Packages changed: AppStream (1.1.3 -> 1.1.5) Mesa (26.1.5 -> 26.1.6) Mesa-drivers (26.1.5 -> 26.1.6) MicroOS-release (20260724 -> 20260802) NetworkManager PackageKit (1.3.5 -> 1.3.6) apparmor (5.0.1 -> 5.0.2) ca-certificates (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) chrony cockpit (361 -> 364) cockpit-podman (120 -> 128) cryptsetup (2.8.6 -> 2.8.7) faad2 (2.11.2.git13 -> 2.11.2.git18) fwupd (2.1.6 -> 2.1.7) gcc (15 -> 16) gcc16 (16.1.1+git8886 -> 16.1.1+git9481) glib2 (2.88.2 -> 2.88.3) grub2 gvfs hwinfo (25.4 -> 25.5) kernel-firmware-amdgpu (20260629 -> 20260717) kernel-firmware-bluetooth (20260629 -> 20260720) kernel-firmware-platform (20260629 -> 20260717) kernel-firmware-qcom (20260629 -> 20260717) kernel-source (7.1.4 -> 7.1.5) libapparmor (5.0.1 -> 5.0.2) libcontainers-common (20260429 -> 20260521) libeconf (0.8.3 -> 0.8.4) libheif (1.23.0 -> 1.23.1) libmysofa (1.3.3 -> 1.3.5) libndp (1.8 -> 1.9) libostree (2026.1 -> 2026.2) libpng16 (1.6.57 -> 1.6.58) librepo libssh (0.11.4 -> 0.11.5) libxmlb (0.3.27 -> 0.3.29) microos-tools (4.0+git24 -> 4.0+git28) multipath-tools (0.14.3+212+suse.f5d32098 -> 0.15~1+230+suse.d36a6a70) net-tools (3.14~alpha~git.20251212.7011617 -> 3.14~alpha~git.20260718.4f5bfb2) nghttp2 (1.69.0 -> 1.70.0) nghttp3 (1.15.0 -> 1.18.0) ntfs-3g_ntfsprogs (2022.10.3 -> 2026.7.7) nvme-cli (3.0~b.3 -> 3.0~b.4) open-lldp (1.1.1+87.f16f944 -> 1.1+110.f16f944) openssh (10.3p1 -> 10.4p1) pam (1.7.2+git12 -> 1.7.2+git48) pam-full-src (1.7.2+git12 -> 1.7.2+git48) permissions (1699_20260715 -> 1699_20260728) podman (5.8.3 -> 6.0.2) python-certifi (2026.5.20 -> 2026.7.22) qemu (11.0.2 -> 11.0.3) samba (4.24.3+git.475.629de6765b9 -> 4.24.5+git.481.dba78dbdea) selinux-policy (20260715 -> 20260727) shared-mime-info (2.4 -> 2.5.1) skopeo (1.22.2 -> 1.23.0) slirp4netns (1.3.3 -> 1.3.4) spice-vdagent sssd systemd (260.3 -> 261.2) tar tesseract-ocr (5.5.2 -> 5.5.3) update-bootloader (1.27 -> 1.28) util-linux (2.42.1 -> 2.42.2) util-linux-systemd (2.42.1 -> 2.42.2) vim wpa_supplicant wtmpdb (0.75.0+git20251130.0d8fe7a -> 0.76.0+git20260730.89c0861) zimg (3.0.6+20250919.gdf9c147 -> 3.0.6+20260720.g1ad1895) zstd === Details === ==== AppStream ==== Version update (1.1.3 -> 1.1.5) Subpackages: libAppStreamQt3 libappstream5 - Update to 1.1.5 Features: * sysinfo: Implement display size detection on macOS * sysinfo: Assume a more modern display for the handset chassis template * sysinfo: Assume a more modern display for the tablet chassis template * sysinfo: Initial code to autodetect the display size on Wayland * sysinfo: Handle fractional display scaling via xdg-output * Implement support for GCVE as vulnerability database provider * qt: Sync enum mirrors with the C library * qt: Add Artifact, Checksum, Reference, Review and Agreement wrappers * qt: Wrap missing C API on existing classes * reviews: Add simple interface to fetch ODRS reviews for a component * reviews: Implement support for submitting reviews Specification: * docs: Suggest using the longest display side for maximum size constraints Bugfixes: * qt: Add back wrong const Component::addBundle for ABI compatibility * qt: Use strndup for C string-list conversion * pool: Fix bidirectional wildcard search for modalias provides * Make GResources we need outlive main thread destruction * pool: Properly implement cancellation of load operations * sysinfo: Fix display-length setter overriding the shortest edge * relation-check: Don't zero the score if a required check errored * curl: Harden downloader by restricting protocols to only HTTP(S) * curl: Allow making POST requests and changing the user agent * curl: Fix retry-loop data corruption and don't blindly retry POST requests * yaml: Fix potential crashes when encountering missing relation entry values * yaml: Adjust tests and emitter to work around libfyaml string-quoting change * yaml: Ensure version relations are consistently quoted * qt: Fix buffer overrun in stringListToCharArray - Drop patches: * 0001-yaml-Fix-potential-crashes-when-encountering-missing.patch * 0001-yaml-Adjust-tests-and-emitter-to-work-around-libfyam.patch * 0001-yaml-Ensure-version-relations-are-consistently-quote.patch * 0001-trivial-yaml-Ensure-branding-color-values-are-also-c.patch ==== Mesa ==== Version update (26.1.5 -> 26.1.6) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.1.6 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.6 ==== Mesa-drivers ==== Version update (26.1.5 -> 26.1.6) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Update to 26.1.6 bugfix release - -> https://docs.mesa3d.org/relnotes/26.1.6 ==== MicroOS-release ==== Version update (20260724 -> 20260802) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== NetworkManager ==== Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Add 2462.patch: nm-initrd-generator: set parent for NBFT vlan connection (bsc#1259025, glfd#NetworkManager/NetworkManager!2462). - Add NetworkManager-initrd-generator-ip-hcn.patch: handle "ip=hcn" option in nm-initrd-generator, it generates an empty connection (PED-14534). ==== PackageKit ==== Version update (1.3.5 -> 1.3.6) Subpackages: PackageKit-backend-dnf5 libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Update to version 1.3.6 (bsc#1267250, CVE-2026-10294): + Bugfixes: - daemon: stop idle progress timer after flushing updates - tests: Actually run the daemon tests on CI using a helper - tests: daemon: Auto-answer interactive prompts from the test - tests: Refactor and reorganize tests - pk-client: Perform any state changes & teardown before g_task_return_*() - package-sack: Fix a double-free issue on PkTask - Ensure we can send SIGQUIT to spawned backends - Prevent a race between the test harness and pk_readline* for input - daemon: Do not accept symlinks as frontend socket - daemon: Return proper error codes for bad SetHints() input - Don't leak TESTDATADIR into production binaries - daemon: Whitelist ONLY_DOWNLOAD for specific transaction roles only - lib: Don't warn on generic D-Bus errors - Send SIGTERM to ask subprocesses to quit, instead of SIGQUIT - daemon: Check errno instead of kill() return values to determine why it failed - pk-client: Fix race between cancellation and TID/proxy assignment + Miscellaneous: - PkTransaction: Simplify the error quark creation - ci: Ensure D-Bus is available and running for all tests - docs: Add error-checking to PK usage example ==== apparmor ==== Version update (5.0.1 -> 5.0.2) - update to AppArmor 5.0.2 - several fixes in utils, parser and some profiles - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_5.0.2 for the upstream changelog - remove upstreamed patches: - curl.diff - lsblk-mr2147.diff - add nslookup.diff to fix nslookup output ==== ca-certificates ==== Version update (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) - Update to version 2+git20260727.241e0ff: * certbundle.run: fix case where cafile does not exist ==== chrony ==== Subpackages: chrony-pool-openSUSE - Potential incompatibility! Extend UsrEtc (/usr/etc) support to the main configuration: * Ship the vendor chrony.conf and the chrony.d pool defaults under /usr/etc instead of /etc. * chronyd.service now uses /etc/chrony.conf when it exists and falls back to /usr/etc/chrony.conf otherwise (chrony-usretc-service.patch) * Use the confdir directive for chrony.d so that files in /etc/chrony.d override same-named vendor files in /usr/etc/chrony.d * Preserve admin-modified /etc/chrony.conf and /etc/chrony.d/pool.conf across the upgrade via the standard .rpmsave migration scriptlets. * chrony.keys stays in /etc. * To add the new chrony.d overlay/fallback mechanism to existing configurations the "include" line at the end of /etc/chrony.conf needs to be replaced by the "confdir" line from the new /usr/etc/chrony.conf file. ==== cockpit ==== Version update (361 -> 364) Subpackages: cockpit-bridge cockpit-networkmanager cockpit-packagekit cockpit-system cockpit-ws cockpit-ws-selinux - Update to 364 * 364 - Bug fixes and translation updates * 363 - Translation updates * 362 - Bug fixes and translation updates - Drop CVE-2026-4802.patch as this was fixed upstream ==== cockpit-podman ==== Version update (120 -> 128) - Update to 128 * 128 - Translation and dependency updates * 127 - Avoid bogus page reloads on firefox * 126 - Bug fixes and translation updates - Update to 125 * 125 - Dependency updates * 124 - Translation and dependency updates - Update to 123 * 123 - Don't show Quadlet template units - Handle quadlet lifecycle errors - Translation update * 122 - Show description, version and documentation image labels - Bug fixes and translation updates * 120 - Update dependencies - Convert license headers to SPDX format ==== cryptsetup ==== Version update (2.8.6 -> 2.8.7) Subpackages: libcryptsetup12 - Update to 2.8.7: * Changes related to Linux kernel AF_ALG crypto userspace interface deprecation Linux kernel maintainers decided to deprecate the AF_ALG interface, which was heavily used by cryptsetup, with the plan to remove it (or severely limit it) for security reasons. Libcryptsetup uses userspace (primarily via AF_ALG) for processing LUKS keyslots and for on-disk metadata handling for other formats. Using AF_ALG ensured that the same set of algorithms is present in userspace and later in-kernel for device activation. While libcryptsetup has a concept of fallback to userspace library, it was not used in all situations. In this version, libcryptsetup can use a userspace crypto library, AF_ALG (if present), and in some situations (LUKS keyslots), fallback to a temporary dm-crypt mapping. The last option requires root privileges. This ensures that most operations will continue to work even when AF_ALG is disabled or limited. Unfortunately, removing the AF_ALG could cause severe compatibility issues if the required algorithm (or encryption mode) is not implemented in the userspace library. A typical example is the Adiantum cipher, which is implemented only in the kernel. Also, ciphers like Serpent or Twofish (in XTS mode) are missing from several userspace libraries. The cryptsetup benchmark for ciphers is no longer available if the AF_ALG interface is unavailable. * Keyring handling changes. Libcryptsetup can use the kernel keyring to transfer the volume key into the kernel, avoiding sending it as a parameter to system calls. In previous versions, the volume key could be stored in the thread keyring, which should be removed when the process exits. Unfortunately, the thread keyring can remain active in some situations (such as when allocating a loop device). This could be a problem after calling luksSuspend when the volume key could remain in memory. Instead of loading volume keys directly into the thread keyring, cryptsetup now creates an intermediary keyring linked into the thread keyring and loads volume keys there. The intermediary keyring is now removed in the libcryptsetup context destructor (usually on application exit). Note that in previous versions, volume keys persisted until the process exited (even after the context destructor was called). * Changes related to possible LUKS volume key digest collisions. LUKS on-disk metadata uses a volume key digest generated by the PBKDF2 key-derivation algorithm to verify that the decrypted volume key is valid. The use of PBKDF2 (instead of a more suitable cryptographic digest algorithm) is part of the original LUKS design. It was retained for LUKS2 for compatibility (it allows easy in-place conversion). However, PBKDF2 has several design flaws. As it is based on HMAC (Hash-based Message Authentication Code), it also inherits the weak-key HMAC issue. In HMAC, the key can be arbitrarily long. If the key is shorter than the hash internal block size, it is padded with zeroes to a full block size. This flawed padding causes any HMAC key (shorter than the specified block size) to collide with keys that have added trailing zeroes. A collision means that HMAC (and PBKDF2) has the same output for colliding keys. In LUKS, a PBKDF2 collision is not a security issue; it cannot compromise data confidentiality. Moreover, the colliding key has a different length and should be rejected by the underlying block cipher. Unfortunately, in some reencryption scenarios (e.g., a header without keyslots), a collision key could be accepted, leading to possible data corruption. Code now always validates the expected key length. This validation is now strictly implemented in LUKS metadata processing. In the long term, LUKS will need to upgrade to a better volume key digest algorithm, but that will make the format backward-incompatible. * Support Aria and Camellia ciphers in the libgcrypt cryptographic backend. * Fix pkg-config library entry for the Mbed TLS cryptographic backend. * Better document CRYPT_VOLUME_KEY_NO_SEGMENT and CRYPT_VOLUME_KEY_DIGEST_REUSE API flags. The keyslot created with the CRYPT_VOLUME_KEY_NO_SEGMENT flag must always be unbound (not assigned to the default data segment). The use of the CRYPT_VOLUME_KEY_DIGEST_REUSE flag does not make sense without the CRYPT_VOLUME_KEY_NO_SEGMENT or CRYPT_VOLUME_KEY_SET flags. * Fix several possible corner cases in OpenSSL cryptographic backend (based on AI analysis). These include checking before casting from size_t to int, checking return values for the old OpenSSL HMAC API, avoiding sending a partial buffer to the caller if the operation fails, and explicitly checking for buffer length overflow. Most of these cannot happen in the libcryptsetup context, but the cryptographic backend can be used for other projects. * Code hardening based on various AI analysis reports. Including a fix for snprintf truncation in libdevmapper code, avoiding possible leak of JSON keyslot object on error path, and a fix for reencryption temporary device name. * Fix jq (JSON commandline processor) use in testing scripts. After the security update for jq, it no longer processes JSON with trailing zeroes. Regression test scripts were updated to avoid using this scenario. * Add support for --integrity-legacy-hmac in integritysetup open command. Integritysetup open command incorrectly configured options for legacy HMAC devices. To use --integrity-legacy-hmac, it must now be used both on format and open. * Fix cryptsetup --tries option not to overflow for high values. * Remove patches upstream: - cryptsetup-Add-keyring-key-type.patch - cryptsetup-Load-volume-keys-in-intermediary-keyring-linked-in-t.patch - cryptsetup-Use-unique-intermediary-keyring-name-per-device.patch - cryptsetup-tests-revoke-keys-instead-unlinking-from-thread-keyr.patch - cryptsetup-tests-verify-VK-and-internal-keyring-cleanup-after-p.patch - cryptsetup-tests-refactor-keyring-helpers.patch - cryptsetup-tests-verify-intermediary-keyring-cleanup-after-cryp.patch ==== faad2 ==== Version update (2.11.2.git13 -> 2.11.2.git18) - Update to version 2.11.2.git18: * fix signed overflow in fixed-point sample rounding before saturation * prevent num_bits_left underflow in ps_data extension parsing * cap escape length in huffman_spectral_data_2 * fix signed overflow in estimate_current_envelope energy sum * fix ssr_gc_function signature mismatch in ssr gain control ==== fwupd ==== Version update (2.1.6 -> 2.1.7) Subpackages: libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.7: + This release adds the following features: - Add "well known" AppStream IDs for common BIOS settings - Add MTD lock security attribute - Add support for "externally managed" EFI signature lists - Add systemd-pcrlock plugin and hook up to UEFI updates - Add TCG disk encryption security attribute - Enable more plugins when compiling for Android + This release fixes the following bugs: - Add wrappers for input streams for future Rust implementations - Allow overriding some methods in FwupdClient for a future refactor - Allow plain string versions for some AMD GPUs - Allow suspend-to-ram with encrypted RAM - Always test Dell dock type when connected - Avoid possible out-of-bounds read in when parsing the DFU sector - Do not abort when udisks cannot resolve a device - Do not allow force installs over D-Bus - Do not fail to start when a pre-group comment has no keys set - Fall back to copying the file descriptor contents when not sealed - Fix dropped status updates during updates - Fix FW update for Lenovo TBT5 Smart Dock 7500 - Fix fwupd-refresh.service polkit auth errors - Fix segfault parsing some logitech-hidpp bootloader records - Fix the seal self tests when building on a tmpfs - Fix update failure when the TP IC is in bootloader-only mode - Mark Coreboot VBOOT as obsoleting BootGuard verified - Move more per-class limits to the class instances to reduce RSS - Prepare modem-manager firmware after firehose detach - Reject out-of-range CCGX device mode before indexing versions - Require trusted metadata for device updates - Require trusted metadata when using OnlyTrusted - Skip modem-manager secboot status when unsupported - Use safe reads for synaptics-rmi device responses - Validate GUID-defined section offset against EFI section size + This release adds support for the following hardware: - PixArt PJP360 device ==== gcc ==== Version update (15 -> 16) - Bump GCC version to 16, leave -build flavor at 13. - Add packages for Algol 68. - Disable gccgo for loongarch64. ==== gcc16 ==== Version update (16.1.1+git8886 -> 16.1.1+git9481) Subpackages: libgcc_s1 libgomp1 libstdc++6 - Update to gcc-16.1.1+git9481, GCC 16.2 RC1 - Update to gcc-16.1.1+git9423 - Build a full cross-x86_64 compiler [bsc#1272616], but not on %ix86 - Update gcc15-Wtime_t-conversion.patch - Make build recipe compatible with POSIX sh - do not pass in -fhardened ==== glib2 ==== Version update (2.88.2 -> 2.88.3) Subpackages: glib2-tools libgio-2_0-0 libgirepository-2_0-0 libglib-2_0-0 libgmodule-2_0-0 libgobject-2_0-0 typelib-1_0-GLib-2_0 typelib-1_0-GLibUnix-2_0 typelib-1_0-GModule-2_0 typelib-1_0-GObject-2_0 typelib-1_0-Gio-2_0 - Update to version 2.88.3 (CVE-2026-15588): + Fix potential miscompilation with GCC 17 with `G_GNUC_CONST` on `get_type()` functions + Bugs fixed: - G_GNUC_CONST vs get_type comes home to roost - (CVE-2026-15588) Security report: GDBusServer pre-authentication DoS via unbounded SASL line buffering - Drop G_GNUC_CONST for *_get_type - gdbusauth: Limit length of lines read from client - gdbusauth: Unmark a new string as translatable - Several Meson/gcc fixes ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-common grub2-snapper-plugin - Fix KVM and Xen VM images taking too long to boot (bsc#1266384) * 0001-cacheinfo-fix-hit-ratio-calculation-and-statistics-o.patch * 0002-disk-fix-cache-lock-and-hit-counter-for-invalidated-.patch * 0003-disk-reduce-cache-slot-thrashing.patch - Replace patch with upstreamed version * 0001-test-Fix-f-test-on-files-over-network.patch * 0002-http-Return-HTTP-status-code-in-http_establish.patch * 0003-docs-Clarify-test-for-files-on-TFTP-and-HTTP.patch * 0004-tftp-Fix-hang-when-file-is-a-directory.patch ==== gvfs ==== Subpackages: gvfs-backends - don't package capabilities in RPM but rely on permissions profiles instead (bsc#1268674). An upcoming change in rpmlint will raise badness when capabilities are directly packaged in an RPM. gvfsd-nfsd is already whitelisted in the permissions profiles and the proper capabilities will be assigned during %post. ==== hwinfo ==== Version update (25.4 -> 25.5) Subpackages: libhd25 - merge gh#openSUSE/hwinfo#187 - small adjustments to bash-completion, update spec file - 25.5 - merge gh#openSUSE/hwinfo#183 - add bash completion script for hwinfo - merge gh#openSUSE/hwinfo#186 - serial driver file name changed in /proc in current kernel, adjusting code (bsc#1271724) ==== kernel-firmware-amdgpu ==== Version update (20260629 -> 20260717) - Update to version 20260717 (git commit fb91c990e602): * amdgpu: DMCUB updates for various ASICs * amdgpu: DMCUB updates for various ASICs ==== kernel-firmware-bluetooth ==== Version update (20260629 -> 20260720) - Update to version 20260720 (git commit 18cf97993f06): * linux-firmware: Add firmware file for Intel BlazarIW * linux-firmware: Update firmware file for Intel BlazarU core * linux-firmware: Update firmware file for Intel BlazarI core * linux-firmware: Update firmware file for Intel Scorpius core - Update to version 20260703 (git commit c95059a3774b): * QCA: Add Bluetooth firmware for WCN6855 ROM 1.0 ==== kernel-firmware-platform ==== Version update (20260629 -> 20260717) - Update to version 20260717 (git commit fb91c990e602): * powervr: add firmware for Imagination Technologies BXM-4-64 GPU ==== kernel-firmware-qcom ==== Version update (20260629 -> 20260717) - Update to version 20260717 (git commit fb91c990e602): * qcom: add ADSP firmware for hawi platform * qcom: Update DSP firmware for sa8775p platform ==== kernel-source ==== Version update (7.1.4 -> 7.1.5) Subpackages: kernel-64kb kernel-default - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (git-fixes). - commit 862e13e - Linux 7.1.5 (bsc#1012628). - crypto: algif_skcipher - force synchronous processing (bsc#1012628). - iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry (bsc#1012628). - crypto: sun4i-ss - Remove insecure and unused rng_alg (bsc#1012628). - media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work (bsc#1012628). - ALSA: hda/realtek: Add quirk for TongFang X6xx45xU (bsc#1012628). - ALSA: hda: conexant: Remove mic bias threshold override (bsc#1012628). - ALSA: hda: Fix cached processing coefficient verbs (bsc#1012628). - ALSA: hda/realtek: Fix speakers on Legion Pro 7 16ARX8H with codec SSID 17aa:38a7 (bsc#1012628). - media: uvcvideo: Use hw timestaming if the clock buffer is full (bsc#1012628). - media: uvcvideo: Avoid partial metadata buffers (bsc#1012628). - media: uvcvideo: Fix buffer sequence in frame gaps (bsc#1012628). - media: uvcvideo: Fix dev_sof filtering in hw timestamp (bsc#1012628). - media: uvcvideo: Do not add clock samples with small sof delta (bsc#1012628). - media: uvcvideo: Relax the constrains for interpolating the hw clock (bsc#1012628). - media: uvcvideo: Fix sequence number when no EOF (bsc#1012628). - dt-bindings: media: sun4i-a10-video-engine: Add interconnect properties (bsc#1012628). - dt-bindings: power: imx93: Add MIPI PHY power domain (bsc#1012628). - serial: msm: Disable DMA for kernel console UART (bsc#1012628). - serial: max310x: implement gpio_chip::get_direction() (bsc#1012628). - serial: 8250_omap: clear rx_running on zero-length DMA completes (bsc#1012628). - rxrpc: serialize kernel accept preallocation with socket teardown (bsc#1012628). - rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc (bsc#1012628). - rxrpc: Don't move a peeked OOB message onto the pending queue (bsc#1012628). - rxrpc: Fix UAF in rxgk_issue_challenge() (bsc#1012628). - rxrpc: Fix socket notification race (bsc#1012628). - rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) (bsc#1012628). - rxrpc: Fix potential infinite loop in rxrpc_recvmsg() (bsc#1012628). - rxrpc: Fix rxrpc_rotate_tx_rotate() to check there's something to rotate (bsc#1012628). - rxrpc: Fix oob challenge leak in cleanup after notification failure (bsc#1012628). - rxrpc: Fix ACKALL packet handling (bsc#1012628). - rxrpc: Fix the reception of a reply packet before data transmission (bsc#1012628). - rxrpc: Fix leak of connection from OOB challenge (bsc#1012628). - rxrpc: Fix double unlock in rxrpc_recvmsg() (bsc#1012628). - afs: Fix netns teardown to cancel the preallocation charger (bsc#1012628). - afs: fix NULL pointer dereference in afs_get_tree() (bsc#1012628). - afs: handle CB.InitCallBackState3 requests without a server record (bsc#1012628). - afs: Fix further netns teardown to cancel the preallocation charger (bsc#1012628). - afs: Fix uncancelled rxrpc OOB message handler (bsc#1012628). - fbcon: fix NULL pointer dereference for a console without vc_data (bsc#1012628). - fbcon: Use correct type for vc_resize() return value (bsc#1012628). - soc: fsl: qe_ports_ic: Add missing cleanup on device removal (bsc#1012628). - openrisc: mm: Fix section mismatch between map_page and __set_fixmap (bsc#1012628). - clocksource/drivers/sun5i: Handle error returns from devm_reset_control_get_optional_exclusive() (bsc#1012628). - accel/amdxdna: Fix leak when pinning ubuf pages (bsc#1012628). - drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() (bsc#1012628). - drm/rockchip: dw_dp: Switch to drmm_kzalloc() (bsc#1012628). - drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() (bsc#1012628). - drm/rockchip: Test for imported buffers with drm_gem_is_imported() (bsc#1012628). - drm/tidss: Drop extra drm_mode_config_reset() call (bsc#1012628). - drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges (bsc#1012628). - accel/amdxdna: Create shared functions for AIE2 and AIE4 (bsc#1012628). - accel/amdxdna: Adjust size for copy_to_user() (bsc#1012628). - accel/amdxdna: Handle DETACH_DEBUG_BO through config_debug_bo path (bsc#1012628). - accel/amdxdna: Fix iommu_map_sgtable() return value handling (bsc#1012628). ... changelog too long, skipping 3694 lines ... - commit 5c9ff0f ==== libapparmor ==== Version update (5.0.1 -> 5.0.2) - update to AppArmor 5.0.2 - several fixes in utils, parser and some profiles - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_5.0.2 for the upstream changelog - remove upstreamed patches: - curl.diff - lsblk-mr2147.diff - add nslookup.diff to fix nslookup output ==== libcontainers-common ==== Version update (20260429 -> 20260521) Subpackages: libcontainers-default-policy registries-conf-default - New release 20260521 * bump bundled c/common to 0.68.0: + containers.conf: - previously /usr/share/containers/containers.conf, /etc/containers/containers.conf, ~/.config/containers/containers.conf were read all in order; now only the file with the highest precedence is read - ~/.config/containers/containers.conf will be read before a drop-in file from /etc/containers/containers.conf.d/ + storage.conf: - support for drop-in configuration files - storage.rootless.conf.d/ storage.rootful.conf.d/ allow configuring options system wide for all users - rootless_storage_path field is deprecated, instead set graphroot to the same value in a drop-in file under storage.rootless.conf.d/ - graphroot, runroot options in the default storage.conf are now read by all users; if a specific root only graphroot was set, then this option must be moved to a new drop-in under storage.rootful.conf.d/ + registries.conf: - drop support for v1 syntax - support reading the default file under /usr/share/containers - correctly use XDG_CONFIG_HOME for the per user file lookup + registries.d: - support reading files under /usr/share/containers/registries.d/ + policy.json: - add /usr/share/containers/policy.json search location - Move all vendor config files from /etc/containers/ to /usr/share/containers * user-modified files in /etc/containers continue to work as overrides * preserve ownership of /etc/containers * ghost /etc/containers/{storage,containers}.conf - Add Conflicts: podman < 6, buildah < 1.44, skopeo < 1.23 ==== libeconf ==== Version update (0.8.3 -> 0.8.4) - Update to version 0.8.4: * Described content of key_file in econf_readConfig* (#248) * Fix a missing word in README.md (#247) ==== libheif ==== Version update (1.23.0 -> 1.23.1) - Update to version 1.23.1: + FFmpeg decoder plugin gains AV1, VVC, JPEG, and JPEG 2000/HTJ2K decoding + SVT-AV1 encoder: new tune=iq and ms-ssim tune parameters + C++ API: added getters/setters for the CLLI and MDCV HDR metadata boxes + Sequence decoder now scales the alpha auxiliary track to the main image size + Fixed pixi box writing for multi-channel images + Corrected the placement of the TAI clock_type field into the top 2 bits + Empty/unset plugin directory is no longer scanned + CVE-2026-62289 (GHSA-jc8f-p23p-5hjg) Integer underflow in Fraction constructor via double clap transform application + CVE-2026-62291 (GHSA-xpw3-9rhw-482x) Heap out of bounds write in libheif uncompressed encoder when writing images with mismatched auxiliary alpha dimensions + CVE-2026-62292 (GHSA-73p7-m7gg-w2jv) Out-of-bounds read in uncompressed unci tile range slicing + CVE-2026-62377 (GHSA-9ww4-9v47-m7pj) Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file + (GHSA-46rp-pcq2-rpmr) Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth ≤ 8 ==== libmysofa ==== Version update (1.3.3 -> 1.3.5) - Update to 1.3.5: * Harden HDF/SOFA parser against malformed input * Fixed issue with missing boundary check which lead to a stall - Changes in 1.3.4: * “fixes issues with v1.3.3” * added support for General FIR-E ==== libndp ==== Version update (1.8 -> 1.9) - Update to version 1.9: * ndptool: add support for PREF64 option * libndp: add support for PREF64 option * libndp: valid route information option length * SubmittingPatches: update mailing list - Drop libndp-CVE-2024-5564.patch: Fixed upstream. - Use modern macros, make_install and ldconfig_scriptlets. ==== libostree ==== Version update (2026.1 -> 2026.2) Subpackages: libostree-1-1 - Update to 2026.2: * Fix GVariant memory leak during opaque whiteout scanning that could cause bootc install to-disk to fail with EBUSY on unmount * Fix a crash for invalid UTF-8 ref names during pull operations * Fix Kernel argument handling was fixed to properly handle quoted values in /proc/cmdline * Correct staged deployment bootconfig merging to preserve options across re-staging ==== libpng16 ==== Version update (1.6.57 -> 1.6.58) - version update to 1.6.58: * Fixed a regression introduced in version 1.6.56 that caused `png_get_PLTE` to return stale palette data after applying gamma and background transforms in-place. ==== librepo ==== - Pull some fixes from upstream master to fix GPG check of repo metadata * 0001-gpgme-Improve-handling-of-expired-GPG-signatures-wit.patch * 0002-PGP-define-shared-error-message-constants-for-both.patch * 0003-gpgme-report-Signing-key-not-found-when-signing-key.patch * 0004-test-verify-missing-key-error-message-consistency.patch ==== libssh ==== Version update (0.11.4 -> 0.11.5) Subpackages: libssh-config libssh4 - Update to 0.11.5: * Security: - CVE-2026-15370: Stack buffer overflow in SFTP server longname construction (bsc#1272162) - CVE-2026-59843: Denial of service via zero advertised channel packet size (bsc#1272164) - CVE-2026-59844: Denial of service via oversized SFTP read length (bsc#1272165) - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure (bsc#1272166) - CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion (bsc#1272167) - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168) - CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs (bsc#1272169) - CVE-2026-59849: Denial of service via automatic certificate authentication loop (bsc#1272170) - CVE-2026-59850: Use-after-free via data callbacks on closed channels (bsc#1272171) - Zero-initialize every ssh_string * Compatibility: - Fix compatibility with C23 / gcc16 * Bugfixes: - Fix multiple memory leaks, null checks, and error checks - Validate peer public key in DH key exchange - Avoid remote window overflow - Avoid off-by-one overflow during kbdint authentication - Avoid logging uninitialized sequence numbers - Avoid double conversion of SFTP version number - Send correct SFTP server version number - Avoid handling repeated SFTP INIT messages - Harmonize return values from SFTP server callbacks ==== libxmlb ==== Version update (0.3.27 -> 0.3.29) - Update to version 0.3.29: + Bugfixes: - Avoid stale query indexes when reloading the silo - Clear the query cache when reloading the silo - Correctly mark the silo as invalid when re-loading malformed data - Fix building the silo when shared-mime-info is installed - Changes from version 0.3.28: + New Features: - Automatically add system locales when using native-langs - Lower the Meson and GLib deps for RHEL-8 + Bugfixes: - Lazy clear opcode tokens for a ~2% speedup - Speed up negative queries by 11% by defer creating the results objects - Speed up predicates with no bindings by 9% - Speed up the no-results query by 2.5% by using a constant error ==== microos-tools ==== Version update (4.0+git24 -> 4.0+git28) Subpackages: selinux-autorelabel zypp-excludedocs zypp-no-multiversion zypp-no-recommends - Update to version 4.0+git28: * Use zypp.conf.d dropin for ZYPP_SINGLE_RPMTRANS=1 - Update to version 4.0+git27: * Remove obsolete stuff (locale-check, salt-tmpdir) - Update to version 4.0+git26: * test: Check if autorelabel files are removed after reboot * Move cp of /.autorelabel to /etc into rd_microos_relabel ==== multipath-tools ==== Version update (0.14.3+212+suse.f5d32098 -> 0.15~1+230+suse.d36a6a70) Subpackages: kpartx libmpath0 - Update to version 0.15~1+230+suse.d36a6a70: * Even with the libudev wrapper code introduced in 0.14.0, multipathd ran into use-after-free errors in tests where multipathd was restarted frequently. Fix this by preventing thread cancellation during libudev calls. (gh#opensvc/multipath-tools#152). * libmultipath: async_checker: fix sync checker case (bsc#1272188) - Update to version 0.15~1+222+suse.cdcde840 (0.15 pre-release) * All path checkers run in asynchronous mode now by default, using a new generic asynchronous checker framework. This improves the stability of multipathd in the presence of non-responsive devices when using path checkers other than `tur` and `directio`. Use the `force_sync` parameter in `multipath.conf` to switch back to the previous, synchronous behavior, especially if you observe strong spikes of CPU load on systems with a lot of path devices. Note that the likelihood of such spikes should be strongly reduced since multipath-tools 0.10.0. Commit 6f7daba ff. * The configuration options `rr_min_io`, `rr_min_io_rq`, and `rr_weight` are now deprecated and have no effect. These options have not been supported by the kernel since version 4.6. Users should remove them from `multipath.conf`. * Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ("lba-dependent", "transitioning"). * Don't set a hardware handler for bio-based multipath devices. The kernel rejects this anyway. - Bug fixes: * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier. * kpartx: Fix an integer overflow in the GPT partition table size calculation. A crafted partition table with an extremely large number of partition entries could trigger the overflow. (bsc#1268145) * kpartx: Fix several issues in the DASD partition table reader that could be triggered by a maliciously crafted disk image. (bsc#1268144) * Fix duplicate "checker timed out" log messages when `log_checker_err` is set to `once`. (bsc#1254094) * Avoid potential buffer overflows in the iet and datacore prioritizers. * iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. (gh#opensvc/multipath-tools#145) * An overlong partition delimiter (-p option) could cause kpartx to crash. Fix it. * Man page improvements. ==== net-tools ==== Version update (3.14~alpha~git.20251212.7011617 -> 3.14~alpha~git.20260718.4f5bfb2) - Update to version 3.14~alpha~git.20260718.4f5bfb2: * Update config.in: disable AF and HW ROSE by default (obsoletes Update_config.in.patch) * netstat: Keep UTF-8 characters in process names (bsc#1254323, obsoletes net-tools-netstat-ansi-injection.patch) - Update to version 3.14~alpha~git.20260612.2ab3c5e: * netstat: Update email address * doc: describe missing headers * passes -Wunused-parameter * fix type limit warnings * Remove anchient gettext ABOUT-NLS * TODO: removed NLS, add -Wextra * INSTALLING: musl, all features, compile warning todos * netstat.8: minor edits * chore: pedantic zizmor is happy on GH actions * Unified man example format * netstat.8: warn on trustworthyness of program name * man: netstat: add two examples * Rarp: fix nullpointer on unknown hosts * netstat: safe cycles and fix comment * Sanitize cmdline (bsc#1254323, CVE-2024-58251) * Updated translations. - Add Update_config.in.patch: Update config.in: disable AF and HW ROSE by default. This is longer part of the kernel 7.1 source tree. ==== nghttp2 ==== Version update (1.69.0 -> 1.70.0) - Require the versions configure actually checks for: libnghttp3 >= 1.17.0 and libngtcp2 >= 1.23.0. Without them OBS starts the build and lets it fail in configure, instead of holding the package unresolvable until nghttp3 is in place - Update to 1.70.0: * nghttpx: add separate frontend and backend stream timeouts, plus an HTTP/2 stream write timeout * nghttpx: drop HTTP/2 and HTTP/3 connections whose frontend write rate is too low, so a peer can no longer hold a connection open by reading slowly * Rework HTTP header validation, and add the value check that was missing for the priority header field * Fix an out-of-bounds read in the base64 decoder * get_socket_error() now reports the errno of getsockopt() when that call itself fails, instead of a stale value * Update the bundled llhttp to 9.4.2 and mruby to 4.0.0, and refresh the bundled ngtcp2, neverbleed and sfparse * Large internal rework: nghttpx now carries its error paths in std::expected rather than out-parameters - Drop 0001-nghttpx-Tighten-up-CONNECT-and-HTTP-Upgrade-handling.patch, the fix is part of this release (CVE-2026-58055, bsc#1269489) - Mark the doc subpackage noarch, it ships documentation only and rpmlint rightly flagged it with no-binary - Run spec-cleaner: drop the Group tags and sort the build dependencies ==== nghttp3 ==== Version update (1.15.0 -> 1.18.0) - Update to 1.18.0: * Added nghttp3_conn_close_stream2 and the nghttp3_stream_close2 callback * Validate the header length against the estimated uncompressed length * Fix a build error with gcc-16 - Changes from 1.17.0: * Added nghttp3_conn_stream_flushed and public API to encode and decode variable-length integers * Fix header name validation - Changes from 1.16.0: * Added nghttp3_conn_get_stream_user_data * Call the nghttp3_stream_close callback for all streams * Fix a memory leak on the failure path * Ignore content-length for the extended CONNECT * Reject HTTP status codes with a leading zero * Optimize huffman decode length estimation - The library soname is unchanged at 9 ==== ntfs-3g_ntfsprogs ==== Version update (2022.10.3 -> 2026.7.7) Subpackages: ntfs-3g ntfsprogs - Update to version 2026.7.7: * (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616). * Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617). * Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618). * Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569). * Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571). * Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570). * Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572). * Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135). * Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136). - Drop patches fixed upstream: + ntfs3g-unistr-use-after-free.patch + ntfs3g-heap-overflow.patch + 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch + 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch + 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch + 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch + 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch + 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch + 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch ==== nvme-cli ==== Version update (3.0~b.3 -> 3.0~b.4) Subpackages: libnvme3-1 - Update to version 3.0~b.4: * Release v3.0-b.4 * doc: Regenerate all docs for v3.0-b.4 * libnvme/config: add epcsd supporting * libnvme/config: add support for persistent * libnvme/fabrics: remove pdc-enabled build time config * plugins/config: add create command * libnvme/config-emit: ensure config dir exists * shared/fs-util: add missing windows implementation * shared/fs-util: add sh_mkdir_from_fname and shr_dirname * shared: split platform parts into separate files * shared: update prefix for compiler attributes * doc: remove nvme-config.txt * plugins: invoke the arg parser for the remaining commands * discoverd: rename discoverd.conf to nvme-discoverd.conf * ocp: add NULL checks after memory allocation * ocp: fix __le64 usage in C9 log reading * ocp: fix use after free and memory leak related to C9 log page reads * ocp: use libnvme_alloc and libnvme_free for log buffer allocations * ocp: read telemetry log with maximum transfer size * innogrit: fix resource leak in innogrit_vsc_getcdump() * scaleflux: clamp code_type before array access in nvme_parse_evtlog() * wdc: fix out-of-bounds access in wdc_show_cloud_smart_log_normal() * micron: clean up and fix micron telemetry log reading * nbft: ensure transport buffer is null terminated in read_ssns() and read_hfi() * nvme-models: fix stream EOF state errors in __nvme_product_name and pull_class_info * ibm: fix missing break in show_ibm_smart_log() case 0x00f5 * nvme-rpmb: fix out-of-bounds allocation in read_rpmb_key() * tests: align config-convert expectation with preserved legacy json * plugins/ymtc: fix additional smart info display for YMTC PE511 * utils: check asprintf return value * util: fix memory leak in read_binary_file() * util: fix memory leak in read_binary_file() * utils: add crash handlers for option capture * nvme: avoid stale pointer in get_log_offset() * fabrics: avoid double free in build_options() * fabrics: avoid reduntant libnvmf_context_set_crypto() call * fabrics: avoid mem leak in libnvmf_context_set_crypto() * fabrics: accept fabrics arguments for disconnect * nvme: add arg parser to gen/show hostnqn * plugins/keys: report line number 1 based * plugins/keys: show error when missing trailing colon * plugins/keys: update help text for gen-tls * fabrics: add --kxchap-* arguments * nvme: add compat tls/chap key management commands * libnvme: rename DH-HMAC- prefix with KX-HMAC- * tests: add nvme keys tests cases * nvme: split keyring insert out of keys check-tls/check-dhchap * nvme: move key commands into new keys plugin * shared: add more test coverage * libnvme: return libnvmf_tid_parse{,_strict}() as int, not a pointer * libnvme/nbft: tests: Regenerate reference NBFT table dumps * nvme: preserve legacy json config for rollbacks * libnvme: reuse heap reader for NBFT security lists * libnvme: fix comments that still describe removed JSON config support * libnvme/nbft: Add sample synthetic NBFT tables * shared: move init unit test * shared: move compiler-attributes to common code * libnvme: return libnvmf_tid_from_fields() as int, not a pointer * nvme: fix to check sanitize status error * nbft-plugin: fix resource leak in show_nbft() * discoverd: parse discoverd.conf with the shared ini parser * libnvme: parse NBFT Security Profile descriptors * doc: add nvme-discoverd(8) and the design README * meson: make nvmf-autoconnect independently toggleable * discoverd: add the nvme-discoverd daemon * libnvme: harden NBFT interface references * libnvme: validate NBFT descriptor ranges * libnvme: drop test/ioctl's own freep(), use shared/cleanup.h * shared: add README * shared: add test coverage for array-util, base64, crc32 * shared: rename everything to the shr_ namespace * shared: add PTRARRAY_DEFINE() for type-checked ptrarray wrappers * shared: dedup cleanup.h boilerplate * shared: move base64, crc32, and misc utility functions * shared: fix mkdir_p() silently truncating long paths * shared: relicense to LGPL-2.1-or-later * sfx-nvme: fix resource leak in sfx_status() * nbft: fix resource leak of ssns->hfis in read_ssns() * sndk plugin: Fix vs-smart-add-log for NVMe OF * nvme: add utils dump-command-metadata command * memblaze: fix stack overflow in perf-stats-print-x * nvme: add global options config file * shared: move ini parser to common code * nvme: move args into separate header * nvme: do not include libnvme-mi on global level * nvme: change verbosity type * util/json: use stdint types * shared: add a small static utility library * wdc: free dssd_specific_ver when smart_log_ver < 3 * virtium: remove erroneous (float) cast in vt_save_smart_to_vtview_log() * nvme-print: print address instead of traddr * nvme: replace argconfig_parse with parse_args * nvme-cli: resolve hostnqn/hostid on ctx creation * libnvme/tree: free hnqn/hid in error path * sfx-nvme: fix dead assignment in sfx_dump_evtlog() * exclusion: fix uninitialized argument in libnvmf_exclusion_read() * nvme: Fix get-log xfer-len parameter handling * libnvme: generate the trivial libnvme_global_ctx bool accessors ... changelog too long, skipping 105 lines ... unpackaged files. ==== open-lldp ==== Version update (1.1.1+87.f16f944 -> 1.1+110.f16f944) Subpackages: liblldp_clif1 - Changed _services and spec file to recreate the tarball file based on version 1.1 instead of version 1.1.1, since the software that compares versions was having issues with using 1.1.1. (bsc#1268742) ==== openssh ==== Version update (10.3p1 -> 10.4p1) Subpackages: openssh-clients openssh-common openssh-server - Add patch submitted to upstream to fix GSSAPI* options not working after servconf refactoring (https://bugzilla.mindrot.org/show_bug.cgi?id=3974): * 0001-Fix-GSSAPI-server-option-names.diff - Rebase patches: * openssh-8.0p1-gssapi-keyex.patch * openssh-7.7p1-gssapi-new-unique.patch - Update to openssh 10.4p1: = Potentially-incompatible changes * sshd(8): configuration dump mode ("sshd -G") now writes directives in mixed case (e.g. "PubkeyAuthentication") whereas previously it emitted only lower-case names. * sshd(8): on Linux systems with the seccomp sandbox enabled, failures to enable SECCOMP or NO_NEW_PRIVS are now fatal. Previously sshd(8) would log the error but continue operation, to support systems that lacked these features. Now systems that lack these should instead disable the sandbox at configure time. * ssh(1), sshd(8): make the transport protocol stricter by disconnecting if the peer sends non-KEX messages during a post- authentication key re-exchange. Previously a malicious peer could continue sending non-key exchange messages without penalty. These would be buffered, causing memory to be wasted up until the connection terminated or the server/client hit a memory limit. Implementations that do not restrict messages sent during key exchange as per RFC4253 section 7.1 may be disconnected. Reported by Marko Jevtic. = Security * sftp(1): when downloading files on the command-line using "sftp host:/path .", a malicious server could cause the file to be downloaded to an unexpected location. This issue was identified by the Swival Security Scanner. * scp(1): when copying files between two remote destinations, do not allow a malicious server to write files to the parent directory of the intended target directory. This issue was identified by the Swival Security Scanner. * sshd(8): when using the "internal-sftp" SFTP server implementation (this is not the default), long command lines were previously truncated silently after the 9th argument. If a security-relevant option was in the 10th or later position, it would be discarded. Reported by Steve Caffrey. * sshd(8): add a documentation note to mention that the GSSAPIStrictAcceptorCheck option is ineffective when the server is joined to a Windows Active Directory. Reported by Yarin Aharoni of Safebreach. * sshd(8): DisableForwarding=yes didn't override PermitTunnel=yes as it was documented to do. Note that PermitTunnel is not enabled by default. Reported independently by Huzaifa Sidhpurwala of Redhat and Marko Jevtic. * sshd(8): avoid a potential pre-authentication denial of service when GSSAPIAuthentication was enabled (this feature is off by default). This was not mitigated by MaxAuthTries, but would be penalised by PerSourcePenalties. This was reported by Manfred Kaiser of the milCERT AT (Austrian Ministry of Defence). * sshd(8): fix a number of cases where the minimum authentication delay was not being enforced. Reported by the Orange Cyberdefense Vulnerability Team. * ssh(1): fix a possible client-side use-after-free if the server changes its host key during a key reexchange. This was reported by Zhenpeng (Leo) Lin of Depthfirst. = New features * All: add experimental support for a composite post-quantum signature scheme that combines ML-DSA 44 and Ed25519 as specified in draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not enabled by default. To use it, you'll need to add it to HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be generated using "ssh-keygen -t mldsa44-ed25519". * ssh(1), sshd(8): replace the wildcard pattern matcher with an implementation based on an NFA. This avoids exponential worst-case behaviour for the old implementation. = Bugfixes * ssh-agent(1): fix incorrect reply to "query" SSH_AGENTC_EXTENSION requests. bz3967 * sshd(8): avoid sending observably different messages for valid vs invalid users in GSSAPIAuthentication (disabled by default). * ssh(1), sshd(8): fix several bugs that incorrectly classified bulk traffic as interactive. bz3972, bz3958 * ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading resident keys from a FIDO token. Previously, downloads would abort when one was encountered. GHPR657 * ssh(1): fix a potential use-after-free on an error path if cipher_init() fails. * sshd(8): perform stricter encoding and validation of transport state passed between sshd privilege separation subprocesses. This somewhat further hardens the server against attacks on sshd-auth or sshd-session subprocesses. * ssh-agent(1): avoid possible runtime denial of service by enforcing some limits on the length of usernames in key use constraints. * sftp(1): fix two separate one-byte out-of-bounds reads, in SSH2_FXP_REALPATH and batch command processing. * sftp-server(8): disallow use of the copy-data extension to read and write to the same inode simultaneously. * ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent. GHPR679 * sftp(1), scp(1): avoid a situation where sftp_download() could get stuck in a loop if a broken server repeatedly returned zero length while reading a file. ... changelog too long, skipping 79 lines ... * fix-mac-validation-strsep-logic-bug.patch ==== pam ==== Version update (1.7.2+git12 -> 1.7.2+git48) - Update to version 1.7.2+git48: * pam_unix: make SHA512 the default * po: update translations using Weblate (Hebrew) * po: update translations using Weblate (Russian) * po: update translations using Weblate (Greek) * po: update translations using Weblate (Norwegian Nynorsk) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Serbian) * po: update translations using Weblate (Polish) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Hungarian) * po: add translation using Weblate (Kabyle) * po: update translations using Weblate (Indonesian) * po: update translations using Weblate (Lithuanian) * po: update translations using Weblate (Italian) * po: update translations using Weblate (Finnish) * po: update translations using Weblate (Slovenian) * po: update translations using Weblate (Spanish) * po: update translations using Weblate (Punjabi) * po: update translations using Weblate (Kazakh) * po: update translations using Weblate (Swedish) * po: update translations using Weblate (Ukrainian) * po: update translations using Weblate (Portuguese (Brazil)) * po: update translations using Weblate (Turkish) * po: update translations using Weblate (Georgian) * po: update translations using Weblate (Romanian) * po: update translations using Weblate (Czech) * po: update translations using Weblate (Korean) * Update translation files * pam_userdb: fix password comparison timing leak * meson: use an empty array for link args instead of an empty string * pam_succeed_if: prevent logging unknown user names in plaintext * pam_limits: improve 'wrong limit value' log message * pam_pwhistory: allow earlier passwords when remember count is reduced * pam_namespace: fix error handling in secure_opendir() * pam_rhosts: fix typos in pam_rhosts(8) man page * .github: add gcc-15 jobs - Obsoletes pam_userdb-fix-password-comparison-timing-leak.patch ==== pam-full-src ==== Version update (1.7.2+git12 -> 1.7.2+git48) - Update to version 1.7.2+git48: * pam_unix: make SHA512 the default * po: update translations using Weblate (Hebrew) * po: update translations using Weblate (Russian) * po: update translations using Weblate (Greek) * po: update translations using Weblate (Norwegian Nynorsk) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Serbian) * po: update translations using Weblate (Polish) * po: update translations using Weblate (Chinese (Simplified) (zh_CN)) * po: update translations using Weblate (Hungarian) * po: add translation using Weblate (Kabyle) * po: update translations using Weblate (Indonesian) * po: update translations using Weblate (Lithuanian) * po: update translations using Weblate (Italian) * po: update translations using Weblate (Finnish) * po: update translations using Weblate (Slovenian) * po: update translations using Weblate (Spanish) * po: update translations using Weblate (Punjabi) * po: update translations using Weblate (Kazakh) * po: update translations using Weblate (Swedish) * po: update translations using Weblate (Ukrainian) * po: update translations using Weblate (Portuguese (Brazil)) * po: update translations using Weblate (Turkish) * po: update translations using Weblate (Georgian) * po: update translations using Weblate (Romanian) * po: update translations using Weblate (Czech) * po: update translations using Weblate (Korean) * Update translation files * pam_userdb: fix password comparison timing leak * meson: use an empty array for link args instead of an empty string * pam_succeed_if: prevent logging unknown user names in plaintext * pam_limits: improve 'wrong limit value' log message * pam_pwhistory: allow earlier passwords when remember count is reduced * pam_namespace: fix error handling in secure_opendir() * pam_rhosts: fix typos in pam_rhosts(8) man page * .github: add gcc-15 jobs - Obsoletes pam_userdb-fix-password-comparison-timing-leak.patch ==== permissions ==== Version update (1699_20260715 -> 1699_20260728) Subpackages: permctl permissions-config - Update to version 1699_20260728: * profiles: whitelist selinux-sandbox seunshare (bsc#1268256) * profiles: drop netcfg /etc/exports - Update to version 1699_20260723: * profiles: add cap_net_admin for cloud-hypervisor (bsc#1270717) - Update to version 1699_20260722: * profiles: fix ksystemstats6 bsc# reference syntax * profiles: add noisetorch cap_sys_resource (bsc#1270715) - Update to version 1699_20260716: * profiles: reintroduce apptainer starter-suid (bsc#1268675) ==== podman ==== Version update (5.8.3 -> 6.0.2) - Update to version 6.0.2: * Bump to v6.0.2 * Release notes for v6.0.2 * podman-remote: do not check for cgroupv2 * [v6.0] Bump Buildah to v1.44.1 * docs: clarify network create isolate option * test system: increase nproc ulimit to avoid flake * fix broken kube play --wait behavior * test/system: fix broken port bound check logic * test/system: fix "podman rm running container, w/o and w/ force" flake * Fix Windows installer machine scope PATH update * Always unprovision if the WSL machine init fail * Bump Podman to v6.0.2-dev * Bump to v6.0.1 * Release notes for v6.0.1 * Mark pasta forwarder tests as non-parallel * Enable pasta forwarder tests after passt SELinux fix * vendor: bump go.podman.io/common to v0.68.1 and fix pasta API break * macos: Use latest vfkit release in installer * Bump bundled krunkit from 1.3.1 to 1.3.2 * Fix lookup of HyperV VMs with matching name * docs: update network create --route description * docs: fix network create no_default_route doc * Only suggest --replace for commands that have the flag * machine/wsl: fix config mount logic * Bump bundled krunkit from 1.2.1 to 1.3.1 * Restore caching of the default machine image * label machine issues automatically * fix podman machine os upgrade distro check * podman log-level debug must produce the same oci runtime errors * Fix release email * Fix lookup of WSL VMs with matching name * Fix WSL check: assume not installed when --status returns an error * Packit: Add cautionary note to ephemeral copr job * Windows installer tests: download v5.8.3 of the setup bundle * Bump Podman to v6.0.1-dev - Update to version 6.0.0: * Security * This release addresses CVE-2026-57231 (bsc#1269471), where a malicious image using malformed Env entries could cause host environment variables to leak into containers run based on the image, including the ability to use the * glob operator to leak large numbers of environment variables without knowing their exact names (GHSA*4hq8-gpf5-8p68). * Breaking Changes * Due to breaking changes in this release, Podman v6.0.0 must be used with Buildah v1.44.0, Skopeo v1.23, Netavark and Aardvark v2.0.0, and configuration files from the container*libs repository's common/v0.68.0 release. * Support for BoltDB databases has been dropped. Starting Podman 6 when the BoltDB database is in use will have Podman attempt an automatic migration from BoltDB to SQLite. * Support for running on Intel Macs has been removed. * Support for running on Windows 10 has been removed. * Support for running on cgroups v1 systems has been removed. Please update your system to use cgroups v2. * Support for running on iptables has been removed. Please use nftables instead. * Support for CNI networking has been removed. Please use Netavark instead. * Support for the slirp4netns rootless network stack has been removed. Please use Pasta instead. As part of this, the *-network-cmd-path global option, only used with slirp4netns, has been removed. * Podman's configuration file parsing logic has seen a major rewrite. Please see this document for exact details. * Podman's import path has changed from github.com/containers/podman/v5 to go.podman.io/podman/v6 as part of our move into a CNCF*owned GitHub organization. * Network isolation now defaults to enabled, improving Docker compatibility and security. A special workaround for the Docker*compatible API related to isolation being disabled has been removed (#27349). * The way the podman quadlet suite of commands functions has been changed. Previously, Quadlets and their associated files were tracked using a .app file, ensuring that removing a Quadlet also removed all associated non*Quadlet files. Now, Quadlets and associated files are placed in subdirectories, which should reduce bugs and make manual management of Quadlets added by podman quadlet install much easier. * VMs made by podman machine on Linux now mount volumes from the host using systemd. Volume mounts on existing podman machine VMs on Linux have been broken by this change, and the VM will need to be recreated. * The podman volume prune command now matches Docker's behavior by only pruning unused anonymous volumes. Please use the newly*added --all option for the previous behavior (pruning all volumes). * The podman volume list command now combines multiple filters using logical AND instead of logical OR (meaning all filters must match for a container to be included in output) (#26786). * The label!= filter used in many commands now combines the output of multiple instances of the filter with logical AND instead of logical OR. * The --format='{{json .Labels}} option to the podman ps, podman pod ps, and podman volume ls commands now prints its output as comma*separated key=value pairs instead of as a JSON map, improving Docker compatibility (#21847). * The --all-providers option to podman machine list has been removed, as machines from all providers can now be accessed by all commands. * The MemorySwappiness field of podman inspect is now set to nil when not explicitly set by the user (instead of *1), improving Docker compatibility (#23824). * The podman commit command now pauses the container while committing changes, improving security by restricting concurrent modification. The prior behavior can be restored by using podman commit *-pause=false .... * The Go bindings for the REST API have removed the redundant nameOrID ... changelog too long, skipping 267 lines ... * Updated the common library to v0.68.0 ==== python-certifi ==== Version update (2026.5.20 -> 2026.7.22) - Update to 2026.7.22: - fix: update Requests docs link to canonical URL - Include tests in the source distribution ==== qemu ==== Version update (11.0.2 -> 11.0.3) - (Properly, this time for real) fix bsc#1268245: * [openSUSE][RPM] spec: properly fix bsc#1268245 (this time for real!) - Update to latest stable release (11.0.3) Full backport list here: https://lore.kernel.org/qemu-devel/20260725052155.1228635-1-mjt@tls.msk.ru/ A selection of them is reported here below: target/arm: do not clear halting reason in has_work helper target/arm: teach arm_cpu_has_work about halting reasons hw/audio/intel-hda: restrict all DMA engine paths to memories hw/net/cadence: Return current Cadence GEM queue pointers hw/misc/applesmc: Fix a typo setting MSSD key replay: fix use of uninitialized pointer on error hw/display/qxl: validate monitors_config heads[] in phys2virt net: Correct padding check in qemu_receive_packet() hw/net/xilinx_axienet: Fix PHY register 17 link status reporting hw/usb/hcd-xhci-sysbus: Fix OOB heap access in xhci_sysbus_intr_raise() hw/usb/hcd-xhci: Fix guest-triggerable assert() in xhci_find_stream() usbredir: fix infinite loop and SIGFPE with zero max_packet_size usbredir: fix use-after-free on buffered bulk packet overflow tests/qtest: add xhci-pci unplug finalize regression test hw/usb/hcd-xhci-pci: break host link cycle so device_finalize() runs on unplug hw/usb/xhci: clamp interval exponent to avoid UB shift in xhci_init_epctx() accel/tcg: move jit thread manipulation into do_tb_phys_invalidate hw/display/virtio-gpu: Check pixman_image_create_bits() results hw/display/virtio-gpu: handle migration iov allocation failure hw/display/virtio-gpu: cap submit_3d command buffer allocation ui/vnc: validate SetPixelFormat field ranges ui/vnc: fix out-of-bounds write in lossy refresh dirty marking ui/gtk: Narrow DMA-BUF critical section ui/input-barrier: fix off-by-one in keycode bounds check ui/vnc: validate color shifts in SetPixelFormat ui/vnc: fix OOB write in vnc_refresh_lossy_rect net: only advertise passt in netdev help when CONFIG_PASST hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask() hw/usb/hcd-ohci: Make sure that ohci_service_ed_list() cannot loop forever hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure hw/scsi/vmw_pvscsi: add a comment to explain the endianness hw/scsi/vmw_pvscsi: translate data endianness hw/sparc64/niagara: use int64_t for vdisk size to avoid truncation hw/display/qxl: fix TOCTOU in cursor chunk data_size handling hw/misc/ivshmem: clear chardev handlers before freeing peers linux-user/alpha: populate AT_HWCAP from env->amask linux-user/alpha: add coredump support s390x/css: firm up handling of chained TIC CCWs s390x/sclpcpi: check event length field before reading from buffer s390x/sclp: prevent re-reading the sclp header hw/misc/stm32_rcc: Correct offset-to-irq calculation hw/display/sm501: Don't allow guest to set ram size larger than it is hw/display/sm501: Avoid overflow problems in bounds check calculations hw/display/sm501: Catch bad coordinates for RTL operations ... - Fix bsc#1273022: * hw/i386/pc: xen: reinstate the "xenfv" machine alias (bsc#1273022) ==== samba ==== Version update (4.24.3+git.475.629de6765b9 -> 4.24.5+git.481.dba78dbdea) Subpackages: libldb2 samba-ad-dc-libs samba-client samba-client-libs samba-libs - Update to 4.24.5 * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server; (bso#16083);(bsc#1271672). * CVE-2026-58224: CTDB: heap OOB read via unchecked packet length fields;(bso#16085);(bsc#1271673). * CVE-2026-58216: kpasswd service: 6-byte heap OOB read in packet parser;(bso#16087);(bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes;(bso#16115);(bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover;(bso#16147);(bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes; (bso#16148);(bsc#1271677). - Update to 4.24.4 * Use-after-free in handling acls with claims and conditions; (bso#16095). * Compilers may ignore overflow checks - Fix tautological- compare warnings; (bso#16092). * restrict anonymous = 2 breaks RODC functionality; (bso#14638). * warning: assignment discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers]; (bso#16006). * Require NTLMv2 session security on Windows makes trusts to Samba unusable; (bso#16067). * winbindd stuck in init_dc_connection_rpc() returning NT_STATUS_TRUSTED_DOMAIN_FAILURE; (bso#16151). * domain\user not split when provided as username in smbc_set_credentials_with_fallback(); (bso#16149). ==== selinux-policy ==== Version update (20260715 -> 20260727) Subpackages: selinux-policy-targeted - Update to version 20260727: * pwaccessd_t uses nsswitch and newidmapd connects to pwaccessd_t socket (bsc#1271860) * adjust amavis spool path regex for openSUSE (bsc#1268627) * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366) * Support vfs_snapper to work with samba_share_t (bsc#1265400) * vfs_samba uses dbus to communicate with snapper (bsc#1265400) ==== shared-mime-info ==== Version update (2.4 -> 2.5.1) - Update to version 2.5.1: + Updated translations. - Changes from version 2.5: + Add type for Git repository bundles + Add application/vnd.ms-pki.seccat + Add binary magic to PKCS#7 types + Add common file extensions to PKCS and PKIX types + Add PEM identifiers from RFC 7468 + Make application/x-x509-ca-cert a subclass of application/pkix-cert + DOS batch/cmd files: add magic, tests, and *.cmd extension + Add application/x-hwpx + Add Android App Bundles + Fix APNG detection using non-fixed acTL chunk location; add APNG test cases + Add Farbfeld image support and fix its mime + Add type for LRC lyrics + Add text/vnd.plantuml + Add text/n3 + Add text/x-gradle-kts (and remove subclass for Gradle) + Add text/x-sed ("Sed script") + Add application/x-coff + Add application/vnd.ipld.car + Add application/x-brotli and fix brotli magic bytes + Add Playstation graphics (TIM) support + Add text/scriptlet + image/x-flic: fix and improve magic, add alias and generic icon + Add image/x-aseprite (LibreSprite/Aseprite image) and improve magic + Give CSV and TSV files the spreadsheet icon + application/texinfo: use IANA registered type + application/vnd.adobe.flash.movie: add ZWS magic + /matroska: use IANA registered non-x types + application/vnd.bzip3: use IANA registered type + Add PICO-8 (.p8/.p8.rom), TIC-80, Lowres NX, and CHIP-8 source/carts + Add RWL (Leica RW2) and more RAW image mime types; fix MOS mime + Add RVZ & WIA disc image files for GameCube & Wii + AWK family: recognise GNU and New AWK; awk scripts now text/x-awk + Shell scripts now text/*, like file/libmagic + Add MP4 Base Media v[2-5] alongside v1 + Add Slint language (text/slint) with magic and test + Assign video icon to application/vnd.ms-asf + Add ZX Spectrum & clone emulation formats + Add Commodore emulation file support + Add Nero Burning ROM NRG format + Add application/x-lx-executable + Add matches and test cases for .nds/.gba + application/vnd.nintendo.nitro.rom: use IANA registered type + Split audio/x-mod into correct formats; add audio/x-dsp and audio/x-ult test + Add text/x-nsis + Add support for Alpine Linux packages (.apk) + text/x-vala: add executable subclass and shebang magic support + application/x-ruby: add text/x-ruby alias + Add AMF 3D model mime-type + Add mimetypes for Simple File Format Family (SF3) files + Add mimetype for Microsoft Developer Studio files + Add HTTP Archive (HAR) json type + Add application/vnd.cyclonedx+xml and application/vnd.cyclonedx+json + Add text/spdx and application/spdx+json + Add OpenCL C and C++ for OpenCL types + image/vnd.radiance: add image/x-hdr alias; add Radiance HDR image format + Add application/x-pcapng and *.scap glob + Add mimetype for AVCI image + Detect OpenSSH public key and private key files + Add Proxy Auto-Configuration (PAC) + Add application/buildstream+yaml + Add text/x-dockerfile + Update mimetype for Typst source files + Add Portable HalfMap images + Update nushell mime type alias to text/x-nushell + Clean up matches for OLE/CFB based Word files + Add Apple Wallet passes bundle type application/vnd.apple.pkpasses + Add application/typescript; recognize *.cjs as text/javascript + Add comment and keyword magic to C-like source code + Move magic from text/x-csrc and text/x-objcsrc to text/x-objc++src + Add *.LRF glob to MPEG-4 videos + Add PFM, PXR and SCT image formats + Recognize *.sfs, *.sqfs, and *.squashfs as application/vnd.squashfs + Remove the relationship between AppImage and SquashFS + Remove redundant "MZ" magic from application/x-executable + Remove the office document icon from application/x-object + Recognize *.lib as application/x-archive + Rename back legacy OOoXML file formats + text/calendar: add *.ifb and *.icalendar globs and the calendar icon + Add text/x-nix + Add text/x-asm + Add image/x-kiss-cel + Prefer image/vnd.fpx over image/x-fpx and improve its detection + Remove text/htmlh + Add text/x-python2 and separate text/x-cython from ... changelog too long, skipping 48 lines ... - Switch to source service for tarball, and add new sub-module. ==== skopeo ==== Version update (1.22.2 -> 1.23.0) - Update to version 1.23.0: * Bump Skopeo to v1.23.0 * Bump c/common 0.68.0, c/image 5.40.0, c/storage 1.63.0 * Update common, image, and storage deps to 4a820ae * copy: add platform-based filtering via --multi-arch flag * Update module golang.org/x/term to v0.43.0 * Update common, image, and storage deps to abe824d * Update dependency golangci/golangci-lint to v2.12.2 * Update dependency golangci/golangci-lint to v2.12.1 * Update common, image, and storage deps to c03a490 * Update module github.com/Masterminds/semver/v3 to v3.5.0 * Packit: Only create dist-git PRs for rawhide * Cirrus: switch Sequoia matrix from Rawhide back to stable Fedora * Update common, image, and storage deps to b9d5b9a * Remove OWNERS file * Additional cleanup for go module changes * Move skopeo to go.podman.io * Update common, image, and storage deps to 618304d * Update module github.com/containers/ocicrypt to v1.3.0 * Update common, image, and storage deps to 129af75 * Update go.podman.io dependencies * Update module golang.org/x/term to v0.42.0 * Bump google.golang.org/grpc to v1.79.3 - CVE-2026-33186 * chore(deps): update module github.com/go-jose/go-jose/v4 to v4.1.4 [security] * fix(deps): update go.podman.io/storage digest to f0ddf1a * fix(deps): update common, image, and storage deps to 8af7873 * integration: Force amd64 on TestProxyMetadata * fix(deps): update common, image, and storage deps to 94ad023 * Try triggering an ostree image rebuild * chore(deps): update dependency golangci/golangci-lint to v2.11.4 * ci: add riscv64 to local-cross build target * cmd, proxy: use logic from the container-libs/common package * vendor: update go.podman.io/common * fix(deps): update common, image, and storage deps to ddaabae * Use --retry-times 3 for (skopeo sync) tests * Use t.Tempdir() instead of manual os.CreateTemp() in tests * Fix references to a wrong err * fix(deps): update module golang.org/x/term to v0.41.0 * Use fmt.Appendf instead of Sprintf + conversion * Use "any" instead of "interface{}" * Use WaitGroup.Go * Update to Go 1.25 * Update CI image and tests * Replace the boolean for schema1 registry with an enum * chore(deps): update dependency golangci/golangci-lint to v2.11.3 * fix(deps): update common, image, and storage deps to d48bc74 * Link to Podman's LLM policy * fix(deps): update github.com/opencontainers/image-spec digest to a4c6ade * fix(deps): update common, image, and storage deps to 854aaaf * Packit: Re-enable ELN tests * Add a --tls-details option and integration tests * Add an error return value to globalOptions.newSystemContext * Pass a SystemContext to signature.DefaultPolicy * Update container-libs after container-libs#623 * Packit: fix downstream post-modifications action * chore(deps): update dependency golangci/golangci-lint to v2.10.1 * chore(deps): update dependency golangci/golangci-lint to v2.9.0 * fix(deps): update module golang.org/x/term to v0.40.0 * fix(deps): update common, image, and storage deps to 0e2aefd * Update tests for a changed error message * fix(deps): update common, image, and storage deps to b5801a6 * fix(deps): update common, image, and storage deps to b2572af * fix(deps): update module github.com/sirupsen/logrus to v1.9.4 * fix(deps): update common, image, and storage deps to e7626b7 * fix(deps): update module golang.org/x/term to v0.39.0 * chore(deps): update dependency golangci/golangci-lint to v2.8.0 * Document the default of --retry-times * chore: fix function name in comment * skopeo: add `--require-signed` * integration/signing_test: move findFingerprint to utils_test.go * fix(deps): update common, image, and storage deps to b0f86df * Update c/common to match #2765 * fix(deps): update common, image, and storage deps to afd10d8 * chore(deps): update dependency golangci/golangci-lint to v2.7.2 * fix(deps): update module golang.org/x/term to v0.38.0 * Packit: use `post-modifications` hook to update downstream TMT plan * docs: manpage update for `skopeo inspect --manifest-digest` * inspect: --manifest-digest flag * vendor: container-libs commit 01833ef7b7f1d306205be7fa6fb36d0d6a6e3a33 * chore(deps): update dependency golangci/golangci-lint to v2.7.1 * fix(deps): update module github.com/spf13/cobra to v1.10.2 * chore(deps): update dependency golangci/golangci-lint to v2.7.0 * Bump version to 1.22.0-dev * Update common, image, and storage deps to 63be353 * Try triggering an image rebuild * Update common, image, and storage deps to 22d50c5 * Update dependency golangci/golangci-lint to v2.6.2 * vendor: Fetch the latest from container-libs main * golangci-lint: enable gofumpt formatter * format the code with gofumpt * Packit: tmp disable ELN tests * fix(deps): update module golang.org/x/term to v0.37.0 ==== slirp4netns ==== Version update (1.3.3 -> 1.3.4) - Update to 1.3.4 * No change on the source code. So, this release is not worth upgrading, unless you are using the official statically-linked binary release. * The official statically-linked binaries are updated to be linked with the new version of libslirp: v4.9.1 -> v4.9.2 (#362). ==== spice-vdagent ==== - bsc#1269553 - VUL-0: CVE-2026-57965: spice-vdagent: integer overflow in `udscs_write()` can lead to heap buffer overflow Prevent-integer-overflow-in-udscs_write-buf_size-calculation.patch - bsc#1269554 - VUL-0: CVE-2026-57966: spice-vdagent: improper sanitization allows a compromised SPICE host to write arbitrary files to any location on the guest operating system Reject-path-traversal-in-file-transfer-filenames.patch ==== sssd ==== Subpackages: libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap - Enable sssd-idp. This provides external Identity Provider (OAuth2/OpenID Connect) support. Also enables the krb5 idp plugin. ==== systemd ==== Version update (260.3 -> 261.2) Subpackages: libsystemd0 libudev1 systemd-boot systemd-container udev - Import commit 4925d9f07fc697efccd98a93046ff535b8832445 (merge of v261.2) For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/eff9446d505d62c075bed37d606860b38cfe51fb...4925d9f07fc697efccd98a93046ff535b8832445 - Move systemd-vmspawn from the experimental sub-package to systemd-container - Upgrade to v261 (commit eff9446d505d62c075bed37d606860b38cfe51fb) See https://github.com/openSUSE/systemd/blob/SUSE/v261/NEWS for details. ==== tar ==== - Add tar-assume-dir-size-0.patch * Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes (bsc#1271272) ==== tesseract-ocr ==== Version update (5.5.2 -> 5.5.3) Subpackages: libtesseract5 tesseract-ocr-common - Update to version 5.5.3: * Fix missing closing tags in multi-page PAGE XML output * Correct a mutex call to prevent multiple instances * Document memory ownership and lifecycle in the C API * Fix CMAKE_SYSTEM_PROCESSOR detection when cross-compiling on Apple platforms - Switch the documentation BuildRequires from asciidoc to rubygem(asciidoctor): upstream now generates the man pages with asciidoctor and silently skips them otherwise - Drop the gcc13 fallback for Leap 15.x: 15.6 is out of support and its repository has been retired from the devel project ==== update-bootloader ==== Version update (1.27 -> 1.28) - merge gh#openSUSE/update-bootloader#197 - fix test suite - adjust two tests - updated test results - fix command line parser (bsc#1271602) - add test case - update test result - fix and reenable ksh tests: ksh uses alts now - update ksh test results - 1.28 ==== util-linux ==== Version update (2.42.1 -> 2.42.2) Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ==== util-linux-systemd ==== Version update (2.42.1 -> 2.42.2) Subpackages: lastlog2 liblastlog2-2 - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ==== vim ==== Subpackages: vim-data-common vim-small - Guard suse.vimrc against missing syntax without vim-data ==== wpa_supplicant ==== - Add mesh-Reject-AMPE-MIC-element-with-length-AES_BLOCK_S.patch https://w1.fi/security/2026-4/ ==== wtmpdb ==== Version update (0.75.0+git20251130.0d8fe7a -> 0.76.0+git20260730.89c0861) Subpackages: libwtmpdb0 - Update to version 0.76.0+git20260730.89c0861: * Release version 0.76.0 * CI: get rid of obsolete actions * Use _cleanup_, adjust formating * rotate: keep open entries after last boot * wtmpdb: use different variable for (const) char * * Update mkdir_p to fix error code for last call * ignore absence of systemd * ignore absense of dbus ==== zimg ==== Version update (3.0.6+20250919.gdf9c147 -> 3.0.6+20260720.g1ad1895) - Update to version 3.0.6+20260720.g1ad1895: * colorspace: add chromatic adaptation support, disabled by default (new zfilter_graph_builder_params field, required by VapourSynth R78) * colorspace: add BT.1361 transfer characteristics, simplify the xvYCC EOTF, add FMA and F16C feature checks, fix the hash function and an assertion on 240M->709 gamma * depth: add NEON-optimized error diffusion dithering * resize: fix integer weight rounding compensation and impose a maximum tap count on Lanczos * Fix out-of-bounds accesses in several SIMD code paths: the AVX2 u16 permute resizer load, AVX2 and NEON ordered dither reads, NEON error diffusion read, NEON float-to-half write, NEON byte-to-word left-shift read and the AVX2 unresize buffer size calculation * unresize: special-case the LU decomposition of a 1x1 matrix and use double epsilon * common: fix matrix row offset tracking after compaction * graph: fix the 64-byte alignment check, rename factory to observer * Update the bundled graphengine * Test-only, MSVC/Windows and example-code changes omitted here ==== zstd ==== Subpackages: libzstd1 - Cleanup .spec file