Packages changed: ImageMagick (7.1.2.30 -> 7.1.2.31) aaa_base (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202) apparmor bluez (5.82 -> 5.87) cryptsetup (2.8.7 -> 2.8.8) glslang (16.5.0 -> 16.6.0) gnome-shell (50.4 -> 50.5) kdump (2.1.9 -> 2.1.10) kernel-source (7.2.5 -> 7.2.6) libadwaita (1.9.3 -> 1.9.4) libapparmor mozjs140 (140.15.0 -> 140.16.0) mutter (50.4 -> 50.5) openSUSE-release (20260916 -> 20260917) python-pygit2 shaderc (2026.3 -> 2026.4) spice virtualbox (7.2.16 -> 7.2.18) virtualbox-kmp (7.2.16_k7.2.5_1 -> 7.2.18_k7.2.6_1) === Details === ==== ImageMagick ==== Version update (7.1.2.30 -> 7.1.2.31) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - version update to 7.1.2.31 * fix: use registered UHDR module name in policy check #8935 * Also create an SBOM for the portable builds. 482ae0e * Corrected file names. c3d83c6 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c 8f62023 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm 5904641 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r868-pmwh-fv2c 768bdd0 * Added missing include and corrected the module name. 07143f6 * Added missing coders. 7e99fb4 * Fixed the policy check for coders (GHSA-vcjj-32hg-qpx5) 82f373f * More fixes for GHSA-vcjj-32hg-qpx5. dcdbbf4 * Corrected the call to CheckPrimitiveExtent to fix the use of uninitialized heap memory (GHSA-6xf5-c3jx-rp39) 5d29c09 * Moved EscapeParenthesis to the ghostscript-private.h header file. e2bd884 * Escape the labels to prevent code injection (GHSA-5rg6-j44q-q892) 78378cd * Added missing define checks bd96dda * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4fq9-vrx7-gv92 c69f54e * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2w4h-697j-4vrm 86672a1 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qr53-hc3p-fc62 c311471 * Added missing include. 5ccfb2f * Added missing check for eof when using the custom stream reader in ReadBlob 78aff3a * Use a better algorithm to determine the numerator and denominator (GHSA-v45j-x8p4-3mh4) f491576 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v d779ac5 * initial framework for the c2pa coder b34352d * add header 9f2cb10 * add c2pa coder framework a4d1d62 * eliminate compiler warnings a37640f * Removed unused argument 0e94ad4 * Added missing null check to avoid a null pointer dereference (GHSA-92rw-c5mw-27v4) c4b3c90 * https://github.com/ImageMagick/ImageMagick/issues/8927 c717095 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67 282f455 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67 4fe3110 * framework for c2pa coder 7d25548 * add new exception for required manifest b14e552 * add C2PA define 837ec6f * include static header 03a79c3 * cosmetic beeb133 * c2pa decode poc 114618e * https://github.com/ImageMagick/ImageMagick/issues/8930 a96821a * https://github.com/ImageMagick/ImageMagick/issues/8930 c42d72d * create symbolic link only if input file exists d4f900a * correct c2pa delegate de7f30c * More fixes for GHSA-89wq-f8f6-2j2v b5da5ea * Updated the dependencies. 5f49dfb * More fixes for GHSA-5rg6-j44q-q892. 2ba2edf * for now, limit c2pa support to decoding only 977a278 * eliminate compile exception f557204 * eliminate compiler exception a92f423 * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jvjm-9f73-fhpq 8f3a15e * latest autoconf update 8cab7be * check >= limit 404450e * extra check not needed 32bbfb1 * revert e18959a * Removed unused code. ad464d1 * Trim labels to prevent code injection (GHSA-p6j5-2qwh-6486) 8309dc9 - modified patches * ImageMagick-library-installable-in-parallel.patch (refreshed) ==== aaa_base ==== Version update (84.87+git20260610.3b5a868c -> 84.87+git20260916.e122202) Subpackages: aaa_base-extras - Update to version 84.87+git20260916.e122202: * For new GNU Emacs 31.1: use lexical-binding * Let us now fix this syntax error in ls.bash - Update to version 84.87+git20260812.c6d42af: * added requires for gzip and tar to aaa_base-extras (boo#1274604) * fix(ls): deprecate ls.zsh * fix(ls.bash): use alias, func breaks sudo alias * fix(ls.bash): avoid breaking sudo alias expansion * drop dirs from the specfile, they live in the filesystem package ==== apparmor ==== Subpackages: apparmor-abstractions apparmor-docs apparmor-parser apparmor-parser-lang apparmor-profiles apparmor-utils apparmor-utils-lang python3-apparmor - update wg-quick.diff to fix setting DNS (boo#1265394) ==== bluez ==== Version update (5.82 -> 5.87) Subpackages: bluez-auto-enable-devices bluez-cups bluez-obexd bluez-zsh-completion libbluetooth3 - ver 5.87: * Patches removed: hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) hcidump-Fixed-malformed-segment-frame-length.patch (Source file does not exist anymore) bluez-mainloop-Only-connect-to-NOTIFY_SOCKET-if-STATUS-Sta.patch (included in upstream) CVE-2016-9800-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) CVE-2016-9804-tool-hcidump-Fix-memory-leak-with-malformed-packet.patch (Source file does not exist anymore) upstream changes: Fix issue with GATT database and out of sync errors. Fix issue with BASS and setting a stream to idle. Fix issue with BASS and rescanning broadcast sources. Fix issue with BAP and broadcast sink cleanup. Fix issue with BAP and endpoint configuration. Fix issue with BAP and ASE control point properties. Fix issue with BAP and BIG/BIS receiver QoS structures. Fix issue with AVRCP and tracking of TG and CT events. Fix issue with PBAP and Database Identifier length. Fix issue with MCP and ATT disconnect events. ver 5.86: Fix issue with number of retries on authentication failures. Fix issue with G.722 @ 16 kHz codec ID value reported by transport. Add support for Telephony interface. Add support for Ranging profile. Add support for GMAP service. Add support for TMAP service. ver 5.85: Fix issue with handling display of battery charge level. Fix issue with BASS permissions not requiring encryption. Fix issue with handling abort for OBEX SRM operation. Fix issue with handling device privacy. Add support for HFP call answer support. Add support for HFP simple 3-way call support. ver 5.84: Fix issue with AVRCP and handling invalid UTF-8 item name. Fix issue with exposing coordinate sets if LE Audio is disabled. Fix issue with BAP and not responding to SetConfiguration. Add support for BAP unicast endpoint reconfiguration. Add support for BASS and encrypted broadcast source. Add support for HFP and Call Line Identification. ver 5.83: Fix issue with handling BAP and removal of PAC. Fix issue with handling SID for broadcast receiver. Fix issue with handling HSP/HFP reconnection policy. Fix issue with handling cable pairing and Sixaxis controllers. Fix issue with handling virtual cable unplug for HID devices. Fix issue with handling service records for HID devices. Add support for AVDTP and TX timestamps. ==== cryptsetup ==== Version update (2.8.7 -> 2.8.8) Subpackages: cryptsetup-doc cryptsetup-lang libcryptsetup12 - Update to 2.8.8: * integritysetup: add support for keyed discards. An integrity device in standalone mode, with a keyed integrity algorithm like HMAC and enabled discards (TRIM), could be vulnerable to wiping part of the device using a discard pattern. This issue can be worked around by using a keyed discards filler. Once set, it is set permanently for the integrity device and cannot be reverted. Integritysetup now supports a new --allow-discards-keyed option. Once used, it will upgrade the superblock and activate keyed discards. After the upgrade, keyed discards are always used, even with the old --allow-discards option. Keyed discard is available since Linux kernel 7.3. Note: Integritysetup was intended to be used with non-cryptographic integrity protection only. If you need cryptographic protection, use LUKS2 and AEAD (discards are not supported). * Avoid time-of-check/time-of-use (TOCTOU) issue in LUKS header restore. The LUKS header restore function validates the provided header file and then reopens the same file path to restore the LUKS header. In a specifically crafted environment, a symlink flip could occur between validating and restoring the header, resulting in a different file being used for the LUKS header restore (potentially leaking the file content). The libcryptsetup now opens the device only once. The issue affects both LUKS1 and LUKS2. Note: LUKS header backup/restore is a system administrative task (similar to filesystem backup/restore) that must run in a secure environment. Such a backup is usually a multi-step process, and it is up to the caller to ensure security of that environment. * BITLK: harden metadata validation. If a crafted BITLK (BitLocker-compatible) image is opened, the allocated buffer size for the key can be incorrect. This can happen if the encryption is changed from AES-CBC-128 to a mode with an Elephant diffuser, without recalculating the stored key. Also, the data offset can be intentionally wrong, which could lead to an infinite loop when parsing metadata. Note that creating such an incorrect image requires knowledge of the disk password, as MAC protects the metadata, and this MAC is checked by cryptsetup. * Fix possible integer overflow in LUKS metadata parsing. On systems with a 32-bit integer size, the anti-forensic (AF) data size calculation could overflow, causing an application crash. * cryptsetup: fix local memory corruption bug in reencrypt init. If a device intended for reencryption contains more than 16 active LUKS2 keyslots or tokens, the reencryption initialization could corrupt internal memory, leading to an application crash. ==== glslang ==== Version update (16.5.0 -> 16.6.0) - Update to release 16.6.0 * Implemented `GL_EXT_cooperative_matrix_maintenance1`, `GL_EXT_optional_input_attachment_index`, and `DebugEntryPoint` for `NonSemantic.Shader.DebugInfo` 102. ==== gnome-shell ==== Version update (50.4 -> 50.5) Subpackages: gnome-extensions gnome-shell-calendar gnome-shell-lang - Update to version 50.5: + Fix keynav on unlock dialog + Fix glitch when switching workspaces with direct scanout + Support building with libical4 + Refuse to unlock screen after screen time limit was reached + Fix blocking when toggling wireless toggle + Don't show busy cursor when activating actions + Fix glitch when cancelling lock screen prompt with Esc + Track magnifier mouse position without polling + Limit parallel texture loading operations + Open windows created via new-window action on correct workspace + Don't duplicate locale keyboard layout + Cancel mount password dialogs when locking screen + Validate serialized image data before creating pixbuf + Fixed crash + Plugged leaks + Misc. bug fixes and cleanups + Updated translations. ==== kdump ==== Version update (2.1.9 -> 2.1.10) - upgrade to version 2.1.10 * calibrate: measure per-cpu requirements * kdumptool calibrate: take KDUMP_CPUS into account for PPC * PPC: round up KDUMP_CPUS on SMT systems to nearest threads-per-cpu * Set default KDUMP_CPUs to 4 (jsc#PED-16732, bsc#1239999) * add KDUMP_USE_CMA: experimental support for CMA reservation (jsc#PED-14553) - update calibrate values ==== kernel-source ==== Version update (7.2.5 -> 7.2.6) - RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables (git-fixes). - commit 3d19f11 - Update patches.kernel.org/7.2.4-160-nfsd-add-fh_want_write-for-early-verified-SETAT.patch (bsc#1012628 CVE-2026-89697 bsc#1280148). - Update patches.kernel.org/7.2.4-163-nfsd-block-non-SAVEFH-ops-after-FOREIGN-PUTFH-t.patch (bsc#1012628 CVE-2026-89696 bsc#1280146). - Update patches.kernel.org/7.2.4-164-nfsd-cap-decoded-POSIX-ACL-count-to-bound-sort-.patch (bsc#1012628 CVE-2026-89695 bsc#1280155). - Update patches.kernel.org/7.2.4-165-nfsd-check-client-ownership-when-cancelling-a-c.patch (bsc#1012628 CVE-2026-89694 bsc#1280151). - Update patches.kernel.org/7.2.4-166-nfsd-check-nfsd4_acl_to_attr-return-value-in-nf.patch (bsc#1012628 CVE-2026-89693 bsc#1280153). - Update patches.kernel.org/7.2.4-167-nfsd-clear-CALLBACK_RUNNING-on-failed-delegatio.patch (bsc#1012628 CVE-2026-89692 bsc#1280167). - Update patches.kernel.org/7.2.4-168-nfsd-clear-opcnt-on-compound-arg-release-to-pre.patch (bsc#1012628 CVE-2026-89691 bsc#1280163). - Update patches.kernel.org/7.2.4-172-nfsd-defer-vfree-of-compound-ops-to-fix-rpc_sta.patch (bsc#1012628 CVE-2026-89690 bsc#1280166). - Update patches.kernel.org/7.2.4-173-nfsd-don-t-free-session-slots-that-are-still-in.patch (bsc#1012628 CVE-2026-89689 bsc#1280174). - Update patches.kernel.org/7.2.4-174-nfsd-drop-the-stateid-not-the-stateowner-on-seq.patch (bsc#1012628 CVE-2026-89688 bsc#1280171). - Update patches.kernel.org/7.2.4-175-nfsd-ensure-nfsd_file_do_acquire-does-not-use-a.patch (bsc#1012628 CVE-2026-89687 bsc#1280173). - Update patches.kernel.org/7.2.4-176-nfsd-fix-BUG_ON-in-nfsd4_alloc_layout_stateid-o.patch (bsc#1012628 CVE-2026-89686 bsc#1280184). - Update patches.kernel.org/7.2.4-177-nfsd-fix-clock-domain-mismatch-in-clients_still.patch (bsc#1012628 CVE-2026-89685 bsc#1280179). - Update patches.kernel.org/7.2.4-178-nfsd-fix-cpntf-publish-race-in-nfs4_init_cp_sta.patch (bsc#1012628 CVE-2026-89684 bsc#1280178). - Update patches.kernel.org/7.2.4-179-nfsd-fix-dentry-ref-leak-on-V4ROOT-export-fileh.patch (bsc#1012628 CVE-2026-89683 bsc#1280193). - Update patches.kernel.org/7.2.4-180-nfsd-fix-fcache_disposal-UAF-by-inlining-dispos.patch (bsc#1012628 CVE-2026-89682 bsc#1280191). - Update patches.kernel.org/7.2.4-182-nfsd-fix-layout-fence-worker-double-reference-r.patch (bsc#1012628 CVE-2026-89681 bsc#1280189). - Update patches.kernel.org/7.2.4-184-nfsd-fix-nfsd_file-leak-on-inter-server-COPY-se.patch (bsc#1012628 CVE-2026-89680 bsc#1280206). - Update patches.kernel.org/7.2.4-185-nfsd-fix-null-dereference-in-nfsd4_setattr-for-.patch (bsc#1012628 CVE-2026-89679 bsc#1280203). - Update patches.kernel.org/7.2.4-186-nfsd-fix-partial-write-detection-in-nfsd_direct.patch (bsc#1012628 CVE-2026-89678 bsc#1280199). - Update patches.kernel.org/7.2.4-187-nfsd-fix-possible-fh_compose-of-wrong-dentry-in.patch (bsc#1012628 CVE-2026-89677 bsc#1280224). - Update patches.kernel.org/7.2.4-190-nfsd-fix-stale-s2s_cp_stateids-IDR-entry-for-as.patch (bsc#1012628 CVE-2026-89676 bsc#1280219). - Update patches.kernel.org/7.2.4-191-nfsd-fix-UAF-in-async-copy-cancel-and-shutdown.patch (bsc#1012628 CVE-2026-89675 bsc#1280216). - Update patches.kernel.org/7.2.4-193-nfsd-fix-XDR-length-calculation-in-nfsd4_ff_enc.patch (bsc#1012628 CVE-2026-89674 bsc#1280243). - Update patches.kernel.org/7.2.4-194-nfsd-fix-XDR-padding-calculation-in-ff_encode_g.patch (bsc#1012628 CVE-2026-89673 bsc#1280237). - Update patches.kernel.org/7.2.4-195-nfsd-gate-nfs2-setacl-by-argp-mask.patch (bsc#1012628 CVE-2026-89672 bsc#1280235). - Update patches.kernel.org/7.2.4-196-nfsd-gate-nfs3-setacl-by-argp-mask.patch (bsc#1012628 CVE-2026-89671 bsc#1280252). - Update patches.kernel.org/7.2.4-197-nfsd-hold-rcu-across-localio-cmpxchg-retry.patch (bsc#1012628 CVE-2026-89670 bsc#1280250). - Update patches.kernel.org/7.2.4-198-nfsd-initialize-copy-notify-stateid-before-publ.patch (bsc#1012628 CVE-2026-89669 bsc#1280251). - Update patches.kernel.org/7.2.4-200-nfsd-move-nfsd_debugfs_init-after-nfsd4_init_sl.patch (bsc#1012628 CVE-2026-89668 bsc#1280279). - Update patches.kernel.org/7.2.4-201-nfsd-close-shrinker-GC-fsnotify-vs-per-net-shut.patch (bsc#1012628 CVE-2026-89667 bsc#1280261). - Update patches.kernel.org/7.2.4-205-nfsd-release-OPEN-decoded-posix-ACLs-via-op_rel.patch (bsc#1012628 CVE-2026-89664 bsc#1280272). ... changelog too long, skipping 3681 lines ... - commit 16c1085 ==== libadwaita ==== Version update (1.9.3 -> 1.9.4) Subpackages: libadwaita-1-0 libadwaita-lang typelib-1_0-Adw-1 - Update to version 1.9.4: + AdwAnimation: Fix AdwCallbackAnimationTarget annotations + AdwActionRow: Ensure :use-markup property is set in constructed() + AdwTabBar/AdwTabGrid: Clear a dangling idle callback in dispose ==== libapparmor ==== - update wg-quick.diff to fix setting DNS (boo#1265394) ==== mozjs140 ==== Version update (140.15.0 -> 140.16.0) - Update to version 140.16.0: + See https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/ ==== mutter ==== Version update (50.4 -> 50.5) Subpackages: mutter-lang - Update to version 50.5: + Make software cursor overlay visibility per-view + Fix multiple monitors being reported as primary + Fix desaturated SDR content in HDR mode + Fix offscreen effect glitches on resource scale changes + Fix hang on external monitor hotplug + Fix direct scanout handling for captures without dma-buf + Prevent modifier release from stopping key repeat + Do not require EDID to generate device color profile + Handle cross GPU buffer scanout + Fix listing all supported fallback resolutions + Fixed crashes + Plugged leaks + Updated translations. ==== openSUSE-release ==== Version update (20260916 -> 20260917) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== python-pygit2 ==== - Exclude another broken test (bsc#1278723) - Fix BlobIO deadlock (gh#libgit2/pygit2#1488) * Fix-BlobIO-cleanup-deadlock.patch ==== shaderc ==== Version update (2026.3 -> 2026.4) - Update to release 2026.4 * Incorporate fixes for SPV_KHR_abort abortEXT(...) * glslc: option -fshader-stage now accepts all shader stage names as allowed in #pragma shader_stage()> This includes ray tracing, task, and mesh shader stages. ==== spice ==== - bsc#1278684 - Core dump messages when a vm is shut down on KVM/Qemu. Fix-keyboard-and-mouse-state-leaks-on-interface-removal.patch ==== virtualbox ==== Version update (7.2.16 -> 7.2.18) - Update to release 7.2.18 * Storage: Fixed data corruption in VDI differencing images after writing full blocks of zeroes and reopening the image. * Graphics: Fixed a VM process crash that could occur on Linux hosts with 3D acceleration enabled. * Shared Clipboard: Fixed the first character being removed from filenames when copying files located directly in a filesystem root. * Linux 7.3-rc support. - Drop kernel-7.3.patch (merged) ==== virtualbox-kmp ==== Version update (7.2.16_k7.2.5_1 -> 7.2.18_k7.2.6_1) - Update to release 7.2.18 * Storage: Fixed data corruption in VDI differencing images after writing full blocks of zeroes and reopening the image. * Graphics: Fixed a VM process crash that could occur on Linux hosts with 3D acceleration enabled. * Shared Clipboard: Fixed the first character being removed from filenames when copying files located directly in a filesystem root. * Linux 7.3-rc support. - Drop kernel-7.3.patch (merged)