Packages changed: MozillaFirefox aaa_base (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) apache2-mod_php8 (8.5.10 -> 8.5.11) argyllcms (3.4.1 -> 3.5.0) bash (5.3.15 -> 5.3.20) bind (9.20.26 -> 9.20.29) bluez cairo (1.18.4 -> 1.18.6) dbus-1-glib (0.114 -> 0.116) dracut (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) elilo emacs flatpak (1.18.3 -> 1.18.4) fwupd (2.1.7 -> 2.1.8) gcr (4.4.0.1 -> 4.4.1) gimp gnome-user-docs (50.4 -> 50.5) google-noto-coloremoji-fonts (20250916 -> 20260924) gpsd gspell (1.14.4 -> 1.14.5) jitterentropy kernel-source (7.2.7 -> 7.2.8) kirigami-addons6 (1.13.0 -> 1.14.0) libX11 libXi libXpm libXtst liblognorm (2.1.0 -> 2.1.1) libphonenumber (9.0.38 -> 9.0.40) libsecret (0.21.7 -> 0.21.8.2) libslirp (4.9.3+4 -> 4.9.5+1) libstorage-ng (4.5.354 -> 4.5.355) libtasn1 libupnp (22.1.2 -> 22.1.5) llvm23 (23.1.1 -> 23.1.2) openSUSE-release (20260924 -> 20260929) orca (50.2 -> 50.3) osinfo-db pam (1.7.2+git48 -> 1.7.3) pam-full-src (1.7.2+git48 -> 1.7.3) parted (3.7 -> 3.8) php8 (8.5.10 -> 8.5.11) plocate (1.1.24 -> 1.1.25) polkit-default-privs (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) python-click (8.4.2 -> 8.5.0) python-cryptography (50.0.0 -> 50.0.1) python-httpx python-pypdf (6.16.2 -> 6.19.0) readline (8.3.3 -> 8.3.6) rpcbind rsyslog rubygem-cgi (0.5.0 -> 0.5.2) shadow (4.20.2 -> 4.20.3) simdutf (9.2.0 -> 9.2.1) tuned (2.27.0.0+git.38d4414 -> 2.28.0) unbound (1.26.0 -> 1.26.1) utf8proc (2.11.3 -> 2.12.0) virtualbox (7.2.18 -> 7.2.20) virtualbox-kmp (7.2.18_k7.2.7_1 -> 7.2.20_k7.2.8_1) vlc (3.0.23 -> 3.0.24) xdg-dbus-proxy (0.1.8 -> 0.1.9) yast2-trans (84.87.20260916.f55042cfcf -> 84.87.20260923.cade5cf3bd) === Details === ==== MozillaFirefox ==== Subpackages: MozillaFirefox-branding-upstream MozillaFirefox-translations-common - Skip profiling when %want_reproducible_builds is set (boo#1040589) ==== aaa_base ==== Version update (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) Subpackages: aaa_base-extras - Update to version 84.87+git20260924.144354a1: * change requires for aaa_base-extras also to pathes ==== apache2-mod_php8 ==== Version update (8.5.10 -> 8.5.11) - version update to 8.5.11 BCMath: Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. Core: Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection. Fixed bug GH-15375 (Nested "yield from" skips items after a valid() or next() call on the inner generator). Fixed bug GH-23232 (lone namespace separator asks the autoloader for an empty class name). Fixed bug GH-23301 (Nested "yield from" yields a value twice when the middle generator delegates again). DOM: Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the null namespace in spec-following mode. Fixed stale getElementsByClassName() and other node list caches after className/classList writes and attribute removals. Fixed a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude(). Fixed a crash in DOMXPath when a php:function callback receives a nodeset and a later callback returns a node from another document. Fixed bug GH-23331 (UAF when node_list_unlink() skips attribute children that still have a live wrapper). Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the value of an attribute whose child still has a live wrapper. GD: Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the wrong argument in error messages. FPM: Fixed bug GH-19320 (FPM UID and GID overflow). Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison). (CVE-2026-91768) Intl: Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle returning UTF-16 offsets instead of grapheme offsets. Fixed a memory leak when dumping IntlCalendar instances. Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator() results. Fixed a double-free when IntlGregorianCalendar construction fails after the ICU constructor adopts the TimeZone. Fixed bug GH-23094 (NumberFormatter parsing offsets use UTF-16 positions for UTF-8 strings). Fixed Locale::parseLocale() reading past a trailing '-' or '_'. Fixed grapheme_str_split() treating UBRK_DONE as a byte index. Fixed a leak in Locale::getKeywords() when a keyword value cannot be read. Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed from compiled rules. MBString: Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the replacement when a \k backref has no closing delimiter. MySQLnd: Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218) ODBC: Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type() returning uninitialized memory when SQLColAttribute fails. Opcache: Fixed opcache.protect_memory race under ZTS. Fixed a tracing JIT crash when compiling a side trace for a method of a class that could not be stored in the inheritance cache. Fixed a crash when the huge page SHM remap discarded mappings outside the reserved address range. OpenSSL: Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769) Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN). (CVE-2026-91767) PDO: Fixed a leak when a persistent connection failed a liveness check with no other live PDO handle. PDO_PGSQL: Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching (PDO::ATTR_PREFETCH => 0). PDO Sqlite: Fixed bug GH-20214 (PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode). Phar: Fixed bug GH-23418 (Use-after-free when looking up mounted directories). Fixed bug GH-23477 (Memory leak on duplicate native Phar manifest entries). Fixed GHSA-j3wh-g957-2m85 (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (CVE-2026-6103) Readline: Fixed the interactive shell not waiting for the pager process to exit. SOAP: Fixed WSDL cache corruption when a soap:header defines headerfaults. Fixed stack overflow when parsing a WSDL with self-referential schema groups or attributeGroups. Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765) Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181) Standard: Fixed a segfault when a stream filter callback unsets StreamBucket::$data before re-attaching the bucket. Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682) Fixed read buffer compaction in php_stream_filter_flush(). Fixed bug GH-22410 (Incorrect float behavior with large numbers). Fixed GH-23338 (fsockopen()/pfsockopen() ValueError reported wrong argument number for $timeout). Fixed bug GH-23576 (Next index for array returned from array_keys() is wrong). Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL). (CVE-2026-92842) Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766) SimpleXML: Fixed writing to a dimension of the object returned by attributes() not creating the attribute. Fixed child elements of the element returned by SimpleXMLElement::addChild() not being accessible by property name when namespaces are involved. Windows: Fixed GHSA-9f67-6fw4-hpfp (Reserved device names are not rejected before file and stream I/O). (CVE-2026-17545) Zip: Fixed bug GH-17787 (ZipArchive stream stops reading early when the archive is freed while the stream is still open). Fixed bug GH-23276 (ZipArchive subclass storing its own stream cannot be garbage collected). SAPI: Fixed fuzzer targets failing to build in isolation. Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo) ==== argyllcms ==== Version update (3.4.1 -> 3.5.0) - Update to 3.5.0 (bug fix release): * Fixed bug in targen (introduced in 3.3.0) that added a default ink limit for all device types, wrongly reducing it by 10% for additive devices unless overridden later in profiling. * Changed colprof to ignore, rather than warn about, an ink limit set for an additive device space. * Fixed reported problem with some models of Spyder2024. * Tweaked i1d3 frequency measurement mode for more consistent zero-black readings, matching period measurement mode on Rev. B instruments affected by the 0x83 bug. * Added Munsell Linear Grayscale scanin reference files. * Added -g option to xicc/fakeCMY to emit RGB values instead of CMY. * Added -o observer option to xicc/specplot. * Improved robustness of command name filename parsing in a number of utilities. * Expanded spectro/average to handle input test charts. * Improved JETI Specbos 2501 operation. - Spec cleanup: drop obsolete Group: tags, convert libtiff-devel and the udev runtime Requires to their pkgconfig() provider form, and use the standard parallel-make macro for the bundled ajam build tool. ==== bash ==== Version update (5.3.15 -> 5.3.20) Subpackages: bash-lang bash-loadables bash-sh - Add upstream patches * Bash-5.3 Official patch 16 -- bash53-016 On recent versions of macOS, the pipe size is dynamic and changes due to system-wide total pipe usage, so we have to check whether or not bash can use the size determined at compile time. * Bash-5.3 Official patch 17 -- bash53-017 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * Bash-5.3 Official patch 18 -- bash53-018 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * Bash-5.3 Official patch 19 -- bash53-019 On some systems, macOS in particular, isalpha(3) returns true for bytes between 128 and 255. Bash uses this to determine whether or not these characters are permitted to be part of a shell identifier, and can consume one byte too many when determining the end of a variable name. * Bash-5.3 Official patch 20 -- bash53-020 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== bind ==== Version update (9.20.26 -> 9.20.29) Subpackages: bind-doc bind-utils - Update named.root - Upgrade to release 9.20.29 Security Fixes: * Prevent excessive CPU use validating crafted DNSSEC responses. (CVE-2026-19668) [bsc#1280436] * Require a TSIG on every message of incoming zone transfers. (CVE-2026-19033) [bsc#1280430] * Prevent a DNSSEC downgrade of secure delegations via unrelated NSEC3 records. (CVE-2026-77119) [bsc#1280440] * Prevent forged DNSSEC-validated NXDOMAIN responses. (CVE-2026-19941) [bsc#1280437] * DNS64 with break-dnssec could cause an assertion failure. (CVE-2026-19666) [bsc#1280433] * Reject oversized negative cache records. (CVE-2026-19667) [bsc#1280435] * Prevent resolver crash with cached DNSSEC proofs. (CVE-2026-19662) [bsc#1280432] * Discard repeated SOA, CNAME, and DNAME records when parsing DNS messages. (CVE-2026-75029) [bsc#1280438] * Fix an unauthenticated crash on HTTPS using SIG(0). (CVE-2026-77692) [bsc#1280441] * Cached HTTPS/SVCB aliases could exhaust resolver CPU. (CVE-2026-81736) [bsc#1280445] * Prevent TKEY queries from terminating named without global options. (CVE-2026-76163) [bsc#1280439] * Out-of-zone records in a zone database could be served as authoritative. (CVE-2026-78301) [bsc#1280442] * Fix crash on wildcard answers carrying both NSEC and NSEC3 proofs. (CVE-2026-80274) [bsc#1280443] * Following HTTPS/SVCB aliases could leak resolver cache memory. (CVE-2026-81563) [bsc#1280444] New Features: * Disclose active Negative Trust Anchors with Extended DNS Error 33. Feature Changes: * Reject oversized and malformed DNSKEY records up front. * Speed up RPZ policy zone updates. Bug Fixes: * Prevent a crash when using both dns64 and filter-a. * Stop passing UDP client addresses to update-policy external helpers. * Missing required NSEC3 for delegation not detected. * Tighten EUI48 and EUI64 text parsing. * GeoIP ACL state could be stale or wrong after reload. * Honor DNSSEC policy key tag ranges. * Fix a double free in mdig when EDNS options are specified. * Fix a crash when an IXFR falls back to AXFR with updates still pending. * Fix DS requests to parental agents over TLS. * Fix the rndc-confgen -q (quiet) option. * Enforce query ACLs for redirect zones and searched DLZs. * Check asnum validity in GeoIP ACLs. * Fix a crash on remote-servers lists that reference themselves. * A record from outside a response policy zone could crash named. * Invalid key-store configuration could abort the DNSSEC tools. * NSEC signature set could bypass the secure-delegation check. * Fix a possible nsupdate issue when using GSS-TSIG. * Fix a crash with a single-element geoip sortlist. * Prevent out-of-bailiwick CNAMEs from evicting cached records. * Restore periodic cleanup of stale resolver address data. * Fix named-checkconf/named crash with malformed key name. * Prevent resolver crashes while processing DNS over TCP. * Ensure NSEC authority does not cross zonecut boundary. * Treat an unusable NSEC3 chain as a verification failure. * Treat non-canonical RPZ prefixes as any other failure. * Negative caching stopped working with stale-answer-client-timeout set to 0. * An unterminated OpenSSL private-key Label: field could be read past its parser buffer. * Restore SMF support on Solaris and illumos. * Fix compilation on GNU/Hurd. * dig +yaml was producing invalid YAML when a lookup failed. * Properly prevent TSIG generation command line injection attacks. * Fix a potential heap bounds overflow write in dnssec-signzone. * Fix crashes on invalid DNSTAP input in dnstap-read. ==== bluez ==== Subpackages: bluez-auto-enable-devices bluez-cups bluez-obexd bluez-zsh-completion libbluetooth3 - Add fix-crash-on-UUID-discovery.patch ==== cairo ==== Version update (1.18.4 -> 1.18.6) Subpackages: libcairo-gobject2 libcairo-script-interpreter2 libcairo2 - Update to version 1.18.6: + The XCB surface triggered an UAF warning when building with GCC. + The clipping code was accessing various fields in a guard value, and causing a crash inside Inkscape. + Multiple fixes for the Windows backends, including improvements in the thread safety of the DirectWrite code. + The DirectWrite backend now supports COLRv1 fonts. + Multiple fixes for building with MSVC and ClangCL. + A leak in the PDF surfaces has been fixed. + Various gaps between abutting rectangles when drawing with ANTIALIAS_NONE were removed by using absolute coordinates and avoiding rounding errors. + Remove an overflow when computing the buffer size in the XRender code. - Refresh cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff with quilt. ==== dbus-1-glib ==== Version update (0.114 -> 0.116) - Update to version 0.116: + Bug fixes: - Remove `G_GNUC_CONST` from `_get_type()` functions. This can cause miscompilation with gcc-16. - Disable bash completion by default. This is an unmaintained bash completion for dbus-send(1), which is not part of GLib, and apparently doesn't work as intended. For a dbus-send equivalent with shell completion, please try GLib's gdbus(1) or systemd's busctl(1). - Drop (and obsolete) bash-completion sub-package following upstream changes. ==== dracut ==== Version update (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) - Update to version 112+suse.53.g97cbf62: * fix(fips): use BOOT_IMAGE_NAME instead of BOOT_IMAGE in path check ==== elilo ==== - Add elilo-objcopy-target.diff to use correct objcopy options. ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Add patch bsc1282390.patch * Fix bsc#1282390 (CVE-2026-96442): arbitrary code execution when viewing or editing untrusted text files in modes other than Emacs Lisp mode due to incomplete fix for older CVE ==== flatpak ==== Version update (1.18.3 -> 1.18.4) Subpackages: flatpak-remote-flathub flatpak-selinux flatpak-zsh-completion libflatpak0 system-user-flatpak - Update to version 1.18.4: + Security fixes: - Prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious app is installed (CVE-2026-97024, GHSA-8xgq-v545-vgv) - Prevent privileged deletion of arbitrary files when a malicious app is installed (CVE-2026-97023, GHSA-5p67-xh8x-rq54) - When downloading apps or runtimes from an OCI repository that requires authentication, don't make the authentication token visible to other users (CVE-2026-97025, GHSA-7rvf-rqr3-43j4) - Restrict permissions on temporary repository directories in /var/tmp/flatpak-cache-* (CVE-2026-97026, GHSA-r9w3-qx54-qvc8) - Filter .desktop and D-Bus .service files against an allowlist of fields, preventing denial of service and unintended interactions with host services (CVE-2026-97027, GHSA-v64f-hrwr-j4vh) - Prevent apps from sending signals to a process group that includes a parent process outside the app, causing denial of service by killing the desktop environment (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2) + Bug fixes: - Update Meson wrap subprojects for projects that are normally taken from the host system: - xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422) - Improve hardening against symlink traversal, related to CVE-2026-97023 and CVE-2026-97024 + Internal changes: - Add CVE IDs and reporter credits to 1.18.1's NEWS entry - Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries ==== fwupd ==== Version update (2.1.7 -> 2.1.8) Subpackages: fwupd-bash-completion fwupd-lang libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.8: + This release adds the following features: - Add a new plugin to poke bootupd when the ESP changes - Add RSA-3072 signature verification support for Lenovo accessories + This release fixes the following bugs: - Add a workaround for the systemd-pcrosseparator.service PCR0 extension - Add hashes for the latest DBX for offline machines - Add user aware message to complete the dell-dock update - Allow enumeration BIOS settings to take either string or integer - Allow redfish firmware blobs up to 512MiB - Always use base-16 when parsing the UEFI capsule index - Do not allow a DFU altname or STM32 sector size of zero - Fix a buffer overwrite when parsing Synaptics CAPE HID reports - Fix a dell-dock crash via malformed EC_CMD_GET_DOCK_INFO response - Fix a file descriptor leak when getting firmware details - Fix a memory leak when parsing an invalid TPM eventlog - Fix a NULL deref when enumerating a broken synaptics-rmi device - Fix a snapd error when installing the latest dbx - Fix an integer underflow in Focal FP HID CRC parser - Fix eMMC error recovery command when setting install mode fails - Fix firmware recovery of Logitech Unifying devices - Increase the Huddly USB bulk write timeout to 30s - Invalidate the Wacom descriptor cache when the block count changes - Limit decompressing LZMA streams to 2GiB - Update PCB version checking logic in usi-dock - Use the stricter PolicyKit action ID when the device has gone - Verify the jcat item IDs before using them as filenames + This release adds support for the following hardware: - ASUS GX5407 - Elan PID 0CB6 - FocalTech MOC fingerprint sensors - Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000 - MaxLinear MxL862xx - MediaTek MT9700 FCTE and MT9701 KSMU - Pixart PID 4F01, 4F02, 4F0D and 4F0E - Rolling RW101 ==== gcr ==== Version update (4.4.0.1 -> 4.4.1) Subpackages: gcr-lang gcr-ssh-agent gcr-ssh-askpass gcr-viewer libgck-2-2 libgcr-4-4 typelib-1_0-Gck-2 typelib-1_0-Gcr-4 - Update to version 4.4.1: + gcr: - Support zero mtime - Fix memory leak in GcrSystemPrompt call closure + docs: Fix a method reference in gcr_prompt_set_choice_label() + Updated translations. ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - CVE-2026-96543: out-of-bounds heap write when loading non-square PVR images (bsc#1282539) * gimp-CVE-2026-96543.patch - CVE-2026-96544: integer overflow in the PVR image loader leads to an out-of-bounds heap read (bsc#1282541) * gimp-CVE-2026-96544.patch * gimp-CVE-2026-96544-2.patch - CVE-2026-96545: out-of-bounds heap read in the 4bpp TIM image loader (bsc#1282602) * gimp-CVE-2026-96545.patch - Add gimp-initialize-sgi-tables.patch: ensure that SGI tables are initialized. Clean-up for the fix for CVE-2026-66757 (bsc#1279838 glgo#GNOME/gimp!2997). - CVE-2026-90948: When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size (bsc#1280512) * gimp-CVE-2026-90948.patch - CVE-2026-90949: When processing a compressed selection channel in gimp's PSP file loader, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed (bsc#1280513) * gimp-CVE-2026-90949.patch - CVE-2026-92248: When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header (bsc#1280739) * gimp-CVE-2026-92248.patch * gimp-CVE-2026-92248-2.patch ==== gnome-user-docs ==== Version update (50.4 -> 50.5) - Update to version 50.5: + Updated translations. ==== google-noto-coloremoji-fonts ==== Version update (20250916 -> 20260924) - Update to v2.057 * Unicode 18.0 update - 19 new emojis (9 new emoji code points plus 10 skin-tone sequences for directional thumbs) ==== gpsd ==== - Fix for gpsprof arbitrary OS command execution via code injection in the attacker-controlled SKY.satellites[].used field, inserted unsanitized into a gnuplot heredoc data block; sat.used is now forced to a boolean (CVE-2026-60122 [bsc#1280016]) + 5a9c44a4.patch ==== gspell ==== Version update (1.14.4 -> 1.14.5) Subpackages: gspell-lang libgspell-1-3 - Update to version 1.14.5: + Don't annotate get_type() functions with G_GNUC_CONST. + Updated translations. ==== jitterentropy ==== Subpackages: libjitterentropy3 libjitterentropy3-32bit - OSR has to be at least 5 according to current reviews. (bsc#1282301) jitterentropy-minimum-osr.patch ==== kernel-source ==== Version update (7.2.7 -> 7.2.8) - Update patches.kernel.org/7.2.4-018-clocksource-drivers-timer-sun4i-Advertise-a-rea.patch (bsc#1012628 CVE-2026-93219 bsc#1282749). - Update patches.kernel.org/7.2.4-048-mm-huge_memory-skip-device-private-PMDs-in-madv.patch (bsc#1012628 CVE-2026-93218 bsc#1282748). - Update patches.kernel.org/7.2.4-050-mm-hugetlb-fix-boot-panic-with-CONFIG_DEBUG_VM-.patch (bsc#1012628 CVE-2026-93232 bsc#1282694). - Update patches.kernel.org/7.2.4-051-mm-hugetlb-initialize-gigantic-bootmem-hugepage.patch (bsc#1012628 CVE-2026-93230 bsc#1282693). - Update patches.kernel.org/7.2.4-054-mm-madvise-skip-device-private-PMDs-in-cold-and.patch (bsc#1012628 CVE-2026-93217 bsc#1282760). - Update patches.kernel.org/7.2.4-060-mm-mm_init-deferred_grow_zone-fix-out-of-range-.patch (bsc#1012628 CVE-2026-93227 bsc#1282696). - Update patches.kernel.org/7.2.4-061-mm-page_owner-use-memcg_data-snapshot-to-avoid-.patch (bsc#1012628 CVE-2026-93216 bsc#1282780). - Update patches.kernel.org/7.2.4-094-cdx-Fix-double-free-when-sysfs-file-creation-fa.patch (bsc#1012628 CVE-2026-93215 bsc#1282758). - Update patches.kernel.org/7.2.4-114-usb-gadget-f_tcm-fix-deadlock-in-usbg_make_tpg.patch (bsc#1012628 CVE-2026-93214 bsc#1282776). - Update patches.kernel.org/7.2.4-127-of-fix-out-of-bounds-read-in-of_alias_scan-stem.patch (bsc#1012628 CVE-2026-93213 bsc#1282775). - Update patches.kernel.org/7.2.4-144-nfsd-guard-nfsd_serv-deref-in-nfsd_file_net_dis.patch (bsc#1012628 CVE-2026-93212 bsc#1282774). - Update patches.kernel.org/7.2.4-162-nfsd-add-missing-read-barrier-to-rpc_status_get.patch (bsc#1012628 CVE-2026-93229 bsc#1282698). - Update patches.kernel.org/7.2.4-169-nfsd-convert-nfsd_net-boolean-flags-to-unsigned.patch (bsc#1012628 CVE-2026-93221 bsc#1282736). - Update patches.kernel.org/7.2.4-199-nfsd-initialize-DRC-hash-table-before-registeri.patch (bsc#1012628 CVE-2026-93211 bsc#1282740). - Update patches.kernel.org/7.2.4-243-smb-client-harden-DFS-cache-against-invalid-tar.patch (bsc#1012628 CVE-2026-93210 bsc#1282737). - Update patches.kernel.org/7.2.4-343-Bluetooth-hci_core-use-skb_get-instead-of-skb_c.patch (bsc#1012628 CVE-2026-93209 bsc#1282735). - Update patches.kernel.org/7.2.4-348-kasan-fix-cache-shrink-race-with-CPU-hotplug.patch (bsc#1012628 CVE-2026-93208 bsc#1282732). - Update patches.kernel.org/7.2.4-357-ipv6-use-RCU-iterator-to-dump-route-exceptions.patch (bsc#1012628 CVE-2026-93226 bsc#1282723). - Update patches.kernel.org/7.2.4-369-phy-fsl-imx8mq-usb-fix-typec-switch-leak-on-pro.patch (bsc#1012628 CVE-2026-93225 bsc#1282726). - Update patches.kernel.org/7.2.4-371-SUNRPC-Zero-rpc_gss_wire_cred-at-svcauth_gss_de.patch (bsc#1012628 CVE-2026-93207 bsc#1282672). - Update patches.kernel.org/7.2.4-393-svcrdma-Fix-unmatched-rn_unregister-on-failed-a.patch (bsc#1012628 CVE-2026-93224 bsc#1282703). - Update patches.kernel.org/7.2.4-398-svcrdma-Reject-Write-Reply-chunks-with-segcount.patch (bsc#1012628 CVE-2026-93228 bsc#1282697). - Update patches.kernel.org/7.2.4-401-udf-reject-VAT-indexes-equal-to-the-entry-count.patch (bsc#1012628 CVE-2026-89525 bsc#1282288). - Update patches.kernel.org/7.2.4-404-staging-media-tegra-video-fix-of_node_put-on-VI.patch (bsc#1012628 CVE-2026-93223 bsc#1282741). - Update patches.kernel.org/7.2.4-418-sched_ext-Keep-kick_sync-waiting-on-the-rq-s-ow.patch (bsc#1012628 CVE-2026-93220 bsc#1282750). - Update patches.kernel.org/7.2.4-486-lockd-fix-swapped-arguments-in-nlmsvc_match_ip.patch (bsc#1012628 CVE-2026-93231 bsc#1282778). - Update patches.kernel.org/7.2.4-534-PCI-proc-Use-file_ns_capable-when-checking-conf.patch (bsc#1012628 CVE-2026-93206 bsc#1282729). - Update patches.kernel.org/7.2.4-541-iommu-arm-smmu-v3-Manage-teardown-with-devm.patch (bsc#1012628 CVE-2026-93205 bsc#1282727). - Update patches.kernel.org/7.2.4-703-signal-avoid-shared-siginfo-namespace-rewrites.patch (bsc#1012628 CVE-2026-93222 bsc#1282742). - Update patches.kernel.org/7.2.5-097-mm-secretmem-properly-account-locked-pages.patch (bsc#1012628 CVE-2026-93243 bsc#1282687). - Update patches.kernel.org/7.2.5-128-memcg-bypass-the-reclaim-and-oom-killer-for-dyi.patch (bsc#1012628 CVE-2026-93241 bsc#1282781). - Update patches.kernel.org/7.2.5-129-memcg-make-the-v1-soft-limit-knob-inert.patch (bsc#1012628 CVE-2026-93240 bsc#1282779). - Update patches.kernel.org/7.2.5-146-arm64-mm-Fix-the-lockless-page-table-walk-in-sh.patch (bsc#1012628 CVE-2026-93239 bsc#1282681). ... changelog too long, skipping 1612 lines ... - commit 93e89db ==== kirigami-addons6 ==== Version update (1.13.0 -> 1.14.0) Subpackages: kirigami-addons6-lang libKirigamiAddonsComponents6 libKirigamiAddonsStatefulApp6 libKirigamiApp6 - Update to 1.14.0 https://carlschwan.eu/2026/09/17/imprint-1.0-and-kirigami-addons-1.14.0/ ==== libX11 ==== Subpackages: libX11-6 libX11-data libX11-xcb1 - 0001-1281653_CVE-2026-94283_ximcp-bound-XIM_OPEN_REPLY-attribute-lengths-to-the-.patch * Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser (boo#1281653, CVE-2026-94283) - 0002-1281657_CVE-2026-94284_ximcp-bound-XIM_REGISTER_TRIGGERKEYS-keylist-lengths.patch * Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser (boo#1281657, CVE-2026-94284) - 0003-1281661_CVE-2026-94285_lcGenConv-bound-byteM_parse_codeset-reads-to-remaini.patch * Out-of-bounds read in libX11's byte-oriented codeset parser (boo#1281661, CVE-2026-94285) ==== libXi ==== - 0001-boo1281605_CVE-2026-93541_XQueryDeviceState-check-ValuatorClass-num_valuators-.patch * Out-of-bounds read in libXi's XQueryDeviceState() (boo#1281605, CVE-2026-93541) - 0002-boo1281606_CVE-2026-93542_size_classes-copy_classes-bound-XI2-class-lengths-to.patch * Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() (boo#1281606, CVE-2026-93542) - 0003-boo1281608_CVE-2026-93543_size_classes-copy_classes-enforce-XI2-per-type-class.patch * Out-of-bounds read in libXi's XI2 class parser (boo#1281608, CVE-2026-93543) - 0004-boo1281609_CVE-2026-93544_XIQueryDevice-keep-padded-name-and-class-bytes-withi.patch * Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing (boo#1281609, CVE-2026-93544) - 0005-boo1281612_CVE-2026-93545_XListInputDevices-validate-device-name-lengths-again.patch * Out-of-bounds read in libXi's XListInputDevices() (boo#1281612, CVE-2026-93545) - 0006-boo1281615_CVE-2026-94281_XListInputDevices-validate-class-lengths-cumulativel.patch * Out-of-bounds read in libXi's XListInputDevices() class parsing (boo#1281615, CVE-2026-94281) - 0007-boo1281651_CVE-2026-94282_wireToEnterLeave-validate-buttons_len-against-the-re.patch * Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversio (boo#1281651, CVE-2026-94282) ==== libXpm ==== - 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch * Denial of service via unsigned underflow in libXpm's write path (boo#1281669, CVE-2026-94287) ==== libXtst ==== - 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch * Out-of-bounds read in libXtst's RECORD reply parser (boo#1281665, CVE-2026-94286) ==== liblognorm ==== Version update (2.1.0 -> 2.1.1) - update to 2.1.1: * TurboVM: fix optimized builds failing on an uninitialized repeat name length warning * parser(date-rfc5424): prevent millisecond timestamp overflow: parse only the required millisecond precision while still consuming additional fractional digits * parser(literal): prevent reads past the input terminator: embedded NUL bytes no longer let byte-counted literal matching continue past the duplicated C string terminator * parser(date-rfc3164): reject a null format safely: malformed parser JSON no longer causes a null-pointer dereference and continues to use the established default string output ==== libphonenumber ==== Version update (9.0.38 -> 9.0.40) - update to 9.0.40: * Updated phone metadata for region code(s): BD, CA, CD, EE, IL, LI, PA, SB, SR, UG, VN, ZW * New geocoding data for country calling code(s): 1273 (en) * Updated geocoding data for country calling code(s): 263 (en) * Updated carrier data for country calling code(s): 36 (en), 39 (en), 81 (en), 84 (en), 226 (en), 243 (en), 256 (en), 597 (en), 677 (en), 880 (en), 972 (en), 994 (en) * Updated / refreshed time zone meta data. - includes changes from 9.0.39: * Updated alternate formatting data for country calling code(s): 91 * Updated phone metadata for region code(s): BD, HK, IN, PA, PT, TR * Updated geocoding data for country calling code(s): 91 (en) * Updated carrier data for country calling code(s): 90 (en), 359 (en), 852 (en, zh), 966 (en) ==== libsecret ==== Version update (0.21.7 -> 0.21.8.2) Subpackages: libsecret-1-0 libsecret-lang typelib-1_0-Secret-1 - Update to version 0.21.8.2: + Release to bump meson.build version - Changes from version 0.21.8.1: + Make secret_item_load_secrets_sync match async behavior - Update to version 0.21.8: + Allow the content type to have additional parameters + Support individually encrypted items + Ensure we return chained up GTask + Ensure length of DH shared secret match length of prime on GnuTLS + file-backend: - Add thread safety and file-based locking to prevent concurrent write races - Fix possible memory leak in error path of secret_file_backend_real_search() + file-collection: Fix memory leaks on repeated calls + Replace some SecretSync with a sync implementation + Add linker version script to hide private symbols + Stop using CONST annotations on non-const fns + secret-tool: - Align behavior for collection option - Document --collection option + meson: Put test setup behind a feature option + Several test and CI improvements + Updated translations. ==== libslirp ==== Version update (4.9.3+4 -> 4.9.5+1) - Update to version 4.9.5+1: * note CVE numbers * Release v4.9.5 * Set UDP sockets in blocking mode * dhcpv6: fix bounding the reply against the interface MTU * dhcpv6: bound the reply against the interface MTU * ncsi: bounds-check OEM command bodies before dereferencing them * Release v4.9.4 * ip_input: update hlen on ip_reass * ip6_input: Trim mbuf to ip6-announced length * Fix reporting oob output * Note about the security contact - fixes CVE-2026-95507, CVE-2026-95508 ==== libstorage-ng ==== Version update (4.5.354 -> 4.5.355) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Danish) (bsc#1149754) - 4.5.355 ==== libtasn1 ==== Subpackages: libtasn1-6 libtasn1-6-32bit - Update Source URLS - guard against future removal of egrep/fgrep ==== libupnp ==== Version update (22.1.2 -> 22.1.5) Subpackages: libixml22 libupnp22 - Update to release 22.1.5 * Fix SID matching for incoming GENA NOTIFY requests. [GHSA-ggw2-jjv9-h22c] - Update to release 22.1.4 * Stopped counting the read-head entity bytes against header sizes. * Sockets are now closed when http_OpenHttpGetEx() gets a bad response. ==== llvm23 ==== Version update (23.1.1 -> 23.1.2) Subpackages: clang-tools clang23 libLLVM23 libclang-cpp23 libclang13 libclang_rt23 llvm23-gold - Update to version 23.1.2. * This release contains bug-fixes for the LLVM 23.1.0 release. This release is API and ABI compatible with 23.1.0. ==== openSUSE-release ==== Version update (20260924 -> 20260929) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== orca ==== Version update (50.2 -> 50.3) Subpackages: orca-lang - Update to version 50.3: + General: - Fix traceback when using object navigator to click on an object. - Fix two issues related to running unit tests downstream. + New and updated translations (THANKS EVERYONE!!!): - Add python3-setproctitle Recommends. Orca uses this to set its process name when available. - Add python3-psutil Recommends: Support system information commands. ==== osinfo-db ==== - Add support for SLES-16.2 add-sles16.2-support.patch - Add support for openSUSE Leap 16.2 add-opensuse-leap-16.2-support.patch - Adjust SLES 16.1 version number and include release date add-sles16.1-support.patch ==== pam ==== Version update (1.7.2+git48 -> 1.7.3) Subpackages: pam-32bit - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== pam-full-src ==== Version update (1.7.2+git48 -> 1.7.3) Subpackages: pam-extra pam-manpages - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== parted ==== Version update (3.7 -> 3.8) Subpackages: libparted-fs-resize0 libparted2 parted-lang - switch from ftp to https for sources - updated parted.keyring - update to version 3.8 - update to version 3.7.14: - Fix gnu_read problems with block size > 512b - update to version 3.7.13: - Add support for ExFAT - Fix CVE-2026-89085 and CVE-2026-89088 - Add various checks for increased security ==== php8 ==== Version update (8.5.10 -> 8.5.11) Subpackages: php8-ctype php8-dom php8-iconv php8-openssl php8-pdo php8-sqlite php8-tokenizer php8-xmlreader php8-xmlwriter - version update to 8.5.11 BCMath: Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. Core: Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection. Fixed bug GH-15375 (Nested "yield from" skips items after a valid() or next() call on the inner generator). Fixed bug GH-23232 (lone namespace separator asks the autoloader for an empty class name). Fixed bug GH-23301 (Nested "yield from" yields a value twice when the middle generator delegates again). DOM: Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the null namespace in spec-following mode. Fixed stale getElementsByClassName() and other node list caches after className/classList writes and attribute removals. Fixed a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude(). Fixed a crash in DOMXPath when a php:function callback receives a nodeset and a later callback returns a node from another document. Fixed bug GH-23331 (UAF when node_list_unlink() skips attribute children that still have a live wrapper). Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the value of an attribute whose child still has a live wrapper. GD: Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the wrong argument in error messages. FPM: Fixed bug GH-19320 (FPM UID and GID overflow). Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison). (CVE-2026-91768) Intl: Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle returning UTF-16 offsets instead of grapheme offsets. Fixed a memory leak when dumping IntlCalendar instances. Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator() results. Fixed a double-free when IntlGregorianCalendar construction fails after the ICU constructor adopts the TimeZone. Fixed bug GH-23094 (NumberFormatter parsing offsets use UTF-16 positions for UTF-8 strings). Fixed Locale::parseLocale() reading past a trailing '-' or '_'. Fixed grapheme_str_split() treating UBRK_DONE as a byte index. Fixed a leak in Locale::getKeywords() when a keyword value cannot be read. Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed from compiled rules. MBString: Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the replacement when a \k backref has no closing delimiter. MySQLnd: Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218) ODBC: Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type() returning uninitialized memory when SQLColAttribute fails. Opcache: Fixed opcache.protect_memory race under ZTS. Fixed a tracing JIT crash when compiling a side trace for a method of a class that could not be stored in the inheritance cache. Fixed a crash when the huge page SHM remap discarded mappings outside the reserved address range. OpenSSL: Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769) Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN). (CVE-2026-91767) PDO: Fixed a leak when a persistent connection failed a liveness check with no other live PDO handle. PDO_PGSQL: Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching (PDO::ATTR_PREFETCH => 0). PDO Sqlite: Fixed bug GH-20214 (PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode). Phar: Fixed bug GH-23418 (Use-after-free when looking up mounted directories). Fixed bug GH-23477 (Memory leak on duplicate native Phar manifest entries). Fixed GHSA-j3wh-g957-2m85 (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (CVE-2026-6103) Readline: Fixed the interactive shell not waiting for the pager process to exit. SOAP: Fixed WSDL cache corruption when a soap:header defines headerfaults. Fixed stack overflow when parsing a WSDL with self-referential schema groups or attributeGroups. Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765) Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181) Standard: Fixed a segfault when a stream filter callback unsets StreamBucket::$data before re-attaching the bucket. Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682) Fixed read buffer compaction in php_stream_filter_flush(). Fixed bug GH-22410 (Incorrect float behavior with large numbers). Fixed GH-23338 (fsockopen()/pfsockopen() ValueError reported wrong argument number for $timeout). Fixed bug GH-23576 (Next index for array returned from array_keys() is wrong). Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL). (CVE-2026-92842) Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766) SimpleXML: Fixed writing to a dimension of the object returned by attributes() not creating the attribute. Fixed child elements of the element returned by SimpleXMLElement::addChild() not being accessible by property name when namespaces are involved. Windows: Fixed GHSA-9f67-6fw4-hpfp (Reserved device names are not rejected before file and stream I/O). (CVE-2026-17545) Zip: Fixed bug GH-17787 (ZipArchive stream stops reading early when the archive is freed while the stream is still open). Fixed bug GH-23276 (ZipArchive subclass storing its own stream cannot be garbage collected). SAPI: Fixed fuzzer targets failing to build in isolation. Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo) ==== plocate ==== Version update (1.1.24 -> 1.1.25) Subpackages: plocate-apparmor - original tar-ball (https://plocate.sesse.net/download/plocate-1.1.25.tar.gz) is botched, adjust %autosetup call - update to version 1.1.25: * Fix two early-exit bugs with multiple databases * Drop setgid properly, including the saved gid * Fix a potential symlink-checking race in updatedb ==== polkit-default-privs ==== Version update (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) - Update to version 1550+20260928.d1c0e7e: * profiles: added datarecovery run-ddrescue action (bsc#1280118) ==== python-click ==== Version update (8.4.2 -> 8.5.0) - Update to 8.5.0 * Argument accepts a help parameter, and help output includes a Positional arguments section * confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo() * Fix test failures when using pytest >= 9.1 * Path with allow_dash=True no longer triggers a BytesWarning * Add custom_version_option(), a --version option whose output is produced by a callback * style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError * get_binary_stream() and get_text_stream() are deprecated and will be removed in Click 9.0 * Deprecate CliRunner.isolated_filesystem() ==== python-cryptography ==== Version update (50.0.0 -> 50.0.1) - update to 50.0.1: * Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2. ==== python-httpx ==== - Add patch support-click-8.5.0.patch: * Do not use CliRunner.isolated_filesystem - Add patch support-pytest-9.1.patch: * Filter logs due to pytest 9.1 changes ==== python-pypdf ==== Version update (6.16.2 -> 6.19.0) - Update to 6.19.0 * SEC: Limit size of alphabetical page labels * Replace PdfWriter method add_js * Move static value out of loop body for appearance stream data * Reduce number of full data lookups for attachment mapping API 6.18.1 * SEC: Further restrict FlateDecode recovery * SEC: Limit entry count for TrueType and Type1 font /Widths * SEC: Limit allowed length of tokens in parse_bfchar * Fix compatibility with fonttools < 4.58.0 6.18.0 * SEC: Limit allowed length of indirect object tokens * Rework configuration value handling * Draw borders and backgrounds for appearance streams and annotations 6.17.0 * SEC: Limit value for Roman numerals * _cmap.py: Also parse encoding for embedded CFF Type1 fonts * Cache repeated text extraction character lookups - Drop fonttools-slfo.patch, no longer needed (and skip the test) - Skip some flaky tests ==== readline ==== Version update (8.3.3 -> 8.3.6) - Add upstream patches * readline83-004 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * readline83-005 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * readline83-006 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== rpcbind ==== - Bound stats lists in rpcbs_getaddr() and rpcbs_rmtcall() (bsc#1282326, CVE-2026-94640) * add 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch ==== rsyslog ==== - fix VUL-0: imdtls permitted-peer authorization bypass (bsc#1281628) * add 0001-imdtls-reject-clients-that-fail-peer-verification.patch ==== rubygem-cgi ==== Version update (0.5.0 -> 0.5.2) - Update to 0.5.2 (also covers skipped 0.5.1): * Handle a POST request with a missing/empty Content-Length instead of raising TypeError/ArgumentError (gh#ruby/cgi#56) * Fix CGI.unescapeHTML raising Encoding::CompatibilityError in the pure-Ruby fallback on mixed non-ASCII input (gh#ruby/cgi#103) * Fix escape_html/h/unescape_html aliases to actually dispatch to the C extension instead of the slower pure-Ruby implementation * Harden CGI::Session's file-store filename hashing: use SHA-256 instead of MD5, and add a configurable :digest option (default stays MD5 for backward compatibility) * Various documentation improvements - Run spec-cleaner (tag order, License operator casing normalized to the SPDX "AND") ==== shadow ==== Version update (4.20.2 -> 4.20.3) Subpackages: libsubid6 login_defs shadow-pw-mgmt - Update to 4.20.3: * Build error when using '--with-nscd=no' (bug introduced in v4.19.0). ==== simdutf ==== Version update (9.2.0 -> 9.2.1) - Update to version 9.2.1: + Misc. bug fixes and cleanups. ==== tuned ==== Version update (2.27.0.0+git.38d4414 -> 2.28.0) - Update to version 2.28.0: * bootloader: add bootc loader-entries set-options-for-source support so kernel-argument ownership on image mode (bootc) systems survives reboots (RHEL-170825); fixed tempdir permissions (RHEL-121198) and restored initrd generation from /tmp with an added ownership check * systemd: set the systemd manager's CPUAffinity via a new /etc/systemd/system.conf.d/00-tuned.conf drop-in instead of editing system.conf directly, and stop backing up the old file (RHEL-97580, RHEL-84365); the empty template upstream's Makefile now installs there is dropped from the package (rpmlint filelist-forbidden-systemd-userdirs) since the plugin creates it itself on first use * net: recognize more ethtool coalescing options instead of failing on unsupported ones (RHEL-152675); fixed the ring parser for rx-mini/rx-jumbo (RHEL-168025) * functions: use the nl80211-based iw tool for Wi-Fi power saving, falling back to iwpriv on legacy drivers (rhbz#2372365); adds a new mandatory Requires: iw * scheduler: handle EPERM, not just EIO, when setting IRQ affinity on kernel >= 6.12 (RHEL-153655) * network-latency: raise the AVC cache size to 8192, avoiding latency spikes on RHEL-9/10 kernels * openshift: add the network-throughput profile; dropped support for vm.laptop_mode, deprecated since kernel 7.0 * many more fixes and improvements; see upstream's release notes for the full list - Switch source from the hand-maintained git-snapshot _service (tracking master with no fixed revision) to the real v2.28.0 upstream release tarball, now that upstream is tagging releases again; drop _service/_servicedata/*.obscpio/*.obsinfo - Spec cleanup: drop obsolete Group: tags and redundant default file-attribute lines; switch the GObject Introspection build dependency to its two pkgconfig provider names (gobject-introspection-1.0, gobject-introspection-no-export-1.0) ==== unbound ==== Version update (1.26.0 -> 1.26.1) Subpackages: libunbound8 unbound-anchor - Update to 1.26.1: * Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. [bsc#1280411] * Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. [bsc#1280409] * Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. [bsc#1280412] * Fix CVE-2026-77955, Possible ZONEMD verification bypass window. [bsc#1280404] * Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. [bsc#1280405] * Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. [bsc#1280406] * Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. [bsc#1280413] * Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. [bsc#1280414] * Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. [bsc#1280403] ==== utf8proc ==== Version update (2.11.3 -> 2.12.0) - update to 2.12.0: * Unicode 18 support. This includes the modified grapheme-break rule GB9c in UAX 29, which removes some grapheme breaks for Indic characters * options arguments are changed from an enum to unsigned int, since they are generally bitwise "or" of enum values; this should be backwards binary compatible * int *last_boundclass parameter of utf8proc_decompose_char is changed to a utf8proc_int32_t * (affecting only rare systems where int is not 32 bits, on which the last_boundclass argument would have produced incorrect results) * New utf8proc_free function to free memory allocated by utf8proc * utf8proc_normalize_utf32 can now handle invalid codepoints ≥ 0x110000. They are passed through unchanged rather than dropped, and composition never runs across one * Fix UTF8PROC_CHARBOUND emitting no 0xff grapheme markers when combined with UTF8PROC_COMPOSE or UTF8PROC_DECOMPOSE, a regression in 2.11.3 ==== virtualbox ==== Version update (7.2.18 -> 7.2.20) - Add Requires(post) as needed - Update to release 7.2.20 * Fixed a regression on Windows hosts causing VMs to fail with VERR_SUP_VP_FOUND_EXEC_MEMORY. ==== virtualbox-kmp ==== Version update (7.2.18_k7.2.7_1 -> 7.2.20_k7.2.8_1) - Add Requires(post) as needed - Update to release 7.2.20 * Fixed a regression on Windows hosts causing VMs to fail with VERR_SUP_VP_FOUND_EXEC_MEMORY. ==== vlc ==== Version update (3.0.23 -> 3.0.24) Subpackages: libvlc5 libvlccore9 vlc-codec-gstreamer vlc-lang vlc-noX vlc-qt - Update to version 3.0.24: + Codecs: - Use FFmpeg 8.1 (upgraded from 4.4) - Support APV decoder (FFmpeg 8) - Support Atrac3/Atrac9 decoding - Remove schroedinger support for dirac in favor of avcodec - Fix Speex leaks and packetization issues - Fix WebVTT CSS parsing and error handling - Fix FLAC and HEVC packetizer edge cases - Fix AudioToolbox MIDI synthesizer crash on macOS 26+ + Demuxers: - Add support for CEA-708 closed captions in MP4 - Expose ID3v2 metadata in MPEG demuxer - Improve subtitle language detection from filenames and SSA/ASS metadata - Fix several MKV crashes, leaks, hangs and malformed file handling issues - Fix AVI hang with zero-sized strd chunks - Fix MP4, MPEG-TS, Ogg, RealAudio and subtitle demuxing edge cases + Access: - Switch RIST input and output to librist, with main and simple profile support - Add SRT listener mode support - Add SFTP public key authentication options and ED25519 hostkey support - Update SMB2 share enumeration - Don't ship RealRTSP plugin (build disabled for all configurations) + Service Discovery: - Include Chromecast model in mDNS renderer names - Fix IPv6 addresses in Bonjour service URLs + Video Output: - Fix Direct3D11 adjust filter and texture leaks - Fix MediaCodec crop validation - Super Resolution scaling with Moore Threads GPUs + Interface: - Qt: Fix default open dialog location - Qt: Fix effects window geometry saving - Qt: Improve hotkeys dialog strings + Stream Output: - Disable HEVC for original Chromecast devices + Security: - Switch to a new RSA-4096 key for update verification - Fix multiple OOB, integer overflow, double-free and use-after-free issues - See https://www.videolan.org/security/ - CVE-2026-56711: picture: inline AllocatePicture() and use overflow helpers + Misc: - Add Flatpak build support - Fix Audio EQ filter High Frequency parameter - Fix artwork preparser crash when artwork title is null - Fix LibVLC media list player race - Remove NPAPI browser plugin + Lua: - Remove broken youtube.lua plugin - Drop vlc-gstreamer-1.28-build-fix.patch: fixed upstream. ==== xdg-dbus-proxy ==== Version update (0.1.8 -> 0.1.9) - Update to version 0.1.9: + Fix message filtering bypass vulnerabilities (CVE-2026-94422, GHSA-2cgv-pwcq-wvpq): - Don't allow method calls and signals to be treated as requested replies, even if they specify a reply serial number - Only allow replies that were sent to the appropriate destination + Improve automated tests to include attempts to exploit CVE-2026-94422 ==== yast2-trans ==== Version update (84.87.20260916.f55042cfcf -> 84.87.20260923.cade5cf3bd) Subpackages: yast2-trans-af yast2-trans-ar yast2-trans-bg yast2-trans-bn yast2-trans-bs yast2-trans-ca yast2-trans-cs yast2-trans-cy yast2-trans-da yast2-trans-de yast2-trans-el yast2-trans-en_GB yast2-trans-es yast2-trans-et yast2-trans-fa yast2-trans-fi yast2-trans-fr yast2-trans-gl yast2-trans-gu yast2-trans-hi yast2-trans-hr yast2-trans-hu yast2-trans-id yast2-trans-it yast2-trans-ja yast2-trans-jv yast2-trans-ka yast2-trans-km yast2-trans-ko yast2-trans-lo yast2-trans-lt yast2-trans-mk yast2-trans-mr yast2-trans-nb yast2-trans-nl yast2-trans-pa yast2-trans-pl yast2-trans-pt yast2-trans-pt_BR yast2-trans-ro yast2-trans-ru yast2-trans-si yast2-trans-sk yast2-trans-sl yast2-trans-sr yast2-trans-sv yast2-trans-ta yast2-trans-th yast2-trans-tr yast2-trans-uk yast2-trans-vi yast2-trans-wa yast2-trans-xh yast2-trans-zh_CN yast2-trans-zh_TW yast2-trans-zu - Update to version 84.87.20260923.cade5cf3bd: * Translated using Weblate (Danish) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan)