Packages changed: bash-completion (2.17.0 -> 2.18.0) binutils (2.45 -> 2.47) cups freerdp (3.31.1 -> 3.32.1) fribidi (1.0.16 -> 1.0.17) hwinfo (25.5 -> 26.0) kernel-firmware-amdgpu (20260829 -> 20260926) kernel-firmware-ath10k (20260809 -> 20260926) kernel-firmware-ath11k (20260610 -> 20260926) kernel-firmware-ath12k (20260813 -> 20260926) kernel-firmware-bluetooth (20260828 -> 20260929) kernel-firmware-brcm (20260610 -> 20260915) kernel-firmware-intel (20260728 -> 20260916) kernel-firmware-iwlwifi (20260820 -> 20260926) kernel-firmware-media (20260813 -> 20260926) kernel-firmware-mediatek kernel-firmware-mwifiex (20260610 -> 20260926) kernel-firmware-network kernel-firmware-platform kernel-firmware-qcom (20260828 -> 20260929) kernel-firmware-qlogic kernel-firmware-realtek (20260731 -> 20260915) kernel-firmware-sound (20260825 -> 20260926) libraw libsodium libtheora libupnp (22.1.5 -> 22.1.7) mozjs140 (140.16.0 -> 140.17.0) nbd openSUSE-release (20260929 -> 20260930) openexr (3.4.14 -> 3.4.15) openssh python-jmespath python-msgpack (1.2.1 -> 1.2.2) sdbootutil (1+git20260909.7cfa1f0 -> 1+git20260929.26b6989) selinux-policy (20260923 -> 20260928) slang tesseract-ocr vsftpd wireplumber yast2-auth-client (5.0.4 -> 5.0.5) === Details === ==== bash-completion ==== Version update (2.17.0 -> 2.18.0) - Update to 2.18.0: This release comes with notable changes to the directories used for looking up and sourcing completion recipes and helpers, allowing for more flexibility and customization and fewer conflicts between things shipping with bash-completion and third party/upstream/origin packages. Files that come with bash-completion itself are located in directories reserved for that use, their names ending with -core and -fallback. Packages should continue install their files in the same completions and helpers dirs like before; these directories precede the bash-completion "core" ones in lookup order. A new concept of startup dirs has been introduced. Files from these directories are sourced eagerly on bash-completion startup. This replaces and allows for more flexibility than using the deprecated /etc/bash_completion.d directory for this purpose. * Features _comp__init: source system startup files earlier (b09700d) _comp_compgen_filedir: automatically add -f on _comp_compgen -C or -P (#1552) (6d5fca6) _comp_compgen_filedir: support "filedir -X" (ce28419) _comp_compgen_sysv_services: factorize SysV service generation (c4c8c4b) aclocal,automake: support versioned 1.17 executables (94bbb3a) aclocal,automake: support versioned 1.18 executables (9287b4b) apt-*: update known options up to apt 3.2.0 (c421d50) apt-cache: update known options up to apt 3.2.0 (0ab85c5) apt-get: update known options up to apt 3.2.0 (6a18e0c) apt-mark: update known options up to apt 3.2.0 (644a026) codex: 3rd party fallback completion loader (0f425bd) copilot: 3rd party fallback completion loader (744602a) curlie: alias to curl (dd8f6e0) curl: more option argument (non-)completions (5099cef) dive: add 3rd party fallback completion loader (f817cca) doas: add new completion (f047b70) doas: generate completions as if we're root (a705713) encore: 3rd party fallback completion loader (1e54d02) etcdctl,etcdutl: 3rd party fallback completion loaders (39f8ddf) helium: alias to chromium-browser (8600af0) inotifywait2: generate exclude filenames prefixed by @ (c1e2f1b) inotifywait: generate exclude filenames prefixed by @ (0a2c165) ip: Check /usr/share config path (45530b0) jq: --rawfile arg (non-)completion (4f454d8) jreleaser: add 3rd party fallback completion loader (e1c2815) mago: add 3rd party fallback completion loader (97c4c49) ogg123: associate opus extension (7d3ea33) opencode: add 3rd party fallback completion loader (dbcea18) pnpm: add 3rd party fallback completion loader (44804ae) pydoc: support versioned 3.13..15 executables (bd60b26) python,pyvenv: support versioned 3.14 and .15 executables (72a2e47) release-plz: add 3rd party fallback completion loader (c3c4066) rumdl: add 3rd party fallback completion loader (5ef9790) skupper: add 3rd-party fallback completion loader (4237c9c) ssh-keygen: -M arg completion (b13bf99) ssh-keygen: -Z argument completion (c763d52) ssh-keygen: update -t arg completions (4269a90) ssh-keygen: update -Y arg completions (a73bcaf) ssh: do not complete -P arg (tag) (7d26a86) ssh: include proxy in -O arg completions (fc1df1f) ssh: more option arg (non-)completions (33f789c) sudo-rs,sudo.ws: alias to sudo (084cc68) sudo: more option argument (non-)completions (216135e) support the "startup{,-core}" directory (d6169af) syncthing: add 3rd party fallback completion loader (bc5dfff) tmux: complete src/target session arguments (18b6da4) tmux: complete target-session arguments (ced59c3) ty: add 3rd party fallback completion loader (57a2b31) waydroid: add 3rd party fallback completion loader (acc800f) xrdb: misc improvements (#1669) (461f90c) zed: 3rd party fallback completion loader (83532fa) * Bug Fixes _comp_compgen_services: fix no completions without sysvdir (a2e2659) _comp_compgen_services: skip service status marks (1ac9169) _comp_compgen_sysv_services: do not generate names in subdirs (5557fbe) _comp_compgen: clear the variable when no completions are generated (c07bd66) _comp_complete_service: fix init-script-action parsing (#1499) (91e075a) _comp_complete_user_at_host: care about $cur starting with "-" (277da58) _comp_load: deprecate unsuffixed "completions/" w/o ".bash" (06910da) _comp_load: drop support for "_" (f245356) _known_hosts: fix spacing of an error message (0463570) _known_hosts: work around custom IFS (8171929) _variable_assignments: exclude invalid timezones for "TZ" (d405a1d) add compatibility wrapper for tail (f6fee8a) alternatives: work around localvar_inherit (360192a) apt-get,ebtables,iptables,mplayer,service: avoid | and | in sed (ed64c30) apt-get,gpg{,2},ipmitool,screen: avoid \t, \r, \w in POSIX sed (da40e7a) ccache: fix a wrong AWK condition (c300c0f) cd: Complete from . on empty CDPATH entry (#1527) (6f1eba6) cd: fix cdable_vars overwritten by another generator (24bd420) cd: work around bash-4.2 nounset (45d1c93) compatdir: shadow compat files of the same name (ff1bf72) completion load precedence more (0a15408) export: complete options not at $1 (832822d) export: suffix "=" only when unique and already complete (76f980c) export: work around custom IFS (2617d26) fbgs,fbi: add mandatory semicolons before "}" in POSIX sed (288e77e) fix non-POSIX sed expressions (e999091) gnokii: use double \ in [...] for POSIX.1-2024 recommendation (ab0483a) inotifywait: add -t in noargopts (0295129) interdiff: move to fallback for the upstream completion (11987a4) invoke-rc.d: avoid using non-POSIX | in sed (db928dd) invoke-rc.d: fix a bug of generating existing words (dfb903b) ... changelog too long, skipping 57 lines ... fails duwe e.g. missing network ==== binutils ==== Version update (2.45 -> 2.47) Subpackages: libctf-nobfd0 libctf0 - Update to 2.47: * New major version for libsframe.so.3 (SFrame V3 format, the V2 format is discontinued, added V3 support in gas and ld) * SFrame V3 support in objdump and readelf * add --got-contents to readelf * deprecate s390-* targets (the 31bit ones) * objdump: aarch64 disassember got "-M annotate" displaying a symbol associated with an undefined instruction, if there is one * objdump: x86(-64) disasm got "-M annotate-immediates" displaying a symbol associated with an immediate, if there is one * add --debug-dir= to readelf and objdump, for separate debuginfo files * removed targets: NaCL, Solaris/PowerPC * assembler: - ELF: new attribute letter 'E', for entity size for arbitrary sections - add --reloc-section-sym=[all|internal|none] to control adjusting local binding symbol relocs to section symbols - x86-64: add AMD Zen6 support - risc-v: add extensions sdtrig v1.0, ssstrict v1.0, smpmpmt v1.0, zv*dota* and vendor extensions xsmtvdot v1.0, xsmtvdotii v1.0 - arm: add remaining Armv9.6 insns ('+sme-mop4', '+sme-tmop', '+ssve-bitperm' and '+ssve-fexpa'); several Armv9.7 extensions ('+f16f32dot', '+f16f32mm', '+f16mm', '+gcie', '+lscp', '+mtetc', '+sme2p3', '+sve-b16mm', '+sve2p3' and '+tlbid') and future extensions POE2 and vMTE ('+poe2', '+tev' and '+mops-go'); remove TME extensions (gas will warn on use) - deprecated .vtable_entry and .vtable_inherit directives * linker: - x86(-64): Add --(no-)gnu-tls-tag and --(no-)gnu2-tls-tag options to add a GLIBC_ABI_GNU_TLS/GLIBC_ABI_GNU2_TLS dependency to the output when an input file uses ___tls_get_addr or R_386_TLS_DESC_CALL or R_X86_64_TLSDESC_CALL relocs - add --discard-sframe (omitting any .sframe sections in the output, also inhibiting synthesizing sframe data for linker generated code like the PLT) - add optimization level zero (-O 0) disabling section merging - add --start-lib/--end-lib and LIB linker script statement, treating a list of object files as members of an artificial archive - add support for archives without index on all targets, not just XCOFF - Contains fixes for these non-CVEs (not security bugs per upstreams SECURITY.md): * bsc#1252237 aka CVE-2025-11839 aka PR33448 * bsc#1252238 aka CVE-2025-11840 aka PR33455 * bsc#1254442 aka CVE-2025-11082 aka PR33464 * bsc#1259077 aka CVE-2026-3441 no PR * bsc#1259078 aka CVE-2026-3442 no PR * bsc#1259322 aka CVE-2025-69644 aka PR33639 * bsc#1259323 aka CVE-2025-69645 aka PR33637 * bsc#1259324 aka CVE-2025-69646 aka PR33638 * bsc#1259394 aka CVE-2025-69649 aka PR33697 * bsc#1259397 aka CVE-2025-69652 aka PR33701 * bsc#1259421 aka CVE-2025-69647 aka PR33640 * bsc#1259422 aka CVE-2025-69648 aka PR33641 * bsc#1260338 aka CVE-2026-4647 aka PR33919 * bsc#1262564 aka CVE-2026-6846 aka PR34049 * bsc#1274433 aka CVE-2026-18220 no PR * bsc#1282138 aka CVE-2026-15003 aka PR34053 - Add binutils-2.47.tar.bz2.sig, binutils-2.47.tar.bz2, binutils-2.47-branch.diff.gz - Remove binutils-2.45.tar.bz2.sig, binutils-2.45.tar.bz2, binutils-2.45-branch.diff.gz - Remove upstreamed patches: pr32556.diff, pr33450.diff, pr33452.diff, pr33456.diff, pr33456-2.diff, pr33457.diff, pr33499.diff, pr33502.diff, pr33427-fix-loongarch64-glibc-build-with-gcc16.patch, binutils-fix-c23.diff . - Adjust binutils-build-as-needed.diff, binutils-disable-code-arch-error.diff, binutils-fix-abierrormsg.diff, binutils-fix-invalid-op-errata.diff, binutils-fix-relax.diff, binutils-workaround-premature-libsframe-uninst.diff, binutils-znow.patch, s390-pic-dso.diff, x86-64-biarch.patch, binutils-compat-old-behaviour.diff, binutils-revert-plt32-in-branches.diff, binutils-revert-rela.diff, cross-avr-nesc-as.patch . - Limit internal static linking of libsframe to very old (SLE-12-*) codestreams. - Don't use libalternatives on SLE16. [bsc#1269059] ==== cups ==== Subpackages: cups-client cups-config libcups2 libcupsimage2 - Drop obsolete -fstack-protector from CFLAGS/CXXFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== freerdp ==== Version update (3.31.1 -> 3.32.1) Subpackages: libfreerdp3-3 librdtk0-0 libwinpr3-3 - Update to version 3.32.1: + Regression and bugfix release. After the latest hardening a few corner cases were not covered by regression tests and needed adjustment. Most notably fragmented static channel PDU were rejected breaking copy & paste for larger data. - AAudio backend for android - iOS client updates + CVE: - GHSA-9qqc-m43j-g4r2 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3m9q-g533-rqjq - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-262p-h989-vmpv - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5xjc-c64q-m8r6 - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f3vg-h45x-6wgf - https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c49c-xm94-5qf3 - Update to version 3.32.0: + Thanks to all the people doing in depth code reviews and security reports.: - [proxy] add configuration options for /sec:ext or PROTOCOL_HYBRID_EX - [proxy] add configuration options for target certificate policy. NOTE: This changes default behavior from accept unless denied to deny unless accepted! Requires an update of your proxy configuration file if you rely on this. - [SDL,xfreerdp] seamless Entra/Azure integration on linux (with helper binaries) - [beta] Basic SDL client RAILS support for X11/wayland (other platforms currently lack some features / platform integration code, as we still need some native hooks) - [RDPECAM] stops camera streams now when the remote no longer requests frames. (no more camera LED after closing the windows application accessing it) - [RDPEWA] support user verification in addition to / instead of pin - [RDPEUSB] properly map interface index to interface numbers (more devices should work now) - [android] updated touch pointer - [wlfreerdp] shortcut inhibit release on mouse leave window - [xfreerdp] rails improvements, hopefully no longer shrinking windows - Full support for [MS-RDPBCGR] 2.2.10.2 Early User Authorization Result PDU, so now you get a error message if a user is not allowed to log in instead of a network failed message. (Authentication /sec:ext or PROTOCOL_HYBRID_EX) - [shadow] add configuration options for /sec:ext or PROTOCOL_HYBRID_EX - [gateway] split HTTP timeout from TCP connect timeout - [ffmpeg] support generic hardware accelerated encoding/decoding, replacing the old VAAPI only implementation. (still experimental as there are often driver issues) ## CVE Note: Advisories will be published days/weeks after the release, so links are 404 until then. - By Opensec Intelligence - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xq87-9rrm-6wqw - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3rvr-qvx8-rj23 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pvgq-84w2-93ph - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xm53-352c-57jw - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mq5-xh88-9v62 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mqxv-c882-m8w9 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q6pp-28g8-xqjc - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jgw9-wqvx-j495 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5cgr-vmp8-fmvj - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m7g5-gw57-cwcr - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjxv-5j98-cqx4 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pw4j-ff39-9vjm - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-87v8-2gwr-ww9j - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h7fx-22wv-4cg8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-996j-34w6-5hgm - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-52xc-5973-w5vv - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qjwp-c855-hc69 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4ww8-3vqm-jgcf - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-96rv-gf42-7wq9 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9qr4-rgq4-jfp8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cq4m-gwc5-w8rc - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q9p9-j22r-577p - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2jfv-j3wx-5cg4 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-g8jw-gv54-r94p - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7vfc-chg9-q5r8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f46f-pxh9-w2rh - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pg3f-chj4-mrw6 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f526-rq4j-5ch8 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8rpr-jjjg-5qv6 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cmgx-558f-vh67 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m998-cvfm-9444 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-99p4-8j24-wvj4 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-97pf-pwp3-2wrv - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-27m7-gwhh-6hhf - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qpfh-m9w6-xf2x - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q56j-jjh6-38jf - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f554-v4xw-5j39 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-chh2-527f-x255 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-xf45-j844-588v - By @DavidKorczynski - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qq23-mqmv-pc65 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jhxw-3hj9-9hqh - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h44v-39x6-9xvg - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6vjv-4hm3-6698 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c3rh-2hv6-7hf2 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jp2r-gm4v-wvq2 - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-gvq8-v2fm-ffxv ... changelog too long, skipping 25 lines ... - Https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-83g2-gf92-5c4g ==== fribidi ==== Version update (1.0.16 -> 1.0.17) Subpackages: libfribidi0 - Update to 1.0.17: * Update Unicode character databases to v18.0.0. * Performance improvements: eliminate quadratic worst-case behavior in FSI base direction resolution, N0 bracket pairing, embedding-level resolution, and fribidi_reorder_line(). * Fix fribidi_set_reorder_nsm() and fribidi_set_mirroring() not taking effect when called before fribidi_log2vis(). * Fix bracket pairing (N0) to match brackets by canonical equivalence only, per UAX #9 BD16. * Fix stack buffer overflow when parsing character-set equivalence tables, and out-of-bounds read on trailing '_' in charset data. * Fix truncation of lines/output containing embedded NUL bytes. * Generate and install the fribidi(1) man page. - Add BuildRequires: help2man to generate fribidi(1) man page. - Package %{_mandir}/man1/fribidi.1*. - Drop ancient ppc64 obsoletes for fribidi-64bit. ==== hwinfo ==== Version update (25.5 -> 26.0) - merge gh#openSUSE/hwinfo#191 - code cleanup: remove some unused variables - 26.0 - merge gh#openSUSE/hwinfo#193 - add MMC/SD card block device support - add some minor improvements - merge gh#openSUSE/hwinfo#188 - Fix check_hd being built without LDFLAGS - merge gh#openSUSE/hwinfo#190 - fix(s390): fix memory leaks on skip paths in ccw device scan - merge gh#openSUSE/hwinfo#189 - fix(s390): fix out-of-bounds write in cutypes scan loop ==== kernel-firmware-amdgpu ==== Version update (20260829 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * amdgpu: update VPE 2.0.0 firmware * amdgpu: update VCN 5.3.0 firmware * amdgpu: update GC 11.7.0 MES firmware * amdgpu: update PSP 15.0.9 firmware * amdgpu: update PSP 15.0.0 firmware * Revert "amdgpu: update GC 11.0.0 firmware" * Revert "amdgpu: update GC 11.0.0 firmware" * amdgpu: DMCUB updates for various ASICs - Update to version 20260915 (git commit 4584045b2121): * Revert "amdgpu: update VCN 5.3.0 firmware" * Revert "amdgpu: update VCN 5.0.1 firmware" * Revert "amdgpu: update VCN 5.0.0 firmware" * Revert "amdgpu: update VCN 4.0.6 firmware" * Revert "amdgpu: update VCN 4.0.6 firmware" * Revert "amdgpu: update VCN 4.0.5 firmware" * Revert "amdgpu: update VCN 4.0.5 firmware" * Revert "amdgpu: update vcn 4.0.4 firmware" * Revert "amdgpu: update VCN 4.0.3 firmware" * Revert "amdgpu: update VCN 4.0.2 firmware" * Revert "amdgpu: update VCN 4.0.2 firmware" * Revert "amdgpu: update VCN 4.0.0 firmware" * Revert "amdgpu: update VCN 3.1.2 firmware" * amdgpu: partially revert 9f1eb5124635 * amdgpu: partially revert e3e45091597e * amdgpu: partially revert 7df10898a825 * amdgpu: partially revert 7b262e1ddce5 * amdgpu: partially revert 17ee8fdf9196 * amdgpu: partially revert 063e840eb6a5 * Partially revert "amdgpu: DMCUB updates for various ASICs" - Update to version 20260912 (git commit d371ae3b6888): * amdgpu: update vangogh firmware * amdgpu: update VPE 6.1.1 firmware * amdgpu: update VCN 4.0.6 firmware * amdgpu: update PSP 14.0.1 firmware * amdgpu: update GC 11.5.1 firmware * amdgpu: update VCN 4.0.5 firmware * amdgpu: update PSP 14.0.0 firmware * amdgpu: update GC 11.5.0 firmware * amdgpu: update renoir firmware * amdgpu: update yellow carp firmware * amdgpu: update PSP 13.0.5 firmware * amdgpu: update PSP 13.0.11 firmware * amdgpu: update GC 11.0.4 firmware * amdgpu: update VCN 4.0.2 firmware * amdgpu: update PSP 13.0.4 firmware * amdgpu: update GC 11.0.1 firmware * amdgpu: update SMU 14.0.3 firmware * amdgpu: update PSP 14.0.3 firmware * amdgpu: update GC 12.0.1 firmware * amdgpu: update PSP 14.0.2 firmware * amdgpu: update GC 12.0.0 firmware * amdgpu: update SMU 13.0.7 firmware * amdgpu: update PSP 13.0.7 firmware * amdgpu: update GC 11.0.2 firmware * amdgpu: update SMU 13.0.10 firmware * amdgpu: update PSP 13.0.10 firmware * amdgpu: update GC 11.0.3 firmware * amdgpu: update SMU 13.0.0 firmware * amdgpu: update PSP 13.0.0 firmware * amdgpu: update GC 11.0.0 firmware * amdgpu: update beige goby firmware * amdgpu: update dimgrey cavefish firmware * amdgpu: update navy flounder firmware * amdgpu: update sienna cichlid firmware * amdgpu: update navi14 firmware * amdgpu: update navi12 firmware * amdgpu: update navi10 firmware * amdgpu: update PSP 15.0.9 firmware * amdgpu: update GC 11.7.1 firmware * amdgpu: update VCN 5.3.0 firmware * amdgpu: update PSP 15.0.0 firmware * amdgpu: update GC 11.7.0 firmware * amdgpu: update PSP 14.0.5 firmware * amdgpu: update GC 11.5.3 firmware * amdgpu: update VPE 6.1.3 firmware * amdgpu: update PSP 14.0.4 firmware * amdgpu: update GC 11.5.2 firmware * amdgpu: update green sardine firmware * amdgpu: DMCUB updates for various ASICs - Update to version 20260904 (git commit 2f2bf38a3d03): * amdgpu: DMCUB updates for various ASICs - Update aliases from 7.3-rc1 ==== kernel-firmware-ath10k ==== Version update (20260809 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * qcom/shikra: link WiFi firmware from the ath10k subdir - Update to version 20260915 (git commit 4584045b2121): * qcom/sdm845: Let SHIFT6mq use the provided Wi-Fi firmware - Update to version 20260912 (git commit d371ae3b6888): * ath10k: WCN3990: hw1.0: add shikra firmware files ==== kernel-firmware-ath11k ==== Version update (20260610 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * ath11k: WCN6855 hw2.0: update board-2.bin ==== kernel-firmware-ath12k ==== Version update (20260813 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * ath12k: WCN7850 hw2.0: update board-2.bin * ath12k: QCC2072 hw1.0: update board-2.bin - Update to version 20260902 (git commit abddc5b93044): * ath12k: QCC2072 hw1.0: update to WLAN.COL.1.0.c2-00277-QCACOLSWPL_V1_TO_SILICONZ-1 ==== kernel-firmware-bluetooth ==== Version update (20260828 -> 20260929) - Update to version 20260929 (git commit 33b68e2c7011): * QCA: Add QCA2066 Bluetooth firmware hpnv21g.30c * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00653 - Update to version 20260926 (git commit 9b858e5bb58d): * qca: group the QCA61x4 USB firmware files * qca: fix the version of the WCN785x USB firmware * intel: Update ibt-00a0-01a1-pci.ddc for BE211 - Whale Peak2 (WhP2) - Update to version 20260916 (git commit e289868675d1): * QCA: Update Bluetooth firmware for QCC2072 UART interface: 1.1.0-00340 to 1.1.0-00355 - Update to version 20260910 (git commit eeccccbe83da): * QCA: Add Bluetooth firmware for WCN7750 on Maili platform - Update to version 20260902 (git commit abddc5b93044): * QCA: Add Bluetooth firmware hmtnv20.b201/b202 for WCN7850 on Nord platform * QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00079 ==== kernel-firmware-brcm ==== Version update (20260610 -> 20260915) - Update to version 20260915 (git commit 4584045b2121): * WHENCE: add missing symlink for TaiqiCat (TQC) A01 - Update to version 20260902 (git commit abddc5b93044): * [cypress]: Update firmware for cyfmac43455 SDIO ==== kernel-firmware-intel ==== Version update (20260728 -> 20260916) - Update to version 20260916 (git commit e289868675d1): * intel_vpu: Update NPU firmware ==== kernel-firmware-iwlwifi ==== Version update (20260820 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * iwlwifi: add Bz/Sc FW for core24.80-41 release * iwlwifi: Update Bz/Fm firmware for core24.80-41 release * iwlwifi: Add Hr/Gf firmware for core24.80-41 release * iwlwifi: update ty/So/Ma firmwares for core24.80-41 release * iwlwifi: Add cc/Qu/QuZ firmwares for core24.80-41 release - Update aliases ==== kernel-firmware-media ==== Version update (20260813 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * qcom: vpu: add Gen2 firmware binary for Hawi * qcom: vpu: add Gen2 firmware binary for Maili - Update to version 20260915 (git commit 4584045b2121): * qcom: vpu: add Gen2 firmware binary for sc8280xp - Update to version 20260910 (git commit eeccccbe83da): * qcom: vpu: Update video firmware binary for Glymur ==== kernel-firmware-mediatek ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-mwifiex ==== Version update (20260610 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * linux-firmware: mwifiex: add IW416 firmware ==== kernel-firmware-network ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-platform ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-qcom ==== Version update (20260828 -> 20260929) - Update to version 20260929 (git commit 33b68e2c7011): * qcom: update ADSP firmware for hawi platform * Revert "qcom: update ADSP firmware for qcs615 platform"q * qcom: Add gpu firmwares for Hawi and Maili chipsets - Update to version 20260926 (git commit 9b858e5bb58d): * qcom: update Rubik Pi 3 ADSP firmware * qcom: add CDSP firmware for hawi platform - Update to version 20260916 (git commit e289868675d1): * qcom: add ADSP firmware for maili platform - Update to version 20260915 (git commit 4584045b2121): * qcom/sdm845: Let SHIFT6mq use the provided Wi-Fi firmware - Update to version 20260910 (git commit eeccccbe83da): * qcom: Update ADSP firmware for sa8775p platform * qcom: point qcs8300 firmawre to sa8775p instance * qcom: update ADSP firmware for qcs615 platform * qcom: Add ADSP firmware for sc8280xp-radxa-dragon-q8b * qcom: sdm845: Add GPU firmware for SHIFT6mq * qcom: Update ADSP firmware for QCM6490 platform - Update aliases from 7.3-rc1 ==== kernel-firmware-qlogic ==== - Update aliases from 7.3-rc1 ==== kernel-firmware-realtek ==== Version update (20260731 -> 20260915) - Update to version 20260915 (git commit 4584045b2121): * rtl_nic: add firmware rtl8261d.bin for RTL8261d ==== kernel-firmware-sound ==== Version update (20260825 -> 20260926) - Update to version 20260926 (git commit 9b858e5bb58d): * cirrus: cs35l56: Correct firmware instances for 103c8c52 and 103c8c53 * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops * cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops * cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for some Dell laptops - Update to version 20260912 (git commit d371ae3b6888): * cirrus: cs35l57: Add firmware for Cirrus Amps for a Lenovo laptop - Update to version 20260910 (git commit eeccccbe83da): * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops * cs35l56: Add non-spkid firmware names for Thinkbook 16P Gen6 (17AA3921) - Update to version 20260903 (git commit ec2d074008a5): * cirrus: Version and cleanup of SDCA FW files - Update to version 20260902 (git commit abddc5b93044): * cirrus: cs35l41: Add Firmware for ASUS Zenbook Laptop using CS35L41 HDA - Update aliases from 7.3-rc1 ==== libraw ==== - added patches CVE-2026-88387: incorrect numeric conversion in `LibRaw::parse_tiff_ifd()` when processing TIFF tag `0x00fe` can lead to undefined behavior and a process crash when a specially crafted file is processed [bsc#1282783] * libraw-CVE-2026-88387.patch ==== libsodium ==== - Disable upstream SSP handling via --disable-ssp: distro optflags already carry -fstack-protector-strong, and upstream's appended basic -fstack-protector silently downgraded it. ==== libtheora ==== Subpackages: libtheora1 libtheoradec2 libtheoraenc2 - Disable asm on 32-bit arm until next release https://gitlab.xiph.org/xiph/theora/-/work_items/2338 ==== libupnp ==== Version update (22.1.5 -> 22.1.7) Subpackages: libixml22 libupnp22 - Update to release 22.1.7 * Fix a memory leak when a GENA subscription is freed. [GHSA-h9f5-9vwp-h89q] - Update to release 22.1.6 * GHSA-mhhw-gm73-c57g: Fix a heap over-read when parsing the Callback header of an incoming GENA SUBSCRIBE request. [GHSA-mhhw-gm73-c57g] ==== mozjs140 ==== Version update (140.16.0 -> 140.17.0) - Update to version 140.17.0. + See https://www.firefox.com/en-US/firefox/140.17.0/releasenotes/ - Rebase mozjs140-rust1.98.patch ==== nbd ==== - Add nbd-fix-help-parsing.patch to fix nbd-client -h segfaulting (boo#1282852): usage_error() was called with a NULL format string, which vsnprintf dereferences (upstream commit 89ba7b537954) ==== openSUSE-release ==== Version update (20260929 -> 20260930) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openexr ==== Version update (3.4.14 -> 3.4.15) Subpackages: libIex-3_4-33 libIex-3_4-33-x86-64-v3 libIlmThread-3_4-33 libIlmThread-3_4-33-x86-64-v3 libOpenEXR-3_4-33 libOpenEXR-3_4-33-x86-64-v3 libOpenEXRCore-3_4-33 libOpenEXRCore-3_4-33-x86-64-v3 - version update to 3.4.15 * fixes two memory issues when parsing IDManifests - added patches CVE-2026-88384: NULL pointer dereference in the C++ attribute parsing path when a specially crafted EXR file containing an unknown-type attribute with dataSize set to zero is processed [bsc#1282700] * openexr-CVE-2026-88384.patch ==== openssh ==== Subpackages: openssh-clients openssh-common openssh-server - Backport openssh-10.5p1-sync-readpassphrase.patch: sync readpassphrase(3) with OpenBSD libc so that SIG_IGN dispositions are preserved instead of being overridden; fixes ssh-add spinning when started in a background process group with no controlling tty and certain signals ignored (mindrot#3995, upstream commits 58db2ec9cac0 and e3cb2b2278c2). ==== python-jmespath ==== - Remove unneeded {Build,}Requires on ply. ==== python-msgpack ==== Version update (1.2.1 -> 1.2.2) - Update to 1.2.2: * Fix a use-after-free: unpackb() could build ExtraData.extra from already-freed memory when the input was a non-contiguous buffer (gh#msgpack/msgpack-python#720) * Fix silent datetime truncation in Unpacker with datetime=3 * Add a reentrant guard to Unpacker.feed() * Validate the nanoseconds range when unpacking timestamps in the C extension * Fix Timestamp.from_datetime() precision loss for far-future datetimes * Raise OverflowError instead of silently truncating when use_single_float cannot represent a value * Translate RecursionError to StackError in the fallback Unpacker.skip() ==== sdbootutil ==== Version update (1+git20260909.7cfa1f0 -> 1+git20260929.26b6989) Subpackages: sdbootutil-bash-completion sdbootutil-dracut-measure-pcr sdbootutil-snapper - Update to version 1+git20260929.26b6989: * Increase the timeout for the update-prediction service * Keep /.snapshots mounted for the shutdown helper * Serialize the update-predictions service and the shutdown helper * Do not ask to fix ROOTFS when the root is encrypted * Use >&2 instead of /dev/stderr * Revert "Move back from oneshot the update-predictions service" * Move back from oneshot the update-predictions service * Fix SELinux AVC from grep redirector * Use DSP for the LUKS2 swap partition * Add missing tight ESP unit test scenario * Don't count reused kernel when calculating free space - Update to version 1+git20260924.2b7b94e: * Improve detection of encrypted device when RAID is used * Support btrfs RAID1 configurations * Move the service from oneshot to exec to avoid the wait * Drop shift variations already present as a component * Fix Supplement use of 'if' instead of 'and' * Hide the warning for entries that uses @ * Accept _ instead of @ as snapshot prefix for version * Drop chown and set ownership via install * Use bootctl to generate the random seed * Start the validation with the strongest bank * Parse the JSON output of findmnt * Use stdin for qrencode * Fix log file permissions * Improve PCR15 diagnosis in status command * Avoid abrmd TCTI error message * Do not fail if pcrlock lock verb cannot reproduce the event log * The completion subpackage supplements the main one * Detect when grubenv is full * Use systemd-analyze to compare versions in status * Fix bootcounter in GRUB2 EFI variable * Drop lowercase in dd * Fix loader_conf_set for paths ==== selinux-policy ==== Version update (20260923 -> 20260928) Subpackages: selinux-policy-targeted - Update to version 20260928: * Allow sdbootutil_t write access to /var/lib/sdbootutil (bsc#1281087) ==== slang ==== - Drop obsolete -fstack-protector from CFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== tesseract-ocr ==== Subpackages: libtesseract5 libtesseract5-x86-64-v3 tesseract-ocr-common - Update tesseract-CVE-2026-88053.patch to null the adaptive template pointer arrays again and the class pruners as upstream does, fixing an abort at exit on every run and invalid frees when a corrupt traineddata is rejected (boo#1282863) ==== vsftpd ==== - Drop obsolete -fstack-protector from CFLAGS (predates distro - fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== wireplumber ==== Subpackages: libwireplumber-0_5-0 wireplumber-bash-completion wireplumber-lang wireplumber-zsh-completion - Modify environment file name in patch ==== yast2-auth-client ==== Version update (5.0.4 -> 5.0.5) - fix non specified optional params being unconditionally added to net cmd arg list; (bsc#1274806). - fix undefined conf.ad_user (NameError) in netcmd call; (bsc#1274612). - CVE-2026-59681: yast2-auth-client: OS command injection via unsanitized passed to net cmd. - Bump version to 5.0.5 for bsc#1272775.