Packages changed: ImageMagick (7.1.2.28 -> 7.1.2.29) MozillaFirefox (153.0.1 -> 153.0.3) SDL3 (3.4.12 -> 3.4.14) breeze6 emacs git kernel-source (7.1.5 -> 7.1.6) libpsl (0.23.0 -> 0.23.1) libssh2_org libvirt (12.5.0 -> 12.6.0) nfs-utils open-isns (0.103+2.296d533bd52a -> 0.103+4.60de8b5) openblas_openmp openblas_pthreads plasma6-integration plasma6-workspace python-pyzmq selinux-policy (20260727 -> 20260804) shadow (4.19.4 -> 4.20.0) swtpm unbound (1.25.2 -> 1.26.0) xen === Details === ==== ImageMagick ==== Version update (7.1.2.28 -> 7.1.2.29) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - version update to 7.1.2.29 * Updated the dependencies. 90f5b91 * add WEBP compress case when writing f35294e * Removed unnecessary include. 1e2f64f * Removed checks for values from tif_config.h that are not included, libtiff will report errors itself now. 7cf1988 * Only set the TIFFTAG_WEBP_LEVEL when the quality is not undefined. 02ac849 * Make sure we read the bits_per_sample before using it. 0af4ede * Added missing typecast. b919b37 ==== MozillaFirefox ==== Version update (153.0.1 -> 153.0.3) Subpackages: MozillaFirefox-branding-upstream MozillaFirefox-translations-common - Mozilla Firefox 153.0.3 https://www.firefox.com/en-US/firefox/153.0.3/releasenotes/ * The smart window suggestion list now shows more results, making it easier to find history and switch to open tabs. (bmo#2019042) * The smart window assistant can now answer questions directly using web search results from Exa, instead of handing off to a search engine. (bmo#2046183, bmo#2044385) * Fixed audio and video failing to play, or hanging when seeking, on websites that load media from a Blob URL. (bmo#2056444) * Fixed the Bookmarks, History, and other sidebars failing to open when the sidebar is hidden and the password manager has been turned off by an enterprise policy. (bmo#2056857) * Fixed a Mozilla VPN upgrade offer appearing for people in regions where Mozilla VPN is not sold. (bmo#2058264) * Fixed frequent Inspector crashes in the Developer Tools on pages where an extension content script had added event listeners. (bmo#2042101) - refresh upstream signing key ==== SDL3 ==== Version update (3.4.12 -> 3.4.14) - Update to release 3.4.14 * GPU buffers and textures can have multiple read usages * Fixed X11 crash if the IME service was shutdown in the background * Fixed hang when hiding an X11 window on some window managers * Fixed Xbox controllers not being detected if SDL is built with GameInput support ==== breeze6 ==== Subpackages: breeze6-cursors breeze6-decoration breeze6-style breeze6-style-lang - Move Qt 5 style into a separate optional package ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Configure wayland the compilation support native with ahead of time (aot) to avoid compiling threads (boo#1271643) ==== git ==== Subpackages: git-core git-email git-gui git-web gitk perl-Git - Remove dependency on update-desktop-files, use translate-suse-desktop (jsc#PED-15206) ==== kernel-source ==== Version update (7.1.5 -> 7.1.6) - Linux 7.1.6 (bsc#1012628). - platform/x86/intel-uncore-freq: Fix current_freq_khz after CPU hotplug (bsc#1012628). - sched_ext: Skip ops.set_weight() for disabled tasks (bsc#1012628). - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (bsc#1012628). - seqlock: Allow UBSAN_ALIGNMENT to fail optimizing (bsc#1012628). - KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1012628). - KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (bsc#1012628). - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1012628). - KVM: x86/mmu: Fix use-after-free on vendor module reload (bsc#1012628). - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (bsc#1012628). - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (bsc#1012628). - xprtrdma: Clear receive-side ownership pointers on release (bsc#1012628). - arm64: tegra: Remove fallback compatible for GPCDMA (bsc#1012628). - Docs/admin-guide/cgroup-v2: fix memory.stat doc details (bsc#1012628). - sched_ext: Annotate ksyncs with __rcu in alloc/free_kick_syncs() (bsc#1012628). - arm64: tegra: Fix CPU compatible string to cortex-a78ae on Tegra234 (bsc#1012628). - xfrm: propagate -EINPROGRESS from validate_xmit_xfrm() (bsc#1012628). - xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1012628). - firmware: arm_ffa: Respect firmware advertised RX/TX buffer size limits (bsc#1012628). - IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1012628). - mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins() (bsc#1012628). - mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy() (bsc#1012628). - mtd: mtdswap: remove debugfs stats file on teardown (bsc#1012628). - mtd: nand: mtk-ecc: stop on ECC idle timeouts (bsc#1012628). - btrfs: reject free space cache with more entries than pages (bsc#1012628). - btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1012628). - btrfs: fallback to transaction csum tree on a commit root csum miss (bsc#1012628). - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (bsc#1012628). - sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() (bsc#1012628). - reset: spacemit: k3: fix USB2 ahb reset (bsc#1012628). - xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1012628). - xfrm: reject optional IPTFS templates in outbound policies (bsc#1012628). - RDMA/cma: Fix hardware address comparison length in netevent callback (bsc#1012628). - RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1012628). - RDMA/irdma: Remove redundant legacy_mode checks (bsc#1012628). - RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1012628). - RDMA/erdma: initialize ret for empty receive WR lists (bsc#1012628). - RDMA/mana_ib: initialize err for empty send WR lists (bsc#1012628). - RDMA/core: Fix memory leak in __ib_create_cq() on invalid cqe (bsc#1012628). - RDMA/hns: Fix potential integer overflow in mhop hem cleanup (bsc#1012628). - RDMA/siw: publish QP after initialization (bsc#1012628). - mtd: fix double free and WARN_ON in add_mtd_device() error paths (bsc#1012628). - selftests/alsa: Fix memory leak in find_controls error path (bsc#1012628). - RDMA/irdma: Prevent overflows in memory contiguity checks (bsc#1012628). - xfrm: clear mode callbacks after failed mode setup (bsc#1012628). - xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() (bsc#1012628). - xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() (bsc#1012628). - xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (bsc#1012628). - wifi: mac80211: allocate backup ieee80211_nan_sched_cfg off stack (bsc#1012628). - ALSA: usb-audio: Fix imbalance per-channel volume of sticky mixers (bsc#1012628). - wifi: cfg80211: cancel sched scan results work on unregister (bsc#1012628). - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (bsc#1012628). - wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() (bsc#1012628). - wifi: mac80211_hwsim: clamp virtio RX length before skb_put ... changelog too long, skipping 1266 lines ... - commit 05b8588 ==== libpsl ==== Version update (0.23.0 -> 0.23.1) - Update to version 0.23.1: * Fix reproducible builds, a regression introduced in 0.23.0 * psl-make-dafsa embeds only the basename of the input file * Allow explicitly disabling fuzzing at configure time ==== libssh2_org ==== - Security fixes: * CVE-2026-58050: Attacker controlled attribute count from a publickey-subsystem response is used without bounds checking and can cause to a heap buffer overflow in a connecting libssh2 client (bsc#1269568) * CVE-2026-58051: Public key list is increased and does not zero-initialized new entries, which can cause an uninitialized pointer to be freed when a malformed response is sent by an SSH server (bsc#1269567) * Add patches - libssh2-CVE-2026-58050.patch - libssh2-CVE-2026-58051.patch - Security fixes: * CVE-2026-66032: Arbitrary code execution via double-free in SFTP session (bsc#1272737) * CVE-2026-66033: Denial of Service via integer underflow in AES-GCM cipher negotiation (bsc#1272736) * CVE-2026-66034: Information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735) * CVE-2026-66035: Arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734) * Add patches: - libssh2-CVE-2026-66032.patch - libssh2-CVE-2026-66033.patch - libssh2-CVE-2026-66034.patch - libssh2-CVE-2026-66035.patch ==== libvirt ==== Version update (12.5.0 -> 12.6.0) Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - virsh: Fix potential NULL pointer dereference crash bsc#1272852 - Update to libvirt 12.6.0 - CVE-2026-15268, CVE-2026-61477, CVE-2026-61478, CVE-2026-63622, CVE-2026-63623 - jsc#PED-14588 - Many incremental improvements and bug fixes, see https://libvirt.org/news.html#v12-6-0-2026-08-03 ==== nfs-utils ==== Subpackages: libnfsidmap1 nfs-client nfs-kernel-server - Require python3-PyYAML on openSUSE and SLE: the python-* symbol is valid in both cases. On openSUSE, this is provided by the module targetting the primary interpreter, which matches the shebang of the python scripts lines being /usr/bin/python3. - nfs-client: make the rpcctl util executable (bsc#1273197) The specfile intentionally clears the execute bit for all python-based utilities during the build, in order to prevent generating a package dependency to the python interpreter. It subsequently restores the execute bit explicitly for every single script. In the case of rpcctl this was overlooked when the utility was introduced, and therefore it was packaged without execute permissions. Fix this by restoring the permissions. - Introduce new sub-package nfs-tools-extra, and move all python-based tools into that (bsc#1268167). The nfs-utils base packages previously suggested python-base as a soft dependency, as some of the less used tools rely on that. Some of those have further specific python dependencies (such as nfsdclnts which needs pyyaml). We do not want to pull in python as a strict requirement to any of the base nfs-utils packages to keep the base as minimal as possible. Thus we introduce a new package (nfs-tools-extra) that includes all those optional python-based tools, and make that package require pyyaml and python transitively. Also, the base packages now suggest nfs-tools-extra, instead of python. - update to 2.9.2: * nfsd: fix memory overflow for haddr * gssd: fix memory leak in gssd_free_client * Pass ignore_hosts to export_create() in export_read() * mountd/exportd: disable netlink when falling back to /proc * nfs.conf: add no-netlink option to exportd and mountd stanzas * nfsstat: display NFSv4 callback operation statistics * libnfsidmap: avoid malloc(0) for empty Local-Realms * exportfs: drop unused is_export parameter from xtab_read() and xtab_write() * support/backend_sqlite.c: fix getrandom() fallback * nfs-iostat: add option to display throughput in MB/s * exportfs: release NFSv4 state when last client is unexported ==== open-isns ==== Version update (0.103+2.296d533bd52a -> 0.103+4.60de8b5) - Update to version 0.103+4.60de8b5: * Fix issue in error path causing double-free. Fixes issue CVE-2026-55995 bsc#1268685 ==== openblas_openmp ==== Subpackages: compatlibopenblas_openmp0 libopenblas_openmp0 - Let the compat package provide libopenblas.so.0 instead of the flavour package: * every flavour carries the SONAME libopenblas.so.0, but the libraries live in the private flavour directory, so the automatic provide advertises a SONAME the dynamic linker cannot resolve * the update-alternatives link that does make it resolvable belongs to the compatlib package, which was only reachable through Supplements, and OBS build roots do not honour Supplements * consumers therefore resolved against the flavour package alone and then failed at load time, for example libarpack2, which broke every gdal-linked package in Application:Geo * filter the generated provide and declare it on the compat package ==== openblas_pthreads ==== Subpackages: compatlibopenblas_pthreads0 libopenblas_pthreads0 - Let the compat package provide libopenblas.so.0 instead of the flavour package: * every flavour carries the SONAME libopenblas.so.0, but the libraries live in the private flavour directory, so the automatic provide advertises a SONAME the dynamic linker cannot resolve * the update-alternatives link that does make it resolvable belongs to the compatlib package, which was only reachable through Supplements, and OBS build roots do not honour Supplements * consumers therefore resolved against the flavour package alone and then failed at load time, for example libarpack2, which broke every gdal-linked package in Application:Geo * filter the generated provide and declare it on the compat package ==== plasma6-integration ==== Subpackages: plasma6-integration-plugin plasma6-integration-plugin-lang - Put Qt 5 integration into a separate optional package ==== plasma6-workspace ==== Subpackages: plasma6-session plasma6-session-x11 plasma6-workspace-lang plasma6-workspace-libs sddm-qt6-branding-openSUSE - sddm.conf: Set plasmawayland.desktop as default session - No longer recommend plasma6-session-x11 ==== python-pyzmq ==== - Pin scikit-build-core's CMake build directory for reproducible builds. Otherwise it uses a random tempdir whose path leaks into the debug info that the linker hashes into the GNU build-id note of the later-stripped _zmq*.so, making the build non-reproducible even though the actual code is identical. ==== selinux-policy ==== Version update (20260727 -> 20260804) Subpackages: selinux-policy-targeted - Update to version 20260804: * Use NetworkManager_t instead of networkmanager_t * Changes adapting to bind packages with suffixes * Dontaudit unconfined_t map its private directories * Support cronie create crontab backups * Allow nfsidmapd read virt lib files * Allow sysadm_t run and read/write networkmanager bpf programs * Allow dhcpc_hook_t connect to init_t over a unix stream socket * Allow unconfined_t mounton its lnk_files * Allow wireguard read cgroup files * Label /usr/local/share/man with man_t * Allow pcscd get attributes of a pty filesystem * Allow geoclue read cgroup files * Allow init_t nnp domain transition to postgresql_t * Move bootupd systemd interface to 2 optional blocks * Allow net_admin to the nfsd_t domain * Allow kernel write to unconfined and sysadm users' keys * Allow staff user ioctl cockpit-session stream sockets * Allow the staff user mount on tmpfs directories * Allow staff user the dac_override capability in the user namespace * Allow aide get attributes of all filesystems * Make insights_client_t accessible from the system cronjob * Support systemtap on a UEFI+SecureBoot system * Allow systemd-coredump signull spc container * Allow dhcpcd hook scripts read generic files in /proc - Syncing with upstream rawhide selinux-policy up to: * 5c9bff8fbdaeb41b724b68937c706dc5e42a490a ==== shadow ==== Version update (4.19.4 -> 4.20.0) Subpackages: login_defs shadow-pw-mgmt - Update to 4.20.0: * Removals: The following programs and features were deprecated in 4.19 or earlier, and have been removed in 4.20. + expiry(1) (deprecated in 4.19). See #1481 and #1432. + login.defs(5): ENCRYPT_METHOD: DES (deprecated in 4.19). See #1456. + login.defs(5): ENCRYPT_METHOD: MD5 (deprecated in 4.19). See #1457. + login.defs(5): MD5_CRPYT_ENAB (deprecated since the dinosaurs were around). See #1455. + shadow(5): .sp_min (deprecated in 4.19). See #1482. This also includes the following removals: - chage(1): -m,--mindays (also the interactive version) - passwd(1): -n,--mindays - login.defs(5): PASS_MIN_DAYS This feature is considered a vulnerability, and was removed without replacement. Programs will now fail when any of those flags or variable are specified. This is intentional, and should help identify any scripts that rely on these. + groupmems(8) (deprecated in 4.19). See #1343 and #1601. Use usermod(8) instead. + logoutd(8) (deprecated in 4.19). See #999 and #1344. * Defaults: The following default values were changed. + login.defs(5): Remove defaults for password expiration (PASS_MAX_DAYS, PASS_WARN_AGE). See #1428. + login.defs(5): ENCRYPT_METHOD: Default to SHA512 (previously, it was DES). See #1278 and #1454. Users should still explicitly specify it, since other programs that read login.defs(5) may still default to DES. * Features: The following features that were optional in 4.19 are now unconditionally supported in 4.20. + SHA256, SHA512 See #1278 and #1452. * Regressions: Some regressions have been introduced (as side effects of bug fixes) and they're here to stay. Users must adapt. + `su - ` as root brings inappropriate ioctl for device #1704 + `usermod --unlock` on an account without valid password will exit with status 20 instead of print a warning #1706 * Dependencies: + We've removed an unused dependency (libattr). See #1473. * Deprecations: No new deprecations since 4.19. However, we maintain the deprecations from then. - Refresh patches: * shadow-login_defs-comments.patch Line offsets and dropping MD5_CRYPT_ENAB. * shadow-login_defs-suse.patch Drop PASS_MAX_DAYS/PASS_MIN_DAYS/PASS_WARN_AGE. We set them to 0 earlier to disable them because PAM handles it. So we have the same effect still. Drop PASS_MAX_LEN since DES support got removed. Drop MD5_CRYPT_ENAB. PASS_CHANGE_TRIES got dropped upstream. * shadow-login_defs-unused-by-pam.patch Drop PASS_MAX_DAYS, PASS_MIN_DAYS, PASS_WARN_AGE, PASS_MAX_LEN, and PASS_MIN_LEN. * shadow-util-linux.patch - Add PASS_ALWAYS_WARN, PASS_CHANGE_TRIES, PASS_MAX_DAYS, PASS_MIN_LEN, PASS_WARN_AGE, OBSCURE_CHECKS_ENAB to false positives in shadow-login_defs-check.sh - Add shadow-4.20-stdint.patch to fix an include ==== swtpm ==== Subpackages: swtpm-selinux - Fix SELinux policy for virtqemud_t swtpm_t setsched process and unix socket interactions. Allows virtqemud_t to: Signal and control swtpm_t processes (noatsecure, rlimitinh, siginh, signull, setsched), create and listen on Unix stream sockets with swtpm_t processes (bsc#1266339). Already accepted on upstream: https://github.com/stefanberger/swtpm/pull/1132 - Add patch: 1132.patch ==== unbound ==== Version update (1.25.2 -> 1.26.0) Subpackages: libunbound8 unbound-anchor - Update to 1.26.0: * Update icannbundle.pem certificates in unbound-anchor, valid for 2009-2029 and 2025-2045 * Add max-transfer-size and max-transfer-time options to limit auth-zone and rpz transfer size and time, default disabled * Overload local_data_remove in unbound-control to also remove specific records * Add local-zone types block_aaaa, block_a_wdata and block_aaaa_wdata; fix respip+dns64 to use original A records instead of ones already modified by respip * ipsecmod hook script now needs to start with '#!/bin/sh', it is executed with execv instead of system for security * Server now continues to start if a secondary zone fails to load from its zonefile, or if a primary zonefile is missing; $INCLUDE is no longer allowed in secondary zone zonefiles * Auth-zone and RPZ zones now drop out-of-zone content on load * Primary hostname for zone transfers can now use CNAME(s) * Fix windows 64bit build for libssp dependency * Update IANA portlist * Fix heap out-of-bounds write via size_t-to-int truncation in setup_if()/outside_network_create() for large num_ports values * Fix to clean up log ids after a failure to start a worker thread * Relax assertions after the TTL 0 handling change in cachedb and packet_rrset_copy_region * Fix val_find_DS to check the result of packet_rrset_copy_region before using it * Fix that dns64 answers check the AAAA query is DNSSEC validated, improving RFC6147 conformance * Fix allocation-failure hardening of rrset cache wildcard storage and canonical NSEC owner replacement * Fix DNSSEC validation and DNSKEY size calculation for noncanonical RSA DNSKEYs with leading zeroes * Fix mixed class referrals to use the query class * Fix serve-expired responses from cachedb to not store bogus data * Fix lame server detection for selfpointed glue records * Fix cleanup of DoH sessions when the same query is on multiple streams * Fix for signed same-owner CNAME and ordinary RRset responses * Fix mesh new client/callback to roll back added address, tcp mesh state and callback on initialization failure * Fix autotrust state-file line overflow that could give a hold-down bypass * Fix to limit the DSNS per-label walk in the iterator * Fix that the ratelimit is decremented on successful referrals * Fix msgencode insert_query assertion for a local_alias * Fix to reset the tcp-timeout before applying a load based reduction * Fix to correctly decrement per-netblock tcp connection limits * Fix, in depth, for respip rewrite of dns64 responses * Fix that dns64 with subnetcache does not write ECS scoped answers to the global cache * Fix ipset module name-too-long checks and race conditions on the local name buffer and socket close * Fix validator to cap the number of ANY RRsets it validates and shorten the wait timer * Fix race condition causing segfault when starting threads * Fix header_seen detection for trust anchor files to detect the id line * Fix heap use-after-free in class response processing when at least two distinct classes are configured * Fix negative cache to work with NSEC3 records without salt * Fix parse of svcbparam ech, it had an incorrect length * Fix that quotation and escaping works the same in auth-zone url content as in zonefile reads * Fix ipset module to use larger domain name buffers and check buffer lengths * Fix PROXYv2 header read and consume to check the header size * Fix negative cache NSEC3 nodata proof to use the correct message size * Fix fast_reload for when a ZONEMD lookup is in progress * Fix that validation canonicalization of domain names in rdata checks buffer bounds * Fix dump_cache to use a larger record buffer and check that an owner name does not collide with BADRR * Fix that dns64 cleans up the allocated message if the adjust routines fail, and checks for malformed A/AAAA in auth-zones * Fix pythonmod script read for numeric overflow * Fix configure to detect the correct QUIC early-data function and to check for the ngtcp2_crypto_ossl header * Fix compile with OpenSSL 4.0.1, and with OpenSSL 1.0.2 and earlier in server cleanup * Fix that auth-zone/rpz allow-notify addresses and netblocks are available from start, and fix the probe step skip * Fix to perform a full transfer periodically to stop increasing memory usage for rpz zones * Fix assertion failure for a long HTTP header that fills the buffer, and buffer overflow with lower than default size and http transfer * Fix that misconfigured iter-scrub-ns: 0 causes request failures * Fix fast_reload handling of in-progress ZONEMD lookups and of removing an auth zone while its lookups are in progress * Fix integer overflow in infra-cache-max-rtt calculation and for very high values of sock-queue-timeout * Fix erroneous DNS error report values after a bogus AAAA query * Fix fast_reload to not terminate the server on config errors for key files * Fix log of an aliased qname to not use freed region memory ... changelog too long, skipping 76 lines ... * pythonmod: check the return value after ftell() ==== xen ==== - Re-enable aarch64 builds