Packages changed: AppStream (1.2.0 -> 1.2.1) Mesa (26.2.3 -> 26.2.4) Mesa-drivers (26.2.3 -> 26.2.4) MicroOS-release (20260930 -> 20261003) ModemManager NetworkManager (1.56.1 -> 1.58.1) bash-completion busybox chrony cups-filters2 expat (2.8.4 -> 2.8.5) faad2 (2.11.3 -> 2.11.4) fontconfig (2.18.1 -> 2.18.3) gcc16 (16.2.0+git9497 -> 16.2.1+git9713) ghostscript (10.07.1 -> 10.08.0) google-noto-fonts (20260901 -> 20261001) harfbuzz (14.5.0 -> 14.5.1) hwdata (0.411 -> 0.412) libpng16 (1.6.58 -> 1.6.59) libupnp (22.1.7 -> 22.1.8) openssh pcre2 (10.48 -> 10.49) poppler poppler-qt6 python-PyJWT (2.13.0 -> 2.15.1) python-charset-normalizer (3.4.9 -> 3.5.2) python-oauthlib (3.3.1 -> 4.0.0) python-urllib3 (2.7.0 -> 2.8.0) python313 python313-core qemu rsync selinux-policy (20260928 -> 20261002) talloc (2.4.4 -> 2.5.0) tevent (0.17.1 -> 0.17.2) timezone (2026d -> 2026e) vim (9.2.0901 -> 9.2.1161) vulkan-loader (1.4.357 -> 1.4.363) vulkan-tools (1.4.357 -> 1.4.363) wireplumber (0.5.17 -> 0.5.18) === Details === ==== AppStream ==== Version update (1.2.0 -> 1.2.1) Subpackages: libAppStreamQt3 libappstream5 - Update to version 1.2.1: + Features: - Curl: Include "libcurl" in UA string so AI bot protection hits us less - Compose: Permit changing the downloader user agent - Compose: Try to guess what media we actually downloaded if processing failed - Add support for elogind + Bugfixes: - Meson: Make sed command cross-platform friendly - Meson: Don't use any absolute include path to find libstemmer.h - System-info: Avoid overflow in physical memory total on 32-bit systems - Compose: Flag a missing ffprobe as its own error - Docs: Work around a rare DAPS race condition when building documentation - Resolve or skip failing tests on riscv64 & s390x - Validator: Fix validation of `references` elements - Tests: Relax fontconfig orthography data check for 2.18.3 bug + Miscellaneous: Compose: Move media detection to the worker process ==== Mesa ==== Version update (26.2.3 -> 26.2.4) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.2.4 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.4 - require llvm23 also for sle16 ==== Mesa-drivers ==== Version update (26.2.3 -> 26.2.4) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Update to 26.2.4 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.4 - require llvm23 also for sle16 ==== MicroOS-release ==== Version update (20260930 -> 20261003) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== ModemManager ==== Subpackages: libmm-glib0 - Update version dependencies according to meson.build. ==== NetworkManager ==== Version update (1.56.1 -> 1.58.1) Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Disable 464XLAT Customer-side Translator (CLAT) support on %ix86: + Introduce bcond_with/withot bpf build condition, based on arch + Pass -Dclat=false to meson when bpf is disabled + Only conditionally BuildRequire libbpf and cross-bpf-gcc - Update version dependencies according to meson.build. - Update to version 1.58.1: + Overview of changes since NetworkManager-1.58.0: - For private connections (the ones that specify a user in the "connection.permissions" property), the 802.1X "ca-path" and "phase2-ca-path" properties are no longer accepted and activation fails, as the daemon would otherwise let the owner of the profile choose the CA trust store used to validate the authentication server. Such profiles must clear those properties and use "ca-cert" or "system-ca-certs" instead. - Fix IPv4 forwarding not enabled on modem data interfaces. - Log a warning when ignoring DHCPv4 option 3 (Router) due to the presence of option 121/249 (Classless Static Routes) results in no gateway. - Set the parent interface by name for NBFT VLAN connections in the initrd generator to avoid race conditions at boot. - Perform the connectivity check also when the interface only has an IPv4 link-scope default route. - Ignore unspecified addresses as DNS nameservers from RDNSS and DHCPv6, and skip invalid nameservers when configuring systemd-resolved. - Fix auto-connect to SAE (WPA3) networks with key-mgmt=wpa-psk profiles. - Fix DNS server port number not forwarded to systemd-resolved for DNS URIs. - Fix normalization of Bluetooth NAP connections. - Fix multiple crashes. NetworkManager-1.58 + General: - Unify the versioning to use everywhere the scheme with the - rcX or -dev suffixes when appropriate. This affects, for example, the URL and filename of the release tarball and the version reported by nmcli and the daemon. As an exception, the C API will continue to use the 90+ scheme for RC versions. - Install the systemd units in the initramfs using a systemd generator. + Core: - Connection profiles with manual IP addressing and with gateways that are not directly reachable will generate a warning on activation and when they are added/modified via nmcli and nmtui. NetworkManager currently adds on-link routes for them automatically, but this will change in the future. To fix the warning, users should add addresses or routes whose subnets cover these gateways. A gateway (either the default gateway or the next-hop of a route) is considered directly reachable if it falls within the subnet of a direct route (a route without a next hop) or of a prefix route from a static address. - Use an internal implementation of the ping functionality when the "connection.gateway-ping-timeout" or "connection.ip-ping-addresses" properties are set, instead of relying on the "ping" tool. - Add support for CLAT (464XLAT) using a BPF program, controlled by the "ipv4.clat" property. CLAT is still disabled by default for now. - Change the default value of the ipv4.dhcp-ipv6-only-preferred property to a new value "auto" which automatically enables the option when CLAT is enabled ("yes" or "auto") in the connection profile. - Allow persisting the managed state across reboots from the D-Bus API and nmcli. time as a change to the managed state from the D-Bus API and nmcli. - IPv6 interfaces that receive PD via DHCPv6 are considered healthy without a non-temporary address. The delegated prefix can be used via an interface configured with "ipv6.method: shared" - Fix reapply not honoring the ipv6.ignore-auto-dns, ipv6.ignore-auto-routes and ipv6.never-default properties when DHCPv6 was not restarted (for example when the IPv6 DNS came from a DHCPv6 lease), so that DHCPv6-provided DNS and routes are now correctly suppressed on reapply without a connection restart. + Connectivity: - A new "check-connectivity" configuration option is available to disable the connectivity check for selected interfaces. - Restrict the connectivity check to use the DNS servers defined on the same link. If the link has no DNS servers, the connectivity check will use any servers available in the system. - Fix stale global connectivity state with connectivity checking enabled: NetworkManager could report limited connectivity while another device had full connectivity, or keep reporting limited after a device regained internet access. + DHCP: - The internal DHCPv4 client now ignores option 3 (Router) if the lease contains option 121 (Classless Static Route), as recommended by RFC 3442. - Fix an out-of-bounds read in the internal DHCPv4 client that an on-link attacker could trigger with a malformed UDP packet, crashing NetworkManager. - Validate hostnames and MUD URLs before pasting them into the dhclient configuration file, rejecting characters that could alter the config syntax (CVE-2026-10805). + Wi-Fi: ... changelog too long, skipping 80 lines ... translator) support. ==== bash-completion ==== - Based on the new fallback feature: split old delete list of completions in a fallback and a remove list and handle the to be removed like adb and the fallbacks like bts ==== busybox ==== - Fix pre-authentication heap buffer overflow in TLS caused by unit confusion in the Montgomery reduction buffer allocation (CVE-2026-88830, bsc#1282575) * 0001-tls-fix-undersized-buffer-calculation.patch - Fix httpd silently failing open when IP deny rules contain an invalid CIDR prefix length (CVE-2026-88831, bsc#1282550) * 0001-httpd-fix-handling-of-D-1.2.3-999.patch - Fix heap buffer overflow when parsing the volume ID of crafted romfs filesystem images (CVE-2026-88832, bsc#1282576) * 0001-volume_id-romfs-limit-the-maximum-size-of-label-to-V.patch - Fix out-of-bounds read in dpkg read_package_field() stepping past the NUL terminator on malformed .deb packages (CVE-2026-88835, bsc#1282551) * 0001-dpkg-free-results-of-read_package_field-preliminary-.patch * 0002-dpkg-reformat-code-in-read_package_field-exposing-wh.patch * 0003-dpkg-fix-cases-where-read_package_field-returns-offs.patch - Fix out-of-bounds read and silent corruption of the dpkg status file caused by write_status_file() not resetting the field_start cursor between package stanzas (CVE-2026-88841, bsc#1282653) * 0004-dpkg-fix-field-handling-in-write_status_file.patch - Fix httpd misidentifying yescrypt password hashes as plaintext (CVE-2026-88837, bsc#1282552) * 0001-httpd-allow-yescrypt-passwords-y.patch - Fix out-of-bounds write of heap pointers in the passwd/group parser due to a stale tokenize() endpoint (CVE-2026-88839, bsc#1282568) * 0001-libpwdgrp-tokenizer-fix-for-trailing-whitespace-remo.patch ==== chrony ==== Subpackages: chrony-pool-openSUSE - (bsc#1273873): Replace chrony-usretc-service.patch with chrony-usretc-config-fallback.patch to let chronyd itself fall back to /usr/etc/chrony.conf when /etc/chrony.conf is absent and no -f is given. - Rework chrony-service-ordering.patch (bsc#1145193, bsc#1279495): * chronyd.service: drop the time-sync.target coupling (Wants= and Before=); chronyd is Type=notify, so readiness only means the daemon started, not that the clock is synced. * chronyd.service: also drop "Wants=network.target", keeping just After=nss-lookup.target and After=network.target. * chrony-wait.service: add After=/Wants=network-online.target so it no longer times out before the network is up. - Default OPTIONS to "-s" in the chronyd sysconfig to seed the clock from the RTC (or driftfile) at start-up; override in /etc/sysconfig/chronyd. ==== cups-filters2 ==== - revert previous change and --enable-universal-cups-filter again because '--disable-universal-cups-filter' does not work because it results a /usr/share/cups/mime/cupsfilters.convs which only has a few text/plain rules for text-only printers (in particular nothing for PDF and image formats), see https://bugzilla.suse.com/show_bug.cgi?id=1283295 ==== expat ==== Version update (2.8.4 -> 2.8.5) - security update: * CVE-2026-102633: expat: Denial of Service via integer overflow in expat_realloc (bsc#1283493) - Added patch expat-CVE-2026-102633.patch - update to 2.8.5 (bsc#1282347, CVE-2026-93990): * Security fixes: * CVE-2026-93990: reject high surrogates not followed by a low surrogate during UTF-16 decoding; malformed UTF-16 could be smuggled into the application (CVSS 9.8) * Bug fixes: * Fix an OOM-related memory leak on a failed overflow check * Fix memory alignment for architectures with 128bit pointers * Mark XML_SetHashSalt deprecated ==== faad2 ==== Version update (2.11.3 -> 2.11.4) - Update to version 2.11.4: + Fix the fixed-point SBR envelope estimate + Fix PNS decoding window offset clamping for short sequences + Add sample-accurate gapless MP4 container trimming (`elst` atom and `iTunSMPB` metadata support, including SBR decoder delay adjustment) + Fix `-g`/`--no-gapless` CLI option parsing and metadata tag handling + Fix mono HE-AAC channel counts and PS signaling for HE-AAC v2 MP4 files ==== fontconfig ==== Version update (2.18.1 -> 2.18.3) Subpackages: libfontconfig1 - add 583.patch to protect against a potential type confusion - Update to 2.18.3 * ci: Add --werror option to the build script * fc-cat: exit with non-zero if not successfully done * Workaround a longstanding use-after-free warning * Fix a null pointer dereference * Add Noto Sans as system-ui for fallback * Drop Noto Sans CJK KR from 60-nonlatin.conf * Correct sat.orth * Add an orth file for Balinese * Update orth files for jv, so, su, tl to use native scripts * Add orth files for scripts used by Noto font families * Update mni.orth to use Meetei Mayek script * Add orth files for Cuneiform languages (akk, sux, hit) * ci: Suppress abidiff false positives for all internal structs * test: Add cache format compatibility tests for orth file additions * Add orth files for ancient scripts (xna, hlu, ecy) * fc-cache: Create backward-compatible cache symlinks for cross-version discovery * ci: Update dependencies * Add implicit rule to update genericfamily property against syntactic-sugar * fc-genconf: Use alias syntactic-sugar instead of the pair of test-edit config * Allow to limit the targeted family for TTC * test: Fix test_genconf.py to avoid unexpected family name in testing conf * ci: Enable -Werror in CI * ci: drop duplicate pipelines * ci: cleanup * ci: gate distro jobs until all tests passed * ci: reduce more duplicate jobs * ci: Update base ci-templates * test: Fix compiler warnings * fc-fontations: Allow unnecessary_transmutes lint in bindgen-generated Rust code * Fix another compiler warnings * ci: Bump FreeBSD version to 14.4 * Fix the compiler warnings on MinGW * Update INSTALL * Fix "FileType is deprecated" * Fix unknown type name locale_t on macOS - Update to 2.18.2 * test: fix unexpected error when something went wrong in pytest * test: Fix a regression for sysroot in test framework * test: Fix a test case failure when BUILDDIR is under /tmp * test: cleanup * Add .gitignore * meson: Add tests-external-fonts option to disable network-dependent tests * Add .editorconfig * test: improve marker handling * test: Fix a fail on subproject build * test: Do not assume all-files-installed before testing * ci: set SOURCE_DATE_EPOCH to the build script * test: unset SOURCE_DATE_EPOCH for some test cases * Use genericfamily for the search of monospace against :spacing=100 * conf.d: Add OpenMoji Color and OpenMoji Black * test: Fix a KeyError * Add a hash table for fonts to generate expected genericfamily * Add Nerd Fonts to the table * doc: Fallback to wkhtmltopdf if no docbook2pdf available * fc-genericfamily: Add Noto fonts * fc-cache: do not generate cache when target directory is in deny list * conf.d/Makefile.am: install 05-macos.conf for macOS only * Add more conditional code for FcLocaleSetCurrent() * Do not ship unnecessary files in archive * fc-genericfamily: Add major missing fonts across multiple categories * Use Special FC_CACHE_VERSION for snapshot * new-version.sh: fix an error * Fix FcNameUnparse regression. * Fix FcNameUnparse regression. - modified patches * fontconfig-autoconf269.patch (refreshed) ==== gcc16 ==== Version update (16.2.0+git9497 -> 16.2.1+git9713) Subpackages: cpp16 libgcc_s1 libgomp1 libstdc++6 - Update to gcc-16 branch head, git9713 * pulls fix for use-after-free in __gnu_pbds::priority_queue. [bsc#1283123] (CVE-2026-102010) - Update to gcc-16 branch head, git9708 * pulls fix for ICE building firefox on arm [bsc#1268791, gcc#125953] * remove gcc16-pr124811.patch and gcc16-znver6-cpuid.patch included in the update ==== ghostscript ==== Version update (10.07.1 -> 10.08.0) - Version upgrade to 10.08.0 See 'Recent Changes in Ghostscript' at Ghostscript upstream https://ghostscript.readthedocs.io/en/gs10.08.0/News.html * This release addresses a number of potential security issues. * The 10.08.0 release removes a number of old, unmaintained and (at the time of this release) untestable and thus unmaintainable devices from the default builds, as a precursor to removal of the device sources in the next release. This process will continue as development time allows. If you rely on any of the removed devices and are willing to help testing them, please get in touch at: bugs.ghostscript.com * The usual round of bug fixes, compatibility changes, and incremental improvements. - In particular it fixes CVE-2026-39919 "Heap buffer overflow in the JPEG 2000 (JPXDecode) output adapter via component subsampling mismatch (base/sjpx_openjpeg.c)" https://bugs.ghostscript.com/show_bug.cgi?id=709666 "heap-based buffer overflow in the JPEG 2000 output adapter allows attackers to cause memory corruption by supplying crafted PDFs" (bsc#1280620) ==== google-noto-fonts ==== Version update (20260901 -> 20261001) Subpackages: google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Update to 20261001: * Sans Devanagari: - Remove incorrectly localized Nepali fixes (#62) - Improve rendering of U+0908 - Improve rendering of certain Nepali conjuncts - Improve Rakar U+094D and U+0930 for the Marathi language - Adjust some glyphs for Santali ==== harfbuzz ==== Version update (14.5.0 -> 14.5.1) Subpackages: libharfbuzz-gobject0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.5.1: + Map the `fonupa` (Uralic Phonetic Alphabet) BCP 47 variant to the `UPPH` OpenType language system tag. + Produce smaller `cmap` subtables and drop no-op variation device tables when subsetting. + Fix possible deadlock in `hb_font_destroy()` after `hb_ft_font_set_funcs()`, a regression from 14.5.0. + Fix signed integer overflows when scaling glyph extents and applying synthetic slant and emboldening. + Fix float-to-int overflow in `VARC` component axis coordinates with malformed fonts. + Fix a memory leak in the experimental WebAssembly shaper when shaping with features. + Fix accumulator overflows in the experimental raster library when rendering glyphs with very many overlapping edges. + Fix heap buffer overflow in the experimental GPU library with malicious `COLR` fonts. + Various build and CI fixes. - Update version dependencies according to meson.build. ==== hwdata ==== Version update (0.411 -> 0.412) - Update to 0.412: * pci.ids refreshed to the 2026.10.01 snapshot, 247 lines added and 19 removed * Six new vendor ids: 0168 Chengdu ZeoberCom (23 CPCI/PCI interface cards), 1ca5 Corerise Electronics (Comay SBC208 SCSI controller), 2159 AIC Semiconductor Shanghai, 215a Suzhou Ruixin (5 devices), and 215e SmarCo HT Tech and 2165 Dnotitia * AIC Semiconductor moved off the wrong vendor id a69c onto 2159, keeping its AIC8800M80X2P network controller * AMD entries renamed and added: Granite Ridge and Raphael now carry the Radeon 610M name, and GB100 [B200], GB203 [GeForce RTX 5070], GB20B [RTX Spark N1X], TB500 RP x16/x8/x4/x2/x1 and GR100/GR102 are new * Broadcom/LSI gained two SAS9300-16e Fibre Channel ids; the 1107 WCN785x entry is renamed NCM8x5/WCN785x * usb.ids, pnp.ids, iab.txt and oui.txt are unchanged ==== libpng16 ==== Version update (1.6.58 -> 1.6.59) - version update to 1.6.59: * Fixed CVE-2026-46675 (medium severity): Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression. (Reported independently by Ze Sheng and .) * Fixed a regression introduced in version 1.6.47 that caused libpng to reject hIST chunks in their correct position, after PLTE. (Contributed by Yuki Sekiguchi.) * Prevented a double free of `png_struct` members after an allocation failure. (Contributed by Anthony Hurtado.) * Applied fixes and updates to the CMake build. * Adopted the REUSE Specification for licensing the CI files. - fixes CVE-2026-46675 [bsc#1283183] ==== libupnp ==== Version update (22.1.7 -> 22.1.8) Subpackages: libixml22 libupnp22 - Update to release 22.1.8 * Cap the MX header of an incoming SSDP M-SEARCH request at 5 seconds [GHSA-8pj8-vmhq-qwvj] * Fix denial of service of the miniserver worker threads by connections that send nothing [GHSA-hwrm-c56x-fj22] * Fix a path traversal in the web server on Windows [GHSA-f8rh-7wq7-v4m7] ==== openssh ==== Subpackages: openssh-clients openssh-common openssh-server - Update openssh-8.4p1-ssh_config_d.patch with mentions of the configuration drop-in directories (bsc#1259462). - Add openssh-10.5p1-propagate-restrict-keyword.patch (bsc#1275079). - Drop obsolete -fstack-protector from CFLAGS/CXXFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== pcre2 ==== Version update (10.48 -> 10.49) Subpackages: libpcre2-16-0 libpcre2-8-0 - Update to 10.49: * GHSA-r9hj-j2rw-4q3m: out-of-bounds write in JIT matching with large stack allocations (boo#1283020) ==== poppler ==== Subpackages: libpoppler-cpp3 libpoppler164 - ensure python3 is available due adding python3-base to Buildrequires ==== poppler-qt6 ==== - ensure python3 is available due adding python3-base to Buildrequires ==== python-PyJWT ==== Version update (2.13.0 -> 2.15.1) - Update to 2.15.1 * Accept trailing Base64URL = padding when decoding JWS segments, so tokens issued by AWS ALB and similar systems verify instead of raising DecodeError: Invalid crypto padding. Non-alphabet junk such as !!!! remains rejected (#1209). - Update to 2.15.0 (fixes CVE-2026-101918 (bsc#1283061), CVE-2026-102275 (bsc#1283072)) * Wrap recursion errors from deeply nested JWT payloads in DecodeError instead of exposing a raw RecursionError. * Support Python 3.15 by @kytta in #1202 * JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in #1208 * PyJWKClient.fetch_data() now raises PyJWKClientError("The JWKS endpoint did not return a JSON object") when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in #1208 * Return cached PyJWKSet values from PyJWKClient.get_jwk_set() instead of raising PyJWKClientError("The JWKS endpoint did not return a JSON object"). JWKSetCache.put() documents PyJWKSet as the cached value, so callers pre-populating the cache to avoid a network round-trip could not read it back in #914 and [#1208] * PyJWKClient.get_jwk_set() now caches the key set it returns, so a fetch_data() override that filters or transforms the JWKS is no longer undone by the next cache hit in #1208 * Raise the documented PyJWTError subclass instead of leaking a TypeError when the exp, nbf, or iat claim decodes to a non-numeric, non-string value such as a list, dict, or null. * Reject OKP JWK private keys when their public x component does not match the private d component. * Treat malformed JWK Set members as unusable keys rather than letting AttributeError or TypeError escape PyJWKSet. A member that is not a JSON object is skipped, a key whose components have the wrong type raises InvalidKeyError and is skipped, and a set left with no usable keys raises PyJWKSetError. A single bad entry no longer fails an otherwise usable JWK Set in #1208 * Wrap http.client.HTTPException (e.g. IncompleteRead from a truncated response) in PyJWKClient.fetch_data as PyJWKClientConnectionError, matching the other network failure modes the method already documents. - Update to 2.14.0 (fixes CVE-2026-102270 (bsc#1283067), CVE-2026-101917 (bsc#1283060), CVE-2026-102273 (bsc#1283070), CVE-2026-102272 (bsc#1283069), CVE-2026-102271 (bsc#1283068), CVE-2026-103001 (bsc#1283829), CVE-2026-102274 (bsc#1283071), CVE-2026-102269 (bsc#1283066), CVE-2026-102265 (bsc#1283062), CVE-2026-102268 (bsc#1283065), CVE-2026-102267 (bsc#1283064), CVE-2026-102266 (bsc#1283063)) * Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See GHSA-r6x4-923q-g947, GHSA-ffc3-869f-jxw9, GHSA-p4g4-x82p-q773, and GHSA-w2cx-738m-mc7w. * Reject automatic redirects when PyJWKClient fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See GHSA-9v7f-9g4p-ffgj. * Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See GHSA-2gx3-rcp4-g85q. * Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See GHSA-8wjv-2p76-3863 and GHSA-w6j9-cwv2-h6wq. * Enforce compact JWS encoding rules during decoding. See GHSA-hxm8-2xgr-2p9m. * Reject detached-payload arguments for attached JWS inputs. Thanks to @xclow3n for reporting this behavior; fixed in commit 37b54877. * Apply HMAC key validation consistently when keys are loaded through PyJWK and PyJWKClient. See GHSA-pxh4-856f-4h89. * Reject empty HMAC keys when represented as JWKs. See GHSA-pxh4-856f-4h89. ==== python-charset-normalizer ==== Version update (3.4.9 -> 3.5.2) - Update to version 3.5.2 Fixed * Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. * Supported encodings without aliases failing name resolution or being ignored in charset declarations. - Update to version 3.5.1 Fixed * No longer decoding large content when the noise detector output give a high entropy. Only impacted large content input >1M bytes. - Update to version 3.5.0 Added * Explicit support for Python 3.15 Fixed * Comparing a CharsetMatch to a non-alias encoding strings (#773) * Return 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (#774). * A file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset. * iso2022* cases misdetected due to a flaw in our multibyte chunking logic. Changed * Replaced the optional mypyc build with Cython extensions while retaining the pure Python fallback. * Applied micro-optimization on several utils. * CharsetMatches no longer sort on each match insertion. Misc * Removed an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache). ==== python-oauthlib ==== Version update (3.3.1 -> 4.0.0) - Update to 4.0.0 (bsc#1283526, CVE-2026-49264, bsc#1283527, CVE-2026-49265) OAuth2.0 Provider: * Breaking: #951: Removed JSONP support from token revocation endpoint. * Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client. * #963: Improved PKCE code comparison Misc: * #904: Stop installing examples into site-packages. * #930: Add Python3.14, Python3.14t. * #932: Dropped EOL Python 3.8 from CI. ==== python-urllib3 ==== Version update (2.7.0 -> 2.8.0) - Update to 2.8.0: [#] Security - The TLS configuration for HTTPS proxies could be ignored or overridden. (bsc#1283908, CVE-2026-97687) - ``HTTPResponse.stream()`` and ``read_chunked()`` could buffer a chunk-size line of unbounded length in memory. (bsc#1283910, CVE-2026-97689) - Chunked Deflate streaming could enter an infinite loop. (bsc#1283909, CVE-2026-97688) [#]# caution urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes. Configure proxy CA certificates and client certificates in ``proxy_ssl_context``, and proxy identity checks with ``proxy_assert_hostname`` or ``proxy_assert_fingerprint``. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections. [#] Deprecations & Removals - Deprecated using an empty collection as the ``Retry`` option ``allowed_methods`` to retry any verb. [#] Features - Added ``Url.auth_decoded`` and ``Url.auth_decoded_joined`` convenience properties to the result of ``parse_url()``. - Added ``basic_auth_encoding`` and ``proxy_basic_auth_encoding`` parameters to ``urllib3.util.make_headers()``. [#] Bugfixes - Fixed response header handling to replace obsolete folded header lines (`obs-fold`) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as ``Set-Cookie``. - Fixed usage of ``proxy_ssl_context`` with ``ProxyManager`` when ``use_forwarding_for_https=True``. Passing ``ssl_context`` instead of ``proxy_ssl_context`` for HTTPS proxies in this configuration now emits a ``FutureWarning`` and will raise an error in v3.0. - Changed behavior of the default ``ConnectionPool.pool`` initialization. ``LifoQueue`` is now resolved from the ``queue`` module after the ``ConnectionPool`` is instantiated instead of using the default cached ``QueueCls`` class property. This is done because sometimes the ``queue.LifoQueue`` is monkey-patched late in the program, such as by gevent. - Raised ``UnrewindableBodyError`` instead of ``ValueError`` when retrying a request whose body had ``tell()`` but not ``seek()``. - Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. - Fixed ``HTTPResponse.drain_conn()`` to discard unread response data in 64 KiB chunks (same as the default ``amt`` when doing ``HTTPResponse.stream(...)``). - Fixed ``is_ipaddress()`` to detect non-standard IPv4 forms accepted by ``socket.connect``, such as hex (``0x7f000001``), octal (``0177.0.0.1``), and decimal integers (``2130706433``), ensuring SSL certificate verification uses the correct mode for these addresses. - Fixed ``HTTPConnectionPool.urlopen`` raising a misleading ``FullPoolError`` instead of ``ValueError`` when called with an invalid ``timeout`` argument on a pool created with ``block=True``. - Fixed port-zero handling to preserve explicit ``:0`` values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, ``connection_from_url()``, and HTTP/2 request authority. - Fixed a bug where ``PoolManager`` passed the ``assert_hostname`` and ``assert_fingerprint`` parameters to HTTP connection pools. - Fixed ``HTTPConnectionPool.urlopen()`` and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. - Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. - Fixed ``HTTPSConnection.connect()`` overriding ``ProxyConfig.ssl_context``'s certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy. ``HTTPSConnection`` no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ``ssl_context`` as a fallback when an HTTPS proxy forwards an HTTP target. - Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. - Fixed an ``AttributeError`` on Python built with OpenSSL 4+, where ``ssl.PROTOCOL_TLSv1`` no longer exists. - Fixed ``urllib3.contrib.pyopenssl`` to use cryptography APIs when reading a certificate subject and loading encrypted private keys, avoiding ``DeprecationWarning`` raised by pyOpenSSL 26.3.0+. - Fixed handling of HTTP 303 redirects for requests with chunked or file-like bodies. - Fixed ``assert_fingerprint()`` to raise ``SSLError`` instead of ``binascii.Error`` when a fingerprint has a supported length but ... changelog too long, skipping 9 lines ... - Fixed flaky tests. ==== python313 ==== - CVE-2026-15310: bound zipfile decompression for bzip2/LZMA/Zstandard (bsc#1277111, gh#python/cpython#156002) CVE-2026-15310-bound-zipfile-decompression.patch ==== python313-core ==== Subpackages: libpython3_13-1_0 python313-base - CVE-2026-15310: bound zipfile decompression for bzip2/LZMA/Zstandard (bsc#1277111, gh#python/cpython#156002) CVE-2026-15310-bound-zipfile-decompression.patch ==== qemu ==== - Bugfixes and (spec-file) improvements: * vapic: confine the VAPIC region to 0xc0000..0xe0000 (bsc#1282077, CVE-2026-81627) * hw/9pfs: mutate FID path from main thread only (bsc#1282578, CVE-2026-93834) * [openSUSE][RPM] spec: drop qemu-ipxe Requires for ppc (bsc#1282918) * [openSUSE][RPM] spec: stub out all iotests when running under user emulation (e.g., for riscv64) * target/ppc/kvm: Use host compatibility mode for nested guests (bsc#1263864) * target/ppc/kvm: Add support for querying host compatibility mode (bsc#1263864) * linux-headers: Update to include KVM_CAP_PPC_COMPAT_CAPS (bsc#1263864) * file-posix: Tolerate unaligned hole at middle (bsc#1277435) * [openSUSE][RPM] spec: skip the tests that require get_mempolicy under linux-user * [openSUSE][RPM] build all firmware on riscv64 and fix user tests ==== rsync ==== - Limit the number of check jobs to the available jobs ==== selinux-policy ==== Version update (20260928 -> 20261002) Subpackages: selinux-policy-targeted - Update to version 20261002: * Allow gnome-remote-desktop use kerberos * Allow gnome-remote-desktop read password files * Add new interfaces for rhc-worker-playbook * Allow virtqemud getattr fuse filesystem conditionally * Allow cloud-init the setgid capability * Allow bootupd read proc dirs * Allow bootupd read /proc/swaps * Allow login_userdomain dbus chat with power-profiles-daemon * Allow icecast create and use unix dgram sockets * Allow systemd-coredump send a null signal to unconfined services * Allow samba_dcerpcd_t signull smbd_t * Make post-te statement extraction tolerant of leading whitespace * Allow login/pam_systemd started by kmscon to access env vars * Allow sshd-session tcp connect to all reserved ports * Allow sshd-session connect to vnc port * Allow sshd-session transition on passwd execution * Allow dhcpc-hook get init status * Allow kmscon read systemd_ssh_issue PID files * Rearrange kmscon policy to comply with formatting rules * Allow kmscon signal init * Allow systemd-timedated read network sysctls * Add CI check for whitespace on pull requests * Remove commented-out interface calls * Fix whitespace across all policy modules * Move systemd_read_userdbd_runtime_sock_files() to another optional block * Use udev_manage_pid_lnk_files() instead of direct reference - Syncing with upstream rawhide selinux-policy up to: * f52a7800ecaecff7a39f95cd1b89b686daf6729b ==== talloc ==== Version update (2.4.4 -> 2.5.0) - Fix building of the `man` multibuild. - Extend talloc-python3.5-fix-soabi_name.patch to preserve underscores in PYTHON_LIBNAME_SO_ABI_FLAG as well as public library filenames. This keeps the pkg-config Libs entry consistent with the installed libpytalloc-util library and fixes Samba linking without a post-install name substitution. - Declare the python-rpm-macros build dependency explicitly and update the man-page build-cycle comment for the separate multibuild flavor. - Update to 2.5.0 * alloc: Add talloc_asprintf_addsep() * lib:talloc:testsuite remove unread global test_abort_stop * Replace memset_s() with memset_explicit() - Convert the package to _multibuild flavors: the man pages are now built from the "man" flavor of talloc.spec instead of a generated talloc-man.spec, so pre_checkin.sh, talloc-man.spec and talloc-man.changes are gone. No need to maintain duplicate files. - Merge the duplicated %if blocks in the spec file and give the man flavor its own summary and description. - Remove use of obsolete %py3* macros, use only the maintained ones from `python-rpm-macros` package. - Make rpmlint happy. ==== tevent ==== Version update (0.17.1 -> 0.17.2) - Update to 0.17.2 * let tevent_common_have_events() ignore fd events without active flags, in order to avoid tevent_loop_wait() to loop forever with only such events. * ignore fd events without flags in tevent_common_have_events() ==== timezone ==== Version update (2026d -> 2026e) - Update to 2026e: * Manitoba moves to permanent -05 on 2026-10-31 ==== vim ==== Version update (9.2.0901 -> 9.2.1161) Subpackages: vim-data-common vim-small - Update to 9.2.1161: 9.2.0958: Vim9: wrong type for the rest of a tuple in an unpack assignment 9.2.0959: tests: Test_xrestore() is flaky and cannot recover 9.2.0960: double-free in string_reduce() 9.2.0961: base64_encode() gives wrong result for a zero byte 9.2.0962: popup images are not using the kitty protocol properly 9.2.0963: crash when sound-folding a crafted spell file 9.2.0964: 'isprint' is applied to the leading byte of a character 9.2.0965: GTK4: blurry text rendering 9.2.0966: GTK4: window opens two lines too small 9.2.0967: hit-enter prompt eats keys from a running mapping 9.2.0968: status line height is wrong after exchanging or rotating windows 9.2.0969: runtime(shaderslang): matchit % breaks on braces 9.2.0970: buffered listener cannot obtain the text of a change 9.2.0971: "=~" and the match functions compile their pattern on every call 9.2.0972: extend() family does not accept a blob 9.2.0973: Vim9: internal error when a class member is initialized with a closure 9.2.0974: tests: Test_clientserver_serverlist_list() is flaky 9.2.0975: Vim9: assignment to a member of an object member fails 9.2.0976: Vim9: line continuation for command arguments is undocumented 9.2.0977: tests: test_terminal_visual_empty_listchars() is flaky 9.2.0978: terminal: empty lines don't use the background color of hl-terminal 9.2.0979: terminal: mouse stays enabled after Vim is killed with SIGTERM 9.2.0980: runtime(netrw): prioritize g:netrw_home on Neovim 9.2.0981: substitute: wrong text after undo of a confirmed \r 9.2.0982: tests: test_substitute leaves swapfiles behind 9.2.0983: 'laststatus' is ignored when creating a full-height vertical split 9.2.0984: runtime(zip): cannot adjust zip command line 9.2.0985: Multiline messages not visible when mapping starts cmdline 9.2.0986: long options are accepted with a trailing garbage 9.2.0987: heap-buffer-overflow in spell_suggest() 9.2.0988: tests: Test_terminal_csi_resize_oob() returns early 9.2.0989: libvterm: hang when rendering REP with no preceding char 9.2.0990: libvterm: crash when a scroll region outlives a resize 9.2.0991: autocmd: events are triggered for what happened while they were ignored 9.2.0992: popup filter gets the key at the hit-enter prompt 9.2.0993: runtime(netrw): error when parent dir of g:netrw_home doesn't exist 9.2.0994: Vim9: No error for :open during compilation 9.2.0995: tests: no check that g:netrw_home has higher priority than $MYVIMDIR 9.2.0996: debugger: crash when evaluating a variable in a :def function frame 9.2.0997: ch_sendexpr() cannot answer a request named with a string id 9.2.0998: Reject non-string-literal arguments to STRLEN_LITERAL 9.2.0999: serverlist() fails when there is no connection to the server 9.2.1000: Vim9: listener_add() fails when given only a callback 9.2.1001: complete_info() does not report the item highlight groups 9.2.1002: filetype: bazelrc files are not recognized 9.2.1003: popup: border is not shown when the popup does not fit 9.2.1004: a completion function cannot tell why it was called 9.2.1005: backupcopy=auto overwrites a file in place with umask 9.2.1006: fold functions do not accept window id 9.2.1007: fuzzy completion list wrongly sorted after complete() 9.2.1008: Vim9: hang when a line break is used before "->(" 9.2.1009: duplicate dict code in ins_compl_dict_alloc() 9.2.1010: compile error when folding feature is disabled 9.2.1011: [security]: arbitrary Ex command execution during C omni-completion 9.2.1012: tests: no enough testing for complete_info() "auto" 9.2.1013: [security]: out-of-bounds access in libvterm CSI 8 t resize 9.2.1014: [security]: overflow in undo file entry size check on 32-bit arch 9.2.1015: Vim9: v:errmsg is set while looking ahead at a command 9.2.1016: tests: viminfo bar line length overflow test fails under ASAN 9.2.1017: heap-use-after-free in ml_open_file() 9.2.1018: filetype: radvd config files are not recognized 9.2.1019: completion asked for during 'autocompletedelay' looks automatic 9.2.1020: autocmd: crash when 'eventignore' is changed while it is being set 9.2.1021: GTK: Cursor blinks irregularly 9.2.1022: popup: width changes while scrolling 9.2.1023: GvimExt: destructors of polymorphic classes are not virtual 9.2.1024: 'wildmode' list:full does not complete first match 9.2.1025: NFA regexp matching is slower than necessary 9.2.1026: heap-use-after-free via DiffUpdated autocommand 9.2.1027: runtime(helptoc): FuzzySearch() highlights matched characters at the wrong column 9.2.1028: redraw: cursor is left in the wrong place with an operator pending 9.2.1029: NFA regexp matching is slower than necessary 9.2.1030: using wrong printing font with pango 9.2.1031: 'wildmode' list:full does not show 'wildmenu' 9.2.1032: scrolling moves cursor up with 'scrolloffpad' 9.2.1033: session: sourcing fails on lambdas 9.2.1034: NFA regexp matching is slow for ASCII text 9.2.1035: filetype: Github citation files are not recognized 9.2.1036: syntax highlighting is slower than necessary 9.2.1037: crash when slicing a range() list with too many items 9.2.1038: CursorLineFold/Sign highlighting depends on 'cursorlineopt' 9.2.1039: MS-Windows: Unix domain socket channels fail 9.2.1040: matchfuzzypos() can be improved 9.2.1041: vim_strbyte() can be improved 9.2.1042: sign: placing many signs is slower than necessary 9.2.1043: matchlist() allocates empty strings for unmatched submatches 9.2.1044: Vim script execution is slower than necessary 9.2.1045: runtime(netrw): raises E46 when changing directory fails 9.2.1046: regex: case-insensitive match fails on multi-byte string with re=1 9.2.1047: Copying a List is slower than necessary 9.2.1048: session: syntax error when restoring session 9.2.1049: Cannot use the stdin and stdout of Vim as a channel 9.2.1050: tests: test_suspend() fails on Solaris 9.2.1051: getdigits() overflow behaviour is not portable 9.2.1052: filetype: evcxr history files are not recognized 9.2.1053: libvterm: characters can get a different width in a terminal window 9.2.1054: Virtual Replace mode: BS over multi-byte text eats the padding 9.2.1055: Vim9: a lambda with a block body fails to compile after error ... changelog too long, skipping 162 lines ... 9.2.0957: filetype: ArgoCD config file is not recognized ==== vulkan-loader ==== Version update (1.4.357 -> 1.4.363) - Update to tag SDK-1.4.363.0 * Release VK_INSTANCE_LAYERS in enable_correct_layers_from_settings * Fix whole-wildcard and short prefix globs in determine_filter_type * Speed up vkGet{Instance,Device}ProcAddr lookups * loader: apply settings device configurations to device groups * loader: clamp driver-reported device extension count to caller buffer ==== vulkan-tools ==== Version update (1.4.357 -> 1.4.363) - Update to tag SDK-1.4.363.0 * vulkaninfo: Enable more instance extensions * Add VK_EXT_display_surface_counter instance extension * vulkaninfo: Include extended flags in video format props output ==== wireplumber ==== Version update (0.5.17 -> 0.5.18) Subpackages: libwireplumber-0_5-0 - Update to version 0.5.18: * Additions & Enhancements: - Improved find-best-profile to rank profiles on the availability of their output routes before their priority, so that UCM cards bundling HDMI outputs together with speakers or headphones no longer select a profile whose analog output is unplugged when a monitor is connected - Improved HDMI node descriptions: the monitor name is now taken from hdmi.product.name (set by PipeWire from the current ELD) so that it is correct for displays switched on after the card was set up, the alsa.name suffix is also shown for UCM devices, the ELD-detected channel layout is shown for UCM devices, and the channel suffix is added after monitor.alsa.rules are applied - Improved the ALSA node error recovery to allow at most 3 attempts per device (reset after 60s without errors), instead of looping forever on devices that keep failing after being re-opened * Fixes: - Fixed WpImplModule to load and destroy modules on the client context's thread, avoiding unsafe teardown of modules such as filter-chain with LV2 plugins - Fixed autoswitch-bluetooth-profile in several scenarios: it no longer gets overridden by EnumProfile triggered profile selection, a pending profile restore is cancelled when a headset profile is applied explicitly (fixing HFP capture dying shortly after starting), and filter chains such as EasyEffects are now correctly followed to the Bluetooth loopback source - Fixed a failed node creation or an error raised in a Lua async event hook step freezing the event dispatcher, and made the v4l2 monitor advance its transition when a device is disabled - Fixed software-dsp leaking hidden parent node ids, which caused nodes created later with a reused id to be hidden from every new client - Fixed the linking policy to to bypass find-media-role-target for smart filters and to defer immediate linking for any node with a link-group, avoiding linking cycles when smart filters have media.role set - Fixed prepare-link to destroy dont-reconnect streams when their target is removed, as it was done in 0.4, instead of leaving them unlinked forever - Fixed default-nodes to rank stored nodes by their position in the stack only, so that priority.session no longer overrides the user's most recent selection - Fixed the access scripts to activate permission managers when they load, so that their permissions are ready before any client connects, instead of letting the first short-lived client see hidden devices - Fixed disabling device.restore-profile at runtime, which was still saving profiles - Fixed a use-after-free in module-settings on malformed configuration, and also the active call count in module-modem-manager on reconnect