Packages changed: AppStream (1.1.5 -> 1.2.0) MicroOS-release (20260915 -> 20260919) aaa_base (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202) apparmor at-spi2-core (2.60.6 -> 2.60.7) bluez (5.82 -> 5.87) ca-certificates-mozilla (2.84 -> 2.90) crypto-policies cryptsetup (2.8.7 -> 2.8.8) gettext-runtime glslang (16.5.0 -> 16.6.0) grub2 kdump (2.1.9 -> 2.1.10) kernel-source (7.2.5 -> 7.2.6) libapparmor libcanberra libsoup mozilla-nspr ncurses (6.6.20260815 -> 6.6.20260912) newt nvme-cli (3.0+6.g1ac60ca4b -> 3.1) pam pam-full-src permissions (1699_20260806 -> 1699_20260917) pipewire (1.6.8 -> 1.6.9) poppler (26.07.0 -> 26.09.0) poppler-qt6 (26.07.0 -> 26.09.0) pulseaudio-qt6 (1.8.1 -> 1.9.0) python-greenlet (3.5.5 -> 3.5.6) python313 (3.13.14 -> 3.13.15) python313-core (3.13.14 -> 3.13.15) rpm selinux-policy (20260910 -> 20260914) shaderc (2026.3 -> 2026.4) snappy (1.2.2 -> 1.3.0) sssd timezone (2026c -> 2026d) vmaf (3.2.0 -> 3.2.1) xz (5.8.3 -> 5.8.4) === Details === ==== AppStream ==== Version update (1.1.5 -> 1.2.0) Subpackages: libAppStreamQt3 libappstream5 - Update to 1.2.0 * This release marks the libappstream-compose API as stable. * This release introduces a new, lightly sandboxed (on Linux) media worker for appstream-compose and switches to VIPS for image processing. * This release introduces My headline! markup for AppStream descriptions. Older versions will remove this markup, so only use it if your target clients have a recent version of AppStream. Features: * compose: Create AscMedia for isolated out-of-process media handling using asc-mediaworker * compose: Process images, fonts & videos via the media worker * Generalize path segment validation, use it in the compose media worker * compose: Switch from using GdkPixbuf to VIPS for image processing * compose: Harmonize supported formats, don't read XPM/TIFF/BMP * compose: Make JPEG-XL the default image output format * compose: Implement basic support for FreeBSD * compose: Rely on VIPS for SVG support, drop our dedicated librsvg path * compose: Make image-targets and image batch-processing public API * compose: Expose the source-icon convention and a hint-tag lookup as public API * compose: Drop unstable-API marker * compose: Don't create image thumbnails that aren't substantially smaller * compose: Only transfer pre-opened fds and no more directory fd to the worker * compose: Implement a basic sandbox for the mediaworker using Landlock * compose: Use RESTRICT_SELF_TSYNC and block UDP access on newer Landlock * compose: Mix the output image format type into the GCID * compose: Make AscUnit a proper abstract class * compose: Improve API documentation * Always sanitize whitespaces in keywords and drop empty ones * Assume a language element without percentage means full translation * news-to-metainfo: Support a details URL in the YAML variant * news-convert: Support inline Markdown in news text * news-convert: Support headers in XML<->YAML/NEWS/Markdown conversions * ascli: news-convert: Support standalone release XML as source/target * Whitespace-sanitize all description markup we read * Output descriptions as literals in YAML and wrap markup ourselves Specification: * docs: Document the appstreamcli news file conversion helper * Implement support for headings in description markup Bugfixes: * meson: Set _POSIX_C_SOURCE on Linux only * compose: Fix a race where units were deleting each other's icon directories * compose: Fix documentation and introspection annotation issues * compose: Drop dead public API, make some API private * compose: Sharpen with libvips instead of a hand-rolled unsharp mask * compose: Only read AVIF from HEIF containers, never HEIC * compose: Fix double-free crash when processing fonts * compose: Guard against bad locale in path names * compose: Ensure component-IDs are safe to use in filesystem paths * compose: Escape values for HTML reports, and create proper plain-text if needed * compose: Make missing-launchable-desktop-file an error * Fix a few translator hints that weren't picked up properly * Don't accept empty strings as URLs * its: Fix description inline markup translation for release data * validator: Fix improper use of variadic arguments * validator: Properly validate component-IDs with random UTF-8 characters * validator: Abort ID validation after the first invalid character * pool: Resolve crash if data locations are changed on a loaded pool * Fix wrong string comparison when detecting arm64 machines * ascli: Resolve crash when selection is cancelled in install/remove * Fix another crash when converting invalid description markup to Markdown * apt: Treat icon tarballs as hostile, instead of trusted * apt: Fix empty-directory check nuking the icon cache on every refresh * utils: Ensure we never ever follow symlinks when recursively deleting caches * xml: Only emit description enumerations for locales that are in them * cache: Never infinite-recurse when resolving addons for a component * yaml: Don't leave old header data around when parsing multiple YAML catalogs Miscellaneous: * compose: Stop leaking private symbols out of the shared library ... changelog too long, skipping 22 lines ... * ascli: Guard against bad bundle values when calling "install" ==== MicroOS-release ==== Version update (20260915 -> 20260919) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== aaa_base ==== Version update (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202) - Update to version 84.87+git20260916.e122202: * For new GNU Emacs 31.1: use lexical-binding * Let us now fix this syntax error in ls.bash - Update to version 84.87+git20260812.c6d42af: * added requires for gzip and tar to aaa_base-extras (boo#1274604) * fix(ls): deprecate ls.zsh * fix(ls.bash): use alias, func breaks sudo alias * fix(ls.bash): avoid breaking sudo alias expansion * drop dirs from the specfile, they live in the filesystem package ==== apparmor ==== - update wg-quick.diff to fix setting DNS (boo#1265394) ==== at-spi2-core ==== Version update (2.60.6 -> 2.60.7) Subpackages: libatk-1_0-0 libatk-bridge-2_0-0 libatspi0 typelib-1_0-Atk-1_0 typelib-1_0-Atspi-2_0 - Update to version 2.60.7: + libatspi: Fix transfer annotation on atspi_document_get_text_selections. + atk-bridge: Release disconnected direct connections. ==== bluez ==== Version update (5.82 -> 5.87) Subpackages: bluez-cups libbluetooth3 - ver 5.87: * Patches removed: hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) hcidump-Fixed-malformed-segment-frame-length.patch (Source file does not exist anymore) bluez-mainloop-Only-connect-to-NOTIFY_SOCKET-if-STATUS-Sta.patch (included in upstream) CVE-2016-9800-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) CVE-2016-9804-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) upstream changes: Fix issue with GATT database and out of sync errors. Fix issue with BASS and setting a stream to idle. Fix issue with BASS and rescanning broadcast sources. Fix issue with BAP and broadcast sink cleanup. Fix issue with BAP and endpoint configuration. Fix issue with BAP and ASE control point properties. Fix issue with BAP and BIG/BIS receiver QoS structures. Fix issue with AVRCP and tracking of TG and CT events. Fix issue with PBAP and Database Identifier length. Fix issue with MCP and ATT disconnect events. ver 5.86: Fix issue with number of retries on authentication failures. Fix issue with G.722 @ 16 kHz codec ID value reported by transport. Add support for Telephony interface. Add support for Ranging profile. Add support for GMAP service. Add support for TMAP service. ver 5.85: Fix issue with handling display of battery charge level. Fix issue with BASS permissions not requiring encryption. Fix issue with handling abort for OBEX SRM operation. Fix issue with handling device privacy. Add support for HFP call answer support. Add support for HFP simple 3-way call support. ver 5.84: Fix issue with AVRCP and handling invalid UTF-8 item name. Fix issue with exposing coordinate sets if LE Audio is disabled. Fix issue with BAP and not responding to SetConfiguration. Add support for BAP unicast endpoint reconfiguration. Add support for BASS and encrypted broadcast source. Add support for HFP and Call Line Identification. ver 5.83: Fix issue with handling BAP and removal of PAC. Fix issue with handling SID for broadcast receiver. Fix issue with handling HSP/HFP reconnection policy. Fix issue with handling cable pairing and Sixaxis controllers. Fix issue with handling virtual cable unplug for HID devices. Fix issue with handling service records for HID devices. Add support for AVDTP and TX timestamps. ==== ca-certificates-mozilla ==== Version update (2.84 -> 2.90) - Updated to 2.90 state (bsc#1279961) - Removed: - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - certSIGN ROOT CA - Entrust Root Certification Authority - PKI Root Certification Authority - FIRMAPROFESIONAL CA ROOT-A WEB - GLOBALTRUST 2020 - Secure Global CA - SecureSign Root CA12 - SecureTrust CA - TeliaSonera Root CA v1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - XRamp Global Certification Authority - Added: - SECOM SMIME RSA Root CA 2024 - SECOM TLS ECC Root CA 2024 - SECOM TLS RSA Root CA 2024 - SecureSign Root CA16 - Telia EC Email Root CA v3 - Telia EC TLS Root CA v3 - Telia RSA Email Root CA v3 - Telia RSA TLS Root CA v3 ==== crypto-policies ==== - Add configure-python-interpreter.patch removing dependency on `python3-base`, all Python scripts are now dependent on the primary Python interpreter directly without `/usr/bin/python3` mediation. ==== cryptsetup ==== Version update (2.8.7 -> 2.8.8) Subpackages: libcryptsetup12 - Update to 2.8.8: * integritysetup: add support for keyed discards. An integrity device in standalone mode, with a keyed integrity algorithm like HMAC and enabled discards (TRIM), could be vulnerable to wiping part of the device using a discard pattern. This issue can be worked around by using a keyed discards filler. Once set, it is set permanently for the integrity device and cannot be reverted. Integritysetup now supports a new --allow-discards-keyed option. Once used, it will upgrade the superblock and activate keyed discards. After the upgrade, keyed discards are always used, even with the old --allow-discards option. Keyed discard is available since Linux kernel 7.3. Note: Integritysetup was intended to be used with non-cryptographic integrity protection only. If you need cryptographic protection, use LUKS2 and AEAD (discards are not supported). * Avoid time-of-check/time-of-use (TOCTOU) issue in LUKS header restore. The LUKS header restore function validates the provided header file and then reopens the same file path to restore the LUKS header. In a specifically crafted environment, a symlink flip could occur between validating and restoring the header, resulting in a different file being used for the LUKS header restore (potentially leaking the file content). The libcryptsetup now opens the device only once. The issue affects both LUKS1 and LUKS2. Note: LUKS header backup/restore is a system administrative task (similar to filesystem backup/restore) that must run in a secure environment. Such a backup is usually a multi-step process, and it is up to the caller to ensure security of that environment. * BITLK: harden metadata validation. If a crafted BITLK (BitLocker-compatible) image is opened, the allocated buffer size for the key can be incorrect. This can happen if the encryption is changed from AES-CBC-128 to a mode with an Elephant diffuser, without recalculating the stored key. Also, the data offset can be intentionally wrong, which could lead to an infinite loop when parsing metadata. Note that creating such an incorrect image requires knowledge of the disk password, as MAC protects the metadata, and this MAC is checked by cryptsetup. * Fix possible integer overflow in LUKS metadata parsing. On systems with a 32-bit integer size, the anti-forensic (AF) data size calculation could overflow, causing an application crash. * cryptsetup: fix local memory corruption bug in reencrypt init. If a device intended for reencryption contains more than 16 active LUKS2 keyslots or tokens, the reencryption initialization could corrupt internal memory, leading to an application crash. ==== gettext-runtime ==== Subpackages: envsubst libtextstyle0 - Fix for automake1.19: Update patch 0001-msgcat-Add-feature-to-use-the-newest-po-file.patch with Makefile.in so the build doesn't try to regenerate this file with automake-1.18 ==== glslang ==== Version update (16.5.0 -> 16.6.0) - Update to release 16.6.0 * Implemented `GL_EXT_cooperative_matrix_maintenance1`, `GL_EXT_optional_input_attachment_index`, and `DebugEntryPoint` for `NonSemantic.Shader.DebugInfo` 102. ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-common grub2-snapper-plugin - Add SBAT Provides to support shim SBAT dependency checks (bsc#1278729) ==== kdump ==== Version update (2.1.9 -> 2.1.10) - upgrade to version 2.1.10 * calibrate: measure per-cpu requirements * kdumptool calibrate: take KDUMP_CPUS into account for PPC * PPC: round up KDUMP_CPUS on SMT systems to nearest threads-per-cpu * Set default KDUMP_CPUs to 4 (jsc#PED-16732, bsc#1239999) * add KDUMP_USE_CMA: experimental support for CMA reservation (jsc#PED-14553) - update calibrate values ==== kernel-source ==== Version update (7.2.5 -> 7.2.6) Subpackages: kernel-64kb kernel-default - RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables (git-fixes). - commit 3d19f11 - Update patches.kernel.org/7.2.4-160-nfsd-add-fh_want_write-for-early-verified-SETAT.patch (bsc#1012628 CVE-2026-89697 bsc#1280148). - Update patches.kernel.org/7.2.4-163-nfsd-block-non-SAVEFH-ops-after-FOREIGN-PUTFH-t.patch (bsc#1012628 CVE-2026-89696 bsc#1280146). - Update patches.kernel.org/7.2.4-164-nfsd-cap-decoded-POSIX-ACL-count-to-bound-sort-.patch (bsc#1012628 CVE-2026-89695 bsc#1280155). - Update patches.kernel.org/7.2.4-165-nfsd-check-client-ownership-when-cancelling-a-c.patch (bsc#1012628 CVE-2026-89694 bsc#1280151). - Update patches.kernel.org/7.2.4-166-nfsd-check-nfsd4_acl_to_attr-return-value-in-nf.patch (bsc#1012628 CVE-2026-89693 bsc#1280153). - Update patches.kernel.org/7.2.4-167-nfsd-clear-CALLBACK_RUNNING-on-failed-delegatio.patch (bsc#1012628 CVE-2026-89692 bsc#1280167). - Update patches.kernel.org/7.2.4-168-nfsd-clear-opcnt-on-compound-arg-release-to-pre.patch (bsc#1012628 CVE-2026-89691 bsc#1280163). - Update patches.kernel.org/7.2.4-172-nfsd-defer-vfree-of-compound-ops-to-fix-rpc_sta.patch (bsc#1012628 CVE-2026-89690 bsc#1280166). - Update patches.kernel.org/7.2.4-173-nfsd-don-t-free-session-slots-that-are-still-in.patch (bsc#1012628 CVE-2026-89689 bsc#1280174). - Update patches.kernel.org/7.2.4-174-nfsd-drop-the-stateid-not-the-stateowner-on-seq.patch (bsc#1012628 CVE-2026-89688 bsc#1280171). - Update patches.kernel.org/7.2.4-175-nfsd-ensure-nfsd_file_do_acquire-does-not-use-a.patch (bsc#1012628 CVE-2026-89687 bsc#1280173). - Update patches.kernel.org/7.2.4-176-nfsd-fix-BUG_ON-in-nfsd4_alloc_layout_stateid-o.patch (bsc#1012628 CVE-2026-89686 bsc#1280184). - Update patches.kernel.org/7.2.4-177-nfsd-fix-clock-domain-mismatch-in-clients_still.patch (bsc#1012628 CVE-2026-89685 bsc#1280179). - Update patches.kernel.org/7.2.4-178-nfsd-fix-cpntf-publish-race-in-nfs4_init_cp_sta.patch (bsc#1012628 CVE-2026-89684 bsc#1280178). - Update patches.kernel.org/7.2.4-179-nfsd-fix-dentry-ref-leak-on-V4ROOT-export-fileh.patch (bsc#1012628 CVE-2026-89683 bsc#1280193). - Update patches.kernel.org/7.2.4-180-nfsd-fix-fcache_disposal-UAF-by-inlining-dispos.patch (bsc#1012628 CVE-2026-89682 bsc#1280191). - Update patches.kernel.org/7.2.4-182-nfsd-fix-layout-fence-worker-double-reference-r.patch (bsc#1012628 CVE-2026-89681 bsc#1280189). - Update patches.kernel.org/7.2.4-184-nfsd-fix-nfsd_file-leak-on-inter-server-COPY-se.patch (bsc#1012628 CVE-2026-89680 bsc#1280206). - Update patches.kernel.org/7.2.4-185-nfsd-fix-null-dereference-in-nfsd4_setattr-for-.patch (bsc#1012628 CVE-2026-89679 bsc#1280203). - Update patches.kernel.org/7.2.4-186-nfsd-fix-partial-write-detection-in-nfsd_direct.patch (bsc#1012628 CVE-2026-89678 bsc#1280199). - Update patches.kernel.org/7.2.4-187-nfsd-fix-possible-fh_compose-of-wrong-dentry-in.patch (bsc#1012628 CVE-2026-89677 bsc#1280224). - Update patches.kernel.org/7.2.4-190-nfsd-fix-stale-s2s_cp_stateids-IDR-entry-for-as.patch (bsc#1012628 CVE-2026-89676 bsc#1280219). - Update patches.kernel.org/7.2.4-191-nfsd-fix-UAF-in-async-copy-cancel-and-shutdown.patch (bsc#1012628 CVE-2026-89675 bsc#1280216). - Update patches.kernel.org/7.2.4-193-nfsd-fix-XDR-length-calculation-in-nfsd4_ff_enc.patch (bsc#1012628 CVE-2026-89674 bsc#1280243). - Update patches.kernel.org/7.2.4-194-nfsd-fix-XDR-padding-calculation-in-ff_encode_g.patch (bsc#1012628 CVE-2026-89673 bsc#1280237). - Update patches.kernel.org/7.2.4-195-nfsd-gate-nfs2-setacl-by-argp-mask.patch (bsc#1012628 CVE-2026-89672 bsc#1280235). - Update patches.kernel.org/7.2.4-196-nfsd-gate-nfs3-setacl-by-argp-mask.patch (bsc#1012628 CVE-2026-89671 bsc#1280252). - Update patches.kernel.org/7.2.4-197-nfsd-hold-rcu-across-localio-cmpxchg-retry.patch (bsc#1012628 CVE-2026-89670 bsc#1280250). - Update patches.kernel.org/7.2.4-198-nfsd-initialize-copy-notify-stateid-before-publ.patch (bsc#1012628 CVE-2026-89669 bsc#1280251). - Update patches.kernel.org/7.2.4-200-nfsd-move-nfsd_debugfs_init-after-nfsd4_init_sl.patch (bsc#1012628 CVE-2026-89668 bsc#1280279). - Update patches.kernel.org/7.2.4-201-nfsd-close-shrinker-GC-fsnotify-vs-per-net-shut.patch (bsc#1012628 CVE-2026-89667 bsc#1280261). - Update patches.kernel.org/7.2.4-205-nfsd-release-OPEN-decoded-posix-ACLs-via-op_rel.patch (bsc#1012628 CVE-2026-89664 bsc#1280272). ... changelog too long, skipping 3681 lines ... - commit 16c1085 ==== libapparmor ==== - update wg-quick.diff to fix setting DNS (boo#1265394) ==== libcanberra ==== - Migrate to xz compression and manual service run ==== libsoup ==== - Add libsoup-CVE-2026-85534.patch: Never send more body bytes than nghttp2 requested (bsc#1279239, CVE-2026-85534) - Add libsoup-CVE-2026-85197.patch: fix crash in on_data_read after connection has been destroyed (bsc#1279238, CVE-2026-85197) ==== mozilla-nspr ==== - Add Make-x86-assembly-files-compatible-with-SHSTK-IBT.patch to support -fcf-protection in assembly sources. ==== ncurses ==== Version update (6.6.20260815 -> 6.6.20260912) Subpackages: libncurses6 ncurses-utils terminfo-base - Work around common name in certificate of www.invisible-island.net - Add ncurses patch 20260912 + build-fix for sizeof(mmask_t) configure check (cf:20260829). + review/fix teraterm* (report by Jakub Horky) + modify flash for vt525 to use DECRARA (patch by Branden Robinson) + update config.guess, config.sub - Add ncurses patch 20260905 + modify endwin() and doupdate() to save/restore keypad and meta modes (report by Ferenc Wagner). + improve range-checks for xterm X10 and SGR mouse protocol. + correct modifier-masking for buttons 6-11 in mouse version 3 (report by Ravi Arnan Irianto). + build-fix for Ada95 with ABI 7 (report by Branden Robinson) - Add ncurses patch 20260829 + add configure check to ensure that mmask_t is large enough for the configured mouse version (report by Ravi Arnan Irianto) + add mouse-parsing for extended buttons with mouse version 3 (report by Ravi Arnan Irianto). - Add ncurses patch 20260822 + add a limit-check in wborder (patch by Bjoern Foersterling). + improve limit-checks for trace calls in read_entry.c (report by Yeo JooHo). + improve tic warnings regarding the empty smir/rmir strings which may be added in dump_entry.c for termcap if ich/ich1 are present but smir/rmir are not. + add sun+fkeys -TD + add dtterm-sk, dtterm+sk -TD + add ich1 to several entries, providing for support of non-curses applications via termcap only -TD + add dch/dch1 to rxvt-basic -TD + drop redundant xterm=setaf2 (patch by Branden Robinson) + documentation improvements (patches by Branden Robinson). + improve color discussion in man pages + improve formatting/style of man pages > improve wide-character support with UCRT (patches by Liu Hao) + use UCRT's wcrtomb rather than _nc_wctomb + skip trailing cells of double-width characters ==== newt ==== - Use %python3_version instead of the obsolete %py3_ver. ==== nvme-cli ==== Version update (3.0+6.g1ac60ca4b -> 3.1) Subpackages: libnvme3-1 - Update to version 3.1: * Release v3.1 * doc: Regenerate all docs for v3.1 * tests: NUL-terminate literals copied into dc_entry_is_self() test data * plugin: fix out-of-bounds read of argv[1] in help() with no sub-argument * libnvme: fix NBFT entry list leak in libnvmf_discover_nbft() * huawei: guard against a null list_items in huawei_json_print_list_items() * solidigm: also guard against a null ilog in ilog_dump_identify_page() * plugins/sandisk: fix uninitialized market_name_len in enc_drive_capabilities * plugins/exclusion: fix errno reliance in read_file() * plugins/sandisk: update version * plugins/sandisk: use nvme_get_pci_ids * plugins/sandisk: port vs-smart-add-log from wdc * libnvme: reject a persona hostnqn with no hostid * shared: drop the retry loop from shr_read_file()/shr_read_file_as_string() * shared: return error codes from shr_read_file() and shr_read_file_as_string() * tests: bound the interface name copy in mock-ifaddrs init_entry() * wdc: use shr_getrandom() for the send/receive correlation handle * rpmb: use shr_getrandom() for the authentication nonce * keys: check chmod() return value in append_keyfile() * shared: add shr_getrandom() * solidigm: fix NULL DMA target in ilog_dump_pel() * tests: fix unit mismatch in test_admin_fw_download_cb's data check * innogrit: remove dead fclose() guards before the first fopen() in getcdump * solidigm: fix unreachable error-recovery path in parse_tracker_chunk_json() * nvme: fix nvme_decide_retry() always returning false * nbft: fix truncated PCI segment number in pci_sbdf_to_string() * ocp: check ocp_get_uuid_index() before issuing the get-log command * tests,tree-fabrics: check and acknowledge return values * mi-mctp: fix endian conversion direction for MPR retry time * fs-util: restore path separator unconditionally in shr_mkdir_p() * tests: check write() return value in test_read_all() * wdc: bound the device-reported Capture Diagnostics log length * solidigm: replace read_file2buffer() with shared file-reading helpers * sandisk: fix 32-bit overflow and unchecked realloc in sndk_do_cap_udui * mi-mctp-ae: bound the AE number before indexing the enabled-events map * shared: use memmove() for the sha256 intra-buffer carry-over copy * fabrics: fix NULL dereference in dc_log_decision() * netapp: fix NULL format string in netapp_smdevices_print_regular() * tests: fix NULL dereference in mi-mctp aem_handler() * ocp: fix NULL dereference and zero-fill bug in parse_event_fifo() * nvme-print: bound-check FDP config descriptor walk against log size * nvme-print: fix endian bugs and bound the EOM descriptor walk * nvme-print: fix integer overflow in EOM descriptor offset * shared: add shr_buf_has_room() * tests: fix dangling pointer in test_nvmf_sanitize_addrs() * tests: use shr_read_file_as_string() in shr_table tests * tests: fix uninitialized buffer and NULL %s in check_normalize() * shared: add shr_read_file_as_string() * scaleflux: fix scandir(3) result leak in nvme_expand_cap * wdc: fix out-of-bounds read of pre-v4 cloud smart log hardware revision * nvme-print,fabrics: fix uninitialized reads * utils: fix allocation leak in copy_options() * shannon: fix file descriptor leak in set_additional_feature() * rpmb: validate config block size before write * discoverd: honor persistent=force against EPCSD=0 * resv-plugin: size the resv report from the registrant count * ccan: cast pointers to void * in fprintf for %p format specifier * libnvme: pick the right self entry on a multi-homed DC * discoverd: use __cleanup_tid in two loops * sandisk: fix stack buffer overflow in C2 marketing-name parser * discoverd: validate DLPE target before host-side inheritance * nvme-models: fix pci.ids parser line loss * tests: check errno after rewind in capture helpers * huawei: null-check root/devices in huawei_json_print_list_items * solidigm: guard ilog->cfg dereference in ilog_dump_identify_page * libnvme: initialize TLS key IDs * exclusion: preserve errno across free/fclose in read_file * nvme-print-json: fix leaks in json_phy_rx_eom_descs * wdc: close output file via __cleanup_file in wdc_enc_get_log * lm: fix double fclose in lm_migration_send * completions: document no-trailing-space insertion checks in TESTING.md * completions: test the generator against a synthetic fixture * nvme-print-json: use CAP property fields string table * nvme-print: add CAP property fields string table * nvme-print-json: combine obj_add_str and obj_add_string duplicated * nvme-print: change string variables as constant * nvme-print-json: fix to output alloc_error * nvme-print-stdout: use libnvme API to print CAP property * nvme-types-base: fix CAP property NSSRS bit name * nvme-types-base: add CAP property NSSES bit * nvme-types-base: change file header description NVMe revision to 2.4 * micron: clamp num_entries in vs-fw-activate-history to the table size * seagate: clamp supported-log-pages count and keep JSON clean * libnvme: add test for var_size_tags 32B guard sts range * tests: cover invalid_tags() STS-too-wide rejection * libnvme: fix undefined shifts in nvme_init_var_size_tags() 32B guard case * nvme: reject out-of-range storage tag size in invalid_tags() * shared: drop dead `at_line_start = true` in shr_print_word_wrapped() * solidigm: drop dead initializer in telemetry_log_data_area_get_offset() * solidigm: report failure restoring workload-tracker config * huawei: check libnvme_get_nsid() failure in huawei_get_nvme_info() * micron: drop dead `err = 0` in micron_telemetry_log() * ocp: fix empty-description case in parse_ocp_telemetry_string_log() * ocp: drop dead m_512_sz/m_512_off initial stores in get_telemetry_dump() * sandisk: drop dead stores flagged by clang-analyze * sandisk: fix telemetry write error handling, drop a dead store * wdc: fix telemetry write error handling, drop dead stores * huawei: skip a list entry if its JSON object fails to allocate ... changelog too long, skipping 47 lines ... * feat: add remaining feature commands ==== pam ==== - Apply livepatching only for SLES, not for Factory. Keeping lto optimisation for openSUSE. * On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS. - Make sure we don't lose distribution compiler flags. ==== pam-full-src ==== - Apply livepatching only for SLES, not for Factory. Keeping lto optimisation for openSUSE. * On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS. - Make sure we don't lose distribution compiler flags. ==== permissions ==== Version update (1699_20260806 -> 1699_20260917) Subpackages: permctl permissions-config - Update to version 1699_20260917: * profiles: added CAP_PERFMON for ksystemstats_xe_helper (bsc#1280113) * profiles: document nvidia-modprobe's special case ==== pipewire ==== Version update (1.6.8 -> 1.6.9) Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Update to version 1.6.9: * This is a bugfix release that is API and ABI compatible with the previous 1.6.x releases. * Highlights - Improve JACK object callbacks, avoid reporting old removed objects. - Tweak the resampler cutoff frequencies to preserve more high frequencies when upsampling. - More small fixes and improvements. * Modules - Fix RAOP encryption for OpenSSL >= 3. (#5370 (closed)) - Fix netjack2 discovery timeout. - Fix potential truncated audio in RAOP. - Fix potential metadata update problems. (#5445 (closed)) - Fix RAOP over TCP. - Fix potential overflows in client node buffer checks. (#5462) - Add node.network=true to network sinks and sources so that pavucontrol and others don't wake them up. (#3268 (closed)) * SPA - Fix opus audio info type. - Tweak the upsample cutoff frequencies to preserve more high frequencies when upsampling. (#5390 (closed)) - Fix filter-graph property notification in some cases. - Remove limits on filter-graph descriptions in audioconvert. - Improve dynamic reconfiguration of filter-graphs in audioconvert. - Improve passthrough format handling in audioconvert. - Improve the FC and LFE volumes when upmixing is enabled. - Fix v4l2 controls when one can not be read. - Require 0.6.0 libcamera now. - Improve format filtering in v4l2. * Pulse-server - Don't let a pending sibling message starve capture. - Fix name of ALSA source. - Fix potential crash with the active_port_name. (#5435 (closed)) * Bluetooth - Fix a potential leak when transport fails to start. - Fix potential crash when cleaning up iso-io transport. * JACK - Rework the object lookups to avoid removed objects from leaking. (#5356 (closed)) * GStreamer - Add fixes for state changes and other lockups. * ALSA Plugin - Generate poll errors when stopping. (#5444 (closed)) * Tools - Handle EOF correctly for encoded files in pw-cat. - Fix loopback channel and position handling. - Fix mp3 encoding in pw-record. - Support A-law in pw-record. - Disable libcamera support when building in Leap 16.1 or older since pipewire now needs at least libcamera 0.6.0 . ==== poppler ==== Version update (26.07.0 -> 26.09.0) - Update to version 26.09.0: + core: - Subset fonts when saving changes in Annotations and Forms when using fontconfig - NSS: Don't infinite loop on wrong password - Internal code improvements - Fix crashes in malformed documents + utils: - pdftotext: Add -urls option to print link URLs next to their text - pdftohtml: Improve speed by ignoring tiling patterns earlier - pdfimages: Fix typo in manpage + glib: Remove G_GNUC_CONST in enum _get_type funcs + build system: harfbuzz is now required for font subsetting - Changes from version 26.08.0: + core: - GPG based signature improvements - Internal code improvements + utils: - pdftohtml: Fix crash when using dataurls. - pdfimages: Add min-height and min-width options + glib: Stop using G_GNUC_CONST in _get_type funcs + build system: - Slight increase in compilation of utils folder - Fix -Wunused-command-line-argument when using clang - Use cmake modern way to check for linker support - Bump soname following upstream changes. - Use ldconfig_scriptlets macro for post(un) handling. - Add pkgconfig(harfbuzz) BuildRequires: New dependency. ==== poppler-qt6 ==== Version update (26.07.0 -> 26.09.0) - Update to version 26.09.0: + core: - Subset fonts when saving changes in Annotations and Forms when using fontconfig - NSS: Don't infinite loop on wrong password - Internal code improvements - Fix crashes in malformed documents + utils: - pdftotext: Add -urls option to print link URLs next to their text - pdftohtml: Improve speed by ignoring tiling patterns earlier - pdfimages: Fix typo in manpage + glib: Remove G_GNUC_CONST in enum _get_type funcs + build system: harfbuzz is now required for font subsetting - Changes from version 26.08.0: + core: - GPG based signature improvements - Internal code improvements + utils: - pdftohtml: Fix crash when using dataurls. - pdfimages: Add min-height and min-width options + glib: Stop using G_GNUC_CONST in _get_type funcs + build system: - Slight increase in compilation of utils folder - Fix -Wunused-command-line-argument when using clang - Use cmake modern way to check for linker support - Bump soname following upstream changes. - Use ldconfig_scriptlets macro for post(un) handling. - Add pkgconfig(harfbuzz) BuildRequires: New dependency. ==== pulseaudio-qt6 ==== Version update (1.8.1 -> 1.9.0) - Update to 1.9.0: * context: reset before reconnectDaemon * context: remove stray return in void function * server: do not return incorrect default devices * server: cleanup findByName a bit * Extract and install Qt metatypes ==== python-greenlet ==== Version update (3.5.5 -> 3.5.6) - Update to 3.5.6 * Correct a race condition that could lead to garbage collection unintentionally being disabled. See PR 529 by Yurii. ==== python313 ==== Version update (3.13.14 -> 3.13.15) - Restore back macros.python3, we need it. - CVE-2026-19672: in tarfile, handle a member that leaves the destination and comes back (bsc#1276227, gh#python/cpython#156000) CVE-2026-19672-tarfile-outside-dirs.patch CVE-2026-17084: Don't consider Unicode codepoint attributes outside RFC 3454 (bsc#1276226) CVE-2026-17084-unicode-rfc3454.patch - Add sphinx9-runtime-node.patch fixing documentation build with Sphinx 9 by importing the extension's Node type at runtime. - Restore the self-contained structure of the python313 package in openSUSE Factory: * the package has started to rely on the separate virtual `python3` package for the generic interpreter entry points and for the `python3*` Provides (bsc#1258364). That structure is meant for the SUSE Linux family of distros, it does not belong to Factory * python313 provides python3, python3-base and the other `python3*` virtual names again * python313 owns the python3 and pydoc3 binaries, the python3.1(1) man page, python3-config, libpython3.so and the unversioned pkg-config files again * python313 uses the rpm-build-python generated `python(abi)` Provides - Update to 3.13.15 - Tools/Demos - gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms. - gh-155207: Argument Clinic now supports the --dry-run and - -diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file. - gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code. - gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale. - Tests - gh-76595: Add C API tests for PyCapsule_Import(). - gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job. - gh-154144: Fix building the _testcapi module on NetBSD. - gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run. - gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout. - gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix). - Security - gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). - gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings (bsc#1273148, CVE-2026-6879). - gh-152216: Update bundled libexpat to version 2.8.2. - gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). - gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). - gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330 (bsc#1268977, CVE-2026-11940). - gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). - gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted (bsc#1257044, CVE-2025-15366). - Library ... changelog too long, skipping 525 lines ... - reproducible_stencils.patch ==== python313-core ==== Version update (3.13.14 -> 3.13.15) Subpackages: libpython3_13-1_0 python313-base - Restore back macros.python3, we need it. - CVE-2026-19672: in tarfile, handle a member that leaves the destination and comes back (bsc#1276227, gh#python/cpython#156000) CVE-2026-19672-tarfile-outside-dirs.patch CVE-2026-17084: Don't consider Unicode codepoint attributes outside RFC 3454 (bsc#1276226) CVE-2026-17084-unicode-rfc3454.patch - Add sphinx9-runtime-node.patch fixing documentation build with Sphinx 9 by importing the extension's Node type at runtime. - Restore the self-contained structure of the python313 package in openSUSE Factory: * the package has started to rely on the separate virtual `python3` package for the generic interpreter entry points and for the `python3*` Provides (bsc#1258364). That structure is meant for the SUSE Linux family of distros, it does not belong to Factory * python313 provides python3, python3-base and the other `python3*` virtual names again * python313 owns the python3 and pydoc3 binaries, the python3.1(1) man page, python3-config, libpython3.so and the unversioned pkg-config files again * python313 uses the rpm-build-python generated `python(abi)` Provides - Update to 3.13.15 - Tools/Demos - gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms. - gh-155207: Argument Clinic now supports the --dry-run and - -diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file. - gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code. - gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale. - Tests - gh-76595: Add C API tests for PyCapsule_Import(). - gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job. - gh-154144: Fix building the _testcapi module on NetBSD. - gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run. - gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout. - gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix). - Security - gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). - gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings (bsc#1273148, CVE-2026-6879). - gh-152216: Update bundled libexpat to version 2.8.2. - gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). - gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). - gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330 (bsc#1268977, CVE-2026-11940). - gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). - gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted (bsc#1257044, CVE-2025-15366). - Library ... changelog too long, skipping 525 lines ... - reproducible_stencils.patch ==== rpm ==== Subpackages: rpm-plugin-selinux - Don’t be dependent on python3-base, it is perfectly OK to use any Python interpreter for python-rpm-packaging. - Remove obsolete Python2-based removal of Python directories (why?) ==== selinux-policy ==== Version update (20260910 -> 20260914) Subpackages: selinux-policy-targeted - Update to version 20260914: * Label charon-nm as ipsec_exec_t (bsc#1278135) * Fix corrupted formatting in files.if * Allow nsswitch_domain connect to read xdm pid socket files * nsresourced fixes for mkosi (bsc#1279902) * Allow sshd-session connect to gnome remote desktop port * Allow sshd-session to connect to all generic ports * Allow sshd-session connect to port 443/tcp (http_port_t) * Allow sshd-session connect to tcp/22 (ssh_port_t) * Allow rsync to getattr pipes and sockes if rsync_export_all_ro is set (bsc#1279051) * Introduce files_getattr_non_auth_sockets * Introduce files_getattr_non_auth_pipes interface * Allow rsync to read var_t (bsc#1279565) * Update udev_manage_pid_files() to include symlinks read * Support vfs_snapper to work with samba_share_t (bsc#1265400) * vfs_samba uses dbus to communicate with snapper (bsc#1265400) * fix NetworkManager dnsmasq-forwarders.conf labeling (bsc#1260038) * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366) * Allow kmscon read cocpit's pid files * fix vpnc_t setpgid permission for openconnect (bsc#1272934) * Allow systemd-sysctl to create /run/sysctl.d * Allow systemd to create /run/udev/control * Allow systemd-coredumpd to create /run/systemd/coredumpd/kernel * Allow bootupcl nnp transition to mount_t * Networkmanager: Remove files_manage_etc_files for console_t * Networkmanager: Allow NM to manage files under /run * Allow login_userdomain read/write kmscon devpts chr_files * Support console version of initial-setup * ssh-session accesses gitolite ssh config files (bsc#1277259) * Allow kmscon use netlink permissions (#3368) * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783) * Allow ssh_agent_type manage ssh_home_t files and sock_files * Allow sshd-session manage ssh_home_t socke files * Allow sshd-session X11 forwarding * Allow lsmd-plugin read udev pid files * Allow virtstoraged domain transition on iscsiadm execution * Revert "Allow virtqemud domain transition on iscsiadm execution" * Allow rhsmcertd search gconf home data dirs * Allow rhsmcertd read gconf home files * Revert "Allow rhsmcertd read gconf home files" * Allow postmap read aliases * Allow lsmd-plugin use libStorageMgmt to provision storage * Update dhcpc-hook policy * Allow virtqemud domain transition on iscsiadm execution * Allow virtqemud domain transition on udev execution * Allow virtqemud relabelfrom its private fifo files * Support gnome-remote-desktop's smartcard redirection support * Allow qatlib manage hugetlbfs directories * Allow sanlock the sys_admin capability * Allow rhsmcertd read gconf home files * Allow rhsmcertd read insights-client config files * Allow insights-client read install_t process state * Allow insights-client read the process state of the init scripts * Allow namespace_init_t execute generic programs in bin directories * Update the ssh_server_template() template * Add rules for sshd vsock socket read/write * Allow dhcpc hook query the chronyd service * Allow insights-client read gconf home files * Allow login_userdomain mount, remount, unmount all mount points * Allow login_userdomain mount on all mount points * Revert "Allow userdomain get attributes of files on an nsfs filesystem" * Allow accountsd create and use its private tmpfs files * Add the anaconda_read_state_install() interface * Update qatlib policy * Allow rhsmcertd read the file_contexts files * rhsmcertd: allow bootc/ostree transient package persistence detection * Allow virtproxyd connect to systemd-homed over a unix stream socket * Allow system_mail_t read procmail home content * Label malware-detection-config.yml with insights_client_etc_rw_t * Add bcachefs as a SELinux capable filesystem * Allow unconfined_service_t nnp_transition to container_runtime_t * Add the files_write_system_conf_files() interface * Allow haveged (entropyd_t) create and use its private tmpfs files * Allow ctdbd manage access to Samba PID directories * Allow rhsmcertd read selinux config and default file contexts * Allow staff_t and user_t execute udev without a domain transition * Allow mpd dbus chat with avahi * Allow init_t nnp domain transition to mpd_t * Update tuned-ppd policy * Update policy for virsh_ssh_t to help with live migration * Update sysadm policy for encrypted volumes usage * Allow bootupd read all passwd sources * Allow local login and sshd-session signull cockpit-session * Allow sysadm_t read/write kvm devices * Allow sysadm user run fail2ban-client * Add 2 interfaces helping to handle cloud-what cache files * Allow all domains to use inherited sshd-session pipes * Dontaudit tlp_t dac_override (bsc#1272935) - Syncing with upstream rawhide selinux-policy up to: * dc63e37474fac5e8f74560acfc1bfdb0f785ec24 - Update embedded container-selinux version to commit: * 4ac019955c8885496ffbd978520c905434d4273e (v2.251.0) ==== shaderc ==== Version update (2026.3 -> 2026.4) - Update to release 2026.4 * Incorporate fixes for SPV_KHR_abort abortEXT(...) * glslc: option -fshader-stage now accepts all shader stage names as allowed in #pragma shader_stage()> This includes ray tracing, task, and mesh shader stages. ==== snappy ==== Version update (1.2.2 -> 1.3.0) - Update to 1.3.0: * Fixed a uint32_t overflow when decompressor accepted an input with incorrect format * Significant RISC-V efficiency improvements * New API on providing your own memory context * Supporting compression levels (1-2) in C API * Various other small fixes - Refresh reenable-rtti.patch - Disable LiteralLengthU32Overflow test in 32 bit architectures ==== sssd ==== Subpackages: libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap - Fix IDP provider cross-user impersonation; (bsc#1279915); (CVE-2026-87853); Add patch 0018-IDP-fix-user-matching-in-eval_access_token_buf.patch ==== timezone ==== Version update (2026c -> 2026d) - Updat to 2026d: * Canada’s Northwest Territories moved to permanent -06 on 2026-08-21 * Obsolescent settings like TZ="EST5EDT" now conform better to POSIX * Fix security, performance and porting bugs in zic and localtime ==== vmaf ==== Version update (3.2.0 -> 3.2.1) - Update to release 3.2.1 * libvmaf/speed_chroma: remove bilinear prescale index/weight computation from per-pixel loop. * Add ARM NEON implementation for 8-bit integer motion feature. ==== xz ==== Version update (5.8.3 -> 5.8.4) Subpackages: liblzma5 - Update to version 5.8.4: * Fix an invalid memory access in lzma_alone_decoder(), lzma_lzip_decoder(), lzma_auto_decoder(), and lzma_microlzma_decoder() after a failed allocation is followed by decoder reinitialization; could crash (GHSA-5qpq-xqfv-j9pg, CVE pending, affects all versions since 5.0.0) * Fix wrong error code/assertion failure in lzma_stream_buffer_decode() on truncated input * Fix a performance issue and a theoretical integer overflow in lzma_index_cat(), used by "xz --list" * Fix bogus/too-low memory usage reporting in lzma_index_decoder() * Fix lzma_index_dup() copying the wrong check type * Fix a missing synchronization in the threaded .xz decoder affecting lzma_get_progress() * xz: fix two use-after-free bugs (--files/--files0 via XZ_OPT/XZ_DEFAULTS, and --verbose with redirected stderr) * Add Landlock ABI 9 support on Linux * Fix "xz --list" totals overflow check, an xzgrep option- injection quoting bug, and an ARM64/LoongArch unaligned- read issue; see upstream's release notes for the full list - spec-cleaner cleanup: drop Group: tags, convert static-devel's Requires to pkgconfig(liblzma)