/7.2.6-0394-firmware-arm_scmi-Quiesce-notifications-before.patch (bsc#1012628 CVE-2026-93091 bsc#1284033). - Update patches.kernel.org/7.2.6-0395-firmware-arm_scmi-Clean-up-channels-on-setup-f.patch (bsc#1012628 CVE-2026-93090 bsc#1284032). - Update patches.kernel.org/7.2.6-0396-firmware-arm_scmi-Free-transport-channel-on-ID.patch (bsc#1012628 CVE-2026-93089 bsc#1284031). - Update patches.kernel.org/7.2.6-0397-firmware-arm_scmi-Avoid-IDR-updates-while-clea.patch (bsc#1012628 CVE-2026-93086 bsc#1284024). - Update patches.kernel.org/7.2.7-002-wifi-mt76-mt7921-validate-CLC-firmware-records.patch (bsc#1012628 CVE-2026-98159 bsc#1283416). - Update patches.kernel.org/7.2.7-005-ppp_async-drop-the-errored-frame-instead-of-res.patch (bsc#1012628 CVE-2026-98158 bsc#1283933). - Update patches.kernel.org/7.2.7-011-EDAC-device_sysfs-Use-kstrtouint-for-poll_msec-.patch (bsc#1012628 CVE-2026-98157 bsc#1283792). - Update patches.kernel.org/7.2.7-013-drm-virtio-use-the-DMA-API-for-resource-backing.patch (bsc#1012628 CVE-2026-98156 bsc#1283982). - Update patches.kernel.org/7.2.7-014-accel-qaic-Address-potential-out-of-bounds-read.patch (bsc#1012628 CVE-2026-98155 bsc#1283288). - Update patches.kernel.org/7.2.7-015-nvme-rdma-fix-EIO-cleanup-order-in-queue_rq.patch (bsc#1012628 CVE-2026-98154 bsc#1283418). - Update patches.kernel.org/7.2.7-018-nvme-fix-racy-access-to-FDP-placement-id-array.patch (bsc#1012628 CVE-2026-98153 bsc#1283800). - Update patches.kernel.org/7.2.7-019-nvmet-rdma-fix-queue-leak-when-connect-backlog-.patch (bsc#1012628 CVE-2026-98152 bsc#1283755). - Update patches.kernel.org/7.2.7-023-bpf-Fix-REG-INVARIANTS-VIOLATION-on-speculative.patch (bsc#1012628 CVE-2026-98151 bsc#1283801). - Update patches.kernel.org/7.2.7-024-bpf-Fix-BPF_F_CPU-validation-for-sparse-CPU-IDs.patch (bsc#1012628 CVE-2026-98150 bsc#1283419). - Update patches.kernel.org/7.2.7-025-bpf-Fix-percpu-map-update-indexing-with-sparse-.patch (bsc#1012628 CVE-2026-98149 bsc#1283420). - Update patches.kernel.org/7.2.7-027-drm-gud-validate-GUD_ROTATION_0-is-present-in-s.patch (bsc#1012628 CVE-2026-98148 bsc#1283421). - Update patches.kernel.org/7.2.7-028-printk-Don-t-WARN-on-kthread_run-failure.patch (bsc#1012628 CVE-2026-98147 bsc#1283799). - Update patches.kernel.org/7.2.7-030-accel-amdxdna-reject-a-command-chain-that-carri.patch (bsc#1012628 CVE-2026-98145 bsc#1283422). - Update patches.kernel.org/7.2.7-031-accel-amdxdna-put-the-chained-BO-when-its-mappi.patch (bsc#1012628 CVE-2026-98144 bsc#1283423). - Update patches.kernel.org/7.2.7-034-accel-ethosu-Don-t-read-the-U65-rounding-mode-a.patch (bsc#1012628 CVE-2026-98143 bsc#1283430). - Update patches.kernel.org/7.2.7-036-drm-cirrus-qemu-Validate-BAR0-size-during-probe.patch (bsc#1012628 CVE-2026-98142 bsc#1283819). - Update patches.kernel.org/7.2.7-038-ntfs-propagate-reparse-index-insertion-failure.patch (bsc#1012628 CVE-2026-98141 bsc#1283431). - Update patches.kernel.org/7.2.7-042-ntfs-fix-kmap_local-leak-in-write_mft_record_no.patch (bsc#1012628 CVE-2026-98140 bsc#1283417). - Update patches.kernel.org/7.2.7-043-ntfs-only-count-successfully-cleared-runs-when-.patch (bsc#1012628 CVE-2026-98139 bsc#1283433). - Update patches.kernel.org/7.2.7-045-ntfs-do-not-mark-the-volume-clean-in-sync_fs-wh.patch (bsc#1012628 CVE-2026-98138 bsc#1283440). - Update patches.kernel.org/7.2.7-046-ntfs-treat-any-nonzero-dio-zero-range-return-as.patch (bsc#1012628 CVE-2026-98137 bsc#1283441). - Update patches.kernel.org/7.2.7-047-ntfs-bound-AttrDef-table-walk-to-the-loaded-tab.patch (bsc#1012628 CVE-2026-98136 bsc#1283442). - Update patches.kernel.org/7.2.7-048-ntfs-reject-invalid-sectors_per_cluster-in-the-.patch (bsc#1012628 CVE-2026-98135 bsc#1283434). - Update patches.kernel.org/7.2.7-049-bpf-check_cond_jmp_op-properly-infer-if-registe.patch (bsc#1012628 CVE-2026-98134 bsc#1283839). ... changelog too long, skipping 1926 lines ... - commit f0bad6b ==== libcontainers-common ==== Version update (20260521 -> 20260915) Subpackages: libcontainers-default-policy registries-conf-default - New release 20260915 * bump bundled c/common to 0.69.2 ==== netavark ==== Version update (2.0.0 -> 2.1.0) - Update to version 2.1.0: * Allow isolated networks to access published ports on other networks when trying to connect to them via the host port. * Fixed a network teardown problem when the netns is not accessible to still do as much as we can, i.e. remove firewall rules. * Fixed a network teardown ordering problem, the bridge interface is now removed after the firewall rules to avoid routing issues. * Dependency updates. ==== passt ==== Version update (20260612.a9c61ff -> 20261002.cba3570) Subpackages: passt-selinux - Drop qrap from %files, removed upstream - Update to version 20261002.cba3570: * tcp: Don't fast re-transmit if only our FIN is outstanding * apparmor: Fixes for new user namespace detaching procedure * util: Make setting uidmap and gidmap errors non-fatal * selinux: Allow passt to use setgid and setuid capabilities in namespace * apparmor: allow netns paths on /tmp again * udp: Add missing @now parameter doc to udp_flow_from_tap() * apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only * pasta: Add --no-pidns to keep spawned command in caller's PID namespace * contrib/apparmor: add missing setfcap capability * vhost_user: Reset vq enable flag in vu_cleanup() * Add Zed editor settings * util, pasta: Remove some unneeded #includes * util: Add missing O_CLOEXEC for !HAS_GETRANDOM path * util: Eliminate a stray trailing whitespace * clangd: Add _GNU_SOURCE to default clangd options * udp_flow: Remove obsolete comment * parse: Convert parse_mac() to conventions of parse.c * isolation: Don't create our userns as nobody * isolation: Create helper function to enter user namespace * util, pasta: Generalise [ug]id_map creation * pasta: Include pasta.h in pasta.c * netlink: Don't warn about multiple interfaces when there's only one * isolation: Include linux_dep.h for close_range() * fwd: Don't log warnings when failing to bind "weak" ports, just debug messages * treewide: Sandbox qrap * conf, fwd: Prefer same-scope address as inbound source address from host * conf: Honour --address, --gateway, --netmask in local mode as well * pasta: Regression test for bug 216 * pasta: Do not configure ID mappings when invoked with --netns-only * pif: Add message to static_assert for C11 compliance, fix build with gcc 8 * udp, icmp: Remove unused timer_run fields from protocol contexts * main: Ensure fds 0-2 are populated * isolation: Move --fd descriptor to a number of our choosing * conf: Make conf_tap_fd() operate more like conf_mode() * isolation, conf: Set c->fd_tap from early parse of --fd * isolation: Move close_open_files() to isolate_fds() * passt: Always close pidfile_fd, not just when daemonizing * tap: Fix EAGAIN/EWOULDBLOCK check in tap_pasta_input() * passt.1, pesto.1: ::1 is an address, not a port * dhcp: Make option parsing more robust, explicitly handle options 0 and 255 * CONTRIBUTING.md: The tag is "Link:", regardless of how many we have * udp_vu: Check iov_tail_clone() return before assigning to msg_iovlen * passt: Initialise listening socket fds to -1 * fwd: Don't rewrite inbound multicast destinations * fwd: Reorder DNAPT and SNAT steps in fwd_nat_from_host() * fwd: Rework default address logic for inbound flows * udp: Validate that we have a unicast source address * fwd: Clarify semantics of --host-lo-to-ns-lo * dhcpv6: Fix reply destination to match client's source address * selinux: Access to netns for podman-build, read access for netns in general * isolation: Add --chroot-fallback option * fwd, fwd_rule: Implement configurable target address mapping * fwd_rule: Parse target addresses for forwarding rules * fwd_rule: Rewrite forward rule parsing using parse.c helpers * fwd_rule: Allow "all" port specs to be combined with other options * conf: Use new parsing tools to handle -a option * conf: Remove unnecessary mode checks from conf_addr() * conf: Move address configuration into helper function * parse: Add helpers for parsing IP addresses * parse: Move parse_port_range() to new parsing framework * parse: Add helper to parse unsigned integer values * conf: Clean up conf_ip4_prefix() * conf: Remove duplicate parsing of -F option * parse: Start splitting out parsing helpers * conf: Use parameter instead of global in conf_nat() * Makefile: Add missing PESTO_HEADERS variable * udp: Improve messages for errors getting errors * flow, treewide: Promote priority of selected flow-linked messages * flow, udp: Fix errno handling in udp_flow_sock() * flow: Include flow details with higher priority log messages * flow: Indent flow details messages * flow: Regularise flow specific logging helpers * tap: don't let overheard traffic move addr_seen when address is explicit * tap: Trim Ethernet padding from short IPv4 frames instead of dropping them * inany: Fix doc comment to match u32 field, not u64 * pif, util: Move listen(2) call from sock_l4_() to pif_listen() * fwd, pif: Remove duplicated logic between tcp_listen() and udp_listen() * Makefile: Remove unused DUAL_STACK_SOCKETS define * flow: Correct misleading signature of flowside_sock_l4() * tcp: MAX_WINDOW should be unsigned * tcp: Avoid SEQ_*() comparisons against 0 * tcp: Merge common sequence logic from tcp_{buf,vu}_data_from_sock() * cppcheck: Add workaround for cppcheck bug 14847 * cppcheck: Remove unused CPPCHECK_6936 ==== podman ==== Version update (6.0.2 -> 6.1.2) - Update to version 6.1.2: * address CVE-2025-11395 where importing images containing crafted layer tarballs with the `podman load` command, or importing volumes containing crafted symlinks with `podman volume import`, allows overwriting files on the host * address CVE-2026-79699 and CVE-2026-79705 * address CVE-2026-17106, where a crafted tar archive could write outside the extraction directory through the use of malicious links * Fixed broken rootlessport bind behavior with `-p 0.0.0.0:... -p [::]:...` which failed instead of binding both v4 and v6 separately. * new command: `podman volume rename` + allow renaming volumes. Volumes created using volume drivers and volumes that are currently used by a container cannot be renamed * new command: `podman machine restart` + allow easy restart of VMs managed by `podman machine` * command `podman network rm` now includes option `--ignore` + suppresses errors when attempting to remove networks that do not exist * command `podman manifest push` now includes options `--retry` and `--retry-delay` + allow pushes to be automatically retried on failure * Quadlet `.container` units now support key `ImageVolume=` to configure how volumes from images are handled * command `podman generate kube` now includes support for generating container healthchecks as a `livenessProbe` * container.conf: new option `force_port_listen` * command `podman info` now additionally includes free memory available on the host * Pesto rootless port forwarding tool now supports IPv6 port forwarding with source IP preservation * Fixed a bug where the remote Podman client could hang on some operations when connecting to a remote Podman service over SSH * Fixed a bug where the `podman image scp` command could not be used with usernames containing an `@` character * Fixed a bug where the `podman kube play` command did not properly validate requested `hostPort` bindings, allowing the creation of containers with duplicated host ports which would never be able to start at the same time * Fixed a bug where the `podman quadlet list` and `podman quadlet rm` commands did not function properly with uninstantiated template Quadlets. * Fixed a bug where the `podman quadlet install` command would occasionally fail to install a Quadlet if non-quadlet files were specified. * Fixed a bug where the `podman quadlet install` command would not refuse to install Quadlets including non-quadlet files if the `--application` option was not specified. * Fixed a bug where healthcheck logs could be corrupted, preventing proper healthcheck operation, if a healthcheck was killed midway through writing the file. * Fixed a bug where the `podman volume prune --all` command incorrectly discarded label filters, causing `podman volume prune --all --filter label=foo` to prune all volumes, not just those with the `foo` label. * Fixed a bug where the `podman events --format=json` command would print `null` instead of an error when the server sent an event that could not be decoded. * Fixed a bug where a race condition could cause Quadlet to generate corrupt systemd units * Fixed a bug where the `podman inspect` command on a container with a single-element command (e.g. `podman run fedora bash`) would include the command in both `Path` and `Args`, when it should only have been included in `Path` * Fixed a bug where the `--format` option to `podman inspect` on containers did not properly support some format specifiers supported by Docker (e.g. `{{.HostIp}}` did not work, but `{{.HostIP}}` did) * Fixed a bug where the Quadlet generator would not write error messages to `STDERR` but only to `/dev/kmsg`, meaning that errors were not visible from `systemd-analyze --generators verify` and other tooling invoking the systemd generator directly. * Fixed a bug where containers which failed to start would, in some circumstances, not properly clean up, resulting in improper behavior * Fixed a bug where the `podman kube generate` command would improperly generate warning messages only applicable when running as a rootless user on an SELinux enabled system when not running in that configuration * Fixed a bug where the Compat and Libpod Create endpoint for Exec Sessions (`/containers/$CID/exec`) did not honor the `ConsoleSize` parameter in the exec config. * The Compat API has seen further changes to improve support for the Docker v1.44 API, including the deprecation of several fields removed in that release. * Preparations have begun to implement support for the v1.45 API. ==== python-Mako ==== Version update (1.4.1 -> 1.4.3) - update to 1.4.3 * https://docs.makotemplates.org/en/latest/changelog.html#change-1.4.3 * https://docs.makotemplates.org/en/latest/changelog.html#change-1.4.2 ==== python-dbus-python ==== - Drop obsolete -fstack-protector from CFLAGS (predates distro - fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== python-idna ==== Version update (3.19 -> 3.20) - update to 3.20: * Update to Unicode 18.0.0. * Better enforcement of the domain length limit in the incremental codec. * Add support for Python 3.15. ==== python-pycairo ==== Version update (1.29.1 -> 1.29.2) - Update to version 1.29.2: * Update dependencies (cairo 1.18.4 -> 1.18.6) for the Windows wheels - Update version dependencies according to meson.build. ==== rebootmgr ==== Version update (3.3+git20250722.adf0149 -> 4.0+git20261005.1e5481c) - Update to version 4.0+git20261005.1e5481c: * Release version 4.0 * Provide time of reboot request * Create symlinks for metrics and varlink registry * CI: use docbook5 and update actions/checkout * Add metrics support for systemd-report * Convert manpages to docbook5 * A "reboot now" can now cancel pending reboot requests, too * A hard reboot replaces now a soft-reboot * Fix varlink error code definitions * mkdir_p: fix return value if mkdir fails ==== samba ==== Version update (4.24.6+git.488.e38f6c96c62 -> 4.25.0+git.473.e78e78fbf4) Subpackages: libldb2 samba-ad-dc-libs samba-client samba-client-libs samba-libs - Update to 4.25.0 * persistent handles options in WHATSNEW need fixups; (bso#16234). * Bugs in Persistent Handles database layer code; (bso#16237). * smbstatus byte-range locks broken by Persistent Handle changes; (bso#16253). * "getwd cache" removal needs more work; (bso#16233). * SMB3 SESSION SETUP responses must always be signed; (bso#15962). * winbindd_child_msg_filter: talloc_get_type_abort crashes when winbind max domain connections > 1; (bso#16081). * Fix parsing of uppercase "0X" hex values in the "kdc default domain supported enctypes" smb.conf parameter; (bso#16239). * smbd temporary mkdir name can exceed NAME_MAX for otherwise valid client names; (bso#16240). * Samba internal DNS service doesn't handle switch from UDP to TCP when packet is larger than 4k; (bso#15988). * autobuild failures need to be reported in a more verbose way; (bso#16194). * samba-cluster-support should depend on ndr-samba; (bso#16219). * DNS scavenging happens even if fAging is FALSE; (bso#16223). * samba-tool dns zoneoptions $DC_SERVER_IP _msdcs.addom.samba.example.com -P --aging=1 gives WERR_INTERNAL_DB_ERROR; (bso#16226). * dns client problems related to EDNS usage; (bso#16225). - Update to 4.24.7 * POSIX ACL backend silently discards erros when processing NT ACLs with non-canonical ordering; (bso#16097). * dns client problems related to EDNS usage; (bso#16225). * Samba internal DNS service doesn't handle switch from UDP to TCP when packet is larger than 4k; (bso#15988). * autobuild failures need to be reported in a more verbose way; (bso#16194). * DNS scavenging happens even if fAging is FALSE; (bso#16223). * samba-tool dns zoneoptions $DC_SERVER_IP _msdcs.addom.samba.example.com -P --aging=1 gives WERR_INTERNAL_DB_ERROR; (bso#16226). * Incorrect behavior on stream create-disposition when prior handle is closed; (bso#16144). * An inactive node can run recovery resulting in inconsistent databases; (bso#16082). ==== selinux-policy ==== Version update (20261002 -> 20261006) Subpackages: selinux-policy-targeted - Update to version 20261006: * Fix typo in screen.fc * Allow cscreend to start screen as unconfined domain (bsc#1257101) ==== vim ==== Subpackages: vim-data-common vim-small - do not downgrade fortify level (we're anyway at 3 now which made this ineffective)