Packages changed: aaa_base (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) apache2-mod_php8 (8.5.10 -> 8.5.11) argyllcms (3.4.1 -> 3.5.0) bash (5.3.15 -> 5.3.20) bash-completion (2.17.0 -> 2.18.0) bind (9.20.26 -> 9.20.29) binutils (2.45 -> 2.47) bluez cairo (1.18.4 -> 1.18.6) cups dbus-1-glib (0.114 -> 0.116) dracut (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) emacs flatpak (1.18.3 -> 1.18.4) freerdp (3.31.1 -> 3.32.1) fribidi (1.0.16 -> 1.0.17) fwupd (2.1.7 -> 2.1.8) gcr (4.4.0.1 -> 4.4.1) gimp gnome-user-docs (50.4 -> 50.5) google-noto-coloremoji-fonts (20250916 -> 20260924) gpsd gspell (1.14.4 -> 1.14.5) hwinfo (25.5 -> 26.0) jitterentropy kernel-firmware-amdgpu (20260829 -> 20260926) kernel-firmware-ath10k (20260809 -> 20260926) kernel-firmware-ath11k (20260610 -> 20260926) kernel-firmware-ath12k (20260813 -> 20260926) kernel-firmware-bluetooth (20260828 -> 20260929) kernel-firmware-brcm (20260610 -> 20260915) kernel-firmware-intel (20260728 -> 20260916) kernel-firmware-iwlwifi (20260820 -> 20260926) kernel-firmware-media (20260813 -> 20260926) kernel-firmware-mediatek kernel-firmware-mwifiex (20260610 -> 20260926) kernel-firmware-network kernel-firmware-platform kernel-firmware-qcom (20260828 -> 20260929) kernel-firmware-qlogic kernel-firmware-realtek (20260731 -> 20260915) kernel-firmware-sound (20260825 -> 20260926) kernel-source (7.2.7 -> 7.2.8) kirigami-addons6 (1.13.0 -> 1.14.0) libX11 libXi libXpm libXtst liblognorm (2.1.0 -> 2.1.1) libphonenumber (9.0.38 -> 9.0.40) libraw libsecret (0.21.7 -> 0.21.8.2) libslirp (4.9.3+4 -> 4.9.5+1) libsodium libstorage-ng (4.5.354 -> 4.5.355) libtasn1 libtheora libupnp (22.1.2 -> 22.1.7) llvm23 (23.1.1 -> 23.1.2) mozjs140 (140.16.0 -> 140.17.0) nbd openSUSE-release (20260924 -> 20260930) openexr (3.4.14 -> 3.4.15) openssh orca (50.2 -> 50.3) osinfo-db pam (1.7.2+git48 -> 1.7.3) pam-full-src (1.7.2+git48 -> 1.7.3) parted (3.7 -> 3.8) php8 (8.5.10 -> 8.5.11) plocate (1.1.24 -> 1.1.25) polkit-default-privs (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) python-click (8.4.2 -> 8.5.0) python-cryptography (50.0.0 -> 50.0.1) python-httpx python-jmespath python-msgpack (1.2.1 -> 1.2.2) python-pypdf (6.16.2 -> 6.19.0) raspberrypi-firmware-dt readline (8.3.3 -> 8.3.6) rpcbind rsyslog rubygem-cgi (0.5.0 -> 0.5.2) sdbootutil (1+git20260909.7cfa1f0 -> 1+git20260929.26b6989) selinux-policy (20260923 -> 20260928) shadow (4.20.2 -> 4.20.3) simdutf (9.2.0 -> 9.2.1) slang tesseract-ocr tuned (2.27.0.0+git.38d4414 -> 2.28.0) unbound (1.26.0 -> 1.26.1) utf8proc (2.11.3 -> 2.12.0) vlc (3.0.23 -> 3.0.24) vsftpd wireplumber xdg-dbus-proxy (0.1.8 -> 0.1.9) yast2-auth-client (5.0.4 -> 5.0.5) yast2-trans (84.87.20260916.f55042cfcf -> 84.87.20260923.cade5cf3bd) === Details === ==== aaa_base ==== Version update (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) Subpackages: aaa_base-extras - Update to version 84.87+git20260924.144354a1: * change requires for aaa_base-extras also to pathes ==== apache2-mod_php8 ==== Version update (8.5.10 -> 8.5.11) - version update to 8.5.11 BCMath: Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. Core: Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection. Fixed bug GH-15375 (Nested "yield from" skips items after a valid() or next() call on the inner generator). Fixed bug GH-23232 (lone namespace separator asks the autoloader for an empty class name). Fixed bug GH-23301 (Nested "yield from" yields a value twice when the middle generator delegates again). DOM: Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the null namespace in spec-following mode. Fixed stale getElementsByClassName() and other node list caches after className/classList writes and attribute removals. Fixed a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude(). Fixed a crash in DOMXPath when a php:function callback receives a nodeset and a later callback returns a node from another document. Fixed bug GH-23331 (UAF when node_list_unlink() skips attribute children that still have a live wrapper). Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the value of an attribute whose child still has a live wrapper. GD: Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the wrong argument in error messages. FPM: Fixed bug GH-19320 (FPM UID and GID overflow). Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison). (CVE-2026-91768) Intl: Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle returning UTF-16 offsets instead of grapheme offsets. Fixed a memory leak when dumping IntlCalendar instances. Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator() results. Fixed a double-free when IntlGregorianCalendar construction fails after the ICU constructor adopts the TimeZone. Fixed bug GH-23094 (NumberFormatter parsing offsets use UTF-16 positions for UTF-8 strings). Fixed Locale::parseLocale() reading past a trailing '-' or '_'. Fixed grapheme_str_split() treating UBRK_DONE as a byte index. Fixed a leak in Locale::getKeywords() when a keyword value cannot be read. Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed from compiled rules. MBString: Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the replacement when a \k backref has no closing delimiter. MySQLnd: Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218) ODBC: Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type() returning uninitialized memory when SQLColAttribute fails. Opcache: Fixed opcache.protect_memory race under ZTS. Fixed a tracing JIT crash when compiling a side trace for a method of a class that could not be stored in the inheritance cache. Fixed a crash when the huge page SHM remap discarded mappings outside the reserved address range. OpenSSL: Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769) Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN). (CVE-2026-91767) PDO: Fixed a leak when a persistent connection failed a liveness check with no other live PDO handle. PDO_PGSQL: Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching (PDO::ATTR_PREFETCH => 0). PDO Sqlite: Fixed bug GH-20214 (PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode). Phar: Fixed bug GH-23418 (Use-after-free when looking up mounted directories). Fixed bug GH-23477 (Memory leak on duplicate native Phar manifest entries). Fixed GHSA-j3wh-g957-2m85 (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (CVE-2026-6103) Readline: Fixed the interactive shell not waiting for the pager process to exit. SOAP: Fixed WSDL cache corruption when a soap:header defines headerfaults. Fixed stack overflow when parsing a WSDL with self-referential schema groups or attributeGroups. Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765) Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181) Standard: Fixed a segfault when a stream filter callback unsets StreamBucket::$data before re-attaching the bucket. Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682) Fixed read buffer compaction in php_stream_filter_flush(). Fixed bug GH-22410 (Incorrect float behavior with large numbers). Fixed GH-23338 (fsockopen()/pfsockopen() ValueError reported wrong argument number for $timeout). Fixed bug GH-23576 (Next index for array returned from array_keys() is wrong). Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL). (CVE-2026-92842) Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766) SimpleXML: Fixed writing to a dimension of the object returned by attributes() not creating the attribute. Fixed child elements of the element returned by SimpleXMLElement::addChild() not being accessible by property name when namespaces are involved. Windows: Fixed GHSA-9f67-6fw4-hpfp (Reserved device names are not rejected before file and stream I/O). (CVE-2026-17545) Zip: Fixed bug GH-17787 (ZipArchive stream stops reading early when the archive is freed while the stream is still open). Fixed bug GH-23276 (ZipArchive subclass storing its own stream cannot be garbage collected). SAPI: Fixed fuzzer targets failing to build in isolation. Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo) * fixes CVE-2026-91769 [bsc#1283044] CVE-2026-91765 [bsc#1282875] CVE-2026-91766 [bsc#1282876] CVE-2026-91767 [bsc#1282877] CVE-2026-91768 [bsc#1282878] CVE-2026-6103 [bsc#1282980] CVE-2025-1218 [bsc#1282981] CVE-2026-92842 [bsc#1282985] CVE-2026-93682 [bsc#1282986] CVE-2025-14181 [bsc#1283216] ==== argyllcms ==== Version update (3.4.1 -> 3.5.0) - Update to 3.5.0 (bug fix release): * Fixed bug in targen (introduced in 3.3.0) that added a default ink limit for all device types, wrongly reducing it by 10% for additive devices unless overridden later in profiling. * Changed colprof to ignore, rather than warn about, an ink limit set for an additive device space. * Fixed reported problem with some models of Spyder2024. * Tweaked i1d3 frequency measurement mode for more consistent zero-black readings, matching period measurement mode on Rev. B instruments affected by the 0x83 bug. * Added Munsell Linear Grayscale scanin reference files. * Added -g option to xicc/fakeCMY to emit RGB values instead of CMY. * Added -o observer option to xicc/specplot. * Improved robustness of command name filename parsing in a number of utilities. * Expanded spectro/average to handle input test charts. * Improved JETI Specbos 2501 operation. - Spec cleanup: drop obsolete Group: tags, convert libtiff-devel and the udev runtime Requires to their pkgconfig() provider form, and use the standard parallel-make macro for the bundled ajam build tool. ==== bash ==== Version update (5.3.15 -> 5.3.20) Subpackages: bash-loadables bash-sh - Add upstream patches * Bash-5.3 Official patch 16 -- bash53-016 On recent versions of macOS, the pipe size is dynamic and changes due to system-wide total pipe usage, so we have to check whether or not bash can use the size determined at compile time. * Bash-5.3 Official patch 17 -- bash53-017 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * Bash-5.3 Official patch 18 -- bash53-018 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * Bash-5.3 Official patch 19 -- bash53-019 On some systems, macOS in particular, isalpha(3) returns true for bytes between 128 and 255. Bash uses this to determine whether or not these characters are permitted to be part of a shell identifier, and can consume one byte too many when determining the end of a variable name. * Bash-5.3 Official patch 20 -- bash53-020 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== bash-completion ==== Version update (2.17.0 -> 2.18.0) - Update to 2.18.0: This release comes with notable changes to the directories used for looking up and sourcing completion recipes and helpers, allowing for more flexibility and customization and fewer conflicts between things shipping with bash-completion and third party/upstream/origin packages. Files that come with bash-completion itself are located in directories reserved for that use, their names ending with -core and -fallback. Packages should continue install their files in the same completions and helpers dirs like before; these directories precede the bash-completion "core" ones in lookup order. A new concept of startup dirs has been introduced. Files from these directories are sourced eagerly on bash-completion startup. This replaces and allows for more flexibility than using the deprecated /etc/bash_completion.d directory for this purpose. * Features _comp__init: source system startup files earlier (b09700d) _comp_compgen_filedir: automatically add -f on _comp_compgen -C or -P (#1552) (6d5fca6) _comp_compgen_filedir: support "filedir -X" (ce28419) _comp_compgen_sysv_services: factorize SysV service generation (c4c8c4b) aclocal,automake: support versioned 1.17 executables (94bbb3a) aclocal,automake: support versioned 1.18 executables (9287b4b) apt-*: update known options up to apt 3.2.0 (c421d50) apt-cache: update known options up to apt 3.2.0 (0ab85c5) apt-get: update known options up to apt 3.2.0 (6a18e0c) apt-mark: update known options up to apt 3.2.0 (644a026) codex: 3rd party fallback completion loader (0f425bd) copilot: 3rd party fallback completion loader (744602a) curlie: alias to curl (dd8f6e0) curl: more option argument (non-)completions (5099cef) dive: add 3rd party fallback completion loader (f817cca) doas: add new completion (f047b70) doas: generate completions as if we're root (a705713) encore: 3rd party fallback completion loader (1e54d02) etcdctl,etcdutl: 3rd party fallback completion loaders (39f8ddf) helium: alias to chromium-browser (8600af0) inotifywait2: generate exclude filenames prefixed by @ (c1e2f1b) inotifywait: generate exclude filenames prefixed by @ (0a2c165) ip: Check /usr/share config path (45530b0) jq: --rawfile arg (non-)completion (4f454d8) jreleaser: add 3rd party fallback completion loader (e1c2815) mago: add 3rd party fallback completion loader (97c4c49) ogg123: associate opus extension (7d3ea33) opencode: add 3rd party fallback completion loader (dbcea18) pnpm: add 3rd party fallback completion loader (44804ae) pydoc: support versioned 3.13..15 executables (bd60b26) python,pyvenv: support versioned 3.14 and .15 executables (72a2e47) release-plz: add 3rd party fallback completion loader (c3c4066) rumdl: add 3rd party fallback completion loader (5ef9790) skupper: add 3rd-party fallback completion loader (4237c9c) ssh-keygen: -M arg completion (b13bf99) ssh-keygen: -Z argument completion (c763d52) ssh-keygen: update -t arg completions (4269a90) ssh-keygen: update -Y arg completions (a73bcaf) ssh: do not complete -P arg (tag) (7d26a86) ssh: include proxy in -O arg completions (fc1df1f) ssh: more option arg (non-)completions (33f789c) sudo-rs,sudo.ws: alias to sudo (084cc68) sudo: more option argument (non-)completions (216135e) support the "startup{,-core}" directory (d6169af) syncthing: add 3rd party fallback completion loader (bc5dfff) tmux: complete src/target session arguments (18b6da4) tmux: complete target-session arguments (ced59c3) ty: add 3rd party fallback completion loader (57a2b31) waydroid: add 3rd party fallback completion loader (acc800f) xrdb: misc improvements (#1669) (461f90c) zed: 3rd party fallback completion loader (83532fa) * Bug Fixes _comp_compgen_services: fix no completions without sysvdir (a2e2659) _comp_compgen_services: skip service status marks (1ac9169) _comp_compgen_sysv_services: do not generate names in subdirs (5557fbe) _comp_compgen: clear the variable when no completions are generated (c07bd66) _comp_complete_service: fix init-script-action parsing (#1499) (91e075a) _comp_complete_user_at_host: care about $cur starting with "-" (277da58) _comp_load: deprecate unsuffixed "completions/" w/o ".bash" (06910da) _comp_load: drop support for "_" (f245356) _known_hosts: fix spacing of an error message (0463570) _known_hosts: work around custom IFS (8171929) _variable_assignments: exclude invalid timezones for "TZ" (d405a1d) add compatibility wrapper for tail (f6fee8a) alternatives: work around localvar_inherit (360192a) apt-get,ebtables,iptables,mplayer,service: avoid | and | in sed (ed64c30) apt-get,gpg{,2},ipmitool,screen: avoid \t, \r, \w in POSIX sed (da40e7a) ccache: fix a wrong AWK condition (c300c0f) cd: Complete from . on empty CDPATH entry (#1527) (6f1eba6) cd: fix cdable_vars overwritten by another generator (24bd420) cd: work around bash-4.2 nounset (45d1c93) compatdir: shadow compat files of the same name (ff1bf72) completion load precedence more (0a15408) export: complete options not at $1 (832822d) export: suffix "=" only when unique and already complete (76f980c) export: work around custom IFS (2617d26) fbgs,fbi: add mandatory semicolons before "}" in POSIX sed (288e77e) fix non-POSIX sed expressions (e999091) gnokii: use double \ in [...] for POSIX.1-2024 recommendation (ab0483a) inotifywait: add -t in noargopts (0295129) interdiff: move to fallback for the upstream completion (11987a4) invoke-rc.d: avoid using non-POSIX | in sed (db928dd) invoke-rc.d: fix a bug of generating existing words (dfb903b) ... changelog too long, skipping 57 lines ... fails duwe e.g. missing network ==== bind ==== Version update (9.20.26 -> 9.20.29) Subpackages: bind-doc bind-utils - Update named.root - Upgrade to release 9.20.29 Security Fixes: * Prevent excessive CPU use validating crafted DNSSEC responses. (CVE-2026-19668) [bsc#1280436] * Require a TSIG on every message of incoming zone transfers. (CVE-2026-19033) [bsc#1280430] * Prevent a DNSSEC downgrade of secure delegations via unrelated NSEC3 records. (CVE-2026-77119) [bsc#1280440] * Prevent forged DNSSEC-validated NXDOMAIN responses. (CVE-2026-19941) [bsc#1280437] * DNS64 with break-dnssec could cause an assertion failure. (CVE-2026-19666) [bsc#1280433] * Reject oversized negative cache records. (CVE-2026-19667) [bsc#1280435] * Prevent resolver crash with cached DNSSEC proofs. (CVE-2026-19662) [bsc#1280432] * Discard repeated SOA, CNAME, and DNAME records when parsing DNS messages. (CVE-2026-75029) [bsc#1280438] * Fix an unauthenticated crash on HTTPS using SIG(0). (CVE-2026-77692) [bsc#1280441] * Cached HTTPS/SVCB aliases could exhaust resolver CPU. (CVE-2026-81736) [bsc#1280445] * Prevent TKEY queries from terminating named without global options. (CVE-2026-76163) [bsc#1280439] * Out-of-zone records in a zone database could be served as authoritative. (CVE-2026-78301) [bsc#1280442] * Fix crash on wildcard answers carrying both NSEC and NSEC3 proofs. (CVE-2026-80274) [bsc#1280443] * Following HTTPS/SVCB aliases could leak resolver cache memory. (CVE-2026-81563) [bsc#1280444] New Features: * Disclose active Negative Trust Anchors with Extended DNS Error 33. Feature Changes: * Reject oversized and malformed DNSKEY records up front. * Speed up RPZ policy zone updates. Bug Fixes: * Prevent a crash when using both dns64 and filter-a. * Stop passing UDP client addresses to update-policy external helpers. * Missing required NSEC3 for delegation not detected. * Tighten EUI48 and EUI64 text parsing. * GeoIP ACL state could be stale or wrong after reload. * Honor DNSSEC policy key tag ranges. * Fix a double free in mdig when EDNS options are specified. * Fix a crash when an IXFR falls back to AXFR with updates still pending. * Fix DS requests to parental agents over TLS. * Fix the rndc-confgen -q (quiet) option. * Enforce query ACLs for redirect zones and searched DLZs. * Check asnum validity in GeoIP ACLs. * Fix a crash on remote-servers lists that reference themselves. * A record from outside a response policy zone could crash named. * Invalid key-store configuration could abort the DNSSEC tools. * NSEC signature set could bypass the secure-delegation check. * Fix a possible nsupdate issue when using GSS-TSIG. * Fix a crash with a single-element geoip sortlist. * Prevent out-of-bailiwick CNAMEs from evicting cached records. * Restore periodic cleanup of stale resolver address data. * Fix named-checkconf/named crash with malformed key name. * Prevent resolver crashes while processing DNS over TCP. * Ensure NSEC authority does not cross zonecut boundary. * Treat an unusable NSEC3 chain as a verification failure. * Treat non-canonical RPZ prefixes as any other failure. * Negative caching stopped working with stale-answer-client-timeout set to 0. * An unterminated OpenSSL private-key Label: field could be read past its parser buffer. * Restore SMF support on Solaris and illumos. * Fix compilation on GNU/Hurd. * dig +yaml was producing invalid YAML when a lookup failed. * Properly prevent TSIG generation command line injection attacks. * Fix a potential heap bounds overflow write in dnssec-signzone. * Fix crashes on invalid DNSTAP input in dnstap-read. ==== binutils ==== Version update (2.45 -> 2.47) Subpackages: libctf-nobfd0 libctf0 - Update to 2.47: * New major version for libsframe.so.3 (SFrame V3 format, the V2 format is discontinued, added V3 support in gas and ld) * SFrame V3 support in objdump and readelf * add --got-contents to readelf * deprecate s390-* targets (the 31bit ones) * objdump: aarch64 disassember got "-M annotate" displaying a symbol associated with an undefined instruction, if there is one * objdump: x86(-64) disasm got "-M annotate-immediates" displaying a symbol associated with an immediate, if there is one * add --debug-dir= to readelf and objdump, for separate debuginfo files * removed targets: NaCL, Solaris/PowerPC * assembler: - ELF: new attribute letter 'E', for entity size for arbitrary sections - add --reloc-section-sym=[all|internal|none] to control adjusting local binding symbol relocs to section symbols - x86-64: add AMD Zen6 support - risc-v: add extensions sdtrig v1.0, ssstrict v1.0, smpmpmt v1.0, zv*dota* and vendor extensions xsmtvdot v1.0, xsmtvdotii v1.0 - arm: add remaining Armv9.6 insns ('+sme-mop4', '+sme-tmop', '+ssve-bitperm' and '+ssve-fexpa'); several Armv9.7 extensions ('+f16f32dot', '+f16f32mm', '+f16mm', '+gcie', '+lscp', '+mtetc', '+sme2p3', '+sve-b16mm', '+sve2p3' and '+tlbid') and future extensions POE2 and vMTE ('+poe2', '+tev' and '+mops-go'); remove TME extensions (gas will warn on use) - deprecated .vtable_entry and .vtable_inherit directives * linker: - x86(-64): Add --(no-)gnu-tls-tag and --(no-)gnu2-tls-tag options to add a GLIBC_ABI_GNU_TLS/GLIBC_ABI_GNU2_TLS dependency to the output when an input file uses ___tls_get_addr or R_386_TLS_DESC_CALL or R_X86_64_TLSDESC_CALL relocs - add --discard-sframe (omitting any .sframe sections in the output, also inhibiting synthesizing sframe data for linker generated code like the PLT) - add optimization level zero (-O 0) disabling section merging - add --start-lib/--end-lib and LIB linker script statement, treating a list of object files as members of an artificial archive - add support for archives without index on all targets, not just XCOFF - Contains fixes for these non-CVEs (not security bugs per upstreams SECURITY.md): * bsc#1252237 aka CVE-2025-11839 aka PR33448 * bsc#1252238 aka CVE-2025-11840 aka PR33455 * bsc#1254442 aka CVE-2025-11082 aka PR33464 * bsc#1259077 aka CVE-2026-3441 no PR * bsc#1259078 aka CVE-2026-3442 no PR * bsc#1259322 aka CVE-2025-69644 aka PR33639 * bsc#1259323 aka CVE-2025-69645 aka PR33637 * bsc#1259324 aka CVE-2025-69646 aka PR33638 * bsc#1259394 aka CVE-2025-69649 aka PR33697 * bsc#1259397 aka CVE-2025-69652 aka PR33701 * bsc#1259421 aka CVE-2025-69647 aka PR33640 * bsc#1259422 aka CVE-2025-69648 aka PR33641 * bsc#1260338 aka CVE-2026-4647 aka PR33919 * bsc#1262564 aka CVE-2026-6846 aka PR34049 * bsc#1274433 aka CVE-2026-18220 no PR * bsc#1282138 aka CVE-2026-15003 aka PR34053 - Add binutils-2.47.tar.bz2.sig, binutils-2.47.tar.bz2, binutils-2.47-branch.diff.gz - Remove binutils-2.45.tar.bz2.sig, binutils-2.45.tar.bz2, binutils-2.45-branch.diff.gz - Remove upstreamed patches: pr32556.diff, pr33450.diff, pr33452.diff, pr33456.diff, pr33456-2.diff, pr33457.diff, pr33499.diff, pr33502.diff, pr33427-fix-loongarch64-glibc-build-with-gcc16.patch, binutils-fix-c23.diff . - Adjust binutils-build-as-needed.diff, binutils-disable-code-arch-error.diff, binutils-fix-abierrormsg.diff, binutils-fix-invalid-op-errata.diff, binutils-fix-relax.diff, binutils-workaround-premature-libsframe-uninst.diff, binutils-znow.patch, s390-pic-dso.diff, x86-64-biarch.patch, binutils-compat-old-behaviour.diff, binutils-revert-plt32-in-branches.diff, binutils-revert-rela.diff, cross-avr-nesc-as.patch . - Limit internal static linking of libsframe to very old (SLE-12-*) codestreams. - Don't use libalternatives on SLE16. [bsc#1269059] ==== bluez ==== Subpackages: bluez-auto-enable-devices bluez-cups bluez-obexd bluez-zsh-completion libbluetooth3 - Add fix-crash-on-UUID-discovery.patch ==== cairo ==== Version update (1.18.4 -> 1.18.6) Subpackages: libcairo-gobject2 libcairo-script-interpreter2 libcairo2 - Update to version 1.18.6: + The XCB surface triggered an UAF warning when building with GCC. + The clipping code was accessing various fields in a guard value, and causing a crash inside Inkscape. + Multiple fixes for the Windows backends, including improvements in the thread safety of the DirectWrite code. + The DirectWrite backend now supports COLRv1 fonts. + Multiple fixes for building with MSVC and ClangCL. + A leak in the PDF surfaces has been fixed. + Various gaps between abutting rectangles when drawing with ANTIALIAS_NONE were removed by using absolute coordinates and avoiding rounding errors. + Remove an overflow when computing the buffer size in the XRender code. - Refresh cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff with quilt. ==== cups ==== Subpackages: cups-client cups-config libcups2 libcupsimage2 - Drop obsolete -fstack-protector from CFLAGS/CXXFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== dbus-1-glib ==== Version update (0.114 -> 0.116) - Update to version 0.116: + Bug fixes: - Remove `G_GNUC_CONST` from `_get_type()` functions. This can cause miscompilation with gcc-16. - Disable bash completion by default. This is an unmaintained bash completion for dbus-send(1), which is not part of GLib, and apparently doesn't work as intended. For a dbus-send equivalent with shell completion, please try GLib's gdbus(1) or systemd's busctl(1). - Drop (and obsolete) bash-completion sub-package following upstream changes. ==== dracut ==== Version update (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) - Update to version 112+suse.53.g97cbf62: * fix(fips): use BOOT_IMAGE_NAME instead of BOOT_IMAGE in path check ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Add patch bsc1282390.patch * Fix bsc#1282390 (CVE-2026-96442): arbitrary code execution when viewing or editing untrusted text files in modes other than Emacs Lisp mode due to incomplete fix for older CVE ==== flatpak ==== Version update (1.18.3 -> 1.18.4) Subpackages: flatpak-remote-flathub flatpak-selinux flatpak-zsh-completion libflatpak0 system-user-flatpak - Update to version 1.18.4: + Security fixes: - Prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious app is installed (CVE-2026-97024, GHSA-8xgq-v545-vgv) - Prevent privileged deletion of arbitrary files when a malicious app is installed (CVE-2026-97023, GHSA-5p67-xh8x-rq54) - When downloading apps or runtimes from an OCI repository that requires authentication, don't make the authentication token visible to other users (CVE-2026-97025, GHSA-7rvf-rqr3-43j4) - Restrict permissions on temporary repository directories in /var/tmp/flatpak-cache-* (CVE-2026-97026, GHSA-r9w3-qx54-qvc8) - Filter .desktop and D-Bus .service files against an allowlist of fields, preventing denial of service and unintended interactions with host services (CVE-2026-97027, GHSA-v64f-hrwr-j4vh) - Prevent apps from sending signals to a process group that includes a parent process outside the app, causing denial of service by killing the desktop environment (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2) + Bug fixes: - Update Meson wrap subprojects for projects that are normally taken from the host system: - xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422) - Improve hardening against symlink traversal, related to CVE-2026-97023 and CVE-2026-97024 + Internal changes: - Add CVE IDs and reporter credits to 1.18.1's NEWS entry - Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries ==== freerdp ==== Version update (3.31.1 -> 3.32.1) Subpackages: libfreerdp3-3 librdtk0-0 libwinpr3-3 - Update to version 3.32.1: + Regression and bugfix release. After the latest hardening a few corner cases were not covered by regression tests and needed adjustment. Most notably fragmented static channel PDU were rejected breaking copy & paste for larger data. - AAudio backend for android - iOS client updates + CVE: - GHSA-9qqc-m43j-g4r2 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3m9q-g533-rqjq - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-262p-h989-vmpv - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5xjc-c64q-m8r6 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f3vg-h45x-6wgf - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c49c-xm94-5qf3 - Update to version 3.32.0: + Thanks to all the people doing in depth code reviews and security reports.: - [proxy] add configuration options for /sec:ext or PROTOCOL_HYBRID_EX - [proxy] add configuration options for target certificate policy. NOTE: This changes default behavior from accept unless denied to deny unless accepted! Requires an update of your proxy configuration file if you rely on this. - [SDL,xfreerdp] seamless Entra/Azure integration on linux (with helper binaries) - [beta] Basic SDL client RAILS support for X11/wayland (other platforms currently lack some features / platform integration code, as we still need some native hooks) - [RDPECAM] stops camera streams now when the remote no longer requests frames. (no more camera LED after closing the windows application accessing it) - [RDPEWA] support user verification in addition to / instead of pin - [RDPEUSB] properly map interface index to interface numbers (more devices should work now) - [android] updated touch pointer - [wlfreerdp] shortcut inhibit release on mouse leave window - [xfreerdp] rails improvements, hopefully no longer shrinking windows - Full support for [MS-RDPBCGR] 2.2.10.2 Early User Authorization Result PDU, so now you get a error message if a user is not allowed to log in instead of a network failed message. (Authentication /sec:ext or PROTOCOL_HYBRID_EX) - [shadow] add configuration options for /sec:ext or PROTOCOL_HYBRID_EX - [gateway] split HTTP timeout from TCP connect timeout - [ffmpeg] support generic hardware accelerated encoding/decoding, replacing the old VAAPI only implementation. (still experimental as there are often driver issues) ## CVE Note: Advisories will be published days/weeks after the release, so links are 404 until then. - By Opensec Intelligence - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xq87-9rrm-6wqw - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3rvr-qvx8-rj23 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pvgq-84w2-93ph - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xm53-352c-57jw - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mq5-xh88-9v62 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mqxv-c882-m8w9 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q6pp-28g8-xqjc - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jgw9-wqvx-j495 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5cgr-vmp8-fmvj - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m7g5-gw57-cwcr - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjxv-5j98-cqx4 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pw4j-ff39-9vjm - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-87v8-2gwr-ww9j - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h7fx-22wv-4cg8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-996j-34w6-5hgm - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-52xc-5973-w5vv - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qjwp-c855-hc69 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4ww8-3vqm-jgcf - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-96rv-gf42-7wq9 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9qr4-rgq4-jfp8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cq4m-gwc5-w8rc - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q9p9-j22r-577p - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2jfv-j3wx-5cg4 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-g8jw-gv54-r94p - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7vfc-chg9-q5r8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f46f-pxh9-w2rh - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pg3f-chj4-mrw6 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f526-rq4j-5ch8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8rpr-jjjg-5qv6 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cmgx-558f-vh67 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m998-cvfm-9444 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-99p4-8j24-wvj4 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-97pf-pwp3-2wrv - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-27m7-gwhh-6hhf - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qpfh-m9w6-xf2x - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q56j-jjh6-38jf - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f554-v4xw-5j39 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-chh2-527f-x255 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xf45-j844-588v - By @DavidKorczynski - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qq23-mqmv-pc65 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jhxw-3hj9-9hqh - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h44v-39x6-9xvg - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6vjv-4hm3-6698 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c3rh-2hv6-7hf2 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jp2r-gm4v-wvq2 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-gvq8-v2fm-ffxv ... changelog too long, skipping 25 lines ... - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-83g2-gf92-5c4g ==== fribidi ==== Version update (1.0.16 -> 1.0.17) Subpackages: libfribidi0 - Update to 1.0.17: * Update Unicode character databases to v18.0.0. * Performance improvements: eliminate quadratic worst-case behavior in FSI base direction resolution, N0 bracket pairing, embedding-level resolution, and fribidi_reorder_line(). * Fix fribidi_set_reorder_nsm() and fribidi_set_mirroring() not taking effect when called before fribidi_log2vis(). * Fix bracket pairing (N0) to match brackets by canonical equivalence only, per UAX #9 BD16. * Fix stack buffer overflow when parsing character-set equivalence tables, and out-of-bounds read on trailing '_' in charset data. * Fix truncation of lines/output containing embedded NUL bytes. * Generate and install the fribidi(1) man page. - Add BuildRequires: help2man to generate fribidi(1) man page. - Package %{_mandir}/man1/fribidi.1*. - Drop ancient ppc64 obsoletes for fribidi-64bit. ==== fwupd ==== Version update (2.1.7 -> 2.1.8) Subpackages: fwupd-bash-completion libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.8: + This release adds the following features: - Add a new plugin to poke bootupd when the ESP changes - Add RSA-3072 signature verification support for Lenovo accessories + This release fixes the following bugs: - Add a workaround for the systemd-pcrosseparator.service PCR0 extension - Add hashes for the latest DBX for offline machines - Add user aware message to complete the dell-dock update - Allow enumeration BIOS settings to take either string or integer - Allow redfish firmware blobs up to 512MiB - Always use base-16 when parsing the UEFI capsule index - Do not allow a DFU altname or STM32 sector size of zero - Fix a buffer overwrite when parsing Synaptics CAPE HID reports - Fix a dell-dock crash via malformed EC_CMD_GET_DOCK_INFO response - Fix a file descriptor leak when getting firmware details - Fix a memory leak when parsing an invalid TPM eventlog - Fix a NULL deref when enumerating a broken synaptics-rmi device - Fix a snapd error when installing the latest dbx - Fix an integer underflow in Focal FP HID CRC parser - Fix eMMC error recovery command when setting install mode fails - Fix firmware recovery of Logitech Unifying devices - Increase the Huddly USB bulk write timeout to 30s - Invalidate the Wacom descriptor cache when the block count changes - Limit decompressing LZMA streams to 2GiB - Update PCB version checking logic in usi-dock - Use the stricter PolicyKit action ID when the device has gone - Verify the jcat item IDs before using them as filenames + This release adds support for the following hardware: - ASUS GX5407 - Elan PID 0CB6 - FocalTech MOC fingerprint sensors - Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000 - MaxLinear MxL862xx - MediaTek MT9700 FCTE and MT9701 KSMU - Pixart PID 4F01, 4F02, 4F0D and 4F0E - Rolling RW101 ==== gcr ==== Version update (4.4.0.1 -> 4.4.1) Subpackages: gcr-ssh-agent gcr-ssh-askpass gcr-viewer libgck-2-2 libgcr-4-4 typelib-1_0-Gck-2 typelib-1_0-Gcr-4 - Update to version 4.4.1: + gcr: - Support zero mtime - Fix memory leak in GcrSystemPrompt call closure + docs: Fix a method reference in gcr_prompt_set_choice_label() + Updated translations. ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - CVE-2026-96543: out-of-bounds heap write when loading non-square PVR images (bsc#1282539) * gimp-CVE-2026-96543.patch - CVE-2026-96544: integer overflow in the PVR image loader leads to an out-of-bounds heap read (bsc#1282541) * gimp-CVE-2026-96544.patch * gimp-CVE-2026-96544-2.patch - CVE-2026-96545: out-of-bounds heap read in the 4bpp TIM image loader (bsc#1282602) * gimp-CVE-2026-96545.patch - Add gimp-initialize-sgi-tables.patch: ensure that SGI tables are initialized. Clean-up for the fix for CVE-2026-66757 (bsc#1279838 glgo#GNOME/gimp!2997). - CVE-2026-90948: When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size (bsc#1280512) * gimp-CVE-2026-90948.patch - CVE-2026-90949: When processing a compressed selection channel in gimp's PSP file loader, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed (bsc#1280513) * gimp-CVE-2026-90949.patch - CVE-2026-92248: When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header (bsc#1280739) * gimp-CVE-2026-92248.patch * gimp-CVE-2026-92248-2.patch ==== gnome-user-docs ==== Version update (50.4 -> 50.5) - Update to version 50.5: + Updated translations. ==== google-noto-coloremoji-fonts ==== Version update (20250916 -> 20260924) - Update to v2.057 * Unicode 18.0 update - 19 new emojis (9 new emoji code points plus 10 skin-tone sequences for directional thumbs) ==== gpsd ==== - Fix for gpsprof arbitrary OS command execution via code injection in the attacker-controlled SKY.satellites[].used field, inserted unsanitized into a gnuplot heredoc data block; sat.used is now forced to a boolean (CVE-2026-60122 [bsc#1280016]) + 5a9c44a4.patch ==== gspell ==== Version update (1.14.4 -> 1.14.5) - Update to version 1.14.5: + Don't annotate get_type() functions with G_GNUC_CONST. + Updated translations. ==== hwinfo ==== Version update (25.5 -> 26.0) - merge gh#openSUSE/hwinfo#191 - code cleanup: remove some unused variables - 26.0 - merge gh#openSUSE/hwinfo#193 - add MMC/SD card block device support - add some minor improvements - merge gh#openSUSE/hwinfo#188 - Fix check_hd being built without LDFLAGS - merge gh#openSUSE/hwinfo#190 - fix(s390): fix memory leaks on skip paths in ccw device scan - merge gh#openSUSE/hwinfo#189 - fix(s390): fix out-of-bounds write in cutypes scan loop ==== jitterentropy ==== - OSR has to be at least 5 according to current reviews. (bsc#1282301) jitterentropy-minimum-osr.patch ==== kernel-firmware-amdgpu ==== Version update (20260829 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * amdgpu: update VPE 2.0.0 firmware * amdgpu: update VCN 5.3.0 firmware * amdgpu: update GC 11.7.0 MES firmware * amdgpu: update PSP 15.0.9 firmware * amdgpu: update PSP 15.0.0 firmware * Revert "amdgpu: update GC 11.0.0 firmware" * Revert "amdgpu: update GC 11.0.0 firmware" * amdgpu: DMCUB updates for various ASICs - Update to version 20260915 (git commit 4584045b2121): * Revert "amdgpu: update VCN 5.3.0 firmware" * Revert "amdgpu: update VCN 5.0.1 firmware" * Revert "amdgpu: update VCN 5.0.0 firmware" * Revert "amdgpu: update VCN 4.0.6 firmware" * Revert "amdgpu: update VCN 4.0.6 firmware" * Revert "amdgpu: update VCN 4.0.5 firmware" * Revert "amdgpu: update VCN 4.0.5 firmware" * Revert "amdgpu: update vcn 4.0.4 firmware" * Revert "amdgpu: update VCN 4.0.3 firmware" * Revert "amdgpu: update VCN 4.0.2 firmware" * Revert "amdgpu: update VCN 4.0.2 firmware" * Revert "amdgpu: update VCN 4.0.0 firmware" * Revert "amdgpu: update VCN 3.1.2 firmware" * amdgpu: partially revert 9f1eb5124635 * amdgpu: partially revert e3e45091597e * amdgpu: partially revert 7df10898a825 * amdgpu: partially revert 7b262e1ddce5 * amdgpu: partially revert 17ee8fdf9196 * amdgpu: partially revert 063e840eb6a5 * Partially revert "amdgpu: DMCUB updates for various ASICs" - Update to version 20260912 (git commit d371ae3b6888): * amdgpu: update vangogh firmware * amdgpu: update VPE 6.1.1 firmware * amdgpu: update VCN 4.0.6 firmware * amdgpu: update PSP 14.0.1 firmware * amdgpu: update GC 11.5.1 firmware * amdgpu: update VCN 4.0.5 firmware * amdgpu: update PSP 14.0.0 firmware * amdgpu: update GC 11.5.0 firmware * amdgpu: update renoir firmware * amdgpu: update yellow carp firmware * amdgpu: update PSP 13.0.5 firmware * amdgpu: update PSP 13.0.11 firmware * amdgpu: update GC 11.0.4 firmware * amdgpu: update VCN 4.0.2 firmware * amdgpu: update PSP 13.0.4 firmware * amdgpu: update GC 11.0.1 firmware * amdgpu: update SMU 14.0.3 firmware * amdgpu: update PSP 14.0.3 firmware * amdgpu: update GC 12.0.1 firmware * amdgpu: update PSP 14.0.2 firmware * amdgpu: update GC 12.0.0 firmware * amdgpu: update SMU 13.0.7 firmware * amdgpu: update PSP 13.0.7 firmware * amdgpu: update GC 11.0.2 firmware * amdgpu: update SMU 13.0.10 firmware * amdgpu: update PSP 13.0.10 firmware * amdgpu: update GC 11.0.3 firmware * amdgpu: update SMU 13.0.0 firmware * amdgpu: update PSP 13.0.0 firmware * amdgpu: update GC 11.0.0 firmware * amdgpu: update beige goby firmware * amdgpu: update dimgrey cavefish firmware * amdgpu: update navy flounder firmware * amdgpu: update sienna cichlid firmware * amdgpu: update navi14 firmware * amdgpu: update navi12 firmware * amdgpu: update navi10 firmware * amdgpu: update PSP 15.0.9 firmware * amdgpu: update GC 11.7.1 firmware * amdgpu: update VCN 5.3.0 firmware * amdgpu: update PSP 15.0.0 firmware * amdgpu: update GC 11.7.0 firmware * amdgpu: update PSP 14.0.5 firmware * amdgpu: update GC 11.5.3 firmware * amdgpu: update VPE 6.1.3 firmware * amdgpu: update PSP 14.0.4 firmware * amdgpu: update GC 11.5.2 firmware * amdgpu: update green sardine firmware * amdgpu: DMCUB updates for various ASICs - Update to version 20260904 (git commit 2f2bf38a3d03): * amdgpu: DMCUB updates for various ASICs - Update aliases from 7.3-rc1 ==== kernel-firmware-ath10k ==== Version update (20260809 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * qcom/shikra: link WiFi firmware from the ath10k subdir - Update to version 20260915 (git commit 4584045b2121): * qcom/sdm845: Let SHIFT6mq use the provided Wi-Fi firmware - Update to version 20260912 (git commit d371ae3b6888): * ath10k: WCN3990: hw1.0: add shikra firmware files ==== kernel-firmware-ath11k ==== Version update (20260610 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * ath11k: WCN6855 hw2.0: update board-2.bin ==== kernel-firmware-ath12k ==== Version update (20260813 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * ath12k: WCN7850 hw2.0: update board-2.bin * ath12k: QCC2072 hw1.0: update board-2.bin - Update to version 20260902 (git commit abddc5b93044): * ath12k: QCC2072 hw1.0: update to WLAN.COL.1.0.c2-00277-QCACOLSWPL_V1_TO_SILICONZ-1 ==== kernel-firmware-bluetooth ==== Version update (20260828 -> 20260929) - Update to version 20260929 (git commit 33b68e2c7011): * QCA: Add QCA2066 Bluetooth firmware hpnv21g.30c * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00653 - Update to version 20260926 (git commit 9b858e5bb58d): * qca: group the QCA61x4 USB firmware files * qca: fix the version of the WCN785x USB firmware * intel: Update ibt-00a0-01a1-pci.ddc for BE211 - Whale Peak2 (WhP2) - Update to version 20260916 (git commit e289868675d1): * QCA: Update Bluetooth firmware for QCC2072 UART interface: 1.1.0-00340 to 1.1.0-00355 - Update to version 20260910 (git commit eeccccbe83da): * QCA: Add Bluetooth firmware for WCN7750 on Maili platform - Update to version 20260902 (git commit abddc5b93044): * QCA: Add Bluetooth firmware hmtnv20.b201/b202 for WCN7850 on Nord platform * QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00079 ==== kernel-firmware-brcm ==== Version update (20260610 -> 20260915) - Update to version 20260915 (git commit 4584045b2121): * WHENCE: add missing symlink for TaiqiCat (TQC) A01 - Update to version 20260902 (git commit abddc5b93044): * [cypress]: Update firmware for cyfmac43455 SDIO ==== kernel-firmware-intel ==== Version update (20260728 -> 20260916) - Update to version 20260916 (git commit e289868675d1): * intel_vpu: Update NPU firmware ==== kernel-firmware-iwlwifi ==== Version update (20260820 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * iwlwifi: add Bz/Sc FW for core24.80-41 release * iwlwifi: Update Bz/Fm firmware for core24.80-41 release * iwlwifi: Add Hr/Gf firmware for core24.80-41 release * iwlwifi: update ty/So/Ma firmwares for core24.80-41 release * iwlwifi: Add cc/Qu/QuZ firmwares for core24.80-41 release - Update aliases ==== kernel-firmware-media ==== Version update (20260813 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * qcom: vpu: add Gen2 firmware binary for Hawi * qcom: vpu: add Gen2 firmware binary for Maili - Update to version 20260915 (git commit 4584045b2121): * qcom: vpu: add Gen2 firmware binary for sc8280xp - Update to version 20260910 (git commit eeccccbe83da): * qcom: vpu: Update video firmware binary for Glymur ==== kernel-firmware-mediatek ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-mwifiex ==== Version update (20260610 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * linux-firmware: mwifiex: add IW416 firmware ==== kernel-firmware-network ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-platform ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-qcom ==== Version update (20260828 -> 20260929) - Update to version 20260929 (git commit 33b68e2c7011): * qcom: update ADSP firmware for hawi platform * Revert "qcom: update ADSP firmware for qcs615 platform"q * qcom: Add gpu firmwares for Hawi and Maili chipsets - Update to version 20260926 (git commit 9b858e5bb58d): * qcom: update Rubik Pi 3 ADSP firmware * qcom: add CDSP firmware for hawi platform - Update to version 20260916 (git commit e289868675d1): * qcom: add ADSP firmware for maili platform - Update to version 20260915 (git commit 4584045b2121): * qcom/sdm845: Let SHIFT6mq use the provided Wi-Fi firmware - Update to version 20260910 (git commit eeccccbe83da): * qcom: Update ADSP firmware for sa8775p platform * qcom: point qcs8300 firmawre to sa8775p instance * qcom: update ADSP firmware for qcs615 platform * qcom: Add ADSP firmware for sc8280xp-radxa-dragon-q8b * qcom: sdm845: Add GPU firmware for SHIFT6mq * qcom: Update ADSP firmware for QCM6490 platform - Update aliases from 7.3-rc1 ==== kernel-firmware-qlogic ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-realtek ==== Version update (20260731 -> 20260915) - Update to version 20260915 (git commit 4584045b2121): * rtl_nic: add firmware rtl8261d.bin for RTL8261d ==== kernel-firmware-sound ==== Version update (20260825 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * cirrus: cs35l56: Correct firmware instances for 103c8c52 and 103c8c53 * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops * cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for some Dell laptops - Update to version 20260912 (git commit d371ae3b6888): * cirrus: cs35l57: Add firmware for Cirrus Amps for a Lenovo laptop - Update to version 20260910 (git commit eeccccbe83da): * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops * cs35l56: Add non-spkid firmware names for Thinkbook 16P Gen6 (17AA3921) - Update to version 20260903 (git commit ec2d074008a5): * cirrus: Version and cleanup of SDCA FW files - Update to version 20260902 (git commit abddc5b93044): * cirrus: cs35l41: Add Firmware for ASUS Zenbook Laptop using CS35L41 HDA - Update aliases from 7.3-rc1 ==== kernel-source ==== Version update (7.2.7 -> 7.2.8) Subpackages: kernel-64kb kernel-default - Update patches.kernel.org/7.2.4-018-clocksource-drivers-timer-sun4i-Advertise-a-rea.patch (bsc#1012628 CVE-2026-93219 bsc#1282749). - Update patches.kernel.org/7.2.4-048-mm-huge_memory-skip-device-private-PMDs-in-madv.patch (bsc#1012628 CVE-2026-93218 bsc#1282748). - Update patches.kernel.org/7.2.4-050-mm-hugetlb-fix-boot-panic-with-CONFIG_DEBUG_VM-.patch (bsc#1012628 CVE-2026-93232 bsc#1282694). - Update patches.kernel.org/7.2.4-051-mm-hugetlb-initialize-gigantic-bootmem-hugepage.patch (bsc#1012628 CVE-2026-93230 bsc#1282693). - Update patches.kernel.org/7.2.4-054-mm-madvise-skip-device-private-PMDs-in-cold-and.patch (bsc#1012628 CVE-2026-93217 bsc#1282760). - Update patches.kernel.org/7.2.4-060-mm-mm_init-deferred_grow_zone-fix-out-of-range-.patch (bsc#1012628 CVE-2026-93227 bsc#1282696). - Update patches.kernel.org/7.2.4-061-mm-page_owner-use-memcg_data-snapshot-to-avoid-.patch (bsc#1012628 CVE-2026-93216 bsc#1282780). - Update patches.kernel.org/7.2.4-094-cdx-Fix-double-free-when-sysfs-file-creation-fa.patch (bsc#1012628 CVE-2026-93215 bsc#1282758). - Update patches.kernel.org/7.2.4-114-usb-gadget-f_tcm-fix-deadlock-in-usbg_make_tpg.patch (bsc#1012628 CVE-2026-93214 bsc#1282776). - Update patches.kernel.org/7.2.4-127-of-fix-out-of-bounds-read-in-of_alias_scan-stem.patch (bsc#1012628 CVE-2026-93213 bsc#1282775). - Update patches.kernel.org/7.2.4-144-nfsd-guard-nfsd_serv-deref-in-nfsd_file_net_dis.patch (bsc#1012628 CVE-2026-93212 bsc#1282774). - Update patches.kernel.org/7.2.4-162-nfsd-add-missing-read-barrier-to-rpc_status_get.patch (bsc#1012628 CVE-2026-93229 bsc#1282698). - Update patches.kernel.org/7.2.4-169-nfsd-convert-nfsd_net-boolean-flags-to-unsigned.patch (bsc#1012628 CVE-2026-93221 bsc#1282736). - Update patches.kernel.org/7.2.4-199-nfsd-initialize-DRC-hash-table-before-registeri.patch (bsc#1012628 CVE-2026-93211 bsc#1282740). - Update patches.kernel.org/7.2.4-243-smb-client-harden-DFS-cache-against-invalid-tar.patch (bsc#1012628 CVE-2026-93210 bsc#1282737). - Update patches.kernel.org/7.2.4-343-Bluetooth-hci_core-use-skb_get-instead-of-skb_c.patch (bsc#1012628 CVE-2026-93209 bsc#1282735). - Update patches.kernel.org/7.2.4-348-kasan-fix-cache-shrink-race-with-CPU-hotplug.patch (bsc#1012628 CVE-2026-93208 bsc#1282732). - Update patches.kernel.org/7.2.4-357-ipv6-use-RCU-iterator-to-dump-route-exceptions.patch (bsc#1012628 CVE-2026-93226 bsc#1282723). - Update patches.kernel.org/7.2.4-369-phy-fsl-imx8mq-usb-fix-typec-switch-leak-on-pro.patch (bsc#1012628 CVE-2026-93225 bsc#1282726). - Update patches.kernel.org/7.2.4-371-SUNRPC-Zero-rpc_gss_wire_cred-at-svcauth_gss_de.patch (bsc#1012628 CVE-2026-93207 bsc#1282672). - Update patches.kernel.org/7.2.4-393-svcrdma-Fix-unmatched-rn_unregister-on-failed-a.patch (bsc#1012628 CVE-2026-93224 bsc#1282703). - Update patches.kernel.org/7.2.4-398-svcrdma-Reject-Write-Reply-chunks-with-segcount.patch (bsc#1012628 CVE-2026-93228 bsc#1282697). - Update patches.kernel.org/7.2.4-401-udf-reject-VAT-indexes-equal-to-the-entry-count.patch (bsc#1012628 CVE-2026-89525 bsc#1282288). - Update patches.kernel.org/7.2.4-404-staging-media-tegra-video-fix-of_node_put-on-VI.patch (bsc#1012628 CVE-2026-93223 bsc#1282741). - Update patches.kernel.org/7.2.4-418-sched_ext-Keep-kick_sync-waiting-on-the-rq-s-ow.patch (bsc#1012628 CVE-2026-93220 bsc#1282750). - Update patches.kernel.org/7.2.4-486-lockd-fix-swapped-arguments-in-nlmsvc_match_ip.patch (bsc#1012628 CVE-2026-93231 bsc#1282778). - Update patches.kernel.org/7.2.4-534-PCI-proc-Use-file_ns_capable-when-checking-conf.patch (bsc#1012628 CVE-2026-93206 bsc#1282729). - Update patches.kernel.org/7.2.4-541-iommu-arm-smmu-v3-Manage-teardown-with-devm.patch (bsc#1012628 CVE-2026-93205 bsc#1282727). - Update patches.kernel.org/7.2.4-703-signal-avoid-shared-siginfo-namespace-rewrites.patch (bsc#1012628 CVE-2026-93222 bsc#1282742). - Update patches.kernel.org/7.2.5-097-mm-secretmem-properly-account-locked-pages.patch (bsc#1012628 CVE-2026-93243 bsc#1282687). - Update patches.kernel.org/7.2.5-128-memcg-bypass-the-reclaim-and-oom-killer-for-dyi.patch (bsc#1012628 CVE-2026-93241 bsc#1282781). - Update patches.kernel.org/7.2.5-129-memcg-make-the-v1-soft-limit-knob-inert.patch (bsc#1012628 CVE-2026-93240 bsc#1282779). - Update patches.kernel.org/7.2.5-146-arm64-mm-Fix-the-lockless-page-table-walk-in-sh.patch (bsc#1012628 CVE-2026-93239 bsc#1282681). ... changelog too long, skipping 1612 lines ... - commit 93e89db ==== kirigami-addons6 ==== Version update (1.13.0 -> 1.14.0) Subpackages: libKirigamiAddonsComponents6 libKirigamiAddonsStatefulApp6 libKirigamiApp6 - Update to 1.14.0 https://carlschwan.eu/2026/09/17/imprint-1.0-and-kirigami-addons-1.14.0/ ==== libX11 ==== Subpackages: libX11-6 libX11-data libX11-xcb1 - 0001-1281653_CVE-2026-94283_ximcp-bound-XIM_OPEN_REPLY-attribute-lengths-to-the-.patch * Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser (boo#1281653, CVE-2026-94283) - 0002-1281657_CVE-2026-94284_ximcp-bound-XIM_REGISTER_TRIGGERKEYS-keylist-lengths.patch * Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser (boo#1281657, CVE-2026-94284) - 0003-1281661_CVE-2026-94285_lcGenConv-bound-byteM_parse_codeset-reads-to-remaini.patch * Out-of-bounds read in libX11's byte-oriented codeset parser (boo#1281661, CVE-2026-94285) ==== libXi ==== - 0001-boo1281605_CVE-2026-93541_XQueryDeviceState-check-ValuatorClass-num_valuators-.patch * Out-of-bounds read in libXi's XQueryDeviceState() (boo#1281605, CVE-2026-93541) - 0002-boo1281606_CVE-2026-93542_size_classes-copy_classes-bound-XI2-class-lengths-to.patch * Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() (boo#1281606, CVE-2026-93542) - 0003-boo1281608_CVE-2026-93543_size_classes-copy_classes-enforce-XI2-per-type-class.patch * Out-of-bounds read in libXi's XI2 class parser (boo#1281608, CVE-2026-93543) - 0004-boo1281609_CVE-2026-93544_XIQueryDevice-keep-padded-name-and-class-bytes-withi.patch * Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing (boo#1281609, CVE-2026-93544) - 0005-boo1281612_CVE-2026-93545_XListInputDevices-validate-device-name-lengths-again.patch * Out-of-bounds read in libXi's XListInputDevices() (boo#1281612, CVE-2026-93545) - 0006-boo1281615_CVE-2026-94281_XListInputDevices-validate-class-lengths-cumulativel.patch * Out-of-bounds read in libXi's XListInputDevices() class parsing (boo#1281615, CVE-2026-94281) - 0007-boo1281651_CVE-2026-94282_wireToEnterLeave-validate-buttons_len-against-the-re.patch * Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversio (boo#1281651, CVE-2026-94282) ==== libXpm ==== - 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch * Denial of service via unsigned underflow in libXpm's write path (boo#1281669, CVE-2026-94287) ==== libXtst ==== - 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch * Out-of-bounds read in libXtst's RECORD reply parser (boo#1281665, CVE-2026-94286) ==== liblognorm ==== Version update (2.1.0 -> 2.1.1) - update to 2.1.1: * TurboVM: fix optimized builds failing on an uninitialized repeat name length warning * parser(date-rfc5424): prevent millisecond timestamp overflow: parse only the required millisecond precision while still consuming additional fractional digits * parser(literal): prevent reads past the input terminator: embedded NUL bytes no longer let byte-counted literal matching continue past the duplicated C string terminator * parser(date-rfc3164): reject a null format safely: malformed parser JSON no longer causes a null-pointer dereference and continues to use the established default string output ==== libphonenumber ==== Version update (9.0.38 -> 9.0.40) - update to 9.0.40: * Updated phone metadata for region code(s): BD, CA, CD, EE, IL, LI, PA, SB, SR, UG, VN, ZW * New geocoding data for country calling code(s): 1273 (en) * Updated geocoding data for country calling code(s): 263 (en) * Updated carrier data for country calling code(s): 36 (en), 39 (en), 81 (en), 84 (en), 226 (en), 243 (en), 256 (en), 597 (en), 677 (en), 880 (en), 972 (en), 994 (en) * Updated / refreshed time zone meta data. - includes changes from 9.0.39: * Updated alternate formatting data for country calling code(s): 91 * Updated phone metadata for region code(s): BD, HK, IN, PA, PT, TR * Updated geocoding data for country calling code(s): 91 (en) * Updated carrier data for country calling code(s): 90 (en), 359 (en), 852 (en, zh), 966 (en) ==== libraw ==== - added patches CVE-2026-88387: incorrect numeric conversion in `LibRaw::parse_tiff_ifd()` when processing TIFF tag `0x00fe` can lead to undefined behavior and a process crash when a specially crafted file is processed [bsc#1282783] * libraw-CVE-2026-88387.patch ==== libsecret ==== Version update (0.21.7 -> 0.21.8.2) Subpackages: libsecret-1-0 typelib-1_0-Secret-1 - Update to version 0.21.8.2: + Release to bump meson.build version - Changes from version 0.21.8.1: + Make secret_item_load_secrets_sync match async behavior - Update to version 0.21.8: + Allow the content type to have additional parameters + Support individually encrypted items + Ensure we return chained up GTask + Ensure length of DH shared secret match length of prime on GnuTLS + file-backend: - Add thread safety and file-based locking to prevent concurrent write races - Fix possible memory leak in error path of secret_file_backend_real_search() + file-collection: Fix memory leaks on repeated calls + Replace some SecretSync with a sync implementation + Add linker version script to hide private symbols + Stop using CONST annotations on non-const fns + secret-tool: - Align behavior for collection option - Document --collection option + meson: Put test setup behind a feature option + Several test and CI improvements + Updated translations. ==== libslirp ==== Version update (4.9.3+4 -> 4.9.5+1) - Update to version 4.9.5+1: * note CVE numbers * Release v4.9.5 * Set UDP sockets in blocking mode * dhcpv6: fix bounding the reply against the interface MTU * dhcpv6: bound the reply against the interface MTU * ncsi: bounds-check OEM command bodies before dereferencing them * Release v4.9.4 * ip_input: update hlen on ip_reass * ip6_input: Trim mbuf to ip6-announced length * Fix reporting oob output * Note about the security contact - fixes CVE-2026-95507, CVE-2026-95508 ==== libsodium ==== - Disable upstream SSP handling via --disable-ssp: distro optflags already carry -fstack-protector-strong, and upstream's appended basic -fstack-protector silently downgraded it. ==== libstorage-ng ==== Version update (4.5.354 -> 4.5.355) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Danish) (bsc#1149754) - 4.5.355 ==== libtasn1 ==== - Update Source URLS - guard against future removal of egrep/fgrep ==== libtheora ==== Subpackages: libtheora1 libtheoradec2 libtheoraenc2 - Disable asm on 32-bit arm until next release https://gitlab.xiph.org/xiph/theora/-/work_items/2338 ==== libupnp ==== Version update (22.1.2 -> 22.1.7) Subpackages: libixml22 libupnp22 - Update to release 22.1.7 * Fix a memory leak when a GENA subscription is freed. [GHSA-h9f5-9vwp-h89q] - Update to release 22.1.6 * GHSA-mhhw-gm73-c57g: Fix a heap over-read when parsing the Callback header of an incoming GENA SUBSCRIBE request. [GHSA-mhhw-gm73-c57g] - Update to release 22.1.5 * Fix SID matching for incoming GENA NOTIFY requests. [GHSA-ggw2-jjv9-h22c] - Update to release 22.1.4 * Stopped counting the read-head entity bytes against header sizes. * Sockets are now closed when http_OpenHttpGetEx() gets a bad response. ==== llvm23 ==== Version update (23.1.1 -> 23.1.2) Subpackages: clang-tools clang23 libLLVM23 libclang-cpp23 libclang13 libclang_rt23 llvm23-gold - Update to version 23.1.2. * This release contains bug-fixes for the LLVM 23.1.0 release. This release is API and ABI compatible with 23.1.0. ==== mozjs140 ==== Version update (140.16.0 -> 140.17.0) - Update to version 140.17.0. + See https://www.firefox.com/en-US/firefox/140.17.0/releasenotes/ - Rebase mozjs140-rust1.98.patch ==== nbd ==== - Add nbd-fix-help-parsing.patch to fix nbd-client -h segfaulting (boo#1282852): usage_error() was called with a NULL format string, which vsnprintf dereferences (upstream commit 89ba7b537954) ==== openSUSE-release ==== Version update (20260924 -> 20260930) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openexr ==== Version update (3.4.14 -> 3.4.15) Subpackages: libIex-3_4-33 libIlmThread-3_4-33 libOpenEXR-3_4-33 libOpenEXRCore-3_4-33 - version update to 3.4.15 * fixes two memory issues when parsing IDManifests - added patches CVE-2026-88384: NULL pointer dereference in the C++ attribute parsing path when a specially crafted EXR file containing an unknown-type attribute with dataSize set to zero is processed [bsc#1282700] * openexr-CVE-2026-88384.patch ==== openssh ==== Subpackages: openssh-clients openssh-common openssh-server - Backport openssh-10.5p1-sync-readpassphrase.patch: sync readpassphrase(3) with OpenBSD libc so that SIG_IGN dispositions are preserved instead of being overridden; fixes ssh-add spinning when started in a background process group with no controlling tty and certain signals ignored (mindrot#3995, upstream commits 58db2ec9cac0 and e3cb2b2278c2). ==== orca ==== Version update (50.2 -> 50.3) - Update to version 50.3: + General: - Fix traceback when using object navigator to click on an object. - Fix two issues related to running unit tests downstream. + New and updated translations (THANKS EVERYONE!!!): - Add python3-setproctitle Recommends. Orca uses this to set its process name when available. - Add python3-psutil Recommends: Support system information commands. ==== osinfo-db ==== - Add support for SLES-16.2 add-sles16.2-support.patch - Add support for openSUSE Leap 16.2 add-opensuse-leap-16.2-support.patch - Adjust SLES 16.1 version number and include release date add-sles16.1-support.patch ==== pam ==== Version update (1.7.2+git48 -> 1.7.3) - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== pam-full-src ==== Version update (1.7.2+git48 -> 1.7.3) Subpackages: pam-extra pam-manpages - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== parted ==== Version update (3.7 -> 3.8) Subpackages: libparted-fs-resize0 libparted2 - switch from ftp to https for sources - updated parted.keyring - update to version 3.8 - update to version 3.7.14: - Fix gnu_read problems with block size > 512b - update to version 3.7.13: - Add support for ExFAT - Fix CVE-2026-89085 and CVE-2026-89088 - Add various checks for increased security ==== php8 ==== Version update (8.5.10 -> 8.5.11) Subpackages: php8-ctype php8-dom php8-iconv php8-openssl php8-pdo php8-sqlite php8-tokenizer php8-xmlreader php8-xmlwriter - version update to 8.5.11 BCMath: Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. Core: Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection. Fixed bug GH-15375 (Nested "yield from" skips items after a valid() or next() call on the inner generator). Fixed bug GH-23232 (lone namespace separator asks the autoloader for an empty class name). Fixed bug GH-23301 (Nested "yield from" yields a value twice when the middle generator delegates again). DOM: Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the null namespace in spec-following mode. Fixed stale getElementsByClassName() and other node list caches after className/classList writes and attribute removals. Fixed a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude(). Fixed a crash in DOMXPath when a php:function callback receives a nodeset and a later callback returns a node from another document. Fixed bug GH-23331 (UAF when node_list_unlink() skips attribute children that still have a live wrapper). Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the value of an attribute whose child still has a live wrapper. GD: Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the wrong argument in error messages. FPM: Fixed bug GH-19320 (FPM UID and GID overflow). Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison). (CVE-2026-91768) Intl: Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle returning UTF-16 offsets instead of grapheme offsets. Fixed a memory leak when dumping IntlCalendar instances. Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator() results. Fixed a double-free when IntlGregorianCalendar construction fails after the ICU constructor adopts the TimeZone. Fixed bug GH-23094 (NumberFormatter parsing offsets use UTF-16 positions for UTF-8 strings). Fixed Locale::parseLocale() reading past a trailing '-' or '_'. Fixed grapheme_str_split() treating UBRK_DONE as a byte index. Fixed a leak in Locale::getKeywords() when a keyword value cannot be read. Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed from compiled rules. MBString: Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the replacement when a \k backref has no closing delimiter. MySQLnd: Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218) ODBC: Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type() returning uninitialized memory when SQLColAttribute fails. Opcache: Fixed opcache.protect_memory race under ZTS. Fixed a tracing JIT crash when compiling a side trace for a method of a class that could not be stored in the inheritance cache. Fixed a crash when the huge page SHM remap discarded mappings outside the reserved address range. OpenSSL: Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769) Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN). (CVE-2026-91767) PDO: Fixed a leak when a persistent connection failed a liveness check with no other live PDO handle. PDO_PGSQL: Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching (PDO::ATTR_PREFETCH => 0). PDO Sqlite: Fixed bug GH-20214 (PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode). Phar: Fixed bug GH-23418 (Use-after-free when looking up mounted directories). Fixed bug GH-23477 (Memory leak on duplicate native Phar manifest entries). Fixed GHSA-j3wh-g957-2m85 (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (CVE-2026-6103) Readline: Fixed the interactive shell not waiting for the pager process to exit. SOAP: Fixed WSDL cache corruption when a soap:header defines headerfaults. Fixed stack overflow when parsing a WSDL with self-referential schema groups or attributeGroups. Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765) Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181) Standard: Fixed a segfault when a stream filter callback unsets StreamBucket::$data before re-attaching the bucket. Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682) Fixed read buffer compaction in php_stream_filter_flush(). Fixed bug GH-22410 (Incorrect float behavior with large numbers). Fixed GH-23338 (fsockopen()/pfsockopen() ValueError reported wrong argument number for $timeout). Fixed bug GH-23576 (Next index for array returned from array_keys() is wrong). Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in convert.* stream filters when line-break-chars contains NUL). (CVE-2026-92842) Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766) SimpleXML: Fixed writing to a dimension of the object returned by attributes() not creating the attribute. Fixed child elements of the element returned by SimpleXMLElement::addChild() not being accessible by property name when namespaces are involved. Windows: Fixed GHSA-9f67-6fw4-hpfp (Reserved device names are not rejected before file and stream I/O). (CVE-2026-17545) Zip: Fixed bug GH-17787 (ZipArchive stream stops reading early when the archive is freed while the stream is still open). Fixed bug GH-23276 (ZipArchive subclass storing its own stream cannot be garbage collected). SAPI: Fixed fuzzer targets failing to build in isolation. Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo) * fixes CVE-2026-91769 [bsc#1283044] CVE-2026-91765 [bsc#1282875] CVE-2026-91766 [bsc#1282876] CVE-2026-91767 [bsc#1282877] CVE-2026-91768 [bsc#1282878] CVE-2026-6103 [bsc#1282980] CVE-2025-1218 [bsc#1282981] CVE-2026-92842 [bsc#1282985] CVE-2026-93682 [bsc#1282986] CVE-2025-14181 [bsc#1283216] ==== plocate ==== Version update (1.1.24 -> 1.1.25) Subpackages: plocate-apparmor - original tar-ball (https://plocate.sesse.net/download/plocate-1.1.25.tar.gz) is botched, adjust %autosetup call - update to version 1.1.25: * Fix two early-exit bugs with multiple databases * Drop setgid properly, including the saved gid * Fix a potential symlink-checking race in updatedb ==== polkit-default-privs ==== Version update (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) - Update to version 1550+20260928.d1c0e7e: * profiles: added datarecovery run-ddrescue action (bsc#1280118) ==== python-click ==== Version update (8.4.2 -> 8.5.0) - Update to 8.5.0 * Argument accepts a help parameter, and help output includes a Positional arguments section * confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo() * Fix test failures when using pytest >= 9.1 * Path with allow_dash=True no longer triggers a BytesWarning * Add custom_version_option(), a --version option whose output is produced by a callback * style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError * get_binary_stream() and get_text_stream() are deprecated and will be removed in Click 9.0 * Deprecate CliRunner.isolated_filesystem() ==== python-cryptography ==== Version update (50.0.0 -> 50.0.1) - update to 50.0.1: * Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2. ==== python-httpx ==== - Add patch support-click-8.5.0.patch: * Do not use CliRunner.isolated_filesystem - Add patch support-pytest-9.1.patch: * Filter logs due to pytest 9.1 changes ==== python-jmespath ==== - Remove unneeded {Build,}Requires on ply. ==== python-msgpack ==== Version update (1.2.1 -> 1.2.2) - Update to 1.2.2: * Fix a use-after-free: unpackb() could build ExtraData.extra from already-freed memory when the input was a non-contiguous buffer (gh#msgpack/msgpack-python#720) * Fix silent datetime truncation in Unpacker with datetime=3 * Add a reentrant guard to Unpacker.feed() * Validate the nanoseconds range when unpacking timestamps in the C extension * Fix Timestamp.from_datetime() precision loss for far-future datetimes * Raise OverflowError instead of silently truncating when use_single_float cannot represent a value * Translate RecursionError to StackError in the fallback Unpacker.skip() ==== python-pypdf ==== Version update (6.16.2 -> 6.19.0) - Update to 6.19.0 * SEC: Limit size of alphabetical page labels * Replace PdfWriter method add_js * Move static value out of loop body for appearance stream data * Reduce number of full data lookups for attachment mapping API 6.18.1 * SEC: Further restrict FlateDecode recovery * SEC: Limit entry count for TrueType and Type1 font /Widths * SEC: Limit allowed length of tokens in parse_bfchar * Fix compatibility with fonttools < 4.58.0 6.18.0 * SEC: Limit allowed length of indirect object tokens * Rework configuration value handling * Draw borders and backgrounds for appearance streams and annotations 6.17.0 * SEC: Limit value for Roman numerals * _cmap.py: Also parse encoding for embedded CFF Type1 fonts * Cache repeated text extraction character lookups - Drop fonttools-slfo.patch, no longer needed (and skip the test) - Skip some flaky tests ==== raspberrypi-firmware-dt ==== - Fix regression in SRAM range (bsc#1282097) ==== readline ==== Version update (8.3.3 -> 8.3.6) - Add upstream patches * readline83-004 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * readline83-005 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * readline83-006 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== rpcbind ==== - Bound stats lists in rpcbs_getaddr() and rpcbs_rmtcall() (bsc#1282326, CVE-2026-94640) * add 0001-rpcbind-bound-stats-lists-in-rpcbs_getaddr-and-rpcbs.patch ==== rsyslog ==== - fix VUL-0: imdtls permitted-peer authorization bypass (bsc#1281628) * add 0001-imdtls-reject-clients-that-fail-peer-verification.patch ==== rubygem-cgi ==== Version update (0.5.0 -> 0.5.2) - Update to 0.5.2 (also covers skipped 0.5.1): * Handle a POST request with a missing/empty Content-Length instead of raising TypeError/ArgumentError (gh#ruby/cgi#56) * Fix CGI.unescapeHTML raising Encoding::CompatibilityError in the pure-Ruby fallback on mixed non-ASCII input (gh#ruby/cgi#103) * Fix escape_html/h/unescape_html aliases to actually dispatch to the C extension instead of the slower pure-Ruby implementation * Harden CGI::Session's file-store filename hashing: use SHA-256 instead of MD5, and add a configurable :digest option (default stays MD5 for backward compatibility) * Various documentation improvements - Run spec-cleaner (tag order, License operator casing normalized to the SPDX "AND") ==== sdbootutil ==== Version update (1+git20260909.7cfa1f0 -> 1+git20260929.26b6989) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper - Update to version 1+git20260929.26b6989: * Increase the timeout for the update-prediction service * Keep /.snapshots mounted for the shutdown helper * Serialize the update-predictions service and the shutdown helper * Do not ask to fix ROOTFS when the root is encrypted * Use >&2 instead of /dev/stderr * Revert "Move back from oneshot the update-predictions service" * Move back from oneshot the update-predictions service * Fix SELinux AVC from grep redirector * Use DSP for the LUKS2 swap partition * Add missing tight ESP unit test scenario * Don't count reused kernel when calculating free space - Update to version 1+git20260924.2b7b94e: * Improve detection of encrypted device when RAID is used * Support btrfs RAID1 configurations * Move the service from oneshot to exec to avoid the wait * Drop shift variations already present as a component * Fix Supplement use of 'if' instead of 'and' * Hide the warning for entries that uses @ * Accept _ instead of @ as snapshot prefix for version * Drop chown and set ownership via install * Use bootctl to generate the random seed * Start the validation with the strongest bank * Parse the JSON output of findmnt * Use stdin for qrencode * Fix log file permissions * Improve PCR15 diagnosis in status command * Avoid abrmd TCTI error message * Do not fail if pcrlock lock verb cannot reproduce the event log * The completion subpackage supplements the main one * Detect when grubenv is full * Use systemd-analyze to compare versions in status * Fix bootcounter in GRUB2 EFI variable * Drop lowercase in dd * Fix loader_conf_set for paths ==== selinux-policy ==== Version update (20260923 -> 20260928) Subpackages: selinux-policy-targeted - Update to version 20260928: * Allow sdbootutil_t write access to /var/lib/sdbootutil (bsc#1281087) ==== shadow ==== Version update (4.20.2 -> 4.20.3) Subpackages: libsubid6 login_defs shadow-pw-mgmt - Update to 4.20.3: * Build error when using '--with-nscd=no' (bug introduced in v4.19.0). ==== simdutf ==== Version update (9.2.0 -> 9.2.1) - Update to version 9.2.1: + Misc. bug fixes and cleanups. ==== slang ==== - Drop obsolete -fstack-protector from CFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== tesseract-ocr ==== Subpackages: libtesseract5 tesseract-ocr-common - Update tesseract-CVE-2026-88053.patch to null the adaptive template pointer arrays again and the class pruners as upstream does, fixing an abort at exit on every run and invalid frees when a corrupt traineddata is rejected (boo#1282863) ==== tuned ==== Version update (2.27.0.0+git.38d4414 -> 2.28.0) - Update to version 2.28.0: * bootloader: add bootc loader-entries set-options-for-source support so kernel-argument ownership on image mode (bootc) systems survives reboots (RHEL-170825); fixed tempdir permissions (RHEL-121198) and restored initrd generation from /tmp with an added ownership check * systemd: set the systemd manager's CPUAffinity via a new /etc/systemd/system.conf.d/00-tuned.conf drop-in instead of editing system.conf directly, and stop backing up the old file (RHEL-97580, RHEL-84365); the empty template upstream's Makefile now installs there is dropped from the package (rpmlint filelist-forbidden-systemd-userdirs) since the plugin creates it itself on first use * net: recognize more ethtool coalescing options instead of failing on unsupported ones (RHEL-152675); fixed the ring parser for rx-mini/rx-jumbo (RHEL-168025) * functions: use the nl80211-based iw tool for Wi-Fi power saving, falling back to iwpriv on legacy drivers (rhbz#2372365); adds a new mandatory Requires: iw * scheduler: handle EPERM, not just EIO, when setting IRQ affinity on kernel >= 6.12 (RHEL-153655) * network-latency: raise the AVC cache size to 8192, avoiding latency spikes on RHEL-9/10 kernels * openshift: add the network-throughput profile; dropped support for vm.laptop_mode, deprecated since kernel 7.0 * many more fixes and improvements; see upstream's release notes for the full list - Switch source from the hand-maintained git-snapshot _service (tracking master with no fixed revision) to the real v2.28.0 upstream release tarball, now that upstream is tagging releases again; drop _service/_servicedata/*.obscpio/*.obsinfo - Spec cleanup: drop obsolete Group: tags and redundant default file-attribute lines; switch the GObject Introspection build dependency to its two pkgconfig provider names (gobject-introspection-1.0, gobject-introspection-no-export-1.0) ==== unbound ==== Version update (1.26.0 -> 1.26.1) Subpackages: libunbound8 unbound-anchor - Update to 1.26.1: * Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. [bsc#1280411] * Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. [bsc#1280409] * Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. [bsc#1280412] * Fix CVE-2026-77955, Possible ZONEMD verification bypass window. [bsc#1280404] * Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. [bsc#1280405] * Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. [bsc#1280406] * Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. [bsc#1280413] * Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. [bsc#1280414] * Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. [bsc#1280403] ==== utf8proc ==== Version update (2.11.3 -> 2.12.0) - update to 2.12.0: * Unicode 18 support. This includes the modified grapheme-break rule GB9c in UAX 29, which removes some grapheme breaks for Indic characters * options arguments are changed from an enum to unsigned int, since they are generally bitwise "or" of enum values; this should be backwards binary compatible * int *last_boundclass parameter of utf8proc_decompose_char is changed to a utf8proc_int32_t * (affecting only rare systems where int is not 32 bits, on which the last_boundclass argument would have produced incorrect results) * New utf8proc_free function to free memory allocated by utf8proc * utf8proc_normalize_utf32 can now handle invalid codepoints ≥ 0x110000. They are passed through unchanged rather than dropped, and composition never runs across one * Fix UTF8PROC_CHARBOUND emitting no 0xff grapheme markers when combined with UTF8PROC_COMPOSE or UTF8PROC_DECOMPOSE, a regression in 2.11.3 ==== vlc ==== Version update (3.0.23 -> 3.0.24) Subpackages: libvlc5 libvlccore9 vlc-codec-gstreamer vlc-noX vlc-qt - Update to version 3.0.24: + Codecs: - Use FFmpeg 8.1 (upgraded from 4.4) - Support APV decoder (FFmpeg 8) - Support Atrac3/Atrac9 decoding - Remove schroedinger support for dirac in favor of avcodec - Fix Speex leaks and packetization issues - Fix WebVTT CSS parsing and error handling - Fix FLAC and HEVC packetizer edge cases - Fix AudioToolbox MIDI synthesizer crash on macOS 26+ + Demuxers: - Add support for CEA-708 closed captions in MP4 - Expose ID3v2 metadata in MPEG demuxer - Improve subtitle language detection from filenames and SSA/ASS metadata - Fix several MKV crashes, leaks, hangs and malformed file handling issues - Fix AVI hang with zero-sized strd chunks - Fix MP4, MPEG-TS, Ogg, RealAudio and subtitle demuxing edge cases + Access: - Switch RIST input and output to librist, with main and simple profile support - Add SRT listener mode support - Add SFTP public key authentication options and ED25519 hostkey support - Update SMB2 share enumeration - Don't ship RealRTSP plugin (build disabled for all configurations) + Service Discovery: - Include Chromecast model in mDNS renderer names - Fix IPv6 addresses in Bonjour service URLs + Video Output: - Fix Direct3D11 adjust filter and texture leaks - Fix MediaCodec crop validation - Super Resolution scaling with Moore Threads GPUs + Interface: - Qt: Fix default open dialog location - Qt: Fix effects window geometry saving - Qt: Improve hotkeys dialog strings + Stream Output: - Disable HEVC for original Chromecast devices + Security: - Switch to a new RSA-4096 key for update verification - Fix multiple OOB, integer overflow, double-free and use-after-free issues - See https://www.videolan.org/security/ - CVE-2026-56711: picture: inline AllocatePicture() and use overflow helpers + Misc: - Add Flatpak build support - Fix Audio EQ filter High Frequency parameter - Fix artwork preparser crash when artwork title is null - Fix LibVLC media list player race - Remove NPAPI browser plugin + Lua: - Remove broken youtube.lua plugin - Drop vlc-gstreamer-1.28-build-fix.patch: fixed upstream. ==== vsftpd ==== - Drop obsolete -fstack-protector from CFLAGS (predates distro - fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== wireplumber ==== Subpackages: libwireplumber-0_5-0 wireplumber-bash-completion wireplumber-zsh-completion - Modify environment file name in patch ==== xdg-dbus-proxy ==== Version update (0.1.8 -> 0.1.9) - Update to version 0.1.9: + Fix message filtering bypass vulnerabilities (CVE-2026-94422, GHSA-2cgv-pwcq-wvpq): - Don't allow method calls and signals to be treated as requested replies, even if they specify a reply serial number - Only allow replies that were sent to the appropriate destination + Improve automated tests to include attempts to exploit CVE-2026-94422 ==== yast2-auth-client ==== Version update (5.0.4 -> 5.0.5) - fix non specified optional params being unconditionally added to net cmd arg list; (bsc#1274806). - fix undefined conf.ad_user (NameError) in netcmd call; (bsc#1274612). - CVE-2026-59681: yast2-auth-client: OS command injection via unsanitized passed to net cmd. - Bump version to 5.0.5 for bsc#1272775. ==== yast2-trans ==== Version update (84.87.20260916.f55042cfcf -> 84.87.20260923.cade5cf3bd) Subpackages: yast2-trans-af yast2-trans-ar yast2-trans-bg yast2-trans-bn yast2-trans-bs yast2-trans-ca yast2-trans-cs yast2-trans-cy yast2-trans-da yast2-trans-de yast2-trans-el yast2-trans-en_GB yast2-trans-es yast2-trans-et yast2-trans-fa yast2-trans-fi yast2-trans-fr yast2-trans-gl yast2-trans-gu yast2-trans-hi yast2-trans-hr yast2-trans-hu yast2-trans-id yast2-trans-it yast2-trans-ja yast2-trans-jv yast2-trans-ka yast2-trans-km yast2-trans-ko yast2-trans-lo yast2-trans-lt yast2-trans-mk yast2-trans-mr yast2-trans-nb yast2-trans-nl yast2-trans-pa yast2-trans-pl yast2-trans-pt yast2-trans-pt_BR yast2-trans-ro yast2-trans-ru yast2-trans-si yast2-trans-sk yast2-trans-sl yast2-trans-sr yast2-trans-sv yast2-trans-ta yast2-trans-th yast2-trans-tr yast2-trans-uk yast2-trans-vi yast2-trans-wa yast2-trans-xh yast2-trans-zh_CN yast2-trans-zh_TW yast2-trans-zu - Update to version 84.87.20260923.cade5cf3bd: * Translated using Weblate (Danish) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan) * Translated using Weblate (Catalan)