Packages changed: MicroOS-release (20260924 -> 20260930) aaa_base (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) bash (5.3.15 -> 5.3.20) bash-completion (2.17.0 -> 2.18.0) bluez cairo (1.18.4 -> 1.18.6) cups dracut (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) flatpak (1.18.3 -> 1.18.4) fribidi (1.0.16 -> 1.0.17) fwupd (2.1.7 -> 2.1.8) gcr (4.4.0.1 -> 4.4.1) google-noto-coloremoji-fonts (20250916 -> 20260924) gpsd hwinfo (25.5 -> 26.0) jeos-firstboot (1.5.9 -> 1.5.14) jitterentropy kernel-firmware-amdgpu (20260829 -> 20260926) kernel-firmware-ath10k (20260809 -> 20260926) kernel-firmware-ath11k (20260610 -> 20260926) kernel-firmware-ath12k (20260813 -> 20260926) kernel-firmware-bluetooth (20260828 -> 20260929) kernel-firmware-brcm (20260610 -> 20260915) kernel-firmware-intel (20260728 -> 20260916) kernel-firmware-iwlwifi (20260820 -> 20260926) kernel-firmware-media (20260813 -> 20260926) kernel-firmware-mediatek kernel-firmware-mwifiex (20260610 -> 20260926) kernel-firmware-network kernel-firmware-platform kernel-firmware-qcom (20260828 -> 20260929) kernel-firmware-qlogic kernel-firmware-realtek (20260731 -> 20260915) kernel-firmware-sound (20260825 -> 20260926) kernel-source (7.2.7 -> 7.2.8) kirigami-addons6 (1.13.0 -> 1.14.0) libX11 libXi libXpm libXtst libraw libsecret (0.21.7 -> 0.21.8.2) libslirp (4.9.3+4 -> 4.9.5+1) libsodium libtasn1 libtheora libupnp (22.1.2 -> 22.1.7) llvm23 (23.1.1 -> 23.1.2) openexr (3.4.14 -> 3.4.15) openssh pam (1.7.2+git48 -> 1.7.3) pam-full-src (1.7.2+git48 -> 1.7.3) parted (3.7 -> 3.8) polkit-default-privs (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) python-cryptography (50.0.0 -> 50.0.1) raspberrypi-firmware-dt readline (8.3.3 -> 8.3.6) sdbootutil (1+git20260909.7cfa1f0 -> 1+git20260929.26b6989) selinux-policy (20260923 -> 20260928) shadow (4.20.2 -> 4.20.3) slang sof-firmware (2025.12.2 -> 2026.09.1) tesseract-ocr vlc (3.0.23 -> 3.0.24) wireplumber xdg-dbus-proxy (0.1.8 -> 0.1.9) === Details === ==== MicroOS-release ==== Version update (20260924 -> 20260930) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== aaa_base ==== Version update (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) - Update to version 84.87+git20260924.144354a1: * change requires for aaa_base-extras also to pathes ==== bash ==== Version update (5.3.15 -> 5.3.20) Subpackages: bash-sh - Add upstream patches * Bash-5.3 Official patch 16 -- bash53-016 On recent versions of macOS, the pipe size is dynamic and changes due to system-wide total pipe usage, so we have to check whether or not bash can use the size determined at compile time. * Bash-5.3 Official patch 17 -- bash53-017 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * Bash-5.3 Official patch 18 -- bash53-018 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * Bash-5.3 Official patch 19 -- bash53-019 On some systems, macOS in particular, isalpha(3) returns true for bytes between 128 and 255. Bash uses this to determine whether or not these characters are permitted to be part of a shell identifier, and can consume one byte too many when determining the end of a variable name. * Bash-5.3 Official patch 20 -- bash53-020 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== bash-completion ==== Version update (2.17.0 -> 2.18.0) - Update to 2.18.0: This release comes with notable changes to the directories used for looking up and sourcing completion recipes and helpers, allowing for more flexibility and customization and fewer conflicts between things shipping with bash-completion and third party/upstream/origin packages. Files that come with bash-completion itself are located in directories reserved for that use, their names ending with -core and -fallback. Packages should continue install their files in the same completions and helpers dirs like before; these directories precede the bash-completion "core" ones in lookup order. A new concept of startup dirs has been introduced. Files from these directories are sourced eagerly on bash-completion startup. This replaces and allows for more flexibility than using the deprecated /etc/bash_completion.d directory for this purpose. * Features _comp__init: source system startup files earlier (b09700d) _comp_compgen_filedir: automatically add -f on _comp_compgen -C or -P (#1552) (6d5fca6) _comp_compgen_filedir: support "filedir -X" (ce28419) _comp_compgen_sysv_services: factorize SysV service generation (c4c8c4b) aclocal,automake: support versioned 1.17 executables (94bbb3a) aclocal,automake: support versioned 1.18 executables (9287b4b) apt-*: update known options up to apt 3.2.0 (c421d50) apt-cache: update known options up to apt 3.2.0 (0ab85c5) apt-get: update known options up to apt 3.2.0 (6a18e0c) apt-mark: update known options up to apt 3.2.0 (644a026) codex: 3rd party fallback completion loader (0f425bd) copilot: 3rd party fallback completion loader (744602a) curlie: alias to curl (dd8f6e0) curl: more option argument (non-)completions (5099cef) dive: add 3rd party fallback completion loader (f817cca) doas: add new completion (f047b70) doas: generate completions as if we're root (a705713) encore: 3rd party fallback completion loader (1e54d02) etcdctl,etcdutl: 3rd party fallback completion loaders (39f8ddf) helium: alias to chromium-browser (8600af0) inotifywait2: generate exclude filenames prefixed by @ (c1e2f1b) inotifywait: generate exclude filenames prefixed by @ (0a2c165) ip: Check /usr/share config path (45530b0) jq: --rawfile arg (non-)completion (4f454d8) jreleaser: add 3rd party fallback completion loader (e1c2815) mago: add 3rd party fallback completion loader (97c4c49) ogg123: associate opus extension (7d3ea33) opencode: add 3rd party fallback completion loader (dbcea18) pnpm: add 3rd party fallback completion loader (44804ae) pydoc: support versioned 3.13..15 executables (bd60b26) python,pyvenv: support versioned 3.14 and .15 executables (72a2e47) release-plz: add 3rd party fallback completion loader (c3c4066) rumdl: add 3rd party fallback completion loader (5ef9790) skupper: add 3rd-party fallback completion loader (4237c9c) ssh-keygen: -M arg completion (b13bf99) ssh-keygen: -Z argument completion (c763d52) ssh-keygen: update -t arg completions (4269a90) ssh-keygen: update -Y arg completions (a73bcaf) ssh: do not complete -P arg (tag) (7d26a86) ssh: include proxy in -O arg completions (fc1df1f) ssh: more option arg (non-)completions (33f789c) sudo-rs,sudo.ws: alias to sudo (084cc68) sudo: more option argument (non-)completions (216135e) support the "startup{,-core}" directory (d6169af) syncthing: add 3rd party fallback completion loader (bc5dfff) tmux: complete src/target session arguments (18b6da4) tmux: complete target-session arguments (ced59c3) ty: add 3rd party fallback completion loader (57a2b31) waydroid: add 3rd party fallback completion loader (acc800f) xrdb: misc improvements (#1669) (461f90c) zed: 3rd party fallback completion loader (83532fa) * Bug Fixes _comp_compgen_services: fix no completions without sysvdir (a2e2659) _comp_compgen_services: skip service status marks (1ac9169) _comp_compgen_sysv_services: do not generate names in subdirs (5557fbe) _comp_compgen: clear the variable when no completions are generated (c07bd66) _comp_complete_service: fix init-script-action parsing (#1499) (91e075a) _comp_complete_user_at_host: care about $cur starting with "-" (277da58) _comp_load: deprecate unsuffixed "completions/" w/o ".bash" (06910da) _comp_load: drop support for "_" (f245356) _known_hosts: fix spacing of an error message (0463570) _known_hosts: work around custom IFS (8171929) _variable_assignments: exclude invalid timezones for "TZ" (d405a1d) add compatibility wrapper for tail (f6fee8a) alternatives: work around localvar_inherit (360192a) apt-get,ebtables,iptables,mplayer,service: avoid | and | in sed (ed64c30) apt-get,gpg{,2},ipmitool,screen: avoid \t, \r, \w in POSIX sed (da40e7a) ccache: fix a wrong AWK condition (c300c0f) cd: Complete from . on empty CDPATH entry (#1527) (6f1eba6) cd: fix cdable_vars overwritten by another generator (24bd420) cd: work around bash-4.2 nounset (45d1c93) compatdir: shadow compat files of the same name (ff1bf72) completion load precedence more (0a15408) export: complete options not at $1 (832822d) export: suffix "=" only when unique and already complete (76f980c) export: work around custom IFS (2617d26) fbgs,fbi: add mandatory semicolons before "}" in POSIX sed (288e77e) fix non-POSIX sed expressions (e999091) gnokii: use double \ in [...] for POSIX.1-2024 recommendation (ab0483a) inotifywait: add -t in noargopts (0295129) interdiff: move to fallback for the upstream completion (11987a4) invoke-rc.d: avoid using non-POSIX | in sed (db928dd) invoke-rc.d: fix a bug of generating existing words (dfb903b) ... changelog too long, skipping 57 lines ... fails duwe e.g. missing network ==== bluez ==== Subpackages: bluez-cups libbluetooth3 - Add fix-crash-on-UUID-discovery.patch ==== cairo ==== Version update (1.18.4 -> 1.18.6) Subpackages: libcairo-gobject2 libcairo2 - Update to version 1.18.6: + The XCB surface triggered an UAF warning when building with GCC. + The clipping code was accessing various fields in a guard value, and causing a crash inside Inkscape. + Multiple fixes for the Windows backends, including improvements in the thread safety of the DirectWrite code. + The DirectWrite backend now supports COLRv1 fonts. + Multiple fixes for building with MSVC and ClangCL. + A leak in the PDF surfaces has been fixed. + Various gaps between abutting rectangles when drawing with ANTIALIAS_NONE were removed by using absolute coordinates and avoiding rounding errors. + Remove an overflow when computing the buffer size in the XRender code. - Refresh cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff with quilt. ==== cups ==== Subpackages: cups-client cups-config libcups2 libcupsimage2 - Drop obsolete -fstack-protector from CFLAGS/CXXFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== dracut ==== Version update (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) Subpackages: dracut-ima - Update to version 112+suse.53.g97cbf62: * fix(fips): use BOOT_IMAGE_NAME instead of BOOT_IMAGE in path check ==== flatpak ==== Version update (1.18.3 -> 1.18.4) Subpackages: flatpak-selinux libflatpak0 system-user-flatpak - Update to version 1.18.4: + Security fixes: - Prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious app is installed (CVE-2026-97024, GHSA-8xgq-v545-vgv) - Prevent privileged deletion of arbitrary files when a malicious app is installed (CVE-2026-97023, GHSA-5p67-xh8x-rq54) - When downloading apps or runtimes from an OCI repository that requires authentication, don't make the authentication token visible to other users (CVE-2026-97025, GHSA-7rvf-rqr3-43j4) - Restrict permissions on temporary repository directories in /var/tmp/flatpak-cache-* (CVE-2026-97026, GHSA-r9w3-qx54-qvc8) - Filter .desktop and D-Bus .service files against an allowlist of fields, preventing denial of service and unintended interactions with host services (CVE-2026-97027, GHSA-v64f-hrwr-j4vh) - Prevent apps from sending signals to a process group that includes a parent process outside the app, causing denial of service by killing the desktop environment (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2) + Bug fixes: - Update Meson wrap subprojects for projects that are normally taken from the host system: - xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422) - Improve hardening against symlink traversal, related to CVE-2026-97023 and CVE-2026-97024 + Internal changes: - Add CVE IDs and reporter credits to 1.18.1's NEWS entry - Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries ==== fribidi ==== Version update (1.0.16 -> 1.0.17) - Update to 1.0.17: * Update Unicode character databases to v18.0.0. * Performance improvements: eliminate quadratic worst-case behavior in FSI base direction resolution, N0 bracket pairing, embedding-level resolution, and fribidi_reorder_line(). * Fix fribidi_set_reorder_nsm() and fribidi_set_mirroring() not taking effect when called before fribidi_log2vis(). * Fix bracket pairing (N0) to match brackets by canonical equivalence only, per UAX #9 BD16. * Fix stack buffer overflow when parsing character-set equivalence tables, and out-of-bounds read on trailing '_' in charset data. * Fix truncation of lines/output containing embedded NUL bytes. * Generate and install the fribidi(1) man page. - Add BuildRequires: help2man to generate fribidi(1) man page. - Package %{_mandir}/man1/fribidi.1*. - Drop ancient ppc64 obsoletes for fribidi-64bit. ==== fwupd ==== Version update (2.1.7 -> 2.1.8) Subpackages: libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.8: + This release adds the following features: - Add a new plugin to poke bootupd when the ESP changes - Add RSA-3072 signature verification support for Lenovo accessories + This release fixes the following bugs: - Add a workaround for the systemd-pcrosseparator.service PCR0 extension - Add hashes for the latest DBX for offline machines - Add user aware message to complete the dell-dock update - Allow enumeration BIOS settings to take either string or integer - Allow redfish firmware blobs up to 512MiB - Always use base-16 when parsing the UEFI capsule index - Do not allow a DFU altname or STM32 sector size of zero - Fix a buffer overwrite when parsing Synaptics CAPE HID reports - Fix a dell-dock crash via malformed EC_CMD_GET_DOCK_INFO response - Fix a file descriptor leak when getting firmware details - Fix a memory leak when parsing an invalid TPM eventlog - Fix a NULL deref when enumerating a broken synaptics-rmi device - Fix a snapd error when installing the latest dbx - Fix an integer underflow in Focal FP HID CRC parser - Fix eMMC error recovery command when setting install mode fails - Fix firmware recovery of Logitech Unifying devices - Increase the Huddly USB bulk write timeout to 30s - Invalidate the Wacom descriptor cache when the block count changes - Limit decompressing LZMA streams to 2GiB - Update PCB version checking logic in usi-dock - Use the stricter PolicyKit action ID when the device has gone - Verify the jcat item IDs before using them as filenames + This release adds support for the following hardware: - ASUS GX5407 - Elan PID 0CB6 - FocalTech MOC fingerprint sensors - Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000 - MaxLinear MxL862xx - MediaTek MT9700 FCTE and MT9701 KSMU - Pixart PID 4F01, 4F02, 4F0D and 4F0E - Rolling RW101 ==== gcr ==== Version update (4.4.0.1 -> 4.4.1) Subpackages: libgck-2-2 libgcr-4-4 - Update to version 4.4.1: + gcr: - Support zero mtime - Fix memory leak in GcrSystemPrompt call closure + docs: Fix a method reference in gcr_prompt_set_choice_label() + Updated translations. ==== google-noto-coloremoji-fonts ==== Version update (20250916 -> 20260924) - Update to v2.057 * Unicode 18.0 update - 19 new emojis (9 new emoji code points plus 10 skin-tone sequences for directional thumbs) ==== gpsd ==== - Fix for gpsprof arbitrary OS command execution via code injection in the attacker-controlled SKY.satellites[].used field, inserted unsanitized into a gnuplot heredoc data block; sat.used is now forced to a boolean (CVE-2026-60122 [bsc#1280016]) + 5a9c44a4.patch ==== hwinfo ==== Version update (25.5 -> 26.0) - merge gh#openSUSE/hwinfo#191 - code cleanup: remove some unused variables - 26.0 - merge gh#openSUSE/hwinfo#193 - add MMC/SD card block device support - add some minor improvements - merge gh#openSUSE/hwinfo#188 - Fix check_hd being built without LDFLAGS - merge gh#openSUSE/hwinfo#190 - fix(s390): fix memory leaks on skip paths in ccw device scan - merge gh#openSUSE/hwinfo#189 - fix(s390): fix out-of-bounds write in cutypes scan loop ==== jeos-firstboot ==== Version update (1.5.9 -> 1.5.14) - Update to version 1.5.14: * Refine the JEOS_USER_GROUPS option and use it for the builtin default * Read jeos-firstboot.conf in jeos-config as well * Add configuration variables on groups to add users to * Move welcome_screen_with_console_switch stub to end of file * Fix welcome_screen_with_console_switch undefined in jeos-config ==== jitterentropy ==== - OSR has to be at least 5 according to current reviews. (bsc#1282301) jitterentropy-minimum-osr.patch ==== kernel-firmware-amdgpu ==== Version update (20260829 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * amdgpu: update VPE 2.0.0 firmware * amdgpu: update VCN 5.3.0 firmware * amdgpu: update GC 11.7.0 MES firmware * amdgpu: update PSP 15.0.9 firmware * amdgpu: update PSP 15.0.0 firmware * Revert "amdgpu: update GC 11.0.0 firmware" * Revert "amdgpu: update GC 11.0.0 firmware" * amdgpu: DMCUB updates for various ASICs - Update to version 20260915 (git commit 4584045b2121): * Revert "amdgpu: update VCN 5.3.0 firmware" * Revert "amdgpu: update VCN 5.0.1 firmware" * Revert "amdgpu: update VCN 5.0.0 firmware" * Revert "amdgpu: update VCN 4.0.6 firmware" * Revert "amdgpu: update VCN 4.0.6 firmware" * Revert "amdgpu: update VCN 4.0.5 firmware" * Revert "amdgpu: update VCN 4.0.5 firmware" * Revert "amdgpu: update vcn 4.0.4 firmware" * Revert "amdgpu: update VCN 4.0.3 firmware" * Revert "amdgpu: update VCN 4.0.2 firmware" * Revert "amdgpu: update VCN 4.0.2 firmware" * Revert "amdgpu: update VCN 4.0.0 firmware" * Revert "amdgpu: update VCN 3.1.2 firmware" * amdgpu: partially revert 9f1eb5124635 * amdgpu: partially revert e3e45091597e * amdgpu: partially revert 7df10898a825 * amdgpu: partially revert 7b262e1ddce5 * amdgpu: partially revert 17ee8fdf9196 * amdgpu: partially revert 063e840eb6a5 * Partially revert "amdgpu: DMCUB updates for various ASICs" - Update to version 20260912 (git commit d371ae3b6888): * amdgpu: update vangogh firmware * amdgpu: update VPE 6.1.1 firmware * amdgpu: update VCN 4.0.6 firmware * amdgpu: update PSP 14.0.1 firmware * amdgpu: update GC 11.5.1 firmware * amdgpu: update VCN 4.0.5 firmware * amdgpu: update PSP 14.0.0 firmware * amdgpu: update GC 11.5.0 firmware * amdgpu: update renoir firmware * amdgpu: update yellow carp firmware * amdgpu: update PSP 13.0.5 firmware * amdgpu: update PSP 13.0.11 firmware * amdgpu: update GC 11.0.4 firmware * amdgpu: update VCN 4.0.2 firmware * amdgpu: update PSP 13.0.4 firmware * amdgpu: update GC 11.0.1 firmware * amdgpu: update SMU 14.0.3 firmware * amdgpu: update PSP 14.0.3 firmware * amdgpu: update GC 12.0.1 firmware * amdgpu: update PSP 14.0.2 firmware * amdgpu: update GC 12.0.0 firmware * amdgpu: update SMU 13.0.7 firmware * amdgpu: update PSP 13.0.7 firmware * amdgpu: update GC 11.0.2 firmware * amdgpu: update SMU 13.0.10 firmware * amdgpu: update PSP 13.0.10 firmware * amdgpu: update GC 11.0.3 firmware * amdgpu: update SMU 13.0.0 firmware * amdgpu: update PSP 13.0.0 firmware * amdgpu: update GC 11.0.0 firmware * amdgpu: update beige goby firmware * amdgpu: update dimgrey cavefish firmware * amdgpu: update navy flounder firmware * amdgpu: update sienna cichlid firmware * amdgpu: update navi14 firmware * amdgpu: update navi12 firmware * amdgpu: update navi10 firmware * amdgpu: update PSP 15.0.9 firmware * amdgpu: update GC 11.7.1 firmware * amdgpu: update VCN 5.3.0 firmware * amdgpu: update PSP 15.0.0 firmware * amdgpu: update GC 11.7.0 firmware * amdgpu: update PSP 14.0.5 firmware * amdgpu: update GC 11.5.3 firmware * amdgpu: update VPE 6.1.3 firmware * amdgpu: update PSP 14.0.4 firmware * amdgpu: update GC 11.5.2 firmware * amdgpu: update green sardine firmware * amdgpu: DMCUB updates for various ASICs - Update to version 20260904 (git commit 2f2bf38a3d03): * amdgpu: DMCUB updates for various ASICs - Update aliases from 7.3-rc1 ==== kernel-firmware-ath10k ==== Version update (20260809 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * qcom/shikra: link WiFi firmware from the ath10k subdir - Update to version 20260915 (git commit 4584045b2121): * qcom/sdm845: Let SHIFT6mq use the provided Wi-Fi firmware - Update to version 20260912 (git commit d371ae3b6888): * ath10k: WCN3990: hw1.0: add shikra firmware files ==== kernel-firmware-ath11k ==== Version update (20260610 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * ath11k: WCN6855 hw2.0: update board-2.bin ==== kernel-firmware-ath12k ==== Version update (20260813 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * ath12k: WCN7850 hw2.0: update board-2.bin * ath12k: QCC2072 hw1.0: update board-2.bin - Update to version 20260902 (git commit abddc5b93044): * ath12k: QCC2072 hw1.0: update to WLAN.COL.1.0.c2-00277-QCACOLSWPL_V1_TO_SILICONZ-1 ==== kernel-firmware-bluetooth ==== Version update (20260828 -> 20260929) - Update to version 20260929 (git commit 33b68e2c7011): * QCA: Add QCA2066 Bluetooth firmware hpnv21g.30c * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00653 - Update to version 20260926 (git commit 9b858e5bb58d): * qca: group the QCA61x4 USB firmware files * qca: fix the version of the WCN785x USB firmware * intel: Update ibt-00a0-01a1-pci.ddc for BE211 - Whale Peak2 (WhP2) - Update to version 20260916 (git commit e289868675d1): * QCA: Update Bluetooth firmware for QCC2072 UART interface: 1.1.0-00340 to 1.1.0-00355 - Update to version 20260910 (git commit eeccccbe83da): * QCA: Add Bluetooth firmware for WCN7750 on Maili platform - Update to version 20260902 (git commit abddc5b93044): * QCA: Add Bluetooth firmware hmtnv20.b201/b202 for WCN7850 on Nord platform * QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00079 ==== kernel-firmware-brcm ==== Version update (20260610 -> 20260915) - Update to version 20260915 (git commit 4584045b2121): * WHENCE: add missing symlink for TaiqiCat (TQC) A01 - Update to version 20260902 (git commit abddc5b93044): * [cypress]: Update firmware for cyfmac43455 SDIO ==== kernel-firmware-intel ==== Version update (20260728 -> 20260916) - Update to version 20260916 (git commit e289868675d1): * intel_vpu: Update NPU firmware ==== kernel-firmware-iwlwifi ==== Version update (20260820 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * iwlwifi: add Bz/Sc FW for core24.80-41 release * iwlwifi: Update Bz/Fm firmware for core24.80-41 release * iwlwifi: Add Hr/Gf firmware for core24.80-41 release * iwlwifi: update ty/So/Ma firmwares for core24.80-41 release * iwlwifi: Add cc/Qu/QuZ firmwares for core24.80-41 release - Update aliases ==== kernel-firmware-media ==== Version update (20260813 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * qcom: vpu: add Gen2 firmware binary for Hawi * qcom: vpu: add Gen2 firmware binary for Maili - Update to version 20260915 (git commit 4584045b2121): * qcom: vpu: add Gen2 firmware binary for sc8280xp - Update to version 20260910 (git commit eeccccbe83da): * qcom: vpu: Update video firmware binary for Glymur ==== kernel-firmware-mediatek ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-mwifiex ==== Version update (20260610 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * linux-firmware: mwifiex: add IW416 firmware ==== kernel-firmware-network ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-platform ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-qcom ==== Version update (20260828 -> 20260929) - Update to version 20260929 (git commit 33b68e2c7011): * qcom: update ADSP firmware for hawi platform * Revert "qcom: update ADSP firmware for qcs615 platform"q * qcom: Add gpu firmwares for Hawi and Maili chipsets - Update to version 20260926 (git commit 9b858e5bb58d): * qcom: update Rubik Pi 3 ADSP firmware * qcom: add CDSP firmware for hawi platform - Update to version 20260916 (git commit e289868675d1): * qcom: add ADSP firmware for maili platform - Update to version 20260915 (git commit 4584045b2121): * qcom/sdm845: Let SHIFT6mq use the provided Wi-Fi firmware - Update to version 20260910 (git commit eeccccbe83da): * qcom: Update ADSP firmware for sa8775p platform * qcom: point qcs8300 firmawre to sa8775p instance * qcom: update ADSP firmware for qcs615 platform * qcom: Add ADSP firmware for sc8280xp-radxa-dragon-q8b * qcom: sdm845: Add GPU firmware for SHIFT6mq * qcom: Update ADSP firmware for QCM6490 platform - Update aliases from 7.3-rc1 ==== kernel-firmware-qlogic ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-realtek ==== Version update (20260731 -> 20260915) - Update to version 20260915 (git commit 4584045b2121): * rtl_nic: add firmware rtl8261d.bin for RTL8261d ==== kernel-firmware-sound ==== Version update (20260825 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * cirrus: cs35l56: Correct firmware instances for 103c8c52 and 103c8c53 * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops * cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for some Dell laptops - Update to version 20260912 (git commit d371ae3b6888): * cirrus: cs35l57: Add firmware for Cirrus Amps for a Lenovo laptop - Update to version 20260910 (git commit eeccccbe83da): * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops * cs35l56: Add non-spkid firmware names for Thinkbook 16P Gen6 (17AA3921) - Update to version 20260903 (git commit ec2d074008a5): * cirrus: Version and cleanup of SDCA FW files - Update to version 20260902 (git commit abddc5b93044): * cirrus: cs35l41: Add Firmware for ASUS Zenbook Laptop using CS35L41 HDA - Update aliases from 7.3-rc1 ==== kernel-source ==== Version update (7.2.7 -> 7.2.8) Subpackages: kernel-64kb kernel-default - Update patches.kernel.org/7.2.4-018-clocksource-drivers-timer-sun4i-Advertise-a-rea.patch (bsc#1012628 CVE-2026-93219 bsc#1282749). - Update patches.kernel.org/7.2.4-048-mm-huge_memory-skip-device-private-PMDs-in-madv.patch (bsc#1012628 CVE-2026-93218 bsc#1282748). - Update patches.kernel.org/7.2.4-050-mm-hugetlb-fix-boot-panic-with-CONFIG_DEBUG_VM-.patch (bsc#1012628 CVE-2026-93232 bsc#1282694). - Update patches.kernel.org/7.2.4-051-mm-hugetlb-initialize-gigantic-bootmem-hugepage.patch (bsc#1012628 CVE-2026-93230 bsc#1282693). - Update patches.kernel.org/7.2.4-054-mm-madvise-skip-device-private-PMDs-in-cold-and.patch (bsc#1012628 CVE-2026-93217 bsc#1282760). - Update patches.kernel.org/7.2.4-060-mm-mm_init-deferred_grow_zone-fix-out-of-range-.patch (bsc#1012628 CVE-2026-93227 bsc#1282696). - Update patches.kernel.org/7.2.4-061-mm-page_owner-use-memcg_data-snapshot-to-avoid-.patch (bsc#1012628 CVE-2026-93216 bsc#1282780). - Update patches.kernel.org/7.2.4-094-cdx-Fix-double-free-when-sysfs-file-creation-fa.patch (bsc#1012628 CVE-2026-93215 bsc#1282758). - Update patches.kernel.org/7.2.4-114-usb-gadget-f_tcm-fix-deadlock-in-usbg_make_tpg.patch (bsc#1012628 CVE-2026-93214 bsc#1282776). - Update patches.kernel.org/7.2.4-127-of-fix-out-of-bounds-read-in-of_alias_scan-stem.patch (bsc#1012628 CVE-2026-93213 bsc#1282775). - Update patches.kernel.org/7.2.4-144-nfsd-guard-nfsd_serv-deref-in-nfsd_file_net_dis.patch (bsc#1012628 CVE-2026-93212 bsc#1282774). - Update patches.kernel.org/7.2.4-162-nfsd-add-missing-read-barrier-to-rpc_status_get.patch (bsc#1012628 CVE-2026-93229 bsc#1282698). - Update patches.kernel.org/7.2.4-169-nfsd-convert-nfsd_net-boolean-flags-to-unsigned.patch (bsc#1012628 CVE-2026-93221 bsc#1282736). - Update patches.kernel.org/7.2.4-199-nfsd-initialize-DRC-hash-table-before-registeri.patch (bsc#1012628 CVE-2026-93211 bsc#1282740). - Update patches.kernel.org/7.2.4-243-smb-client-harden-DFS-cache-against-invalid-tar.patch (bsc#1012628 CVE-2026-93210 bsc#1282737). - Update patches.kernel.org/7.2.4-343-Bluetooth-hci_core-use-skb_get-instead-of-skb_c.patch (bsc#1012628 CVE-2026-93209 bsc#1282735). - Update patches.kernel.org/7.2.4-348-kasan-fix-cache-shrink-race-with-CPU-hotplug.patch (bsc#1012628 CVE-2026-93208 bsc#1282732). - Update patches.kernel.org/7.2.4-357-ipv6-use-RCU-iterator-to-dump-route-exceptions.patch (bsc#1012628 CVE-2026-93226 bsc#1282723). - Update patches.kernel.org/7.2.4-369-phy-fsl-imx8mq-usb-fix-typec-switch-leak-on-pro.patch (bsc#1012628 CVE-2026-93225 bsc#1282726). - Update patches.kernel.org/7.2.4-371-SUNRPC-Zero-rpc_gss_wire_cred-at-svcauth_gss_de.patch (bsc#1012628 CVE-2026-93207 bsc#1282672). - Update patches.kernel.org/7.2.4-393-svcrdma-Fix-unmatched-rn_unregister-on-failed-a.patch (bsc#1012628 CVE-2026-93224 bsc#1282703). - Update patches.kernel.org/7.2.4-398-svcrdma-Reject-Write-Reply-chunks-with-segcount.patch (bsc#1012628 CVE-2026-93228 bsc#1282697). - Update patches.kernel.org/7.2.4-401-udf-reject-VAT-indexes-equal-to-the-entry-count.patch (bsc#1012628 CVE-2026-89525 bsc#1282288). - Update patches.kernel.org/7.2.4-404-staging-media-tegra-video-fix-of_node_put-on-VI.patch (bsc#1012628 CVE-2026-93223 bsc#1282741). - Update patches.kernel.org/7.2.4-418-sched_ext-Keep-kick_sync-waiting-on-the-rq-s-ow.patch (bsc#1012628 CVE-2026-93220 bsc#1282750). - Update patches.kernel.org/7.2.4-486-lockd-fix-swapped-arguments-in-nlmsvc_match_ip.patch (bsc#1012628 CVE-2026-93231 bsc#1282778). - Update patches.kernel.org/7.2.4-534-PCI-proc-Use-file_ns_capable-when-checking-conf.patch (bsc#1012628 CVE-2026-93206 bsc#1282729). - Update patches.kernel.org/7.2.4-541-iommu-arm-smmu-v3-Manage-teardown-with-devm.patch (bsc#1012628 CVE-2026-93205 bsc#1282727). - Update patches.kernel.org/7.2.4-703-signal-avoid-shared-siginfo-namespace-rewrites.patch (bsc#1012628 CVE-2026-93222 bsc#1282742). - Update patches.kernel.org/7.2.5-097-mm-secretmem-properly-account-locked-pages.patch (bsc#1012628 CVE-2026-93243 bsc#1282687). - Update patches.kernel.org/7.2.5-128-memcg-bypass-the-reclaim-and-oom-killer-for-dyi.patch (bsc#1012628 CVE-2026-93241 bsc#1282781). - Update patches.kernel.org/7.2.5-129-memcg-make-the-v1-soft-limit-knob-inert.patch (bsc#1012628 CVE-2026-93240 bsc#1282779). - Update patches.kernel.org/7.2.5-146-arm64-mm-Fix-the-lockless-page-table-walk-in-sh.patch (bsc#1012628 CVE-2026-93239 bsc#1282681). ... changelog too long, skipping 1612 lines ... - commit 93e89db ==== kirigami-addons6 ==== Version update (1.13.0 -> 1.14.0) Subpackages: libKirigamiAddonsComponents6 libKirigamiAddonsStatefulApp6 libKirigamiApp6 - Update to 1.14.0 https://carlschwan.eu/2026/09/17/imprint-1.0-and-kirigami-addons-1.14.0/ ==== libX11 ==== Subpackages: libX11-6 libX11-data libX11-xcb1 - 0001-1281653_CVE-2026-94283_ximcp-bound-XIM_OPEN_REPLY-attribute-lengths-to-the-.patch * Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser (boo#1281653, CVE-2026-94283) - 0002-1281657_CVE-2026-94284_ximcp-bound-XIM_REGISTER_TRIGGERKEYS-keylist-lengths.patch * Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser (boo#1281657, CVE-2026-94284) - 0003-1281661_CVE-2026-94285_lcGenConv-bound-byteM_parse_codeset-reads-to-remaini.patch * Out-of-bounds read in libX11's byte-oriented codeset parser (boo#1281661, CVE-2026-94285) ==== libXi ==== - 0001-boo1281605_CVE-2026-93541_XQueryDeviceState-check-ValuatorClass-num_valuators-.patch * Out-of-bounds read in libXi's XQueryDeviceState() (boo#1281605, CVE-2026-93541) - 0002-boo1281606_CVE-2026-93542_size_classes-copy_classes-bound-XI2-class-lengths-to.patch * Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() (boo#1281606, CVE-2026-93542) - 0003-boo1281608_CVE-2026-93543_size_classes-copy_classes-enforce-XI2-per-type-class.patch * Out-of-bounds read in libXi's XI2 class parser (boo#1281608, CVE-2026-93543) - 0004-boo1281609_CVE-2026-93544_XIQueryDevice-keep-padded-name-and-class-bytes-withi.patch * Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing (boo#1281609, CVE-2026-93544) - 0005-boo1281612_CVE-2026-93545_XListInputDevices-validate-device-name-lengths-again.patch * Out-of-bounds read in libXi's XListInputDevices() (boo#1281612, CVE-2026-93545) - 0006-boo1281615_CVE-2026-94281_XListInputDevices-validate-class-lengths-cumulativel.patch * Out-of-bounds read in libXi's XListInputDevices() class parsing (boo#1281615, CVE-2026-94281) - 0007-boo1281651_CVE-2026-94282_wireToEnterLeave-validate-buttons_len-against-the-re.patch * Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversio (boo#1281651, CVE-2026-94282) ==== libXpm ==== - 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch * Denial of service via unsigned underflow in libXpm's write path (boo#1281669, CVE-2026-94287) ==== libXtst ==== - 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch * Out-of-bounds read in libXtst's RECORD reply parser (boo#1281665, CVE-2026-94286) ==== libraw ==== - added patches CVE-2026-88387: incorrect numeric conversion in `LibRaw::parse_tiff_ifd()` when processing TIFF tag `0x00fe` can lead to undefined behavior and a process crash when a specially crafted file is processed [bsc#1282783] * libraw-CVE-2026-88387.patch ==== libsecret ==== Version update (0.21.7 -> 0.21.8.2) Subpackages: libsecret-1-0 typelib-1_0-Secret-1 - Update to version 0.21.8.2: + Release to bump meson.build version - Changes from version 0.21.8.1: + Make secret_item_load_secrets_sync match async behavior - Update to version 0.21.8: + Allow the content type to have additional parameters + Support individually encrypted items + Ensure we return chained up GTask + Ensure length of DH shared secret match length of prime on GnuTLS + file-backend: - Add thread safety and file-based locking to prevent concurrent write races - Fix possible memory leak in error path of secret_file_backend_real_search() + file-collection: Fix memory leaks on repeated calls + Replace some SecretSync with a sync implementation + Add linker version script to hide private symbols + Stop using CONST annotations on non-const fns + secret-tool: - Align behavior for collection option - Document --collection option + meson: Put test setup behind a feature option + Several test and CI improvements + Updated translations. ==== libslirp ==== Version update (4.9.3+4 -> 4.9.5+1) - Update to version 4.9.5+1: * note CVE numbers * Release v4.9.5 * Set UDP sockets in blocking mode * dhcpv6: fix bounding the reply against the interface MTU * dhcpv6: bound the reply against the interface MTU * ncsi: bounds-check OEM command bodies before dereferencing them * Release v4.9.4 * ip_input: update hlen on ip_reass * ip6_input: Trim mbuf to ip6-announced length * Fix reporting oob output * Note about the security contact - fixes CVE-2026-95507, CVE-2026-95508 ==== libsodium ==== - Disable upstream SSP handling via --disable-ssp: distro optflags already carry -fstack-protector-strong, and upstream's appended basic -fstack-protector silently downgraded it. ==== libtasn1 ==== - Update Source URLS - guard against future removal of egrep/fgrep ==== libtheora ==== Subpackages: libtheora1 libtheoradec2 libtheoraenc2 - Disable asm on 32-bit arm until next release https://gitlab.xiph.org/xiph/theora/-/work_items/2338 ==== libupnp ==== Version update (22.1.2 -> 22.1.7) Subpackages: libixml22 libupnp22 - Update to release 22.1.7 * Fix a memory leak when a GENA subscription is freed. [GHSA-h9f5-9vwp-h89q] - Update to release 22.1.6 * GHSA-mhhw-gm73-c57g: Fix a heap over-read when parsing the Callback header of an incoming GENA SUBSCRIBE request. [GHSA-mhhw-gm73-c57g] - Update to release 22.1.5 * Fix SID matching for incoming GENA NOTIFY requests. [GHSA-ggw2-jjv9-h22c] - Update to release 22.1.4 * Stopped counting the read-head entity bytes against header sizes. * Sockets are now closed when http_OpenHttpGetEx() gets a bad response. ==== llvm23 ==== Version update (23.1.1 -> 23.1.2) - Update to version 23.1.2. * This release contains bug-fixes for the LLVM 23.1.0 release. This release is API and ABI compatible with 23.1.0. ==== openexr ==== Version update (3.4.14 -> 3.4.15) Subpackages: libIex-3_4-33 libIlmThread-3_4-33 libOpenEXR-3_4-33 libOpenEXRCore-3_4-33 - version update to 3.4.15 * fixes two memory issues when parsing IDManifests - added patches CVE-2026-88384: NULL pointer dereference in the C++ attribute parsing path when a specially crafted EXR file containing an unknown-type attribute with dataSize set to zero is processed [bsc#1282700] * openexr-CVE-2026-88384.patch ==== openssh ==== Subpackages: openssh-clients openssh-common openssh-server - Backport openssh-10.5p1-sync-readpassphrase.patch: sync readpassphrase(3) with OpenBSD libc so that SIG_IGN dispositions are preserved instead of being overridden; fixes ssh-add spinning when started in a background process group with no controlling tty and certain signals ignored (mindrot#3995, upstream commits 58db2ec9cac0 and e3cb2b2278c2). ==== pam ==== Version update (1.7.2+git48 -> 1.7.3) - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== pam-full-src ==== Version update (1.7.2+git48 -> 1.7.3) - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== parted ==== Version update (3.7 -> 3.8) Subpackages: libparted-fs-resize0 libparted2 - switch from ftp to https for sources - updated parted.keyring - update to version 3.8 - update to version 3.7.14: - Fix gnu_read problems with block size > 512b - update to version 3.7.13: - Add support for ExFAT - Fix CVE-2026-89085 and CVE-2026-89088 - Add various checks for increased security ==== polkit-default-privs ==== Version update (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) - Update to version 1550+20260928.d1c0e7e: * profiles: added datarecovery run-ddrescue action (bsc#1280118) ==== python-cryptography ==== Version update (50.0.0 -> 50.0.1) - update to 50.0.1: * Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2. ==== raspberrypi-firmware-dt ==== - Fix regression in SRAM range (bsc#1282097) ==== readline ==== Version update (8.3.3 -> 8.3.6) - Add upstream patches * readline83-004 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * readline83-005 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * readline83-006 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== sdbootutil ==== Version update (1+git20260909.7cfa1f0 -> 1+git20260929.26b6989) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper sdbootutil-tukit - Update to version 1+git20260929.26b6989: * Increase the timeout for the update-prediction service * Keep /.snapshots mounted for the shutdown helper * Serialize the update-predictions service and the shutdown helper * Do not ask to fix ROOTFS when the root is encrypted * Use >&2 instead of /dev/stderr * Revert "Move back from oneshot the update-predictions service" * Move back from oneshot the update-predictions service * Fix SELinux AVC from grep redirector * Use DSP for the LUKS2 swap partition * Add missing tight ESP unit test scenario * Don't count reused kernel when calculating free space - Update to version 1+git20260924.2b7b94e: * Improve detection of encrypted device when RAID is used * Support btrfs RAID1 configurations * Move the service from oneshot to exec to avoid the wait * Drop shift variations already present as a component * Fix Supplement use of 'if' instead of 'and' * Hide the warning for entries that uses @ * Accept _ instead of @ as snapshot prefix for version * Drop chown and set ownership via install * Use bootctl to generate the random seed * Start the validation with the strongest bank * Parse the JSON output of findmnt * Use stdin for qrencode * Fix log file permissions * Improve PCR15 diagnosis in status command * Avoid abrmd TCTI error message * Do not fail if pcrlock lock verb cannot reproduce the event log * The completion subpackage supplements the main one * Detect when grubenv is full * Use systemd-analyze to compare versions in status * Fix bootcounter in GRUB2 EFI variable * Drop lowercase in dd * Fix loader_conf_set for paths ==== selinux-policy ==== Version update (20260923 -> 20260928) Subpackages: selinux-policy-targeted - Update to version 20260928: * Allow sdbootutil_t write access to /var/lib/sdbootutil (bsc#1281087) ==== shadow ==== Version update (4.20.2 -> 4.20.3) Subpackages: libsubid6 login_defs shadow-pw-mgmt - Update to 4.20.3: * Build error when using '--with-nscd=no' (bug introduced in v4.19.0). ==== slang ==== - Drop obsolete -fstack-protector from CFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== sof-firmware ==== Version update (2025.12.2 -> 2026.09.1) - Update to version 2026.09.1: * Changes in 2026.09.1: + SOF v2.15 signed binary added for Intel ARL-S; with this all Intel Meteor Lake and newer platforms are upgraded to SOF v2.15 * Changes in 2026.09: + SOF v2.15 signed binaries, tools and topologies ==== tesseract-ocr ==== Subpackages: libtesseract5 tesseract-ocr-common - Update tesseract-CVE-2026-88053.patch to null the adaptive template pointer arrays again and the class pruners as upstream does, fixing an abort at exit on every run and invalid frees when a corrupt traineddata is rejected (boo#1282863) ==== vlc ==== Version update (3.0.23 -> 3.0.24) Subpackages: libvlc5 libvlccore9 vlc-noX vlc-qt - Update to version 3.0.24: + Codecs: - Use FFmpeg 8.1 (upgraded from 4.4) - Support APV decoder (FFmpeg 8) - Support Atrac3/Atrac9 decoding - Remove schroedinger support for dirac in favor of avcodec - Fix Speex leaks and packetization issues - Fix WebVTT CSS parsing and error handling - Fix FLAC and HEVC packetizer edge cases - Fix AudioToolbox MIDI synthesizer crash on macOS 26+ + Demuxers: - Add support for CEA-708 closed captions in MP4 - Expose ID3v2 metadata in MPEG demuxer - Improve subtitle language detection from filenames and SSA/ASS metadata - Fix several MKV crashes, leaks, hangs and malformed file handling issues - Fix AVI hang with zero-sized strd chunks - Fix MP4, MPEG-TS, Ogg, RealAudio and subtitle demuxing edge cases + Access: - Switch RIST input and output to librist, with main and simple profile support - Add SRT listener mode support - Add SFTP public key authentication options and ED25519 hostkey support - Update SMB2 share enumeration - Don't ship RealRTSP plugin (build disabled for all configurations) + Service Discovery: - Include Chromecast model in mDNS renderer names - Fix IPv6 addresses in Bonjour service URLs + Video Output: - Fix Direct3D11 adjust filter and texture leaks - Fix MediaCodec crop validation - Super Resolution scaling with Moore Threads GPUs + Interface: - Qt: Fix default open dialog location - Qt: Fix effects window geometry saving - Qt: Improve hotkeys dialog strings + Stream Output: - Disable HEVC for original Chromecast devices + Security: - Switch to a new RSA-4096 key for update verification - Fix multiple OOB, integer overflow, double-free and use-after-free issues - See https://www.videolan.org/security/ - CVE-2026-56711: picture: inline AllocatePicture() and use overflow helpers + Misc: - Add Flatpak build support - Fix Audio EQ filter High Frequency parameter - Fix artwork preparser crash when artwork title is null - Fix LibVLC media list player race - Remove NPAPI browser plugin + Lua: - Remove broken youtube.lua plugin - Drop vlc-gstreamer-1.28-build-fix.patch: fixed upstream. ==== wireplumber ==== Subpackages: libwireplumber-0_5-0 - Modify environment file name in patch ==== xdg-dbus-proxy ==== Version update (0.1.8 -> 0.1.9) - Update to version 0.1.9: + Fix message filtering bypass vulnerabilities (CVE-2026-94422, GHSA-2cgv-pwcq-wvpq): - Don't allow method calls and signals to be treated as requested replies, even if they specify a reply serial number - Only allow replies that were sent to the appropriate destination + Improve automated tests to include attempts to exploit CVE-2026-94422