Packages changed: ImageMagick (7.1.2.28 -> 7.1.2.29) MozillaFirefox (153.0.1 -> 153.0.3) SDL3 (3.4.12 -> 3.4.14) breeze6 crypto-policies emacs gd gimp git google-noto-fonts (20260701 -> 20260801) grub2 gstreamer (1.28.5 -> 1.28.6) gstreamer-devtools (1.28.5 -> 1.28.6) gstreamer-plugins-bad (1.28.5 -> 1.28.6) gstreamer-plugins-base (1.28.5 -> 1.28.6) gstreamer-plugins-good (1.28.5 -> 1.28.6) gstreamer-plugins-libav (1.28.5 -> 1.28.6) gstreamer-plugins-rs (1.28.5 -> 1.28.6) gstreamer-plugins-ugly (1.28.5 -> 1.28.6) hwdata (0.409 -> 0.410) kernel-source (7.1.5 -> 7.1.6) libXfont2 libgpg-error libphonenumber (9.0.34 -> 9.0.36) libpsl (0.23.0 -> 0.23.1) libraw (0.22.1 -> 0.22.2) libssh2_org libvirt (12.5.0 -> 12.6.0) mozjs140 (140.12.0 -> 140.13.0) mpg123 (1.33.6 -> 1.33.7) nano (9.1 -> 9.2) nfs-utils ngtcp2 (1.24.0 -> 1.25.0) open-isns (0.103+2.296d533bd52a -> 0.103+4.60de8b5) openSUSE-release (20260802 -> 20260806) openblas_openmp openblas_pthreads plasma6-integration plasma6-workspace polkit-default-privs (1550+20260623.563df94 -> 1550+20260803.90784eb) python-anyio (4.13.0 -> 4.14.2) python-charset-normalizer (3.4.7 -> 3.4.9) python-cryptography (49.0.0 -> 50.0.0) python-numpy python-pip (26.1.2 -> 26.2) python-pyOpenSSL (26.3.0 -> 26.4.0) python-pyzmq qtkeychain-qt6 (0.16.0 -> 0.17.0) selinux-policy (20260727 -> 20260804) shadow (4.19.4 -> 4.20.0) socat swtpm u-boot-rpiarm64 (2026.01 -> 2026.07) unbound (1.25.2 -> 1.26.0) usbredir (0.14.0 -> 0.15.0) vulkan-loader (1.4.350 -> 1.4.357) vulkan-tools (1.4.350 -> 1.4.357) === Details === ==== ImageMagick ==== Version update (7.1.2.28 -> 7.1.2.29) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - version update to 7.1.2.29 * Updated the dependencies. 90f5b91 * add WEBP compress case when writing f35294e * Removed unnecessary include. 1e2f64f * Removed checks for values from tif_config.h that are not included, libtiff will report errors itself now. 7cf1988 * Only set the TIFFTAG_WEBP_LEVEL when the quality is not undefined. 02ac849 * Make sure we read the bits_per_sample before using it. 0af4ede * Added missing typecast. b919b37 ==== MozillaFirefox ==== Version update (153.0.1 -> 153.0.3) Subpackages: MozillaFirefox-branding-upstream - Mozilla Firefox 153.0.3 https://www.firefox.com/en-US/firefox/153.0.3/releasenotes/ * The smart window suggestion list now shows more results, making it easier to find history and switch to open tabs. (bmo#2019042) * The smart window assistant can now answer questions directly using web search results from Exa, instead of handing off to a search engine. (bmo#2046183, bmo#2044385) * Fixed audio and video failing to play, or hanging when seeking, on websites that load media from a Blob URL. (bmo#2056444) * Fixed the Bookmarks, History, and other sidebars failing to open when the sidebar is hidden and the password manager has been turned off by an enterprise policy. (bmo#2056857) * Fixed a Mozilla VPN upgrade offer appearing for people in regions where Mozilla VPN is not sold. (bmo#2058264) * Fixed frequent Inspector crashes in the Developer Tools on pages where an extension content script had added event listeners. (bmo#2042101) - refresh upstream signing key ==== SDL3 ==== Version update (3.4.12 -> 3.4.14) - Update to release 3.4.14 * GPU buffers and textures can have multiple read usages * Fixed X11 crash if the IME service was shutdown in the background * Fixed hang when hiding an X11 window on some window managers * Fixed Xbox controllers not being detected if SDL is built with GameInput support ==== breeze6 ==== Subpackages: breeze6-cursors breeze6-decoration breeze6-style - Move Qt 5 style into a separate optional package ==== crypto-policies ==== Subpackages: crypto-policies-scripts - Disable umac-128* in DEFAULT, FUTURE and BSI openssh policies (bsc#1259515) * Add patch: crypto-policies-Disable-umac-128-in-DEFAULT-FUTURE-and-BSI-openssh-policies.patch ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Configure wayland the compilation support native with ahead of time (aot) to avoid compiling threads (boo#1271643) ==== gd ==== Subpackages: libgd3 - modified patches [bsc#1273101] * gd-CVE-2026-9672.patch (fix wrong backport) ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - Add CVE fixes: + gimp-CVE-2026-66757.patch (bsc#1273151 CVE-2026-66757) + gimp-CVE-2026-66758.patch (bsc#1273152 CVE-2026-66758) + gimp-CVE-2026-66759.patch (bsc#1273153 CVE-2026-66759) ==== git ==== Subpackages: git-core git-email git-gui git-web gitk perl-Git - Remove dependency on update-desktop-files, use translate-suse-desktop (jsc#PED-15206) ==== google-noto-fonts ==== Version update (20260701 -> 20260801) Subpackages: google-noto-sans-arabic-fonts google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Update to 20260801: * Sans Batak: fix the lack of anchoring on the "A" letter (#14) ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-arm64-efi-bls grub2-common grub2-snapper-plugin grub2-systemd-sleep-plugin - Fix crash in booting kernel on some AMD systems (bsc#1271980) * 0001-linux-allocate-EFI-kernel-buffer-as-GRUB_EFI_LOADER_.patch ==== gstreamer ==== Version update (1.28.5 -> 1.28.6) Subpackages: gstreamer-utils libgstreamer-1_0-0 typelib-1_0-Gst-1_0 - Update to version 1.28.6: + Highlighted bugfixes in 1.28.6 - Various security fixes and playback fixes - playbin3, playbin: fix stalls after re-enabling previously disabled subtitles - Fix regression in core if a pad is re-linked while changed sticky events are being pushed - dtls/webrtc: fix some issues with OpenSSL 4.0.0 - RTP retransmission bitrate estimation fixes - Fix RTP depayloading of SMPTE ST291 frames with multiple ANC packets - Add H.266 muxing support to the Rust (f)mp4 muxers - Better handling of input buffers without timestamps in Rust (f)mp4 muxers - webrtcsink H.264 level/profile negotiation fixes and support for nvv4l2h265enc encoder - SMPTE ST2038 ancillary metadata and closed caption combiner improvements - Fix SEI insertion into H.265/HEVC streams with alpha - Windows D3D11 WinRT screen capture element fixes - Improved coded buffer size handling for VA encoders - Textaccumulate: various tweaks how the element outputs text, plus better handling of French punctuation - hlssink3: improved handling of input buffers without timestamps - Fix build against FFmpeg 9.0 - cerbero: fix Windows packages binary size increase regression; upgrade libsrt recipe to 1.5.6 - Various bug fixes, build fixes, memory leak fixes, and other stability and reliability improvements + gstreamer: - baseparse: Don't reset infer_ts/pts_interpolate subclass configuration in reset() and related fixes - cpuid: fix AArch64 NEON detection to check HWCAP_ASIMD, not HWCAP_NEON - pad: fix livelock when pushing changed sticky events when the pad is re-linked - valve: Don't send a reconfigure even when setting the drop property to the same value - meson: Make the g-ir-scanner init section consistent across modules - meson: use dependency('dl') instead of cc.find_library('dl') ==== gstreamer-devtools ==== Version update (1.28.5 -> 1.28.6) - Update to version 1.28.6: + meson: Make the g-ir-scanner init section consistent across modules and fix validate g-ir-scanner invocation so that it doesn't load any plugins + meson: use dependency('dl') instead of cc.find_library('dl') + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-bad ==== Version update (1.28.5 -> 1.28.6) Subpackages: libgstadaptivedemux-1_0-0 libgstanalytics-1_0-0 libgstbadaudio-1_0-0 libgstbasecamerabinsrc-1_0-0 libgstcodecparsers-1_0-0 libgstcodecs-1_0-0 libgstcuda-1_0-0 libgsthip-1_0-0 libgstinsertbin-1_0-0 libgstisoff-1_0-0 libgstmpegts-1_0-0 libgstmse-1_0-0 libgstphotography-1_0-0 libgstplay-1_0-0 libgstsctp-1_0-0 libgsturidownloader-1_0-0 libgstva-1_0-0 libgstvulkan-1_0-0 libgstwayland-1_0-0 libgstwebrtc-1_0-0 libgstwebrtcnice-1_0-0 - Update to version 1.28.6: + adpcmdec: Fix IMA ADPCM input size check to match with the actual code + baseparse: Don't reset infer_ts/pts_interpolate subclass configuration in reset() and related fixes + d3d11winrtcapture: Fix incorrect capture height + dtls: make BIO read signal retry instead of EOF when no data + dtls: New DTLS test failure with OpenSSL 4.0.0 + dvdspu: Fix too strict off-by-one bounds check in a couple of places + h263parse: diracparse: Sync baseparse configuration with other compressed video parsers + h265parser: Fix out-of-bounds writes in RPS parsing + h265seiinserter: Fix HEVC with alpha stream handling + h266parser: fix SEI parsing error handler + meson: Make the g-ir-scanner init section consistent across modules + mpegpsdemux: Use byte readers for parsing data and make sure enough data is available + openjpegdec: Various issues related to striped mode and image origins, plus memory leaks + pnmdec: Don't assert if creating the output state fails and don't flush more data than is available + tfliteinference: fix leaks + tsdemux: Don't assert if stream pad was not yet created + vabaseenc: clamp driver-reported coded size to the coded buffer size + vtdec: Don't register the hw-only variant on simulators + vulkantrash: avoid reinitializing trash objects multiple times + waylandsink: Omit reporting drop frame on preroll + webrtcbin: fix possible floating leak for post-aux + wlvideobufferpool: Fix memory leak in gst_wl_video_buffer_pool_alloc_buffer + docs: Fix build when mse library is disabled + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-base ==== Version update (1.28.5 -> 1.28.6) Subpackages: libgstallocators-1_0-0 libgstapp-1_0-0 libgstaudio-1_0-0 libgstfft-1_0-0 libgstgl-1_0-0 libgstpbutils-1_0-0 libgstriff-1_0-0 libgstrtp-1_0-0 libgstrtsp-1_0-0 libgstsdp-1_0-0 libgsttag-1_0-0 libgstvideo-1_0-0 typelib-1_0-GstAudio-1_0 typelib-1_0-GstPbutils-1_0 typelib-1_0-GstTag-1_0 typelib-1_0-GstVideo-1_0 - Update to version 1.28.6: + gl/eagl: Fix GstGLUIView leak from duplicate __bridge_retained + playsink: don't wait for text pad block during reconfiguration + typefind: Actually register various forgotten typefinders + meson: Make the g-ir-scanner init section consistent across modules + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-good ==== Version update (1.28.5 -> 1.28.6) Subpackages: gstreamer-plugins-good-gtk - Update to version 1.28.6: + aacparse: Don't assert on parsing errors or insufficient data + avidemux: Make sure enough data is available when parsing FUJIFILM strd and various other fixes + matroskademux: Make sure enough data is available when parsing FLAC headers + rtph264depay: rtph265depay: Limit the maximum fragmentation unit size + rtpqcelpdepay: Handle changes in interleave value correctly + rtpsource: fix bitrate estimation for RTX + v4l2: Use MPLANE flag to determine n_v4l_planes directly + y4mdec: Some parsing fixes + tests: qtmux: drain to EOS before teardown in test_caps_renego + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-libav ==== Version update (1.28.5 -> 1.28.6) - Update to version 1.28.6: + Fix build failure with FFmpeg 9.0 + libav: FFmpeg 9.0 Build Failure + avdemux: Close demuxer on pad deactivation instead of state change and don't use uninitialized audio channel positions + avdemux: Use a dynamic-sized array for the AVStreams ==== gstreamer-plugins-rs ==== Version update (1.28.5 -> 1.28.6) - Update to version 1.28.6: + hlsbasesink: Don't unwrap() running_time when a segment is added + hlssink3: don't unwrap() PTS of a fragment's first buffer + isobmff: Add support for video/x-h266 + isofmp4mux: use previous highest PTS when none are available + rtp: fix overflowing adds + rtpsmpte291depay: Fix depayloading frames with multiple ANC packets + rtprecv: fix deadlock handling RTCP packet in buffer list + st2038combiner: Fix off-by-one when ST-2038 pads are skewed + textaccumulate: output joined single buffer, add list as meta + webrtc: add support for nvv4l2h265enc + webrtcsink: handle level-asymmetry-allowed when answering + meson: Work around openssl-sys detection bug on Windows + meson: Sort entries for deterministic build results + Clippy and cargo test fixes + Fix some hotdoc markdown code blocks in various docs ==== gstreamer-plugins-ugly ==== Version update (1.28.5 -> 1.28.6) - Update to version 1.28.6: + asfdemux: Avoid integer overflows during bounds checks + dvdsubdec: Clip subpicture rectangle to the frame size + rtpasfdepay: Drop packets that are larger than the negotiated maximum packet size and various other fixes ==== hwdata ==== Version update (0.409 -> 0.410) - Update to version 0.410: * Update pci and vendor ids ==== kernel-source ==== Version update (7.1.5 -> 7.1.6) Subpackages: kernel-64kb kernel-default - Linux 7.1.6 (bsc#1012628). - platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug (bsc#1012628). - sched_ext: Skip ops.set_weight() for disabled tasks (bsc#1012628). - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (bsc#1012628). - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing (bsc#1012628). - KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1012628). - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (bsc#1012628). - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1012628). - KVM: x86/mmu: Fix use-after-free on vendor module reload (bsc#1012628). - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (bsc#1012628). - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (bsc#1012628). - xprtrdma: Clear receive-side ownership pointers on release (bsc#1012628). - arm64: tegra: Remove fallback compatible for GPCDMA (bsc#1012628). - Docs/admin-guide/cgroup-v2: fix memory.stat doc details (bsc#1012628). - sched_ext: Annotate ksyncs with __rcu in alloc/free_kick_syncs() (bsc#1012628). - arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 (bsc#1012628). - xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() (bsc#1012628). - xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1012628). - firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (bsc#1012628). - IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1012628). - mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins() (bsc#1012628). - mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy() (bsc#1012628). - mtd: mtdswap: remove debugfs stats file on teardown (bsc#1012628). - mtd: nand: mtk-ecc: stop on ECC idle timeouts (bsc#1012628). - btrfs: reject free space cache with more entries than pages (bsc#1012628). - btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1012628). - btrfs: fallback to transaction csum tree on a commit root csum miss (bsc#1012628). - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (bsc#1012628). - sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() (bsc#1012628). - reset: spacemit: k3: fix USB2 ahb reset (bsc#1012628). - xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1012628). - xfrm: reject optional IPTFS templates in outbound policies (bsc#1012628). - RDMA/cma: Fix hardware address comparison length in netevent callback (bsc#1012628). - RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1012628). - RDMA/irdma: Remove redundant legacy_mode checks (bsc#1012628). - RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1012628). - RDMA/erdma: initialize ret for empty receive WR lists (bsc#1012628). - RDMA/mana_ib: initialize err for empty send WR lists (bsc#1012628). - RDMA/core: Fix memory leak in __ib_create_cq() on invalid cqe (bsc#1012628). - RDMA/hns: Fix potential integer overflow in mhop hem cleanup (bsc#1012628). - RDMA/siw: publish QP after initialization (bsc#1012628). - mtd: fix double free and WARN_ON in add_mtd_device() error paths (bsc#1012628). - selftests/alsa: Fix memory leak in find_controls error path (bsc#1012628). - RDMA/irdma: Prevent overflows in memory contiguity checks (bsc#1012628). - xfrm: clear mode callbacks after failed mode setup (bsc#1012628). - xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() (bsc#1012628). - xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (bsc#1012628). - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (bsc#1012628). - wifi: mac80211: allocate backup ieee80211_nan_sched_cfg off stack (bsc#1012628). - ALSA: usb-audio: Fix imbalance per-channel volume of sticky mixers (bsc#1012628). - wifi: cfg80211: cancel sched scan results work on unregister (bsc#1012628). - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (bsc#1012628). - wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() (bsc#1012628). - wifi: mac80211_hwsim: clamp virtio RX length before skb_put ... changelog too long, skipping 1266 lines ... - commit 05b8588 ==== libXfont2 ==== - bsc1272660_CVE-2026-59679_0001-fserve-validate-num_chars-against-encoding-array-siz.patch * libXfont2 fs_read_glyphs() heap OOB read/write via encoding array index mismatch (CVE-2026-59679, bsc#1272660) - bsc1272661_CVE-2026-44950-0002-fserve-bounds-check-cumulative-glyph-data-writes-in-.patch * libXfont2 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow (CVE-2026-44950, bsc#1272661) ==== libgpg-error ==== - Add upstream patch to fix build on 32-bit arm: * libgpg-error-fix-armv7.patch ==== libphonenumber ==== Version update (9.0.34 -> 9.0.36) - update to 9.0.36: * Updated alternate formatting data for country calling code(s): 995 * Updated phone metadata for region code(s): BD, EH, FO, GE, IL, LI, MA, ML, NO, SJ * Updated short number metadata for region code(s): FO, IT * Updated carrier data for country calling code(s): 47 (en), 61 (en), 212 (en), 256 (en), 298 (en), 423 (en), 972 (en), 995 (en) - includes changes from 9.0.35: * Updated alternate formatting data for country calling code(s): 995 * Updated phone metadata for region code(s): AC, CN, FO, GE, IR, KE, SE, UG, ZW * Updated short number metadata for region code(s): FR * Updated geocoding data for country calling code(s): 86 (en, zh) * Updated carrier data for country calling code(s): 61 (en), 86 (en, zh), 93 (en, fa), 247 (en), 250 (en), 254 (en), 256 (en), 263 (en), 298 (en), 420 (en), 976 (en), 995 (en) ==== libpsl ==== Version update (0.23.0 -> 0.23.1) - Update to version 0.23.1: * Fix reproducible builds, a regression introduced in 0.23.0 * psl-make-dafsa embeds only the basename of the input file * Allow explicitly disabling fuzzing at configure time ==== libraw ==== Version update (0.22.1 -> 0.22.2) - update to 0.22.2: * Fixed 6yr old typos in USE_6BY9RPI 8- and 16- bit decoders * trimSpaces: Improved handling of zero-length strings and strings consisting only of spaces * Misc fixups * Fix links to license files in contributing document * removeExcessiveSpaces: handle zero-length strings the right way * contributing rules updated * Zero read buffers before fread * FP DNG loader: check for tile index; convertFloatToInt: avoid possible integer overflow * open_bayer(): reject images with raw size/visible size less than 22 (as in open_file/identify); vng_interpolate: do not interpolate images less than 8x8 * PPM16 thumb: check against LIBRAW_MAX_THUMBNAIL_MB * open_bayer(): additional input data checks * Olympus/14bit: refuse incorrect wbits metadata * X3F decoder: initialise raw storage if LIBRAW_CALLOC_RAWSTORE defined * crx decoder: check plane size agains imgdata.rawparams.max_raw_memory_mb * Crx decoder: avoid possible int32 overflow on allocation size calculations * check for ifd->bps values in FP DNG decoder * fixed stack memory/previous image metadata exposure (reported by DMSAN) * LibRaw_memmgr: allow malloc to fail on local pointer array small allocation. It will definitely fall later on large-buffer allocation * rotated fuji: stricter image size limits; raw2image(ex): avoid possible 32-bit overflow on alloc size calculations * width/height and iwidth/height values documented * width/height and iwidth/height values documented * wavelet denoise: ensure allocation size not exceed 4GB * unpack_thumb: check JPEG thumbnail size before performing allocation; Remove all allocation test results because LibRaw::calloc/malloc will raise exception if allocation fails * removed row_stride signed/unsigned mix; check row_stride value against buffer size * fixed possible next struct item override in x3f_parse * parse_phase_one: prevent buffer overrun if incorrect flat field data provided * Limit parse_mos recursion depth; parse_qt: raise exception, do not hide too depth nesting error * parse_qt: avoid too deep recursion ==== libssh2_org ==== - Security fixes: * CVE-2026-58050: Attacker controlled attribute count from a publickey-subsystem response is used without bounds checking and can cause to a heap buffer overflow in a connecting libssh2 client (bsc#1269568) * CVE-2026-58051: Public key list is increased and does not zero-initialized new entries, which can cause an uninitialized pointer to be freed when a malformed response is sent by an SSH server (bsc#1269567) * Add patches - libssh2-CVE-2026-58050.patch - libssh2-CVE-2026-58051.patch - Security fixes: * CVE-2026-66032: Arbitrary code execution via double-free in SFTP session (bsc#1272737) * CVE-2026-66033: Denial of Service via integer underflow in AES-GCM cipher negotiation (bsc#1272736) * CVE-2026-66034: Information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735) * CVE-2026-66035: Arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734) * Add patches: - libssh2-CVE-2026-66032.patch - libssh2-CVE-2026-66033.patch - libssh2-CVE-2026-66034.patch - libssh2-CVE-2026-66035.patch ==== libvirt ==== Version update (12.5.0 -> 12.6.0) Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - virsh: Fix potential NULL pointer dereference crash bsc#1272852 - Update to libvirt 12.6.0 - CVE-2026-15268, CVE-2026-61477, CVE-2026-61478, CVE-2026-63622, CVE-2026-63623 - jsc#PED-14588 - Many incremental improvements and bug fixes, see https://libvirt.org/news.html#v12-6-0-2026-08-03 ==== mozjs140 ==== Version update (140.12.0 -> 140.13.0) - Update to version 140.13.0: + Various security fixes + See https://www.firefox.com/en-US/firefox/140.13.0/releasenotes/ ==== mpg123 ==== Version update (1.33.6 -> 1.33.7) Subpackages: libmpg123-0 mpg123-openal - Update to version 1.33.7 mpg123: * Fix information disclosure of uninitialied memory for - -auth-file without line endings. * Fix out-of-bounds read/write when combining --continue - -random --listentry where n is larger than the playlist size. * Fix a harmless valgrind memory leak report by not nulling playlist name. * Fix a mostly harmless OOB read of 1 byte when printing USLT lyrics. * Fix leaking file descriptor on read error from --equalizer file. * Hardening of loading HTTP(S) via curl or wget against funky URLs by including the -- separator. No actual vulnerability, tough, just extra care. out123: * Fix heap overrun on --endian conversion with differing input and output channel counts. * Fix parsing of filter specs with whitespace before commas, which resulted in out-of-bounds writes before. libmpg123, mpg123: Harden memory realloc calls against multiplication overflow of size_t in arguments. Specifically, this addresses part of bug 389 with possible application abuse of mpg123_set_index64(). libmpg123: * Fix possible use of uninitialized values in layer III dequantization. III_dequantize_sample() for consistent output also for strange input. The new code seems to be slightly faster after some rearrangements. * Fix a double free when deleting a handle after failed mpg123_decoder() call (possibly among others). * More strong wording in API that ID3 text convenience links are short-lived, but safeguard against ignorant use by nulling them early. * Prevent double free in mpg123_set_index() 32 bit wrapper being called with index size 0. * Harden against an application wielding a foot gun by handing in an undersized decoding buffer betwee seek and read (return error before trying to decode and discard frames in that case). * Do properly terminate ID3v2 texts coming in UTF16 encoding when they overwrite previous frames, like with other encodings. The symptom was a shorter second frame resulting in a combined text with the earlier longer frame. * Check and properly handle null source buffer and zero size in mpg123_store_utf8() instead of reading past (before) buffers. * Ensure clients get ID3v1 data with (unmotivated) mpg123_id3_raw() only if the parser decided that it is there, not possibly the last 128 bytes of a seekable stream without ID3v1 tag. * Prevent impossible NtoM resampling with too low target rate (like 1 Hz) which would trgger endless looping. libout123: * Fix deadlock in buffer mode when combined with (stereo) 24 bit output. Now also mpg123 --buffer 4096 -e s24 shall actuallly work. Sorry. * Abort early on zero/negative rate and channel count in out123_start(). * Fix divide by zero in WAV writing by catching channel counts that go zero in the 16 bit WAV header field. libsyn123: * Explictly reject mismatched format for appending filters with syn123_setup_filter(), preventing memory errors from that API-violating use. * Harden the dirty resampling interpolator against extreme rates (around 1e18 Hz) by fixing a sample offset check to not do the exact overflowing addition that it is supposed to guard against. The fine resampler was… fine. * Error out on trying to create a filter of order 0 instead of dividing by zero later. ==== nano ==== Version update (9.1 -> 9.2) - Update to version 9.2: * Nano refuses to start when standard output is not a terminal. * Options --newbuffer and 'set newbuffer' were added as better synonyms of --multibuffer (which keeps working). * The legacy keystroke pairs ^W^T and ^/^T are recognized again. * Fix a crash at startup when a section of the history file is overlong. ==== nfs-utils ==== Subpackages: libnfsidmap1 nfs-client nfs-kernel-server - Require python3-PyYAML on openSUSE and SLE: the python-* symbol is valid in both cases. On openSUSE, this is provided by the module targetting the primary interpreter, which matches the shebang of the python scripts lines being /usr/bin/python3. - nfs-client: make the rpcctl util executable (bsc#1273197) The specfile intentionally clears the execute bit for all python-based utilities during the build, in order to prevent generating a package dependency to the python interpreter. It subsequently restores the execute bit explicitly for every single script. In the case of rpcctl this was overlooked when the utility was introduced, and therefore it was packaged without execute permissions. Fix this by restoring the permissions. - Introduce new sub-package nfs-tools-extra, and move all python-based tools into that (bsc#1268167). The nfs-utils base packages previously suggested python-base as a soft dependency, as some of the less used tools rely on that. Some of those have further specific python dependencies (such as nfsdclnts which needs pyyaml). We do not want to pull in python as a strict requirement to any of the base nfs-utils packages to keep the base as minimal as possible. Thus we introduce a new package (nfs-tools-extra) that includes all those optional python-based tools, and make that package require pyyaml and python transitively. Also, the base packages now suggest nfs-tools-extra, instead of python. - update to 2.9.2: * nfsd: fix memory overflow for haddr * gssd: fix memory leak in gssd_free_client * Pass ignore_hosts to export_create() in export_read() * mountd/exportd: disable netlink when falling back to /proc * nfs.conf: add no-netlink option to exportd and mountd stanzas * nfsstat: display NFSv4 callback operation statistics * libnfsidmap: avoid malloc(0) for empty Local-Realms * exportfs: drop unused is_export parameter from xtab_read() and xtab_write() * support/backend_sqlite.c: fix getrandom() fallback * nfs-iostat: add option to display throughput in MB/s * exportfs: release NFSv4 state when last client is unexported ==== ngtcp2 ==== Version update (1.24.0 -> 1.25.0) Subpackages: libngtcp2-16 libngtcp2_crypto_gnutls8 libngtcp2_crypto_ossl0 - Update to 1.25.0: * Fix build error with gcc-16 * Add ngtcp2_stream_close2 callback * Verify the end offset of STREAM frame before updating flow control * Rework connection flow window accounting after sending STOP_SENDING * Stop buffering data after shutting downstream read * Expand NGTCP2_MAX_INITIAL_CRYPTO_OFFSET to 64K so that large post-quantum key shares are no longer rejected * Handle a client migrating back to the original path * crypto/quictls: Rework the global initialization * ksl: Align keys in 8 bytes boundary * bbr: Update longterm variable computation * Optimize rob and acktr - Drop the now-dead libnghttp3 dependency: --with-libnghttp3 and its BuildRequires only affect the examples, which - -enable-lib-only does not build - Declare the version floors configure actually checks: pkgconfig(gnutls) >= 3.7.3 and pkgconfig(openssl) >= 1.1.1 - Clean up the spec file with spec-cleaner (drop obsolete Group tags) ==== open-isns ==== Version update (0.103+2.296d533bd52a -> 0.103+4.60de8b5) - Update to version 0.103+4.60de8b5: * Fix issue in error path causing double-free. Fixes issue CVE-2026-55995 bsc#1268685 ==== openSUSE-release ==== Version update (20260802 -> 20260806) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openblas_openmp ==== Subpackages: compatlibopenblas_openmp0 libopenblas_openmp0 - Let the compat package provide libopenblas.so.0 instead of the flavour package: * every flavour carries the SONAME libopenblas.so.0, but the libraries live in the private flavour directory, so the automatic provide advertises a SONAME the dynamic linker cannot resolve * the update-alternatives link that does make it resolvable belongs to the compatlib package, which was only reachable through Supplements, and OBS build roots do not honour Supplements * consumers therefore resolved against the flavour package alone and then failed at load time, for example libarpack2, which broke every gdal-linked package in Application:Geo * filter the generated provide and declare it on the compat package ==== openblas_pthreads ==== Subpackages: compatlibopenblas_pthreads0 libopenblas_pthreads0 - Let the compat package provide libopenblas.so.0 instead of the flavour package: * every flavour carries the SONAME libopenblas.so.0, but the libraries live in the private flavour directory, so the automatic provide advertises a SONAME the dynamic linker cannot resolve * the update-alternatives link that does make it resolvable belongs to the compatlib package, which was only reachable through Supplements, and OBS build roots do not honour Supplements * consumers therefore resolved against the flavour package alone and then failed at load time, for example libarpack2, which broke every gdal-linked package in Application:Geo * filter the generated provide and declare it on the compat package ==== plasma6-integration ==== - Put Qt 5 integration into a separate optional package ==== plasma6-workspace ==== Subpackages: plasma6-session plasma6-session-x11 plasma6-workspace-libs sddm-qt6-branding-openSUSE - sddm.conf: Set plasmawayland.desktop as default session - No longer recommend plasma6-session-x11 ==== polkit-default-privs ==== Version update (1550+20260623.563df94 -> 1550+20260803.90784eb) - Update to version 1550+20260803.90784eb: * profiles: renamed calamares (bsc#1273196) * build(deps): bump actions/checkout from 6.0.2 to 7.0.1 ==== python-anyio ==== Version update (4.13.0 -> 4.14.2) - Instead of using sed make a proper patch extend_timeouts.patch to increase timeout in test_pytest_plugin module - Add robust_test_shielded_cancel_sleep_time.patch making that test more robust (gh#agronholm/anyio!1264). - Add fix-uvloop-closed-loop-race.patch to protect against a race condition in the test_cancel_worker_thread test (gh#agronholm/anyio!1266). - Update to 4.14.2: - Changed ByteReceiveStream.receive() implementations to raise a ValueError when max_bytes is not a positive integer - Fixed CapacityLimiter.total_tokens rejecting float("inf") when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (value is math.inf), so only the exact math.inf singleton was accepted, while every backend setter (using math.isinf()) accepts any positive infinity - Fixed to_process.run_sync() deadlocking when the worker function writes enough data to sys.stderr to fill the (undrained) pipe buffer. The worker process now redirects sys.stderr to os.devnull as well, matching the documented behavior - Fixed TLSStream.wrap() matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate - Fixed anyio.open_process() (and run_process()) ignoring the extra_groups argument, as it mistakenly passed the value of the group argument instead - Fixed CapacityLimiter.acquire_nowait() and CapacityLimiter.acquire_nowait_on_behalf_of() raising trio.WouldBlock instead of anyio.WouldBlock on the trio backend when there are no tokens available - Fixed CapacityLimiter on the asyncio backend over-granting tokens (borrowed_tokens exceeding total_tokens and available_tokens going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises WouldBlock - Fixed unnecessary CPU spin when delivering cancellation from CancelScope on asyncio under certain conditions, including improper cancel scope nesting - Update to 4.14.1: - Fixed teardown of higher-scoped async fixtures failing on asyncio with RuntimeError: Attempted to exit cancel scope in a different task than it was entered in when an async test raise an outcome exception (e.g., pytest.skip(), pytest.xfail(), or pytest.fail()) - Fixed CapacityLimiter.total_tokens rejecting a value of 0 when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens - Update to 4.14.0: - Added support for Python 3.15 - Added an asynchronous implementation of the itertools module - Added the local_port parameter to connect_tcp() to allow binding to a specific local port before connecting - Added support for custom capacity limiters in async path and file I/O functions and classes - Added the create_task() task group method for easier asyncio migration (returns a TaskHandle) - Changed TaskGroup.start_soon() to return a TaskHandle - Added an option for TaskGroup.start() to return a TaskHandle - Added the cancel() convenience method to TaskGroup as a shortcut for cancelling the task group's cancel scope - Improved the error message when a known backend is not installed to suggest the install command - Improved anyio.Path to preserve subclass types by returning Self in methods that return path objects - Changed the parameter type annotation in anyio.Path.write_bytes() to accept any ReadableBuffer, thus allowing it to accept bytearray and memoryview to match pathlib.Path.write_bytes() - Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables: TaskGroup.start_soon() TaskGroup.start() anyio.from_thread.run() - This reverts an earlier change from v3.7.0 which was made in error. - Changed anyio.run to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio - Changed several classes (and their subclasses) to have __slots__ (with __weakref__): anyio.CancelScope anyio.CapacityLimiter anyio.Condition anyio.Event anyio.Lock anyio.ResourceGuard anyio.Semaphore - Fixed cancellation exception escaping a cancel scope when triggered via check_cancelled() in a worker thread - Fixed TaskGroup raising AttributeError instead of a clear ... changelog too long, skipping 24 lines ... cancelled waiters left queued during release ==== python-charset-normalizer ==== Version update (3.4.7 -> 3.4.9) - update to 3.4.9: * Regression in our fallback path leading to a decode error. * We've yanked 3.4.8 as a result of that bug. * Wall import time due to cascade codec imports for our multibyte first sort of iana supported codecs * Unnecessary json import at runtime * Inverse capitalization not seen by noise detector * No longer holding a global cache for our noise / coherence measurements. Relax RSS memory usage. * Micro-optimizations in our noise / coherence measurements. * No longer using regex search by default for our preemptive charset mark algorithm. * Raised upperbound of setuptools to v83. * Raised upperbound of mypy(c) to v2.1. ==== python-cryptography ==== Version update (49.0.0 -> 50.0.0) - update to 50.0.0 (bsc#1273551, CVE-2026-69247): * SECURITY ISSUE: :func:`~cryptography.hazmat.primitives.serial ization.pkcs7.pkcs7_decrypt_der` and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in RFC 3218. Credit to @X1AOxiang for reporting the issue * Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm. * Added xof() class methods to :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing algorithm instances configured for use with :class:`~cryptography.hazmat.primitives.hashes.XOFHash`. * The :mod:`X.509 verification ` APIs are now considered stable and are subject to our API stability policy. * Added the :doc:`/cobblestone` recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages. * Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them. * Added support for using :class:`~cryptography.x509.Name` as a field type in the :doc:`/hazmat/asn1/index` module. * Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it. * Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field. * :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading certificates, CSRs and CRLs. * :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported when building against AWS-LC. * HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC. * Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported when building against AWS-LC. * :func:`~cryptography.hazmat.primitives.serialization.load_der _public_key` and :func:`~cryptography.hazmat.primitives.seria lization.load_pem_public_key` now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits, matching the minimum already enforced when loading DH private keys and when constructing :class:`~cryptography.hazmat.primitives.asy mmetric.dh.DHParameterNumbers`. * Added :class:`~cryptography.hazmat.primitives.asymmetric.mlds a.MLDSAMuHasher` for incrementally computing the ML-DSA mu (message representative) used by the external-mu signing and verification APIs. * The builtin :class:`~cryptography.hazmat.primitives.hashes.HashAlgorithm` classes and the classes in :mod:`~cryptography.hazmat.primitives.asymmetric.padding` can now be compared with ==. * :class:`~cryptography.x509.CertificateBuilder` now supports creating unsigned certificates (RFC 9925) with the create_unsigned method. * The :mod:`X.509 verification ` APIs now permit ML-DSA-44, ML-DSA-65, and ML-DSA-87 (RFC 9881) public keys and signatures by default. ==== python-numpy ==== - Skip a test to unblock Python 3.15 until new upstream release. ==== python-pip ==== Version update (26.1.2 -> 26.2) - Update to 26.2 (bsc#1273090, CVE-2026-13346): [#] Deprecations and Removals - Newly published packages will no longer be immediately visible to pip if the index uses caching. To install a newly published package, use ``--refresh-package``. - Drop support for detecting legacy, non-:pep:`405`, ``virtualenv`` (< 20) environments. - Constraints files, including ``PIP_CONSTRAINT``, no longer affect isolated build environments. Use ``--build-constraint`` or the ``PIP_BUILD_CONSTRAINT`` environment variable to constrain build dependencies instead. The ``--use-feature=build-constraint`` flag is now always enabled and has no effect. [#] Features - Declare support for Python 3.15 - Support self-referential extras officially. pip has supported this by accident since version 21.2. - Add ``--only-deps`` flag to instruct pip to select only the dependencies of supplied packages. It cannot be used with ``--no-deps``, ``-r``, ``--group``, or ``--requirements-from-script``. - Cache simple responses in accordance to their ``Cache-Control`` header instead of always revalidating on every request. To refresh cached package index responses and ensure newly published packages are found, use ``--refresh-package ``. - Add ``--no-require-hashes`` to disable automatic enablement of ``--require-hashes`` when encountering a requirement with hashes. - Honor ``--only-final`` when sourcing requirements with ``-r pylock.toml``. - Add support for ``pylock.toml`` ``upload-time`` field, so ``--uploaded-prior-to`` works with ``-r pylock.toml``. - Better error messages in case of conflicts with requirements from ``-r pylock.toml``. - Add experimental support for isolating build subprocesses by creating standard virtual environments. This will fix most (if not all) subtle isolation issues that can lead to broken builds exclusive to pip. The feature can be enabled via ``--use-feature=venv-isolation`` and will be enabled by default in a future release. Note that the feature has limited compatibility with ``--use-feature=inprocess-build-deps``. While most builds should work with both features enabled, there are known edge cases. ``inprocess-build-deps`` will not be enabled by default until they are fixed. - Present more informative diagnostic errors on uncaught network errors. - Allow opting out of Git partial clones with ``PIP_NO_PARTIAL_CLONE_FOR_BROKEN_GIT_SERVER``. - Add a ``--no-proxy-env`` (or ``--proxy ""``) option to ignore proxies configured via non-pip environment variables or configuration files. A proxy set with ``--proxy`` is still used. - Add support for pulling username from keyring subprocess provider - Speedup tab autocompletion by lazy-importing certain modules. - Improve cached wheel lookup performance when many cached wheels are checked for compatibility. - Speed up path compaction when displaying uninstall changes. [#] Bug Fixes - Only emit the invalid-metadata warning once per location per run, instead of repeating it during the same command. - Handle ``BrokenPipeError`` when pip output is piped to a command that closes early. - Follow symlinks while checking if installed scripts are on PATH. - Stop dropping extras from messages about candidates with inconsistent metadata. - Stop animating progress bars and status spinners when running on CI, even if ``FORCE_COLOR`` is set. - Ensure truststore feature remains active while initially connecting to a HTTPS proxy. - Address encoding warnings emitted when Python's UTF-8 Mode is enabled by continuing to use the configured locale. - Raise an error when the :pep:`658` ``.metadata`` file used during dependency resolution disagrees with the downloaded wheel's ``METADATA`` on ``Name``, ``Version``, ``Requires-Dist``, ``Requires-Python`` or ``Provides-Extra``. - Prevent system packages from leaking into isolated build environments on Python 3.15 - Never use persistent wheel cache for local directory requirements even if there is a matching entry. - Avoid re-fetching a pinned Git commit that is already present locally. - Report the correct configuration level for ``cert`` in ``pip debug`` output. - Fix ``pip show`` crash when a distribution has no ``Metadata-Version``. - Remove empty ``http-v2`` cache directories when running ``pip cache purge``. - Report a copy failure in ``pip wheel`` instead of a misleading build failure. - Make ``pip install`` conflict checks independent of installed distribution iteration order. - Fix ``ProtocolError`` exceptions raised after an incomplete download from bypassing download resume logic and leading to a crash. - Fix caching bug where local directory requirements would be cached if the directory name contains a dash. - Avoid reparsing distribution metadata when formatting the default ``pip list`` columns output with the importlib backend. - Fix decoding the URL path twice while determining a link filename (CVE-2026-13346). ... changelog too long, skipping 38 lines ... requirement marker. ==== python-pyOpenSSL ==== Version update (26.3.0 -> 26.4.0) - Update to 26.4.0: * Maximum supported cryptography version is now 50.x. ==== python-pyzmq ==== - Pin scikit-build-core's CMake build directory for reproducible builds. Otherwise it uses a random tempdir whose path leaks into the debug info that the linker hashes into the GNU build-id note of the later-stripped _zmq*.so, making the build non-reproducible even though the actual code is identical. ==== qtkeychain-qt6 ==== Version update (0.16.0 -> 0.17.0) Subpackages: libqt6keychain1 qtkeychain-qt6-lang - Update to 0.17.0 * Windows: Do not ignore "service" when storing data. Note: This is a breaking change. * Android: Support payloads > 256kb * Add wasm backend * CMake: Assume Qt 6 by default; pass -DBUILD_WITH_QT5=ON to use Qt 5 ==== selinux-policy ==== Version update (20260727 -> 20260804) Subpackages: selinux-policy-targeted - Update to version 20260804: * Use NetworkManager_t instead of networkmanager_t * Changes adapting to bind packages with suffixes * Dontaudit unconfined_t map its private directories * Support cronie create crontab backups * Allow nfsidmapd read virt lib files * Allow sysadm_t run and read/write networkmanager bpf programs * Allow dhcpc_hook_t connect to init_t over a unix stream socket * Allow unconfined_t mounton its lnk_files * Allow wireguard read cgroup files * Label /usr/local/share/man with man_t * Allow pcscd get attributes of a pty filesystem * Allow geoclue read cgroup files * Allow init_t nnp domain transition to postgresql_t * Move bootupd systemd interface to 2 optional blocks * Allow net_admin to the nfsd_t domain * Allow kernel write to unconfined and sysadm users' keys * Allow staff user ioctl cockpit-session stream sockets * Allow the staff user mount on tmpfs directories * Allow staff user the dac_override capability in the user namespace * Allow aide get attributes of all filesystems * Make insights_client_t accessible from the system cronjob * Support systemtap on a UEFI+SecureBoot system * Allow systemd-coredump signull spc container * Allow dhcpcd hook scripts read generic files in /proc - Syncing with upstream rawhide selinux-policy up to: * 5c9bff8fbdaeb41b724b68937c706dc5e42a490a ==== shadow ==== Version update (4.19.4 -> 4.20.0) Subpackages: login_defs shadow-pw-mgmt - Update to 4.20.0: * Removals: The following programs and features were deprecated in 4.19 or earlier, and have been removed in 4.20. + expiry(1) (deprecated in 4.19). See #1481 and #1432. + login.defs(5): ENCRYPT_METHOD: DES (deprecated in 4.19). See #1456. + login.defs(5): ENCRYPT_METHOD: MD5 (deprecated in 4.19). See #1457. + login.defs(5): MD5_CRPYT_ENAB (deprecated since the dinosaurs were around). See #1455. + shadow(5): .sp_min (deprecated in 4.19). See #1482. This also includes the following removals: - chage(1): -m,--mindays (also the interactive version) - passwd(1): -n,--mindays - login.defs(5): PASS_MIN_DAYS This feature is considered a vulnerability, and was removed without replacement. Programs will now fail when any of those flags or variable are specified. This is intentional, and should help identify any scripts that rely on these. + groupmems(8) (deprecated in 4.19). See #1343 and #1601. Use usermod(8) instead. + logoutd(8) (deprecated in 4.19). See #999 and #1344. * Defaults: The following default values were changed. + login.defs(5): Remove defaults for password expiration (PASS_MAX_DAYS, PASS_WARN_AGE). See #1428. + login.defs(5): ENCRYPT_METHOD: Default to SHA512 (previously, it was DES). See #1278 and #1454. Users should still explicitly specify it, since other programs that read login.defs(5) may still default to DES. * Features: The following features that were optional in 4.19 are now unconditionally supported in 4.20. + SHA256, SHA512 See #1278 and #1452. * Regressions: Some regressions have been introduced (as side effects of bug fixes) and they're here to stay. Users must adapt. + `su - ` as root brings inappropriate ioctl for device #1704 + `usermod --unlock` on an account without valid password will exit with status 20 instead of print a warning #1706 * Dependencies: + We've removed an unused dependency (libattr). See #1473. * Deprecations: No new deprecations since 4.19. However, we maintain the deprecations from then. - Refresh patches: * shadow-login_defs-comments.patch Line offsets and dropping MD5_CRYPT_ENAB. * shadow-login_defs-suse.patch Drop PASS_MAX_DAYS/PASS_MIN_DAYS/PASS_WARN_AGE. We set them to 0 earlier to disable them because PAM handles it. So we have the same effect still. Drop PASS_MAX_LEN since DES support got removed. Drop MD5_CRYPT_ENAB. PASS_CHANGE_TRIES got dropped upstream. * shadow-login_defs-unused-by-pam.patch Drop PASS_MAX_DAYS, PASS_MIN_DAYS, PASS_WARN_AGE, PASS_MAX_LEN, and PASS_MIN_LEN. * shadow-util-linux.patch - Add PASS_ALWAYS_WARN, PASS_CHANGE_TRIES, PASS_MAX_DAYS, PASS_MIN_LEN, PASS_WARN_AGE, OBSCURE_CHECKS_ENAB to false positives in shadow-login_defs-check.sh - Add shadow-4.20-stdint.patch to fix an include ==== socat ==== - Use %{arm} instead of armv6l/armv6hl to include armv7 as well ==== swtpm ==== Subpackages: swtpm-selinux - Fix SELinux policy for virtqemud_t swtpm_t setsched process and unix socket interactions. Allows virtqemud_t to: Signal and control swtpm_t processes (noatsecure, rlimitinh, siginh, signull, setsched), create and listen on Unix stream sockets with swtpm_t processes (bsc#1266339). Already accepted on upstream: https://github.com/stefanberger/swtpm/pull/1132 - Add patch: 1132.patch ==== u-boot-rpiarm64 ==== Version update (2026.01 -> 2026.07) Subpackages: u-boot-rpiarm64-doc - Update to 2026.07: * Full changelog available at: https://source.denx.de/u-boot/u-boot/-/compare/v2026.04...v2026.07 - Use tools-only config instead of sandbox for u-boot-tools - Handle openSUSE:Factory:LegacyARM and remove old Leap:15.2 - Update to 2026.04: * Full changelog available at: https://source.denx.de/u-boot/u-boot/-/compare/v2026.01...v2026.04 - Patch queue updated from https://github.com/openSUSE/u-boot.git tumbleweed-2026.04 * Patches dropped: 0014-Enable-EFI-and-ISO-partitions-suppo.patch 0015-cmd-boot-add-brom-cmd-to-reboot-to-.patch 0016-Kconfig-add-btrfs-to-standard-boot.patch * Patches added: 0014-cmd-boot-add-brom-cmd-to-reboot-to-.patch 0015-Kconfig-add-btrfs-to-standard-boot.patch ==== unbound ==== Version update (1.25.2 -> 1.26.0) Subpackages: libunbound8 unbound-anchor - Update to 1.26.0: * Update icannbundle.pem certificates in unbound-anchor, valid for 2009-2029 and 2025-2045 * Add max-transfer-size and max-transfer-time options to limit auth-zone and rpz transfer size and time, default disabled * Overload local_data_remove in unbound-control to also remove specific records * Add local-zone types block_aaaa, block_a_wdata and block_aaaa_wdata; fix respip+dns64 to use original A records instead of ones already modified by respip * ipsecmod hook script now needs to start with '#!/bin/sh', it is executed with execv instead of system for security * Server now continues to start if a secondary zone fails to load from its zonefile, or if a primary zonefile is missing; $INCLUDE is no longer allowed in secondary zone zonefiles * Auth-zone and RPZ zones now drop out-of-zone content on load * Primary hostname for zone transfers can now use CNAME(s) * Fix windows 64bit build for libssp dependency * Update IANA portlist * Fix heap out-of-bounds write via size_t-to-int truncation in setup_if()/outside_network_create() for large num_ports values * Fix to clean up log ids after a failure to start a worker thread * Relax assertions after the TTL 0 handling change in cachedb and packet_rrset_copy_region * Fix val_find_DS to check the result of packet_rrset_copy_region before using it * Fix that dns64 answers check the AAAA query is DNSSEC validated, improving RFC6147 conformance * Fix allocation-failure hardening of rrset cache wildcard storage and canonical NSEC owner replacement * Fix DNSSEC validation and DNSKEY size calculation for noncanonical RSA DNSKEYs with leading zeroes * Fix mixed class referrals to use the query class * Fix serve-expired responses from cachedb to not store bogus data * Fix lame server detection for selfpointed glue records * Fix cleanup of DoH sessions when the same query is on multiple streams * Fix for signed same-owner CNAME and ordinary RRset responses * Fix mesh new client/callback to roll back added address, tcp mesh state and callback on initialization failure * Fix autotrust state-file line overflow that could give a hold-down bypass * Fix to limit the DSNS per-label walk in the iterator * Fix that the ratelimit is decremented on successful referrals * Fix msgencode insert_query assertion for a local_alias * Fix to reset the tcp-timeout before applying a load based reduction * Fix to correctly decrement per-netblock tcp connection limits * Fix, in depth, for respip rewrite of dns64 responses * Fix that dns64 with subnetcache does not write ECS scoped answers to the global cache * Fix ipset module name-too-long checks and race conditions on the local name buffer and socket close * Fix validator to cap the number of ANY RRsets it validates and shorten the wait timer * Fix race condition causing segfault when starting threads * Fix header_seen detection for trust anchor files to detect the id line * Fix heap use-after-free in class response processing when at least two distinct classes are configured * Fix negative cache to work with NSEC3 records without salt * Fix parse of svcbparam ech, it had an incorrect length * Fix that quotation and escaping works the same in auth-zone url content as in zonefile reads * Fix ipset module to use larger domain name buffers and check buffer lengths * Fix PROXYv2 header read and consume to check the header size * Fix negative cache NSEC3 nodata proof to use the correct message size * Fix fast_reload for when a ZONEMD lookup is in progress * Fix that validation canonicalization of domain names in rdata checks buffer bounds * Fix dump_cache to use a larger record buffer and check that an owner name does not collide with BADRR * Fix that dns64 cleans up the allocated message if the adjust routines fail, and checks for malformed A/AAAA in auth-zones * Fix pythonmod script read for numeric overflow * Fix configure to detect the correct QUIC early-data function and to check for the ngtcp2_crypto_ossl header * Fix compile with OpenSSL 4.0.1, and with OpenSSL 1.0.2 and earlier in server cleanup * Fix that auth-zone/rpz allow-notify addresses and netblocks are available from start, and fix the probe step skip * Fix to perform a full transfer periodically to stop increasing memory usage for rpz zones * Fix assertion failure for a long HTTP header that fills the buffer, and buffer overflow with lower than default size and http transfer * Fix that misconfigured iter-scrub-ns: 0 causes request failures * Fix fast_reload handling of in-progress ZONEMD lookups and of removing an auth zone while its lookups are in progress * Fix integer overflow in infra-cache-max-rtt calculation and for very high values of sock-queue-timeout * Fix erroneous DNS error report values after a bogus AAAA query * Fix fast_reload to not terminate the server on config errors for key files * Fix log of an aliased qname to not use freed region memory ... changelog too long, skipping 76 lines ... * pythonmod: check the return value after ftell() ==== usbredir ==== Version update (0.14.0 -> 0.15.0) Subpackages: libusbredirhost1 libusbredirparser1 - Update to version 0.15.0: * Fix server crash on second incoming connection (closes #38). * usbredirtestclient: fix memory leak. * Fix -Wincompatible-pointer-types on mingw32. - Clean up spec file using spec-cleaner: * Prune over-expanded pkgconfig GLib requirements. * Use %?ext_man macro for manpage compression. - Enable test suite run during build in %check. ==== vulkan-loader ==== Version update (1.4.350 -> 1.4.357) - Update to tag SDK-1.4.357.0 * Log driverUUID instead of deviceUUID for missing device config * Some fixes to missing bounds checks, overflows, out-of-bounds reads ==== vulkan-tools ==== Version update (1.4.350 -> 1.4.357) - Update to tag SDK-1.4.357.0 * vulkaninfo: Add VK_KHR_display support and related fixes