Packages changed: AppStream (1.1.3 -> 1.1.5) faad2 (2.11.2.git13 -> 2.11.2.git18) freerdp (3.28.0 -> 3.30.0) gvfs highway inxi (3.3.40 -> 3.3.41) libmysofa (1.3.3 -> 1.3.5) linux-glibc-devel (7.0 -> 7.1) net-tools (3.14~alpha~git.20251212.7011617 -> 3.14~alpha~git.20260718.4f5bfb2) openSUSE-release (20260726 -> 20260728) perl-Net-DNS (1.550.0 -> 1.560.0) systemd (261.1 -> 261.2) tesseract-ocr (5.5.2 -> 5.5.3) zimg (3.0.6+20250919.gdf9c147 -> 3.0.6+20260720.g1ad1895) === Details === ==== AppStream ==== Version update (1.1.3 -> 1.1.5) Subpackages: AppStream-lang libAppStreamQt3 libappstream5 - Update to 1.1.5 Features: * sysinfo: Implement display size detection on macOS * sysinfo: Assume a more modern display for the handset chassis template * sysinfo: Assume a more modern display for the tablet chassis template * sysinfo: Initial code to autodetect the display size on Wayland * sysinfo: Handle fractional display scaling via xdg-output * Implement support for GCVE as vulnerability database provider * qt: Sync enum mirrors with the C library * qt: Add Artifact, Checksum, Reference, Review and Agreement wrappers * qt: Wrap missing C API on existing classes * reviews: Add simple interface to fetch ODRS reviews for a component * reviews: Implement support for submitting reviews Specification: * docs: Suggest using the longest display side for maximum size constraints Bugfixes: * qt: Add back wrong const Component::addBundle for ABI compatibility * qt: Use strndup for C string-list conversion * pool: Fix bidirectional wildcard search for modalias provides * Make GResources we need outlive main thread destruction * pool: Properly implement cancellation of load operations * sysinfo: Fix display-length setter overriding the shortest edge * relation-check: Don't zero the score if a required check errored * curl: Harden downloader by restricting protocols to only HTTP(S) * curl: Allow making POST requests and changing the user agent * curl: Fix retry-loop data corruption and don't blindly retry POST requests * yaml: Fix potential crashes when encountering missing relation entry values * yaml: Adjust tests and emitter to work around libfyaml string-quoting change * yaml: Ensure version relations are consistently quoted * qt: Fix buffer overrun in stringListToCharArray - Drop patches: * 0001-yaml-Fix-potential-crashes-when-encountering-missing.patch * 0001-yaml-Adjust-tests-and-emitter-to-work-around-libfyam.patch * 0001-yaml-Ensure-version-relations-are-consistently-quote.patch * 0001-trivial-yaml-Ensure-branding-color-values-are-also-c.patch ==== faad2 ==== Version update (2.11.2.git13 -> 2.11.2.git18) - Update to version 2.11.2.git18: * fix signed overflow in fixed-point sample rounding before saturation * prevent num_bits_left underflow in ps_data extension parsing * cap escape length in huffman_spectral_data_2 * fix signed overflow in estimate_current_envelope energy sum * fix ssr_gc_function signature mismatch in ssr gain control ==== freerdp ==== Version update (3.28.0 -> 3.30.0) Subpackages: libfreerdp3-3 librdtk0-0 libwinpr3-3 - Add build conditional for faad2, separate sdl package - Add pkgconfig(faad2) BuildRequires and pass -DWITH_FAAD2=ON to cmake: Support audio via optional faad2 codec. - Drop pkgconfig(gstreamer-1.0) and pkgconfig(gstreamer-plugins-base-1.0) BuildRequires, and stop passing -DWITH_GSTREAMER_1_0=ON and -DWITH_GSTREAMER_0_10=OFF to cmake, they are off by default and deprecated. - Update to version 3.30.0: + Security, bugfix and maintenance release. + CVE fixes: * CVE-XXXX-XXXXX (GHSA-m37j-jcr2-8gcc) * CVE-XXXX-XXXXX (GHSA-vv64-95pc-vj9v) * CVE-XXXX-XXXXX (GHSA-rqgv-grx4-xm6x) + Changes: * Logon info update (#13060) * Websocket regression fix (#13064) * Sdl clipbaord and bounds checks (#13065) * [core,rdstls] improve version handling (#13066) * [channels,drdynvc] fix channel unref on create request send failure (#13067) * Audin checks (#13068) * [channels,rdpsnd] tighten bounds checks (#13070) * Pcap cleanup (#13071) - Update to version 3.29.0: + Security, bugfix and maintenance release. + CVE fixes: * CVE-XXXX-XXXXX (GHSA-43hh-p3vw-hfx3) * CVE-XXXX-XXXXX (GHSA-ph3q-f9w8-7jf3) * CVE-XXXX-XXXXX (GHSA-mwwh-mhp9-q7vm) * CVE-XXXX-XXXXX (GHSA-whq8-c3v3-p8v8) * CVE-XXXX-XXXXX (GHSA-hgj8-g595-wfc6) * CVE-XXXX-XXXXX (GHSA-8v6m-2cmc-chx9) * CVE-XXXX-XXXXX (GHSA-5wr6-8m8j-3h7f) * CVE-XXXX-XXXXX (GHSA-89c6-jjrw-96h4) * CVE-XXXX-XXXXX (GHSA-8xqm-wp3f-rfp9) * CVE-XXXX-XXXXX (GHSA-jm8r-22j6-4m4v) * CVE-XXXX-XXXXX (GHSA-2c6r-4pr4-9x8m) * CVE-XXXX-XXXXX (GHSA-qmvw-52ph-q5pv) * CVE-XXXX-XXXXX (GHSA-34hq-hwjw-q8v3) * CVE-XXXX-XXXXX (GHSA-33gg-h66j-3697) * CVE-XXXX-XXXXX (GHSA-vxp3-7g6q-rq2w) * CVE-XXXX-XXXXX (GHSA-v89x-pc32-hqr7) * CVE-XXXX-XXXXX (GHSA-pfxq-3qmw-8vjx) * CVE-XXXX-XXXXX (GHSA-78jj-45vh-jpm5) * CVE-XXXX-XXXXX (GHSA-69xf-pqrw-596x) * CVE-XXXX-XXXXX (GHSA-8jj2-67pg-j6mg) * CVE-XXXX-XXXXX (GHSA-qrxx-7g3c-j6w3) * CVE-XXXX-XXXXX (GHSA-cj9v-h4hq-29jr) + Changes: * [client,sdl] Handle requested clipboard MIME formats (#13007) * [client,x11] Fix RAIL HiDef window maximize (#13010) * [channels,rdpecam] filter devices without supported formats (#13015) * [codec,planar] fix input checks (#13016) * [client] do not build wayland and windows (#13017) * [client,windows] add server response size check (#13018) * fix processImageName length check in rail get appid resp ex (#13020) * [channels,rdpecam] add data validity checks (#13021) * Scard alloc update reorder (#13022) * H264 decoder surface dimension mismatch (#13024) * [core,security] reject short server random in security_establish_keys (#13023) * Async update (#13025) * [core,rdstls] add endpoint FedAuth token authentication (#13026) * Resource limits (#13027) * Path checks (#13028) * [emu,scard] require Lc of 2 for select-by-FID in vgids_ins_select (#13030) * runtime hardening (#13032) * H264 fix (#13036) * [crypto,x509] improve hardening against embedded \0 (#13035) * [core,rail] unify RAIL_UNICODE_STRING handling (#13039) * [channels,rail] rail_server_handle_messages (#13037) * [channels,rdpecam] fix reading of config descriptor (#13042) * [codec,av1] bound decode output to decoded frame size (#13044) * Bounds check fixes (#13043) * [codec,av1] add region rects checks like with AVC modes (#13045) * Ios fixes (#13029) * Ios warn fixes (#13047) * [utils,smartcard] exclude ndr padding from returned buffer length (#13046) * Serial alloc checks (#13049) * Android build fixes (#13050) * [client,android] update build (#13051) ==== gvfs ==== Subpackages: gvfs-backend-afc gvfs-backend-goa gvfs-backend-gphoto gvfs-backend-samba gvfs-backends gvfs-fuse gvfs-lang - don't package capabilities in RPM but rely on permissions profiles instead (bsc#1268674). An upcoming change in rpmlint will raise badness when capabilities are directly packaged in an RPM. gvfsd-nfsd is already whitelisted in the permissions profiles and the proper capabilities will be assigned during %post. ==== highway ==== - Add upstream patch to fix build on aarch64 with gcc16: * gcc16-aarch64.patch ==== inxi ==== Version update (3.3.40 -> 3.3.41) - Update to version 3.3.41: * A few minor errors in gpu id led to a long needed update to gpu data sources and detection logic, as well as forcing some known gpu IDs to the right generation. ==== libmysofa ==== Version update (1.3.3 -> 1.3.5) - Update to 1.3.5: * Harden HDF/SOFA parser against malformed input * Fixed issue with missing boundary check which lead to a stall - Changes in 1.3.4: * “fixes issues with v1.3.3” * added support for General FIR-E ==== linux-glibc-devel ==== Version update (7.0 -> 7.1) - Update to kernel headers 7.1 ==== net-tools ==== Version update (3.14~alpha~git.20251212.7011617 -> 3.14~alpha~git.20260718.4f5bfb2) Subpackages: net-tools-lang - Update to version 3.14~alpha~git.20260718.4f5bfb2: * Update config.in: disable AF and HW ROSE by default (obsoletes Update_config.in.patch) * netstat: Keep UTF-8 characters in process names (bsc#1254323, obsoletes net-tools-netstat-ansi-injection.patch) - Update to version 3.14~alpha~git.20260612.2ab3c5e: * netstat: Update email address * doc: describe missing headers * passes -Wunused-parameter * fix type limit warnings * Remove anchient gettext ABOUT-NLS * TODO: removed NLS, add -Wextra * INSTALLING: musl, all features, compile warning todos * netstat.8: minor edits * chore: pedantic zizmor is happy on GH actions * Unified man example format * netstat.8: warn on trustworthyness of program name * man: netstat: add two examples * Rarp: fix nullpointer on unknown hosts * netstat: safe cycles and fix comment * Sanitize cmdline (bsc#1254323, CVE-2024-58251) * Updated translations. - Add Update_config.in.patch: Update config.in: disable AF and HW ROSE by default. This is longer part of the kernel 7.1 source tree. ==== openSUSE-release ==== Version update (20260726 -> 20260728) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== perl-Net-DNS ==== Version update (1.550.0 -> 1.560.0) - updated to 1.560.0 (1.56) see /usr/share/doc/packages/perl-Net-DNS/Changes Fix rt.cpan.org #180088 Documentation issue for Net::DNS::RR::RRSIG::verify() Fix rt.cpan.org #179946 Denial of Service via long DNS compression chains CVE-2026-64194 bsc#1272214 Fix rt.cpan.org #179945 Remote code injection via EDNS EXTENDED ERROR CVE-2026-64193 bsc#1272212 Fix rt.cpan.org #179692/#176900 UNIX.pm: Unreachable code warning using Apache/mod_perl ==== systemd ==== Version update (261.1 -> 261.2) Subpackages: libsystemd0 libsystemd0-32bit libudev1 systemd-32bit systemd-boot systemd-container systemd-lang udev - Import commit 4925d9f07fc697efccd98a93046ff535b8832445 (merge of v261.2) For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/eff9446d505d62c075bed37d606860b38cfe51fb...4925d9f07fc697efccd98a93046ff535b8832445 - Move systemd-vmspawn from the experimental sub-package to systemd-container ==== tesseract-ocr ==== Version update (5.5.2 -> 5.5.3) Subpackages: libtesseract5 libtesseract5-x86-64-v3 tesseract-ocr-common - Update to version 5.5.3: * Fix missing closing tags in multi-page PAGE XML output * Correct a mutex call to prevent multiple instances * Document memory ownership and lifecycle in the C API * Fix CMAKE_SYSTEM_PROCESSOR detection when cross-compiling on Apple platforms - Switch the documentation BuildRequires from asciidoc to rubygem(asciidoctor): upstream now generates the man pages with asciidoctor and silently skips them otherwise - Drop the gcc13 fallback for Leap 15.x: 15.6 is out of support and its repository has been retired from the devel project ==== zimg ==== Version update (3.0.6+20250919.gdf9c147 -> 3.0.6+20260720.g1ad1895) - Update to version 3.0.6+20260720.g1ad1895: * colorspace: add chromatic adaptation support, disabled by default (new zfilter_graph_builder_params field, required by VapourSynth R78) * colorspace: add BT.1361 transfer characteristics, simplify the xvYCC EOTF, add FMA and F16C feature checks, fix the hash function and an assertion on 240M->709 gamma * depth: add NEON-optimized error diffusion dithering * resize: fix integer weight rounding compensation and impose a maximum tap count on Lanczos * Fix out-of-bounds accesses in several SIMD code paths: the AVX2 u16 permute resizer load, AVX2 and NEON ordered dither reads, NEON error diffusion read, NEON float-to-half write, NEON byte-to-word left-shift read and the AVX2 unresize buffer size calculation * unresize: special-case the LU decomposition of a 1x1 matrix and use double epsilon * common: fix matrix row offset tracking after compaction * graph: fix the 64-byte alignment check, rename factory to observer * Update the bundled graphengine * Test-only, MSVC/Windows and example-code changes omitted here