Packages changed:
AppStream (1.1.5 -> 1.2.0)
MicroOS-release (20260915 -> 20260919)
aaa_base (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202)
apparmor
at-spi2-core (2.60.6 -> 2.60.7)
bluez (5.82 -> 5.87)
ca-certificates-mozilla (2.84 -> 2.90)
crypto-policies
cryptsetup (2.8.7 -> 2.8.8)
gettext-runtime
glslang (16.5.0 -> 16.6.0)
grub2
kdump (2.1.9 -> 2.1.10)
kernel-source (7.2.5 -> 7.2.6)
libapparmor
libcanberra
libsoup
mozilla-nspr
ncurses (6.6.20260815 -> 6.6.20260912)
newt
nvme-cli (3.0+6.g1ac60ca4b -> 3.1)
pam
pam-full-src
permissions (1699_20260806 -> 1699_20260917)
pipewire (1.6.8 -> 1.6.9)
poppler (26.07.0 -> 26.09.0)
poppler-qt6 (26.07.0 -> 26.09.0)
pulseaudio-qt6 (1.8.1 -> 1.9.0)
python-greenlet (3.5.5 -> 3.5.6)
python313 (3.13.14 -> 3.13.15)
python313-core (3.13.14 -> 3.13.15)
rpm
selinux-policy (20260910 -> 20260914)
shaderc (2026.3 -> 2026.4)
snappy (1.2.2 -> 1.3.0)
sssd
timezone (2026c -> 2026d)
vmaf (3.2.0 -> 3.2.1)
xz (5.8.3 -> 5.8.4)
=== Details ===
==== AppStream ====
Version update (1.1.5 -> 1.2.0)
Subpackages: libAppStreamQt3 libappstream5
- Update to 1.2.0
* This release marks the libappstream-compose API as stable.
* This release introduces a new, lightly sandboxed (on Linux)
media worker for appstream-compose and switches to VIPS for
image processing.
* This release introduces My headline! markup
for AppStream descriptions. Older versions will remove this
markup, so only use it if your target clients have a recent
version of AppStream.
Features:
* compose: Create AscMedia for isolated out-of-process media
handling using asc-mediaworker
* compose: Process images, fonts & videos via the media worker
* Generalize path segment validation, use it in the compose
media worker
* compose: Switch from using GdkPixbuf to VIPS for image
processing
* compose: Harmonize supported formats, don't read XPM/TIFF/BMP
* compose: Make JPEG-XL the default image output format
* compose: Implement basic support for FreeBSD
* compose: Rely on VIPS for SVG support, drop our dedicated
librsvg path
* compose: Make image-targets and image batch-processing
public API
* compose: Expose the source-icon convention and a hint-tag
lookup as public API
* compose: Drop unstable-API marker
* compose: Don't create image thumbnails that aren't
substantially smaller
* compose: Only transfer pre-opened fds and no more directory
fd to the worker
* compose: Implement a basic sandbox for the mediaworker
using Landlock
* compose: Use RESTRICT_SELF_TSYNC and block UDP access on
newer Landlock
* compose: Mix the output image format type into the GCID
* compose: Make AscUnit a proper abstract class
* compose: Improve API documentation
* Always sanitize whitespaces in keywords and drop empty ones
* Assume a language element without percentage means full
translation
* news-to-metainfo: Support a details URL in the YAML variant
* news-convert: Support inline Markdown in news text
* news-convert: Support headers in XML<->YAML/NEWS/Markdown
conversions
* ascli: news-convert: Support standalone release XML as
source/target
* Whitespace-sanitize all description markup we read
* Output descriptions as literals in YAML and wrap markup
ourselves
Specification:
* docs: Document the appstreamcli news file conversion helper
* Implement support for headings in description markup
Bugfixes:
* meson: Set _POSIX_C_SOURCE on Linux only
* compose: Fix a race where units were deleting each other's
icon directories
* compose: Fix documentation and introspection annotation
issues
* compose: Drop dead public API, make some API private
* compose: Sharpen with libvips instead of a hand-rolled
unsharp mask
* compose: Only read AVIF from HEIF containers, never HEIC
* compose: Fix double-free crash when processing fonts
* compose: Guard against bad locale in path names
* compose: Ensure component-IDs are safe to use in filesystem
paths
* compose: Escape values for HTML reports, and create proper
plain-text if needed
* compose: Make missing-launchable-desktop-file an error
* Fix a few translator hints that weren't picked up properly
* Don't accept empty strings as URLs
* its: Fix description inline markup translation for release
data
* validator: Fix improper use of variadic arguments
* validator: Properly validate component-IDs with random
UTF-8 characters
* validator: Abort ID validation after the first invalid
character
* pool: Resolve crash if data locations are changed on a
loaded pool
* Fix wrong string comparison when detecting arm64 machines
* ascli: Resolve crash when selection is cancelled in
install/remove
* Fix another crash when converting invalid description markup
to Markdown
* apt: Treat icon tarballs as hostile, instead of trusted
* apt: Fix empty-directory check nuking the icon cache on
every refresh
* utils: Ensure we never ever follow symlinks when recursively
deleting caches
* xml: Only emit description enumerations for locales that are
in them
* cache: Never infinite-recurse when resolving addons for
a component
* yaml: Don't leave old header data around when parsing
multiple YAML catalogs
Miscellaneous:
* compose: Stop leaking private symbols out of the shared library
... changelog too long, skipping 22 lines ...
* ascli: Guard against bad bundle values when calling "install"
==== MicroOS-release ====
Version update (20260915 -> 20260919)
Subpackages: MicroOS-release-appliance MicroOS-release-dvd
- automatically generated by openSUSE-release-tools/pkglistgen
==== aaa_base ====
Version update (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202)
- Update to version 84.87+git20260916.e122202:
* For new GNU Emacs 31.1: use lexical-binding
* Let us now fix this syntax error in ls.bash
- Update to version 84.87+git20260812.c6d42af:
* added requires for gzip and tar to aaa_base-extras (boo#1274604)
* fix(ls): deprecate ls.zsh
* fix(ls.bash): use alias, func breaks sudo alias
* fix(ls.bash): avoid breaking sudo alias expansion
* drop dirs from the specfile, they live in the filesystem package
==== apparmor ====
- update wg-quick.diff to fix setting DNS (boo#1265394)
==== at-spi2-core ====
Version update (2.60.6 -> 2.60.7)
Subpackages: libatk-1_0-0 libatk-bridge-2_0-0 libatspi0 typelib-1_0-Atk-1_0 typelib-1_0-Atspi-2_0
- Update to version 2.60.7:
+ libatspi: Fix transfer annotation on
atspi_document_get_text_selections.
+ atk-bridge: Release disconnected direct connections.
==== bluez ====
Version update (5.82 -> 5.87)
Subpackages: bluez-cups libbluetooth3
- ver 5.87:
* Patches removed:
hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore)
hcidump-Fixed-malformed-segment-frame-length.patch (Source file does not exist anymore)
bluez-mainloop-Only-connect-to-NOTIFY_SOCKET-if-STATUS-Sta.patch (included in upstream)
CVE-2016-9800-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore)
CVE-2016-9804-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore)
upstream changes:
Fix issue with GATT database and out of sync errors.
Fix issue with BASS and setting a stream to idle.
Fix issue with BASS and rescanning broadcast sources.
Fix issue with BAP and broadcast sink cleanup.
Fix issue with BAP and endpoint configuration.
Fix issue with BAP and ASE control point properties.
Fix issue with BAP and BIG/BIS receiver QoS structures.
Fix issue with AVRCP and tracking of TG and CT events.
Fix issue with PBAP and Database Identifier length.
Fix issue with MCP and ATT disconnect events.
ver 5.86:
Fix issue with number of retries on authentication failures.
Fix issue with G.722 @ 16 kHz codec ID value reported by transport.
Add support for Telephony interface.
Add support for Ranging profile.
Add support for GMAP service.
Add support for TMAP service.
ver 5.85:
Fix issue with handling display of battery charge level.
Fix issue with BASS permissions not requiring encryption.
Fix issue with handling abort for OBEX SRM operation.
Fix issue with handling device privacy.
Add support for HFP call answer support.
Add support for HFP simple 3-way call support.
ver 5.84:
Fix issue with AVRCP and handling invalid UTF-8 item name.
Fix issue with exposing coordinate sets if LE Audio is disabled.
Fix issue with BAP and not responding to SetConfiguration.
Add support for BAP unicast endpoint reconfiguration.
Add support for BASS and encrypted broadcast source.
Add support for HFP and Call Line Identification.
ver 5.83:
Fix issue with handling BAP and removal of PAC.
Fix issue with handling SID for broadcast receiver.
Fix issue with handling HSP/HFP reconnection policy.
Fix issue with handling cable pairing and Sixaxis controllers.
Fix issue with handling virtual cable unplug for HID devices.
Fix issue with handling service records for HID devices.
Add support for AVDTP and TX timestamps.
==== ca-certificates-mozilla ====
Version update (2.84 -> 2.90)
- Updated to 2.90 state (bsc#1279961)
- Removed:
- AffirmTrust Commercial
- AffirmTrust Networking
- AffirmTrust Premium
- AffirmTrust Premium ECC
- certSIGN ROOT CA
- Entrust Root Certification Authority
- PKI Root Certification Authority
- FIRMAPROFESIONAL CA ROOT-A WEB
- GLOBALTRUST 2020
- Secure Global CA
- SecureSign Root CA12
- SecureTrust CA
- TeliaSonera Root CA v1
- Trustwave Global Certification Authority
- Trustwave Global ECC P256 Certification Authority
- Trustwave Global ECC P384 Certification Authority
- XRamp Global Certification Authority
- Added:
- SECOM SMIME RSA Root CA 2024
- SECOM TLS ECC Root CA 2024
- SECOM TLS RSA Root CA 2024
- SecureSign Root CA16
- Telia EC Email Root CA v3
- Telia EC TLS Root CA v3
- Telia RSA Email Root CA v3
- Telia RSA TLS Root CA v3
==== crypto-policies ====
- Add configure-python-interpreter.patch removing dependency on
`python3-base`, all Python scripts are now dependent on the
primary Python interpreter directly without `/usr/bin/python3`
mediation.
==== cryptsetup ====
Version update (2.8.7 -> 2.8.8)
Subpackages: libcryptsetup12
- Update to 2.8.8:
* integritysetup: add support for keyed discards.
An integrity device in standalone mode, with a keyed integrity
algorithm like HMAC and enabled discards (TRIM), could be
vulnerable to wiping part of the device using a discard pattern.
This issue can be worked around by using a keyed discards filler.
Once set, it is set permanently for the integrity device and
cannot be reverted.
Integritysetup now supports a new --allow-discards-keyed option.
Once used, it will upgrade the superblock and activate keyed
discards.
After the upgrade, keyed discards are always used, even with the
old --allow-discards option.
Keyed discard is available since Linux kernel 7.3.
Note: Integritysetup was intended to be used with non-cryptographic
integrity protection only. If you need cryptographic protection,
use LUKS2 and AEAD (discards are not supported).
* Avoid time-of-check/time-of-use (TOCTOU) issue in LUKS header
restore. The LUKS header restore function validates the provided
header file and then reopens the same file path to restore the
LUKS header. In a specifically crafted environment, a symlink
flip could occur between validating and restoring the header,
resulting in a different file being used for the LUKS header
restore (potentially leaking the file content).
The libcryptsetup now opens the device only once. The issue
affects both LUKS1 and LUKS2.
Note: LUKS header backup/restore is a system administrative task
(similar to filesystem backup/restore) that must run in a secure
environment. Such a backup is usually a multi-step process, and
it is up to the caller to ensure security of that environment.
* BITLK: harden metadata validation.
If a crafted BITLK (BitLocker-compatible) image is opened, the
allocated buffer size for the key can be incorrect. This can
happen if the encryption is changed from AES-CBC-128 to a mode with
an Elephant diffuser, without recalculating the stored key. Also,
the data offset can be intentionally wrong, which could lead to an
infinite loop when parsing metadata.
Note that creating such an incorrect image requires knowledge of
the disk password, as MAC protects the metadata, and this MAC is
checked by cryptsetup.
* Fix possible integer overflow in LUKS metadata parsing.
On systems with a 32-bit integer size, the anti-forensic (AF)
data size calculation could overflow, causing an application crash.
* cryptsetup: fix local memory corruption bug in reencrypt init.
If a device intended for reencryption contains more than 16 active
LUKS2 keyslots or tokens, the reencryption initialization could
corrupt internal memory, leading to an application crash.
==== gettext-runtime ====
Subpackages: envsubst libtextstyle0
- Fix for automake1.19: Update patch
0001-msgcat-Add-feature-to-use-the-newest-po-file.patch
with Makefile.in so the build doesn't try to regenerate this file
with automake-1.18
==== glslang ====
Version update (16.5.0 -> 16.6.0)
- Update to release 16.6.0
* Implemented `GL_EXT_cooperative_matrix_maintenance1`,
`GL_EXT_optional_input_attachment_index`,
and `DebugEntryPoint` for `NonSemantic.Shader.DebugInfo` 102.
==== grub2 ====
Subpackages: grub2-arm64-efi grub2-common grub2-snapper-plugin
- Add SBAT Provides to support shim SBAT dependency checks (bsc#1278729)
==== kdump ====
Version update (2.1.9 -> 2.1.10)
- upgrade to version 2.1.10
* calibrate: measure per-cpu requirements
* kdumptool calibrate: take KDUMP_CPUS into account for PPC
* PPC: round up KDUMP_CPUS on SMT systems to nearest threads-per-cpu
* Set default KDUMP_CPUs to 4 (jsc#PED-16732, bsc#1239999)
* add KDUMP_USE_CMA: experimental support for CMA reservation (jsc#PED-14553)
- update calibrate values
==== kernel-source ====
Version update (7.2.5 -> 7.2.6)
Subpackages: kernel-64kb kernel-default
- RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables
(git-fixes).
- commit 3d19f11
- Update
patches.kernel.org/7.2.4-160-nfsd-add-fh_want_write-for-early-verified-SETAT.patch
(bsc#1012628 CVE-2026-89697 bsc#1280148).
- Update
patches.kernel.org/7.2.4-163-nfsd-block-non-SAVEFH-ops-after-FOREIGN-PUTFH-t.patch
(bsc#1012628 CVE-2026-89696 bsc#1280146).
- Update
patches.kernel.org/7.2.4-164-nfsd-cap-decoded-POSIX-ACL-count-to-bound-sort-.patch
(bsc#1012628 CVE-2026-89695 bsc#1280155).
- Update
patches.kernel.org/7.2.4-165-nfsd-check-client-ownership-when-cancelling-a-c.patch
(bsc#1012628 CVE-2026-89694 bsc#1280151).
- Update
patches.kernel.org/7.2.4-166-nfsd-check-nfsd4_acl_to_attr-return-value-in-nf.patch
(bsc#1012628 CVE-2026-89693 bsc#1280153).
- Update
patches.kernel.org/7.2.4-167-nfsd-clear-CALLBACK_RUNNING-on-failed-delegatio.patch
(bsc#1012628 CVE-2026-89692 bsc#1280167).
- Update
patches.kernel.org/7.2.4-168-nfsd-clear-opcnt-on-compound-arg-release-to-pre.patch
(bsc#1012628 CVE-2026-89691 bsc#1280163).
- Update
patches.kernel.org/7.2.4-172-nfsd-defer-vfree-of-compound-ops-to-fix-rpc_sta.patch
(bsc#1012628 CVE-2026-89690 bsc#1280166).
- Update
patches.kernel.org/7.2.4-173-nfsd-don-t-free-session-slots-that-are-still-in.patch
(bsc#1012628 CVE-2026-89689 bsc#1280174).
- Update
patches.kernel.org/7.2.4-174-nfsd-drop-the-stateid-not-the-stateowner-on-seq.patch
(bsc#1012628 CVE-2026-89688 bsc#1280171).
- Update
patches.kernel.org/7.2.4-175-nfsd-ensure-nfsd_file_do_acquire-does-not-use-a.patch
(bsc#1012628 CVE-2026-89687 bsc#1280173).
- Update
patches.kernel.org/7.2.4-176-nfsd-fix-BUG_ON-in-nfsd4_alloc_layout_stateid-o.patch
(bsc#1012628 CVE-2026-89686 bsc#1280184).
- Update
patches.kernel.org/7.2.4-177-nfsd-fix-clock-domain-mismatch-in-clients_still.patch
(bsc#1012628 CVE-2026-89685 bsc#1280179).
- Update
patches.kernel.org/7.2.4-178-nfsd-fix-cpntf-publish-race-in-nfs4_init_cp_sta.patch
(bsc#1012628 CVE-2026-89684 bsc#1280178).
- Update
patches.kernel.org/7.2.4-179-nfsd-fix-dentry-ref-leak-on-V4ROOT-export-fileh.patch
(bsc#1012628 CVE-2026-89683 bsc#1280193).
- Update
patches.kernel.org/7.2.4-180-nfsd-fix-fcache_disposal-UAF-by-inlining-dispos.patch
(bsc#1012628 CVE-2026-89682 bsc#1280191).
- Update
patches.kernel.org/7.2.4-182-nfsd-fix-layout-fence-worker-double-reference-r.patch
(bsc#1012628 CVE-2026-89681 bsc#1280189).
- Update
patches.kernel.org/7.2.4-184-nfsd-fix-nfsd_file-leak-on-inter-server-COPY-se.patch
(bsc#1012628 CVE-2026-89680 bsc#1280206).
- Update
patches.kernel.org/7.2.4-185-nfsd-fix-null-dereference-in-nfsd4_setattr-for-.patch
(bsc#1012628 CVE-2026-89679 bsc#1280203).
- Update
patches.kernel.org/7.2.4-186-nfsd-fix-partial-write-detection-in-nfsd_direct.patch
(bsc#1012628 CVE-2026-89678 bsc#1280199).
- Update
patches.kernel.org/7.2.4-187-nfsd-fix-possible-fh_compose-of-wrong-dentry-in.patch
(bsc#1012628 CVE-2026-89677 bsc#1280224).
- Update
patches.kernel.org/7.2.4-190-nfsd-fix-stale-s2s_cp_stateids-IDR-entry-for-as.patch
(bsc#1012628 CVE-2026-89676 bsc#1280219).
- Update
patches.kernel.org/7.2.4-191-nfsd-fix-UAF-in-async-copy-cancel-and-shutdown.patch
(bsc#1012628 CVE-2026-89675 bsc#1280216).
- Update
patches.kernel.org/7.2.4-193-nfsd-fix-XDR-length-calculation-in-nfsd4_ff_enc.patch
(bsc#1012628 CVE-2026-89674 bsc#1280243).
- Update
patches.kernel.org/7.2.4-194-nfsd-fix-XDR-padding-calculation-in-ff_encode_g.patch
(bsc#1012628 CVE-2026-89673 bsc#1280237).
- Update
patches.kernel.org/7.2.4-195-nfsd-gate-nfs2-setacl-by-argp-mask.patch
(bsc#1012628 CVE-2026-89672 bsc#1280235).
- Update
patches.kernel.org/7.2.4-196-nfsd-gate-nfs3-setacl-by-argp-mask.patch
(bsc#1012628 CVE-2026-89671 bsc#1280252).
- Update
patches.kernel.org/7.2.4-197-nfsd-hold-rcu-across-localio-cmpxchg-retry.patch
(bsc#1012628 CVE-2026-89670 bsc#1280250).
- Update
patches.kernel.org/7.2.4-198-nfsd-initialize-copy-notify-stateid-before-publ.patch
(bsc#1012628 CVE-2026-89669 bsc#1280251).
- Update
patches.kernel.org/7.2.4-200-nfsd-move-nfsd_debugfs_init-after-nfsd4_init_sl.patch
(bsc#1012628 CVE-2026-89668 bsc#1280279).
- Update
patches.kernel.org/7.2.4-201-nfsd-close-shrinker-GC-fsnotify-vs-per-net-shut.patch
(bsc#1012628 CVE-2026-89667 bsc#1280261).
- Update
patches.kernel.org/7.2.4-205-nfsd-release-OPEN-decoded-posix-ACLs-via-op_rel.patch
(bsc#1012628 CVE-2026-89664 bsc#1280272).
... changelog too long, skipping 3681 lines ...
- commit 16c1085
==== libapparmor ====
- update wg-quick.diff to fix setting DNS (boo#1265394)
==== libcanberra ====
- Migrate to xz compression and manual service run
==== libsoup ====
- Add libsoup-CVE-2026-85534.patch: Never send more body bytes than
nghttp2 requested (bsc#1279239, CVE-2026-85534)
- Add libsoup-CVE-2026-85197.patch: fix crash in on_data_read after
connection has been destroyed (bsc#1279238, CVE-2026-85197)
==== mozilla-nspr ====
- Add Make-x86-assembly-files-compatible-with-SHSTK-IBT.patch to
support -fcf-protection in assembly sources.
==== ncurses ====
Version update (6.6.20260815 -> 6.6.20260912)
Subpackages: libncurses6 ncurses-utils terminfo-base
- Work around common name in certificate of www.invisible-island.net
- Add ncurses patch 20260912
+ build-fix for sizeof(mmask_t) configure check (cf:20260829).
+ review/fix teraterm* (report by Jakub Horky)
+ modify flash for vt525 to use DECRARA (patch by Branden Robinson)
+ update config.guess, config.sub
- Add ncurses patch 20260905
+ modify endwin() and doupdate() to save/restore keypad and meta modes
(report by Ferenc Wagner).
+ improve range-checks for xterm X10 and SGR mouse protocol.
+ correct modifier-masking for buttons 6-11 in mouse version 3
(report by Ravi Arnan Irianto).
+ build-fix for Ada95 with ABI 7 (report by Branden Robinson)
- Add ncurses patch 20260829
+ add configure check to ensure that mmask_t is large enough for the
configured mouse version (report by Ravi Arnan Irianto)
+ add mouse-parsing for extended buttons with mouse version 3 (report
by Ravi Arnan Irianto).
- Add ncurses patch 20260822
+ add a limit-check in wborder (patch by Bjoern Foersterling).
+ improve limit-checks for trace calls in read_entry.c (report by Yeo
JooHo).
+ improve tic warnings regarding the empty smir/rmir strings which
may be added in dump_entry.c for termcap if ich/ich1 are present but
smir/rmir are not.
+ add sun+fkeys -TD
+ add dtterm-sk, dtterm+sk -TD
+ add ich1 to several entries, providing for support of non-curses
applications via termcap only -TD
+ add dch/dch1 to rxvt-basic -TD
+ drop redundant xterm=setaf2 (patch by Branden Robinson)
+ documentation improvements (patches by Branden Robinson).
+ improve color discussion in man pages
+ improve formatting/style of man pages
> improve wide-character support with UCRT (patches by Liu Hao)
+ use UCRT's wcrtomb rather than _nc_wctomb
+ skip trailing cells of double-width characters
==== newt ====
- Use %python3_version instead of the obsolete %py3_ver.
==== nvme-cli ====
Version update (3.0+6.g1ac60ca4b -> 3.1)
Subpackages: libnvme3-1
- Update to version 3.1:
* Release v3.1
* doc: Regenerate all docs for v3.1
* tests: NUL-terminate literals copied into dc_entry_is_self() test data
* plugin: fix out-of-bounds read of argv[1] in help() with no sub-argument
* libnvme: fix NBFT entry list leak in libnvmf_discover_nbft()
* huawei: guard against a null list_items in huawei_json_print_list_items()
* solidigm: also guard against a null ilog in ilog_dump_identify_page()
* plugins/sandisk: fix uninitialized market_name_len in enc_drive_capabilities
* plugins/exclusion: fix errno reliance in read_file()
* plugins/sandisk: update version
* plugins/sandisk: use nvme_get_pci_ids
* plugins/sandisk: port vs-smart-add-log from wdc
* libnvme: reject a persona hostnqn with no hostid
* shared: drop the retry loop from shr_read_file()/shr_read_file_as_string()
* shared: return error codes from shr_read_file() and shr_read_file_as_string()
* tests: bound the interface name copy in mock-ifaddrs init_entry()
* wdc: use shr_getrandom() for the send/receive correlation handle
* rpmb: use shr_getrandom() for the authentication nonce
* keys: check chmod() return value in append_keyfile()
* shared: add shr_getrandom()
* solidigm: fix NULL DMA target in ilog_dump_pel()
* tests: fix unit mismatch in test_admin_fw_download_cb's data check
* innogrit: remove dead fclose() guards before the first fopen() in getcdump
* solidigm: fix unreachable error-recovery path in parse_tracker_chunk_json()
* nvme: fix nvme_decide_retry() always returning false
* nbft: fix truncated PCI segment number in pci_sbdf_to_string()
* ocp: check ocp_get_uuid_index() before issuing the get-log command
* tests,tree-fabrics: check and acknowledge return values
* mi-mctp: fix endian conversion direction for MPR retry time
* fs-util: restore path separator unconditionally in shr_mkdir_p()
* tests: check write() return value in test_read_all()
* wdc: bound the device-reported Capture Diagnostics log length
* solidigm: replace read_file2buffer() with shared file-reading helpers
* sandisk: fix 32-bit overflow and unchecked realloc in sndk_do_cap_udui
* mi-mctp-ae: bound the AE number before indexing the enabled-events map
* shared: use memmove() for the sha256 intra-buffer carry-over copy
* fabrics: fix NULL dereference in dc_log_decision()
* netapp: fix NULL format string in netapp_smdevices_print_regular()
* tests: fix NULL dereference in mi-mctp aem_handler()
* ocp: fix NULL dereference and zero-fill bug in parse_event_fifo()
* nvme-print: bound-check FDP config descriptor walk against log size
* nvme-print: fix endian bugs and bound the EOM descriptor walk
* nvme-print: fix integer overflow in EOM descriptor offset
* shared: add shr_buf_has_room()
* tests: fix dangling pointer in test_nvmf_sanitize_addrs()
* tests: use shr_read_file_as_string() in shr_table tests
* tests: fix uninitialized buffer and NULL %s in check_normalize()
* shared: add shr_read_file_as_string()
* scaleflux: fix scandir(3) result leak in nvme_expand_cap
* wdc: fix out-of-bounds read of pre-v4 cloud smart log hardware revision
* nvme-print,fabrics: fix uninitialized reads
* utils: fix allocation leak in copy_options()
* shannon: fix file descriptor leak in set_additional_feature()
* rpmb: validate config block size before write
* discoverd: honor persistent=force against EPCSD=0
* resv-plugin: size the resv report from the registrant count
* ccan: cast pointers to void * in fprintf for %p format specifier
* libnvme: pick the right self entry on a multi-homed DC
* discoverd: use __cleanup_tid in two loops
* sandisk: fix stack buffer overflow in C2 marketing-name parser
* discoverd: validate DLPE target before host-side inheritance
* nvme-models: fix pci.ids parser line loss
* tests: check errno after rewind in capture helpers
* huawei: null-check root/devices in huawei_json_print_list_items
* solidigm: guard ilog->cfg dereference in ilog_dump_identify_page
* libnvme: initialize TLS key IDs
* exclusion: preserve errno across free/fclose in read_file
* nvme-print-json: fix leaks in json_phy_rx_eom_descs
* wdc: close output file via __cleanup_file in wdc_enc_get_log
* lm: fix double fclose in lm_migration_send
* completions: document no-trailing-space insertion checks in TESTING.md
* completions: test the generator against a synthetic fixture
* nvme-print-json: use CAP property fields string table
* nvme-print: add CAP property fields string table
* nvme-print-json: combine obj_add_str and obj_add_string duplicated
* nvme-print: change string variables as constant
* nvme-print-json: fix to output alloc_error
* nvme-print-stdout: use libnvme API to print CAP property
* nvme-types-base: fix CAP property NSSRS bit name
* nvme-types-base: add CAP property NSSES bit
* nvme-types-base: change file header description NVMe revision to 2.4
* micron: clamp num_entries in vs-fw-activate-history to the table size
* seagate: clamp supported-log-pages count and keep JSON clean
* libnvme: add test for var_size_tags 32B guard sts range
* tests: cover invalid_tags() STS-too-wide rejection
* libnvme: fix undefined shifts in nvme_init_var_size_tags() 32B guard case
* nvme: reject out-of-range storage tag size in invalid_tags()
* shared: drop dead `at_line_start = true` in shr_print_word_wrapped()
* solidigm: drop dead initializer in telemetry_log_data_area_get_offset()
* solidigm: report failure restoring workload-tracker config
* huawei: check libnvme_get_nsid() failure in huawei_get_nvme_info()
* micron: drop dead `err = 0` in micron_telemetry_log()
* ocp: fix empty-description case in parse_ocp_telemetry_string_log()
* ocp: drop dead m_512_sz/m_512_off initial stores in get_telemetry_dump()
* sandisk: drop dead stores flagged by clang-analyze
* sandisk: fix telemetry write error handling, drop a dead store
* wdc: fix telemetry write error handling, drop dead stores
* huawei: skip a list entry if its JSON object fails to allocate
... changelog too long, skipping 47 lines ...
* feat: add remaining feature commands
==== pam ====
- Apply livepatching only for SLES, not for Factory. Keeping lto
optimisation for openSUSE.
* On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS.
- Make sure we don't lose distribution compiler flags.
==== pam-full-src ====
- Apply livepatching only for SLES, not for Factory. Keeping lto
optimisation for openSUSE.
* On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS.
- Make sure we don't lose distribution compiler flags.
==== permissions ====
Version update (1699_20260806 -> 1699_20260917)
Subpackages: permctl permissions-config
- Update to version 1699_20260917:
* profiles: added CAP_PERFMON for ksystemstats_xe_helper (bsc#1280113)
* profiles: document nvidia-modprobe's special case
==== pipewire ====
Version update (1.6.8 -> 1.6.9)
Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools
- Update to version 1.6.9:
* This is a bugfix release that is API and ABI compatible with
the previous 1.6.x releases.
* Highlights
- Improve JACK object callbacks, avoid reporting old removed
objects.
- Tweak the resampler cutoff frequencies to preserve more high
frequencies when upsampling.
- More small fixes and improvements.
* Modules
- Fix RAOP encryption for OpenSSL >= 3. (#5370 (closed))
- Fix netjack2 discovery timeout.
- Fix potential truncated audio in RAOP.
- Fix potential metadata update problems. (#5445 (closed))
- Fix RAOP over TCP.
- Fix potential overflows in client node buffer checks. (#5462)
- Add node.network=true to network sinks and sources so that
pavucontrol and others don't wake them up. (#3268 (closed))
* SPA
- Fix opus audio info type.
- Tweak the upsample cutoff frequencies to preserve more high
frequencies when upsampling. (#5390 (closed))
- Fix filter-graph property notification in some cases.
- Remove limits on filter-graph descriptions in audioconvert.
- Improve dynamic reconfiguration of filter-graphs in
audioconvert.
- Improve passthrough format handling in audioconvert.
- Improve the FC and LFE volumes when upmixing is enabled.
- Fix v4l2 controls when one can not be read.
- Require 0.6.0 libcamera now.
- Improve format filtering in v4l2.
* Pulse-server
- Don't let a pending sibling message starve capture.
- Fix name of ALSA source.
- Fix potential crash with the active_port_name.
(#5435 (closed))
* Bluetooth
- Fix a potential leak when transport fails to start.
- Fix potential crash when cleaning up iso-io transport.
* JACK
- Rework the object lookups to avoid removed objects from
leaking. (#5356 (closed))
* GStreamer
- Add fixes for state changes and other lockups.
* ALSA Plugin
- Generate poll errors when stopping. (#5444 (closed))
* Tools
- Handle EOF correctly for encoded files in pw-cat.
- Fix loopback channel and position handling.
- Fix mp3 encoding in pw-record.
- Support A-law in pw-record.
- Disable libcamera support when building in Leap 16.1 or older
since pipewire now needs at least libcamera 0.6.0 .
==== poppler ====
Version update (26.07.0 -> 26.09.0)
- Update to version 26.09.0:
+ core:
- Subset fonts when saving changes in Annotations and Forms
when using fontconfig
- NSS: Don't infinite loop on wrong password
- Internal code improvements
- Fix crashes in malformed documents
+ utils:
- pdftotext: Add -urls option to print link URLs next to their
text
- pdftohtml: Improve speed by ignoring tiling patterns earlier
- pdfimages: Fix typo in manpage
+ glib: Remove G_GNUC_CONST in enum _get_type funcs
+ build system: harfbuzz is now required for font subsetting
- Changes from version 26.08.0:
+ core:
- GPG based signature improvements
- Internal code improvements
+ utils:
- pdftohtml: Fix crash when using dataurls.
- pdfimages: Add min-height and min-width options
+ glib: Stop using G_GNUC_CONST in _get_type funcs
+ build system:
- Slight increase in compilation of utils folder
- Fix -Wunused-command-line-argument when using clang
- Use cmake modern way to check for linker support
- Bump soname following upstream changes.
- Use ldconfig_scriptlets macro for post(un) handling.
- Add pkgconfig(harfbuzz) BuildRequires: New dependency.
==== poppler-qt6 ====
Version update (26.07.0 -> 26.09.0)
- Update to version 26.09.0:
+ core:
- Subset fonts when saving changes in Annotations and Forms
when using fontconfig
- NSS: Don't infinite loop on wrong password
- Internal code improvements
- Fix crashes in malformed documents
+ utils:
- pdftotext: Add -urls option to print link URLs next to their
text
- pdftohtml: Improve speed by ignoring tiling patterns earlier
- pdfimages: Fix typo in manpage
+ glib: Remove G_GNUC_CONST in enum _get_type funcs
+ build system: harfbuzz is now required for font subsetting
- Changes from version 26.08.0:
+ core:
- GPG based signature improvements
- Internal code improvements
+ utils:
- pdftohtml: Fix crash when using dataurls.
- pdfimages: Add min-height and min-width options
+ glib: Stop using G_GNUC_CONST in _get_type funcs
+ build system:
- Slight increase in compilation of utils folder
- Fix -Wunused-command-line-argument when using clang
- Use cmake modern way to check for linker support
- Bump soname following upstream changes.
- Use ldconfig_scriptlets macro for post(un) handling.
- Add pkgconfig(harfbuzz) BuildRequires: New dependency.
==== pulseaudio-qt6 ====
Version update (1.8.1 -> 1.9.0)
- Update to 1.9.0:
* context: reset before reconnectDaemon
* context: remove stray return in void function
* server: do not return incorrect default devices
* server: cleanup findByName a bit
* Extract and install Qt metatypes
==== python-greenlet ====
Version update (3.5.5 -> 3.5.6)
- Update to 3.5.6
* Correct a race condition that could lead to garbage collection
unintentionally being disabled. See PR 529 by Yurii.
==== python313 ====
Version update (3.13.14 -> 3.13.15)
- Restore back macros.python3, we need it.
- CVE-2026-19672: in tarfile, handle a member that leaves the
destination and comes back (bsc#1276227, gh#python/cpython#156000)
CVE-2026-19672-tarfile-outside-dirs.patch
CVE-2026-17084: Don't consider Unicode codepoint attributes
outside RFC 3454 (bsc#1276226)
CVE-2026-17084-unicode-rfc3454.patch
- Add sphinx9-runtime-node.patch fixing documentation build with
Sphinx 9 by importing the extension's Node type at runtime.
- Restore the self-contained structure of the python313 package in
openSUSE Factory:
* the package has started to rely on the separate virtual `python3`
package for the generic interpreter entry points and for the
`python3*` Provides (bsc#1258364). That structure is meant for the
SUSE Linux family of distros, it does not belong to Factory
* python313 provides python3, python3-base and the other `python3*`
virtual names again
* python313 owns the python3 and pydoc3 binaries, the python3.1(1)
man page, python3-config, libpython3.so and the unversioned
pkg-config files again
* python313 uses the rpm-build-python generated `python(abi)` Provides
- Update to 3.13.15
- Tools/Demos
- gh-155218: Fix Argument Clinic generating the flags of the
optional groups in different order on 32-bit and 64-bit
platforms.
- gh-155207: Argument Clinic now supports the --dry-run and
- -diff options. They list the files which would be changed,
or write a unified diff of the changes to the standard
output, without modifying any file.
- gh-64502: Fix Argument Clinic support of parameters with
a default value used together with optional groups. Such
parameters were always required in the generated parsing
code.
- gh-154580: Fix python-gdb.py raising UnicodeEncodeError
when pretty-printing a non-ASCII str in a locale whose host
charset cannot encode it, such as any non-ASCII string in
the C locale.
- Tests
- gh-76595: Add C API tests for PyCapsule_Import().
- gh-154167: The test runner (regrtest) now restores the
default SIGINT handler if it was inherited as ignored, so
the test suite no longer hangs when run as a shell
background job.
- gh-154144: Fix building the _testcapi module on NetBSD.
- gh-152548: Add the test.support.isolation.runInSubprocess()
decorator to run a test method or TestCase subclass in
a fresh interpreter subprocess, isolated from the rest of
the test run.
- gh-151626: Fix several tests in test.test_inspect,
test.test_import, test.test_importlib, test.test_py_compile
and test.test_compileall that failed when the test suite
was run with PYTHONPYCACHEPREFIX set. These tests now
neutralize the pycache prefix where they assume the default
__pycache__ bytecode layout.
- gh-151096: Fix test_embed failing when CPython is
configured with a split exec prefix (--exec-prefix
differing from --prefix).
- Security
- gh-153030: Fixed quadratic complexity in incremental
parsing of long unterminated constructs (such as tags or
comments) in html.parser.HTMLParser, which could be
exploited for a denial of service (bsc#1271192,
CVE-2026-15308).
- gh-152674: The xml.etree.ElementTree.Element methods
findall(), iterfind() and find() avoid quadratic behavior
when using XPath index predicates ([1], [last()],
[last()-N]) on XML documents with many same-tag siblings
(bsc#1273148, CVE-2026-6879).
- gh-152216: Update bundled libexpat to version 2.8.2.
- gh-151987: The tarfile.TarFile.extract() method now applies
the given filter when it extracts a link target from the
archive as a fallback (bsc#1269959, CVE-2026-4360).
- gh-151981: In tarfile, seeking a stream now stops when end
of the stream is reached (bsc#1269788, CVE-2026-11972).
- gh-151544: Modules/Setup.local is no longer used as
a landmark to discover whether Python is running in
a source tree, as it could potentially affect actual
installs. The pybuilddir.txt file is now the sole indicator
of running in a source tree.
- gh-151558: Fixed an vulnerability in the tarfile data and
tar extraction filters where crafted archives could create
a symlink pointing outside the destination directory. This
was a bypass of CVE 2025-4330 (bsc#1268977,
CVE-2026-11940).
- gh-150743: http.client now limits the number of
chunked-response trailer lines it will read to 100, and the
number of interim (1xx) responses it will skip to 100.
A malicious or broken server could previously stream
trailer lines or 100 Continue responses forever, hanging
the client even when a socket timeout was in use. Reported
by @YLChen-007 via GHSA-w4q2-g22w-6fr4.
- gh-143927: Normalize all line endings (CR, CRLF, and LF) to
LF+TAB when writing multi-line configparser values
(bsc#1269066, CVE-2026-0864).
- gh-143921: Reject NUL, CR and LF characters in IMAP
commands. Other control characters are allowed and sent
quoted (bsc#1257044, CVE-2025-15366).
- Library
... changelog too long, skipping 525 lines ...
- reproducible_stencils.patch
==== python313-core ====
Version update (3.13.14 -> 3.13.15)
Subpackages: libpython3_13-1_0 python313-base
- Restore back macros.python3, we need it.
- CVE-2026-19672: in tarfile, handle a member that leaves the
destination and comes back (bsc#1276227, gh#python/cpython#156000)
CVE-2026-19672-tarfile-outside-dirs.patch
CVE-2026-17084: Don't consider Unicode codepoint attributes
outside RFC 3454 (bsc#1276226)
CVE-2026-17084-unicode-rfc3454.patch
- Add sphinx9-runtime-node.patch fixing documentation build with
Sphinx 9 by importing the extension's Node type at runtime.
- Restore the self-contained structure of the python313 package in
openSUSE Factory:
* the package has started to rely on the separate virtual `python3`
package for the generic interpreter entry points and for the
`python3*` Provides (bsc#1258364). That structure is meant for the
SUSE Linux family of distros, it does not belong to Factory
* python313 provides python3, python3-base and the other `python3*`
virtual names again
* python313 owns the python3 and pydoc3 binaries, the python3.1(1)
man page, python3-config, libpython3.so and the unversioned
pkg-config files again
* python313 uses the rpm-build-python generated `python(abi)` Provides
- Update to 3.13.15
- Tools/Demos
- gh-155218: Fix Argument Clinic generating the flags of the
optional groups in different order on 32-bit and 64-bit
platforms.
- gh-155207: Argument Clinic now supports the --dry-run and
- -diff options. They list the files which would be changed,
or write a unified diff of the changes to the standard
output, without modifying any file.
- gh-64502: Fix Argument Clinic support of parameters with
a default value used together with optional groups. Such
parameters were always required in the generated parsing
code.
- gh-154580: Fix python-gdb.py raising UnicodeEncodeError
when pretty-printing a non-ASCII str in a locale whose host
charset cannot encode it, such as any non-ASCII string in
the C locale.
- Tests
- gh-76595: Add C API tests for PyCapsule_Import().
- gh-154167: The test runner (regrtest) now restores the
default SIGINT handler if it was inherited as ignored, so
the test suite no longer hangs when run as a shell
background job.
- gh-154144: Fix building the _testcapi module on NetBSD.
- gh-152548: Add the test.support.isolation.runInSubprocess()
decorator to run a test method or TestCase subclass in
a fresh interpreter subprocess, isolated from the rest of
the test run.
- gh-151626: Fix several tests in test.test_inspect,
test.test_import, test.test_importlib, test.test_py_compile
and test.test_compileall that failed when the test suite
was run with PYTHONPYCACHEPREFIX set. These tests now
neutralize the pycache prefix where they assume the default
__pycache__ bytecode layout.
- gh-151096: Fix test_embed failing when CPython is
configured with a split exec prefix (--exec-prefix
differing from --prefix).
- Security
- gh-153030: Fixed quadratic complexity in incremental
parsing of long unterminated constructs (such as tags or
comments) in html.parser.HTMLParser, which could be
exploited for a denial of service (bsc#1271192,
CVE-2026-15308).
- gh-152674: The xml.etree.ElementTree.Element methods
findall(), iterfind() and find() avoid quadratic behavior
when using XPath index predicates ([1], [last()],
[last()-N]) on XML documents with many same-tag siblings
(bsc#1273148, CVE-2026-6879).
- gh-152216: Update bundled libexpat to version 2.8.2.
- gh-151987: The tarfile.TarFile.extract() method now applies
the given filter when it extracts a link target from the
archive as a fallback (bsc#1269959, CVE-2026-4360).
- gh-151981: In tarfile, seeking a stream now stops when end
of the stream is reached (bsc#1269788, CVE-2026-11972).
- gh-151544: Modules/Setup.local is no longer used as
a landmark to discover whether Python is running in
a source tree, as it could potentially affect actual
installs. The pybuilddir.txt file is now the sole indicator
of running in a source tree.
- gh-151558: Fixed an vulnerability in the tarfile data and
tar extraction filters where crafted archives could create
a symlink pointing outside the destination directory. This
was a bypass of CVE 2025-4330 (bsc#1268977,
CVE-2026-11940).
- gh-150743: http.client now limits the number of
chunked-response trailer lines it will read to 100, and the
number of interim (1xx) responses it will skip to 100.
A malicious or broken server could previously stream
trailer lines or 100 Continue responses forever, hanging
the client even when a socket timeout was in use. Reported
by @YLChen-007 via GHSA-w4q2-g22w-6fr4.
- gh-143927: Normalize all line endings (CR, CRLF, and LF) to
LF+TAB when writing multi-line configparser values
(bsc#1269066, CVE-2026-0864).
- gh-143921: Reject NUL, CR and LF characters in IMAP
commands. Other control characters are allowed and sent
quoted (bsc#1257044, CVE-2025-15366).
- Library
... changelog too long, skipping 525 lines ...
- reproducible_stencils.patch
==== rpm ====
Subpackages: rpm-plugin-selinux
- Don’t be dependent on python3-base, it is perfectly OK to use
any Python interpreter for python-rpm-packaging.
- Remove obsolete Python2-based removal of Python directories
(why?)
==== selinux-policy ====
Version update (20260910 -> 20260914)
Subpackages: selinux-policy-targeted
- Update to version 20260914:
* Label charon-nm as ipsec_exec_t (bsc#1278135)
* Fix corrupted formatting in files.if
* Allow nsswitch_domain connect to read xdm pid socket files
* nsresourced fixes for mkosi (bsc#1279902)
* Allow sshd-session connect to gnome remote desktop port
* Allow sshd-session to connect to all generic ports
* Allow sshd-session connect to port 443/tcp (http_port_t)
* Allow sshd-session connect to tcp/22 (ssh_port_t)
* Allow rsync to getattr pipes and sockes if rsync_export_all_ro is set (bsc#1279051)
* Introduce files_getattr_non_auth_sockets
* Introduce files_getattr_non_auth_pipes interface
* Allow rsync to read var_t (bsc#1279565)
* Update udev_manage_pid_files() to include symlinks read
* Support vfs_snapper to work with samba_share_t (bsc#1265400)
* vfs_samba uses dbus to communicate with snapper (bsc#1265400)
* fix NetworkManager dnsmasq-forwarders.conf labeling (bsc#1260038)
* Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366)
* Allow kmscon read cocpit's pid files
* fix vpnc_t setpgid permission for openconnect (bsc#1272934)
* Allow systemd-sysctl to create /run/sysctl.d
* Allow systemd to create /run/udev/control
* Allow systemd-coredumpd to create /run/systemd/coredumpd/kernel
* Allow bootupcl nnp transition to mount_t
* Networkmanager: Remove files_manage_etc_files for console_t
* Networkmanager: Allow NM to manage files under /run
* Allow login_userdomain read/write kmscon devpts chr_files
* Support console version of initial-setup
* ssh-session accesses gitolite ssh config files (bsc#1277259)
* Allow kmscon use netlink permissions (#3368)
* Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783)
* Allow ssh_agent_type manage ssh_home_t files and sock_files
* Allow sshd-session manage ssh_home_t socke files
* Allow sshd-session X11 forwarding
* Allow lsmd-plugin read udev pid files
* Allow virtstoraged domain transition on iscsiadm execution
* Revert "Allow virtqemud domain transition on iscsiadm execution"
* Allow rhsmcertd search gconf home data dirs
* Allow rhsmcertd read gconf home files
* Revert "Allow rhsmcertd read gconf home files"
* Allow postmap read aliases
* Allow lsmd-plugin use libStorageMgmt to provision storage
* Update dhcpc-hook policy
* Allow virtqemud domain transition on iscsiadm execution
* Allow virtqemud domain transition on udev execution
* Allow virtqemud relabelfrom its private fifo files
* Support gnome-remote-desktop's smartcard redirection support
* Allow qatlib manage hugetlbfs directories
* Allow sanlock the sys_admin capability
* Allow rhsmcertd read gconf home files
* Allow rhsmcertd read insights-client config files
* Allow insights-client read install_t process state
* Allow insights-client read the process state of the init scripts
* Allow namespace_init_t execute generic programs in bin directories
* Update the ssh_server_template() template
* Add rules for sshd vsock socket read/write
* Allow dhcpc hook query the chronyd service
* Allow insights-client read gconf home files
* Allow login_userdomain mount, remount, unmount all mount points
* Allow login_userdomain mount on all mount points
* Revert "Allow userdomain get attributes of files on an nsfs filesystem"
* Allow accountsd create and use its private tmpfs files
* Add the anaconda_read_state_install() interface
* Update qatlib policy
* Allow rhsmcertd read the file_contexts files
* rhsmcertd: allow bootc/ostree transient package persistence detection
* Allow virtproxyd connect to systemd-homed over a unix stream socket
* Allow system_mail_t read procmail home content
* Label malware-detection-config.yml with insights_client_etc_rw_t
* Add bcachefs as a SELinux capable filesystem
* Allow unconfined_service_t nnp_transition to container_runtime_t
* Add the files_write_system_conf_files() interface
* Allow haveged (entropyd_t) create and use its private tmpfs files
* Allow ctdbd manage access to Samba PID directories
* Allow rhsmcertd read selinux config and default file contexts
* Allow staff_t and user_t execute udev without a domain transition
* Allow mpd dbus chat with avahi
* Allow init_t nnp domain transition to mpd_t
* Update tuned-ppd policy
* Update policy for virsh_ssh_t to help with live migration
* Update sysadm policy for encrypted volumes usage
* Allow bootupd read all passwd sources
* Allow local login and sshd-session signull cockpit-session
* Allow sysadm_t read/write kvm devices
* Allow sysadm user run fail2ban-client
* Add 2 interfaces helping to handle cloud-what cache files
* Allow all domains to use inherited sshd-session pipes
* Dontaudit tlp_t dac_override (bsc#1272935)
- Syncing with upstream rawhide selinux-policy up to:
* dc63e37474fac5e8f74560acfc1bfdb0f785ec24
- Update embedded container-selinux version to commit:
* 4ac019955c8885496ffbd978520c905434d4273e (v2.251.0)
==== shaderc ====
Version update (2026.3 -> 2026.4)
- Update to release 2026.4
* Incorporate fixes for SPV_KHR_abort abortEXT(...)
* glslc: option -fshader-stage now accepts all shader stage names
as allowed in #pragma shader_stage()> This includes ray
tracing, task, and mesh shader stages.
==== snappy ====
Version update (1.2.2 -> 1.3.0)
- Update to 1.3.0:
* Fixed a uint32_t overflow when decompressor accepted an input with incorrect format
* Significant RISC-V efficiency improvements
* New API on providing your own memory context
* Supporting compression levels (1-2) in C API
* Various other small fixes
- Refresh reenable-rtti.patch
- Disable LiteralLengthU32Overflow test in 32 bit architectures
==== sssd ====
Subpackages: libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap
- Fix IDP provider cross-user impersonation; (bsc#1279915);
(CVE-2026-87853); Add patch
0018-IDP-fix-user-matching-in-eval_access_token_buf.patch
==== timezone ====
Version update (2026c -> 2026d)
- Updat to 2026d:
* Canada’s Northwest Territories moved to permanent -06 on
2026-08-21
* Obsolescent settings like TZ="EST5EDT" now conform better to
POSIX
* Fix security, performance and porting bugs in zic and localtime
==== vmaf ====
Version update (3.2.0 -> 3.2.1)
- Update to release 3.2.1
* libvmaf/speed_chroma: remove bilinear prescale index/weight
computation from per-pixel loop.
* Add ARM NEON implementation for 8-bit integer motion feature.
==== xz ====
Version update (5.8.3 -> 5.8.4)
Subpackages: liblzma5
- Update to version 5.8.4:
* Fix an invalid memory access in lzma_alone_decoder(),
lzma_lzip_decoder(), lzma_auto_decoder(), and
lzma_microlzma_decoder() after a failed allocation is
followed by decoder reinitialization; could crash
(GHSA-5qpq-xqfv-j9pg, CVE pending, affects all versions
since 5.0.0)
* Fix wrong error code/assertion failure in
lzma_stream_buffer_decode() on truncated input
* Fix a performance issue and a theoretical integer
overflow in lzma_index_cat(), used by "xz --list"
* Fix bogus/too-low memory usage reporting in
lzma_index_decoder()
* Fix lzma_index_dup() copying the wrong check type
* Fix a missing synchronization in the threaded .xz
decoder affecting lzma_get_progress()
* xz: fix two use-after-free bugs (--files/--files0 via
XZ_OPT/XZ_DEFAULTS, and --verbose with redirected stderr)
* Add Landlock ABI 9 support on Linux
* Fix "xz --list" totals overflow check, an xzgrep option-
injection quoting bug, and an ARM64/LoongArch unaligned-
read issue; see upstream's release notes for the full list
- spec-cleaner cleanup: drop Group: tags, convert
static-devel's Requires to pkgconfig(liblzma)