Packages changed: MicroOS-release (20260728 -> 20260729) PackageKit (1.3.5 -> 1.3.6) ca-certificates (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) fwupd (2.1.6 -> 2.1.7) libostree (2026.1 -> 2026.2) ntfs-3g_ntfsprogs (2022.10.3 -> 2026.7.7) selinux-policy (20260715 -> 20260727) sssd util-linux (2.42.1 -> 2.42.2) util-linux-systemd (2.42.1 -> 2.42.2) === Details === ==== MicroOS-release ==== Version update (20260728 -> 20260729) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== PackageKit ==== Version update (1.3.5 -> 1.3.6) Subpackages: PackageKit-backend-dnf5 libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Update to version 1.3.6 (bsc#1267250, CVE-2026-10294): + Bugfixes: - daemon: stop idle progress timer after flushing updates - tests: Actually run the daemon tests on CI using a helper - tests: daemon: Auto-answer interactive prompts from the test - tests: Refactor and reorganize tests - pk-client: Perform any state changes & teardown before g_task_return_*() - package-sack: Fix a double-free issue on PkTask - Ensure we can send SIGQUIT to spawned backends - Prevent a race between the test harness and pk_readline* for input - daemon: Do not accept symlinks as frontend socket - daemon: Return proper error codes for bad SetHints() input - Don't leak TESTDATADIR into production binaries - daemon: Whitelist ONLY_DOWNLOAD for specific transaction roles only - lib: Don't warn on generic D-Bus errors - Send SIGTERM to ask subprocesses to quit, instead of SIGQUIT - daemon: Check errno instead of kill() return values to determine why it failed - pk-client: Fix race between cancellation and TID/proxy assignment + Miscellaneous: - PkTransaction: Simplify the error quark creation - ci: Ensure D-Bus is available and running for all tests - docs: Add error-checking to PK usage example ==== ca-certificates ==== Version update (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) - Update to version 2+git20260727.241e0ff: * certbundle.run: fix case where cafile does not exist ==== fwupd ==== Version update (2.1.6 -> 2.1.7) Subpackages: libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.7: + This release adds the following features: - Add "well known" AppStream IDs for common BIOS settings - Add MTD lock security attribute - Add support for "externally managed" EFI signature lists - Add systemd-pcrlock plugin and hook up to UEFI updates - Add TCG disk encryption security attribute - Enable more plugins when compiling for Android + This release fixes the following bugs: - Add wrappers for input streams for future Rust implementations - Allow overriding some methods in FwupdClient for a future refactor - Allow plain string versions for some AMD GPUs - Allow suspend-to-ram with encrypted RAM - Always test Dell dock type when connected - Avoid possible out-of-bounds read in when parsing the DFU sector - Do not abort when udisks cannot resolve a device - Do not allow force installs over D-Bus - Do not fail to start when a pre-group comment has no keys set - Fall back to copying the file descriptor contents when not sealed - Fix dropped status updates during updates - Fix FW update for Lenovo TBT5 Smart Dock 7500 - Fix fwupd-refresh.service polkit auth errors - Fix segfault parsing some logitech-hidpp bootloader records - Fix the seal self tests when building on a tmpfs - Fix update failure when the TP IC is in bootloader-only mode - Mark Coreboot VBOOT as obsoleting BootGuard verified - Move more per-class limits to the class instances to reduce RSS - Prepare modem-manager firmware after firehose detach - Reject out-of-range CCGX device mode before indexing versions - Require trusted metadata for device updates - Require trusted metadata when using OnlyTrusted - Skip modem-manager secboot status when unsupported - Use safe reads for synaptics-rmi device responses - Validate GUID-defined section offset against EFI section size + This release adds support for the following hardware: - PixArt PJP360 device ==== libostree ==== Version update (2026.1 -> 2026.2) Subpackages: libostree-1-1 - Update to 2026.2: * Fix GVariant memory leak during opaque whiteout scanning that could cause bootc install to-disk to fail with EBUSY on unmount * Fix a crash for invalid UTF-8 ref names during pull operations * Fix Kernel argument handling was fixed to properly handle quoted values in /proc/cmdline * Correct staged deployment bootconfig merging to preserve options across re-staging ==== ntfs-3g_ntfsprogs ==== Version update (2022.10.3 -> 2026.7.7) Subpackages: ntfs-3g ntfsprogs - Update to version 2026.7.7: * (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616). * Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617). * Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618). * Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569). * Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571). * Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570). * Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572). * Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135). * Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136). - Drop patches fixed upstream: + ntfs3g-unistr-use-after-free.patch + ntfs3g-heap-overflow.patch + 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch + 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch + 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch + 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch + 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch + 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch + 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch ==== selinux-policy ==== Version update (20260715 -> 20260727) Subpackages: selinux-policy-targeted - Update to version 20260727: * pwaccessd_t uses nsswitch and newidmapd connects to pwaccessd_t socket (bsc#1271860) * adjust amavis spool path regex for openSUSE (bsc#1268627) * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366) * Support vfs_snapper to work with samba_share_t (bsc#1265400) * vfs_samba uses dbus to communicate with snapper (bsc#1265400) ==== sssd ==== Subpackages: libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap - Enable sssd-idp. This provides external Identity Provider (OAuth2/OpenID Connect) support. Also enables the krb5 idp plugin. ==== util-linux ==== Version update (2.42.1 -> 2.42.2) Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ==== util-linux-systemd ==== Version update (2.42.1 -> 2.42.2) Subpackages: lastlog2 liblastlog2-2 - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219).