Packages changed: grub2 gstreamer (1.28.5 -> 1.28.6) gstreamer-devtools (1.28.5 -> 1.28.6) gstreamer-plugins-bad (1.28.5 -> 1.28.6) gstreamer-plugins-base (1.28.5 -> 1.28.6) gstreamer-plugins-good (1.28.5 -> 1.28.6) gstreamer-plugins-libav (1.28.5 -> 1.28.6) gstreamer-plugins-rs (1.28.5 -> 1.28.6) gstreamer-plugins-ugly (1.28.5 -> 1.28.6) libXfont2 openSUSE-release (20260805 -> 20260806) python-anyio (4.13.0 -> 4.14.2) python-charset-normalizer (3.4.7 -> 3.4.9) python-cryptography (49.0.0 -> 50.0.0) python-numpy python-pyOpenSSL (26.3.0 -> 26.4.0) socat usbredir (0.14.0 -> 0.15.0) === Details === ==== grub2 ==== Subpackages: grub2-common grub2-i386-pc grub2-snapper-plugin grub2-systemd-sleep-plugin grub2-x86_64-efi grub2-x86_64-efi-bls - Fix crash in booting kernel on some AMD systems (bsc#1271980) * 0001-linux-allocate-EFI-kernel-buffer-as-GRUB_EFI_LOADER_.patch ==== gstreamer ==== Version update (1.28.5 -> 1.28.6) Subpackages: gstreamer-lang gstreamer-utils libgstreamer-1_0-0 typelib-1_0-Gst-1_0 - Update to version 1.28.6: + Highlighted bugfixes in 1.28.6 - Various security fixes and playback fixes - playbin3, playbin: fix stalls after re-enabling previously disabled subtitles - Fix regression in core if a pad is re-linked while changed sticky events are being pushed - dtls/webrtc: fix some issues with OpenSSL 4.0.0 - RTP retransmission bitrate estimation fixes - Fix RTP depayloading of SMPTE ST291 frames with multiple ANC packets - Add H.266 muxing support to the Rust (f)mp4 muxers - Better handling of input buffers without timestamps in Rust (f)mp4 muxers - webrtcsink H.264 level/profile negotiation fixes and support for nvv4l2h265enc encoder - SMPTE ST2038 ancillary metadata and closed caption combiner improvements - Fix SEI insertion into H.265/HEVC streams with alpha - Windows D3D11 WinRT screen capture element fixes - Improved coded buffer size handling for VA encoders - Textaccumulate: various tweaks how the element outputs text, plus better handling of French punctuation - hlssink3: improved handling of input buffers without timestamps - Fix build against FFmpeg 9.0 - cerbero: fix Windows packages binary size increase regression; upgrade libsrt recipe to 1.5.6 - Various bug fixes, build fixes, memory leak fixes, and other stability and reliability improvements + gstreamer: - baseparse: Don't reset infer_ts/pts_interpolate subclass configuration in reset() and related fixes - cpuid: fix AArch64 NEON detection to check HWCAP_ASIMD, not HWCAP_NEON - pad: fix livelock when pushing changed sticky events when the pad is re-linked - valve: Don't send a reconfigure even when setting the drop property to the same value - meson: Make the g-ir-scanner init section consistent across modules - meson: use dependency('dl') instead of cc.find_library('dl') ==== gstreamer-devtools ==== Version update (1.28.5 -> 1.28.6) - Update to version 1.28.6: + meson: Make the g-ir-scanner init section consistent across modules and fix validate g-ir-scanner invocation so that it doesn't load any plugins + meson: use dependency('dl') instead of cc.find_library('dl') + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-bad ==== Version update (1.28.5 -> 1.28.6) Subpackages: gstreamer-plugins-bad-lang libgstadaptivedemux-1_0-0 libgstanalytics-1_0-0 libgstbadaudio-1_0-0 libgstbasecamerabinsrc-1_0-0 libgstcodecparsers-1_0-0 libgstcodecs-1_0-0 libgstcuda-1_0-0 libgsthip-1_0-0 libgstinsertbin-1_0-0 libgstisoff-1_0-0 libgstmpegts-1_0-0 libgstmse-1_0-0 libgstphotography-1_0-0 libgstplay-1_0-0 libgstsctp-1_0-0 libgsturidownloader-1_0-0 libgstva-1_0-0 libgstvulkan-1_0-0 libgstwayland-1_0-0 libgstwebrtc-1_0-0 libgstwebrtcnice-1_0-0 - Update to version 1.28.6: + adpcmdec: Fix IMA ADPCM input size check to match with the actual code + baseparse: Don't reset infer_ts/pts_interpolate subclass configuration in reset() and related fixes + d3d11winrtcapture: Fix incorrect capture height + dtls: make BIO read signal retry instead of EOF when no data + dtls: New DTLS test failure with OpenSSL 4.0.0 + dvdspu: Fix too strict off-by-one bounds check in a couple of places + h263parse: diracparse: Sync baseparse configuration with other compressed video parsers + h265parser: Fix out-of-bounds writes in RPS parsing + h265seiinserter: Fix HEVC with alpha stream handling + h266parser: fix SEI parsing error handler + meson: Make the g-ir-scanner init section consistent across modules + mpegpsdemux: Use byte readers for parsing data and make sure enough data is available + openjpegdec: Various issues related to striped mode and image origins, plus memory leaks + pnmdec: Don't assert if creating the output state fails and don't flush more data than is available + tfliteinference: fix leaks + tsdemux: Don't assert if stream pad was not yet created + vabaseenc: clamp driver-reported coded size to the coded buffer size + vtdec: Don't register the hw-only variant on simulators + vulkantrash: avoid reinitializing trash objects multiple times + waylandsink: Omit reporting drop frame on preroll + webrtcbin: fix possible floating leak for post-aux + wlvideobufferpool: Fix memory leak in gst_wl_video_buffer_pool_alloc_buffer + docs: Fix build when mse library is disabled + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-base ==== Version update (1.28.5 -> 1.28.6) Subpackages: gstreamer-plugins-base-lang libgstallocators-1_0-0 libgstapp-1_0-0 libgstaudio-1_0-0 libgstfft-1_0-0 libgstgl-1_0-0 libgstpbutils-1_0-0 libgstriff-1_0-0 libgstrtp-1_0-0 libgstrtsp-1_0-0 libgstsdp-1_0-0 libgsttag-1_0-0 libgstvideo-1_0-0 typelib-1_0-GstAudio-1_0 typelib-1_0-GstPbutils-1_0 typelib-1_0-GstTag-1_0 typelib-1_0-GstVideo-1_0 - Update to version 1.28.6: + gl/eagl: Fix GstGLUIView leak from duplicate __bridge_retained + playsink: don't wait for text pad block during reconfiguration + typefind: Actually register various forgotten typefinders + meson: Make the g-ir-scanner init section consistent across modules + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-good ==== Version update (1.28.5 -> 1.28.6) Subpackages: gstreamer-plugins-good-gtk gstreamer-plugins-good-lang - Update to version 1.28.6: + aacparse: Don't assert on parsing errors or insufficient data + avidemux: Make sure enough data is available when parsing FUJIFILM strd and various other fixes + matroskademux: Make sure enough data is available when parsing FLAC headers + rtph264depay: rtph265depay: Limit the maximum fragmentation unit size + rtpqcelpdepay: Handle changes in interleave value correctly + rtpsource: fix bitrate estimation for RTX + v4l2: Use MPLANE flag to determine n_v4l_planes directly + y4mdec: Some parsing fixes + tests: qtmux: drain to EOS before teardown in test_caps_renego + Remove incorrect G_GNUC_CONST annotation for _get_type() functions and some other functions ==== gstreamer-plugins-libav ==== Version update (1.28.5 -> 1.28.6) - Update to version 1.28.6: + Fix build failure with FFmpeg 9.0 + libav: FFmpeg 9.0 Build Failure + avdemux: Close demuxer on pad deactivation instead of state change and don't use uninitialized audio channel positions + avdemux: Use a dynamic-sized array for the AVStreams ==== gstreamer-plugins-rs ==== Version update (1.28.5 -> 1.28.6) - Update to version 1.28.6: + hlsbasesink: Don't unwrap() running_time when a segment is added + hlssink3: don't unwrap() PTS of a fragment's first buffer + isobmff: Add support for video/x-h266 + isofmp4mux: use previous highest PTS when none are available + rtp: fix overflowing adds + rtpsmpte291depay: Fix depayloading frames with multiple ANC packets + rtprecv: fix deadlock handling RTCP packet in buffer list + st2038combiner: Fix off-by-one when ST-2038 pads are skewed + textaccumulate: output joined single buffer, add list as meta + webrtc: add support for nvv4l2h265enc + webrtcsink: handle level-asymmetry-allowed when answering + meson: Work around openssl-sys detection bug on Windows + meson: Sort entries for deterministic build results + Clippy and cargo test fixes + Fix some hotdoc markdown code blocks in various docs ==== gstreamer-plugins-ugly ==== Version update (1.28.5 -> 1.28.6) Subpackages: gstreamer-plugins-ugly-lang - Update to version 1.28.6: + asfdemux: Avoid integer overflows during bounds checks + dvdsubdec: Clip subpicture rectangle to the frame size + rtpasfdepay: Drop packets that are larger than the negotiated maximum packet size and various other fixes ==== libXfont2 ==== - bsc1272660_CVE-2026-59679_0001-fserve-validate-num_chars-against-encoding-array-siz.patch * libXfont2 fs_read_glyphs() heap OOB read/write via encoding array index mismatch (CVE-2026-59679, bsc#1272660) - bsc1272661_CVE-2026-44950-0002-fserve-bounds-check-cumulative-glyph-data-writes-in-.patch * libXfont2 fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow (CVE-2026-44950, bsc#1272661) ==== openSUSE-release ==== Version update (20260805 -> 20260806) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== python-anyio ==== Version update (4.13.0 -> 4.14.2) - Instead of using sed make a proper patch extend_timeouts.patch to increase timeout in test_pytest_plugin module - Add robust_test_shielded_cancel_sleep_time.patch making that test more robust (gh#agronholm/anyio!1264). - Add fix-uvloop-closed-loop-race.patch to protect against a race condition in the test_cancel_worker_thread test (gh#agronholm/anyio!1266). - Update to 4.14.2: - Changed ByteReceiveStream.receive() implementations to raise a ValueError when max_bytes is not a positive integer - Fixed CapacityLimiter.total_tokens rejecting float("inf") when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (value is math.inf), so only the exact math.inf singleton was accepted, while every backend setter (using math.isinf()) accepts any positive infinity - Fixed to_process.run_sync() deadlocking when the worker function writes enough data to sys.stderr to fill the (undrained) pipe buffer. The worker process now redirects sys.stderr to os.devnull as well, matching the documented behavior - Fixed TLSStream.wrap() matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate - Fixed anyio.open_process() (and run_process()) ignoring the extra_groups argument, as it mistakenly passed the value of the group argument instead - Fixed CapacityLimiter.acquire_nowait() and CapacityLimiter.acquire_nowait_on_behalf_of() raising trio.WouldBlock instead of anyio.WouldBlock on the trio backend when there are no tokens available - Fixed CapacityLimiter on the asyncio backend over-granting tokens (borrowed_tokens exceeding total_tokens and available_tokens going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises WouldBlock - Fixed unnecessary CPU spin when delivering cancellation from CancelScope on asyncio under certain conditions, including improper cancel scope nesting - Update to 4.14.1: - Fixed teardown of higher-scoped async fixtures failing on asyncio with RuntimeError: Attempted to exit cancel scope in a different task than it was entered in when an async test raise an outcome exception (e.g., pytest.skip(), pytest.xfail(), or pytest.fail()) - Fixed CapacityLimiter.total_tokens rejecting a value of 0 when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens - Update to 4.14.0: - Added support for Python 3.15 - Added an asynchronous implementation of the itertools module - Added the local_port parameter to connect_tcp() to allow binding to a specific local port before connecting - Added support for custom capacity limiters in async path and file I/O functions and classes - Added the create_task() task group method for easier asyncio migration (returns a TaskHandle) - Changed TaskGroup.start_soon() to return a TaskHandle - Added an option for TaskGroup.start() to return a TaskHandle - Added the cancel() convenience method to TaskGroup as a shortcut for cancelling the task group's cancel scope - Improved the error message when a known backend is not installed to suggest the install command - Improved anyio.Path to preserve subclass types by returning Self in methods that return path objects - Changed the parameter type annotation in anyio.Path.write_bytes() to accept any ReadableBuffer, thus allowing it to accept bytearray and memoryview to match pathlib.Path.write_bytes() - Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables: TaskGroup.start_soon() TaskGroup.start() anyio.from_thread.run() - This reverts an earlier change from v3.7.0 which was made in error. - Changed anyio.run to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio - Changed several classes (and their subclasses) to have __slots__ (with __weakref__): anyio.CancelScope anyio.CapacityLimiter anyio.Condition anyio.Event anyio.Lock anyio.ResourceGuard anyio.Semaphore - Fixed cancellation exception escaping a cancel scope when triggered via check_cancelled() in a worker thread - Fixed TaskGroup raising AttributeError instead of a clear ... changelog too long, skipping 24 lines ... cancelled waiters left queued during release ==== python-charset-normalizer ==== Version update (3.4.7 -> 3.4.9) - update to 3.4.9: * Regression in our fallback path leading to a decode error. * We've yanked 3.4.8 as a result of that bug. * Wall import time due to cascade codec imports for our multibyte first sort of iana supported codecs * Unnecessary json import at runtime * Inverse capitalization not seen by noise detector * No longer holding a global cache for our noise / coherence measurements. Relax RSS memory usage. * Micro-optimizations in our noise / coherence measurements. * No longer using regex search by default for our preemptive charset mark algorithm. * Raised upperbound of setuptools to v83. * Raised upperbound of mypy(c) to v2.1. ==== python-cryptography ==== Version update (49.0.0 -> 50.0.0) - update to 50.0.0 (bsc#1273551, CVE-2026-69247): * SECURITY ISSUE: :func:`~cryptography.hazmat.primitives.serial ization.pkcs7.pkcs7_decrypt_der` and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in RFC 3218. Credit to @X1AOxiang for reporting the issue * Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm. * Added xof() class methods to :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing algorithm instances configured for use with :class:`~cryptography.hazmat.primitives.hashes.XOFHash`. * The :mod:`X.509 verification ` APIs are now considered stable and are subject to our API stability policy. * Added the :doc:`/cobblestone` recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages. * Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them. * Added support for using :class:`~cryptography.x509.Name` as a field type in the :doc:`/hazmat/asn1/index` module. * Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it. * Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field. * :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading certificates, CSRs and CRLs. * :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported when building against AWS-LC. * HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC. * Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported when building against AWS-LC. * :func:`~cryptography.hazmat.primitives.serialization.load_der _public_key` and :func:`~cryptography.hazmat.primitives.seria lization.load_pem_public_key` now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits, matching the minimum already enforced when loading DH private keys and when constructing :class:`~cryptography.hazmat.primitives.asy mmetric.dh.DHParameterNumbers`. * Added :class:`~cryptography.hazmat.primitives.asymmetric.mlds a.MLDSAMuHasher` for incrementally computing the ML-DSA mu (message representative) used by the external-mu signing and verification APIs. * The builtin :class:`~cryptography.hazmat.primitives.hashes.HashAlgorithm` classes and the classes in :mod:`~cryptography.hazmat.primitives.asymmetric.padding` can now be compared with ==. * :class:`~cryptography.x509.CertificateBuilder` now supports creating unsigned certificates (RFC 9925) with the create_unsigned method. * The :mod:`X.509 verification ` APIs now permit ML-DSA-44, ML-DSA-65, and ML-DSA-87 (RFC 9881) public keys and signatures by default. ==== python-numpy ==== - Skip a test to unblock Python 3.15 until new upstream release. ==== python-pyOpenSSL ==== Version update (26.3.0 -> 26.4.0) - Update to 26.4.0: * Maximum supported cryptography version is now 50.x. ==== socat ==== - Use %{arm} instead of armv6l/armv6hl to include armv7 as well ==== usbredir ==== Version update (0.14.0 -> 0.15.0) Subpackages: libusbredirhost1 libusbredirparser1 - Update to version 0.15.0: * Fix server crash on second incoming connection (closes #38). * usbredirtestclient: fix memory leak. * Fix -Wincompatible-pointer-types on mingw32. - Clean up spec file using spec-cleaner: * Prune over-expanded pkgconfig GLib requirements. * Use %?ext_man macro for manpage compression. - Enable test suite run during build in %check.