Packages changed: MicroOS-release (20260902 -> 20260904) SDL3 (3.4.14 -> 3.4.16) dmidecode ffmpeg-8 gcc16 gpg2 (2.5.21 -> 2.5.22) gpgme (2.1.2 -> 2.2.0) gpgmepp (2.1.0 -> 2.2.0) iproute2 (7.1 -> 7.2) kquickimageeditor6 (0.6.2.1 -> 0.7.0.1) libcupsfilters libgcrypt (1.12.2 -> 1.12.3) libjpeg-turbo libksba (1.8.0 -> 1.8.1) libnftnl (1.3.1 -> 1.3.2) mozilla-nspr (4.39 -> 4.40) mozilla-nss (3.126.1 -> 3.127) nftables (1.1.6 -> 1.1.7) python-tornado6 sdbootutil (1+git20260825.c7a5a97 -> 1+git20260903.f91f636) sdl2-compat (2.32.70 -> 2.32.72) suse-module-tools (16.1.6 -> 16.1.7) === Details === ==== MicroOS-release ==== Version update (20260902 -> 20260904) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== SDL3 ==== Version update (3.4.14 -> 3.4.16) - Update to release 3.4.16 * Fixed loading BMP files with < 8 bits per pixel and odd widths * Fixed the depth format sample count support check in the GPU API * Removed WM_TAKE_FOCUS from WM_PROTOCOLS for X11 windows * Report SDL_PenInputFlags in SDL_PenProximityEvent * Fixed vertical high-resolution mouse wheel scaling on evdev * Fixed joystick stick calibration on Nintendo Joy-Con controllers ==== dmidecode ==== - Display slot information for EDSFF (jsc#NVIDIA-68) * dmidecode-Display-slot-information-for-EDSFF.patch ==== ffmpeg-8 ==== Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Add ffmpeg-8-CVE-2026-75147.patch: Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU size in the keyframe search loop. (CVE-2026-75147, bsc#1276413) - Add ffmpeg-8-CVE-2026-75146.patch: Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative fragment index. (CVE-2026-75146, bsc#1276412) - Add ffmpeg-8-CVE-2026-75145.patch: Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow the OBU size to (long). (CVE-2026-75145, bsc#1276411) - Add ffmpeg-8-CVE-2026-75144.patch: Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data units larger than the RTP payload buffer. (CVE-2026-75144, bsc#1276410) - Add ffmpeg-8-CVE-2026-75143.patch: Backport 1c10bcc2 from upstream, avformat/librist: honor the caller buffer size in librist_read. (CVE-2026-75143, bsc#1276409) - Add ffmpeg-8-CVE-2026-75142.patch: Backport 9d786e4b from upstream, avformat/mpegenc: reject stream counts that overflow the system header. (CVE-2026-75142, bsc#1276408) - Add ffmpeg-8-CVE-2026-75141.patch: Backport acf5d7cd from upstream, avformat/hevc: reject hvcC NAL arrays that overflow the 16-bit count. (CVE-2026-75141, bsc#1276407) - Add ffmpeg-8-CVE-2026-70632.patch: Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 output wider than the plane. (CVE-2026-70632, bsc#1274289) - Add ffmpeg-8-CVE-2026-70631.patch: Backport 3c287af3 from upstream, avcodec/tiff: reject inflate output shorter than the strip. (CVE-2026-70631, bsc#1274287) - Add ffmpeg-8-CVE-2026-70630.patch: Backport c22667d0 from upstream, avcodec/screenpresso: reject deflate output shorter than the frame. (CVE-2026-70630, bsc#1274282) - Add ffmpeg-8-CVE-2026-70629.patch: Backport a5fe21a1 from upstream, avcodec/rscc: do not leave uninitilized data when the input is too short. (CVE-2026-70629, bsc#1274270) - Add ffmpeg-8-CVE-2026-70628.patch: Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid signed overflow in the capacity check. (CVE-2026-70628, bsc#1274268) - Add ffmpeg-8-CVE-2026-66037.patch: Backport f15e730c from upstream, avformat/iamf_parse: check count_label against the available bytes. (CVE-2026-66037, bsc#1272764) - Add ffmpeg-8-CVE-2026-66036.patch: Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support dynamic frame sizes. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-66036-shim01.patch Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject unsupported frame parameter changes. This patch is for facilitate ffmpeg-CVE-2026-66036.patch. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-65706.patch: Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the temp row buffer for the widest plane. (CVE-2026-65706, bsc#1272762) - Add ffmpeg-8-CVE-2026-65705.patch: Backport 30a52276 from upstream, avfilter/vf_floodfill: remove unneeded variables. (CVE-2026-65705, bsc#1272761) - Add ffmpeg-8-CVE-2026-65704.patch: Backport 52f7983f from upstream, avformat/ty: don't let the Series2 AC3 trim underflow the packet size. (CVE-2026-65704, bsc#1272760) - Add ffmpeg-8-CVE-2026-65703.patch: Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference frame before reallocating on size change. (CVE-2026-65703, bsc#1272759) - Add ffmpeg-8-CVE-2026-64834.patch: Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF objects smaller than their header. (CVE-2026-64834, bsc#1272757) - Add ffmpeg-8-CVE-2026-64833.patch: Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS core_size against the packet size in the HD path. (CVE-2026-64833, bsc#1272755) - Add ffmpeg-8-CVE-2026-58049.patch: Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit DLTA accesses stay within the row. (CVE-2026-58049, bsc#1269550) - Rename the ffmpeg BRPM back to ffmpeg-8 to make room for ffmpeg-9 to fill the role. [boo#1271606] - Rename the ffmpeg-8 BRPM to ffmpeg. [boo#1271606] ==== gcc16 ==== Subpackages: cpp16 libgcc_s1 libgomp1 libstdc++6 - Add gcc16-pr124811.patch to fix build reproducability when PCH is used - Add gcc16-znver6-cpuid.patch to fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390, make sure to configure s390x with - -disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ==== gpg2 ==== Version update (2.5.21 -> 2.5.22) - Update to 2.5.22: * gpg: New option "primary" for the --card-edit "generate" command. This option is useful create only the primary key on the first slot of an OpenPGP card * gpgsm: Emit issuer and serial no. when the certificate is not found * A range of bug fixes ==== gpgme ==== Version update (2.1.2 -> 2.2.0) - Update to 2.2.0: * gpgme_verify_result_t now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Handle the new SIGINFO status line * Ignore TRUST_ status lines if no NEWSIG was seen ==== gpgmepp ==== Version update (2.1.0 -> 2.2.0) - Update to 2.2.0: * Signature now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Added missing getters for the number of notations of a signature and the numbers of created signatures and of invalid signing keys of a signing result ==== iproute2 ==== Version update (7.1 -> 7.2) - Update to release 7.2 * dpll: Added frequency monitoring support * dpll: monitor: add -t/--timestamp and --tshort options * rdma: netns can now be specified by PID * bridge: vlan: Added support for neigh_forward_grat * netshaper: Added bw-min and weight parameter support * netshaper: Added group command for creating scheduling hierarchies * iplink: bridge: Added stp_mode support * devlink: Added dump support for resource show - Ditch libnetlink-devel. This was never really a public API, and mipv6d (its original user back in 2014) has long had its own copy of libnetlink. ==== kquickimageeditor6 ==== Version update (0.6.2.1 -> 0.7.0.1) Subpackages: kquickimageeditor6-imports libKQuickImageEditor1 - Update to 0.7.0.1: * Fix build on ARM with SVE - Update to 0.7.0: * Removed OpenCV dependency by replacing the stack blur with a Qt Concurrency and Highway SIMD library based implementation. * Added color adjustment API. * Added repainted signal to AnnotationDocument. AnnotationDocument periodically repaints annotationsImage and canvasBaseImage. * AnnotationDocument::renderToImage always returns the latest image. If necessary, it will wait for repaints to finish before returning. * Annotation shadows don't jitter as much while being drawn or resized. * Added hasSelectionChanged and optionsChanged signals to SelectedItemWrapper. * For more details see https://mail.kde.org/pipermail/kde-announce/2026-August/000524.html - Add %check ==== libcupsfilters ==== Subpackages: libcupsfilters2 - libcupsfilters-2.1.1-CVE-2026-64611.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/4b343522823403df01f6753082df83f07d18c217 backported to libcupsfilters 2.1.1 to fix CVE-2026-64611 "Infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4 "user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop" (bsc#1273145) - libcupsfilters-2.1.1-CVE-2026-64612.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 backported to libcupsfilters 2.1.1 to fix CVE-2026-64612 "Malformed PNG aborts CUPS image filter process (missing libpng setjmp recovery)" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch "authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG" (bsc#1273146) ==== libgcrypt ==== Version update (1.12.2 -> 1.12.3) - Update to 1.12.3: * Validate hash algorithm for use with RSA modulus * Validate parameters of Balloon KDF * Validate parallelism of Argon2 KDF * Fix parsing quoted parts and CRLF/LFCR in s-expression * Support BUFLEN check for GCRYMPI_FMT_SSH * Fix RSA PSS verify message length checking * Avoid a NULL ptr deref due to a unsupported genkey flag for ECC * Assert 32 KiB input cap in gcm_ctr_encrypt * Fix assertion failure in OCB when a buffered block becomes block 65536 * Fix OOB read in IMIT MAC verify of GOST28147 * Fix CMAC block-count truncation for 64 GiB writes * Fix AEAD spurious byte-counter carry for 4 GiB adds * Validate all KEM input lengths * Add length check of DATALEN when parsing s-expression * Only accept canonical value for S with EdDSA * Only accept canonical signatures for RSA * Fix an assertion failure for invalid small-order Ed25519 public keys * Validate length of supplied receiver public-key length in DHKEM decapsulation * Use a more strict value for the PKCS#1 minimal frame length. * Use just strong random for the Dilithium signature nonce and the Kyber encapsulation coins * Allow internal users to skip fast random poll for ciphers and hashes * Speedup sntrup761 by defer reduction in polynomial multiplication, reading random with a single call, and reducing freeze helpers w/o division * Avoid byte-wise load/store on RISC-V with Zicclsm * Use unaligned vector memory access on RSIV-V when supported * Add Intel SM4 instructions accelerated AVX512 and AVX2 implementation * Add Intel SM3 extension implementation * Add Intel SHA512 extension implementation * kyber: Accept and return a seed using the gcry_pk_genkey API * Add curve "ietf25" as alternative to "Curve25519" with exact RFC-8410 semantics. The name "X25519" was already used as an alias, thus this new name. * Add straight-line speculation hardening for function ends * Fix constant time memequal check for SM2 * Add post-quantum algorithm benchmarking to bench-slope * Due to the minor API updates and but with no newer branch released the SO name has been updated. - update upstream signing key ==== libjpeg-turbo ==== - do not skip djpeg12-shared-3x2-float-prog-cmp, use correct parameters instead ==== libksba ==== Version update (1.8.0 -> 1.8.1) - Update to 1.8.1: * Fix CMS parser to avoid possible infinite loop - drop libksba-nobetasuffix.patch, not needed when autoreconf is not run. Also don't run it. - Fix fgrep deprecation warnings in ksba-config --libs output boo#1203092 add libksba-1.8.1-fgrep-warning.patch, sent upstream ==== libnftnl ==== Version update (1.3.1 -> 1.3.2) - Update to release 1.3.2 * Support for connlimit stateful objects * Now validates geneve class and type attribute size in setter and validates that the kernel does not provide too long geneve data attributes. * Do not print userdata content through snprintf API. * Enhancements for the snprint API to display data according to size and byteorder, this includes new functions nftnl_{expr,set_elem}_set_imm() to decorate the data. * More improvements for the snprintf() API for set elements: no colon is printed if data is not provided, print object names in maps and print flags only if non-zero. ==== mozilla-nspr ==== Version update (4.39 -> 4.40) - update to version 4.40 * no upstream release notes found ==== mozilla-nss ==== Version update (3.126.1 -> 3.127) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs - update to NSS 3.127 * bmo#2060720 - Round ECH ClientHelloInner padding up to a multiple of 32 * bmo#2063071 - make selfserv listen on IPv6 wildcard on dual-stack hosts * bmo#2059176 - EC_DerivePublicKey() failure is not propagated in sftk_mkPrivKey() * bmo#2052210 - Generate additional test message for Thunderbird (HTML with remote image) * bmo#1869493 - Heap-buffer overflow in AES Keywrap * bmo#2054609 - remove cipher suite order exception from bug 946147 * bmo#2061107 - restore pkcs12.h for source compatibility * bmo#2056291 - remove support for pre-v1.0 PKCS#12 * bmo#2054719 - fix content type tag for CMS AuthEnvelopedData plaintext * bmo#2060118 - remove DH_GenParam support * bmo#2053831 - clang format * bmo#2054714 - avoid leaking stale ECH outer extensions across HRR * bmo#2053831 - Drop CKF_VERIFY flag from CKM_HKDF_DATA derivation in ECH GREASE * bmo#2053831 - Adjust PK11_Derive and TLS 1.3 derivation templates for CKM_HKDF_DATA and CKO_DATA compliance * bmo#2053831 - Use CKF_HKDF_SALT_DATA in tls13_HkdfExtract for CKO_DATA keys per PKCS#11 v3.2 * bmo#2057184 - Enable -Wunused-but-set-variable/-global in werror.py * bmo#2056846 - Remove unused policy string callback to fix - Wunused-but-set-global * bmo#2052709 - Convert NSS 3.126 release notes to Markdown * bmo#2052709 - Rename doc/rst to doc/src and update references * bmo#2052709 - Apply markdownlint to the converted Markdown docs * bmo#2052709 - Fix Markdown documentation build warnings * bmo#2052709 - Convert documentation from reStructuredText to Markdown (automated) ==== nftables ==== Version update (1.1.6 -> 1.1.7) Subpackages: libnftables1 python313-nftables - Update to release 1.1.7 * Fix spurious EEXIST error when using the create element command with large batches. * Improve error reporting for syntax errors by printing expected tokens. * Set element support for multi-statements, e.g. counter + quota. * Connlimit support with maps. * Support for using bitmask datatypes as set key, e.g. tcp flags. - Delete support-reproducible-build.patch (merged) ==== python-tornado6 ==== - Add patch run-multi-process-in-fresh-process.patch: * Run test_multi_process in a fresh subprocess to avoid a warning. ==== sdbootutil ==== Version update (1+git20260825.c7a5a97 -> 1+git20260903.f91f636) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper sdbootutil-tukit - Update to version 1+git20260903.f91f636: * Include FIDO2 unlocked devices for ordering (bsc#1234010) * Test in parallel for speed up * Add --repair parameter to cleanup * Fix shellcheck complain * Report entries with missing files * Avoid duplicate entries in non-snapper systems * Add initial tests for sdbootutil * Report the error if bootctl clean fails - Update to version 1+git20260901.41540d5: * No warn if a component is not in the event log * Add status command * Select the new sdbootutil if available * Skip blank lines in measure-pcr-generator.sh * Do not change crypttab for unrelated entries * Report the bad PCR when update-prediction fail * Do not write the recovery PIN in the journal * Improves non snapshot system support * Update help message for --measure-pcr * Report when PCR 7 is dropped because shim update * Add --strict parameter for --pcr policy * Report dropped PCRs via a warn * Adjust the limits for PolicyOR issues * Avoid update predictions if the service is up * Keep the exit status of sdbootutil call - Update to version 1+git20260827.786f9a8: * Do not accept empty passwords * jeos-firstboot-enroll: report errors also in the journal * Restore old crypttab via the exit trap * Update CLAUDE data * Detect half created openssl keys * check_enrolled report when something was written in the LUKS2 header * Improve a bit the disk-encryption-tool keyslot detection * Avoid leak of env var secrets * Wipe the d-e-t key in the enroll service and jeos module * Remove the correct keyslot left by d-e-t * Differentiate tpm2 and tpm2+pin for unattended unlock * Use is_same_device in detect_tracked_device and drop greps * Refactor check to avoid shellcheck complain * Parse the entry file in a sigle place * Validate the entry with the new kernel name * Refactor enrollment interface and deprecate the old one * New kernels will have different hash * Warn If no crypttab entry found * Extend is_same_device * jeos-firstboot-enroll: validate the passwords * sdbootutil-enroll: report when no encryption method is provided * Write recovery pin after enrollment in jeos module * Write recovery pin after enrollment * Improve error detection in sdbootutil-enroll * Increase keyctl timeout * Merge require_unlock and set_unlock_method * Be sure that the terminal check works with snapper * Renerate initrd when new measure-pcr keys are created * Separate ask-* parameters * Fix reading credential and keyctl password * Get the device password for each enrolling mechanism * Drop elements from crypttab if the enrollment fails * Validate the enrollment for each method * Add warning when enrolling FIDO2 token ==== sdl2-compat ==== Version update (2.32.70 -> 2.32.72) - Update to release 2.32.72 * Fixed a crash during the menu transition in Super Mario War. * Fixed menu rendering in The Ur-Quan Masters. * Fixed loading screen flickering in Payday 2. * Fixed the pointer position in Augustus when screen scaling is enabled. * Fixed an out of bounds exception in the OBS plugin "input-overlay" when using the new Steam Controller. ==== suse-module-tools ==== Version update (16.1.6 -> 16.1.7) Subpackages: suse-module-tools-scriptlets - Update to version 16.1.7: * If no initrd is found rebuild it (gh#openSUSE/suse-module-tools#133)