Packages changed: MicroOS-release (20260722 -> 20260723) btrfsprogs (7.0 -> 7.1) dracut (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) kf6-kimageformats libdrm mozilla-nss (3.124 -> 3.125) ngtcp2 (1.22.1 -> 1.24.0) open-vm-tools qemu selinux-policy (20260702 -> 20260715) srt (1.5.5 -> 1.5.6) vim wget === Details === ==== MicroOS-release ==== Version update (20260722 -> 20260723) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== btrfsprogs ==== Version update (7.0 -> 7.1) Subpackages: btrfsprogs-udev-rules libbtrfs0 libbtrfsutil1 - update to 7.1 * mkfs: * use GET_CSUMS ioctl (if provided by kernel, 7.2) to reuse existing checksums for --rootdir, works with --reflink to avoid reading file data * fix last block handling for reflink * fix handling of incompressible data extents * fix --rootdir size estimation when using hardlinks * fi mkswapfile: add option to specify page size, useful on ARM64 * check: add option to skip qgroup verification to speed up check * in experimental build, use V2 of tree search ioctl, this can use larger buffer * preliminary fscrypt support * enhance filesystem opening modes with more fine-grained support of partially damaged trees and allow to skip non-essential trees * other: * stability and error handling fixes * CI updates * updated tests * documentation updates ==== dracut ==== Version update (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) Subpackages: dracut-ima - Update to version 110+suse.45.geaec47e4: * fix(systemd-networkd): escape values from DHCP options (bsc#1264833, GHSA-x37p-6hhc-6628) * feat(base): add escape function implementing printf %q * fix(systemd-networkd): get DHCP options values from networkctl * fix(kernel-modules): include xhci-pci-prom21 for early USB ==== kf6-kimageformats ==== - Add upstream change (kde#523105) * 0001-HEIF-keep-reader-callback-table-alive.patch ==== libdrm ==== Subpackages: libdrm2 libdrm_amdgpu1 libdrm_intel1 - add upstream signing key and validate source signature ==== mozilla-nss ==== Version update (3.124 -> 3.125) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs - update to NSS 3.125 * no public releasenotes yet ==== ngtcp2 ==== Version update (1.22.1 -> 1.24.0) Subpackages: libngtcp2-16 libngtcp2_crypto_gnutls8 libngtcp2_crypto_ossl0 - Update to 1.24.0: * crypto: Add openssl libs to cryptotest * Add --disable-crypto configure option * crypto: Add ngtcp2_crypto_ossl_free * examples: Avoid the deprecated nghttp3 APIs * lib: Add recv_stop_sending callback * lib: Add ngtcp2_conn_set_max_stream_data_thresh * lib: Tweak ngtcp2_conn_set_max_stream_data_thresh * Remove max stream data thresh * Rewrite window filter from scratch * lib: Tweak app-limited detection * lib: Simplify app-limited conditions * Bump openssl to v4.0.1 * Bump boringssl * Bump aws-lc to v5.1.0 * Bump picotls * Bump wolfssl to v5.9.2-stable - Update to 1.23.0: * log: Faster logging * Use ULL consistently * Transit to closing state when sending application close * Specify QualifierOrder * Provide generic ngtcp2_max and ngtcp2_min * Add ngtcp2_secure_clear * Clear sensitive secrets and keys after use * Add const version * crypto: Add tests for token validation * Add const and remove duplicated code * Remove stale function declarations * crypto: Deal with overflow when computing token timeout * build(deps): bump actions/github-script from 8 to 9 * Revert "fix: prevent max_idle_timeout multiplication overflow in transport params decode" * Deal with large max_idle_timeout that could overflow in computation * Fix qlog params set stack overflow * Log enhancement * Bump LibreSSL to v4.3.1 by @nak3 in #2161 * pq: Adopt designated initializers * Add missing initialization for fields that are not used for CRYPTO * rst: Rename TCP centric variable names * bbr: Cap maximum drain rounds * GHA: Avoid azure Ubuntu mirror * Bump openssl to v4.0.0 * Bump boringssl * Bump picotls * Bump wolfssl to v5.9.1-stable * Bump aws-lc to v1.73.0 * Bump wolfssl to v5.9.1-stable in interop Dockerfile * lib: Apply absolute upper bound against CRYPTO data offset * Adopt sphinx version-add and version-deprecated directives * ppe: Robust ngtcp2_ppe_padding_size * ppe: Ensure packet protection sample with ngtcp2_ppe_dgram_padding_size * cubic: Add missing is_cwnd_limited reset after exiting slow start * Make bitwise operations robust * Make all private hex constants unsigned * lib: Ensure that unidirectional stream shutdown flags properly set * More unsigned hex integer literals * Fix strict aliasing issue in ngtcp2_get_varint * Net cleanup * Bump boringssl * Bump picotls * Bump libressl to v4.3.2 * Consider static const if possible ==== open-vm-tools ==== Subpackages: libvmtools0 - Remove all dependencies on update-desktop-files - open-vm-tools (PED-15231) Remove BuildRequires: update-desktop-files and %suse_update_desktop_file vmware-user-autostart from the spec file. ==== qemu ==== - Properly fix bsc#1268245: * [openSUSE][RPM] spec: fix missing unversioned ppc64 linker (bsc#1268245) ==== selinux-policy ==== Version update (20260702 -> 20260715) Subpackages: selinux-policy-targeted - fix cleanoldsepoldir.sh to properly handle migration markers when /var/lib/selinux doesn't exists (backported from SLFO_Main codebase) - Update to version 20260715: * Allow snapper_sdbootutil_plugin_t status and stop unit files(bsc#1271391) * Allow sdbootutil_t read and write snapperd_t pipes (bsc#1271391) - Update to version 20260713: * Fix wrong gen_requires in snapper_read_data_files (bsc#1271282) ==== srt ==== Version update (1.5.5 -> 1.5.6) - Update to version 1.5.6: + Security Notice: This release includes important security updates that address two significant CVE vulnerabilities affecting previous versions of the library. Users are strongly encouraged to upgrade to this version as soon as possible to benefit from these fixes and reduce exposure to the associated security risks. + The resolved CVEs are listed below: - CVE-2026-55869: Heap-Based Buffer Overflow in KMREQ Handling - CVE-2026-55868: Encryption State Machine Downgrade + Security Improvements: - Implemented security improvements for KMREQ buffer validation. This fix addresses a vulnerability where received message sizes were not verified against the destination buffer size during the copy process. The update enforces word-aligned validation to prevent overflows when copying to internal arrays. - Added strict validation of KMRSP wire length to prevent stack overflows. - Resolved an OOB read in LOSSREPORT range parsing. The logic previously read a "HI" sequence number word following a "LO" marker without verifying if the "HI" word existed in the wire payload. - Fixed an OOB read vulnerability in DROPREQ payload parsing. The handler now verifies that the wire payload meets the minimum 8-byte length requirement (two 32-bit sequence numbers) before attempting to process the request, preventing reads beyond the packet slot. - Introduced a guard in CRcvBuffer::dropMessage to reject requested drop ranges that extend beyond the end of the receiver buffer. + Important Bug Fixes: - Streamlined the library cleanup sequence by removing redundant post-cleaning of closed sockets. Architecture logic dictates that the Garbage Collector (GC) thread is the primary owner of socket deletion. Once the GC thread is joined, all sockets are considered deleted; further post-checks are unnecessary and avoid potential undefined behavior in cases where the library state might be corrupted. - Fixed a segmentation fault (SEGV) occurring during global or static initialization when ENABLE_HEAVY_LOGGING was active. + Build System Enhancements: - Transitioned the CI/CD pipeline to a robust Linux configuration matrix, serving as the modern replacement for Travis CI. The new system includes various platform and compiler combinations and incorporates specific fixes for MinGW builds and C++11 syntax compatibility. + Documentation Updates: Corrected a typographical error in the documentation regarding the separator used for searchParameters. ==== vim ==== Subpackages: vim-data-common vim-small - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). ==== wget ==== - Fix metalink regression from CVE-2026-58469 fix See: commit 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf from https://gitlab.com/gnuwget/wget [bsc#1272219, CVE-2026-58469] * CVE-2026-58469.patch