Packages changed: Mesa (26.1.6 -> 26.2.0) Mesa-drivers (26.1.6 -> 26.2.0) MozillaFirefox-branding-openSUSE cifs-utils dracut (112+suse.28.g84b3ea7 -> 112+suse.29.gc0c5e1d) kernel-source (7.1.7 -> 7.1.8) lapack libpsl (0.23.1 -> 0.23.2) mozilla-nss openSUSE-release (20260811 -> 20260812) openssh (10.4p1 -> 10.5p1) selinux-policy (20260804 -> 20260810) suitesparse (7.12.2 -> 7.13.0) === Details === ==== Mesa ==== Version update (26.1.6 -> 26.2.0) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Apparently %patch -P 18 -p1 is ignored when the patch does not exist on TW. But seems to fail on older distributions. Remove the line for the dropped patch. - Update to 26.2.0 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.0 - drop patches u_PR-40161.patch - refresh patches n_drirc-disable-rgb10-for-chromium-on-amd.patch ==== Mesa-drivers ==== Version update (26.1.6 -> 26.2.0) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Apparently %patch -P 18 -p1 is ignored when the patch does not exist on TW. But seems to fail on older distributions. Remove the line for the dropped patch. - Update to 26.2.0 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.0 - drop patches u_PR-40161.patch - refresh patches n_drirc-disable-rgb10-for-chromium-on-amd.patch ==== MozillaFirefox-branding-openSUSE ==== - recognize Leap 15.6, 16.0 and 16.1 ==== cifs-utils ==== Subpackages: wb-cifs-idmap-plugin - Correctly fix shebangs in Python scripts (bsc#1270134). ==== dracut ==== Version update (112+suse.28.g84b3ea7 -> 112+suse.29.gc0c5e1d) - Update to version 112+suse.29.gc0c5e1d * fix(base): sanitize message written by die() to the emergency hook - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency hook script in die() (bsc#1274432) ==== kernel-source ==== Version update (7.1.7 -> 7.1.8) - Update patches.kernel.org/7.1.2-007-crypto-qat-remove-unused-character-device-and-I.patch (bsc#1012628 CVE-2026-64529 bsc#1274262). - Update patches.kernel.org/7.1.4-009-KVM-VMX-Grab-vmcs12-on-CR8-interception-update-.patch (bsc#1012628 CVE-2026-64604 bsc#1274286). - Update patches.kernel.org/7.1.4-014-platform-x86-intel-hid-Protect-ACPI-notify-hand.patch (bsc#1012628 CVE-2026-64603 bsc#1274295). - Update patches.kernel.org/7.1.4-019-rust-block-fix-GenDisk-cleanup-paths.patch (bsc#1012628 CVE-2026-64509 bsc#1274254). - Update patches.kernel.org/7.1.4-030-wifi-rtw89-correct-drop-logic-for-malformed-AMP.patch (bsc#1012628 bsc#1271359 CVE-2026-64506 bsc#1274228). - Update patches.kernel.org/7.1.4-039-iio-adc-ad_sigma_delta-fix-clear_pending_event-.patch (bsc#1012628 CVE-2026-64502 bsc#1274269). - Update patches.kernel.org/7.1.4-043-iio-adc-spear-Initialize-completion-before-requ.patch (bsc#1012628 CVE-2026-64602 bsc#1274294). - Update patches.kernel.org/7.1.4-081-ALSA-virtio-Validate-control-metadata-from-the-.patch (bsc#1012628 CVE-2026-64490 bsc#1274253). - Update patches.kernel.org/7.1.4-082-ALSA-ymfpci-check-snd_ctl_new1-return-value.patch (bsc#1012628 CVE-2026-64489 bsc#1274281). - Update patches.kernel.org/7.1.4-085-ALSA-cmipci-check-snd_ctl_new1-return-value.patch (bsc#1012628 CVE-2026-64486 bsc#1274243). - Update patches.kernel.org/7.1.4-091-ALSA-hda-cs35l41-Fix-firmware-load-work-teardow.patch (bsc#1012628 CVE-2026-64481 bsc#1274547). - Update patches.kernel.org/7.1.4-095-ALSA-ice1712-check-snd_ctl_new1-return-value.patch (bsc#1012628 CVE-2026-64480 bsc#1274239). - Update patches.kernel.org/7.1.4-097-ALSA-us144mkii-capture_urb_complete-redundant-u.patch (bsc#1012628 CVE-2026-64601 bsc#1274293). - Update patches.kernel.org/7.1.4-099-ALSA-usb-audio-avoid-kobject-path-lookup-in-Dua.patch (bsc#1012628 CVE-2026-64478 bsc#1274321). - Update patches.kernel.org/7.1.4-105-x86-fs-resctrl-Prevent-out-of-bounds-access-whi.patch (bsc#1012628 CVE-2026-64477 bsc#1274264). - Update patches.kernel.org/7.1.4-107-vfio-pci-Latch-disable_idle_d3-per-device.patch (bsc#1012628 CVE-2026-64476 bsc#1274245). - Update patches.kernel.org/7.1.4-108-vfio-pci-Release-the-VGA-arbiter-client-on-regi.patch (bsc#1012628 CVE-2026-64475 bsc#1274319). - Update patches.kernel.org/7.1.4-110-vfio-prevent-infinite-loop-in-vfio_mig_get_next.patch (bsc#1012628 CVE-2026-64474 bsc#1274316). - Update patches.kernel.org/7.1.4-114-Bluetooth-btusb-fix-use-after-free-on-registrat.patch (bsc#1012628 CVE-2026-64471 bsc#1274278). - Update patches.kernel.org/7.1.4-123-rust_binder-clear-freeze-listener-on-node-remov.patch (bsc#1012628 CVE-2026-64466 bsc#1274288). - Update patches.kernel.org/7.1.4-152-staging-vme_user-bound-slave-read-write-to-the-.patch (bsc#1012628 CVE-2026-64449 bsc#1274280). - Update patches.kernel.org/7.1.4-161-staging-rtl8723bs-fix-WEP-length-underflow-and-.patch (bsc#1012628 CVE-2026-64445 bsc#1274290). - Update patches.kernel.org/7.1.4-162-staging-rtl8723bs-fix-OOB-read-in-OnAssocRsp-IE.patch (bsc#1012628 CVE-2026-64444 bsc#1274265). - Update patches.kernel.org/7.1.4-166-staging-rtl8723bs-fix-OOB-reads-in-rtw_get_sec_.patch (bsc#1012628 CVE-2026-64441 bsc#1274261). - Update patches.kernel.org/7.1.4-167-staging-rtl8723bs-fix-OOB-write-in-HT_caps_hand.patch (bsc#1012628 CVE-2026-64440 bsc#1274258). - Update patches.kernel.org/7.1.4-168-crypto-amlogic-avoid-double-cleanup-in-meson_cr.patch (bsc#1012628 CVE-2026-64599 bsc#1274314). - Update patches.kernel.org/7.1.4-171-ksmbd-fix-use-after-free-of-a-deferred-file_loc.patch (bsc#1012628 CVE-2026-64437 bsc#1274271). - Update patches.kernel.org/7.1.4-172-net-af_key-initialize-alg_key_len-for-IPComp-st.patch (bsc#1012628 CVE-2026-64436 bsc#1274277). - Update patches.kernel.org/7.1.4-175-Bluetooth-MGMT-Fix-UAF-of-hci_conn_params-in-ad.patch (bsc#1012628 CVE-2026-64433 bsc#1274283). - Update patches.kernel.org/7.1.4-178-fs-ntfs3-validate-Dirty-Page-Table-capacity-in-.patch (bsc#1012628 CVE-2026-64432 bsc#1274231). - Update patches.kernel.org/7.1.4-179-ntfs-avoid-calling-post_write_mst_fixup-for-inv.patch (bsc#1012628 CVE-2026-64431 bsc#1274255). - Update patches.kernel.org/7.1.4-180-NTB-epf-Avoid-calling-pci_irq_vector-from-hardi.patch (bsc#1012628 CVE-2026-64430 bsc#1274257). - Update patches.kernel.org/7.1.4-187-netpoll-fix-a-use-after-free-on-shutdown-path.patch (bsc#1012628 CVE-2026-64424 bsc#1274256). ... changelog too long, skipping 865 lines ... - commit 7d2ce4d ==== lapack ==== Subpackages: libblas3 libcblas3 liblapack3 - Switch Conflicts with openblas alterative providers from libopenblas_{openmp,pthreads,serial}0 to compatlibopenblas_{openmp,pthreads,serial}0 when not built with alternatives enabled. - Fix aarch64 build on 15.x by properly forcing macro expansion and dropping redundant %{_lto_cflags} ==== libpsl ==== Version update (0.23.1 -> 0.23.2) - Update to version 0.23.2: * Fix a configure.ac typo (LC_ALL=Cdate) that made COPYRIGHT_YEAR ignore SOURCE_DATE_EPOCH and fall back to the current build date, so the copyright year embedded in the installed libpsl.h and in the psl.1 manual page is reproducible again * meson: derive the copyright date with portable C code instead of invoking the external date command * Drop the empty README file in favour of README.md ==== mozilla-nss ==== Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - Move the test suite into a separate multibuild flavour: * the test suite is 1465s of a 1586s build, of which only 83s is compiling nss itself, and 1278 packages build depend on nss, so a large part of the distribution waits on it * the default flavour now builds and packages only, the new test flavour runs the same suite completely unchanged * the test flavour ships no packages, so a red run blocks no rebuild * the sqlite3 command line tool is only used by the test suite and is now required by that flavour alone - No shipped file changes: the FIPS integrity checksums are produced by shlibsign in build and again in the install post step, both of which run before check, so the test suite only ever consumed them ==== openSUSE-release ==== Version update (20260811 -> 20260812) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== openssh ==== Version update (10.4p1 -> 10.5p1) Subpackages: openssh-clients openssh-common openssh-server - Update to openssh 10.5p1: = Potentially-incompatible changes * Portable OpenSSH now requires ECC (Elliptic Curve Cryptography) support in libcrypto, including support for the NISTP521 curve. ECC is included in the default build configurations of all versions of all libcrypto implementations currently supported by OpenSSH, including LibreSSL, OpenSSL, BoringSSL and AWS LC. The --without-openssl build configuration is not affected. = Security * ssh-agent(1): fix an interaction between agent locking and the session-bind@openssh.com extension that is used to identify forwarded agents. These binding requests were refused when the agent was locked, with the result that operations that were intended to be limited to local use only could be performed remotely, including the ability to add PKCS#11 tokens and make use of keys that had destination restrictions applied. Reported by sn0x-sharma * ssh(1): avoid potential realloc use-after-free in the client if a remote forwarding is added via the local session multiplexing socket while a remote forwarding open request is pending with the server. Report and fix from Brian Mingus of Cognatory * sshd(8): make the authorized_keys "restrict" keyword apply correctly to tunnel forwarding too (which is administratively disabled by default). Reported by Erichen, Institute of Computing Technology, Chinese Academy of Sciences = New features * ssh-keygen(1): add ability to set or clear the touch-required and verify-required flags on FIDO private keys when resetting a private key's passphrase. * ssh(1): tweak ordering of certificates tried during pubkey authentication to prefer FIDO keys that do not require user presence (touch) first, and FIDO keys that require user verification via PIN or biometrics last. This effectively tries low-friction authenticators before higher friction ones. * ssh(1): add a "ssh -Z user@host" mode that prints the keys that will be tried for public key authentication in the order that they will be used. * sshd(8) use setproctitle(3) to identify sshd-session when its acting as a post-authentication monitor. = Bugfixes * ssh-keyscan(1): make reading the server banner a non-blocking operation to prevent a stuck server from blocking a many-host keyscan from proceeding. * sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the packet code as this provides context of the failing peer (address, port, user, etc). * sshd(8): when signing hostkey proofs for a client UpdateHostKeys request, allow each hostkey to perform at most one signature operation. * sshd(8) fix GSSAPI option names, that were broken during a servconf.c refactoring in openssh-10.4; bz3974. * ssh-keygen(1): pass back errors from ed25519 key generation, which theoretically can fail. GHPR702. * sshd(8): move check of public key type against allowed algorithms to before parsing of the key sent by the peer. This removes at least some key parsing and verification paths from the pre-auth attack surface. Suggested by Christopher Paul Rohlf of Anthropic. * ssh-keygen(1): fix double frees (impossible to reach outside of a test harness), and also use freezero where possible. From Christopher Paul Rohlf at Anthropic. * sshd(8): fix ChannelTimeout and RekeyLimit not being applied in sshd_config Match blocks. * sshd(8): in sshd config dump mode, write all directives in mixed case for consistency = Portability * sshd(8): re-allow PAMServiceName inside a Match block, which was incorrectly disabled during a refactoring in openssh-10.4. bz3987 - Drop patch which is already included upstream: * 0001-Fix-GSSAPI-server-option-names.diff - Rebase patches: * openssh-7.7p1-fips.patch * openssh-7.7p1-pam_check_locks.patch * openssh-8.0p1-gssapi-keyex.patch * openssh-8.1p1-audit.patch * openssh-9.6p1-crypto-policies-man.patch ==== selinux-policy ==== Version update (20260804 -> 20260810) Subpackages: selinux-policy-targeted - Update to version 20260810: * (open)SUSE only sendmail fixes (bsc#1273901) ==== suitesparse ==== Version update (7.12.2 -> 7.13.0) Subpackages: libamd3 libcamd3 libccolamd3 libcholmod5 libcolamd3 libsuitesparseconfig7 libumfpack6 - Update to 7.13.0 * GraphBLAS 10.4.1: memory arenas, faster GhB MATLAB/Octave interface * ParU 1.1.2: backport to gcc 7.5.0 - Update to 7.12.3 * ParU 1.1.1: MATLAB mexFunction does not #include mkl.h on Intel systems * GraphBLAS 10.3.2: minor update for recent clang compilers * SuiteSparse_config 7.12.3: version update to match SuiteSparse. Require cmake 3.23 for CUDA -arch="all" parameter to nvcc. * CSparse 4.4.2: minor fix to build system; sync version with CXSparse * UMFPACK 6.3.8: sync definition and declaration of umf_row_search.