Packages changed: MozillaFirefox (154.0 -> 155.0) SDL3 (3.4.14 -> 3.4.16) cups-filters dmidecode emacs ffmpeg-8 gcc16 gegl gimp gpg2 (2.5.21 -> 2.5.22) gpgme (2.1.2 -> 2.2.0) gpgmepp (2.1.0 -> 2.2.0) imlib2 (1.12.6 -> 1.12.7) iproute2 (7.1 -> 7.2) kquickimageeditor6 (0.6.2.1 -> 0.7.0.1) libcloudproviders (0.4.0 -> 0.4.1) libcupsfilters libgcrypt (1.12.2 -> 1.12.3) libjpeg-turbo libksba (1.8.0 -> 1.8.1) libnftnl (1.3.1 -> 1.3.2) mozilla-nspr (4.39 -> 4.40) mozilla-nss (3.126.1 -> 3.127) nftables (1.1.6 -> 1.1.7) openSUSE-release (20260902 -> 20260904) publicsuffix (20260819 -> 20260902) python-tornado6 re2c (4.5.1 -> 4.6) salt sdbootutil (1+git20260825.c7a5a97 -> 1+git20260903.f91f636) sdl2-compat (2.32.70 -> 2.32.72) suse-module-tools (16.1.6 -> 16.1.7) tcl yast2-bootloader (5.0.33 -> 5.0.42) === Details === ==== MozillaFirefox ==== Version update (154.0 -> 155.0) Subpackages: MozillaFirefox-branding-upstream MozillaFirefox-translations-common - Mozilla Firefox 155.0 https://www.firefox.com/en-US/firefox/155.0/releasenotes MFSA 2026-82 (bsc#1278001)) * CVE-2026-84117 (bmo#2053320) Privilege escalation in Firefox for Android * CVE-2026-84118 (bmo#2057457) Use-after-free in the JavaScript: GC component * CVE-2026-84119 (bmo#2057817) Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120 (bmo#2058911) Use-after-free in the Audio/Video component * CVE-2026-84121 (bmo#2059018) Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122 (bmo#2059965) Use-after-free in the Audio/Video component * CVE-2026-84123 (bmo#2060047) Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124 (bmo#2061110) Use-after-free in the DOM: Core & HTML component * CVE-2026-84125 (bmo#2063871) Use-after-free in the DOM: Core & HTML component * CVE-2026-84126 (bmo#2063893) Incorrect boundary conditions in the Layout: Grid component * CVE-2026-84127 (bmo#1699444) Information disclosure in the WebExtensions component in Firefox for Android * CVE-2026-84128 (bmo#2044280) Privilege escalation in the WebDriver BiDi component * CVE-2026-84129 (bmo#2055028) Site isolation issue in the DOM: Navigation component * CVE-2026-84130 (bmo#2057834) Information disclosure in the Graphics: WebGPU component * CVE-2026-84131 (bmo#2060008) Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132 (bmo#2063020) Information disclosure in the Networking: HTTP component * CVE-2026-84133 (bmo#2032388) Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134 (bmo#2044882) Other issue in the Profile Backup component * CVE-2026-84135 (bmo#2046661) Other issue in Firefox Focus for Android * CVE-2026-84136 (bmo#2048699) Other issue in the DOM: Navigation component * CVE-2026-84137 (bmo#2051146) Spoofing issue in the DOM: Core & HTML component * CVE-2026-84138 (bmo#2056164) Denial-of-service in the PDF Viewer component * CVE-2026-84139 (bmo#2060153) Clickjacking issue in the DOM: Events component * CVE-2026-84140 (bmo#2063780) Site isolation issue in the DOM: Navigation component * CVE-2026-84141 (bmo#2063994) Integer overflow in the Graphics: ImageLib component * CVE-2026-84142 (bmo#2029421, bmo#2040889, bmo#2045313, bmo#2045435, bmo#2048796, bmo#2053150, bmo#2053578, bmo#2057356, bmo#2058621, bmo#2058626) Internally found bugs fixed in Firefox 155 * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107, bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088, bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109, bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301, bmo#2061325) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726, bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013, bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661, bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144, bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495, bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775, bmo#2061799, bmo#2062395, bmo#2062404) Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001, bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027, bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285, bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400, bmo#2062419) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 - requires * NSPR >= 4.40 * NSS >= 3.127 - glxtest, vaapitest, v4ltest and vulkantest unshipped in favor of gfxtest - Mozilla Firefox 154.0.1 https://www.firefox.com/en-US/firefox/154.0.1/releasenotes * Fixed slower access to saved passwords and unexpected Primary Password prompts caused by recent changes to password storage. (bmo#2064411, bmo#2065593, bmo#2063993) * Fixed an issue where addresses were failing to autofill on some sites. (bmo#2065145, bmo#2063599) * Fixed Firefox adding a new Start Menu shortcut on Windows every time it started. (bmo#2064652) * Fixed an issue where connections to local network devices were ... changelog too long, skipping 6 lines ... start when the system font was MS UI Gothic. (bmo#2056856) ==== SDL3 ==== Version update (3.4.14 -> 3.4.16) - Update to release 3.4.16 * Fixed loading BMP files with < 8 bits per pixel and odd widths * Fixed the depth format sample count support check in the GPU API * Removed WM_TAKE_FOCUS from WM_PROTOCOLS for X11 windows * Report SDL_PenInputFlags in SDL_PenProximityEvent * Fixed vertical high-resolution mouse wheel scaling on evdev * Fixed joystick stick calibration on Nintendo Joy-Con controllers ==== cups-filters ==== Subpackages: cups-filters-cups-browsed - cups-filters-1.28.17-CVE-2026-64611.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/4b343522823403df01f6753082df83f07d18c217 backported to cups-filters 1.28.17 to fix CVE-2026-64611 "Infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4 "user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop" (bsc#1273145) - cups-filters-1.28.17-CVE-2026-64612.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 backported to cups-filters 1.28.17 to fix CVE-2026-64612 "Malformed PNG aborts CUPS image filter process (missing libpng setjmp recovery)" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch "authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG" (bsc#1273146) ==== dmidecode ==== - Display slot information for EDSFF (jsc#NVIDIA-68) * dmidecode-Display-slot-information-for-EDSFF.patch ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Include libdir site-lisp for native modules in load-path by default. boo#1277717 - Add workaround for race in process-tests.el on s390x ==== ffmpeg-8 ==== Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Add ffmpeg-8-CVE-2026-75147.patch: Backport 983dae9c from upstream, avformat/rtpenc_av1: bound OBU size in the keyframe search loop. (CVE-2026-75147, bsc#1276413) - Add ffmpeg-8-CVE-2026-75146.patch: Backport 65b0dab9 from upstream, avformat/dashdec: reject a negative fragment index. (CVE-2026-75146, bsc#1276412) - Add ffmpeg-8-CVE-2026-75145.patch: Backport b4c199c5 from upstream, avformat/rtpenc_av1: do not narrow the OBU size to (long). (CVE-2026-75145, bsc#1276411) - Add ffmpeg-8-CVE-2026-75144.patch: Backport 1c10bcc2 from upstream, avformat/rtpenc_vc2hq: reject data units larger than the RTP payload buffer. (CVE-2026-75144, bsc#1276410) - Add ffmpeg-8-CVE-2026-75143.patch: Backport 1c10bcc2 from upstream, avformat/librist: honor the caller buffer size in librist_read. (CVE-2026-75143, bsc#1276409) - Add ffmpeg-8-CVE-2026-75142.patch: Backport 9d786e4b from upstream, avformat/mpegenc: reject stream counts that overflow the system header. (CVE-2026-75142, bsc#1276408) - Add ffmpeg-8-CVE-2026-75141.patch: Backport acf5d7cd from upstream, avformat/hevc: reject hvcC NAL arrays that overflow the 16-bit count. (CVE-2026-75141, bsc#1276407) - Add ffmpeg-8-CVE-2026-70632.patch: Backport 16b2049d from upstream, avcodec/cfhd: reject transform-2 output wider than the plane. (CVE-2026-70632, bsc#1274289) - Add ffmpeg-8-CVE-2026-70631.patch: Backport 3c287af3 from upstream, avcodec/tiff: reject inflate output shorter than the strip. (CVE-2026-70631, bsc#1274287) - Add ffmpeg-8-CVE-2026-70630.patch: Backport c22667d0 from upstream, avcodec/screenpresso: reject deflate output shorter than the frame. (CVE-2026-70630, bsc#1274282) - Add ffmpeg-8-CVE-2026-70629.patch: Backport a5fe21a1 from upstream, avcodec/rscc: do not leave uninitilized data when the input is too short. (CVE-2026-70629, bsc#1274270) - Add ffmpeg-8-CVE-2026-70628.patch: Backport 02fc47e1 from upstream, avcodec/dvbsub_parser: avoid signed overflow in the capacity check. (CVE-2026-70628, bsc#1274268) - Add ffmpeg-8-CVE-2026-66037.patch: Backport f15e730c from upstream, avformat/iamf_parse: check count_label against the available bytes. (CVE-2026-66037, bsc#1272764) - Add ffmpeg-8-CVE-2026-66036.patch: Backport 62294b6a from upstream, avfilter/vf_hqdn3d: support dynamic frame sizes. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-66036-shim01.patch Backport e3d0c719 from upstream, avfilter/vf_hqdn3d: reject unsupported frame parameter changes. This patch is for facilitate ffmpeg-CVE-2026-66036.patch. (CVE-2026-66036, bsc#1272763) - Add ffmpeg-8-CVE-2026-65706.patch: Backport b3c7ebc1 from upstream, avfilter/vf_swaprect: size the temp row buffer for the widest plane. (CVE-2026-65706, bsc#1272762) - Add ffmpeg-8-CVE-2026-65705.patch: Backport 30a52276 from upstream, avfilter/vf_floodfill: remove unneeded variables. (CVE-2026-65705, bsc#1272761) - Add ffmpeg-8-CVE-2026-65704.patch: Backport 52f7983f from upstream, avformat/ty: don't let the Series2 AC3 trim underflow the packet size. (CVE-2026-65704, bsc#1272760) - Add ffmpeg-8-CVE-2026-65703.patch: Backport 3b85fbe8 from upstream, avcodec/tdsc: unref the reference frame before reallocating on size change. (CVE-2026-65703, bsc#1272759) - Add ffmpeg-8-CVE-2026-64834.patch: Backport 3c441711 from upstream, avformat/rtpdec_asf: reject ASF objects smaller than their header. (CVE-2026-64834, bsc#1272757) - Add ffmpeg-8-CVE-2026-64833.patch: Backport 385ac2fa from upstream, avformat/spdifenc: bound DTS core_size against the packet size in the HD path. (CVE-2026-64833, bsc#1272755) - Add ffmpeg-8-CVE-2026-58049.patch: Backport f8d7795d from upstream, avcodec/rasc: Check that 32-bit DLTA accesses stay within the row. (CVE-2026-58049, bsc#1269550) - Rename the ffmpeg BRPM back to ffmpeg-8 to make room for ffmpeg-9 to fill the role. [boo#1271606] - Rename the ffmpeg-8 BRPM to ffmpeg. [boo#1271606] ==== gcc16 ==== Subpackages: cpp16 gcc16-locale libasan8 libatomic1 libgcc_s1 libgcc_s1-32bit libgccjit0 libgfortran5 libgomp1 libhwasan0 libitm1 liblsan0 libobjc4 libquadmath0 libstdc++6 libstdc++6-32bit libstdc++6-devel-gcc16 libstdc++6-locale libstdc++6-pp libstdc++6-pp-32bit libtsan2 libubsan1 - Add gcc16-pr124811.patch to fix build reproducability when PCH is used - Add gcc16-znver6-cpuid.patch to fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390, make sure to configure s390x with - -disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ==== gegl ==== Subpackages: gegl-0_4 gegl-0_4-lang libgegl-0_4-0 typelib-1_0-Gegl-0_4 - Add gegl-CVE-2026-18300.patch: libs/rgbe: fix >200kb report from ZDI (bsc#1276229, CVE-2026-18300) ==== gimp ==== Subpackages: gimp-plugin-aa gimp-plugin-python3 libgimp-3_0-0 libgimpui-3_0-0 - Replace gimp-CVE-2026-66757.patch with the upstream backport. - Add gimp-CVE-2026-66757-2.patch: fix allocation of SGI tables (glgo#GNOME/gimp!2984). ==== gpg2 ==== Version update (2.5.21 -> 2.5.22) Subpackages: dirmngr gpg2-lang - Update to 2.5.22: * gpg: New option "primary" for the --card-edit "generate" command. This option is useful create only the primary key on the first slot of an OpenPGP card * gpgsm: Emit issuer and serial no. when the certificate is not found * A range of bug fixes ==== gpgme ==== Version update (2.1.2 -> 2.2.0) Subpackages: libgpgme45 - Update to 2.2.0: * gpgme_verify_result_t now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Handle the new SIGINFO status line * Ignore TRUST_ status lines if no NEWSIG was seen ==== gpgmepp ==== Version update (2.1.0 -> 2.2.0) - Update to 2.2.0: * Signature now provides issuer serial number and issuer name for S/MIME certificates used for signing that are not included in a signature * Added missing getters for the number of notations of a signature and the numbers of created signatures and of invalid signing keys of a signing result ==== imlib2 ==== Version update (1.12.6 -> 1.12.7) Subpackages: imlib2-loaders libImlib2-1 - Add imlib2-jpeg-arm32.patch: loader_jpeg: silence -Wcast-align error on 32-bit ARM architectures. - Update to version 1.12.7: + AVIF saver: Fix saving images with alpha + BMP loader: Fix alpha detection + JXL loader: Change runners from max 4 to ncores/2 + JXL loader: Refactor runners handling + PNM loader: add support for 16-bit (high depth) PGM/PPM/PAM + Spec file: Add a %conf section + TIFF saver: Fix saving images with alpha + ico: validate palette size for indexed images + id3: reject external APIC picture links + j2k: limit decoded image dimensions + loaders: limit decompressed temporary output + png: validate APNG IHDR length + scale: add bicubic scaling via uscaler + scale: support flips with uscaler + y4m: read high-bit-depth grayscale samples safely + Updated tests. - Add imlib-ico-loader.patch: Fix ico loader: planes and bpp are defined as uint16 in the spec, thus apply LE_16 macros on it (boo#1278182). ==== iproute2 ==== Version update (7.1 -> 7.2) - Update to release 7.2 * dpll: Added frequency monitoring support * dpll: monitor: add -t/--timestamp and --tshort options * rdma: netns can now be specified by PID * bridge: vlan: Added support for neigh_forward_grat * netshaper: Added bw-min and weight parameter support * netshaper: Added group command for creating scheduling hierarchies * iplink: bridge: Added stp_mode support * devlink: Added dump support for resource show - Ditch libnetlink-devel. This was never really a public API, and mipv6d (its original user back in 2014) has long had its own copy of libnetlink. ==== kquickimageeditor6 ==== Version update (0.6.2.1 -> 0.7.0.1) Subpackages: kquickimageeditor6-imports libKQuickImageEditor1 - Update to 0.7.0.1: * Fix build on ARM with SVE - Update to 0.7.0: * Removed OpenCV dependency by replacing the stack blur with a Qt Concurrency and Highway SIMD library based implementation. * Added color adjustment API. * Added repainted signal to AnnotationDocument. AnnotationDocument periodically repaints annotationsImage and canvasBaseImage. * AnnotationDocument::renderToImage always returns the latest image. If necessary, it will wait for repaints to finish before returning. * Annotation shadows don't jitter as much while being drawn or resized. * Added hasSelectionChanged and optionsChanged signals to SelectedItemWrapper. * For more details see https://mail.kde.org/pipermail/kde-announce/2026-August/000524.html - Add %check ==== libcloudproviders ==== Version update (0.4.0 -> 0.4.1) - Update to version 0.4.1: + Complete the documentation to fix the validation test. ==== libcupsfilters ==== Subpackages: libcupsfilters2 - libcupsfilters-2.1.1-CVE-2026-64611.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/4b343522823403df01f6753082df83f07d18c217 backported to libcupsfilters 2.1.1 to fix CVE-2026-64611 "Infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4 "user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop" (bsc#1273145) - libcupsfilters-2.1.1-CVE-2026-64612.patch is based on https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 backported to libcupsfilters 2.1.1 to fix CVE-2026-64612 "Malformed PNG aborts CUPS image filter process (missing libpng setjmp recovery)" https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch "authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG" (bsc#1273146) ==== libgcrypt ==== Version update (1.12.2 -> 1.12.3) Subpackages: libgcrypt20 libgcrypt20-32bit libgcrypt20-x86-64-v3 - Update to 1.12.3: * Validate hash algorithm for use with RSA modulus * Validate parameters of Balloon KDF * Validate parallelism of Argon2 KDF * Fix parsing quoted parts and CRLF/LFCR in s-expression * Support BUFLEN check for GCRYMPI_FMT_SSH * Fix RSA PSS verify message length checking * Avoid a NULL ptr deref due to a unsupported genkey flag for ECC * Assert 32 KiB input cap in gcm_ctr_encrypt * Fix assertion failure in OCB when a buffered block becomes block 65536 * Fix OOB read in IMIT MAC verify of GOST28147 * Fix CMAC block-count truncation for 64 GiB writes * Fix AEAD spurious byte-counter carry for 4 GiB adds * Validate all KEM input lengths * Add length check of DATALEN when parsing s-expression * Only accept canonical value for S with EdDSA * Only accept canonical signatures for RSA * Fix an assertion failure for invalid small-order Ed25519 public keys * Validate length of supplied receiver public-key length in DHKEM decapsulation * Use a more strict value for the PKCS#1 minimal frame length. * Use just strong random for the Dilithium signature nonce and the Kyber encapsulation coins * Allow internal users to skip fast random poll for ciphers and hashes * Speedup sntrup761 by defer reduction in polynomial multiplication, reading random with a single call, and reducing freeze helpers w/o division * Avoid byte-wise load/store on RISC-V with Zicclsm * Use unaligned vector memory access on RSIV-V when supported * Add Intel SM4 instructions accelerated AVX512 and AVX2 implementation * Add Intel SM3 extension implementation * Add Intel SHA512 extension implementation * kyber: Accept and return a seed using the gcry_pk_genkey API * Add curve "ietf25" as alternative to "Curve25519" with exact RFC-8410 semantics. The name "X25519" was already used as an alias, thus this new name. * Add straight-line speculation hardening for function ends * Fix constant time memequal check for SM2 * Add post-quantum algorithm benchmarking to bench-slope * Due to the minor API updates and but with no newer branch released the SO name has been updated. - update upstream signing key ==== libjpeg-turbo ==== Subpackages: libjpeg8 libjpeg8-x86-64-v3 libturbojpeg0 libturbojpeg0-x86-64-v3 - do not skip djpeg12-shared-3x2-float-prog-cmp, use correct parameters instead ==== libksba ==== Version update (1.8.0 -> 1.8.1) - Update to 1.8.1: * Fix CMS parser to avoid possible infinite loop - drop libksba-nobetasuffix.patch, not needed when autoreconf is not run. Also don't run it. - Fix fgrep deprecation warnings in ksba-config --libs output boo#1203092 add libksba-1.8.1-fgrep-warning.patch, sent upstream ==== libnftnl ==== Version update (1.3.1 -> 1.3.2) - Update to release 1.3.2 * Support for connlimit stateful objects * Now validates geneve class and type attribute size in setter and validates that the kernel does not provide too long geneve data attributes. * Do not print userdata content through snprintf API. * Enhancements for the snprint API to display data according to size and byteorder, this includes new functions nftnl_{expr,set_elem}_set_imm() to decorate the data. * More improvements for the snprintf() API for set elements: no colon is printed if data is not provided, print object names in maps and print flags only if non-zero. ==== mozilla-nspr ==== Version update (4.39 -> 4.40) - update to version 4.40 * no upstream release notes found ==== mozilla-nss ==== Version update (3.126.1 -> 3.127) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.127 * bmo#2060720 - Round ECH ClientHelloInner padding up to a multiple of 32 * bmo#2063071 - make selfserv listen on IPv6 wildcard on dual-stack hosts * bmo#2059176 - EC_DerivePublicKey() failure is not propagated in sftk_mkPrivKey() * bmo#2052210 - Generate additional test message for Thunderbird (HTML with remote image) * bmo#1869493 - Heap-buffer overflow in AES Keywrap * bmo#2054609 - remove cipher suite order exception from bug 946147 * bmo#2061107 - restore pkcs12.h for source compatibility * bmo#2056291 - remove support for pre-v1.0 PKCS#12 * bmo#2054719 - fix content type tag for CMS AuthEnvelopedData plaintext * bmo#2060118 - remove DH_GenParam support * bmo#2053831 - clang format * bmo#2054714 - avoid leaking stale ECH outer extensions across HRR * bmo#2053831 - Drop CKF_VERIFY flag from CKM_HKDF_DATA derivation in ECH GREASE * bmo#2053831 - Adjust PK11_Derive and TLS 1.3 derivation templates for CKM_HKDF_DATA and CKO_DATA compliance * bmo#2053831 - Use CKF_HKDF_SALT_DATA in tls13_HkdfExtract for CKO_DATA keys per PKCS#11 v3.2 * bmo#2057184 - Enable -Wunused-but-set-variable/-global in werror.py * bmo#2056846 - Remove unused policy string callback to fix - Wunused-but-set-global * bmo#2052709 - Convert NSS 3.126 release notes to Markdown * bmo#2052709 - Rename doc/rst to doc/src and update references * bmo#2052709 - Apply markdownlint to the converted Markdown docs * bmo#2052709 - Fix Markdown documentation build warnings * bmo#2052709 - Convert documentation from reStructuredText to Markdown (automated) ==== nftables ==== Version update (1.1.6 -> 1.1.7) Subpackages: libnftables1 python313-nftables - Update to release 1.1.7 * Fix spurious EEXIST error when using the create element command with large batches. * Improve error reporting for syntax errors by printing expected tokens. * Set element support for multi-statements, e.g. counter + quota. * Connlimit support with maps. * Support for using bitmask datatypes as set key, e.g. tcp flags. - Delete support-reproducible-build.patch (merged) ==== openSUSE-release ==== Version update (20260902 -> 20260904) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== publicsuffix ==== Version update (20260819 -> 20260902) - Update to version 20260902 (public_suffix_list.dat snapshot taken from upstream commit of 2026-09-02): * Add builtwithrocket.new and rocketpreview.app to PRIVATE section (#2948) * Add canva-code.cn (#2980) * Add tmp.now to PRIVATE section (Vercel) (#3193) * Add eth.limo and eth.link gateways (#3199) * Remove demo.datacenter.fi and paas.datacenter.fi (#3197) * Remove XnBay Technology entries (#3176) ==== python-tornado6 ==== - Add patch run-multi-process-in-fresh-process.patch: * Run test_multi_process in a fresh subprocess to avoid a warning. ==== re2c ==== Version update (4.5.1 -> 4.6) - Update to version 4.6 * Added support for Zig labeled continue optimization. (#580). * Updated C/C++ examples to use re2c features available in version 4.0 or higher. ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Fix test_tcp for pytest >=8 - Added: * fix-test_tcp-for-pytest-8-779.patch - Fix file handlers leaking on using SyncWrapper (bsc#1272939) - Added: * fix-file-handlers-leaking-on-using-syncwrapper-bsc-1.patch ==== sdbootutil ==== Version update (1+git20260825.c7a5a97 -> 1+git20260903.f91f636) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper - Update to version 1+git20260903.f91f636: * Include FIDO2 unlocked devices for ordering (bsc#1234010) * Test in parallel for speed up * Add --repair parameter to cleanup * Fix shellcheck complain * Report entries with missing files * Avoid duplicate entries in non-snapper systems * Add initial tests for sdbootutil * Report the error if bootctl clean fails - Update to version 1+git20260901.41540d5: * No warn if a component is not in the event log * Add status command * Select the new sdbootutil if available * Skip blank lines in measure-pcr-generator.sh * Do not change crypttab for unrelated entries * Report the bad PCR when update-prediction fail * Do not write the recovery PIN in the journal * Improves non snapshot system support * Update help message for --measure-pcr * Report when PCR 7 is dropped because shim update * Add --strict parameter for --pcr policy * Report dropped PCRs via a warn * Adjust the limits for PolicyOR issues * Avoid update predictions if the service is up * Keep the exit status of sdbootutil call - Update to version 1+git20260827.786f9a8: * Do not accept empty passwords * jeos-firstboot-enroll: report errors also in the journal * Restore old crypttab via the exit trap * Update CLAUDE data * Detect half created openssl keys * check_enrolled report when something was written in the LUKS2 header * Improve a bit the disk-encryption-tool keyslot detection * Avoid leak of env var secrets * Wipe the d-e-t key in the enroll service and jeos module * Remove the correct keyslot left by d-e-t * Differentiate tpm2 and tpm2+pin for unattended unlock * Use is_same_device in detect_tracked_device and drop greps * Refactor check to avoid shellcheck complain * Parse the entry file in a sigle place * Validate the entry with the new kernel name * Refactor enrollment interface and deprecate the old one * New kernels will have different hash * Warn If no crypttab entry found * Extend is_same_device * jeos-firstboot-enroll: validate the passwords * sdbootutil-enroll: report when no encryption method is provided * Write recovery pin after enrollment in jeos module * Write recovery pin after enrollment * Improve error detection in sdbootutil-enroll * Increase keyctl timeout * Merge require_unlock and set_unlock_method * Be sure that the terminal check works with snapper * Renerate initrd when new measure-pcr keys are created * Separate ask-* parameters * Fix reading credential and keyctl password * Get the device password for each enrolling mechanism * Drop elements from crypttab if the enrollment fails * Validate the enrollment for each method * Add warning when enrolling FIDO2 token ==== sdl2-compat ==== Version update (2.32.70 -> 2.32.72) - Update to release 2.32.72 * Fixed a crash during the menu transition in Super Mario War. * Fixed menu rendering in The Ur-Quan Masters. * Fixed loading screen flickering in Payday 2. * Fixed the pointer position in Augustus when screen scaling is enabled. * Fixed an out of bounds exception in the OBS plugin "input-overlay" when using the new Steam Controller. ==== suse-module-tools ==== Version update (16.1.6 -> 16.1.7) Subpackages: suse-module-tools-scriptlets - Update to version 16.1.7: * If no initrd is found rebuild it (gh#openSUSE/suse-module-tools#133) ==== tcl ==== - Split the test suite into a multibuild "test" flavour: the main build no longer runs it (%check measured 326s of a 471s build on aarch64) and no longer pulls in the timezone build dependency; the test flavour builds only a src.rpm - Do not build the test flavour in the Factory rings and staging, which set %_with_ringdisabled - Modernise the spec: drop the obsolete BuildRoot, Group, defattr and PreReq tags, brace all macros, use %autosetup and %make_build - Point URL, Source0 and the description at tcl-lang.org; the tcl.tk domain no longer resolves at all - Run the full test suite: drop the 31-entry known-failures whitelist, every id of which passes again (47159 tests, 43939 passed, 3220 skipped, 0 failed on aarch64); only the riscv64 and qemu-only entries are kept - Fail the build on a crashed or aborted test run, which previously passed silently: the pipeline reported tee's exit status, and tests/all.tcl returns 0 even on failures unless ERROR_ON_FAILURES is set - Drop the dead s390 test guard; only s390x still exists - Drop the ppc64 tcl-64bit and tcl-devel-64bit Obsoletes, added in 2009 for the SLE10-era biarch packages - Drop the %post scriptlet removing a /usr/lib/tcl8.6 compat symlink from the pre-2005 layout; no tcl 8.6 package has ever created it ==== yast2-bootloader ==== Version update (5.0.33 -> 5.0.42) - revert "do not suggest grub2-bls if there are other systems" as it breaks upgrades scenario (bsc#1258861) - 5.0.42 - remove remaining occurrences of trusted boot to fix crash when writting sysconfig for systemd-boot and grub2-bls (bsc#1274932) - 5.0.41 - propose secure boot only for ECKD DASD (bsc#1270367) - 5.0.40 - Reducing error level for not available shim package while using systemd-boot (bsc#1265870). - 5.0.39 - jsc#PED-7975 and bsc#1262249 - dropped trusted boot - 5.0.38 AutoYaST/systemd-boot export/import: Using string for secure_boot setting in export file (bsc#1260385). - 5.0.37 - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.36 - Propose always secure boot with zipl on DASD (jsc#/PED-13734) - Do not suggest grub2-bls if there is another e.g. windows system installed (bsc#1257528, bsc#1257510). - 5.0.34