Packages changed: Mesa (26.2.3 -> 26.2.4) Mesa-drivers (26.2.3 -> 26.2.4) MicroOS-release (20261001 -> 20261002) ModemManager NetworkManager (1.56.1 -> 1.58.1) bash-completion busybox faad2 (2.11.3 -> 2.11.4) ghostscript (10.07.1 -> 10.08.0) harfbuzz (14.5.0 -> 14.5.1) openssh poppler poppler-qt6 python-charset-normalizer (3.4.9 -> 3.5.2) python-oauthlib (3.3.1 -> 4.0.0) qemu rsync vim (9.2.0901 -> 9.2.1161) === Details === ==== Mesa ==== Version update (26.2.3 -> 26.2.4) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.2.4 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.4 - require llvm23 also for sle16 ==== Mesa-drivers ==== Version update (26.2.3 -> 26.2.4) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Update to 26.2.4 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.4 - require llvm23 also for sle16 ==== MicroOS-release ==== Version update (20261001 -> 20261002) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== ModemManager ==== Subpackages: libmm-glib0 - Update version dependencies according to meson.build. ==== NetworkManager ==== Version update (1.56.1 -> 1.58.1) Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Disable 464XLAT Customer-side Translator (CLAT) support on %ix86: + Introduce bcond_with/withot bpf build condition, based on arch + Pass -Dclat=false to meson when bpf is disabled + Only conditionally BuildRequire libbpf and cross-bpf-gcc - Update version dependencies according to meson.build. - Update to version 1.58.1: + Overview of changes since NetworkManager-1.58.0: - For private connections (the ones that specify a user in the "connection.permissions" property), the 802.1X "ca-path" and "phase2-ca-path" properties are no longer accepted and activation fails, as the daemon would otherwise let the owner of the profile choose the CA trust store used to validate the authentication server. Such profiles must clear those properties and use "ca-cert" or "system-ca-certs" instead. - Fix IPv4 forwarding not enabled on modem data interfaces. - Log a warning when ignoring DHCPv4 option 3 (Router) due to the presence of option 121/249 (Classless Static Routes) results in no gateway. - Set the parent interface by name for NBFT VLAN connections in the initrd generator to avoid race conditions at boot. - Perform the connectivity check also when the interface only has an IPv4 link-scope default route. - Ignore unspecified addresses as DNS nameservers from RDNSS and DHCPv6, and skip invalid nameservers when configuring systemd-resolved. - Fix auto-connect to SAE (WPA3) networks with key-mgmt=wpa-psk profiles. - Fix DNS server port number not forwarded to systemd-resolved for DNS URIs. - Fix normalization of Bluetooth NAP connections. - Fix multiple crashes. NetworkManager-1.58 + General: - Unify the versioning to use everywhere the scheme with the - rcX or -dev suffixes when appropriate. This affects, for example, the URL and filename of the release tarball and the version reported by nmcli and the daemon. As an exception, the C API will continue to use the 90+ scheme for RC versions. - Install the systemd units in the initramfs using a systemd generator. + Core: - Connection profiles with manual IP addressing and with gateways that are not directly reachable will generate a warning on activation and when they are added/modified via nmcli and nmtui. NetworkManager currently adds on-link routes for them automatically, but this will change in the future. To fix the warning, users should add addresses or routes whose subnets cover these gateways. A gateway (either the default gateway or the next-hop of a route) is considered directly reachable if it falls within the subnet of a direct route (a route without a next hop) or of a prefix route from a static address. - Use an internal implementation of the ping functionality when the "connection.gateway-ping-timeout" or "connection.ip-ping-addresses" properties are set, instead of relying on the "ping" tool. - Add support for CLAT (464XLAT) using a BPF program, controlled by the "ipv4.clat" property. CLAT is still disabled by default for now. - Change the default value of the ipv4.dhcp-ipv6-only-preferred property to a new value "auto" which automatically enables the option when CLAT is enabled ("yes" or "auto") in the connection profile. - Allow persisting the managed state across reboots from the D-Bus API and nmcli. time as a change to the managed state from the D-Bus API and nmcli. - IPv6 interfaces that receive PD via DHCPv6 are considered healthy without a non-temporary address. The delegated prefix can be used via an interface configured with "ipv6.method: shared" - Fix reapply not honoring the ipv6.ignore-auto-dns, ipv6.ignore-auto-routes and ipv6.never-default properties when DHCPv6 was not restarted (for example when the IPv6 DNS came from a DHCPv6 lease), so that DHCPv6-provided DNS and routes are now correctly suppressed on reapply without a connection restart. + Connectivity: - A new "check-connectivity" configuration option is available to disable the connectivity check for selected interfaces. - Restrict the connectivity check to use the DNS servers defined on the same link. If the link has no DNS servers, the connectivity check will use any servers available in the system. - Fix stale global connectivity state with connectivity checking enabled: NetworkManager could report limited connectivity while another device had full connectivity, or keep reporting limited after a device regained internet access. + DHCP: - The internal DHCPv4 client now ignores option 3 (Router) if the lease contains option 121 (Classless Static Route), as recommended by RFC 3442. - Fix an out-of-bounds read in the internal DHCPv4 client that an on-link attacker could trigger with a malformed UDP packet, crashing NetworkManager. - Validate hostnames and MUD URLs before pasting them into the dhclient configuration file, rejecting characters that could alter the config syntax (CVE-2026-10805). + Wi-Fi: ... changelog too long, skipping 80 lines ... translator) support. ==== bash-completion ==== - Based on the new fallback feature: split old delete list of completions in a fallback and a remove list and handle the to be removed like adb and the fallbacks like bts ==== busybox ==== - Fix pre-authentication heap buffer overflow in TLS caused by unit confusion in the Montgomery reduction buffer allocation (CVE-2026-88830, bsc#1282575) * 0001-tls-fix-undersized-buffer-calculation.patch - Fix httpd silently failing open when IP deny rules contain an invalid CIDR prefix length (CVE-2026-88831, bsc#1282550) * 0001-httpd-fix-handling-of-D-1.2.3-999.patch - Fix heap buffer overflow when parsing the volume ID of crafted romfs filesystem images (CVE-2026-88832, bsc#1282576) * 0001-volume_id-romfs-limit-the-maximum-size-of-label-to-V.patch - Fix out-of-bounds read in dpkg read_package_field() stepping past the NUL terminator on malformed .deb packages (CVE-2026-88835, bsc#1282551) * 0001-dpkg-free-results-of-read_package_field-preliminary-.patch * 0002-dpkg-reformat-code-in-read_package_field-exposing-wh.patch * 0003-dpkg-fix-cases-where-read_package_field-returns-offs.patch - Fix out-of-bounds read and silent corruption of the dpkg status file caused by write_status_file() not resetting the field_start cursor between package stanzas (CVE-2026-88841, bsc#1282653) * 0004-dpkg-fix-field-handling-in-write_status_file.patch - Fix httpd misidentifying yescrypt password hashes as plaintext (CVE-2026-88837, bsc#1282552) * 0001-httpd-allow-yescrypt-passwords-y.patch - Fix out-of-bounds write of heap pointers in the passwd/group parser due to a stale tokenize() endpoint (CVE-2026-88839, bsc#1282568) * 0001-libpwdgrp-tokenizer-fix-for-trailing-whitespace-remo.patch ==== faad2 ==== Version update (2.11.3 -> 2.11.4) - Update to version 2.11.4: + Fix the fixed-point SBR envelope estimate + Fix PNS decoding window offset clamping for short sequences + Add sample-accurate gapless MP4 container trimming (`elst` atom and `iTunSMPB` metadata support, including SBR decoder delay adjustment) + Fix `-g`/`--no-gapless` CLI option parsing and metadata tag handling + Fix mono HE-AAC channel counts and PS signaling for HE-AAC v2 MP4 files ==== ghostscript ==== Version update (10.07.1 -> 10.08.0) - Version upgrade to 10.08.0 See 'Recent Changes in Ghostscript' at Ghostscript upstream https://ghostscript.readthedocs.io/en/gs10.08.0/News.html * This release addresses a number of potential security issues. * The 10.08.0 release removes a number of old, unmaintained and (at the time of this release) untestable and thus unmaintainable devices from the default builds, as a precursor to removal of the device sources in the next release. This process will continue as development time allows. If you rely on any of the removed devices and are willing to help testing them, please get in touch at: bugs.ghostscript.com * The usual round of bug fixes, compatibility changes, and incremental improvements. - In particular it fixes CVE-2026-39919 "Heap buffer overflow in the JPEG 2000 (JPXDecode) output adapter via component subsampling mismatch (base/sjpx_openjpeg.c)" https://bugs.ghostscript.com/show_bug.cgi?id=709666 "heap-based buffer overflow in the JPEG 2000 output adapter allows attackers to cause memory corruption by supplying crafted PDFs" (bsc#1280620) ==== harfbuzz ==== Version update (14.5.0 -> 14.5.1) Subpackages: libharfbuzz-gobject0 libharfbuzz-subset0 libharfbuzz0 typelib-1_0-HarfBuzz-0_0 - Update to version 14.5.1: + Map the `fonupa` (Uralic Phonetic Alphabet) BCP 47 variant to the `UPPH` OpenType language system tag. + Produce smaller `cmap` subtables and drop no-op variation device tables when subsetting. + Fix possible deadlock in `hb_font_destroy()` after `hb_ft_font_set_funcs()`, a regression from 14.5.0. + Fix signed integer overflows when scaling glyph extents and applying synthetic slant and emboldening. + Fix float-to-int overflow in `VARC` component axis coordinates with malformed fonts. + Fix a memory leak in the experimental WebAssembly shaper when shaping with features. + Fix accumulator overflows in the experimental raster library when rendering glyphs with very many overlapping edges. + Fix heap buffer overflow in the experimental GPU library with malicious `COLR` fonts. + Various build and CI fixes. - Update version dependencies according to meson.build. ==== openssh ==== Subpackages: openssh-clients openssh-common openssh-server - Update openssh-8.4p1-ssh_config_d.patch with mentions of the configuration drop-in directories (bsc#1259462). - Add openssh-10.5p1-propagate-restrict-keyword.patch (bsc#1275079). - Drop obsolete -fstack-protector from CFLAGS/CXXFLAGS (added 2006, predates distro -fstack-protector-strong in optflags; the trailing basic flag silently downgraded strong to basic). ==== poppler ==== Subpackages: libpoppler-cpp3 libpoppler164 - ensure python3 is available due adding python3-base to Buildrequires ==== poppler-qt6 ==== - ensure python3 is available due adding python3-base to Buildrequires ==== python-charset-normalizer ==== Version update (3.4.9 -> 3.5.2) - Update to version 3.5.2 Fixed * Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. * Supported encodings without aliases failing name resolution or being ignored in charset declarations. - Update to version 3.5.1 Fixed * No longer decoding large content when the noise detector output give a high entropy. Only impacted large content input >1M bytes. - Update to version 3.5.0 Added * Explicit support for Python 3.15 Fixed * Comparing a CharsetMatch to a non-alias encoding strings (#773) * Return 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (#774). * A file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset. * iso2022* cases misdetected due to a flaw in our multibyte chunking logic. Changed * Replaced the optional mypyc build with Cython extensions while retaining the pure Python fallback. * Applied micro-optimization on several utils. * CharsetMatches no longer sort on each match insertion. Misc * Removed an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache). ==== python-oauthlib ==== Version update (3.3.1 -> 4.0.0) - Update to 4.0.0 (bsc#1283526, CVE-2026-49264, bsc#1283527, CVE-2026-49265) OAuth2.0 Provider: * Breaking: #951: Removed JSONP support from token revocation endpoint. * Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client. * #963: Improved PKCE code comparison Misc: * #904: Stop installing examples into site-packages. * #930: Add Python3.14, Python3.14t. * #932: Dropped EOL Python 3.8 from CI. ==== qemu ==== - Bugfixes and (spec-file) improvements: * vapic: confine the VAPIC region to 0xc0000..0xe0000 (bsc#1282077, CVE-2026-81627) * hw/9pfs: mutate FID path from main thread only (bsc#1282578, CVE-2026-93834) * [openSUSE][RPM] spec: drop qemu-ipxe Requires for ppc (bsc#1282918) * [openSUSE][RPM] spec: stub out all iotests when running under user emulation (e.g., for riscv64) * target/ppc/kvm: Use host compatibility mode for nested guests (bsc#1263864) * target/ppc/kvm: Add support for querying host compatibility mode (bsc#1263864) * linux-headers: Update to include KVM_CAP_PPC_COMPAT_CAPS (bsc#1263864) * file-posix: Tolerate unaligned hole at middle (bsc#1277435) * [openSUSE][RPM] spec: skip the tests that require get_mempolicy under linux-user * [openSUSE][RPM] build all firmware on riscv64 and fix user tests ==== rsync ==== - Limit the number of check jobs to the available jobs ==== vim ==== Version update (9.2.0901 -> 9.2.1161) Subpackages: vim-data-common vim-small - Update to 9.2.1161: 9.2.0958: Vim9: wrong type for the rest of a tuple in an unpack assignment 9.2.0959: tests: Test_xrestore() is flaky and cannot recover 9.2.0960: double-free in string_reduce() 9.2.0961: base64_encode() gives wrong result for a zero byte 9.2.0962: popup images are not using the kitty protocol properly 9.2.0963: crash when sound-folding a crafted spell file 9.2.0964: 'isprint' is applied to the leading byte of a character 9.2.0965: GTK4: blurry text rendering 9.2.0966: GTK4: window opens two lines too small 9.2.0967: hit-enter prompt eats keys from a running mapping 9.2.0968: status line height is wrong after exchanging or rotating windows 9.2.0969: runtime(shaderslang): matchit % breaks on braces 9.2.0970: buffered listener cannot obtain the text of a change 9.2.0971: "=~" and the match functions compile their pattern on every call 9.2.0972: extend() family does not accept a blob 9.2.0973: Vim9: internal error when a class member is initialized with a closure 9.2.0974: tests: Test_clientserver_serverlist_list() is flaky 9.2.0975: Vim9: assignment to a member of an object member fails 9.2.0976: Vim9: line continuation for command arguments is undocumented 9.2.0977: tests: test_terminal_visual_empty_listchars() is flaky 9.2.0978: terminal: empty lines don't use the background color of hl-terminal 9.2.0979: terminal: mouse stays enabled after Vim is killed with SIGTERM 9.2.0980: runtime(netrw): prioritize g:netrw_home on Neovim 9.2.0981: substitute: wrong text after undo of a confirmed \r 9.2.0982: tests: test_substitute leaves swapfiles behind 9.2.0983: 'laststatus' is ignored when creating a full-height vertical split 9.2.0984: runtime(zip): cannot adjust zip command line 9.2.0985: Multiline messages not visible when mapping starts cmdline 9.2.0986: long options are accepted with a trailing garbage 9.2.0987: heap-buffer-overflow in spell_suggest() 9.2.0988: tests: Test_terminal_csi_resize_oob() returns early 9.2.0989: libvterm: hang when rendering REP with no preceding char 9.2.0990: libvterm: crash when a scroll region outlives a resize 9.2.0991: autocmd: events are triggered for what happened while they were ignored 9.2.0992: popup filter gets the key at the hit-enter prompt 9.2.0993: runtime(netrw): error when parent dir of g:netrw_home doesn't exist 9.2.0994: Vim9: No error for :open during compilation 9.2.0995: tests: no check that g:netrw_home has higher priority than $MYVIMDIR 9.2.0996: debugger: crash when evaluating a variable in a :def function frame 9.2.0997: ch_sendexpr() cannot answer a request named with a string id 9.2.0998: Reject non-string-literal arguments to STRLEN_LITERAL 9.2.0999: serverlist() fails when there is no connection to the server 9.2.1000: Vim9: listener_add() fails when given only a callback 9.2.1001: complete_info() does not report the item highlight groups 9.2.1002: filetype: bazelrc files are not recognized 9.2.1003: popup: border is not shown when the popup does not fit 9.2.1004: a completion function cannot tell why it was called 9.2.1005: backupcopy=auto overwrites a file in place with umask 9.2.1006: fold functions do not accept window id 9.2.1007: fuzzy completion list wrongly sorted after complete() 9.2.1008: Vim9: hang when a line break is used before "->(" 9.2.1009: duplicate dict code in ins_compl_dict_alloc() 9.2.1010: compile error when folding feature is disabled 9.2.1011: [security]: arbitrary Ex command execution during C omni-completion 9.2.1012: tests: no enough testing for complete_info() "auto" 9.2.1013: [security]: out-of-bounds access in libvterm CSI 8 t resize 9.2.1014: [security]: overflow in undo file entry size check on 32-bit arch 9.2.1015: Vim9: v:errmsg is set while looking ahead at a command 9.2.1016: tests: viminfo bar line length overflow test fails under ASAN 9.2.1017: heap-use-after-free in ml_open_file() 9.2.1018: filetype: radvd config files are not recognized 9.2.1019: completion asked for during 'autocompletedelay' looks automatic 9.2.1020: autocmd: crash when 'eventignore' is changed while it is being set 9.2.1021: GTK: Cursor blinks irregularly 9.2.1022: popup: width changes while scrolling 9.2.1023: GvimExt: destructors of polymorphic classes are not virtual 9.2.1024: 'wildmode' list:full does not complete first match 9.2.1025: NFA regexp matching is slower than necessary 9.2.1026: heap-use-after-free via DiffUpdated autocommand 9.2.1027: runtime(helptoc): FuzzySearch() highlights matched characters at the wrong column 9.2.1028: redraw: cursor is left in the wrong place with an operator pending 9.2.1029: NFA regexp matching is slower than necessary 9.2.1030: using wrong printing font with pango 9.2.1031: 'wildmode' list:full does not show 'wildmenu' 9.2.1032: scrolling moves cursor up with 'scrolloffpad' 9.2.1033: session: sourcing fails on lambdas 9.2.1034: NFA regexp matching is slow for ASCII text 9.2.1035: filetype: Github citation files are not recognized 9.2.1036: syntax highlighting is slower than necessary 9.2.1037: crash when slicing a range() list with too many items 9.2.1038: CursorLineFold/Sign highlighting depends on 'cursorlineopt' 9.2.1039: MS-Windows: Unix domain socket channels fail 9.2.1040: matchfuzzypos() can be improved 9.2.1041: vim_strbyte() can be improved 9.2.1042: sign: placing many signs is slower than necessary 9.2.1043: matchlist() allocates empty strings for unmatched submatches 9.2.1044: Vim script execution is slower than necessary 9.2.1045: runtime(netrw): raises E46 when changing directory fails 9.2.1046: regex: case-insensitive match fails on multi-byte string with re=1 9.2.1047: Copying a List is slower than necessary 9.2.1048: session: syntax error when restoring session 9.2.1049: Cannot use the stdin and stdout of Vim as a channel 9.2.1050: tests: test_suspend() fails on Solaris 9.2.1051: getdigits() overflow behaviour is not portable 9.2.1052: filetype: evcxr history files are not recognized 9.2.1053: libvterm: characters can get a different width in a terminal window 9.2.1054: Virtual Replace mode: BS over multi-byte text eats the padding 9.2.1055: Vim9: a lambda with a block body fails to compile after error ... changelog too long, skipping 162 lines ... 9.2.0957: filetype: ArgoCD config file is not recognized