Packages changed: ImageMagick (7.1.2.31 -> 7.1.2.32) cairomm cantarell-fonts (0.303.1 -> 0.311) ffmpeg-8 (8.1.2 -> 8.1.3) gimp git (2.55.0 -> 2.56.0) gstreamer-plugins-bad harfbuzz (14.5.1 -> 14.6.0) highway libgexiv2 (0.14.6 -> 0.14.7) libsoup2 libstorage-ng (4.5.360 -> 4.5.362) mariadb mozilla-nss (3.128 -> 3.129) mutter openSUSE-release (20261007 -> 20261008) polkit-default-privs (1550+20260928.d1c0e7e -> 1550+20261007.d5bf5b4) qemu (11.1.1 -> 11.1.2) unzip util-linux (2.42.3 -> 2.42.4) util-linux-systemd (2.42.3 -> 2.42.4) virtualbox virtualbox-kmp webkitgtk3 (2.52.6 -> 2.54.1) webkitgtk4 (2.52.6 -> 2.54.1) xdg-desktop-portal xterm (410 -> 411) yelp === Details === ==== ImageMagick ==== Version update (7.1.2.31 -> 7.1.2.32) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - version update to 7.1.2.32 * Force the system version of zlib in the libjpeg-turbo build. 5f3ddea * Preserve Ultra HDR metadata precision #8938 * Preserve EXIF dimensions during transforms #8937 * latest autoconf update a6ba226 * eliminate compiler warnings 3b5dd62 * eliminate compiler warning 7932a3c * eliminate compiler warning ba5d752 * eliminate compile warning 788a643 * eliminate compile warning 2274d05 * eliminate compiler warnings 1cea164 * eliminate compiler warning b501c08 * eliminate compile warnings 471d079 * eliminate compiler warning c6eda74 * ... f604d6d * eliminate compiler warnings ab76ec8 * replace deprecated -affine option 7ee5fba * Corrected the type in the GetMagickModule define. 96cd772 * Fixed the windows build by reverting some of the changes. f8d3f5e * Removed unnecessary includes. e168300 * Restored the cstring includes in Magick++. 1ef6db5 * Pre-declare libstdc++ global types before MagickCore namespace. 2adb894 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8xmr-6q99-c4x8 af7b850 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cvgp-q487-j22w 0e82a4d * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8x3v-wr32-qqh4 12db6f0 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jjp4-3fwf-393j 1926ccf * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9f9w-84g3-vp2c 15892fc * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v2x3-wpmg-c4w6 fb743d6 * eliminate compiler warning ce948a1 * https://github.com/ImageMagick/ImageMagick/issues/8939 1a0d1b7 * eliminate compiler warning 5921a78 * eliminate compiler warning 0fcc3eb * Fix static libuhdr and module linking #8940 * latest autoconf update e6eed39 * fix: preserve destination on UHDR encoder failure #8941 * https://github.com/ImageMagick/ImageMagick/issues/8939 3501ef3 * revert cd53798 * https://github.com/ImageMagick/ImageMagick/issues/8939 72b82a8 * append random hex code to backup filename 6ace963 * match destructor to constructor 960adad * create a secure temporary filename caaad71 * move O_NOFOLLOW to main IM header 989dfd4 * fix: preserve UHDR resize filters #8942 * https://github.com/ImageMagick/ImageMagick/issues/8939 81142c9 * check for '>' terminator on DOCTYPE 3cb153f * revert 08328d8 * improve DOCTYPE block 3ca8bea * cosmetic a5e13b9 * more robuse DOCTYPE parser 399d4bd * Preserve JPEG comments during automatic Ultra HDR decoding #8943 * Reset gain-map canvas before replaying crops #8944 * Fix grayscale Ultra HDR base encoding #8945 * threads heuristic now based on pixel rather than row count 04fd261 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vv56-wmgw-m36w ce92ae0 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2vwg-3g4g-qprm cafc737 * Compose gain-map crop transforms before rounding #8948 * eliminate compiler warning 8174e9a * eliminate compiler warning ab0c467 * check for connection reset 1532081 * https://github.com/ImageMagick/ImageMagick/issues/8949 9249cab * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q6h4-6f2h-8hfq 2ec49e6 * build(deps): bump ubuntu from `2260313` to `513c074` in /.devcontainer #8951 * Removed incorrect option. c534219 * Disable more parts of libjpeg-turbo in the oss-fuzz build. 599ebe5 * Honor quality settings when transforming retained gain maps #8947 * Revert some of the oss-fuzz changes. a19ff07 * Explicitly set the include dir in the oss-fuzz build to fix libjpeg-turbo issue. 3797e92 * Preserve IPTC profiles during automatic Ultra HDR decoding #8952 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4h52-f5gr-2w2h 2814fa0 * Cache distributed pixel cache shared secret. 6f04f5f * Improved method name. ed3e3ab * No longer include a private header file in a public header file. c9a7583 * Correct exception throwing method. ecb4d97 * More corrections of exception throw methods. 0369b85 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9p7q-63hw-mcr4 e4f7ad9 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f983-243h-9x4r b2d579d * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-233r-2p53-wqf5 6cfb8d8 * eliminate compiler exception ca20b6b * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7q74-r26w-fwcx 9e78949 * block file descriptor inheritance c9120e9 * eliminate compiler warning 4129773 * eliminate compiler exception 1eac014 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5j8x-vq8c-vrp9 5a5c2e5 * Report buffered output failures when closing blobs #8954 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-58h4-rwr6-wj72 d98509b * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2fgx-26mg-j4f4 15ce9c9 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vxwm-jfjc-3r4x 48c49d0 * eliminate compiler warning 281db90 * eliminate compiler warning 9efb94b * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vxwm-jfjc-3r4x 2ed1b96 * Moved unpacking of libraw image to a separate method. fef349d * Various security and performance improvements for the ase decoder (GHSA-gwj6-pm7x-3r63) 5ecd5b0 * Added extra security check (GHSA-gwj6-pm7x-3r63) 0691546 * https://github.com/ImageMagick/ImageMagick/issues/8957 9bf9100 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g6p6-3ggg-3w7j f053f77 * build(deps): bump the codeql-action group with 3 updates #8960 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f32c-2v6j-wvh5 da4cfd7 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w6hf-vvx5-4qmj 7d3a270 * build(deps): bump azure/login from 3.0.2 to 3.1.0 #8961 ... changelog too long, skipping 68 lines ... CVE-2026-106570 [bsc#1284667] ==== cairomm ==== - Update version dependencies according to meson.build. ==== cantarell-fonts ==== Version update (0.303.1 -> 0.311) - Update to version 0.311: + Also provide a ss01 variant for the "fl" ligature, which I forgot in the last release. + Relax Python version requirements to >= 3.10 when using uv. - Changes from version 0.310: + Extend ss01 to all lowercase 'l' characters and add a feature name. + Improve autohinting of 'я' and disable autohinting for 'Ф' because it rendered badly. + Static fonts will now have PANOSE values. They're incomplete, but better than nothing. + The VF will carry a name ID 25 to help e.g. Adobe apps tell it apart from the statics. Maybe it also helps other apps. + Implement soft-dotting for more glyphs. + Remove unreachable glyphs from font, lightening them by a few bytes. + Updated translations. - Call %meson_test in %check section: there are currently no tests defined yet though. ==== ffmpeg-8 ==== Version update (8.1.2 -> 8.1.3) Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Update to release 8.1.3 * More robust parsing of formats - Delete ffmpeg-8-CVE-2026-58049.patch, ffmpeg-8-CVE-2026-64833.patch, ffmpeg-8-CVE-2026-64834.patch, ffmpeg-8-CVE-2026-65703.patch, ffmpeg-8-CVE-2026-65704.patch, ffmpeg-8-CVE-2026-65705.patch, ffmpeg-8-CVE-2026-65706.patch, ffmpeg-8-CVE-2026-66037.patch, ffmpeg-8-CVE-2026-70628.patch, ffmpeg-8-CVE-2026-70629.patch, ffmpeg-8-CVE-2026-70630.patch, ffmpeg-8-CVE-2026-70631.patch, ffmpeg-8-CVE-2026-70632.patch, ffmpeg-8-CVE-2026-75141.patch, ffmpeg-8-CVE-2026-75142.patch, ffmpeg-8-CVE-2026-75143.patch, ffmpeg-8-CVE-2026-75144.patch, ffmpeg-8-CVE-2026-75145.patch, ffmpeg-8-CVE-2026-75146.patch, ffmpeg-8-CVE-2026-75147.patch, ffmpeg-8-CVE-2026-66036-shim01.patch (merged) - Delete ffmpeg-8-CVE-2026-66036.patch (feature patch not accepted upstream for 8.x) - Enable apv encoder support, add pkgconfig(oapv) BuildRequires and pass enable-liboapv to configure. - Add 0001-avcodec-liboapvenc-fix-build-with-openapv-1.1.patch ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - CVE-2026-96546: one-byte out-of-bounds heap read in the uncompressed DDS loader (bsc#1282601) * gimp-CVE-2026-96546.patch - CVE-2026-97185: out-of-bounds write in GIMPressionist plugin via crafted preset file (bsc#1282596) * gimp-CVE-2026-97185.patch ==== git ==== Version update (2.55.0 -> 2.56.0) Subpackages: git-core git-email git-gui git-svn git-web gitk perl-Git - update to 2.56.0: - UI, Workflows & Features - Advice shown by "git status" when the local branch is behind or has diverged from its push branch has been updated to suggest "git pull ". - The handling of promisor-remote protocol capability has been updated to allow the other side to add to the list of promisor remotes via the 'promisor.acceptFromServerURL' configuration variable. - The 'ort' merge backend has been hardened against corrupt trees by ensuring it aborts under appropriate error conditions. - The `fetch.followRemoteHEAD` configuration variable has been added to provide a default for the per-remote `remote..followRemoteHEAD` setting. - "git log --follow" has been updated to better handle non-linear history, in which the path being tracked gets renamed differently in multiple history lines. - The "git repo info" command has been taught new keys to output both absolute and relative paths for "gitdir" and "commondir", supported by a new path-formatting helper extracted from "git rev-parse". - When 'git push origin/main' or 'git branch origin main' is run, the command is now recognized as a potential typo, and advice has been added to offer a typo fix. - The 'git refs' toolbox has been extended with new 'create', 'delete', 'update', and 'rename' subcommands to create, delete, update, and rename references, respectively. - The experimental 'git history' command has been taught a new 'drop' subcommand to remove a commit, with its descendants replayed onto its parent. - The alignment of commit object name abbreviations in 'git blame' output has been optimized to reserve a column for marks (caret, question mark, or asterisk) only when such marks are actually shown. - Option parsing with 'git rev-parse --parseopt' and in most 'git' subcommands has been updated to exit with 0 (instead of 129) when the help option ('-h' or '--help') is requested directly by the user, aligning with standard Unix convention. - The '[includeIf "condition"]' conditional inclusion facility for configuration files has been taught to use the location of the worktree in its condition. - The usage string and SYNOPSIS for 'git fast-export' have been standardized to make them consistent with each other and with other commands. - 'git log --graph' has been modified to visually distinguish parentless 'root' commits (and commits that become roots due to history simplification) by indenting them, preventing them from appearing falsely related to unrelated commits rendered immediately above them. - Userdiff patterns for Swift have been added, with support for Swift-specific constructs such as attributes, modifiers, failable initializers, and generics. - Configuration file locking has been updated to retry for a short period, avoiding failures when multiple processes attempt to update the configuration simultaneously. - The 'remote-object-info' command has been added to 'git cat-file --batch-command', allowing clients to request object metadata (currently size) from a remote server via protocol v2 without downloading the entire object. Format placeholders are dynamically filtered on the client based on server-advertised capabilities, returning empty strings for inapplicable or unsupported fields. - 'git branch -d' has been taught to report when a branch cannot be deleted because it is being used in an active bisect run. - 'git mv' has been updated to check for a missing destination leading directory during the checking phase, allowing 'git mv - n' to report the failure. The error message when the rename(2) syscall fails has also been improved to name both the source and the destination. - 'git add' has been taught a new '--resolved' option to stage conflict-resolved paths, while leaving unrelated local changes unstaged. It scans the unmerged paths for leftover conflict markers and aborts if any are found. - The known limitations of the ref format migration in 'git refs' have been moved to be displayed as a warning admonition directly under the description of the 'migrate' subcommand, improving visibility. A reference to 'git-maintenance' has also been corrected to use the 'linkgit' macro. - The 'git bisect' command has been taught a '--reset-when-found[=]' option that tells the command to automatically run 'git bisect reset' to jump back to the original state or to the found culprit. - The 'git branch' command has been taught the '--delete-merged' option to remove local branches that are already merged into their tracked remote-tracking branches. - The 'remote-object-info' command for 'git cat-file - -batch-command' has been extended to support the '%(objecttype)' placeholder. - The usage string of 'git fast-import' has been updated to use the parse_options() API for displaying help, and its SYNOPSIS in the documentation has been standardized to match. - The error message given by 'git send-email' when a message file is missing a 'Subject:' header has been clarified, and the error string is now terminated with a newline so that Perl avoids appending its internal source location data. - The '--shallow-file' option of 'git' command requires a value, but the code did not check the presence of a value and ... changelog too long, skipping 702 lines ... c486c1df72 hk/typofix later to maint). ==== gstreamer-plugins-bad ==== Subpackages: gstreamer-plugins-bad-lang libgstadaptivedemux-1_0-0 libgstanalytics-1_0-0 libgstbadaudio-1_0-0 libgstbasecamerabinsrc-1_0-0 libgstcodecparsers-1_0-0 libgstcodecs-1_0-0 libgstcuda-1_0-0 libgsthip-1_0-0 libgstinsertbin-1_0-0 libgstisoff-1_0-0 libgstmpegts-1_0-0 libgstmse-1_0-0 libgstphotography-1_0-0 libgstplay-1_0-0 libgstsctp-1_0-0 libgsturidownloader-1_0-0 libgstva-1_0-0 libgstvulkan-1_0-0 libgstwayland-1_0-0 libgstwebrtc-1_0-0 libgstwebrtcnice-1_0-0 - Add pkgconfig(libfreeaptx) BuildRequires and stop passing openaptx=disable to meson setup, build aptx support. Also drop the conditional pkgconfig(libopenaptx) BuildRequires. ==== harfbuzz ==== Version update (14.5.1 -> 14.6.0) Subpackages: libharfbuzz-gobject0 libharfbuzz-icu0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.6.0: * Fix shaping failures caused by out-of-range glyph IDs, a regression from * Update experimental beyond-64k support to the final ISO Open Font Format 5th edition. This support remains disabled by default. * Add support for the `DMAP` table. * Support `FeatureVariations` 1.1 lookup variations, including subsetting and instancing. * Update `VARC` to the revised variation-store format. The new format is incompatible with the previous one. * Various `VARC` fixes. * Fix background color and stride handling in the experimental raster library. * Improve the experimental Rust shaper (HarfRust) and font functions (`fontations`), and update HarfRust to 0.14. * Various subsetting fixes and improvements. * Various fixes for malformed fonts. * Various build and CI fixes. ==== highway ==== - Disable LTO for aarch64 as a Workaround for "error: this operation requires the SVE ISA extension" ==== libgexiv2 ==== Version update (0.14.6 -> 0.14.7) Subpackages: libgexiv2-2 typelib-1_0-GExiv2-0_10 - Update to version 0.14.7: * Fix crash when opening a file without preview images after one with preview images. - Update version dependencies according to meson.build. ==== libsoup2 ==== Subpackages: libsoup-2_4-1 libsoup2-lang - CVE-2026-15711: WebSocket denial of service via oversized control frame protocol violation (bsc#1271446) * libsoup2-CVE-2026-15711.patch - CVE-2026-15714: Out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string (bsc#1271449) * libsoup2-CVE-2026-15714.patch - CVE-2026-66339: proxy credentials leak to destination server via `Proxy-Authorization` header in CONNECT tunnels (bsc#1273156) * libsoup2-CVE-2026-66339.patch - CVE-2026-12547: Header "Proxy-Authorization" leads to credentials being send to different proxy after proxy switch (bsc#1272195) * libsoup2-CVE-2026-12547.patch - CVE-2026-102558: Heap buffer overflow during WebSocket receive-buffer growth (bsc#1283302) * libsoup2-CVE-2026-102558.patch - CVE-2026-102556: Heap buffer overflow from WebSocket Pong signal type confusion (bsc#1283300) * libsoup2-CVE-2026-102556.patch - CVE-2026-102560: Heap buffer overflow during outgoing permessage-deflate buffer growth (bsc#1283304) * libsoup2-CVE-2026-102560.patch - CVE-2026-102557: Heap buffer overflow during WebSocket message reassembly (bsc#1283301) - CVE-2026-102559: Heap buffer overflow during WebSocket client-frame masking (bsc#1283303) * libsoup2-CVE-2026-102557.patch - Tweak libsoup2-CVE-2026-12548.patch and libsoup2-CVE-2026-2708.patch to remove superfluous initializer values in the tests. ==== libstorage-ng ==== Version update (4.5.360 -> 4.5.362) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - merge gh#openSUSE/libstorage-ng#1099 - record json output of lsscsi (since version 0.33) - 4.5.362 - merge gh#openSUSE/libstorage-ng#1098 - improved readability of testsuite data - 4.5.361 ==== mariadb ==== Subpackages: libmariadbd19 mariadb-client mariadb-errormessages - Disable upstream SECURITY_HARDENED (would append -fstack-protector basic, downgrading -fstack-protector-strong from distro optflags; optflags already provide -fPIE/-pie, -z relro/now and - D_FORTIFY_SOURCE=3). ==== mozilla-nss ==== Version update (3.128 -> 3.129) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.129 * bmo#2068788 - emit static library names during static build. * bmo#2067434 - avoid building libcrux twice in makefile builds. * bmo#2068010 - fix non-linux arm64 makefile builds. * bmo#2017322 - set CKA_NSS_SERVER_DISTRUST_AFTER for CN=Izenpe.com. * bmo#2057185 - Document ./mach try and its Mercurial-only caveat in CLAUDE.md. * bmo#2056793 - Add tests for concurrent channel info queries during session replacement. * bmo#2056793 - take the session cache lock when reading ss->sec.ci.sid. * bmo#2066046 - Fix a race in STAN_GetNSSCertificate. * bmo#2066591 - Remove write-only blLib and libraryName statics from freebl's lowhash_vector. * bmo#2025246 - fix unknown key error type in ssl_SetAuthKeyBits. * bmo#2065879 - re-vendor HACL* and simplify run_hacl.sh. * bmo#2065879 - stop clang-formatting the vendored HACL* code. * bmo#2068191 - add --dry-run to mach try to print job list. * bmo#2029288 - avoid integer overflow in PK11_BlockData. * bmo#2066960 - fix UB in ecperf.c. * bmo#2067239 - Old coverity issues. * bmo#2067237 - MLKEM mechinfo needs keys sizes. * bmo#2066900 - pin NSPR 4.40 in CI. * bmo#2066266 - ML-KEM-1024 incorrectly allows an explicit encapsulation seed. * bmo#2066265 - Support for ML-KEM-512 in freebl and softoken. * bmo#2060316 - remove support for pre-standard Kyber. * bmo#2065423 - Build NSPR out of tree, into the dist directory. * bmo#2065423 - Write a machine-readable summary.json for each test run. * bmo#2065423 - Fail test runs on UBSan errors and on core dumps in debug builds. * bmo#2065423 - Link tests_results/latest at the newest test run. * bmo#2065423 - Resolve ssl_gtest_db.sh against QADIR. * bmo#2065423 - Generate nss.pc and nss-config into the dist directory. * bmo#2065423 - Add a --dist option to build.sh. * bmo#2065219 - Update Cryptofuzz version. * bmo#2056790 - Use PK11 digest contexts for explicit hashing in cryptohi. - rebased add-relro-linker-option.patch and nss-fips-constructor-self-tests.patch ==== mutter ==== Subpackages: mutter-lang - Add 5370.patch: wayland: Allow changing selections with the same serial (boo#1284143). ==== openSUSE-release ==== Version update (20261007 -> 20261008) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== polkit-default-privs ==== Version update (1550+20260928.d1c0e7e -> 1550+20261007.d5bf5b4) - Update to version 1550+20261007.d5bf5b4: * profiles: add gnome-remote-desktop use-grd-pcscd action (bsc#1276523) ==== qemu ==== Version update (11.1.1 -> 11.1.2) Subpackages: qemu-audio-spice qemu-block-curl qemu-block-nfs qemu-block-rbd qemu-chardev-spice qemu-guest-agent qemu-hw-display-qxl qemu-hw-display-virtio-gpu qemu-hw-display-virtio-gpu-pci qemu-hw-display-virtio-vga qemu-hw-usb-host qemu-hw-usb-redirect qemu-hw-usb-smartcard qemu-img qemu-ksm qemu-lang qemu-microvm qemu-pr-helper qemu-seabios qemu-tools qemu-ui-curses qemu-ui-gtk qemu-ui-opengl qemu-ui-spice-app qemu-ui-spice-core qemu-vgabios qemu-vmsr-helper qemu-x86 - Update to latest stable release (11.1.2) Full backport list here: https://lore.kernel.org/qemu-devel/20260929144512.126747-1-mjt@tls.msk.ru/ A selection of them is reported here below: target/sh4: Replace TB_FLAG_GUSA_EXCLUSIVE with CF_STEP_ATOMIC accel/tcg: Set CF_NOIRQ during cpu_exec_step_atomic linux-user/sh4: align the vdso sigreturn trampolines linux-user/sh4: fix vdso CFA for rt_sigreturn frames linux-user/sh4: use the kernel's sigreturn trampoline sequence in the vdso target/i386: Mark MOVNTI as not valid with prefixes 0x66, 0xF2, 0xF3 target/i386: Update FPU tag word for FXCH target/i386: Update FPU tag word for FSTP target/i386: Update FPU tag word for FXTRACT's old ST(0) target/i386: Fix FXCH to unconditionally clear C1 target/ppc: Stop vCPU thread before calling parent_unrealize tests/qtest/usb-hcd-xhci: test isoch endpoint type mismatch tests/qtest/usb-hcd-xhci: test isoch pacing with MFINDEX above 2^32 hw/usb/hcd-xhci: don't assert on NAK when retrying an isoch transfer hw/usb/hcd-xhci: fix interval alignment after MFINDEX passes 2^32 hw/usb/hcd-xhci: Set reentrancy guard in timer functions (CVE-2026-17588) tcg/riscv64: Set vtype before whole-register vector loads tests/tcg/s390x: Add regression test for #4449 tcg/optimize: Fix expansion/simplification of deposit tests/tcg/arm: Add regression test for #4448 tcg/optimize: Fix fold_multiply2 vs 1 accel/tcg: Fix TLB_MMIO check in tlb_plugin_lookup() accel/tcg: Use TLB_FORCE_SLOW not TLB_MMIO for system plugins hw/9pfs: mutate FID path from main thread only (CVE-2026-93834) s390x/pci: fix DMA slot leak on I/O TLB entry replacement hw/s390x/ipl: Fix incorrect PCI IPL block lengths linux-user/loongarch64: Detect vector stores in host_signal_write() linux-user: implement mlock2(2) syscall linux-user/riscv: honor zicntrúlse for base counterCSRs system/ram-discard-manager: fix offset_within_address_space in replay_by_populated_state() igvm: mark qigvm_find_param_entry as static igvm: validate and honor byte_offset in parameter directives hw/uefi: add missing uefi_str_is_valid check to uefi_vars_mm_lock_variable target/loongarch: Fix data race in CSR_ESTAT hw/riscv/virt.c: fix aclint soc/mtimer nodename target/arm/hvf: implement MDCCSR_EL0 as RAZ target/arm/whpx: fix whpx-arm post-reset CPU state target/arm/whpx: incorrect ENCODE_AA64_CP_REG parameter order target/arm/whpx: Don't try to sync ARM_CP_CONST registers hw/intc/bcm2835_ic: reject out-of-range FIQ source values qga: Change effective user/group ID in guest-ssh-* commands vhost-user-gpu: validate command buffer size in submit_3d ui/cursor: make the cursor refcount atomic hw/display/qxl: hold ssd.lock while replacing ssd.cursor hw/cxl: fix the CDAT DOE overlapping the Flex Bus DVSEC when sn= is set virtio-scsi: set dataplane_started to false upon failure virtio-balloon: fix free-page BH teardown on unrealize hw/virtio: reject inverted virtio-iommu IOVA ranges hw/net/virtio-net: strip trailing padding when caching RSC segment hw/net/virtio-net: check packet size before VLAN tag access in receive_filter() qapi/misc: Fix missed query-iothreads items hw/cxl: Fix guest-triggerable QEMU exit on reserved interleave ways virtio-gpu: clear res->blob on mapping cleanup ==== unzip ==== Subpackages: unzip-doc - Drop obsolete -fstack-protector from RPM_OPT_FLAGS (predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic) ==== util-linux ==== Version update (2.42.3 -> 2.42.4) Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 util-linux-lang - Update to version 2.42.4 (bsc#1274864, PED-16740): This release enhances previously released security fixes and adds protection against symlink attacks in the legacy mount(2)-based code in libmount. * lib/fileutils: * add safe FD-path and no-symlink helpers * fix RESOLVE_NO_SYMLINKS fallback value * libmount: * add mnt_fs_fetch_ids() and populate uniq_id for utab * use fchmodat2() for X-mount.mode= * restore the original namespace on error paths * secure the idmapped mount replacement * pin the legacy mount target and bind/move source * harden restricted mount targets and post-mount handling * fix X-mount.idmap ID names in code and man page * nsenter: close cgroup.procs fd after join to prevent authority leak [CVE-2026-78408, bsc#1278348] - Add two upstream follow-up fixes (util-linux-libcanonicalize-newline.patch, util-linux-wall-off-by-one.patch). - Fix uuidd tmpfiles installation path (bsc#1283294). - Mark two check known as failing in chroot environment. ==== util-linux-systemd ==== Version update (2.42.3 -> 2.42.4) Subpackages: lastlog2 liblastlog2-2 - Update to version 2.42.4 (bsc#1274864, PED-16740): This release enhances previously released security fixes and adds protection against symlink attacks in the legacy mount(2)-based code in libmount. * lib/fileutils: * add safe FD-path and no-symlink helpers * fix RESOLVE_NO_SYMLINKS fallback value * libmount: * add mnt_fs_fetch_ids() and populate uniq_id for utab * use fchmodat2() for X-mount.mode= * restore the original namespace on error paths * secure the idmapped mount replacement * pin the legacy mount target and bind/move source * harden restricted mount targets and post-mount handling * fix X-mount.idmap ID names in code and man page * nsenter: close cgroup.procs fd after join to prevent authority leak [CVE-2026-78408, bsc#1278348] - Add two upstream follow-up fixes (util-linux-libcanonicalize-newline.patch, util-linux-wall-off-by-one.patch). - Fix uuidd tmpfiles installation path (bsc#1283294). - Mark two check known as failing in chroot environment. ==== virtualbox ==== - Reenable kvm.enable_virt_at_load=0 workaround for Leap 16 (kernel too old to support cooperative KVM) - Move UICommon.so to virtualbox-qt so the virtualbox base RPM is qt-free. ==== virtualbox-kmp ==== - Reenable kvm.enable_virt_at_load=0 workaround for Leap 16 (kernel too old to support cooperative KVM) - Move UICommon.so to virtualbox-qt so the virtualbox base RPM is qt-free. ==== webkitgtk3 ==== Version update (2.52.6 -> 2.54.1) Subpackages: WebKitGTK-4.1-lang libjavascriptcoregtk-4_1-0 libwebkit2gtk-4_1-0 typelib-1_0-JavaScriptCore-4_1 typelib-1_0-WebKit2-4_1 webkit2gtk-4_1-injected-bundles - riscv-platformenable.patch: Fix build for riscv64 - Update to version 2.54.1: + What's new in WebKitGTK 2.54.1?: - Allow pasting in-memory image data from clipboard. - Add User-Agent quirk for Amazon Luna. - Align the filter surface with the device pixel grid. - Fix rendering of scaled or transformed no-repeat background images. - Fix rendering of preserve-3d layers when a layer crosses the camera plane. - Fix SkiaCompositingLayer filter rendering under transforms. - Do not rasterize the part of a tile that the clip drops. - Skip non-composited frames when damage is empty. - Fix text deleted by input method delete-surrounding in contenteditable. - Fix several crashes and rendering issues. - Drop 5d013e57c4c4e2674e28399fc162afa3adf25283.patch and webkitgtk-main-thread.patch: fixed upstream. - Add webkitgtk-skia-s390x.patch: fix skia build on s390x. - Add webkitgtk-main-thread.patch: RELEASE_ASSERT in initializeMainThread aborts Eclipse/SWT applications (bwo#322394). - No longer disable skia for ppc64le. - Add upstream patch: bmalloc installs mimalloc as a system library fix bwo#324458 - 5d013e57c4c4e2674e28399fc162afa3adf25283.patch - Update to version 2.54.0: + Switch web process compositor to use Skia instead of TextureMapper. + Improved damage handling that is now also used during the composition to limit the composited areas. + Implement GPU atlas creation and replay substitution for batched raster image uploads. + Media capability reporting is more accurate. + Video decoding limits are now respected in media capabilities queries. + Add new improved API for page favicons. + Add magnification property to WebKitWebView to handle visual scaling. + Add new API to allow setting a per-navigation custom User-Agent to WebKitWebsitePolicies. + Remove the option to use cairo for 2D rendering. - Update to version 2.53.91 (Unstable): + Handle video orientation in skia compositor. + Do not use cached credentials when Authorization header is present. + Fix scrollbar rendering issues due to incorrect damage. + Add log fallback when journald is not reachable. + Fix several crashes and rendering issues. - Drop webkitgtk-ppc64le-build-fix.patch: Fixed upstream. - Update to version 2.53.4 (Unstable): + Implemented batched painting in skia compositor, which improves performance when there are many layers that can be painted in the same operation. + Avoid unnecessary clips when possible in skia compositor. + Fix synchronization issues between main, scrolling and compositing threads causing glitches while scrolling in some cases. + Limit the damage region of the scrollbar to the region actually painted. + Add support for image/webp to canvas.toDataURL(). + Expose search inputs as WEBKIT_INPUT_PURPOSE_SEARCH. + Add User-Agent quirk for HBO Max. + Fix several crashes and rendering issues. - Changes from version 2.53.3: + Switch web process compositor to use Skia instead of TextureMapper. + Fix missing glyph before ZWJ/ZWNJ if no font is found for the cluster. + Add support for half width fonts. + Support time zone change notifications on linux. + Fix several crashes and rendering issues. - Changes from version 2.53.2: + Only use DMA-BUF mapping for writing to the GPU atlas when possible. + Do not resolve ‘-apple-system’ font to default system font. + Set real time limits when not using the portal. + Report support for supported non-AAC mp4a codecs. + Fix several crashes and rendering issues. - Changes from version 2.53.1: + Remove the option to use cairo for 2D rendering. + Implement GPU atlas creation and replay substitution for batched raster image uploads. + Improved non accelerated composited mode by using the same buffer sharing implementation as accelerated mode. + The on-demand hardware acceleration policy is now deprecated in GTK3 API. + Add new improved API for page favicons. + Add webkit_feature_list_find() to public API. + Support PGO features in regular CMake builds. + Fix several crashes and rendering issues. - Drop riscv-platformenable.patch: fixed upstream. - Rebase webkitgtk-ppc64le-build-fix.patch with quilt. ==== webkitgtk4 ==== Version update (2.52.6 -> 2.54.1) Subpackages: WebKitGTK-6.0-lang libjavascriptcoregtk-6_0-1 libwebkitgtk-6_0-4 typelib-1_0-JavaScriptCore-6_0 typelib-1_0-WebKit-6_0 webkitgtk-6_0-injected-bundles - riscv-platformenable.patch: Fix build for riscv64 - Update to version 2.54.1: + What's new in WebKitGTK 2.54.1?: - Allow pasting in-memory image data from clipboard. - Add User-Agent quirk for Amazon Luna. - Align the filter surface with the device pixel grid. - Fix rendering of scaled or transformed no-repeat background images. - Fix rendering of preserve-3d layers when a layer crosses the camera plane. - Fix SkiaCompositingLayer filter rendering under transforms. - Do not rasterize the part of a tile that the clip drops. - Skip non-composited frames when damage is empty. - Fix text deleted by input method delete-surrounding in contenteditable. - Fix several crashes and rendering issues. - Drop 5d013e57c4c4e2674e28399fc162afa3adf25283.patch and webkitgtk-main-thread.patch: fixed upstream. - Add webkitgtk-skia-s390x.patch: fix skia build on s390x. - Add webkitgtk-main-thread.patch: RELEASE_ASSERT in initializeMainThread aborts Eclipse/SWT applications (bwo#322394). - No longer disable skia for ppc64le. - Add upstream patch: bmalloc installs mimalloc as a system library fix bwo#324458 - 5d013e57c4c4e2674e28399fc162afa3adf25283.patch - Update to version 2.54.0: + Switch web process compositor to use Skia instead of TextureMapper. + Improved damage handling that is now also used during the composition to limit the composited areas. + Implement GPU atlas creation and replay substitution for batched raster image uploads. + Media capability reporting is more accurate. + Video decoding limits are now respected in media capabilities queries. + Add new improved API for page favicons. + Add magnification property to WebKitWebView to handle visual scaling. + Add new API to allow setting a per-navigation custom User-Agent to WebKitWebsitePolicies. + Remove the option to use cairo for 2D rendering. - Update to version 2.53.91 (Unstable): + Handle video orientation in skia compositor. + Do not use cached credentials when Authorization header is present. + Fix scrollbar rendering issues due to incorrect damage. + Add log fallback when journald is not reachable. + Fix several crashes and rendering issues. - Drop webkitgtk-ppc64le-build-fix.patch: Fixed upstream. - Update to version 2.53.4 (Unstable): + Implemented batched painting in skia compositor, which improves performance when there are many layers that can be painted in the same operation. + Avoid unnecessary clips when possible in skia compositor. + Fix synchronization issues between main, scrolling and compositing threads causing glitches while scrolling in some cases. + Limit the damage region of the scrollbar to the region actually painted. + Add support for image/webp to canvas.toDataURL(). + Expose search inputs as WEBKIT_INPUT_PURPOSE_SEARCH. + Add User-Agent quirk for HBO Max. + Fix several crashes and rendering issues. - Changes from version 2.53.3: + Switch web process compositor to use Skia instead of TextureMapper. + Fix missing glyph before ZWJ/ZWNJ if no font is found for the cluster. + Add support for half width fonts. + Support time zone change notifications on linux. + Fix several crashes and rendering issues. - Changes from version 2.53.2: + Only use DMA-BUF mapping for writing to the GPU atlas when possible. + Do not resolve ‘-apple-system’ font to default system font. + Set real time limits when not using the portal. + Report support for supported non-AAC mp4a codecs. + Fix several crashes and rendering issues. - Changes from version 2.53.1: + Remove the option to use cairo for 2D rendering. + Implement GPU atlas creation and replay substitution for batched raster image uploads. + Improved non accelerated composited mode by using the same buffer sharing implementation as accelerated mode. + The on-demand hardware acceleration policy is now deprecated in GTK3 API. + Add new improved API for page favicons. + Add webkit_feature_list_find() to public API. + Support PGO features in regular CMake builds. + Fix several crashes and rendering issues. - Drop riscv-platformenable.patch: fixed upstream. - Rebase webkitgtk-ppc64le-build-fix.patch with quilt. ==== xdg-desktop-portal ==== Subpackages: xdg-desktop-portal-lang - Update version dependencies according to meson.build. ==== xterm ==== Version update (410 -> 411) Subpackages: xterm-bin xterm-resize - update to 411: * add a case for DECSWT in VT520 mode * correct an index computation in VS15/VS16 logic for - emoji_width option * add ich1 to terminfo where appropriate. * drop “GTK_*” from environment filtering * fix a couple of places in terminfo which used BEL rather than ST. * add DECSCUSR 7 for the “power-up” configuration, which can be different from the documented VT520 behavior * correct a limit-check added in patch #399, which resulted in regex-based selections to be limited to the first row of a wrapped line (Redhat #2479962). * add resource brokenCopyArea, using that to control whether XCopyArea is used for indexing and scrolling, as well as inserting or deleting characters and lines. * amend check for validity of C1 controls to check both whether wide-characters have been initialized, as well as whether the current encoding is UTF-8 (Debian #687699). * call Cleanup directly when processing SIGHUP, because the process running in xterm may ignore a killpg sent to the top-level screen's process (Debian #243598). ==== yelp ==== Subpackages: libyelp-1-0 yelp-lang - Update version dependencies according to meson.build.