Packages changed: MicroOS-release (20261009 -> 20261010) appstream-glib baloo-widgets (26.08.1 -> 26.08.2) cyrus-sasl dolphin (26.08.1 -> 26.08.2) dracut (112+suse.53.g97cbf62 -> 112+suse.54.g5c7a104) expat (2.8.5 -> 2.9.0) falkon (26.08.1 -> 26.08.2) ffmpeg-8 ffmpegthumbs (26.08.1 -> 26.08.2) glib2 (2.88.3 -> 2.88.4) gstreamer (1.28.7 -> 1.28.8) gstreamer-plugins-bad (1.28.7 -> 1.28.8) gstreamer-plugins-base (1.28.7 -> 1.28.8) kaccounts-integration (26.08.1 -> 26.08.2) kaccounts-providers (26.08.1 -> 26.08.2) kate (26.08.1 -> 26.08.2) kdegraphics-mobipocket (26.08.1 -> 26.08.2) kdegraphics-thumbnailers (26.08.1 -> 26.08.2) kdenetwork-filesharing (26.08.1 -> 26.08.2) kdialog (26.08.1 -> 26.08.2) kio-extras (26.08.1 -> 26.08.2) kio-gdrive (26.08.1 -> 26.08.2) konsole (26.08.1 -> 26.08.2) kpmcore (26.08.1 -> 26.08.2) kwalletmanager (26.08.1 -> 26.08.2) libeconf (0.8.4 -> 0.8.5) libkdcraw (26.08.1 -> 26.08.2) libkexiv2-qt6 (26.08.1 -> 26.08.2) libkgapi6 (26.08.1 -> 26.08.2) open-iscsi parted partitionmanager (26.08.1 -> 26.08.2) pipewire qrca (26.08.1 -> 26.08.2) signon-kwallet-extension (26.08.1 -> 26.08.2) vlc wireplumber xorg-x11-server xwayland === Details === ==== MicroOS-release ==== Version update (20261009 -> 20261010) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== appstream-glib ==== Subpackages: libappstream-glib8 - Update version dependencies according to meson.build. ==== baloo-widgets ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== cyrus-sasl ==== Subpackages: cyrus-sasl-gssapi libsasl2-3 - Fix heap-based buffer overflow in DIGEST-MD5 add_to_challenge(): buffer size was not recomputed after quoting expanded the value, allowing a malicious server to overflow the client heap. (bsc#1284687) CVE-2026-107161 * add cyrus-sasl-digestmd5-quote-overflow.patch - Clean up an synchronize changes - Fix packages for Immutable Mode - cyrus-sasl (jsc#PED-14856) ==== dolphin ==== Version update (26.08.1 -> 26.08.2) Subpackages: dolphin-part libdolphinvcs6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * CI: Comment flatpak job * confirmationssettingspage: Set vertical text alignment for form labels * kstandarditemlistwidget: Fix poorly legible selection text with certain styles and color schemes (kde#524851) * folderspanel: set hightLightEntireRow for view (kde#486383) * dolphinview: Refresh the default zoom level when previews are toggled (kde#524842) * viewproperties: keep the style chosen for a special folder (kde#501442) ==== dracut ==== Version update (112+suse.53.g97cbf62 -> 112+suse.54.g5c7a104) Subpackages: dracut-ima - Update to version 112+suse.54.g5c7a104: * fix(systemd-pcrextend): add systemd-pcrextend.socket ==== expat ==== Version update (2.8.5 -> 2.9.0) - update to 2.9.0: * Security fixes: * CVE-2026-102633, bsc#1283493: integer overflow in expat_realloc on 32bit platforms * CVE-2026-77214, bsc#1284334: out-of-bounds read in XML_ParseBuffer due to missing validation of the len parameter * drop the patch, fixed upstream: * expat-CVE-2026-102633.patch * Bug fixes: * Handle OOM when copying encodingName in XML_ParserReset * New features: * Properties API to get and set scalar properties of a parser * Five new 64bit location API functions ==== falkon ==== Version update (26.08.1 -> 26.08.2) Subpackages: falkon-kde - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Explicitly enable LocalContentCanAccessFileUrls in QtWebEngine ==== ffmpeg-8 ==== Subpackages: libavcodec62 libavfilter11 libavformat62 libavutil60 libswresample6 libswscale9 - Correctly enable apv encoder, encoder is named liboapv. ==== ffmpegthumbs ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== glib2 ==== Version update (2.88.3 -> 2.88.4) Subpackages: glib2-tools libgio-2_0-0 libgirepository-2_0-0 libglib-2_0-0 libgmodule-2_0-0 libgobject-2_0-0 typelib-1_0-GLib-2_0 typelib-1_0-GLibUnix-2_0 typelib-1_0-GModule-2_0 typelib-1_0-GObject-2_0 typelib-1_0-Gio-2_0 - Update to version 2.88.4: * Bugs fixed: + gio/tests/services: - Installed service file contains build path - Fix installed service file containing build path + docs: Fix gio gi-docgen docs_url + gconstructor: Reference _tls_used also on GCC, CLang + fix: handle long filenames in trash by truncating from front + Backport various security fixes * Updated translations. ==== gstreamer ==== Version update (1.28.7 -> 1.28.8) Subpackages: libgstreamer-1_0-0 - Update to version 1.28.8: * Highlighted bugfixes: + Various security fixes and playback fixes + Fix adaptivedemux2 HLS and DASH playback regression + Fix FLAC audio seeking regression + Various RTP depayloader and RTSP client SDP handling fixes + MXF demuxer: Added support for reading AAF AIFF-AIFC audio + VA-API compositor: Fix alpha blending with Intel driver + Windows media audio/video seeking improvements + AMD AMF AV1 video encoder force-keyframe fixes + Fix endless drain in some FFmpeg wrapper audio encoders and support dual mono hlssink3 improvements + ISOBMFF dash/iso/fmp4 muxer fixes for timestamp rollover in 2036 + cerbero: Rework checksum verification to allow mirror retries + Various bug fixes, build fixes, memory leak fixes, and other stability and reliability improvements * gstreamer: + baseparse: Fix accumulating of detection buffers + buffer: Don't leave buffers with dangling memory pointers if appending memory fails + buffer: Prevent NULL pointer dereferences when deserializing reference timestamp meta + value: fix crash when comparing mixed-type lists + ptp: Fix build failures with Rust 1.99 - Rebase gstreamer-pie.patch with quilt. - Migrate to xz compression and manual service run. ==== gstreamer-plugins-bad ==== Version update (1.28.7 -> 1.28.8) Subpackages: libgstphotography-1_0-0 libgstplay-1_0-0 - Update to version 1.28.8: * adpcmenc: stop the IMA encode loop before reading past the input frame * amfav1enc: Force a key frame on force-key-unit * ccutils: Miscellaneous parsing fixes * closedcaption: Use truncated length when converting CEA708 / CEA608 S334-1A data too * d3d12: Various GstBaseTransform::transform_meta() related fixes * hipevent: Fix device ID getter * hipmemory: Fix minor leak and typo * jpegparse: handle missing NUL terminator in COM segment * mpegts: fix GError usage in a loop * mxfdemux: Add support for reading AAF AIFF-AIFC audio * mxfmux: Fix possible crash when adding a new segment due to frame reordering * nvh264dec: Fix top field POC in DPB entry * rsvgdec: Fix out-of-bounds read when scanning for SVG end tag * rtp: Various small (RTP and not) depayloader fixes * segmentationoverlay: + Fix off-by-one bug and add test + Respect video meta strides * va: compositor: Fix alpha blending with Intel driver * vmaf: use GST_PARAM_DOC_SHOW_DEFAULT for "threads" property * vulkan: + encoder: DPB slots and DBP barrier fixes + h26x enc/dec misc fixes + tests: examples fixes * webrtc/nice: Fix crash in nice_candidate_free during gather - Refresh spandsp3.patch with quilt. - Migrate to xz compression and manual service run ==== gstreamer-plugins-base ==== Version update (1.28.7 -> 1.28.8) Subpackages: libgstallocators-1_0-0 libgstapp-1_0-0 libgstaudio-1_0-0 libgstgl-1_0-0 libgstpbutils-1_0-0 libgstriff-1_0-0 libgsttag-1_0-0 libgstvideo-1_0-0 - Update to version 1.28.8: * appsink: Reset EOS state on PAUSED → READY * audio-resampler-neon: handle Thumb1-only builds correctly * audio-resampler-neon: Follow-up from "fix Thumb encoding and use Clang O2 calculation for strides" * audio: video: Validate audio/video meta deserialization & other meta deserialization fixes * audioconverter: guard against NULL input in do_convert_out * sdpmessage: Avoid sign bit when hex-escaping chars * udmabuf: Open device with O_RDONLY instead O_RDWR * videoconvertscale: Take GstVideoMeta into account when converting - Rebase patches with quilt. - Migrate to xz compression and manual service run. - Drop required versions define, manually set it, as the obs ignores the define. ==== kaccounts-integration ==== Version update (26.08.1 -> 26.08.2) Subpackages: libkaccounts6-2 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * CI: Remove Qt5 build ==== kaccounts-providers ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kate ==== Version update (26.08.1 -> 26.08.2) Subpackages: kate-plugins - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * it makes no sense to detach if we are not in a terminal (kde#525600) ==== kdegraphics-mobipocket ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kdegraphics-thumbnailers ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * gscreator: Return early if img allocation failed ==== kdenetwork-filesharing ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kdialog ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kio-extras ==== Version update (26.08.1 -> 26.08.2) Subpackages: libkioarchive6-6 trash_kcm - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Thumbnail worker: fix unneeded scaling of folder pixmaps and sub thumbs ==== kio-gdrive ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== konsole ==== Version update (26.08.1 -> 26.08.2) Subpackages: konsole-part - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * Fix creation of graphics while scrolling ==== kpmcore ==== Version update (26.08.1 -> 26.08.2) Subpackages: libkpmcore13 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== kwalletmanager ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - Changes since 26.08.1: * src/konfigurator: fix Tab focus (kde#526104) ==== libeconf ==== Version update (0.8.4 -> 0.8.5) - Update to version 0.8.5: * Fix a crash if sections are empty (#249) ==== libkdcraw ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKDcrawQt6-5 libkdcraw-qt6 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkexiv2-qt6 ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKExiv2Qt6-0 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== libkgapi6 ==== Version update (26.08.1 -> 26.08.2) Subpackages: libKPim6GAPICore6 libKPim6GAPIDrive6 libkgapi6-sasl2-kdexoauth2 - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== open-iscsi ==== Subpackages: iscsiuio libopeniscsiusr0 - Update to version 2.1.13.suse+4.dc2446a1: * iscsid: honor REPORT LUNS DATA HAS CHANGED again (#557) * Convert shell scripts to POSIX sh (#552) * Preparing for version 2.1.13 * iscsiuio: fix incorrect comparison of IPv6 subnet mask * usr: verify IPC peer credentials before sending data * login: fix infinite redirect loops with configurable limits * iscsiuio: strengthen IPv6 payload length validation in uip_process() * iscsiuio: strengthen DHCPv6 option parsing loop bound check * iscsiuio: validate DHCPv6 IA_NA option lengths to prevent OOB reads * usr: network code ioctl handling improvements * fix typo in user-facing error message in verify_mode_params() (#548) * gitignore: ignore generated build artifacts (#550) * iscsiadm: handle getopt errors directly (#551) * Fix iscsi_conn_iface_has_ip error handling (#531) * Fix reopen log freq change (#542) * iscsi_net_util: fix broken VLAN support in find_vlan_dev (#545) * Fixes for CVEs CVE-2026-18724 - CVE-2026-18728 (#544) * usr: fix "-Wdiscarded-qualifiers" warning in auth.c (#539) * usr: Fix -Wdiscarded-qualifiers warning in iqn_name_valid (#537) * iscsiuio: Fix -Waddress-of-packed-member (#534) * Fixes CVEs: + bsc#1275171/CVE-2026-18724 + bsc#1275258/CVE-2026-18725 + bsc#1275260/CVE-2026-18726 + bsc#1275261/CVE-2026-18727 + bsc#1275262/CVE-2026-18728 ==== parted ==== Subpackages: libparted-fs-resize0 libparted2 - fix description ==== partitionmanager ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== pipewire ==== Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Add conditional aptx for Tumbleweed, libfreeaptx now awailable. ==== qrca ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== signon-kwallet-extension ==== Version update (26.08.1 -> 26.08.2) - Update to 26.08.2 * New bugfix release * For more details please see: * https://kde.org/announcements/gear/26.08.2/ - No code change since 26.08.1 ==== vlc ==== Subpackages: libvlc5 libvlccore9 vlc-noX vlc-qt - Require vlc from vlc-devel: whereas the desktop app is not exactly needed when building against the libraries, many consumers expect the full stack to be present. - Drop schroedinger-devel BuildRequires: Not needed, nor used. Upstream removed support in 3.0.24 - Rework subpackaging * Split the desktop output plugins out of the main vlc package, for use on headless systems * Installing vlc-noX and vlc-plugins-desktop will now give a fully functional CLI installation, without pulling in the graphical frontend * Main 'vlc' package will now pull in all components for desktop GUI interface ==== wireplumber ==== Subpackages: libwireplumber-0_5-0 - fixup fdupes ==== xorg-x11-server ==== Subpackages: xorg-x11-server-Xvfb - 0001-xkb-NULL-text-pointer-after-free-in-_CheckSetDoodad-.patch XKB SetGeometry TextDoodad Double Free (bsc#1281213, CVE-2026-88812, ZDI-CAN-31221) - 0002-xkb-allocate-names-keys-to-MAP_LENGTH-in-XkbAllocNam.patch XKB ChangeKeycodeRange Heap Out-of-Bounds Write (bsc#1281236, CVE-2026-93520, ZDI-CAN-31941) - 0003-xkb-widen-size_syms-num_syms-size_acts-num_acts-to-u.patch XKB ResizeKeyType Numeric Truncation (bsc#1281227, CVE-2026-93518, ZDI-CAN-31834) - 0004-xkb-fix-CheckKeySyms-overwriting-request-range-symsP.patch XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read (bsc#1281242, CVE-2026-93524, ZDI-CAN-32408) - 0005-randr-fix-size-and-offset-in-RRChangeProviderPropert.patch RandR ChangeProviderProperty Heap Buffer Overflow (bsc#1281238, CVE-2026-93521, ZDI-CAN-31944) - 0006-Xi-validate-modifier-values-in-ProcXIPassiveUngrabDe.patch XInput2 PassiveUngrabDevice Out-of-Bounds Write (bsc#1281241, CVE-2026-93523, ZDI-CAN-32366) - 0007-glx-validate-dataBytes-against-cmdlen-in-RenderLarge.patch GLX RenderLarge Heap Buffer Overflow (bsc#1281225, CVE-2026-93517, ZDI-CAN-31833) - 0008-present-unlink-notifies-from-window-list-in-present_.patch X.Org Server Present Extension Use-After-Free (bsc#1281218, CVE-2026-93515, ZDI-CAN-31830) - 0009-dix-remove-passive-grabs-referencing-a-device-on-rem.patch X.Org Server XInput Passive Grab Use-After-Free (bsc#1281220, CVE-2026-93516, ZDI-CAN-31832) - 0010-Xi-add-bounds-check-for-barrier-events-in-input_cons.patch XFixes Pointer Barrier Event List Buffer Overflow (bsc#1281233, CVE-2026-93519, ZDI-CAN-31938) - 0011-Xi-clean-up-gesture-sprite-traces-in-WindowGone.patch GestureBuildSprite Use-After-Free (bsc#1281244 CVE-2026-93536, ZDI-CAN-32753) ==== xwayland ==== - 0001-xkb-NULL-text-pointer-after-free-in-_CheckSetDoodad-.patch XKB SetGeometry TextDoodad Double Free (bsc#1281213, CVE-2026-88812, ZDI-CAN-31221) - 0002-xkb-allocate-names-keys-to-MAP_LENGTH-in-XkbAllocNam.patch XKB ChangeKeycodeRange Heap Out-of-Bounds Write (bsc#1281236, CVE-2026-93520, ZDI-CAN-31941) - 0003-xkb-widen-size_syms-num_syms-size_acts-num_acts-to-u.patch XKB ResizeKeyType Numeric Truncation (bsc#1281227, CVE-2026-93518, ZDI-CAN-31834) - 0004-xkb-fix-CheckKeySyms-overwriting-request-range-symsP.patch XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read (bsc#1281242, CVE-2026-93524, ZDI-CAN-32408) - 0005-randr-fix-size-and-offset-in-RRChangeProviderPropert.patch RandR ChangeProviderProperty Heap Buffer Overflow (bsc#1281238, CVE-2026-93521, ZDI-CAN-31944) - 0006-Xi-validate-modifier-values-in-ProcXIPassiveUngrabDe.patch XInput2 PassiveUngrabDevice Out-of-Bounds Write (bsc#1281241, CVE-2026-93523, ZDI-CAN-32366) - 0007-glx-validate-dataBytes-against-cmdlen-in-RenderLarge.patch GLX RenderLarge Heap Buffer Overflow (bsc#1281225, CVE-2026-93517, ZDI-CAN-31833) - 0008-present-unlink-notifies-from-window-list-in-present_.patch X.Org Server Present Extension Use-After-Free (bsc#1281218, CVE-2026-93515, ZDI-CAN-31830) - 0009-dix-remove-passive-grabs-referencing-a-device-on-rem.patch X.Org Server XInput Passive Grab Use-After-Free (bsc#1281220, CVE-2026-93516, ZDI-CAN-31832) - 0010-Xi-add-bounds-check-for-barrier-events-in-input_cons.patch XFixes Pointer Barrier Event List Buffer Overflow (bsc#1281233, CVE-2026-93519, ZDI-CAN-31938) - 0011-Xi-clean-up-gesture-sprite-traces-in-WindowGone.patch GestureBuildSprite Use-After-Free (bsc#1281244 CVE-2026-93536, ZDI-CAN-32753) - 0012-glamor-size-tmp_bits-buffer-for-source-coordinate-ra.patch Glamor CopyArea Heap Buffer Overflow (bsc#1281240, CVE-2026-93522, ZDI-CAN-32361)