Packages changed: AppStream (1.1.2 -> 1.1.3) Mesa (26.1.4 -> 26.1.5) Mesa-drivers (26.1.4 -> 26.1.5) MicroOS-release (20260714 -> 20260724) PackageKit acl (2.3.2 -> 2.4.0) aurorae6 (6.7.2 -> 6.7.3) avahi avahi-glib2 blog (2.46 -> 2.47) bluedevil6 (6.7.2 -> 6.7.3) breeze6 (6.7.2 -> 6.7.3) breeze6-gtk (6.7.2 -> 6.7.3) btrfsprogs (7.0 -> 7.1) ca-certificates (2+git20260420.2a8e251 -> 2+git20260717.2e3a23b) dav1d (1.5.3 -> 1.5.4) discover6 (6.7.2 -> 6.7.3) dracut (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) e2fsprogs findutils (4.10.0 -> 4.11.0) firewalld (2.1.2 -> 2.3.2) flatpak-kcm6 (6.7.2 -> 6.7.3) gawk (5.4.0 -> 5.4.1) glslang (16.3.0 -> 16.4.0) gnutls google-noto-fonts (20241201 -> 20260701) gpsd grub2 kactivitymanagerd6 (6.7.2 -> 6.7.3) kde-cli-tools6 (6.7.2 -> 6.7.3) kde-gtk-config6 (6.7.2 -> 6.7.3) kdecoration6 (6.7.2 -> 6.7.3) kdeplasma6-addons (6.7.2 -> 6.7.3) kernel-source (7.1.3 -> 7.1.4) kf6-attica (6.27.0 -> 6.28.0) kf6-baloo (6.27.0 -> 6.28.0) kf6-bluez-qt (6.27.0 -> 6.28.0) kf6-breeze-icons (6.27.0 -> 6.28.0) kf6-frameworkintegration (6.27.0 -> 6.28.0) kf6-karchive (6.27.0 -> 6.28.0) kf6-kauth (6.27.0 -> 6.28.0) kf6-kbookmarks (6.27.0 -> 6.28.0) kf6-kcmutils (6.27.0 -> 6.28.0) kf6-kcodecs (6.27.0 -> 6.28.0) kf6-kcolorscheme (6.27.0 -> 6.28.0) kf6-kcompletion (6.27.0 -> 6.28.0) kf6-kconfig (6.27.0 -> 6.28.0) kf6-kconfigwidgets (6.27.0 -> 6.28.0) kf6-kcontacts (6.27.0 -> 6.28.0) kf6-kcoreaddons (6.27.0 -> 6.28.0) kf6-kcrash (6.27.0 -> 6.28.0) kf6-kdbusaddons (6.27.0 -> 6.28.0) kf6-kdeclarative (6.27.0 -> 6.28.0) kf6-kded (6.27.0 -> 6.28.0) kf6-kdesu (6.27.0 -> 6.28.0) kf6-kdnssd (6.27.0 -> 6.28.0) kf6-kdoctools (6.27.0 -> 6.28.0) kf6-kfilemetadata (6.27.0 -> 6.28.0) kf6-kglobalaccel (6.27.0 -> 6.28.0) kf6-kguiaddons (6.27.0 -> 6.28.0) kf6-kholidays (6.27.0 -> 6.28.0) kf6-ki18n (6.27.0 -> 6.28.0) kf6-kiconthemes (6.27.0 -> 6.28.0) kf6-kidletime (6.27.0 -> 6.28.0) kf6-kimageformats (6.27.0 -> 6.28.0) kf6-kio (6.27.0 -> 6.28.0) kf6-kirigami (6.27.0 -> 6.28.0) kf6-kitemmodels (6.27.0 -> 6.28.0) kf6-kitemviews (6.27.0 -> 6.28.0) kf6-kjobwidgets (6.27.0 -> 6.28.0) kf6-knewstuff (6.27.0 -> 6.28.0) kf6-knotifications (6.27.0 -> 6.28.0) kf6-knotifyconfig (6.27.0 -> 6.28.0) kf6-kpackage (6.27.0 -> 6.28.0) kf6-kparts (6.27.0 -> 6.28.0) kf6-kpty (6.27.0 -> 6.28.0) kf6-kquickcharts (6.27.0 -> 6.28.0) kf6-krunner (6.27.0 -> 6.28.0) kf6-kservice (6.27.0 -> 6.28.0) kf6-kstatusnotifieritem (6.27.0 -> 6.28.0) kf6-ksvg (6.27.0 -> 6.28.0) kf6-ktexteditor (6.27.0 -> 6.28.0) kf6-ktextwidgets (6.27.0 -> 6.28.0) kf6-kunitconversion (6.27.0 -> 6.28.0) kf6-kuserfeedback (6.27.0 -> 6.28.0) kf6-kwallet (6.27.0 -> 6.28.0) kf6-kwidgetsaddons (6.27.0 -> 6.28.0) kf6-kwindowsystem (6.27.0 -> 6.28.0) kf6-kxmlgui (6.27.0 -> 6.28.0) kf6-modemmanager-qt (6.27.0 -> 6.28.0) kf6-networkmanager-qt (6.27.0 -> 6.28.0) kf6-prison (6.27.0 -> 6.28.0) kf6-purpose (6.27.0 -> 6.28.0) kf6-qqc2-desktop-style (6.27.0 -> 6.28.0) kf6-solid (6.27.0 -> 6.28.0) kf6-sonnet (6.27.0 -> 6.28.0) kf6-syndication (6.27.0 -> 6.28.0) kf6-syntax-highlighting (6.27.0 -> 6.28.0) kgamma6 (6.7.2 -> 6.7.3) kglobalacceld6 (6.7.2 -> 6.7.3) kinfocenter6 (6.7.2 -> 6.7.3) kirigami-addons6 (1.12.1 -> 1.13.0) kmenuedit6 (6.7.2 -> 6.7.3) knighttime6 (6.7.2 -> 6.7.3) kpipewire6 (6.7.2 -> 6.7.3) kscreen6 (6.7.2 -> 6.7.3) kscreenlocker6 (6.7.2 -> 6.7.3) ksshaskpass6 (6.7.2 -> 6.7.3) ksystemstats6 (6.7.2 -> 6.7.3) kwayland-integration6 (6.7.2 -> 6.7.3) kwayland6 (6.7.2 -> 6.7.3) kwin6 (6.7.2 -> 6.7.3) layer-shell-qt6 (6.7.2 -> 6.7.3) libdrm libkscreen6 (6.7.2 -> 6.7.3) libksysguard6 (6.7.2 -> 6.7.3) libplasma6 (6.7.2 -> 6.7.3) libseccomp libsoup libtool (2.5.4 -> 2.6.2) libupnp (2.0.2 -> 22.0.4) libzypp (17.38.13 -> 17.38.14) milou6 (6.7.2 -> 6.7.3) mozilla-nss (3.124 -> 3.125) ngtcp2 (1.22.1 -> 1.24.0) ntfs-3g_ntfsprogs open-iscsi open-vm-tools openssl-3 patterns-base perl (5.42.1 -> 5.44.0) permissions (1699_20260707 -> 1699_20260715) pipewire (1.6.7 -> 1.6.8) plasma5support6 (6.7.2 -> 6.7.3) plasma6-activities (6.7.2 -> 6.7.3) plasma6-activities-stats (6.7.2 -> 6.7.3) plasma6-browser-integration (6.7.2 -> 6.7.3) plasma6-desktop (6.7.2 -> 6.7.3) plasma6-integration (6.7.2 -> 6.7.3) plasma6-nm (6.7.2 -> 6.7.3) plasma6-openSUSE plasma6-pa (6.7.2 -> 6.7.3) plasma6-print-manager (6.7.2 -> 6.7.3) plasma6-systemmonitor (6.7.2 -> 6.7.3) plasma6-workspace (6.7.2 -> 6.7.3) policycoreutils polkit polkit-kde-agent-6 (6.7.2 -> 6.7.3) poppler (26.06.0 -> 26.07.0) poppler-qt6 (26.06.0 -> 26.07.0) powerdevil6 (6.7.2 -> 6.7.3) python-pyasn1 (0.6.3 -> 0.6.4) python313 (3.13.13 -> 3.13.14) python313-core (3.13.13 -> 3.13.14) qemu qqc2-breeze-style6 (6.7.2 -> 6.7.3) rootlesskit (3.0.1 -> 3.0.2) run0-wrappers (0.4+git20260203.bbbfcf8 -> 0.5.0+git20260717.efd7268) runc (1.4.2 -> 1.4.3) sddm sddm-kcm6 (6.7.2 -> 6.7.3) sddm-qt6 selinux-policy (20260702 -> 20260715) shaderc (2026.2 -> 2026.3) spectacle (6.7.2 -> 6.7.3) sqlite3 srt (1.5.5 -> 1.5.6) suse-module-tools (16.1.5 -> 16.1.6) systemsettings6 (6.7.2 -> 6.7.3) tar transactional-update (6.1.1 -> 6.1.3) vim wayland (1.25.0 -> 1.26.0) wget xdg-desktop-portal-kde6 (6.7.2 -> 6.7.3) xorg-x11-server (21.1.21 -> 21.1.24) === Details === ==== AppStream ==== Version update (1.1.2 -> 1.1.3) Subpackages: libAppStreamQt3 libappstream5 - Add upstream changes: * 0001-yaml-Fix-potential-crashes-when-encountering-missing.patch * 0001-yaml-Adjust-tests-and-emitter-to-work-around-libfyam.patch * 0001-yaml-Ensure-version-relations-are-consistently-quote.patch * 0001-trivial-yaml-Ensure-branding-color-values-are-also-c.patch - Drop patch, no longer needed: * 0001-Disable-failing-test-with-old-libfyaml.patch - Update to 1.1.3 Features: * Officially support & read JXL images for icons, validate permitted filetypes * meson: Allow disabling command-line tools * news-convert: Recognize "=" as release block header * news-convert: Handle extra linebreaks better and add support for issue-blocks * compose: Create content hashes with Blake3 instead of MD5 * Update static data for category and license additions * validator: Tags without namespace are an error Specification: * docs: Convert to Docbook 5 Bugfixes: * yaml: Ensure certain values are always explicitly emitted as strings * Never emit usertags that are missing a namespace * compose: add bounds checks when parsing malformed translation files * Explicitly add fcfreetype.h include to asc-font.c * compose: Unref icon_policy in asc_compose_finalize * compose: Free array from asc_result_get_component_ids_with_hints Miscellaneous: * yaml: Improve string quoting heuristics * meson: Drop -Winline from maintainer flags - Drop patch, merged upstream: * 0001-Explicitly-add-fcfreetype.h-include-to-asc-font.c.patch - Drop no longer needed patch: * support-meson0.59.patch ==== Mesa ==== Version update (26.1.4 -> 26.1.5) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.1.5 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.5 - fixed hardware supplements for libvulkan_intel/libvulkan_radeon (boo#1271268) ==== Mesa-drivers ==== Version update (26.1.4 -> 26.1.5) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Update to 26.1.5 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.5 - fixed hardware supplements for libvulkan_intel/libvulkan_radeon (boo#1271268) ==== MicroOS-release ==== Version update (20260714 -> 20260724) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== PackageKit ==== Subpackages: PackageKit-backend-dnf5 libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Add PackageKit-zypp-respect-libzypp-package-locks.patch: zypp: respect libzypp package locks (bsc#1263252, gh#PackageKit/PackageKit/commit/1263252). ==== acl ==== Version update (2.3.2 -> 2.4.0) - Update to version 2.4.0: Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent that. ==== aurorae6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== avahi ==== Subpackages: libavahi-client3 libavahi-common3 libavahi-core7 - Add avahi-CVE-2025-59529.patch: limit the number of simple clients (bsc#1255451 CVE-2025-59529). ==== avahi-glib2 ==== - Add avahi-CVE-2025-59529.patch: limit the number of simple clients (bsc#1255451 CVE-2025-59529). ==== blog ==== Version update (2.46 -> 2.47) Subpackages: libblogger2 - Update to version 2.47 This addresses several race conditions, file descriptor leaks, and architectural issues regarding virtual terminal (VT) handling in blogd. * VT Encapsulation: Extracted all kernel-specific terminal ioctls and macros (e.g., KD_GRAPHICS, KD_TEXT) into a dedicated vt.c module. Added clean abstractions like vt_is_graphics(), vt_is_text(), and vt_set_text_mode() to decouple blogd.c and console.c from kernel headers. * List Management & FD Leaks: Fixed dynamic VT allocation in console.c. By resetting the console pointer to NULL before consalloc() and explicitly searching the doubly linked list for the target device ID afterward, we ensure the exact newly allocated terminal node is referenced. This fixes incorrect node assignments and prevents file descriptor leaks. * Smart VT Switching: Optimized the password prompt logic. If the currently active VT is a text console, the prompt is displayed there directly without unnecessary context switches. If the active VT is running a GUI (X11/Wayland), it safely switches to a newly allocated text VT and returns afterward. * EBUSY Race Condition: The child process now explicitly closes the temporary VT file descriptor before initiating the vt_switch back to the original console. This allows the parent process to safely perform vt_disallocate without encountering EBUSY kernel errors. * Timeout Handling: Replaced the infinite wait loop in request_tty() (tty.c) with a safe 2000ms timeout via can_read(). This prevents the daemon from hanging indefinitely on locked terminals and allowed the removal of error-prone alarm() signal hacks. * Lifecycle Management: Ensured newly allocated dynamic VTs are properly initialized via consinitIO() and reliably deallocated upon daemon exit (lcons_shutdown). Fix epoll EEXIST crash and prevent infinite waits on busy terminals This also addresses two critical edge cases that could cause the blogd daemon to either crash or hang during concurrent or blocked prompt requests. Key changes: * epoll.c: Prevent an `EEXIST` crash in `epoll_addition()`. If a file descriptor is already registered in the watch list, the daemon now gracefully updates it using `EPOLL_CTL_MOD` instead of blindly calling `EPOLL_CTL_ADD`. This makes the socket handling robust against rapid, overlapping client requests. * console.c: Add a 2-second deadline (`alarm(2)`) around the `request_tty()` call inside the password-prompt child process. Previously, if a terminal was exclusively locked (e.g. by an X11 server returning EPERM), the child would fall into an infinite inotify wait-loop. With the timeout, the child now dies cleanly, allowing the parent's reaping logic to properly cancel the prompt and send an ANSWER_ENQ (abort) to the waiting client. ==== bluedevil6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== breeze6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: breeze6-cursors breeze6-decoration breeze6-style breeze6-wallpapers - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * breezehelper: Fix asymmetric separators on immutable tabs ==== breeze6-gtk ==== Version update (6.7.2 -> 6.7.3) Subpackages: gtk3-metatheme-breeze6 metatheme-breeze6-common - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== btrfsprogs ==== Version update (7.0 -> 7.1) Subpackages: btrfsprogs-udev-rules libbtrfs0 libbtrfsutil1 - update to 7.1 * mkfs: * use GET_CSUMS ioctl (if provided by kernel, 7.2) to reuse existing checksums for --rootdir, works with --reflink to avoid reading file data * fix last block handling for reflink * fix handling of incompressible data extents * fix --rootdir size estimation when using hardlinks * fi mkswapfile: add option to specify page size, useful on ARM64 * check: add option to skip qgroup verification to speed up check * in experimental build, use V2 of tree search ioctl, this can use larger buffer * preliminary fscrypt support * enhance filesystem opening modes with more fine-grained support of partially damaged trees and allow to skip non-essential trees * other: * stability and error handling fixes * CI updates * updated tests * documentation updates ==== ca-certificates ==== Version update (2+git20260420.2a8e251 -> 2+git20260717.2e3a23b) - Update to version 2+git20260717.2e3a23b: * Fix for 458d37d, logic got wrong - Update to version 2+git20260708.2380cdb: * Remove duplicate I from help text * Blacken test_update_ca_certificates * Replace backticks in shell scripts * Unify quoting in shell scripts * Refactor to POSIX sh * Reduce slashes in shell paths * Unify indentation style in shell scripts * CI: remove black format check and update actions * CI: create /etc/ca-certificates in the container ==== dav1d ==== Version update (1.5.3 -> 1.5.4) - Update to version 1.5.4 * Switch to external checkasm * Add Armv9.3-A GCS (Guarded Control Stack) support * AArch64: optimize ipred_v, ipred_h and ipred_smooth_* 8bpc functions, and reduce .text size * ARM32: optimize prep_neon * RISC-V: ipred_(dc, h, v, pal) optimizations for 8 and 16bpc, generate_grain_y for 8bpc, and optimizations (prep/put_8tap, 6-tap and copy paths) * Schedule tile tasks for all passes at once, improving threading * Precompute the quantization matrix tables at build time * Move loop-invariant computations out of hot loops ==== discover6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: discover6-backend-flatpak discover6-backend-fwupd discover6-notifier - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== dracut ==== Version update (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) Subpackages: dracut-ima - Update to version 110+suse.45.geaec47e4: * fix(systemd-networkd): escape values from DHCP options (bsc#1264833, GHSA-x37p-6hhc-6628) * feat(base): add escape function implementing printf %q * fix(systemd-networkd): get DHCP options values from networkctl * fix(kernel-modules): include xhci-pci-prom21 for early USB ==== e2fsprogs ==== Subpackages: libcom_err2 libext2fs2 - Drop obsolete BuildRoot tag and no-op %defattr lines - Package NOTICE as %license unconditionally - Fix scope of the systemd guard around %preun ==== findutils ==== Version update (4.10.0 -> 4.11.0) - Update to 4.11.0. Announcement: https://savannah.gnu.org/news/?id=10912 Most prominent change in behavior: As announced since the release of 4.7.0 (2019) and mandated by POSIX 2024, the behaviour of the -mount option changed: while it was a mere alias for the -xdev option to prevent descending into directories of another device, the -mount option now makes find(1) ignore files on another device, i.e., 'find -mount' will skip the entry of active mount points already. Example, assuming the PROC filesystem is mounted on '/proc': $ find / -mount -path /proc -print $ find / -xdev -path /proc -print /proc - findutils-avoid-crash-system-loop.patch: Remove now-upstream patch. - findutils-xautofs.patch: Refresh. ==== firewalld ==== Version update (2.1.2 -> 2.3.2) Subpackages: python313-firewall * Fix CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903) [+ 0003-CVE-2026-4948-fix-dbus-setter-authorization.patch] - Update to New Version 2.3.2 * doc(policy): add examples to man page * doc(policies): correct word is asymmetric * fix(doc): dbus: remove links to nonexistent IDs * fix(policy): allow forward ports with ingress zone and egress HOST * fix(server): load firewall rules before claiming dbus * fix(nftables): ipset: add entries from GLib loop when idle * fix(systemd): Requires dbus * fix(nftables): use current pkttype keywords * fix(systemd): use ProtectHome=tmpfs * fix(policy): allow-host-ipv6: allow MLD packets * fix(icmpv6): validate router codes * fix(icmpv6): validate neighbor codes * fix(icmpv6): validate redirect codes * docs(zone): update default zone target description to mention that ICMP is accepted * docs(zone): grammar fixes * docs(zone): mention that the ACCEPT target allows forwarding out of the zone * docs(zone): remove references to specific zone names in description of target attribute * docs: use US spelling of behavior - Update to New Version 2.3.0 -Update to New Version 2.3.0 It also includes all bug fixes since v2.3.0. * feat(policy): add disable flag * feat(client): policy: add disable flag * feat(cli): policy: add disable flag * feat(policy): increase maximum name length to 128 * feat(cli): policy: support setting disable on sets * feat(policy): set: add gateway ==== flatpak-kcm6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * kcm_app-permissions.json: fix BugReportUrl ==== gawk ==== Version update (5.4.0 -> 5.4.1) - update to 5.4.1: * Fix a performance problem in PMA with backing store files 1G or more in size * Fix a bug in gensub() when using MinRX * Unary plus and minus now force their operands to be numeric * Add man page and documentation for the intdiv extension * Enable and update the Georgian translation (ka.po) * Parse time division by zero is no longer a fatal error, but rather a lint warning. Division by zero at runtime remains fatal * Some subtle issues with respect to formatting numeric fields have been fixed * small bug fixes ==== glslang ==== Version update (16.3.0 -> 16.4.0) - Update to release 16.4.0 * Implement `GLSL_EXT_structured_descriptor_heap` with SPIR-V layout generation, heap offset access, buffer references, matrix layout decorations, and correct `readonly`/`writeonly` qualifier propagation for buffer and image descriptors * Fix descriptor heap-bound buffer access to use typed pointers * Omit `NonUniform` decoration when using descriptor heaps, as the SPIR-V spec does not require it * Add `--relax-set-binding-limits` option to allow large `layout(set)` and `layout(binding)` values for descriptor heap-style workflows with sparse set spaces * Reject combined image samplers with `descriptor_heap` * Fix `GL_KHR_compute_shader_derivatives` regressions on shaders using the `GL_NV` variant * Update compute shader derivative rules to allow texture operations with implicit derivatives without extensions, falling back to LoD 0 * New extensions: `GL_EXT_ocp_microscaling_types`, `GL_NV_cooperative_matrix_decode_vector`, `GL_EXT_opacity_micromap_ray_query_mode` and basic support for `GL_NV_desktop_lowp_mediump` ==== gnutls ==== - FIPS: Add NIST SP800-56Brev2 6.4.2.2 check: * Partial public-key validation for RSA OAEP (bsc#1262397) * Add gnutls-FIPS-RSA-OAEP-PK-validation.patch - FIPS: Perform the integrity checks for libleancrypto-fips and libleancrypto with the HMACs provided by the library (bsc#1262399) * Add gnutls-FIPS-HMAC-leancrypto.patch - FIPS: Remove GNUTLS_MAC_SHA1 FIPS self-test (bsc#1262400) * Add gnutls-FIPS-Remove-SHA1-self-test.patch ==== google-noto-fonts ==== Version update (20241201 -> 20260701) Subpackages: google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Drop stale file - Update Source in the spec file to include the download URL - Update to 20260701 * Various updates to the font collection, Too many changes to list * New fonts : - Todhri Fonts (google-noto-serif-todhri-fonts) - Hentaigana Fonts (google-noto-serif-hentaigana-fonts) - Sunuwar Fonts (google-noto-sans-sunuwar-fonts) ==== gpsd ==== - Fix for gpsprof gnuplot command injection via attacker-controlled GPS metadata (CVE-2026-58459 [bsc#1271191]) + 4c06658.patch + 5581ba1.patch + 1a6bb7b.patch ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-common grub2-snapper-plugin - Backport merged upstream patch * 0001-lvm-allocate-metadata-buffer-from-raw-contents.patch - Drop local patch * grub2-lvm-allocate-metadata-buffer-from-raw-contents.patch - Backport merged upstream patch * 0001-net-http-Check-result-of-grub_netbuff_put-in-http_re.patch * 0002-efinet-Add-structures-for-PXE-messages.patch * 0003-efinet-bootp-add-net_dhcp6-command-supporting-dhcpv6.patch * 0004-grub.texi-Add-net_dhcp6-document.patch * 0005-bootp-Process-DHCPACK-packet-during-HTTP-Boot.patch * 0006-efinet-Configure-network-from-UEFI-device-path.patch * 0007-efinet-Set-DNS-server-from-UEFI-protocol.patch * 0008-kern-efi-efi-Print-URI-and-DNS-device-path-info.patch * 0009-kern-efi-efi-Correct-endianness-in-IPv6-device-path.patch * 0010-bootp-Fix-logical-operator-in-DHCP-option-overload-c.patch - Drop local patch * 0003-bootp-New-net_bootp6-command.patch * 0004-efinet-UEFI-IPv6-PXE-support.patch * 0005-grub.texi-Add-net_bootp6-doument.patch * 0006-bootp-Add-processing-DHCPACK-packet-from-HTTP-Boot.patch * 0007-efinet-Setting-network-from-UEFI-device-path.patch * 0008-efinet-Setting-DNS-server-from-UEFI-protocol.patch - Refreshed patch * 0001-add-support-for-UEFI-network-protocols.patch * grub2-bsc1220338-key_protector-implement-the-blocklist.patch ==== kactivitymanagerd6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kde-cli-tools6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kde-gtk-config6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: kde-gtk-config6-gtk3 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kdecoration6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libkdecorations3-6 libkdecorations3private2 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kdeplasma6-addons ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * applets/colorpicker: allow space for all previews (kde#522377) * applets/quicklaunch: avoid infinite regression on edge change * Fix colorpicker button sizing (kde#522377) * [Vietnamese Lunar Calendar] Force using Vietnamese translation (kde#521787) * MediaFrame: Set proper sourceSize to both Image instances (kde#521534) * kdeds/kameleon: Disable kameleon by default (kde#521793) ==== kernel-source ==== Version update (7.1.3 -> 7.1.4) Subpackages: kernel-64kb kernel-default - Update patches.kernel.org/7.1.2-002-fuse-re-lock-request-before-replacing-page-cach.patch (bsc#1012628 CVE-2026-53388). - Update patches.kernel.org/7.1.2-005-iio-light-veml6075-add-bounds-check-to-veml6075.patch (bsc#1012628 CVE-2026-53387). - Update patches.kernel.org/7.1.2-006-iio-adc-ti-ads1298-add-bounds-check-to-pga_sett.patch (bsc#1012628 CVE-2026-53386). - Update patches.kernel.org/7.1.2-008-vc_screen-fix-null-ptr-deref-in-vcs_notifier-du.patch (bsc#1012628 CVE-2026-53385). - Update patches.kernel.org/7.1.2-010-serial-8250_dw-unregister-8250-port-if-clk_noti.patch (bsc#1012628 CVE-2026-53384). - Update patches.kernel.org/7.1.2-012-ksmbd-reject-non-VALID-session-in-compound-requ.patch (bsc#1012628 CVE-2026-53383). - Update patches.kernel.org/7.1.2-013-media-vidtv-fix-NULL-pointer-dereference-in-vid.patch (bsc#1012628 CVE-2026-53382). - Update patches.kernel.org/7.1.2-014-virtiofs-fix-UAF-on-submount-umount.patch (bsc#1012628 CVE-2026-53381). - Update patches.kernel.org/7.1.3-001-KVM-x86-Fix-shadow-paging-use-after-free-due-to.patch (bsc#1012628 CVE-2026-53359 bsc#1270059). - Update patches.kernel.org/7.1.3-006-batman-adv-tp_meter-avoid-divide-by-zero-for-de.patch (bsc#1012628 CVE-2026-63836). - Update patches.kernel.org/7.1.3-018-batman-adv-v-prevent-OGM-aggregation-on-disable.patch (bsc#1012628 CVE-2026-63835). - Update patches.kernel.org/7.1.3-019-batman-adv-tp_meter-restrict-number-of-unacked-.patch (bsc#1012628 CVE-2026-63834). - Update patches.kernel.org/7.1.3-028-ipv6-account-for-fraggap-on-the-paged-allocatio.patch (bsc#1012628 CVE-2026-53362 bsc#1269493). - Update patches.kernel.org/7.1.3-029-ipv4-account-for-fraggap-on-the-paged-allocatio.patch (bsc#1012628 CVE-2026-53366 bsc#1271366). - Update patches.kernel.org/7.1.3-030-ntfs3-reject-direct-userspace-writes-to-reserve.patch (bsc#1012628 CVE-2026-63833). - Update patches.kernel.org/7.1.3-031-wifi-mt76-add-wcid-publish-check-in-mt76_sta_ad.patch (bsc#1012628 CVE-2026-63832). - Update patches.kernel.org/7.1.3-032-mac802154-llsec-add-skb_cow_data-before-in-plac.patch (bsc#1012628 CVE-2026-63831). - Update patches.kernel.org/7.1.3-033-net-skmsg-preserve-sg.copy-across-SG-transforms.patch (bsc#1012628 CVE-2026-63830). - Update patches.kernel.org/7.1.3-034-net-ip_gre-require-CAP_NET_ADMIN-in-the-device-.patch (bsc#1012628 CVE-2026-63829). - Update patches.kernel.org/7.1.3-036-apparmor-mediate-the-implicit-connect-of-TCP-fa.patch (bsc#1012628 CVE-2026-63828). - Update patches.kernel.org/7.1.3-037-apparmor-fix-use-after-free-in-rawdata-dedup-lo.patch (bko#221513 bsc#1012628 CVE-2026-63827). - Update patches.kernel.org/7.1.3-039-fbdev-fix-use-after-free-in-store_modes.patch (bsc#1012628 CVE-2026-63826). - Update patches.kernel.org/7.1.3-045-gcov-use-atomic-counter-updates-to-fix-concurre.patch (bsc#1012628 CVE-2026-63825). - Update patches.kernel.org/7.1.3-046-KEYS-fix-overflow-in-keyctl_pkey_params_get_2.patch (bsc#1012628 CVE-2026-63824). - Update patches.kernel.org/7.1.3-047-keys-Pin-request_key_auth-payload-in-instantiat.patch (bsc#1012628 CVE-2026-63823). - Update patches.kernel.org/7.1.3-052-wifi-ath11k-fix-warning-when-unbinding.patch (bsc#1012628 CVE-2026-63822). - Update patches.kernel.org/7.1.3-056-wifi-rtw88-usb-fix-memory-leaks-on-USB-write-fa.patch (bsc#1012628 CVE-2026-63821). - Update patches.kernel.org/7.1.3-060-f2fs-fix-missing-read-bio-submission-on-large-f.patch (bsc#1012628 CVE-2026-63820). - Update patches.kernel.org/7.1.3-063-f2fs-fix-to-do-sanity-check-on-f2fs_get_node_fo.patch (bsc#1012628 CVE-2026-63819). - Update patches.kernel.org/7.1.3-064-f2fs-validate-orphan-inode-entry-count.patch (bsc#1012628 CVE-2026-63818). - Update patches.kernel.org/7.1.3-065-f2fs-validate-compress-cache-inode-only-when-en.patch (bsc#1012628 CVE-2026-63817). - Update patches.kernel.org/7.1.3-066-f2fs-atomic-fix-UAF-issue-on-f2fs_inode_info.at.patch (bsc#1012628 CVE-2026-63816). - Update patches.kernel.org/7.1.3-068-f2fs-bound-i_inline_xattr_size-for-non-inline-x.patch (bsc#1012628 CVE-2026-63815). ... changelog too long, skipping 1114 lines ... - commit 342bd0e ==== kf6-attica ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Attica6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-baloo ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-baloo-file kf6-baloo-imports kf6-baloo-kioslaves libKF6Baloo6 libKF6BalooEngine6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * CI: Update clang-format job * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-bluez-qt ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-bluez-qt-imports libKF6BluezQt6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-breeze-icons ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6BreezeIcons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Inject version macros to all public headers * Remove duplicated ECMSetupVersion include * Update dependency version to 6.28.0 * Avoid oversized Xcode script input lists * Don't include quiet packages in feature_summary * Update version to 6.28.0 ==== kf6-frameworkintegration ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-frameworkintegration-plugin libKF6Style6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-karchive ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Archive6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kauth ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6AuthCore6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Port to KWaylandExtras::exportToplevel * Update version to 6.28.0 ==== kf6-kbookmarks ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Bookmarks6 libKF6BookmarksWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcmutils ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kcmutils-imports libKF6KCMUtils6 libKF6KCMUtilsCore6 libKF6KCMUtilsQuick6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * KF6KCMUtilsQuick: inject version macros to all public headers * Update dependency version to 6.28.0 * kquickconfigmodule.h: remove unused QQmlComponent include * kcmloadtest: remove unused include * Update version to 6.28.0 ==== kf6-kcodecs ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Codecs6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * [KEncodingProber] Remove some unreachable Reset methods * [KEncodingProber] Reduce scope of some variables * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcolorscheme ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ColorScheme6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcompletion ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Completion6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kconfig ==== Version update (6.27.0 -> 6.28.0) Subpackages: kconf_update6 kf6-kconfig-imports libKF6ConfigCore6 libKF6ConfigGui6 libKF6ConfigQml6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * ksharedconfig: only free the shared config at exit under AddressSanitizer * ksharedconfig: free the per-thread shared config at application exit * Do not launch desktop helper processes on iOS and Android * Do not launch desktop helper processes on iOS * Update version to 6.28.0 ==== kf6-kconfigwidgets ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ConfigWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kcontacts ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Contacts6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * CMake config file: search static-build-only dependencies only on condition * Update version to 6.28.0 ==== kf6-kcoreaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kcoreaddons-imports libKF6CoreAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * KMemoryInfo: add basic GNU/Hurd support * KDirWatch_UnitTest: fix memory leaks * KFileSystemType: add custom determineFileSystemTypeImpl for Hurd * Switch to ECMGenerateExportHeader generating C++ standard attributes * aboutdata: Also fill componentName from AppStream data * Expose basic KSandbox properties to QML * Find AppStream files on Android * fix Clang-Tidy: Method 'test_locking' can be made static * fix Clang-Tidy: Static member accessed through instance * fix Clang-Tidy: Method 'test_fileStaleFiles' can be made static * aboutdata: Fix retrieving untranslated release notes * Update version to 6.28.0 ==== kf6-kcrash ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Crash6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kdbusaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kdbusaddons-tools libKF6DBusAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kdeclarative ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kdeclarative-imports libKF6CalendarEvents6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kded ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Disable startup notification for kded * Update version to 6.28.0 ==== kf6-kdesu ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Su6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kdnssd ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Correctly track Avahi service types * Add basic service browser example * Update version to 6.28.0 ==== kf6-kdoctools ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6DocTools6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kfilemetadata ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6FileMetaData3 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * OSS-Fuzz: serialize AFL fuzzer builds * Integrate KFileMetaData into OSS-Fuzz * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kglobalaccel ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6GlobalAccel6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kguiaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kguiaddons-imports libKF6GuiAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Use iOS-compatible platform and URL handling * Update version to 6.28.0 ==== kf6-kholidays ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kholidays-imports libKF6Holidays6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * holiday_et_am - fix region name * holidays: Add Ethiopian holidays (et_en, et_am) * Updated Croatian holidays as of 2026. * fix occurrence of Mother's Day and Father's Day in Slovakia * Update version to 6.28.0 ==== kf6-ki18n ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-ki18n-imports libKF6I18n6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * KTranscript: Use Q_APPLICATION_STATIC for impl (kde#520512) * fix: use system locale as fallback for macOS app bundle * klocalizedcontext: correctly place deprecation attribute after class keyword * Update version to 6.28.0 ==== kf6-kiconthemes ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kiconthemes-imports libKF6IconThemes6 libKF6IconWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Disable desktop-only KIconThemes tools and plugin on iOS * Update version to 6.28.0 ==== kf6-kidletime ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kidletime-plugins libKF6IdleTime6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Fully port to ecm_qt_declare_logging_category * Fix debug category name kf5idletime_wayland It's not a kf5 * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kimageformats ==== Version update (6.27.0 -> 6.28.0) - Add upstream change (kde#523105) * 0001-HEIF-keep-reader-callback-table-alive.patch - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * EXR: added support for additional metadata * Update dependency version to 6.28.0 * JP2: limits the maximum number of channels to the global value defined * ossfuzz: replace INITGUID with __ANSI__ * JXR: remove INITGUID define * ossfuzz: update libaom and libavif * HEIF: use heif_reader for random access devices * avif: If we only have single image, return false at jumpToNextImage (kde#521200) * Added limit to maximum number of channels * Improve buffer memory management * Update version to 6.28.0 ==== kf6-kio ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6KIO6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Too many changes since 6.27.0, only listing bugfixes: * mkdirjob: add setOwnership to set uid/gid (kde#517067) * deletejob: report files removed before a partial failure (kde#424545) * kfileitem: do not read .directory on slow filesystems in iconName (kde#519189) * widgets/kfileitem: center small icons in grid view (kde#520659) ==== kf6-kirigami ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kirigami-imports libKirigamiPlatform6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Action: only enable alternateShortcut when the action is enabled * FormEntry: fix binding loop * Update dependency version to 6.28.0 * FormEntry: always be hoverEnabled * forms: Dont put items at fractional positions * AbstractApplicationWindow: Fix applications that use an header item (kde#521552) * primitives: Base Icon's node size on icon size, not item size (kde#391315) * AlignedSize: fix docs * controls/private/DefaultChipBackground.qml: remove wrong colorSet * Update version to 6.28.0 ==== kf6-kitemmodels ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kitemmodels-imports libKF6ItemModels6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kitemviews ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ItemViews6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kjobwidgets ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6JobWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-knewstuff ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-knewstuff-imports libKF6NewStuffCore6 libKF6NewStuffWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-knotifications ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-knotifications-imports libKF6Notifications6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * android: Modernize JNI code * Update version to 6.28.0 ==== kf6-knotifyconfig ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6NotifyConfig6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kpackage ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Package6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kparts ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Parts6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Dont copy kaboutdata into khelpmenu * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kpty ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Pty6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kquickcharts ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-krunner ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Runner6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * KRunner::ResultsModel: remove unneeded QIcon include * Update version to 6.28.0 ==== kf6-kservice ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Service6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * services/kservicegroup: include storageId in sorting key (kde#516802) * Update version to 6.28.0 ==== kf6-kstatusnotifieritem ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6StatusNotifierItem6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-ksvg ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-ksvg-imports libKF6Svg6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * KF6Svg: drop publically unused KF6::ConfigCore from public link interface * KSvg::ImageSet: remove unneeded KSharedConfig include * Update version to 6.28.0 ==== kf6-ktexteditor ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6TextEditor6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Fix typo in settings (kde#https://bugs.kde.org/522337) * vi-mode: Fix reversed mouse selection range (kde#454417) * vi-mode: Fix command range for mouse selection (kde#454312) * vi-mode: Implement read-only registers: search and command * Update dependency version to 6.28.0 * vi-mode: Fix register for last inserted text * vi-mode: Simplify validation of register characters * Change setting wording * Word cursor movement: Only stop at underscores in camel cursor * vi-mode: Shorten names for VI modes on the status bar * vi-mode: Allow count for multiple undo/redo * add editor color theme preview icon to config page combo boxes * show preview icons for editor color themes * themeconfig: Set file type instead of highlighting mode * Update version to 6.28.0 ==== kf6-ktextwidgets ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kunitconversion ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6UnitConversion6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * ADD: Wh (watt-hour) energy conversion * Update version to 6.28.0 ==== kf6-kuserfeedback ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kuserfeedback-imports libKF6UserFeedbackCore6 libKF6UserFeedbackWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Inject version macros to all public headers * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-kwallet ==== Version update (6.27.0 -> 6.28.0) Subpackages: kwalletd6 libKF6Wallet6 libKF6WalletBackend6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * fix(ksecretd): reject invalid UTF-8 in `SetSecret`/`CreateItem` instead of silent corruption * Update version to 6.28.0 ==== kf6-kwidgetsaddons ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6WidgetsAddons6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * KJobWidgets: place deprecation attribute standard-type-clang-compatible * Update dependency version to 6.28.0 * Exclude KMimeTypeEditor from iOS builds * Update version to 6.28.0 ==== kf6-kwindowsystem ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-kwindowsystem-imports libKF6WindowSystem6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * platforms/xcb: Handle Xwayland restarts better * platforms/xcb: Manage atoms with a shared pointer * Update dependency version to 6.28.0 * Restore guard for null window in exportWindow (kde#521241) * Provide a future based API to export a window * Update version to 6.28.0 ==== kf6-kxmlgui ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6XmlGui6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Support modifier-only shortcuts in KShortcutsEditor (kde#518302) * Refactor internal KShortcutsEditor bits to support shortcut patterns * don't call moveValuesTo on invalid source (kde#520556) * Update version to 6.28.0 ==== kf6-modemmanager-qt ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6ModemManagerQt6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-networkmanager-qt ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-networkmanager-qt-imports libKF6NetworkManagerQt6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-prison ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-prison-imports libKF6Prison6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Fix documentation syntax * Update dependency version to 6.28.0 * Add support for rendering ITF and Codabar barcodes * Update version to 6.28.0 ==== kf6-purpose ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-purpose-services libKF6Purpose6 libKF6PurposeWidgets6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Fix constraints not being evaluated correctly (kde#521138) * Update version to 6.28.0 ==== kf6-qqc2-desktop-style ==== Version update (6.27.0 -> 6.28.0) - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * ComboBox: Fix width calculation in some situations (kde#522453) * Update dependency version to 6.28.0 * Set implicitWidth for ComboBox popups * Update version to 6.28.0 ==== kf6-solid ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Solid6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * windows: do not query drives without a reachable volume * Allow discovery of Samba shares under BSD. * fix: add missing ARM CPU part numbers from util-linux lscpu-arm.c * QDoc fixes * Update version to 6.28.0 ==== kf6-sonnet ==== Version update (6.27.0 -> 6.28.0) Subpackages: kf6-sonnet-imports libKF6SonnetCore6 libKF6SonnetUi6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-syndication ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6Syndication6 - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Update dependency version to 6.28.0 * Update version to 6.28.0 ==== kf6-syntax-highlighting ==== Version update (6.27.0 -> 6.28.0) Subpackages: libKF6SyntaxHighlighting6 - Add upstream fix: * 0001-Fix-listening-for-language-changes-just-react-on-the.patch - Update to 6.28.0 * New feature release * For more details please see: * https://kde.org/announcements/frameworks/6/6.28.0 - Changes since 6.27.0: * Invalidate cached translations when language changes * Powershell: fix parentheses matching in command substitution with function calls (kde#519774) * Powershell: fix Numeric Suffix when the previous line ends with number * Update dependency version to 6.28.0 * make build reproducable * adapt refs to fixed scope highlighting * Fixes formatting for scopes containing types like 'std::char' or 'std::str::Bytes' which contain 'str' and 'char' * systemd unit: update to systemd v261 * YAML: fix some bad indentation detection, add Timestamp and fix some defects * Fish: end keyword of function as Keyword instead of Control Flow * Fish: use the "Function Doc" style for strings with --description followed by spaces (kde#521369) * Theme: Add preview icon * Zsh: remove String Transl. which does not exist in zsh * Bash: fix String Transl. highlingting (was a String DoubleQ) * Bash: fix context pop of brace command substitution (${ cmd}/${|cmd}) (kde#521069) * Update version to 6.28.0 ==== kgamma6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kglobalacceld6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKGlobalAccelD6-0 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kinfocenter6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kirigami-addons6 ==== Version update (1.12.1 -> 1.13.0) Subpackages: libKirigamiAddonsComponents6 libKirigamiAddonsStatefulApp6 libKirigamiApp6 - Update to 1.13.0 * Fix reference error in about page program icon * Avoid unneeded KCoreAddons version include * FormComboBoxDelegate: Forward more ComboBox APIs * Add a button to reset a time picker back to the current time * Enable KCrash integration on Android * AboutPage: Sync with Kirigami changes to program icon * Replace image in qml-check-i18n job * FormDelegateBackground: Use Kirigami.Units.cornerRadius * Do not explicitly link against Qt6::QuickEffect in onboarding module * Add explicit linkage against Qt6::QuickEffects for apps using the onboarding module * Add org.kde.kirigamiaddons.onboarding module documentation * Fix org.kde.kirigamiaddons.onboarding issues on Android/iOS * Make KCrash and Linux sandbox integration optional on iOS * FormSpinBoxDelegate: Alias more properties and signals * Add new org.kde.kirigamiaddons.onboarding module * KirigamiAppDefaults: Clean up ifdefs * Require Qt 6.9 for unconditional use of the SafeArea API * Form*FieldDelegate: Fix text property not yet updated on signal trigger * Form*FieldDelegate: Add more aliases to input field * FormCard: Fix implicitWidth * Add missing QML module dependencies to Qt.labs.qmlmodels ==== kmenuedit6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== knighttime6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKNightTime0 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kpipewire6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: kpipewire6-imports libKPipeWire6 libKPipeWireDmaBuf6 libKPipeWireRecord6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Restore binary compatibility ==== kscreen6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Take locale into account when formatting refresh rate ==== kscreenlocker6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKScreenLocker6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== ksshaskpass6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== ksystemstats6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Fix crashes in KSysGuard::SensorObject::id() * Guard ksystemstats_intel_helper against path traversal - Drop patches, now upstream: * 0001-Guard-ksystemstats_intel_helper-against-path-travers.patch ==== kwayland-integration6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kwayland6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKWaylandClient6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== kwin6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libkwin6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * wayland: Implement wl_fixes v2 * wayland/tools: Make generated globals set "withdrawn" callbacks * workspace: remove sleep inhibitor if the dpms animation is canceled (kde#523001) * pointer_input: fix waking up screens that temporarily disconnect during dpms (kde#518271) * vulkan/vulkan_device: use a graphics queue instead of transfer * opengl/eglcontext: always bind the desired EGL API before context creation (kde#521742) * backends/drm: allow triple buffering on Nvidia again * autotests: Rework how EI events are drained * effects: Forward tablet events to OffscreenQuickView (kde#468396,kde#522677) * core/drmdevice: also print the error when opening a render node fails * autotests/integration/drm_test: filter out broken VM drivers * autotests/integration/drm_test: fix cases not currently tested in CI * autotests/integration: use framebuffer IDs for comparing buffers * opengl/icc_shader: don't use GL_TEXTURE_1D * plugins/overview: fix middle click with touchpads (kde#522015) * compositor: also set dmabuf feedback if buffer import fails * core/gpumanager: fix the Vulkan device check * libinput: Fix Device::serializeMatrix (kde#521464) * dpmsinputeventfilter: also wake screens on laptop lid open (kde#466748) * backends/drm: apply the amdgpu workaround in both matchPipeline methods * backends/drm: match color pipelines already in importScanoutBuffer (kde#522075) * compositor: attempt direct scanout before preparing rendering * plugins/screencast: in testCreateDmaBuf, also create a framebuffer * wayland/alphamodifier: track the per-surface object * Avoid updating shape when an override-redirect window is moved ==== layer-shell-qt6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libLayerShellQtInterface6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libdrm ==== Subpackages: libdrm2 libdrm_amdgpu1 - add upstream signing key and validate source signature ==== libkscreen6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libKF6Screen8 libKF6ScreenDpms8 libkscreen6-plugin - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libksysguard6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: ksysguardsystemstats6-data libKSysGuardSystemStats2 libksysguard6-imports - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libplasma6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasma7 libplasma6-components libplasma6-desktoptheme - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== libseccomp ==== - Skip tests/52-basic-load.py under qemu emulation ==== libsoup ==== - Rename libsoup-CVE-2026-0716.patch to libsoup-CVE-2026-12478.patch to reflect the new CVE assignment (bsc#1271401 CVE-2026-12478). - Add fix-samsung-tv-playback.patch: Update the content length decimal value when encoding is set to SOUP_ENCODING_CONTENT_LENGTH - Refresh patches with quilt. ==== libtool ==== Version update (2.5.4 -> 2.6.2) - update to version 2.6.2 - Add a new tool, libtool-next-version, to guide users through updating library versions. - Add tagging for Objective-C and Objective-C++, OBJC and OBJCXX. - Increase 5 digit limit on revision value for libraries to 19 digits, which is referencing Unix epoch time in nanoseconds. - Add configuration options to choose whether to use '-nostdlib' to let the compiler frontend decide what standard libraries to link when building C++ shared libraries and modules, --enable-cxx-stdlib and - -disable-cxx-stdlib. - Allow statically linking GCC and Clang compiler support libraries into shared libraries. - Add linking clang_rt static archives compiler internal libraries by their absolute path. - Pass '--target' architecture flag for Clang. - Pass 'resource-dir=*' flag for Clang. - Recognise explicit shared library arguments when linking dependency libraries to a shared library, like exists when linking a program. ==== libupnp ==== Version update (2.0.2 -> 22.0.4) - Update to release 22.0.4 * Raise default SOAP content-length limit from 16K to 64K bytes. * Avoid potential double-unlocking of `GlobalHndRWLock` in function `UpnpSetContentLength`. * Stop resolving DNS during URI/GENA callback parsing [CWE-400 class issue]. * Removed deprecated function `UpnpSetContentLength`. ==== libzypp ==== Version update (17.38.13 -> 17.38.14) - zypp.conf: add solver.NoUpdateProvide (default: false) option. In general, packages that obsolete another package are treated as update candidates for the obsoleted package. However, SUSE-specific update rules prefer candidates that also explicitly 'provide' the obsoleted package. Sometimes it is necessary or helpful to disable this rule. (may help in bsc#1261038) - Use HttpHeader class for defining host specific http headers (bsc#1268321) - Compile and link with -fPIE to build on sparc64 (fixes #742) - version 17.38.14 (35) ==== milou6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== mozilla-nss ==== Version update (3.124 -> 3.125) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs - update to NSS 3.125 * no public releasenotes yet ==== ngtcp2 ==== Version update (1.22.1 -> 1.24.0) Subpackages: libngtcp2-16 libngtcp2_crypto_gnutls8 libngtcp2_crypto_ossl0 - Update to 1.24.0: * crypto: Add openssl libs to cryptotest * Add --disable-crypto configure option * crypto: Add ngtcp2_crypto_ossl_free * examples: Avoid the deprecated nghttp3 APIs * lib: Add recv_stop_sending callback * lib: Add ngtcp2_conn_set_max_stream_data_thresh * lib: Tweak ngtcp2_conn_set_max_stream_data_thresh * Remove max stream data thresh * Rewrite window filter from scratch * lib: Tweak app-limited detection * lib: Simplify app-limited conditions * Bump openssl to v4.0.1 * Bump boringssl * Bump aws-lc to v5.1.0 * Bump picotls * Bump wolfssl to v5.9.2-stable - Update to 1.23.0: * log: Faster logging * Use ULL consistently * Transit to closing state when sending application close * Specify QualifierOrder * Provide generic ngtcp2_max and ngtcp2_min * Add ngtcp2_secure_clear * Clear sensitive secrets and keys after use * Add const version * crypto: Add tests for token validation * Add const and remove duplicated code * Remove stale function declarations * crypto: Deal with overflow when computing token timeout * build(deps): bump actions/github-script from 8 to 9 * Revert "fix: prevent max_idle_timeout multiplication overflow in transport params decode" * Deal with large max_idle_timeout that could overflow in computation * Fix qlog params set stack overflow * Log enhancement * Bump LibreSSL to v4.3.1 by @nak3 in #2161 * pq: Adopt designated initializers * Add missing initialization for fields that are not used for CRYPTO * rst: Rename TCP centric variable names * bbr: Cap maximum drain rounds * GHA: Avoid azure Ubuntu mirror * Bump openssl to v4.0.0 * Bump boringssl * Bump picotls * Bump wolfssl to v5.9.1-stable * Bump aws-lc to v1.73.0 * Bump wolfssl to v5.9.1-stable in interop Dockerfile * lib: Apply absolute upper bound against CRYPTO data offset * Adopt sphinx version-add and version-deprecated directives * ppe: Robust ngtcp2_ppe_padding_size * ppe: Ensure packet protection sample with ngtcp2_ppe_dgram_padding_size * cubic: Add missing is_cwnd_limited reset after exiting slow start * Make bitwise operations robust * Make all private hex constants unsigned * lib: Ensure that unidirectional stream shutdown flags properly set * More unsigned hex integer literals * Fix strict aliasing issue in ngtcp2_get_varint * Net cleanup * Bump boringssl * Bump picotls * Bump libressl to v4.3.2 * Consider static const if possible ==== ntfs-3g_ntfsprogs ==== Subpackages: libntfs-3g89 ntfs-3g ntfsprogs - Adding patch bundle from upstream (download.tuxera.com/opensource) re:cve_2026-04 for v2022.10.3 * bsc#1271104 -> 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch * bsc#1271102 -> 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch * bsc#1271103 -> 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch * bsc#1271105 -> 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch * bsc#1271107 -> 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch * bsc#1271106 -> 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch * bsc#1271108 -> 7_ntfs-3g_2022.10.3-CVE-2026-46572.patch - This file is identical to 3_...42617.patch * bsc#1271109 -> 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch * bsc#1271110 -> 9_ntfs-3g_2022.10.3-CVE-2026-56136.patch - This file is identical to 3_...42617.patch ==== open-iscsi ==== Subpackages: iscsiuio libopeniscsiusr0 - Update to version 2.1.12.suse+0.8f77cf16: * Preparing for version 2.1.12 (#536) * Fix security issues recently discovered by Keith at Linneman Labs (#535) (CVE-2026-44943 and CVE-2026-44944) * iscsi-init.service: Use iscsi-gen-initiatorname * iscsi-gen-initiatorname use @IQN_PREFIX@ as default * avoid possible double free of found in idbm_rec_update_param (#528) * iscsi: validate interface IP against target address family (#527) ==== open-vm-tools ==== Subpackages: libvmtools0 - Remove all dependencies on update-desktop-files - open-vm-tools (PED-15231) Remove BuildRequires: update-desktop-files and %suse_update_desktop_file vmware-user-autostart from the spec file. ==== openssl-3 ==== Subpackages: libopenssl3 - Security fix: (bsc#1271712) * "HollowByte" DoS via attacker-controlled memory allocation. * Grow the init_buf incrementally as we receive data. * Add openssl-HollowByte.patch ==== patterns-base ==== Subpackages: patterns-base-base patterns-base-bootloader patterns-base-minimal_base patterns-base-x11 - Suggest sudo-rpm to give the solver a hint to prefer sudo.rpm over alternative dropins [bsc#1267899] ==== perl ==== Version update (5.42.1 -> 5.44.0) Subpackages: perl-base - update to 5.44.0 * support named parameters in signatures * support aliased refs in mult-var foreach * enhanced /xx regexp pattern modifier * unicode 17.0 is supported * use of getentropy() for PRNG initialization * refreshed patches: perl-HiRes.t-timeout.diff ==== permissions ==== Version update (1699_20260707 -> 1699_20260715) Subpackages: permctl permissions-config - Update to version 1699_20260715: * profiles: add cap_net_raw for ttl (bsc#1270714) ==== pipewire ==== Version update (1.6.7 -> 1.6.8) Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Update to version 1.6.8: * This is a bugfix release that is API and ABI compatible with the previous 1.6.x releases. * Highlights - Fix a data race in JACK that could cause lost MIDI events in ardour. - Fix some unbounded memory allocations. - Various small fixes. * PipeWire - Avoid some graph recalcs, which fixes a bug when suspending a node while it is active. * Modules - Do Content-Length and allocation check in RAOP to avoid OOM errors. - Fix a potential memory leak in the error path of client-node. (#5348 (closed)) * SPA - Fix filter-graph dynamic graph updates. - Avoid 100% when unplugging a card. - Fix filter-graph volumes when the filter is loaded inside a node with hardware volume. (#5344 (closed)) - Add normalize and latency options to the SOFA filter. (#5322) * Bluetooth - Fix a potential leak when transport fails to start. * Pulse-server - Avoid stack exhaustion via unbounded alloca. * JACK - Fix a data race in jack_port_get_buffer() when called from concurrent threads, like in ardour. (#5324 (closed)) * GStreamer - Skip invalid crop metadata. - Avoid crash because metadata listener was registered twice. ==== plasma5support6 ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasma5Support6 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-activities ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasmaActivities7 plasma6-activities-imports - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-activities-stats ==== Version update (6.7.2 -> 6.7.3) Subpackages: libPlasmaActivitiesStats1 - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-browser-integration ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-desktop ==== Version update (6.7.2 -> 6.7.3) Subpackages: plasma6-desktop-emojier - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * kcms/mouse: actually disable if there is only one device * applets/kicker: fix runner list keyboard navigation * kcms/libkwindevices: Fix serializeMatrix serializing in the wrong order ==== plasma6-integration ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * qt6: Skip loading palettes when widget style changes ==== plasma6-nm ==== Version update (6.7.2 -> 6.7.3) Subpackages: plasma6-nm-openconnect plasma6-nm-openvpn - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-openSUSE ==== - Update to 6.7.3 ==== plasma6-pa ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-print-manager ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * kcm: Use Kirigami.StyleHints.showFramedBackground for ScrollView ==== plasma6-systemmonitor ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== plasma6-workspace ==== Version update (6.7.2 -> 6.7.3) Subpackages: plasma6-session plasma6-workspace-libs - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * applets/kicker: Fix counting of m_queryingModels in RunnerModel * runners/services: handle malformed .desktop file names better * applets/kicker: return empty url for systemmodel * components/calendar: fix use-after-free of shared calendar event plugins (kde#520465) * kcm_soundtheme: fix preview sounds not playing (kde#521699) * libkworkspace: make sure outputOrderChanged() is always triggered (kde#518058) * klipper: fix spacing on shortcuts configuration page * kcm_nightlight.json, kcm_notifications.json: fix BugReportUrl * startkde: Log the global theme that gets applied * applets/digital-clock: fix timezone offset (kde#522037) * Klipper: Fix spacing on the action configuration page ==== policycoreutils ==== Subpackages: policycoreutils-python-utils python313-policycoreutils - Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645) - can be dropped once "policycoreutils/scripts/fixfiles: drop /tmp cleanup" is in the upstream release - Add patch: 1271645-drop-tmp-cleanup.patch ==== polkit ==== Subpackages: libpolkit-agent-1-0 libpolkit-gobject-1-0 typelib-1_0-Polkit-1_0 - pkexec: add provides pkexec-rpm to be able to give the solver a hint that this is the real pkexec.rpm [bsc#1267899] ==== polkit-kde-agent-6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== poppler ==== Version update (26.06.0 -> 26.07.0) - Update to version 26.07.0: + core: * Remove deprecated DCT and JPX decoders. * Fix signature regression in some cases. * Fix added annotations getting lost in some cases. * GPG based signature improvements. * Internal code improvements. * Fix crashes in malformed documents. + utils: pdfinfo: sanitize output. + cpp: Add render_hint::ignore_paper_color to allow transparent paper. + glib: construct PopplerPage::mutex (fixes crash on macOS). + qt5: Fix crash in some signature operations. + qt6: Fix crash in some signature operations. - Bump poppler_sover to 162 following upstream changes. ==== poppler-qt6 ==== Version update (26.06.0 -> 26.07.0) - Update to version 26.07.0: + core: * Remove deprecated DCT and JPX decoders. * Fix signature regression in some cases. * Fix added annotations getting lost in some cases. * GPG based signature improvements. * Internal code improvements. * Fix crashes in malformed documents. + utils: pdfinfo: sanitize output. + cpp: Add render_hint::ignore_paper_color to allow transparent paper. + glib: construct PopplerPage::mutex (fixes crash on macOS). + qt5: Fix crash in some signature operations. + qt6: Fix crash in some signature operations. - Bump poppler_sover to 162 following upstream changes. ==== powerdevil6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * BrightnessItem: only do slider->Upower when dragging the slider ==== python-pyasn1 ==== Version update (0.6.3 -> 0.6.4) - Update to 0.6.4 (fixes CVE-2026-59884 (bsc#1271464), CVE-2026-59885 (bsc#1271465), CVE-2026-59886 (bsc#1271466)) * CVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time complexity in the OBJECT IDENTIFIER and RELATIVE-OID decoders. A small crafted substrate encoding many arcs could consume excessive CPU. Arcs are now accumulated in linear time; decoded values are unchanged * CVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag IDs to 20 octets (140 bits), matching the OID arc limit introduced in 0.6.2. Unbounded tag IDs allowed a crafted substrate to consume excessive CPU and memory; longer tag IDs are now rejected with PyAsn1Error. Also fixed Tag and TagSet repr() failing on huge tag IDs due to the integer-to-string conversion limit * CVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and CPU consumption in Real.__float__() for values with large base-10 exponents. Conversion no longer materializes huge intermediate integers; values too large to represent as a Python float raise OverflowError promptly, and prettyPrint() renders them as '' as before. Also fixed base-10 mantissa normalization to use exact integer arithmetic; mantissas larger than 2**53 could previously lose precision through float division * Pinned PyPI publish GitHub Action to an immutable commit ==== python313 ==== Version update (3.13.13 -> 3.13.14) - CVE-2026-11940: fix the symlink escape via tarfile hardlink-extraction fallback (bsc#1268977) CVE-2026-11940-tarfile-escape.patch - CVE-2025-15367: reject control characters in POP3 commands (bsc#1257041) CVE-2025-15366-pop3-ctrl-chars.patch - CVE-2025-15366: reject control characters in IMAP commands (bsc#1257044, gh#python/cpython!143922) CVE-2025-15366-imap-ctrl-chars.patch - Update to 3.13.14: - Security - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. - gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328) - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter. - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) - Core and Builtins - gh-151112: Fix a crash in the compiler that could occur when running out of memory. - gh-151126: Fix a crash, when there’s no memory left on a device, which happened in: - code compilation - _winapi.CreateProcess() - Now these places raise proper MemoryError errors. - gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. - gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. - gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. ... changelog too long, skipping 232 lines ... - CVE-2026-6100-use-after-free-decompression.patch ==== python313-core ==== Version update (3.13.13 -> 3.13.14) Subpackages: libpython3_13-1_0 python313-base - CVE-2026-11940: fix the symlink escape via tarfile hardlink-extraction fallback (bsc#1268977) CVE-2026-11940-tarfile-escape.patch - CVE-2025-15367: reject control characters in POP3 commands (bsc#1257041) CVE-2025-15366-pop3-ctrl-chars.patch - CVE-2025-15366: reject control characters in IMAP commands (bsc#1257044, gh#python/cpython!143922) CVE-2025-15366-imap-ctrl-chars.patch - Update to 3.13.14: - Security - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. - gh-87451: The ftplib module’s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328) - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter. - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) - Core and Builtins - gh-151112: Fix a crash in the compiler that could occur when running out of memory. - gh-151126: Fix a crash, when there’s no memory left on a device, which happened in: - code compilation - _winapi.CreateProcess() - Now these places raise proper MemoryError errors. - gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. - gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. - gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. ... changelog too long, skipping 232 lines ... - CVE-2026-6100-use-after-free-decompression.patch ==== qemu ==== - Properly fix bsc#1268245: * [openSUSE][RPM] spec: fix missing unversioned ppc64 linker (bsc#1268245) ==== qqc2-breeze-style6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== rootlesskit ==== Version update (3.0.1 -> 3.0.2) - Update to version 3.0.2: * v3.0.2 * Build(deps): Bump golang.org/x/sync from 0.21.0 to 0.22.0 * api: expose IPv6 capability in NetworkDriverInfo * Build(deps): Bump golang.org/x/sys from 0.46.0 to 0.47.0 * Build(deps): Bump golang.org/x/sync from 0.20.0 to 0.21.0 * Build(deps): Bump golang.org/x/sys from 0.45.0 to 0.46.0 * chore(deps): update golang.org/x/crypto v0.52.0, golang.org/x/net v0.55.0 * Build(deps): Bump actions/checkout from 6 to 7 * v3.0.1+dev ==== run0-wrappers ==== Version update (0.4+git20260203.bbbfcf8 -> 0.5.0+git20260717.efd7268) - Update to version 0.5.0+git20260717.efd7268: * Release version 0.5.0 * run0-sudo: support environment variables in commandline (#5) * run0-sudo: add test for -k/-K option handling * sudo/su: Fix handling of environment variables with newlines * run0-sudo: improved version of -k/-K options (#6) ==== runc ==== Version update (1.4.2 -> 1.4.3) - update to 1.4.3 (bsc#1268275, CVE-2026-41579): * [CVE-2026-41579][] allowed a malicious image with a `/dev` symlink to have limited write access to the host filesystem in ways that our analysis indicates was too limited to be problematic in practice. This bug was very similar to those fixed in [CVE-2025-31133][], [CVE-2025-52565][], [CVE-2025-31133][] and was simply missed at the time when we hardened the rootfs preparation code. We have conducted a deeper audit and not found any other problematic cases. * Various integration test improvements. (#5222, #5237, #5226, [#5229], #5239, #5249, #5269, #5287, #5295, #5304) * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). - add vendor.tar.gz to bump x/net ==== sddm ==== - Introduce patch to make the default session configurable beyond xsessions/default.desktop and migrate to it: * 0001-Introduce-DefaultSession-option-in-sddm.conf.patch * 0002-Migrate-from-default.desktop-to-General-DefaultSessi.patch - Drop then unnecessary hunk from 0001-Read-the-DISPLAYMANAGER_AUTOLOGIN-value-from-sysconf.patch - Rebase 0003-Leave-duplicate-symlinks-out-of-the-SessionModel.patch ==== sddm-kcm6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== sddm-qt6 ==== Subpackages: sddm-greeter-qt6 - Introduce patch to make the default session configurable beyond xsessions/default.desktop and migrate to it: * 0001-Introduce-DefaultSession-option-in-sddm.conf.patch * 0002-Migrate-from-default.desktop-to-General-DefaultSessi.patch - Drop then unnecessary hunk from 0001-Read-the-DISPLAYMANAGER_AUTOLOGIN-value-from-sysconf.patch - Rebase 0003-Leave-duplicate-symlinks-out-of-the-SessionModel.patch ==== selinux-policy ==== Version update (20260702 -> 20260715) Subpackages: selinux-policy-targeted - fix cleanoldsepoldir.sh to properly handle migration markers when /var/lib/selinux doesn't exists (backported from SLFO_Main codebase) - Update to version 20260715: * Allow snapper_sdbootutil_plugin_t status and stop unit files(bsc#1271391) * Allow sdbootutil_t read and write snapperd_t pipes (bsc#1271391) - Update to version 20260713: * Fix wrong gen_requires in snapper_read_data_files (bsc#1271282) ==== shaderc ==== Version update (2026.2 -> 2026.3) - Update to release 2026.3 * HLSL compilation (i.e. sources for Direct3D) is deprecated and will be removed in a future version. ==== spectacle ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Fix lack of mouse release events when making windows transparent to input after double click (kde#513715) ==== sqlite3 ==== - Add sqlite3-tools and sqlite3-tools-tcl subpackages * Most other distributions have included a separate -tools package with these for a while, but we seemingly haven't been packaging them at all in openSUSE. * New tools include the ones packaged by debian trixie (showdb, showjournal, showstat4, showwal, sqldiff, and sqlite3_analyzer) along with sqlite3_rsync, which is recommended in sqlite3 docs * All tools are in -tools subpackage except for sqlite3_analyzer which is in -tools-tcl ==== srt ==== Version update (1.5.5 -> 1.5.6) - Update to version 1.5.6: + Security Notice: This release includes important security updates that address two significant CVE vulnerabilities affecting previous versions of the library. Users are strongly encouraged to upgrade to this version as soon as possible to benefit from these fixes and reduce exposure to the associated security risks. + The resolved CVEs are listed below: - CVE-2026-55869: Heap-Based Buffer Overflow in KMREQ Handling - CVE-2026-55868: Encryption State Machine Downgrade + Security Improvements: - Implemented security improvements for KMREQ buffer validation. This fix addresses a vulnerability where received message sizes were not verified against the destination buffer size during the copy process. The update enforces word-aligned validation to prevent overflows when copying to internal arrays. - Added strict validation of KMRSP wire length to prevent stack overflows. - Resolved an OOB read in LOSSREPORT range parsing. The logic previously read a "HI" sequence number word following a "LO" marker without verifying if the "HI" word existed in the wire payload. - Fixed an OOB read vulnerability in DROPREQ payload parsing. The handler now verifies that the wire payload meets the minimum 8-byte length requirement (two 32-bit sequence numbers) before attempting to process the request, preventing reads beyond the packet slot. - Introduced a guard in CRcvBuffer::dropMessage to reject requested drop ranges that extend beyond the end of the receiver buffer. + Important Bug Fixes: - Streamlined the library cleanup sequence by removing redundant post-cleaning of closed sockets. Architecture logic dictates that the Garbage Collector (GC) thread is the primary owner of socket deletion. Once the GC thread is joined, all sockets are considered deleted; further post-checks are unnecessary and avoid potential undefined behavior in cases where the library state might be corrupted. - Fixed a segmentation fault (SEGV) occurring during global or static initialization when ENABLE_HEAVY_LOGGING was active. + Build System Enhancements: - Transitioned the CI/CD pipeline to a robust Linux configuration matrix, serving as the modern replacement for Travis CI. The new system includes various platform and compiler combinations and incorporates specific fixes for MinGW builds and C++11 syntax compatibility. + Documentation Updates: Corrected a typographical error in the documentation regarding the separator used for searchParameters. ==== suse-module-tools ==== Version update (16.1.5 -> 16.1.6) Subpackages: suse-module-tools-scriptlets - Update to version 16.1.6: * Add 65-md-raid-properties.rules (bsc#1261555, jsc#PED-16120) Always set serialize_policy sysfs attribute to 1 for RAID1 arrays ==== systemsettings6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 ==== tar ==== - Add tar-acl_-prefix.patch: Avoid acl_ prefix for functions The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. ==== transactional-update ==== Version update (6.1.1 -> 6.1.3) Subpackages: dracut-transactional-update libtukit8 transactional-update-zypp-config tukit tukit-snapper-plugin tukitd - Version 6.1.3: * libtukit: Properly initialize econf_file - Version 6.1.2: * t-u: Fix certificate import [bsc#1271292] * libtukit: Catch plugin exception in destructor * libtukit: Migrate legacy libeconf calls to newer functionality ==== vim ==== Subpackages: vim-data-common vim-small - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). - Add vim-9.2.0780-modelinestrict-allow-wrap.patch: allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Upstream patch 9.2.0350 added the 'modelinestrict' option, enabled by default, whose hardcoded whitelist omits these two purely visual window-local options, so 'nowrap' in a modeline was silently ignored while every other setting on the same line was applied. - Update vim-7.3-name_vimrc.patch: point SYS_VIMRC_FILE at $VIMRUNTIME/suse.vimrc rather than /etc/vimrc, which we no longer own (bsc#1268162). - Update suse.vimrc: source /etc/vimrc at the end of the file, so that a local system vimrc still overrides the distribution defaults. - Drop vim-8.2.2411-globalvimrc.patch: its main.c fallback to suse.vimrc fired only when do_source() of /etc/vimrc returned FAIL, which an empty /etc/vimrc does not. A stale or empty /etc/vimrc therefore suppressed the distribution defaults entirely, losing 'syntax on', the cursor position restore and 'nomodeline' (bsc#1268162). - Build gvim against GTK 3 instead of GTK 4 (bsc#1270238). The GTK 4 clipboard code spins a nested main loop around gdk_clipboard_read_async(), which deadlocks gvim on paste, and its mime type negotiation does not interoperate with Qt clipboard owners. - -enable-gui=gtk4 also forces with_x=no in vim's configure, so gvim lost +X11, +xterm_clipboard, +xsmp and the CUT_BUFFER0 fallback. GTK 3 keeps native Wayland support: * Replace BuildRequires pkgconfig(gtk4) with pkgconfig(gtk+-3.0). * Pass --enable-gui=gtk3 and --with-x=yes in GUI_OPTIONS. ==== wayland ==== Version update (1.25.0 -> 1.26.0) Subpackages: libwayland-client0 libwayland-cursor0 libwayland-egl1 libwayland-server0 - Update to release 1.26 * A new wl_pointer.warp event, to notify a new pointer position without an end-user-initiated motion event. * A new wl_fixes.ack_global_remove request, to address races related to global remove events. * A new wl_display_remove_socket_fd() function to remove sockets previously added via wl_display_add_socket_fd(). * WAYLAND_DEBUG timestamps now use the "HH:MM:ss.xxxxxx" format, making them easier to read and compare with other logs. - Drop pre-Leap-16.x build logic ==== wget ==== - Fix metalink regression from CVE-2026-58469 fix See: commit 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf from https://gitlab.com/gnuwget/wget [bsc#1272219, CVE-2026-58469] * CVE-2026-58469.patch - ftp validate PASV/LPSV response address against control connection peer [bsc#1271320, CVE-2026-15146] * CVE-2026-15146.patch ==== xdg-desktop-portal-kde6 ==== Version update (6.7.2 -> 6.7.3) - Update to 6.7.3: * New bugfix release * For more details see https://kde.org/announcements/plasma/6/6.7.3 - Changes since 6.7.2: * Update version for new release 6.7.3 * Disable background portal on X11 (kde#522864) * appchooser: Unconfuse url vs filename (kde#521748) ==== xorg-x11-server ==== Version update (21.1.21 -> 21.1.24) Subpackages: xorg-x11-server-Xvfb - Update to version 21.1.24 - Replaced xorg-server-21.1.21.tar.xz with xorg-server-21.1.24.tar.xz - Dropped patches now included upstream: * bsc1260922_CVE-2026-33999_xkb-fix-buffer-re-use-in-_XkbSetCompatMap.patch (bsc#1260922, CVE-2026-33999) * bsc1260923_CVE-2026-34000_xkb-Fix-bounds-check-in-_CheckSetGeom.patch (bsc#1260923, CVE-2026-34000) * bsc1260924_CVE-2026-34001_miext-sync-Fix-use-after-free-in-miSyncTriggerFence.patch (bsc#1260924, CVE-2026-34001) * bsc1260925_CVE-2026-34002_0001-xkb-Fix-out-of-bounds-read-in-CheckModifierMap.patch (bsc#1260925, CVE-2026-34002) * bsc1260925_CVE-2026-34002_0002-xkb-Add-more-_XkbCheckRequestBounds.patch (bsc#1260925, CVE-2026-34002) * bsc1260926_CVE-2026-34003_0001-xkb-Add-additional-bound-checking-in-CheckKeyTypes.patch (bsc#1260926, CVE-2026-34003) * bsc1266294_CVE-2026-XXXX1_0007-dix-increase-XLFDMAXFONTNAMELEN-to-match-libXfont2-s.patch (bsc#1266294, CVE-2026-XXXX1) * bsc1266295_CVE-2026-XXXX2_0001-sync-fix-deletion-of-counters-and-fences.patch (bsc#1266295, CVE-2026-XXXX2) * bsc1266296_CVE-2026-XXXX3_0003-xkb-reject-key-types-with-num_levels-exceeding-XkbMa.patch (bsc#1266296, CVE-2026-XXXX3) * bsc1266297_CVE-2026-XXXX4_0004-xkb-clamp-nMaps-to-mapWidths-buffer-size-in-CheckKey.patch (bsc#1266297, CVE-2026-XXXX4) * bsc1266299_CVE-2026-XXXX6_0002-sync-restart-trigger-list-iteration-in-SyncChangeCou.patch (bsc#1266299, CVE-2026-XXXX6) * bsc1266300_CVE-2026-XXXX7_0005-glx-fix-reversed-length-check-in-ChangeDrawableAttri.patch (bsc#1266300, CVE-2026-XXXX7) * bsc1266301_CVE-2026-XXXX8_0006-saver-re-fetch-screen-private-after-CheckScreenPriva.patch (bsc#1266301, CVE-2026-XXXX8) * bsc1266302_CVE-2026-XXXX9_0001-dri2-Use-booleans-for-fake-front-buffer-tracking-in-.patch (bsc#1266302, CVE-2026-XXXX9) * bsc1266302_CVE-2026-XXXX9_0002-dri2-Deduplicate-attachments-in-do_get_buffer.patch (bsc#1266302, CVE-2026-XXXX9) * bsc1268893_CVE-2026-55999_0002-fb-mi-glamor-reject-glyphs-with-negative-dimensions.patch (bsc#1268893, CVE-2026-55999) * bsc1268893_CVE-2026-55999_0003-glamor-reject-fonts-with-per-glyph-metrics-exceeding.patch (bsc#1268893, CVE-2026-55999) * U_GLX-Free-the-tag-of-the-old-context-later.patch (bsc#1268894, CVE-2026-56000) * bsc1268894_CVE-2026-56000_0001-glx-free-old-context-tag-before-allocating-new-one-i.patch (bsc#1268894, CVE-2026-56000)