Packages changed: 7zip (26.02 -> 26.03) AppStream (1.1.5 -> 1.2.0) ImageMagick (7.1.2.30 -> 7.1.2.31) aaa_base (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202) apparmor at-spi2-core (2.60.6 -> 2.60.7) bluez (5.82 -> 5.87) ca-certificates-mozilla (2.84 -> 2.90) crypto-policies cryptsetup (2.8.7 -> 2.8.8) freeipmi (1.6.18 -> 1.6.19) gettext-runtime glslang (16.5.0 -> 16.6.0) gnome-shell (50.4 -> 50.5) grub2 gtk2 jemalloc (5.3.1 -> 5.4.0) kdump (2.1.9 -> 2.1.10) kernel-source (7.2.5 -> 7.2.6) libadwaita (1.9.3 -> 1.9.4) libapparmor libcanberra libsoup libstorage-ng (4.5.352 -> 4.5.353) libvirt mariadb mozilla-nspr mozjs140 (140.15.0 -> 140.16.0) mutter (50.4 -> 50.5) ncurses (6.6.20260815 -> 6.6.20260912) newt nvidia-open-driver-G07-signed (595.99.02_k7.2.5_1 -> 595.99.02_k7.2.6_1) nvidia-open-driver-G07-signed-cuda (615.71.09_k7.2.5_1 -> 615.71.09_k7.2.6_1) nvme-cli (3.0+6.g1ac60ca4b -> 3.1) openSUSE-release (20260915 -> 20260919) ovmf pam pam-full-src perl-Cpanel-JSON-XS (4.440.0 -> 4.520.0) perl-GD (2.860.0 -> 2.910.0) permissions (1699_20260806 -> 1699_20260917) pipewire (1.6.8 -> 1.6.9) poppler (26.07.0 -> 26.09.0) poppler-qt6 (26.07.0 -> 26.09.0) pulseaudio-qt6 (1.8.1 -> 1.9.0) python-greenlet (3.5.5 -> 3.5.6) python-pygit2 python313 (3.13.14 -> 3.13.15) python313-core (3.13.14 -> 3.13.15) rpm ruby4.0 (4.0.6 -> 4.0.7) salt selinux-policy (20260910 -> 20260914) shaderc (2026.3 -> 2026.4) snappy (1.2.2 -> 1.3.0) spice spice-gtk sssd suitesparse (7.14.0 -> 7.14.1) timezone (2026c -> 2026d) tree-sitter vmaf (3.2.0 -> 3.2.1) xz (5.8.3 -> 5.8.4) === Details === ==== 7zip ==== Version update (26.02 -> 26.03) - Update to 26.03: * Improved support for Joliet ISO images and Compound archives. * CVE-2026-58052: 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive. - Drop obsolete suse_version < 1550 workaround, Leap 16.0 is the lowest supported target. - Spec-cleaner pass, no functional change. ==== AppStream ==== Version update (1.1.5 -> 1.2.0) Subpackages: libAppStreamQt3 libappstream5 - Update to 1.2.0 * This release marks the libappstream-compose API as stable. * This release introduces a new, lightly sandboxed (on Linux) media worker for appstream-compose and switches to VIPS for image processing. * This release introduces My headline! markup for AppStream descriptions. Older versions will remove this markup, so only use it if your target clients have a recent version of AppStream. Features: * compose: Create AscMedia for isolated out-of-process media handling using asc-mediaworker * compose: Process images, fonts & videos via the media worker * Generalize path segment validation, use it in the compose media worker * compose: Switch from using GdkPixbuf to VIPS for image processing * compose: Harmonize supported formats, don't read XPM/TIFF/BMP * compose: Make JPEG-XL the default image output format * compose: Implement basic support for FreeBSD * compose: Rely on VIPS for SVG support, drop our dedicated librsvg path * compose: Make image-targets and image batch-processing public API * compose: Expose the source-icon convention and a hint-tag lookup as public API * compose: Drop unstable-API marker * compose: Don't create image thumbnails that aren't substantially smaller * compose: Only transfer pre-opened fds and no more directory fd to the worker * compose: Implement a basic sandbox for the mediaworker using Landlock * compose: Use RESTRICT_SELF_TSYNC and block UDP access on newer Landlock * compose: Mix the output image format type into the GCID * compose: Make AscUnit a proper abstract class * compose: Improve API documentation * Always sanitize whitespaces in keywords and drop empty ones * Assume a language element without percentage means full translation * news-to-metainfo: Support a details URL in the YAML variant * news-convert: Support inline Markdown in news text * news-convert: Support headers in XML<->YAML/NEWS/Markdown conversions * ascli: news-convert: Support standalone release XML as source/target * Whitespace-sanitize all description markup we read * Output descriptions as literals in YAML and wrap markup ourselves Specification: * docs: Document the appstreamcli news file conversion helper * Implement support for headings in description markup Bugfixes: * meson: Set _POSIX_C_SOURCE on Linux only * compose: Fix a race where units were deleting each other's icon directories * compose: Fix documentation and introspection annotation issues * compose: Drop dead public API, make some API private * compose: Sharpen with libvips instead of a hand-rolled unsharp mask * compose: Only read AVIF from HEIF containers, never HEIC * compose: Fix double-free crash when processing fonts * compose: Guard against bad locale in path names * compose: Ensure component-IDs are safe to use in filesystem paths * compose: Escape values for HTML reports, and create proper plain-text if needed * compose: Make missing-launchable-desktop-file an error * Fix a few translator hints that weren't picked up properly * Don't accept empty strings as URLs * its: Fix description inline markup translation for release data * validator: Fix improper use of variadic arguments * validator: Properly validate component-IDs with random UTF-8 characters * validator: Abort ID validation after the first invalid character * pool: Resolve crash if data locations are changed on a loaded pool * Fix wrong string comparison when detecting arm64 machines * ascli: Resolve crash when selection is cancelled in install/remove * Fix another crash when converting invalid description markup to Markdown * apt: Treat icon tarballs as hostile, instead of trusted * apt: Fix empty-directory check nuking the icon cache on every refresh * utils: Ensure we never ever follow symlinks when recursively deleting caches * xml: Only emit description enumerations for locales that are in them * cache: Never infinite-recurse when resolving addons for a component * yaml: Don't leave old header data around when parsing multiple YAML catalogs Miscellaneous: * compose: Stop leaking private symbols out of the shared library ... changelog too long, skipping 22 lines ... * ascli: Guard against bad bundle values when calling "install" ==== ImageMagick ==== Version update (7.1.2.30 -> 7.1.2.31) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - version update to 7.1.2.31 * fix: use registered UHDR module name in policy check #8935 * Also create an SBOM for the portable builds. 482ae0e * Corrected file names. c3d83c6 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c 8f62023 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm 5904641 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r868-pmwh-fv2c 768bdd0 * Added missing include and corrected the module name. 07143f6 * Added missing coders. 7e99fb4 * Fixed the policy check for coders (GHSA-vcjj-32hg-qpx5) 82f373f * More fixes for GHSA-vcjj-32hg-qpx5. dcdbbf4 * Corrected the call to CheckPrimitiveExtent to fix the use of uninitialized heap memory (GHSA-6xf5-c3jx-rp39) 5d29c09 * Moved EscapeParenthesis to the ghostscript-private.h header file. e2bd884 * Escape the labels to prevent code injection (GHSA-5rg6-j44q-q892) 78378cd * Added missing define checks bd96dda * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92 c69f54e * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2w4h-697j-4vrm 86672a1 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62 c311471 * Added missing include. 5ccfb2f * Added missing check for eof when using the custom stream reader in ReadBlob 78aff3a * Use a better algorithm to determine the numerator and denominator (GHSA-v45j-x8p4-3mh4) f491576 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v d779ac5 * initial framework for the c2pa coder b34352d * add header 9f2cb10 * add c2pa coder framework a4d1d62 * eliminate compiler warnings a37640f * Removed unused argument 0e94ad4 * Added missing null check to avoid a null pointer dereference (GHSA-92rw-c5mw-27v4) c4b3c90 * https://github.com/ImageMagick/ImageMagick/issues/8927 c717095 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67 282f455 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67 4fe3110 * framework for c2pa coder 7d25548 * add new exception for required manifest b14e552 * add C2PA define 837ec6f * include static header 03a79c3 * cosmetic beeb133 * c2pa decode poc 114618e * https://github.com/ImageMagick/ImageMagick/issues/8930 a96821a * https://github.com/ImageMagick/ImageMagick/issues/8930 c42d72d * create symbolic link only if input file exists d4f900a * correct c2pa delegate de7f30c * More fixes for GHSA-89wq-f8f6-2j2v b5da5ea * Updated the dependencies. 5f49dfb * More fixes for GHSA-5rg6-j44q-q892. 2ba2edf * for now, limit c2pa support to decoding only 977a278 * eliminate compile exception f557204 * eliminate compiler exception a92f423 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jvjm-9f73-fhpq 8f3a15e * latest autoconf update 8cab7be * check >= limit 404450e * extra check not needed 32bbfb1 * revert e18959a * Removed unused code. ad464d1 * Trim labels to prevent code injection (GHSA-p6j5-2qwh-6486) 8309dc9 - modified patches * ImageMagick-library-installable-in-parallel.patch (refreshed) ==== aaa_base ==== Version update (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202) Subpackages: aaa_base-extras - Update to version 84.87+git20260916.e122202: * For new GNU Emacs 31.1: use lexical-binding * Let us now fix this syntax error in ls.bash - Update to version 84.87+git20260812.c6d42af: * added requires for gzip and tar to aaa_base-extras (boo#1274604) * fix(ls): deprecate ls.zsh * fix(ls.bash): use alias, func breaks sudo alias * fix(ls.bash): avoid breaking sudo alias expansion * drop dirs from the specfile, they live in the filesystem package ==== apparmor ==== Subpackages: apparmor-abstractions apparmor-docs apparmor-parser apparmor-profiles apparmor-utils python3-apparmor - update wg-quick.diff to fix setting DNS (boo#1265394) ==== at-spi2-core ==== Version update (2.60.6 -> 2.60.7) Subpackages: libatk-1_0-0 libatk-bridge-2_0-0 libatspi0 typelib-1_0-Atk-1_0 typelib-1_0-Atspi-2_0 - Update to version 2.60.7: + libatspi: Fix transfer annotation on atspi_document_get_text_selections. + atk-bridge: Release disconnected direct connections. ==== bluez ==== Version update (5.82 -> 5.87) Subpackages: bluez-auto-enable-devices bluez-cups bluez-obexd bluez-zsh-completion libbluetooth3 - ver 5.87: * Patches removed: hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) hcidump-Fixed-malformed-segment-frame-length.patch (Source file does not exist anymore) bluez-mainloop-Only-connect-to-NOTIFY_SOCKET-if-STATUS-Sta.patch (included in upstream) CVE-2016-9800-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) CVE-2016-9804-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) upstream changes: Fix issue with GATT database and out of sync errors. Fix issue with BASS and setting a stream to idle. Fix issue with BASS and rescanning broadcast sources. Fix issue with BAP and broadcast sink cleanup. Fix issue with BAP and endpoint configuration. Fix issue with BAP and ASE control point properties. Fix issue with BAP and BIG/BIS receiver QoS structures. Fix issue with AVRCP and tracking of TG and CT events. Fix issue with PBAP and Database Identifier length. Fix issue with MCP and ATT disconnect events. ver 5.86: Fix issue with number of retries on authentication failures. Fix issue with G.722 @ 16 kHz codec ID value reported by transport. Add support for Telephony interface. Add support for Ranging profile. Add support for GMAP service. Add support for TMAP service. ver 5.85: Fix issue with handling display of battery charge level. Fix issue with BASS permissions not requiring encryption. Fix issue with handling abort for OBEX SRM operation. Fix issue with handling device privacy. Add support for HFP call answer support. Add support for HFP simple 3-way call support. ver 5.84: Fix issue with AVRCP and handling invalid UTF-8 item name. Fix issue with exposing coordinate sets if LE Audio is disabled. Fix issue with BAP and not responding to SetConfiguration. Add support for BAP unicast endpoint reconfiguration. Add support for BASS and encrypted broadcast source. Add support for HFP and Call Line Identification. ver 5.83: Fix issue with handling BAP and removal of PAC. Fix issue with handling SID for broadcast receiver. Fix issue with handling HSP/HFP reconnection policy. Fix issue with handling cable pairing and Sixaxis controllers. Fix issue with handling virtual cable unplug for HID devices. Fix issue with handling service records for HID devices. Add support for AVDTP and TX timestamps. ==== ca-certificates-mozilla ==== Version update (2.84 -> 2.90) - Updated to 2.90 state (bsc#1279961) - Removed: - AffirmTrust Commercial - AffirmTrust Networking - AffirmTrust Premium - AffirmTrust Premium ECC - certSIGN ROOT CA - Entrust Root Certification Authority - PKI Root Certification Authority - FIRMAPROFESIONAL CA ROOT-A WEB - GLOBALTRUST 2020 - Secure Global CA - SecureSign Root CA12 - SecureTrust CA - TeliaSonera Root CA v1 - Trustwave Global Certification Authority - Trustwave Global ECC P256 Certification Authority - Trustwave Global ECC P384 Certification Authority - XRamp Global Certification Authority - Added: - SECOM SMIME RSA Root CA 2024 - SECOM TLS ECC Root CA 2024 - SECOM TLS RSA Root CA 2024 - SecureSign Root CA16 - Telia EC Email Root CA v3 - Telia EC TLS Root CA v3 - Telia RSA Email Root CA v3 - Telia RSA TLS Root CA v3 ==== crypto-policies ==== Subpackages: crypto-policies-scripts - Add configure-python-interpreter.patch removing dependency on `python3-base`, all Python scripts are now dependent on the primary Python interpreter directly without `/usr/bin/python3` mediation. ==== cryptsetup ==== Version update (2.8.7 -> 2.8.8) Subpackages: cryptsetup-doc libcryptsetup12 - Update to 2.8.8: * integritysetup: add support for keyed discards. An integrity device in standalone mode, with a keyed integrity algorithm like HMAC and enabled discards (TRIM), could be vulnerable to wiping part of the device using a discard pattern. This issue can be worked around by using a keyed discards filler. Once set, it is set permanently for the integrity device and cannot be reverted. Integritysetup now supports a new --allow-discards-keyed option. Once used, it will upgrade the superblock and activate keyed discards. After the upgrade, keyed discards are always used, even with the old --allow-discards option. Keyed discard is available since Linux kernel 7.3. Note: Integritysetup was intended to be used with non-cryptographic integrity protection only. If you need cryptographic protection, use LUKS2 and AEAD (discards are not supported). * Avoid time-of-check/time-of-use (TOCTOU) issue in LUKS header restore. The LUKS header restore function validates the provided header file and then reopens the same file path to restore the LUKS header. In a specifically crafted environment, a symlink flip could occur between validating and restoring the header, resulting in a different file being used for the LUKS header restore (potentially leaking the file content). The libcryptsetup now opens the device only once. The issue affects both LUKS1 and LUKS2. Note: LUKS header backup/restore is a system administrative task (similar to filesystem backup/restore) that must run in a secure environment. Such a backup is usually a multi-step process, and it is up to the caller to ensure security of that environment. * BITLK: harden metadata validation. If a crafted BITLK (BitLocker-compatible) image is opened, the allocated buffer size for the key can be incorrect. This can happen if the encryption is changed from AES-CBC-128 to a mode with an Elephant diffuser, without recalculating the stored key. Also, the data offset can be intentionally wrong, which could lead to an infinite loop when parsing metadata. Note that creating such an incorrect image requires knowledge of the disk password, as MAC protects the metadata, and this MAC is checked by cryptsetup. * Fix possible integer overflow in LUKS metadata parsing. On systems with a 32-bit integer size, the anti-forensic (AF) data size calculation could overflow, causing an application crash. * cryptsetup: fix local memory corruption bug in reencrypt init. If a device intended for reencryption contains more than 16 active LUKS2 keyslots or tokens, the reencryption initialization could corrupt internal memory, leading to an application crash. ==== freeipmi ==== Version update (1.6.18 -> 1.6.19) - Update to version 1.6.19 and fix: * bsc#1278719 - CVE-2026-85504 stack-based buffer overflow via malformed Fujitsu SEL long-text responses. * bsc#1278721 CVE-2026-85506 Arbitrary code execution via stack-based buffer overflow in ipmi-oem * bsc#1278722 CVE-2026-85505 Denial of Service via stack-based buffer over-read in ipmi-oem * bsc#1278724 CVE-2026-85507 stack-based buffer overflow in _output_dell_system_info_cmc_info * bsc#1278726 CVE-2026-85508 stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info * bsc#1278727 CVE-2026-85509 stack-based buffer overflow when a BMC returns more bytes than requested ==== gettext-runtime ==== Subpackages: envsubst libtextstyle0 - Fix for automake1.19: Update patch 0001-msgcat-Add-feature-to-use-the-newest-po-file.patch with Makefile.in so the build doesn't try to regenerate this file with automake-1.18 ==== glslang ==== Version update (16.5.0 -> 16.6.0) - Update to release 16.6.0 * Implemented `GL_EXT_cooperative_matrix_maintenance1`, `GL_EXT_optional_input_attachment_index`, and `DebugEntryPoint` for `NonSemantic.Shader.DebugInfo` 102. ==== gnome-shell ==== Version update (50.4 -> 50.5) Subpackages: gnome-extensions gnome-shell-calendar - Update to version 50.5: + Fix keynav on unlock dialog + Fix glitch when switching workspaces with direct scanout + Support building with libical4 + Refuse to unlock screen after screen time limit was reached + Fix blocking when toggling wireless toggle + Don't show busy cursor when activating actions + Fix glitch when cancelling lock screen prompt with Esc + Track magnifier mouse position without polling + Limit parallel texture loading operations + Open windows created via new-window action on correct workspace + Don't duplicate locale keyboard layout + Cancel mount password dialogs when locking screen + Validate serialized image data before creating pixbuf + Fixed crash + Plugged leaks + Misc. bug fixes and cleanups + Updated translations. ==== grub2 ==== Subpackages: grub2-arm64-efi grub2-arm64-efi-bls grub2-common grub2-snapper-plugin grub2-systemd-sleep-plugin - Add SBAT Provides to support shim SBAT dependency checks (bsc#1278729) ==== gtk2 ==== Subpackages: gtk2-data gtk2-tools libgtk-2_0-0 - Rebase automake-1.17.patch to allow usage of automake-1.19.x. ==== jemalloc ==== Version update (5.3.1 -> 5.4.0) - Update to release 5.4.0 * Added `EXTENT_ALLOC_FLAG_PINNED` so custom extent-allocation hooks can mark non-reclaimable mappings, such as HugeTLB pages, for preferential reuse outside the decay and purge pipeline. * Allow resuming per-CPU arena selection via thread.arena. * Replace the runtime `experimental_infallible_new` option with the compile-time `--enable-cxx-infallible-new` option. * `errno` is preserved now across `free`, `free_sized`, `free_aligned_sized`, and across `process_madvise`-based page purging. * Accept NULL in `free_sized()` and `free_aligned_sized()` (C23 correctness). ==== kdump ==== Version update (2.1.9 -> 2.1.10) - upgrade to version 2.1.10 * calibrate: measure per-cpu requirements * kdumptool calibrate: take KDUMP_CPUS into account for PPC * PPC: round up KDUMP_CPUS on SMT systems to nearest threads-per-cpu * Set default KDUMP_CPUs to 4 (jsc#PED-16732, bsc#1239999) * add KDUMP_USE_CMA: experimental support for CMA reservation (jsc#PED-14553) - update calibrate values ==== kernel-source ==== Version update (7.2.5 -> 7.2.6) Subpackages: kernel-64kb kernel-default - RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables (git-fixes). - commit 3d19f11 - Update patches.kernel.org/7.2.4-160-nfsd-add-fh_want_write-for-early-verified-SETAT.patch (bsc#1012628 CVE-2026-89697 bsc#1280148). - Update patches.kernel.org/7.2.4-163-nfsd-block-non-SAVEFH-ops-after-FOREIGN-PUTFH-t.patch (bsc#1012628 CVE-2026-89696 bsc#1280146). - Update patches.kernel.org/7.2.4-164-nfsd-cap-decoded-POSIX-ACL-count-to-bound-sort-.patch (bsc#1012628 CVE-2026-89695 bsc#1280155). - Update patches.kernel.org/7.2.4-165-nfsd-check-client-ownership-when-cancelling-a-c.patch (bsc#1012628 CVE-2026-89694 bsc#1280151). - Update patches.kernel.org/7.2.4-166-nfsd-check-nfsd4_acl_to_attr-return-value-in-nf.patch (bsc#1012628 CVE-2026-89693 bsc#1280153). - Update patches.kernel.org/7.2.4-167-nfsd-clear-CALLBACK_RUNNING-on-failed-delegatio.patch (bsc#1012628 CVE-2026-89692 bsc#1280167). - Update patches.kernel.org/7.2.4-168-nfsd-clear-opcnt-on-compound-arg-release-to-pre.patch (bsc#1012628 CVE-2026-89691 bsc#1280163). - Update patches.kernel.org/7.2.4-172-nfsd-defer-vfree-of-compound-ops-to-fix-rpc_sta.patch (bsc#1012628 CVE-2026-89690 bsc#1280166). - Update patches.kernel.org/7.2.4-173-nfsd-don-t-free-session-slots-that-are-still-in.patch (bsc#1012628 CVE-2026-89689 bsc#1280174). - Update patches.kernel.org/7.2.4-174-nfsd-drop-the-stateid-not-the-stateowner-on-seq.patch (bsc#1012628 CVE-2026-89688 bsc#1280171). - Update patches.kernel.org/7.2.4-175-nfsd-ensure-nfsd_file_do_acquire-does-not-use-a.patch (bsc#1012628 CVE-2026-89687 bsc#1280173). - Update patches.kernel.org/7.2.4-176-nfsd-fix-BUG_ON-in-nfsd4_alloc_layout_stateid-o.patch (bsc#1012628 CVE-2026-89686 bsc#1280184). - Update patches.kernel.org/7.2.4-177-nfsd-fix-clock-domain-mismatch-in-clients_still.patch (bsc#1012628 CVE-2026-89685 bsc#1280179). - Update patches.kernel.org/7.2.4-178-nfsd-fix-cpntf-publish-race-in-nfs4_init_cp_sta.patch (bsc#1012628 CVE-2026-89684 bsc#1280178). - Update patches.kernel.org/7.2.4-179-nfsd-fix-dentry-ref-leak-on-V4ROOT-export-fileh.patch (bsc#1012628 CVE-2026-89683 bsc#1280193). - Update patches.kernel.org/7.2.4-180-nfsd-fix-fcache_disposal-UAF-by-inlining-dispos.patch (bsc#1012628 CVE-2026-89682 bsc#1280191). - Update patches.kernel.org/7.2.4-182-nfsd-fix-layout-fence-worker-double-reference-r.patch (bsc#1012628 CVE-2026-89681 bsc#1280189). - Update patches.kernel.org/7.2.4-184-nfsd-fix-nfsd_file-leak-on-inter-server-COPY-se.patch (bsc#1012628 CVE-2026-89680 bsc#1280206). - Update patches.kernel.org/7.2.4-185-nfsd-fix-null-dereference-in-nfsd4_setattr-for-.patch (bsc#1012628 CVE-2026-89679 bsc#1280203). - Update patches.kernel.org/7.2.4-186-nfsd-fix-partial-write-detection-in-nfsd_direct.patch (bsc#1012628 CVE-2026-89678 bsc#1280199). - Update patches.kernel.org/7.2.4-187-nfsd-fix-possible-fh_compose-of-wrong-dentry-in.patch (bsc#1012628 CVE-2026-89677 bsc#1280224). - Update patches.kernel.org/7.2.4-190-nfsd-fix-stale-s2s_cp_stateids-IDR-entry-for-as.patch (bsc#1012628 CVE-2026-89676 bsc#1280219). - Update patches.kernel.org/7.2.4-191-nfsd-fix-UAF-in-async-copy-cancel-and-shutdown.patch (bsc#1012628 CVE-2026-89675 bsc#1280216). - Update patches.kernel.org/7.2.4-193-nfsd-fix-XDR-length-calculation-in-nfsd4_ff_enc.patch (bsc#1012628 CVE-2026-89674 bsc#1280243). - Update patches.kernel.org/7.2.4-194-nfsd-fix-XDR-padding-calculation-in-ff_encode_g.patch (bsc#1012628 CVE-2026-89673 bsc#1280237). - Update patches.kernel.org/7.2.4-195-nfsd-gate-nfs2-setacl-by-argp-mask.patch (bsc#1012628 CVE-2026-89672 bsc#1280235). - Update patches.kernel.org/7.2.4-196-nfsd-gate-nfs3-setacl-by-argp-mask.patch (bsc#1012628 CVE-2026-89671 bsc#1280252). - Update patches.kernel.org/7.2.4-197-nfsd-hold-rcu-across-localio-cmpxchg-retry.patch (bsc#1012628 CVE-2026-89670 bsc#1280250). - Update patches.kernel.org/7.2.4-198-nfsd-initialize-copy-notify-stateid-before-publ.patch (bsc#1012628 CVE-2026-89669 bsc#1280251). - Update patches.kernel.org/7.2.4-200-nfsd-move-nfsd_debugfs_init-after-nfsd4_init_sl.patch (bsc#1012628 CVE-2026-89668 bsc#1280279). - Update patches.kernel.org/7.2.4-201-nfsd-close-shrinker-GC-fsnotify-vs-per-net-shut.patch (bsc#1012628 CVE-2026-89667 bsc#1280261). - Update patches.kernel.org/7.2.4-205-nfsd-release-OPEN-decoded-posix-ACLs-via-op_rel.patch (bsc#1012628 CVE-2026-89664 bsc#1280272). ... changelog too long, skipping 3681 lines ... - commit 16c1085 ==== libadwaita ==== Version update (1.9.3 -> 1.9.4) Subpackages: libadwaita-1-0 typelib-1_0-Adw-1 - Update to version 1.9.4: + AdwAnimation: Fix AdwCallbackAnimationTarget annotations + AdwActionRow: Ensure :use-markup property is set in constructed() + AdwTabBar/AdwTabGrid: Clear a dangling idle callback in dispose ==== libapparmor ==== - update wg-quick.diff to fix setting DNS (boo#1265394) ==== libcanberra ==== Subpackages: canberra-gtk-play libcanberra-gtk-module-common libcanberra-gtk0 libcanberra-gtk2-module libcanberra-gtk3-0 libcanberra-gtk3-module libcanberra0 - Migrate to xz compression and manual service run ==== libsoup ==== Subpackages: libsoup-3_0-0 typelib-1_0-Soup-3_0 - Add libsoup-CVE-2026-85534.patch: Never send more body bytes than nghttp2 requested (bsc#1279239, CVE-2026-85534) - Add libsoup-CVE-2026-85197.patch: fix crash in on_data_read after connection has been destroyed (bsc#1279238, CVE-2026-85197) ==== libstorage-ng ==== Version update (4.5.352 -> 4.5.353) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - Translated using Weblate (Danish) (bsc#1149754) - 4.5.353 ==== libvirt ==== Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - qemu: Fix missing audit record and shutdown lifecycle event of VMs with shutdown times exceeding 40 seconds bsc#1280884 - qemu: Fix hot plugged host CPUs not being used bsc#1279562 ==== mariadb ==== Subpackages: libmariadbd19 mariadb-client mariadb-errormessages - Ignore multiple perfschema.* tests on armv7 ==== mozilla-nspr ==== - Add Make-x86-assembly-files-compatible-with-SHSTK-IBT.patch to support -fcf-protection in assembly sources. ==== mozjs140 ==== Version update (140.15.0 -> 140.16.0) - Update to version 140.16.0: + See https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/ ==== mutter ==== Version update (50.4 -> 50.5) - Update to version 50.5: + Make software cursor overlay visibility per-view + Fix multiple monitors being reported as primary + Fix desaturated SDR content in HDR mode + Fix offscreen effect glitches on resource scale changes + Fix hang on external monitor hotplug + Fix direct scanout handling for captures without dma-buf + Prevent modifier release from stopping key repeat + Do not require EDID to generate device color profile + Handle cross GPU buffer scanout + Fix listing all supported fallback resolutions + Fixed crashes + Plugged leaks + Updated translations. ==== ncurses ==== Version update (6.6.20260815 -> 6.6.20260912) Subpackages: libncurses6 ncurses-utils terminfo terminfo-base terminfo-iterm terminfo-screen - Work around common name in certificate of www.invisible-island.net - Add ncurses patch 20260912 + build-fix for sizeof(mmask_t) configure check (cf:20260829). + review/fix teraterm* (report by Jakub Horky) + modify flash for vt525 to use DECRARA (patch by Branden Robinson) + update config.guess, config.sub - Add ncurses patch 20260905 + modify endwin() and doupdate() to save/restore keypad and meta modes (report by Ferenc Wagner). + improve range-checks for xterm X10 and SGR mouse protocol. + correct modifier-masking for buttons 6-11 in mouse version 3 (report by Ravi Arnan Irianto). + build-fix for Ada95 with ABI 7 (report by Branden Robinson) - Add ncurses patch 20260829 + add configure check to ensure that mmask_t is large enough for the configured mouse version (report by Ravi Arnan Irianto) + add mouse-parsing for extended buttons with mouse version 3 (report by Ravi Arnan Irianto). - Add ncurses patch 20260822 + add a limit-check in wborder (patch by Bjoern Foersterling). + improve limit-checks for trace calls in read_entry.c (report by Yeo JooHo). + improve tic warnings regarding the empty smir/rmir strings which may be added in dump_entry.c for termcap if ich/ich1 are present but smir/rmir are not. + add sun+fkeys -TD + add dtterm-sk, dtterm+sk -TD + add ich1 to several entries, providing for support of non-curses applications via termcap only -TD + add dch/dch1 to rxvt-basic -TD + drop redundant xterm=setaf2 (patch by Branden Robinson) + documentation improvements (patches by Branden Robinson). + improve color discussion in man pages + improve formatting/style of man pages > improve wide-character support with UCRT (patches by Liu Hao) + use UCRT's wcrtomb rather than _nc_wctomb + skip trailing cells of double-width characters ==== newt ==== - Use %python3_version instead of the obsolete %py3_ver. ==== nvidia-open-driver-G07-signed ==== Version update (595.99.02_k7.2.5_1 -> 595.99.02_k7.2.6_1) Subpackages: nvidia-open-driver-G07-signed-kmp-64kb nvidia-open-driver-G07-signed-kmp-default - fixed build on SLE16.1 ==== nvidia-open-driver-G07-signed-cuda ==== Version update (615.71.09_k7.2.5_1 -> 615.71.09_k7.2.6_1) Subpackages: nvidia-open-driver-G07-signed-cuda-kmp-64kb nvidia-open-driver-G07-signed-cuda-kmp-default - fixed build on SLE16.1 ==== nvme-cli ==== Version update (3.0+6.g1ac60ca4b -> 3.1) Subpackages: libnvme3-1 nvme-cli-bash-completion nvme-cli-zsh-completion - Update to version 3.1: * Release v3.1 * doc: Regenerate all docs for v3.1 * tests: NUL-terminate literals copied into dc_entry_is_self() test data * plugin: fix out-of-bounds read of argv[1] in help() with no sub-argument * libnvme: fix NBFT entry list leak in libnvmf_discover_nbft() * huawei: guard against a null list_items in huawei_json_print_list_items() * solidigm: also guard against a null ilog in ilog_dump_identify_page() * plugins/sandisk: fix uninitialized market_name_len in enc_drive_capabilities * plugins/exclusion: fix errno reliance in read_file() * plugins/sandisk: update version * plugins/sandisk: use nvme_get_pci_ids * plugins/sandisk: port vs-smart-add-log from wdc * libnvme: reject a persona hostnqn with no hostid * shared: drop the retry loop from shr_read_file()/shr_read_file_as_string() * shared: return error codes from shr_read_file() and shr_read_file_as_string() * tests: bound the interface name copy in mock-ifaddrs init_entry() * wdc: use shr_getrandom() for the send/receive correlation handle * rpmb: use shr_getrandom() for the authentication nonce * keys: check chmod() return value in append_keyfile() * shared: add shr_getrandom() * solidigm: fix NULL DMA target in ilog_dump_pel() * tests: fix unit mismatch in test_admin_fw_download_cb's data check * innogrit: remove dead fclose() guards before the first fopen() in getcdump * solidigm: fix unreachable error-recovery path in parse_tracker_chunk_json() * nvme: fix nvme_decide_retry() always returning false * nbft: fix truncated PCI segment number in pci_sbdf_to_string() * ocp: check ocp_get_uuid_index() before issuing the get-log command * tests,tree-fabrics: check and acknowledge return values * mi-mctp: fix endian conversion direction for MPR retry time * fs-util: restore path separator unconditionally in shr_mkdir_p() * tests: check write() return value in test_read_all() * wdc: bound the device-reported Capture Diagnostics log length * solidigm: replace read_file2buffer() with shared file-reading helpers * sandisk: fix 32-bit overflow and unchecked realloc in sndk_do_cap_udui * mi-mctp-ae: bound the AE number before indexing the enabled-events map * shared: use memmove() for the sha256 intra-buffer carry-over copy * fabrics: fix NULL dereference in dc_log_decision() * netapp: fix NULL format string in netapp_smdevices_print_regular() * tests: fix NULL dereference in mi-mctp aem_handler() * ocp: fix NULL dereference and zero-fill bug in parse_event_fifo() * nvme-print: bound-check FDP config descriptor walk against log size * nvme-print: fix endian bugs and bound the EOM descriptor walk * nvme-print: fix integer overflow in EOM descriptor offset * shared: add shr_buf_has_room() * tests: fix dangling pointer in test_nvmf_sanitize_addrs() * tests: use shr_read_file_as_string() in shr_table tests * tests: fix uninitialized buffer and NULL %s in check_normalize() * shared: add shr_read_file_as_string() * scaleflux: fix scandir(3) result leak in nvme_expand_cap * wdc: fix out-of-bounds read of pre-v4 cloud smart log hardware revision * nvme-print,fabrics: fix uninitialized reads * utils: fix allocation leak in copy_options() * shannon: fix file descriptor leak in set_additional_feature() * rpmb: validate config block size before write * discoverd: honor persistent=force against EPCSD=0 * resv-plugin: size the resv report from the registrant count * ccan: cast pointers to void * in fprintf for %p format specifier * libnvme: pick the right self entry on a multi-homed DC * discoverd: use __cleanup_tid in two loops * sandisk: fix stack buffer overflow in C2 marketing-name parser * discoverd: validate DLPE target before host-side inheritance * nvme-models: fix pci.ids parser line loss * tests: check errno after rewind in capture helpers * huawei: null-check root/devices in huawei_json_print_list_items * solidigm: guard ilog->cfg dereference in ilog_dump_identify_page * libnvme: initialize TLS key IDs * exclusion: preserve errno across free/fclose in read_file * nvme-print-json: fix leaks in json_phy_rx_eom_descs * wdc: close output file via __cleanup_file in wdc_enc_get_log * lm: fix double fclose in lm_migration_send * completions: document no-trailing-space insertion checks in TESTING.md * completions: test the generator against a synthetic fixture * nvme-print-json: use CAP property fields string table * nvme-print: add CAP property fields string table * nvme-print-json: combine obj_add_str and obj_add_string duplicated * nvme-print: change string variables as constant * nvme-print-json: fix to output alloc_error * nvme-print-stdout: use libnvme API to print CAP property * nvme-types-base: fix CAP property NSSRS bit name * nvme-types-base: add CAP property NSSES bit * nvme-types-base: change file header description NVMe revision to 2.4 * micron: clamp num_entries in vs-fw-activate-history to the table size * seagate: clamp supported-log-pages count and keep JSON clean * libnvme: add test for var_size_tags 32B guard sts range * tests: cover invalid_tags() STS-too-wide rejection * libnvme: fix undefined shifts in nvme_init_var_size_tags() 32B guard case * nvme: reject out-of-range storage tag size in invalid_tags() * shared: drop dead `at_line_start = true` in shr_print_word_wrapped() * solidigm: drop dead initializer in telemetry_log_data_area_get_offset() * solidigm: report failure restoring workload-tracker config * huawei: check libnvme_get_nsid() failure in huawei_get_nvme_info() * micron: drop dead `err = 0` in micron_telemetry_log() * ocp: fix empty-description case in parse_ocp_telemetry_string_log() * ocp: drop dead m_512_sz/m_512_off initial stores in get_telemetry_dump() * sandisk: drop dead stores flagged by clang-analyze * sandisk: fix telemetry write error handling, drop a dead store * wdc: fix telemetry write error handling, drop dead stores * huawei: skip a list entry if its JSON object fails to allocate ... changelog too long, skipping 47 lines ... * feat: add remaining feature commands ==== openSUSE-release ==== Version update (20260915 -> 20260919) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== ovmf ==== Subpackages: qemu-uefi-aarch64 - Remove DEBUG_TO_MEM build option for AArch64 (bsc#1272814) - The option causes softdog reboot failures on AArch64, so keep it only for the x86_64 builds. ==== pam ==== - Apply livepatching only for SLES, not for Factory. Keeping lto optimisation for openSUSE. * On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS. - Make sure we don't lose distribution compiler flags. ==== pam-full-src ==== Subpackages: pam-extra pam-manpages - Apply livepatching only for SLES, not for Factory. Keeping lto optimisation for openSUSE. * On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS. - Make sure we don't lose distribution compiler flags. ==== perl-Cpanel-JSON-XS ==== Version update (4.440.0 -> 4.520.0) - updated to 4.520.0 (4.52) see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes 4.52 2026-09-12 (rurban) - OSX 10.9 fix for SIMD UTF-8 (Christian Carey) - Change my maintainer email to reini.urban@gmail.com 4.51 2026-09-11 (rurban) - Add faster SIMD UTF-8 validation (GH #213, Zhang Boyang) https://github.com/cyb70289/utf8, MIT. - Fix tests for yath (GH #255, with H.Merijn Brand): the test files now work with Test2::Harness instead of only Test::Harness, and a yath run is added to `make xtest` when yath is installed. - Skip one t/117_numbers.t test on Perls with 32-bit IVs (GH #254, Jeremy Hansen). 4.50 2026-09-08 (rurban) - Add $json->encode_to($fh, $data, [$type]) to stream encoded JSON directly to a filehandle instead of building the whole result in memory (GH #250, requested by yairlenga. designed 2016 in GH #58). Internally flushes a bounded 8k chunk buffer as it fills, keeping peak memory bounded for large data structures. - Encoder performance improvements suggested in GH #237 (17dec): * Large-integer encoding now uses a 100-digit lookup table instead of snprintf, roughly 2x faster for integers outside the existing branchless small-integer fast path (|value| > 59000). * encode_str now bulk-copies runs of consecutive bytes that need no escaping instead of a need()+store per byte, notably faster for strings with few or no characters to escape. Added eg/bench_large.pl with results. ==== perl-GD ==== Version update (2.860.0 -> 2.910.0) - updated to 2.910.0 (2.91) see /usr/share/doc/packages/perl-GD/ChangeLog 2.91 * t/affine.t: compare affineInvert(scale(2,3))'s result with an epsilon (1e-6) instead of exact is_deeply, since -Duselongdouble perls compute the division in extended precision, giving a last-few-ULP-different 1/3 than a plain double (GH #68). * Bumped $VERSION in GD::Image, GD::Image_pm.PL and GD::Polygon to 2.91, in sync with GD.pm; these were left un-bumped in 2.90. 2.90 * Add JXL, UHDR support for new libgd-2.4.0 (from git) - JXL: newFromJxl/newFromJxlData readers, jxl() writer (lossless/distance/effort), magic-byte autodetection in new(). - UHDR: new GD::UHDR class (newFromFile/newFromData, width/height/ hasGainMap, resize/crop/rotate/mirror, file/write, getSdr). - Work around libgd 2.4.0 gd.h no longer declaring gdImageBoundsSafe(). * IMAGEQUANT: trueColorToPaletteSetMethod/SetQuality and the GD_QUANT_* constants for the libimagequant-backed quantizer. Guard for installations without libimagequant. Fix imagequant feature autodetection in Makefile.PL (libimagequant surfaces in gdlib.pc's Libs.private, not Requires.private). * Embed rpath (Linux) and fix stale blib/lib/GD/Image.pm so 'make test' reliably exercises the just-configured libgd (GH #21 test infra); fix GD_LIQ detection from the deprecated gdlib-config script. * Add Affine transformations (GH #21): GD::Image affine matrix builders (affineIdentity/Scale/Rotate/ShearHorizontal/ ShearVertical/Translate/Concat/Invert/Flip/Expansion/ Rectilinear/Equal/ApplyToPoint) and transformAffineGetImage/ transformAffineCopy/transformAffineBoundingBox, wrapping gdAffine*/gdTransformAffine* (libgd >= 2.1.0). Fix GD_AFFINE_* constant visibility (same enum/#ifdef issue as GD_QUANT_*). * Add more previously-unbound libgd methods (libgd >= 2.1.0 unless noted): paletteToTrueColor, crop, cropAuto, cropThreshold, colorReplace, colorReplaceArray, colorReplaceThreshold, convolution, resolution; cloneImage, getTrueColorPixel, perceptualDiff (libgd >= 2.4.0). clone() now uses the native gdImageClone() when available, fixing truecolor-ness loss on the old new()+copy() fallback. Fix GD_CROP_* constant visibility (same enum/#ifdef issue as GD_QUANT_*). * Animated WebP support (libgd >= 2.4.0): new GD::WebpAnimWriter (new/addImage/finish, wrapping gdWebpWriteOpenPtr/AddImage/ PtrFinish) and GD::WebpAnimReader (newFromData/info/nextImage, wrapping gdWebpReadOpenCtx/GetInfo/NextImage) classes. * Animated/multi-image JXL support (libgd >= 2.4.0): new GD::JxlAnimWriter (new/addImage/finish, wrapping gdJxlWriteOpenPtr/AddImage/PtrFinish) and GD::JxlAnimReader (newFromData/info/nextImage, wrapping gdJxlReadOpenCtx/ GetInfo/NextImage) classes, mirroring GD::WebpAnimReader/Writer. * Multi-page TIFF support (libgd >= 2.4.0): new GD::TiffMultiWriter (new/addImage/finish, wrapping gdTiffWriteOpenPtr/AddImage/PtrFinish) and GD::TiffMultiReader (newFromData/info/nextImage, wrapping gdTiffReadOpenCtx/ GetInfo/NextImage) classes, mirroring GD::WebpAnimReader/Writer (pages have no per-page delay; nextImage() returns a page-info hashref instead). Also adds the GD_TIFF_* writer option constants (colorspace, compression, resolution unit, alpha type). * Per-format header introspection (libgd >= 2.4.0): new GD::Image->pngInfoData/jpegInfoData/gifInfoData/bmpInfoData/ avifInfoData/heifInfoData class methods, wrapping gd{Png,Jpeg,Gif,Bmp,Avif,Heif}GetInfoCtx. Each reads just the container facts (dimensions, bit depth, and similar) from an in-memory buffer without fully decoding the image. * Fixed a longstanding bug in the in-memory gdIOCtx used by every newFrom*Data()/*InfoData() method: its getC() callback never advanced the read position, so any decoder reading a buffer byte-by-byte (as the new bmpInfoData()'s BMP header parser does) would spin re-reading the first byte forever. PNG, JPEG, GIF, WebP, TIFF, JXL, AVIF and HEIF decoding were unaffected because they read through the bulk getBuf() callback instead, which was already correct. * Worked around inconsistent success/failure return conventions across libgd's new Get*InfoCtx functions: gdPngGetInfoCtx, gdJpegGetInfoCtx, gdAvifGetInfoCtx and gdHeifGetInfoCtx all return 0 on success despite two of their own header comments claiming the opposite, while gdGifGetInfoCtx and gdBmpGetInfoCtx return 1 on success as documented. 2.87 * fix OpenBSD support (Alexander Bluhm, PR #63) * fix $image->compare() usages (Alexander Bluhm, PR #65, #64) * fix tiff test without libimagequant (Alexander Bluhm, PR #66) ==== permissions ==== Version update (1699_20260806 -> 1699_20260917) Subpackages: permctl permissions-config - Update to version 1699_20260917: * profiles: added CAP_PERFMON for ksystemstats_xe_helper (bsc#1280113) * profiles: document nvidia-modprobe's special case ==== pipewire ==== Version update (1.6.8 -> 1.6.9) Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-jack pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Update to version 1.6.9: * This is a bugfix release that is API and ABI compatible with the previous 1.6.x releases. * Highlights - Improve JACK object callbacks, avoid reporting old removed objects. - Tweak the resampler cutoff frequencies to preserve more high frequencies when upsampling. - More small fixes and improvements. * Modules - Fix RAOP encryption for OpenSSL >= 3. (#5370 (closed)) - Fix netjack2 discovery timeout. - Fix potential truncated audio in RAOP. - Fix potential metadata update problems. (#5445 (closed)) - Fix RAOP over TCP. - Fix potential overflows in client node buffer checks. (#5462) - Add node.network=true to network sinks and sources so that pavucontrol and others don't wake them up. (#3268 (closed)) * SPA - Fix opus audio info type. - Tweak the upsample cutoff frequencies to preserve more high frequencies when upsampling. (#5390 (closed)) - Fix filter-graph property notification in some cases. - Remove limits on filter-graph descriptions in audioconvert. - Improve dynamic reconfiguration of filter-graphs in audioconvert. - Improve passthrough format handling in audioconvert. - Improve the FC and LFE volumes when upmixing is enabled. - Fix v4l2 controls when one can not be read. - Require 0.6.0 libcamera now. - Improve format filtering in v4l2. * Pulse-server - Don't let a pending sibling message starve capture. - Fix name of ALSA source. - Fix potential crash with the active_port_name. (#5435 (closed)) * Bluetooth - Fix a potential leak when transport fails to start. - Fix potential crash when cleaning up iso-io transport. * JACK - Rework the object lookups to avoid removed objects from leaking. (#5356 (closed)) * GStreamer - Add fixes for state changes and other lockups. * ALSA Plugin - Generate poll errors when stopping. (#5444 (closed)) * Tools - Handle EOF correctly for encoded files in pw-cat. - Fix loopback channel and position handling. - Fix mp3 encoding in pw-record. - Support A-law in pw-record. - Disable libcamera support when building in Leap 16.1 or older since pipewire now needs at least libcamera 0.6.0 . ==== poppler ==== Version update (26.07.0 -> 26.09.0) Subpackages: libpoppler-cpp3 libpoppler-glib8 poppler-tools - Update to version 26.09.0: + core: - Subset fonts when saving changes in Annotations and Forms when using fontconfig - NSS: Don't infinite loop on wrong password - Internal code improvements - Fix crashes in malformed documents + utils: - pdftotext: Add -urls option to print link URLs next to their text - pdftohtml: Improve speed by ignoring tiling patterns earlier - pdfimages: Fix typo in manpage + glib: Remove G_GNUC_CONST in enum _get_type funcs + build system: harfbuzz is now required for font subsetting - Changes from version 26.08.0: + core: - GPG based signature improvements - Internal code improvements + utils: - pdftohtml: Fix crash when using dataurls. - pdfimages: Add min-height and min-width options + glib: Stop using G_GNUC_CONST in _get_type funcs + build system: - Slight increase in compilation of utils folder - Fix -Wunused-command-line-argument when using clang - Use cmake modern way to check for linker support - Bump soname following upstream changes. - Use ldconfig_scriptlets macro for post(un) handling. - Add pkgconfig(harfbuzz) BuildRequires: New dependency. ==== poppler-qt6 ==== Version update (26.07.0 -> 26.09.0) - Update to version 26.09.0: + core: - Subset fonts when saving changes in Annotations and Forms when using fontconfig - NSS: Don't infinite loop on wrong password - Internal code improvements - Fix crashes in malformed documents + utils: - pdftotext: Add -urls option to print link URLs next to their text - pdftohtml: Improve speed by ignoring tiling patterns earlier - pdfimages: Fix typo in manpage + glib: Remove G_GNUC_CONST in enum _get_type funcs + build system: harfbuzz is now required for font subsetting - Changes from version 26.08.0: + core: - GPG based signature improvements - Internal code improvements + utils: - pdftohtml: Fix crash when using dataurls. - pdfimages: Add min-height and min-width options + glib: Stop using G_GNUC_CONST in _get_type funcs + build system: - Slight increase in compilation of utils folder - Fix -Wunused-command-line-argument when using clang - Use cmake modern way to check for linker support - Bump soname following upstream changes. - Use ldconfig_scriptlets macro for post(un) handling. - Add pkgconfig(harfbuzz) BuildRequires: New dependency. ==== pulseaudio-qt6 ==== Version update (1.8.1 -> 1.9.0) - Update to 1.9.0: * context: reset before reconnectDaemon * context: remove stray return in void function * server: do not return incorrect default devices * server: cleanup findByName a bit * Extract and install Qt metatypes ==== python-greenlet ==== Version update (3.5.5 -> 3.5.6) - Update to 3.5.6 * Correct a race condition that could lead to garbage collection unintentionally being disabled. See PR 529 by Yurii. ==== python-pygit2 ==== - Exclude another broken test (bsc#1278723) - Fix BlobIO deadlock (gh#libgit2/pygit2#1488) * Fix-BlobIO-cleanup-deadlock.patch ==== python313 ==== Version update (3.13.14 -> 3.13.15) Subpackages: python313-curses python313-dbm python313-tk - Restore back macros.python3, we need it. - CVE-2026-19672: in tarfile, handle a member that leaves the destination and comes back (bsc#1276227, gh#python/cpython#156000) CVE-2026-19672-tarfile-outside-dirs.patch CVE-2026-17084: Don't consider Unicode codepoint attributes outside RFC 3454 (bsc#1276226) CVE-2026-17084-unicode-rfc3454.patch - Add sphinx9-runtime-node.patch fixing documentation build with Sphinx 9 by importing the extension's Node type at runtime. - Restore the self-contained structure of the python313 package in openSUSE Factory: * the package has started to rely on the separate virtual `python3` package for the generic interpreter entry points and for the `python3*` Provides (bsc#1258364). That structure is meant for the SUSE Linux family of distros, it does not belong to Factory * python313 provides python3, python3-base and the other `python3*` virtual names again * python313 owns the python3 and pydoc3 binaries, the python3.1(1) man page, python3-config, libpython3.so and the unversioned pkg-config files again * python313 uses the rpm-build-python generated `python(abi)` Provides - Update to 3.13.15 - Tools/Demos - gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms. - gh-155207: Argument Clinic now supports the --dry-run and - -diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file. - gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code. - gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale. - Tests - gh-76595: Add C API tests for PyCapsule_Import(). - gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job. - gh-154144: Fix building the _testcapi module on NetBSD. - gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run. - gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout. - gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix). - Security - gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). - gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings (bsc#1273148, CVE-2026-6879). - gh-152216: Update bundled libexpat to version 2.8.2. - gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). - gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). - gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330 (bsc#1268977, CVE-2026-11940). - gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). - gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted (bsc#1257044, CVE-2025-15366). - Library ... changelog too long, skipping 525 lines ... - reproducible_stencils.patch ==== python313-core ==== Version update (3.13.14 -> 3.13.15) Subpackages: libpython3_13-1_0 python313-base python313-devel - Restore back macros.python3, we need it. - CVE-2026-19672: in tarfile, handle a member that leaves the destination and comes back (bsc#1276227, gh#python/cpython#156000) CVE-2026-19672-tarfile-outside-dirs.patch CVE-2026-17084: Don't consider Unicode codepoint attributes outside RFC 3454 (bsc#1276226) CVE-2026-17084-unicode-rfc3454.patch - Add sphinx9-runtime-node.patch fixing documentation build with Sphinx 9 by importing the extension's Node type at runtime. - Restore the self-contained structure of the python313 package in openSUSE Factory: * the package has started to rely on the separate virtual `python3` package for the generic interpreter entry points and for the `python3*` Provides (bsc#1258364). That structure is meant for the SUSE Linux family of distros, it does not belong to Factory * python313 provides python3, python3-base and the other `python3*` virtual names again * python313 owns the python3 and pydoc3 binaries, the python3.1(1) man page, python3-config, libpython3.so and the unversioned pkg-config files again * python313 uses the rpm-build-python generated `python(abi)` Provides - Update to 3.13.15 - Tools/Demos - gh-155218: Fix Argument Clinic generating the flags of the optional groups in different order on 32-bit and 64-bit platforms. - gh-155207: Argument Clinic now supports the --dry-run and - -diff options. They list the files which would be changed, or write a unified diff of the changes to the standard output, without modifying any file. - gh-64502: Fix Argument Clinic support of parameters with a default value used together with optional groups. Such parameters were always required in the generated parsing code. - gh-154580: Fix python-gdb.py raising UnicodeEncodeError when pretty-printing a non-ASCII str in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale. - Tests - gh-76595: Add C API tests for PyCapsule_Import(). - gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job. - gh-154144: Fix building the _testcapi module on NetBSD. - gh-152548: Add the test.support.isolation.runInSubprocess() decorator to run a test method or TestCase subclass in a fresh interpreter subprocess, isolated from the rest of the test run. - gh-151626: Fix several tests in test.test_inspect, test.test_import, test.test_importlib, test.test_py_compile and test.test_compileall that failed when the test suite was run with PYTHONPYCACHEPREFIX set. These tests now neutralize the pycache prefix where they assume the default __pycache__ bytecode layout. - gh-151096: Fix test_embed failing when CPython is configured with a split exec prefix (--exec-prefix differing from --prefix). - Security - gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). - gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings (bsc#1273148, CVE-2026-6879). - gh-152216: Update bundled libexpat to version 2.8.2. - gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). - gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). - gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330 (bsc#1268977, CVE-2026-11940). - gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). - gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted (bsc#1257044, CVE-2025-15366). - Library ... changelog too long, skipping 525 lines ... - reproducible_stencils.patch ==== rpm ==== Subpackages: librpmbuild10 rpm-plugin-selinux - Don’t be dependent on python3-base, it is perfectly OK to use any Python interpreter for python-rpm-packaging. - Remove obsolete Python2-based removal of Python directories (why?) ==== ruby4.0 ==== Version update (4.0.6 -> 4.0.7) Subpackages: libruby4_0-4_0 - Update to 4.0.7 - Bug #22188: addr2line doesn't find symbols when compiled with GCC LTO - Ruby - Ruby Issue Tracking System - Bug #22210: Check if issue #19969 is still reproducible / re-opened in 4.0.x - Ruby - Ruby Issue Tracking System - Bug #22217: Segmentation fault when resuming execution with Coverage.start and ruby/debug - Ruby - Ruby Issue Tracking System - Fix formatting in ObjectSpace._id2ref error path by eregon · Pull Request #18206 - Bug #22200: ObjectSpace._id2ref can return a different object than the id's owner on Ruby 4.0 (stale id2ref_tbl entry for objects with generic fields) - Ruby - Ruby Issue Tracking System - Bug #22123: Ruby::Box + BUNDLER_SETUP can evaluate gemspecs before main-box RubyGems initialization - Ruby - Ruby Issue Tracking System - Bump ERB to 6.0.7 by k0kubun · Pull Request #18282 - Bug #22237: GC.auto_compact corrupts a String or segfaults from String#tr with dup or gsub - Ruby - Ruby Issue Tracking System - Bug #22243: Change fork behavior when Process._fork raises an exception during fork with a block argument - Ruby - Ruby Issue Tracking System - Bug #22223: Socket.tcp with connect_timeout returns a phantom "connected" socket for a refused connection on macOS 27 (kernel answers EISCONN on connect retry; SO_ERROR never consulted) - Ruby - Ruby Issue Tracking System - Bug #22220: Performance regression when requiring aws-sdk-ec2 in Ruby 4.0.6 - Ruby - Ruby Issue Tracking System - Bug #22218: Line TracePoint misses executed loop condition after a guard - Ruby - Ruby Issue Tracking System - Bug #22198: win32: heap overflow in Kernel#system - Ruby - Ruby Issue Tracking System - Bug #22196: Heap-use-after-free in fiber_switch with transfer-terminated async tasks on 3.4.10 - Ruby - Ruby Issue Tracking System - Bug #22190: Class#subclasses does not include clones of classes that include modules - Ruby - Ruby Issue Tracking System - Bug #11438: native_thread_init_stack() get machine.stack_start unequal to thread's stack start address, x86 win32 - Ruby - Ruby Issue Tracking System - Bug #22257: Prepending a module to an already-included module leaves stale super caches - Ruby - Ruby Issue Tracking System - Bug #22242: SEGV in method dispatch (vm_call_iseq_setup_kwparm_nokwarg / def_iseq_ptr) on Ruby 4.0.6 — Rails CI - Ruby - Ruby Issue Tracking System - Bug #22269: Coverage.line_stub clobbers already-collected coverage data - Ruby - Ruby Issue Tracking System - Bug #22290: Adding instance variables to anonymous object may bloat all future classes - Ruby - Ruby Issue Tracking System - Bug #22292: YJIT/ZJIT: Struct accessor crashes after an instance variable is set on a Struct that exactly fills the largest GC slot - Ruby - Ruby Issue Tracking System - Bug #20958: fix ENV.keys encoding on windows - Ruby - Ruby Issue Tracking System - Bug #22259: Arrays sharding a buffer segfault when concatenating with each other - Ruby - Ruby Issue Tracking System - Bug #22264: Warning missing from parse.y hash literals - Ruby - Ruby Issue Tracking System - Bug #22303: EncodingError from interpolating symbol crashes whole process - Ruby - Ruby Issue Tracking System - Bug #22224: YJIT: rb_yjit_invalidate_ep_is_bp takes the VM lock stopping Ractors on every Proc materialization; multi-Ractor throughput collapses (up to ~150x) - Ruby - Ruby Issue Tracking System ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Ignore release if not specified in the pkg state (bsc#1280289) - Added: * ignore-release-if-not-specified-in-the-pkg-state-bsc.patch - Stabilize testsuite - Added: * stabilize-testsuite-784.patch ==== selinux-policy ==== Version update (20260910 -> 20260914) Subpackages: selinux-policy-targeted - Update to version 20260914: * Label charon-nm as ipsec_exec_t (bsc#1278135) * Fix corrupted formatting in files.if * Allow nsswitch_domain connect to read xdm pid socket files * nsresourced fixes for mkosi (bsc#1279902) * Allow sshd-session connect to gnome remote desktop port * Allow sshd-session to connect to all generic ports * Allow sshd-session connect to port 443/tcp (http_port_t) * Allow sshd-session connect to tcp/22 (ssh_port_t) * Allow rsync to getattr pipes and sockes if rsync_export_all_ro is set (bsc#1279051) * Introduce files_getattr_non_auth_sockets * Introduce files_getattr_non_auth_pipes interface * Allow rsync to read var_t (bsc#1279565) * Update udev_manage_pid_files() to include symlinks read * Support vfs_snapper to work with samba_share_t (bsc#1265400) * vfs_samba uses dbus to communicate with snapper (bsc#1265400) * fix NetworkManager dnsmasq-forwarders.conf labeling (bsc#1260038) * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366) * Allow kmscon read cocpit's pid files * fix vpnc_t setpgid permission for openconnect (bsc#1272934) * Allow systemd-sysctl to create /run/sysctl.d * Allow systemd to create /run/udev/control * Allow systemd-coredumpd to create /run/systemd/coredumpd/kernel * Allow bootupcl nnp transition to mount_t * Networkmanager: Remove files_manage_etc_files for console_t * Networkmanager: Allow NM to manage files under /run * Allow login_userdomain read/write kmscon devpts chr_files * Support console version of initial-setup * ssh-session accesses gitolite ssh config files (bsc#1277259) * Allow kmscon use netlink permissions (#3368) * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783) * Allow ssh_agent_type manage ssh_home_t files and sock_files * Allow sshd-session manage ssh_home_t socke files * Allow sshd-session X11 forwarding * Allow lsmd-plugin read udev pid files * Allow virtstoraged domain transition on iscsiadm execution * Revert "Allow virtqemud domain transition on iscsiadm execution" * Allow rhsmcertd search gconf home data dirs * Allow rhsmcertd read gconf home files * Revert "Allow rhsmcertd read gconf home files" * Allow postmap read aliases * Allow lsmd-plugin use libStorageMgmt to provision storage * Update dhcpc-hook policy * Allow virtqemud domain transition on iscsiadm execution * Allow virtqemud domain transition on udev execution * Allow virtqemud relabelfrom its private fifo files * Support gnome-remote-desktop's smartcard redirection support * Allow qatlib manage hugetlbfs directories * Allow sanlock the sys_admin capability * Allow rhsmcertd read gconf home files * Allow rhsmcertd read insights-client config files * Allow insights-client read install_t process state * Allow insights-client read the process state of the init scripts * Allow namespace_init_t execute generic programs in bin directories * Update the ssh_server_template() template * Add rules for sshd vsock socket read/write * Allow dhcpc hook query the chronyd service * Allow insights-client read gconf home files * Allow login_userdomain mount, remount, unmount all mount points * Allow login_userdomain mount on all mount points * Revert "Allow userdomain get attributes of files on an nsfs filesystem" * Allow accountsd create and use its private tmpfs files * Add the anaconda_read_state_install() interface * Update qatlib policy * Allow rhsmcertd read the file_contexts files * rhsmcertd: allow bootc/ostree transient package persistence detection * Allow virtproxyd connect to systemd-homed over a unix stream socket * Allow system_mail_t read procmail home content * Label malware-detection-config.yml with insights_client_etc_rw_t * Add bcachefs as a SELinux capable filesystem * Allow unconfined_service_t nnp_transition to container_runtime_t * Add the files_write_system_conf_files() interface * Allow haveged (entropyd_t) create and use its private tmpfs files * Allow ctdbd manage access to Samba PID directories * Allow rhsmcertd read selinux config and default file contexts * Allow staff_t and user_t execute udev without a domain transition * Allow mpd dbus chat with avahi * Allow init_t nnp domain transition to mpd_t * Update tuned-ppd policy * Update policy for virsh_ssh_t to help with live migration * Update sysadm policy for encrypted volumes usage * Allow bootupd read all passwd sources * Allow local login and sshd-session signull cockpit-session * Allow sysadm_t read/write kvm devices * Allow sysadm user run fail2ban-client * Add 2 interfaces helping to handle cloud-what cache files * Allow all domains to use inherited sshd-session pipes * Dontaudit tlp_t dac_override (bsc#1272935) - Syncing with upstream rawhide selinux-policy up to: * dc63e37474fac5e8f74560acfc1bfdb0f785ec24 - Update embedded container-selinux version to commit: * 4ac019955c8885496ffbd978520c905434d4273e (v2.251.0) ==== shaderc ==== Version update (2026.3 -> 2026.4) - Update to release 2026.4 * Incorporate fixes for SPV_KHR_abort abortEXT(...) * glslc: option -fshader-stage now accepts all shader stage names as allowed in #pragma shader_stage()> This includes ray tracing, task, and mesh shader stages. ==== snappy ==== Version update (1.2.2 -> 1.3.0) - Update to 1.3.0: * Fixed a uint32_t overflow when decompressor accepted an input with incorrect format * Significant RISC-V efficiency improvements * New API on providing your own memory context * Supporting compression levels (1-2) in C API * Various other small fixes - Refresh reenable-rtti.patch - Disable LiteralLengthU32Overflow test in 32 bit architectures ==== spice ==== - bsc#1278684 - Core dump messages when a vm is shut down on KVM/Qemu. Fix-keyboard-and-mouse-state-leaks-on-interface-removal.patch ==== spice-gtk ==== Subpackages: libspice-client-glib-2_0-8 libspice-client-glib-helper libspice-client-gtk-3_0-5 - Add 3f85c57.patch: spice-widget: update cairo scale when output scale changes. ==== sssd ==== Subpackages: libnfsidmap-sss libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap - Fix IDP provider cross-user impersonation; (bsc#1279915); (CVE-2026-87853); Add patch 0018-IDP-fix-user-matching-in-eval_access_token_buf.patch ==== suitesparse ==== Version update (7.14.0 -> 7.14.1) Subpackages: libamd3 libcamd3 libccolamd3 libcholmod5 libcolamd3 libsuitesparseconfig7 libumfpack6 - Update to 7.14.1 * GraphBLAS 10.5.1: bug fix ==== timezone ==== Version update (2026c -> 2026d) Subpackages: tzselect - Updat to 2026d: * Canada’s Northwest Territories moved to permanent -06 on 2026-08-21 * Obsolescent settings like TZ="EST5EDT" now conform better to POSIX * Fix security, performance and porting bugs in zic and localtime ==== tree-sitter ==== - Add the %treesitter_queries_install, %treesitter_queries_files and %treesitter_queries_package macros: ship the queries a grammar carries (highlights.scm and friends) in a noarch -queries subpackage under %_datadir/tree-sitter/queries/, keyed like the -wasm modules, for consumers highlighting with the grammar's own queries - Own %_datadir/tree-sitter/queries - tree-sitter-target.py: match a nested grammar source directory (grammars/) as a path prefix, not only a top-level one - Add the %treesitter_wasm_build, %treesitter_wasm_install, %treesitter_wasm_files and %treesitter_wasm_package macros: build every grammar of a package to a WebAssembly module with the distribution's clang, lld and wasi-libc (the tree-sitter CLI's own wasi-sdk invocation) into a noarch -wasm subpackage under %_datadir/tree-sitter/wasm, for consumers running web-tree-sitter - Own %_datadir/tree-sitter/wasm ==== vmaf ==== Version update (3.2.0 -> 3.2.1) - Update to release 3.2.1 * libvmaf/speed_chroma: remove bilinear prescale index/weight computation from per-pixel loop. * Add ARM NEON implementation for 8-bit integer motion feature. ==== xz ==== Version update (5.8.3 -> 5.8.4) Subpackages: liblzma5 - Update to version 5.8.4: * Fix an invalid memory access in lzma_alone_decoder(), lzma_lzip_decoder(), lzma_auto_decoder(), and lzma_microlzma_decoder() after a failed allocation is followed by decoder reinitialization; could crash (GHSA-5qpq-xqfv-j9pg, CVE pending, affects all versions since 5.0.0) * Fix wrong error code/assertion failure in lzma_stream_buffer_decode() on truncated input * Fix a performance issue and a theoretical integer overflow in lzma_index_cat(), used by "xz --list" * Fix bogus/too-low memory usage reporting in lzma_index_decoder() * Fix lzma_index_dup() copying the wrong check type * Fix a missing synchronization in the threaded .xz decoder affecting lzma_get_progress() * xz: fix two use-after-free bugs (--files/--files0 via XZ_OPT/XZ_DEFAULTS, and --verbose with redirected stderr) * Add Landlock ABI 9 support on Linux * Fix "xz --list" totals overflow check, an xzgrep option- injection quoting bug, and an ARM64/LoongArch unaligned- read issue; see upstream's release notes for the full list - spec-cleaner cleanup: drop Group: tags, convert static-devel's Requires to pkgconfig(liblzma)