Packages changed: MicroOS-release (20260924 -> 20260929) aaa_base (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) bash (5.3.15 -> 5.3.20) bluez cairo (1.18.4 -> 1.18.6) dracut (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) flatpak (1.18.3 -> 1.18.4) fwupd (2.1.7 -> 2.1.8) gcr (4.4.0.1 -> 4.4.1) google-noto-coloremoji-fonts (20250916 -> 20260924) gpsd jeos-firstboot (1.5.9 -> 1.5.14) jitterentropy kernel-source (7.2.7 -> 7.2.8) kirigami-addons6 (1.13.0 -> 1.14.0) libX11 libXi libXpm libXtst libsecret (0.21.7 -> 0.21.8.2) libslirp (4.9.3+4 -> 4.9.5+1) libtasn1 libupnp (22.1.2 -> 22.1.5) llvm23 (23.1.1 -> 23.1.2) pam (1.7.2+git48 -> 1.7.3) pam-full-src (1.7.2+git48 -> 1.7.3) parted (3.7 -> 3.8) polkit-default-privs (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) python-cryptography (50.0.0 -> 50.0.1) readline (8.3.3 -> 8.3.6) shadow (4.20.2 -> 4.20.3) vlc (3.0.23 -> 3.0.24) xdg-dbus-proxy (0.1.8 -> 0.1.9) === Details === ==== MicroOS-release ==== Version update (20260924 -> 20260929) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== aaa_base ==== Version update (84.87+git20260916.e122202 -> 84.87+git20260924.144354a1) - Update to version 84.87+git20260924.144354a1: * change requires for aaa_base-extras also to pathes ==== bash ==== Version update (5.3.15 -> 5.3.20) Subpackages: bash-sh - Add upstream patches * Bash-5.3 Official patch 16 -- bash53-016 On recent versions of macOS, the pipe size is dynamic and changes due to system-wide total pipe usage, so we have to check whether or not bash can use the size determined at compile time. * Bash-5.3 Official patch 17 -- bash53-017 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * Bash-5.3 Official patch 18 -- bash53-018 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * Bash-5.3 Official patch 19 -- bash53-019 On some systems, macOS in particular, isalpha(3) returns true for bytes between 128 and 255. Bash uses this to determine whether or not these characters are permitted to be part of a shell identifier, and can consume one byte too many when determining the end of a variable name. * Bash-5.3 Official patch 20 -- bash53-020 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== bluez ==== Subpackages: bluez-cups libbluetooth3 - Add fix-crash-on-UUID-discovery.patch ==== cairo ==== Version update (1.18.4 -> 1.18.6) Subpackages: libcairo-gobject2 libcairo2 - Update to version 1.18.6: + The XCB surface triggered an UAF warning when building with GCC. + The clipping code was accessing various fields in a guard value, and causing a crash inside Inkscape. + Multiple fixes for the Windows backends, including improvements in the thread safety of the DirectWrite code. + The DirectWrite backend now supports COLRv1 fonts. + Multiple fixes for building with MSVC and ClangCL. + A leak in the PDF surfaces has been fixed. + Various gaps between abutting rectangles when drawing with ANTIALIAS_NONE were removed by using absolute coordinates and avoiding rounding errors. + Remove an overflow when computing the buffer size in the XRender code. - Refresh cairo-get_bitmap_surface-bsc1036789-CVE-2017-7475.diff with quilt. ==== dracut ==== Version update (112+suse.51.gf078a84 -> 112+suse.53.g97cbf62) Subpackages: dracut-ima - Update to version 112+suse.53.g97cbf62: * fix(fips): use BOOT_IMAGE_NAME instead of BOOT_IMAGE in path check ==== flatpak ==== Version update (1.18.3 -> 1.18.4) Subpackages: flatpak-selinux libflatpak0 system-user-flatpak - Update to version 1.18.4: + Security fixes: - Prevent privileged overwrite of arbitrary files with an empty file or a symlink to /run/host/monitor/resolv.conf when a malicious app is installed (CVE-2026-97024, GHSA-8xgq-v545-vgv) - Prevent privileged deletion of arbitrary files when a malicious app is installed (CVE-2026-97023, GHSA-5p67-xh8x-rq54) - When downloading apps or runtimes from an OCI repository that requires authentication, don't make the authentication token visible to other users (CVE-2026-97025, GHSA-7rvf-rqr3-43j4) - Restrict permissions on temporary repository directories in /var/tmp/flatpak-cache-* (CVE-2026-97026, GHSA-r9w3-qx54-qvc8) - Filter .desktop and D-Bus .service files against an allowlist of fields, preventing denial of service and unintended interactions with host services (CVE-2026-97027, GHSA-v64f-hrwr-j4vh) - Prevent apps from sending signals to a process group that includes a parent process outside the app, causing denial of service by killing the desktop environment (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2) + Bug fixes: - Update Meson wrap subprojects for projects that are normally taken from the host system: - xdg-dbus-proxy 0.1.9 (CVE-2026-93676, CVE-2026-94422) - Improve hardening against symlink traversal, related to CVE-2026-97023 and CVE-2026-97024 + Internal changes: - Add CVE IDs and reporter credits to 1.18.1's NEWS entry - Remove unnecessary U+200E LEFT-TO-RIGHT MARK from some older NEWS entries ==== fwupd ==== Version update (2.1.7 -> 2.1.8) Subpackages: libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.8: + This release adds the following features: - Add a new plugin to poke bootupd when the ESP changes - Add RSA-3072 signature verification support for Lenovo accessories + This release fixes the following bugs: - Add a workaround for the systemd-pcrosseparator.service PCR0 extension - Add hashes for the latest DBX for offline machines - Add user aware message to complete the dell-dock update - Allow enumeration BIOS settings to take either string or integer - Allow redfish firmware blobs up to 512MiB - Always use base-16 when parsing the UEFI capsule index - Do not allow a DFU altname or STM32 sector size of zero - Fix a buffer overwrite when parsing Synaptics CAPE HID reports - Fix a dell-dock crash via malformed EC_CMD_GET_DOCK_INFO response - Fix a file descriptor leak when getting firmware details - Fix a memory leak when parsing an invalid TPM eventlog - Fix a NULL deref when enumerating a broken synaptics-rmi device - Fix a snapd error when installing the latest dbx - Fix an integer underflow in Focal FP HID CRC parser - Fix eMMC error recovery command when setting install mode fails - Fix firmware recovery of Logitech Unifying devices - Increase the Huddly USB bulk write timeout to 30s - Invalidate the Wacom descriptor cache when the block count changes - Limit decompressing LZMA streams to 2GiB - Update PCB version checking logic in usi-dock - Use the stricter PolicyKit action ID when the device has gone - Verify the jcat item IDs before using them as filenames + This release adds support for the following hardware: - ASUS GX5407 - Elan PID 0CB6 - FocalTech MOC fingerprint sensors - Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000 - MaxLinear MxL862xx - MediaTek MT9700 FCTE and MT9701 KSMU - Pixart PID 4F01, 4F02, 4F0D and 4F0E - Rolling RW101 ==== gcr ==== Version update (4.4.0.1 -> 4.4.1) Subpackages: libgck-2-2 libgcr-4-4 - Update to version 4.4.1: + gcr: - Support zero mtime - Fix memory leak in GcrSystemPrompt call closure + docs: Fix a method reference in gcr_prompt_set_choice_label() + Updated translations. ==== google-noto-coloremoji-fonts ==== Version update (20250916 -> 20260924) - Update to v2.057 * Unicode 18.0 update - 19 new emojis (9 new emoji code points plus 10 skin-tone sequences for directional thumbs) ==== gpsd ==== - Fix for gpsprof arbitrary OS command execution via code injection in the attacker-controlled SKY.satellites[].used field, inserted unsanitized into a gnuplot heredoc data block; sat.used is now forced to a boolean (CVE-2026-60122 [bsc#1280016]) + 5a9c44a4.patch ==== jeos-firstboot ==== Version update (1.5.9 -> 1.5.14) - Update to version 1.5.14: * Refine the JEOS_USER_GROUPS option and use it for the builtin default * Read jeos-firstboot.conf in jeos-config as well * Add configuration variables on groups to add users to * Move welcome_screen_with_console_switch stub to end of file * Fix welcome_screen_with_console_switch undefined in jeos-config ==== jitterentropy ==== - OSR has to be at least 5 according to current reviews. (bsc#1282301) jitterentropy-minimum-osr.patch ==== kernel-source ==== Version update (7.2.7 -> 7.2.8) - Update patches.kernel.org/7.2.4-018-clocksource-drivers-timer-sun4i-Advertise-a-rea.patch (bsc#1012628 CVE-2026-93219 bsc#1282749). - Update patches.kernel.org/7.2.4-048-mm-huge_memory-skip-device-private-PMDs-in-madv.patch (bsc#1012628 CVE-2026-93218 bsc#1282748). - Update patches.kernel.org/7.2.4-050-mm-hugetlb-fix-boot-panic-with-CONFIG_DEBUG_VM-.patch (bsc#1012628 CVE-2026-93232 bsc#1282694). - Update patches.kernel.org/7.2.4-051-mm-hugetlb-initialize-gigantic-bootmem-hugepage.patch (bsc#1012628 CVE-2026-93230 bsc#1282693). - Update patches.kernel.org/7.2.4-054-mm-madvise-skip-device-private-PMDs-in-cold-and.patch (bsc#1012628 CVE-2026-93217 bsc#1282760). - Update patches.kernel.org/7.2.4-060-mm-mm_init-deferred_grow_zone-fix-out-of-range-.patch (bsc#1012628 CVE-2026-93227 bsc#1282696). - Update patches.kernel.org/7.2.4-061-mm-page_owner-use-memcg_data-snapshot-to-avoid-.patch (bsc#1012628 CVE-2026-93216 bsc#1282780). - Update patches.kernel.org/7.2.4-094-cdx-Fix-double-free-when-sysfs-file-creation-fa.patch (bsc#1012628 CVE-2026-93215 bsc#1282758). - Update patches.kernel.org/7.2.4-114-usb-gadget-f_tcm-fix-deadlock-in-usbg_make_tpg.patch (bsc#1012628 CVE-2026-93214 bsc#1282776). - Update patches.kernel.org/7.2.4-127-of-fix-out-of-bounds-read-in-of_alias_scan-stem.patch (bsc#1012628 CVE-2026-93213 bsc#1282775). - Update patches.kernel.org/7.2.4-144-nfsd-guard-nfsd_serv-deref-in-nfsd_file_net_dis.patch (bsc#1012628 CVE-2026-93212 bsc#1282774). - Update patches.kernel.org/7.2.4-162-nfsd-add-missing-read-barrier-to-rpc_status_get.patch (bsc#1012628 CVE-2026-93229 bsc#1282698). - Update patches.kernel.org/7.2.4-169-nfsd-convert-nfsd_net-boolean-flags-to-unsigned.patch (bsc#1012628 CVE-2026-93221 bsc#1282736). - Update patches.kernel.org/7.2.4-199-nfsd-initialize-DRC-hash-table-before-registeri.patch (bsc#1012628 CVE-2026-93211 bsc#1282740). - Update patches.kernel.org/7.2.4-243-smb-client-harden-DFS-cache-against-invalid-tar.patch (bsc#1012628 CVE-2026-93210 bsc#1282737). - Update patches.kernel.org/7.2.4-343-Bluetooth-hci_core-use-skb_get-instead-of-skb_c.patch (bsc#1012628 CVE-2026-93209 bsc#1282735). - Update patches.kernel.org/7.2.4-348-kasan-fix-cache-shrink-race-with-CPU-hotplug.patch (bsc#1012628 CVE-2026-93208 bsc#1282732). - Update patches.kernel.org/7.2.4-357-ipv6-use-RCU-iterator-to-dump-route-exceptions.patch (bsc#1012628 CVE-2026-93226 bsc#1282723). - Update patches.kernel.org/7.2.4-369-phy-fsl-imx8mq-usb-fix-typec-switch-leak-on-pro.patch (bsc#1012628 CVE-2026-93225 bsc#1282726). - Update patches.kernel.org/7.2.4-371-SUNRPC-Zero-rpc_gss_wire_cred-at-svcauth_gss_de.patch (bsc#1012628 CVE-2026-93207 bsc#1282672). - Update patches.kernel.org/7.2.4-393-svcrdma-Fix-unmatched-rn_unregister-on-failed-a.patch (bsc#1012628 CVE-2026-93224 bsc#1282703). - Update patches.kernel.org/7.2.4-398-svcrdma-Reject-Write-Reply-chunks-with-segcount.patch (bsc#1012628 CVE-2026-93228 bsc#1282697). - Update patches.kernel.org/7.2.4-401-udf-reject-VAT-indexes-equal-to-the-entry-count.patch (bsc#1012628 CVE-2026-89525 bsc#1282288). - Update patches.kernel.org/7.2.4-404-staging-media-tegra-video-fix-of_node_put-on-VI.patch (bsc#1012628 CVE-2026-93223 bsc#1282741). - Update patches.kernel.org/7.2.4-418-sched_ext-Keep-kick_sync-waiting-on-the-rq-s-ow.patch (bsc#1012628 CVE-2026-93220 bsc#1282750). - Update patches.kernel.org/7.2.4-486-lockd-fix-swapped-arguments-in-nlmsvc_match_ip.patch (bsc#1012628 CVE-2026-93231 bsc#1282778). - Update patches.kernel.org/7.2.4-534-PCI-proc-Use-file_ns_capable-when-checking-conf.patch (bsc#1012628 CVE-2026-93206 bsc#1282729). - Update patches.kernel.org/7.2.4-541-iommu-arm-smmu-v3-Manage-teardown-with-devm.patch (bsc#1012628 CVE-2026-93205 bsc#1282727). - Update patches.kernel.org/7.2.4-703-signal-avoid-shared-siginfo-namespace-rewrites.patch (bsc#1012628 CVE-2026-93222 bsc#1282742). - Update patches.kernel.org/7.2.5-097-mm-secretmem-properly-account-locked-pages.patch (bsc#1012628 CVE-2026-93243 bsc#1282687). - Update patches.kernel.org/7.2.5-128-memcg-bypass-the-reclaim-and-oom-killer-for-dyi.patch (bsc#1012628 CVE-2026-93241 bsc#1282781). - Update patches.kernel.org/7.2.5-129-memcg-make-the-v1-soft-limit-knob-inert.patch (bsc#1012628 CVE-2026-93240 bsc#1282779). - Update patches.kernel.org/7.2.5-146-arm64-mm-Fix-the-lockless-page-table-walk-in-sh.patch (bsc#1012628 CVE-2026-93239 bsc#1282681). ... changelog too long, skipping 1612 lines ... - commit 93e89db ==== kirigami-addons6 ==== Version update (1.13.0 -> 1.14.0) Subpackages: libKirigamiAddonsComponents6 libKirigamiAddonsStatefulApp6 libKirigamiApp6 - Update to 1.14.0 https://carlschwan.eu/2026/09/17/imprint-1.0-and-kirigami-addons-1.14.0/ ==== libX11 ==== Subpackages: libX11-6 libX11-data libX11-xcb1 - 0001-1281653_CVE-2026-94283_ximcp-bound-XIM_OPEN_REPLY-attribute-lengths-to-the-.patch * Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser (boo#1281653, CVE-2026-94283) - 0002-1281657_CVE-2026-94284_ximcp-bound-XIM_REGISTER_TRIGGERKEYS-keylist-lengths.patch * Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser (boo#1281657, CVE-2026-94284) - 0003-1281661_CVE-2026-94285_lcGenConv-bound-byteM_parse_codeset-reads-to-remaini.patch * Out-of-bounds read in libX11's byte-oriented codeset parser (boo#1281661, CVE-2026-94285) ==== libXi ==== - 0001-boo1281605_CVE-2026-93541_XQueryDeviceState-check-ValuatorClass-num_valuators-.patch * Out-of-bounds read in libXi's XQueryDeviceState() (boo#1281605, CVE-2026-93541) - 0002-boo1281606_CVE-2026-93542_size_classes-copy_classes-bound-XI2-class-lengths-to.patch * Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() (boo#1281606, CVE-2026-93542) - 0003-boo1281608_CVE-2026-93543_size_classes-copy_classes-enforce-XI2-per-type-class.patch * Out-of-bounds read in libXi's XI2 class parser (boo#1281608, CVE-2026-93543) - 0004-boo1281609_CVE-2026-93544_XIQueryDevice-keep-padded-name-and-class-bytes-withi.patch * Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing (boo#1281609, CVE-2026-93544) - 0005-boo1281612_CVE-2026-93545_XListInputDevices-validate-device-name-lengths-again.patch * Out-of-bounds read in libXi's XListInputDevices() (boo#1281612, CVE-2026-93545) - 0006-boo1281615_CVE-2026-94281_XListInputDevices-validate-class-lengths-cumulativel.patch * Out-of-bounds read in libXi's XListInputDevices() class parsing (boo#1281615, CVE-2026-94281) - 0007-boo1281651_CVE-2026-94282_wireToEnterLeave-validate-buttons_len-against-the-re.patch * Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversio (boo#1281651, CVE-2026-94282) ==== libXpm ==== - 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch * Denial of service via unsigned underflow in libXpm's write path (boo#1281669, CVE-2026-94287) ==== libXtst ==== - 0001-boo1281665_CVE-2026-94286_parse_reply_call_callback-check-element-size-against.patch * Out-of-bounds read in libXtst's RECORD reply parser (boo#1281665, CVE-2026-94286) ==== libsecret ==== Version update (0.21.7 -> 0.21.8.2) Subpackages: libsecret-1-0 typelib-1_0-Secret-1 - Update to version 0.21.8.2: + Release to bump meson.build version - Changes from version 0.21.8.1: + Make secret_item_load_secrets_sync match async behavior - Update to version 0.21.8: + Allow the content type to have additional parameters + Support individually encrypted items + Ensure we return chained up GTask + Ensure length of DH shared secret match length of prime on GnuTLS + file-backend: - Add thread safety and file-based locking to prevent concurrent write races - Fix possible memory leak in error path of secret_file_backend_real_search() + file-collection: Fix memory leaks on repeated calls + Replace some SecretSync with a sync implementation + Add linker version script to hide private symbols + Stop using CONST annotations on non-const fns + secret-tool: - Align behavior for collection option - Document --collection option + meson: Put test setup behind a feature option + Several test and CI improvements + Updated translations. ==== libslirp ==== Version update (4.9.3+4 -> 4.9.5+1) - Update to version 4.9.5+1: * note CVE numbers * Release v4.9.5 * Set UDP sockets in blocking mode * dhcpv6: fix bounding the reply against the interface MTU * dhcpv6: bound the reply against the interface MTU * ncsi: bounds-check OEM command bodies before dereferencing them * Release v4.9.4 * ip_input: update hlen on ip_reass * ip6_input: Trim mbuf to ip6-announced length * Fix reporting oob output * Note about the security contact - fixes CVE-2026-95507, CVE-2026-95508 ==== libtasn1 ==== - Update Source URLS - guard against future removal of egrep/fgrep ==== libupnp ==== Version update (22.1.2 -> 22.1.5) Subpackages: libixml22 libupnp22 - Update to release 22.1.5 * Fix SID matching for incoming GENA NOTIFY requests. [GHSA-ggw2-jjv9-h22c] - Update to release 22.1.4 * Stopped counting the read-head entity bytes against header sizes. * Sockets are now closed when http_OpenHttpGetEx() gets a bad response. ==== llvm23 ==== Version update (23.1.1 -> 23.1.2) - Update to version 23.1.2. * This release contains bug-fixes for the LLVM 23.1.0 release. This release is API and ABI compatible with 23.1.0. ==== pam ==== Version update (1.7.2+git48 -> 1.7.3) - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== pam-full-src ==== Version update (1.7.2+git48 -> 1.7.3) - Update to version 1.7.3: * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. * Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and * "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could * allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly * deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in * log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file * handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown * user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week * parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, * documentation improvements, and translation updates. ==== parted ==== Version update (3.7 -> 3.8) Subpackages: libparted-fs-resize0 libparted2 - switch from ftp to https for sources - updated parted.keyring - update to version 3.8 - update to version 3.7.14: - Fix gnu_read problems with block size > 512b - update to version 3.7.13: - Add support for ExFAT - Fix CVE-2026-89085 and CVE-2026-89088 - Add various checks for increased security ==== polkit-default-privs ==== Version update (1550+20260825.76d85e6 -> 1550+20260928.d1c0e7e) - Update to version 1550+20260928.d1c0e7e: * profiles: added datarecovery run-ddrescue action (bsc#1280118) ==== python-cryptography ==== Version update (50.0.0 -> 50.0.1) - update to 50.0.1: * Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2. ==== readline ==== Version update (8.3.3 -> 8.3.6) - Add upstream patches * readline83-004 If readline is invoked with the cursor somewhere other than column 0, and the prompt contains multibyte characters, the display algorithm needs to use a buffer offset, instead of the physical prompt length, to determine whether or not to reprint the prompt from column 0 because the cursor is before the last invisible character in the prompt string. * readline83-005 This patch fixes two problems with the redisplay code. The first is a crash that results if the initial prompt contains more than 256 wrapped lines. The second is a fix to the redisplay code when the first several characters of the prompt string are identical, but the prompt has changed and needs to be redrawn. If these first few characters are part of an escape sequence, the entire sequence needs to be redrawn. * readline83-006 If readline handles a SIGWINCH and resizes its idea of the screen dimensions, it needs to recompute the columns where the prompt wraps lines every time, not just when the screen width decreases. ==== shadow ==== Version update (4.20.2 -> 4.20.3) Subpackages: libsubid6 login_defs shadow-pw-mgmt - Update to 4.20.3: * Build error when using '--with-nscd=no' (bug introduced in v4.19.0). ==== vlc ==== Version update (3.0.23 -> 3.0.24) Subpackages: libvlc5 libvlccore9 vlc-noX vlc-qt - Update to version 3.0.24: + Codecs: - Use FFmpeg 8.1 (upgraded from 4.4) - Support APV decoder (FFmpeg 8) - Support Atrac3/Atrac9 decoding - Remove schroedinger support for dirac in favor of avcodec - Fix Speex leaks and packetization issues - Fix WebVTT CSS parsing and error handling - Fix FLAC and HEVC packetizer edge cases - Fix AudioToolbox MIDI synthesizer crash on macOS 26+ + Demuxers: - Add support for CEA-708 closed captions in MP4 - Expose ID3v2 metadata in MPEG demuxer - Improve subtitle language detection from filenames and SSA/ASS metadata - Fix several MKV crashes, leaks, hangs and malformed file handling issues - Fix AVI hang with zero-sized strd chunks - Fix MP4, MPEG-TS, Ogg, RealAudio and subtitle demuxing edge cases + Access: - Switch RIST input and output to librist, with main and simple profile support - Add SRT listener mode support - Add SFTP public key authentication options and ED25519 hostkey support - Update SMB2 share enumeration - Don't ship RealRTSP plugin (build disabled for all configurations) + Service Discovery: - Include Chromecast model in mDNS renderer names - Fix IPv6 addresses in Bonjour service URLs + Video Output: - Fix Direct3D11 adjust filter and texture leaks - Fix MediaCodec crop validation - Super Resolution scaling with Moore Threads GPUs + Interface: - Qt: Fix default open dialog location - Qt: Fix effects window geometry saving - Qt: Improve hotkeys dialog strings + Stream Output: - Disable HEVC for original Chromecast devices + Security: - Switch to a new RSA-4096 key for update verification - Fix multiple OOB, integer overflow, double-free and use-after-free issues - See https://www.videolan.org/security/ - CVE-2026-56711: picture: inline AllocatePicture() and use overflow helpers + Misc: - Add Flatpak build support - Fix Audio EQ filter High Frequency parameter - Fix artwork preparser crash when artwork title is null - Fix LibVLC media list player race - Remove NPAPI browser plugin + Lua: - Remove broken youtube.lua plugin - Drop vlc-gstreamer-1.28-build-fix.patch: fixed upstream. ==== xdg-dbus-proxy ==== Version update (0.1.8 -> 0.1.9) - Update to version 0.1.9: + Fix message filtering bypass vulnerabilities (CVE-2026-94422, GHSA-2cgv-pwcq-wvpq): - Don't allow method calls and signals to be treated as requested replies, even if they specify a reply serial number - Only allow replies that were sent to the appropriate destination + Improve automated tests to include attempts to exploit CVE-2026-94422