Packages changed: apr-util (1.6.3 -> 1.6.5) babl (0.1.126 -> 0.1.128) cpio java-25-openjdk (25.0.4.0 -> 25.0.4.1) libvirt mozjs140 nghttp3 ngtcp2 openSUSE-release (20260826 -> 20260827) openssl-3 polkit-default-privs (1550+20260803.90784eb -> 1550+20260825.76d85e6) python-numpy (2.4.6 -> 2.5.2) qemu (11.0.3 -> 11.1.0) sdbootutil (1+git20260813.357956d -> 1+git20260825.c7a5a97) selinux-policy (20260820 -> 20260826) serd (0.32.8 -> 0.32.10) wpa_supplicant (2.11 -> 2.12) === Details === ==== apr-util ==== Version update (1.6.3 -> 1.6.5) - Update to 1.6.5. - Changes for APR 1.6.5: * Fix Win32 build breakage in apr_os_exp_time_put() in 1.6.4. - Changes for APR 1.6.4: * configure: Fix detection of on OpenBSD. * Fix apr_parse_addr_port() regression in scope_id parsing introduced. * Fix Win32 file buffer locking behavior for single threaded file streams. * Numerous corrections to APR poll behavior. ==== babl ==== Version update (0.1.126 -> 0.1.128) Subpackages: libbabl-0_1-0 libbabl-0_1-0-x86-64-v3 typelib-1_0-Babl-0_1 - Update to version 0.1.128: + avx512 support is now more extensively checked at runtime + exported symbols and library version, initial WASM support. ==== cpio ==== Subpackages: cpio-lang cpio-mt - Fix CVE-2026-66484: path traversal allows creating hard links outside intended directory via malicious tar archives (bsc#1274856) * CVE-2026-66484.patch - Fix CVE-2026-66485: denial of service via uncontrolled memory allocation from crafted archives (bsc#1274857) * CVE-2026-66485.patch - Fix CVE-2026-66486: terminal control sequence injection via crafted archive member names (bsc#1274858) * CVE-2026-66486.patch - Refresh patches to apply with -p1: * cpio-close_files_after_copy.patch * cpio-default_tape_dev.patch * cpio-dev_number.patch * cpio-eof_tape_handling.patch * cpio-open_nonblock.patch * cpio-use_new_ascii_format.patch * cpio-use_sbin_rmt.patch - Reorder patches, apply with %autosetup -p1 - Add makeinfo build requirement ==== java-25-openjdk ==== Version update (25.0.4.0 -> 25.0.4.1) Subpackages: java-25-openjdk-headless - Update to upstream tag jdk-25.0.4.1+1 (August 2026 CSPU) * Changes + JDK-8382471, bsc#1275777, CVE-2026-60589: Improve Resource Resolving + JDK-8384708, bsc#1275778, CVE-2026-61308: Enhance HTTP Connections + JDK-8386205, bsc#1275764, CVE-2026-70907: Enhance TLS server + JDK-8386298, bsc#1275763, CVE-2026-70906: Improve font loading + JDK-8388788: Bump update version for OpenJDK: jdk-25.0.4.1 + JDK-8389945: [25u] Remove designator DEFAULT_PROMOTED_VERSION_PRE=ea for release 25.0.4.1 - Added patch: * tzdata-2026c.patch + backport upcoming upgrade of timezone data (bsc#1275035) ==== libvirt ==== Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - CVE-2026-77159: qemu: tpm: Avoid following symlinks when chown'ing log file bsc#1274946 - CVE-2026-18917: remote: Fix integer overflow in RPC handler for virNodeGetFreePages bsc#1275863 ==== mozjs140 ==== - Update mozjs140-rust1.98.patch: Base the patch on upstream commited solution from commit 1ecaa12: andle the *-oe-linux-* rust targets added in rustc 1.98 in rust target detection. - Add mozjs140-rust1.98.patch: Fix detection of rust target when building against Rust 1.98 (build system gets confused by the new target x86_64-oe-linux-gnu). ==== nghttp3 ==== - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== ngtcp2 ==== Subpackages: libngtcp2-16 libngtcp2-16-32bit libngtcp2_crypto_gnutls8 libngtcp2_crypto_gnutls8-32bit libngtcp2_crypto_ossl0 - Require boringssl-devel >= 0.20260813 at build time: the previous 0.20210430 snapshot lacks SSL_set_quic_early_data_context, so configure rejected it with a misleading "boringssl was requested but not found" failure instead of an unresolvable dependency - Add ngtcp2-boringssl-shared.patch bulding the boringssl bridge as shared library - Enable building the boringssl bridge in Factory - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== openSUSE-release ==== Version update (20260826 -> 20260827) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openssl-3 ==== Subpackages: libopenssl3 libopenssl3-32bit libopenssl3-x86-64-v3 - Security fix: * CVE-2026-75803: openssl: AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() (bsc#1275837) * Add openssl-CVE-2026-75803.patch - Security fixes in August 2026 release: (bsc#1274774) * CVE-2026-14456: Unbounded Memory Growth in QUIC Server Incoming Channel Queue (bsc#1274791) * CVE-2026-14457: RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate (bsc#1274792) * CVE-2026-18798: QUIC Server May Trigger Double Free When Processing INITIAL Packet (bsc#1274777) * CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343) * CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795) * CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788) * CVE-2026-63073: Untrusted Sender DN Used as Format String in CMP Response Validation (bsc#1274796) * CVE-2026-63074: CMP Indefinite Cache Growth of ExtraCerts (bsc#1274797) * CVE-2026-63075: QUIC ACK-only Packet Retention Can Cause Memory Exhaustion (bsc#1274798) * CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790) * Add patches: openssl-CVE-2026-14456.patch openssl-CVE-2026-14457.patch openssl-CVE-2026-18798.patch openssl-CVE-2026-34181.patch openssl-CVE-2026-54874.patch openssl-CVE-2026-63072.patch openssl-CVE-2026-63073.patch openssl-CVE-2026-63074.patch openssl-CVE-2026-63075.patch openssl-CVE-2026-63076.patch ==== polkit-default-privs ==== Version update (1550+20260803.90784eb -> 1550+20260825.76d85e6) - Update to version 1550+20260825.76d85e6: * profiles: add lact profile-hook action (bsc#1274863) ==== python-numpy ==== Version update (2.4.6 -> 2.5.2) - Update to 2.5.2 * drop support for Python 3.11 * distutils has been removed * many expired deprecations, see below * many new deprecations, see upstream changes * static typing improvements * improved support for free threading * support for descending sorts Expired deprecations: * passing None as dtype to np.finfo will now raise a TypeError * numpy.cross no longer supports 2-dimensional vectors * numpy._core.numerictypes.maximum_sctype has been removed * numpy.row_stack has been removed in favor of numpy.vstack * get_array_wrap has been removed * recfromtxt and recfromcsv have been removed from numpy.lib._npyio in favor of numpy.genfromtxt * numpy.chararray (re-export of numpy.char.chararray) has been removed * bincount now raises a TypeError for non-integer inputs * numpy.lib.math (alias for the standard library math module) has been removed * data type alias 'a' was removed in favor of 'S' * _add_newdoc_ufunc(ufunc, newdoc) has been removed in favor of ufunc.__doc__ = newdoc - Drop numpy-buildfix.patch as distutils was dropped ==== qemu ==== Version update (11.0.3 -> 11.1.0) Subpackages: qemu-audio-spice qemu-block-curl qemu-block-nfs qemu-block-rbd qemu-chardev-spice qemu-guest-agent qemu-hw-display-qxl qemu-hw-display-virtio-gpu qemu-hw-display-virtio-gpu-pci qemu-hw-display-virtio-vga qemu-hw-usb-host qemu-hw-usb-redirect qemu-hw-usb-smartcard qemu-img qemu-ksm qemu-lang qemu-microvm qemu-pr-helper qemu-seabios qemu-tools qemu-ui-curses qemu-ui-gtk qemu-ui-opengl qemu-ui-spice-app qemu-ui-spice-core qemu-vgabios qemu-vmsr-helper qemu-x86 - Revisit the fix for bsc#1232712: * hw/display/xenfb: always register vfb and allocate console early (bsc#1232712) - Switch to ipxe-qemu: * [openSUSE][RPM] spec: stop building edk2-basetools and ipxe - Upgrade to version 11.1.0 The full list of changes are available at: https://wiki.qemu.org/ChangeLog/11.1 Highlights include: * Universal Flash Storage (UFS) emulation support for Write Booster (device-level caching) and Host-Initiated Defragmentation (HID) based on UFS 4.1 specification * vhost-host-user support for offloading real-time clock handling from the hypervisor when using virtio-rtc * GUI: improvements to virtual console handling/specifying of different character encoding and GTK/VNC improvements as well * ARM: support for new architectural CPU features (too many to list here, see full changelog) * ARM: support for new imx8mp-evk machine type (based on i.MX 8MM Evaluation kit) * ARM: 'virt' board support for specifying cache topology, 'hvf' accelerator now supports nested virtualization and vGIC * HPPA: updated to SeaBIOS-hppa v25 firmware, TLB insert fixes for HP-UX 9 * PowerPC: MPIPL support for PowerNV to preserve memory after an unexpected reset, as well as support for emulating a nest MMU * RISC-V: ISA exstention support for big-endian, Zbr/xbr0p93, Zvfbfa, fractional LMUL on vector SHA instructions, KVM support for Zicbop and BFloat16 extensions, and more * RISC-V: new board support for K230, support for Tenstorrent mvendorid, and other misc. fixes/features * s390x: KVM support for ASTFLE facility 2 (for nested) * and lots more... ==== sdbootutil ==== Version update (1+git20260813.357956d -> 1+git20260825.c7a5a97) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper - Update to version 1+git20260825.c7a5a97: * Refactor free space calculation * Do not use /proc/cmdline in half configured systems * Warning when the recovery PIN is not validated * Show default and booted snapshots with marks * Improve detection of snapshot systems * Fix when searching for a boot entry * Fix boot order and boot order entry * Create the entries directory in the ESP * Fix get_final_pcr parser * Keep btrfs error and show it when fails * Fix set -e early exit instances * Fix measure-pcr-validator when there is no terminal * Don't include measure-pcr-validator in initrd if TPM2 is not used * Update predictions even if crypttab did not change * Improve PCR 15 signing * Detect NAME=VALUE passed as parameters and complain * When asking a password, require a terminal * Filter some warnings from pcrlock * Detect directories that are not part of the snapshot * Write bash completion errors to /dev/null * Detect when t-u apply is done and avoid data corruption * Detect pcr-oracle leftovers * Show in title that it's the initial version for transactional systems * Manually generate PCR7 measurements * Regenerate pcrlock.json when it is missing ==== selinux-policy ==== Version update (20260820 -> 20260826) Subpackages: selinux-policy-targeted - Update to version 20260826: * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783) * named filetrans for netconfig (bsc#1275219) * Revert "Apply fix_unconfined.patch" (bsc#1275219) * sshd_session_t needs to access kanidm sshkeys (bsc#1275492) * Fix broken kanidm_sshkeys_t security context (bsc#1275492) * Initial policy for xrdp (bsc#1262291) ==== serd ==== Version update (0.32.8 -> 0.32.10) - update to 0.32.10 * Address new warnings in clang-tidy 22 * Fix writing quotes at the end of long literals ==== wpa_supplicant ==== Version update (2.11 -> 2.12) - Update to v2.12: * support RSN overriding (e.g., WPA3-Personal Compatibility Mode) * EHT/IEEE 802.11be/Wi-Fi 7 - more complete support - fix message validation issues that could enable DoS attacks - fix group key rekeying * enable SAE group 20 by default if SAE-EXT-KEY is enabled * reject unexpected SAE password identifier to avoid DoS attack against a specific STA * mandate use of SAE H2E when using password identifiers * assign VLAN when using SAE with PMKSA caching * support SPP A-MSDU negotiation * support IEEE 802.11bi functionality - changing SAE password identifiers - EPPKE - IEEE 802.1X/EAP in Authentication frames - Association frame encryption - PMKID privacy * remove the driver interface for now obsolete Host AP driver * remove the driver interface for now obsolete Atheros WEXT interface * move supported, basic, and Beacon TX rate configuration to be at BSS level instead of per-radio for all BSSs * fix various issues in Multiple-BSSID functionality * support OpenSSL 3.0 API changes * EAP-TEAP: protocol changes based on RFC 9930; this is not compatible with previous versions * support Automated Frequency Coordination (AFC) on the 6 GHz band * improve GAS/ANQP processing to support larger ANQP responses * a large number of other fixes, cleanup, and extensions * Remove included patches: - 0001-wpa_gui-Port-to-Qt6.patch - CVE-2025-24912.patch - CVE-2026-58374.patch - Require-network_ctx-and-AKMP-match-for-accepting-PMK.patch - SAE-Fix-crash-due-to-NULL-pointer-dereference-in-H2E.patch - mesh-Reject-AMPE-MIC-element-with-length-AES_BLOCK_S.patch - wpa_supplicant_support_pem_encoded_chain.patch * Refresh patches: - Revert-Mark-authorization-completed-on-driver-indica.patch - wpa_supplicant-alloc_size.patch - wpa_supplicant-flush-debug-output.patch - wpa_supplicant-sigusr1-changes-debuglevel.patch - Update build config * CONFIG_HE_OVERRIDES=y (Support HE overrides) * CONFIG_IPV6=y * CONFIG_SAE_PK=y (SAE Public Key, WPA3-Personal) * CONFIG_IEEE80211BE=y (enable native support for Wi-Fi 7) * CONFIG_PMKSA_PRIVACY=y (PMKSA caching privacy support) * CONFIG_IEEE8021X_AUTH=y (IEEE P802.11bi/D4.0, 12.16.5 ) * CONFIG_TLS_ENGINE_TRUSTED_PATH=y - Add RADIUS-Fix-Message-Authenticator-attribute-validatio.patch https://w1.fi/security/2026-5