Packages changed: kernel-source (7.1.3 -> 7.1.4) man-pages-ja permissions (1699_20260707 -> 1699_20260715) python313 (3.13.13 -> 3.13.14) python313-core (3.13.13 -> 3.13.14) === Details === ==== kernel-source ==== Version update (7.1.3 -> 7.1.4) - Update patches.kernel.org/7.1.2-002-fuse-re-lock-request-before-replacing-page-cach.patch (bsc#1012628 CVE-2026-53388). - Update patches.kernel.org/7.1.2-005-iio-light-veml6075-add-bounds-check-to-veml6075.patch (bsc#1012628 CVE-2026-53387). - Update patches.kernel.org/7.1.2-006-iio-adc-ti-ads1298-add-bounds-check-to-pga_sett.patch (bsc#1012628 CVE-2026-53386). - Update patches.kernel.org/7.1.2-008-vc_screen-fix-null-ptr-deref-in-vcs_notifier-du.patch (bsc#1012628 CVE-2026-53385). - Update patches.kernel.org/7.1.2-010-serial-8250_dw-unregister-8250-port-if-clk_noti.patch (bsc#1012628 CVE-2026-53384). - Update patches.kernel.org/7.1.2-012-ksmbd-reject-non-VALID-session-in-compound-requ.patch (bsc#1012628 CVE-2026-53383). - Update patches.kernel.org/7.1.2-013-media-vidtv-fix-NULL-pointer-dereference-in-vid.patch (bsc#1012628 CVE-2026-53382). - Update patches.kernel.org/7.1.2-014-virtiofs-fix-UAF-on-submount-umount.patch (bsc#1012628 CVE-2026-53381). - Update patches.kernel.org/7.1.3-001-KVM-x86-Fix-shadow-paging-use-after-free-due-to.patch (bsc#1012628 CVE-2026-53359 bsc#1270059). - Update patches.kernel.org/7.1.3-006-batman-adv-tp_meter-avoid-divide-by-zero-for-de.patch (bsc#1012628 CVE-2026-63836). - Update patches.kernel.org/7.1.3-018-batman-adv-v-prevent-OGM-aggregation-on-disable.patch (bsc#1012628 CVE-2026-63835). - Update patches.kernel.org/7.1.3-019-batman-adv-tp_meter-restrict-number-of-unacked-.patch (bsc#1012628 CVE-2026-63834). - Update patches.kernel.org/7.1.3-028-ipv6-account-for-fraggap-on-the-paged-allocatio.patch (bsc#1012628 CVE-2026-53362 bsc#1269493). - Update patches.kernel.org/7.1.3-029-ipv4-account-for-fraggap-on-the-paged-allocatio.patch (bsc#1012628 CVE-2026-53366 bsc#1271366). - Update patches.kernel.org/7.1.3-030-ntfs3-reject-direct-userspace-writes-to-reserve.patch (bsc#1012628 CVE-2026-63833). - Update patches.kernel.org/7.1.3-031-wifi-mt76-add-wcid-publish-check-in-mt76_sta_ad.patch (bsc#1012628 CVE-2026-63832). - Update patches.kernel.org/7.1.3-032-mac802154-llsec-add-skb_cow_data-before-in-plac.patch (bsc#1012628 CVE-2026-63831). - Update patches.kernel.org/7.1.3-033-net-skmsg-preserve-sg.copy-across-SG-transforms.patch (bsc#1012628 CVE-2026-63830). - Update patches.kernel.org/7.1.3-034-net-ip_gre-require-CAP_NET_ADMIN-in-the-device-.patch (bsc#1012628 CVE-2026-63829). - Update patches.kernel.org/7.1.3-036-apparmor-mediate-the-implicit-connect-of-TCP-fa.patch (bsc#1012628 CVE-2026-63828). - Update patches.kernel.org/7.1.3-037-apparmor-fix-use-after-free-in-rawdata-dedup-lo.patch (bko#221513 bsc#1012628 CVE-2026-63827). - Update patches.kernel.org/7.1.3-039-fbdev-fix-use-after-free-in-store_modes.patch (bsc#1012628 CVE-2026-63826). - Update patches.kernel.org/7.1.3-045-gcov-use-atomic-counter-updates-to-fix-concurre.patch (bsc#1012628 CVE-2026-63825). - Update patches.kernel.org/7.1.3-046-KEYS-fix-overflow-in-keyctl_pkey_params_get_2.patch (bsc#1012628 CVE-2026-63824). - Update patches.kernel.org/7.1.3-047-keys-Pin-request_key_auth-payload-in-instantiat.patch (bsc#1012628 CVE-2026-63823). - Update patches.kernel.org/7.1.3-052-wifi-ath11k-fix-warning-when-unbinding.patch (bsc#1012628 CVE-2026-63822). - Update patches.kernel.org/7.1.3-056-wifi-rtw88-usb-fix-memory-leaks-on-USB-write-fa.patch (bsc#1012628 CVE-2026-63821). - Update patches.kernel.org/7.1.3-060-f2fs-fix-missing-read-bio-submission-on-large-f.patch (bsc#1012628 CVE-2026-63820). - Update patches.kernel.org/7.1.3-063-f2fs-fix-to-do-sanity-check-on-f2fs_get_node_fo.patch (bsc#1012628 CVE-2026-63819). - Update patches.kernel.org/7.1.3-064-f2fs-validate-orphan-inode-entry-count.patch (bsc#1012628 CVE-2026-63818). - Update patches.kernel.org/7.1.3-065-f2fs-validate-compress-cache-inode-only-when-en.patch (bsc#1012628 CVE-2026-63817). - Update patches.kernel.org/7.1.3-066-f2fs-atomic-fix-UAF-issue-on-f2fs_inode_info.at.patch (bsc#1012628 CVE-2026-63816). - Update patches.kernel.org/7.1.3-068-f2fs-bound-i_inline_xattr_size-for-non-inline-x.patch (bsc#1012628 CVE-2026-63815). ... changelog too long, skipping 1114 lines ... - commit 342bd0e ==== man-pages-ja ==== - Use correct spdx reference for BSD-4-Clause - Add most representeed missing licenses to the main license tag found during legaldb review. ==== permissions ==== Version update (1699_20260707 -> 1699_20260715) Subpackages: permctl permissions-config - Update to version 1699_20260715: * profiles: add cap_net_raw for ttl (bsc#1270714) ==== python313 ==== Version update (3.13.13 -> 3.13.14) Subpackages: python313-curses python313-dbm python313-tk python313-x86-64-v3 - CVE-2026-11940: fix the symlink escape via tarfile hardlink-extraction fallback (bsc#1268977) CVE-2026-11940-tarfile-escape.patch - CVE-2025-15367: reject control characters in POP3 commands (bsc#1257041) CVE-2025-15366-pop3-ctrl-chars.patch - CVE-2025-15366: reject control characters in IMAP commands (bsc#1257044, gh#python/cpython!143922) CVE-2025-15366-imap-ctrl-chars.patch - Update to 3.13.14: - Security - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. - gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328) - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter. - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) - Core and Builtins - gh-151112: Fix a crash in the compiler that could occur when running out of memory. - gh-151126: Fix a crash, when there’s no memory left on a device, which happened in: - code compilation - _winapi.CreateProcess() - Now these places raise proper MemoryError errors. - gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. - gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. - gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. ... changelog too long, skipping 232 lines ... - CVE-2026-6100-use-after-free-decompression.patch ==== python313-core ==== Version update (3.13.13 -> 3.13.14) Subpackages: libpython3_13-1_0 libpython3_13-1_0-x86-64-v3 python313-base python313-base-x86-64-v3 python313-devel - CVE-2026-11940: fix the symlink escape via tarfile hardlink-extraction fallback (bsc#1268977) CVE-2026-11940-tarfile-escape.patch - CVE-2025-15367: reject control characters in POP3 commands (bsc#1257041) CVE-2025-15366-pop3-ctrl-chars.patch - CVE-2025-15366: reject control characters in IMAP commands (bsc#1257044, gh#python/cpython!143922) CVE-2025-15366-imap-ctrl-chars.patch - Update to 3.13.14: - Security - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. - gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328) - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter. - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) - Core and Builtins - gh-151112: Fix a crash in the compiler that could occur when running out of memory. - gh-151126: Fix a crash, when there’s no memory left on a device, which happened in: - code compilation - _winapi.CreateProcess() - Now these places raise proper MemoryError errors. - gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. - gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. - gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. ... changelog too long, skipping 232 lines ... - CVE-2026-6100-use-after-free-decompression.patch