Packages changed: apparmor bzip2 chrony (4.8 -> 4.9) freerdp (3.30.0 -> 3.31.0) libapparmor mlterm (3.9.4 -> 3.9.5) nvidia-open-driver-G07-signed (595.91.07_k7.2.0_1 -> 595.99.02_k7.2.0_1) nvidia-open-driver-G07-signed-cuda openSUSE-release (20260827 -> 20260828) salt srt (1.5.6 -> 1.5.7) wicked === Details === ==== apparmor ==== Subpackages: apparmor-abstractions apparmor-docs apparmor-parser apparmor-parser-lang apparmor-profiles apparmor-utils apparmor-utils-lang python3-apparmor - add changes-since-5.0.2.diff - several profile updates - fix compability with Swig 4.5 (boo#1275508) - drop upstreamed nslookup.diff - refresh kerberosclient-usrmerge.diff - add dovecot.diff with several dovecot profile updates (boo#1265453) ==== bzip2 ==== Subpackages: libbz2-1 libbz2-1-x86-64-v3 - Fix CVE-2026-42250, off‑by‑one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786) * CVE-2026-42250.patch ==== chrony ==== Version update (4.8 -> 4.9) Subpackages: chrony-pool-openSUSE - Add chrony-test-tolerance.patch: relax the clock-accuracy bounds of the offline holdover phase in the 129-reload simulation test. Its jitter is generated by clknetsim via glibc log(), which is not correctly-rounded and differs in the last ULP between architectures (armv7l and ppc64le vs x86_64 and aarch64). Without a server to correct it, that tiny difference grows past the default limit, making the test fail there although chronyd behaves correctly. - Update to 4.9: * New minstratum and maxstratum directives to bound which source strata are acceptable * New maxntsretry option on server/pool to cap the NTS-KE retry interval * New maxtxbuffers directive enabling hardware and kernel TX timestamps on non-Ethernet devices and tunnels * NTP-over-PTP updated to the final specification (RFC 10030) * seccomp filter updated -- we build with --enable-scfilter, so this is on the default path * Better local clock precision measurement, and client logging no longer costs server performance * Fixed ratelimit directives rejecting burst values over 32 * Fixed handling of hardware RX timestamps with a zero interface index * Further refclock, chronyc and OpenBSD changes: see upstream's NEWS for the full list - Drop chrony-libnettle4.patch: merged upstream, 4.9 carries the same NETTLE_VERSION_MAJOR guards verbatim - Bump the bundled clknetsim simulator 6ee99f50 -> 56b60ef2, now taken from the chrony project's own GitLab as 4.9's test/simulation/README directs. 4.9's simulation tests need clknetsim's new raw-socket support; against the old pin all 69 of them fail. ==== freerdp ==== Version update (3.30.0 -> 3.31.0) Subpackages: libfreerdp3-3 librdtk0-0 libwinpr3-3 - Update to version 3.31.0: + Huge bugfix and security release. We've received quite a number of smaller and bigger bugfixes and security reports that have been addressed with this release. Most important user facing change is a optimization of the YUV decoder which will result in faster client graphics for AVC/H264 sessions + CVE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c5gr-hmqp-pwj4 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-h5w2-q35j-443h https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m85m-3qxv-63h5 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r9pv-ffph-6gg6 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ffjr-p229-hpch https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-4464-r7qj-pgrx https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2vf2-grvj-6g8x https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hg4r-vv53-vwf8 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-57h7-vw2f-2f9x https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v649-94v2-p72q https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-j5mq-3349-gwmm https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-23pf-q83q-x45r https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pj8w-fh79-f438 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vccg-35r5-8jrf https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-w9qg-g24r-77f6 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f5p6-88mh-59vg https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-r7jx-j9h7-j4xj https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-x7v6-xfx3-52j6 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-q65v-4w7q-hx3r + Lots of other changes, please see upstream changelog: https://github.com/FreeRDP/FreeRDP/releases/tag/3.31.0 - Add pkgconfig(aom), pkgconfig(dav1d) and pkgconfig(libyuv) BuildRequires: and pass WITH_AOM=ON, WITH_DAV1D=ON and WITH_YUV=ON to cmake, enable optional encoders/decoders. ==== libapparmor ==== - add changes-since-5.0.2.diff - several profile updates - fix compability with Swig 4.5 (boo#1275508) - drop upstreamed nslookup.diff - refresh kerberosclient-usrmerge.diff - add dovecot.diff with several dovecot profile updates (boo#1265453) ==== mlterm ==== Version update (3.9.4 -> 3.9.5) Subpackages: mlterm-common mlterm-ibus mlterm-sdl2 - version update to 3.9.5 * Support text-input-unstable-v3. * Support SGR Mouse Pixel Mode. * Support libvte-2.91-gtk4 compatible library. (Experimental) * Support DRCSMMv3. (https://github.com/kmiya-culti/RLogin/issues/152) * Support selecting regions in pictures with the mouse. (https://github.com/arakiken/mlterm/issues/151) * Support kmsdrm in mlterm-sdl2. (Inspired by https://github.com/chu-hai/mlterm/tree/sdl2_kmsdrm) * Add --adc/use_arabic_dynamic_comb option. (https://github.com/arakiken/mlterm/issues/136) * Add --crsz/cursor_size option to mlterm-fb. (https://github.com/arakiken/mlterm/issues/155) * Add --dndesc/dnd_escape_mode option. (https://github.com/arakiken/mlterm/issues/153) * Add --xtrz/allow_xtwinops_resize option. (https://github.com/arakiken/mlterm/issues/165) * Add vte 0.84 API symbols to libvte compatible library. * Add 52 to DA1. (https://github.com/arakiken/mlterm/issues/144) * Check permissions in Android. * Merge patches: https://github.com/arakiken/mlterm/pull/166 * Bug fixes: https://github.com/arakiken/mlterm/issues/138 https://github.com/arakiken/mlterm/issues/139 https://github.com/arakiken/mlterm/issues/141 https://github.com/arakiken/mlterm/issues/143 https://github.com/arakiken/mlterm/issues/151 https://github.com/arakiken/mlterm/issues/152 https://github.com/arakiken/mlterm/issues/156 https://github.com/arakiken/mlterm/issues/157 https://github.com/arakiken/mlterm/issues/159 https://github.com/arakiken/mlterm/issues/163 Fix dead lock in mlterm-sdl2. Fix segfault in using ibus in wayland. Fix DnD in wayland. Fix segfault in loading a scrollbar with the use of pixmap_engine. - deleted patches * mlterm-gcc15.patch (upstreamed) ==== nvidia-open-driver-G07-signed ==== Version update (595.91.07_k7.2.0_1 -> 595.99.02_k7.2.0_1) - update non-CUDA variant to 595.99.02 (boo#1277068) - enable -rt kernel flavor for SLE >= 16.1 ==== nvidia-open-driver-G07-signed-cuda ==== - update non-CUDA variant to 595.99.02 (boo#1277068) - enable -rt kernel flavor for SLE >= 16.1 ==== openSUSE-release ==== Version update (20260827 -> 20260828) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== salt ==== Subpackages: python313-salt salt-master salt-minion - Honor proxy settings in gitfs, git_pillar and winrepo (bsc#1261147) - Added: * honor-proxy-settings-in-gitfs-git_pillar-and-winrepo.patch ==== srt ==== Version update (1.5.6 -> 1.5.7) - Update to version 1.5.7: + Security Notice: - This release includes important security hardening and multiple vulnerability fixes identified during extensive security audits of the SRT codebase. Several issues could allow memory corruption, protocol state manipulation, resource exhaustion, or misuse of auxiliary tools and CI infrastructure. - Users are strongly encouraged to upgrade to this version to benefit from these security improvements and protocol hardening measures. + Security Improvements: - Handshake and Encryption Security: . Fully remediated the KMREQ processing vulnerability by validating all incoming KM message lengths before they reach internal conversion and copy routines, protecting both HSv4 and HSv5 negotiation paths. . Completed the remediation of the encryption downgrade vulnerability by preventing post-establishment KMRSP messages from modifying the security state of already secured sessions. Additional protections were added for both HSv4 and HSv5 negotiation paths. . Added minimum MSS enforcement during connection negotiation to prevent undersized payload buffers that could otherwise lead to heap corruption and information disclosure during handshake generation. . Hardened handshake state processing to correctly derive connection state from the live connection status and prevent unintended state rollback caused by late or malformed handshake exchanges. - Data Plane Protection: . Fixed validation of ACK control messages to prevent send-buffer corruption caused by forged or malformed acknowledgements. Additional bounds checking now ensures that sequence number ranges remain valid before buffer state updates occur. . Added protection against invalid DROPREQ ranges. Reversed ranges and invalid sequence number distances are now rejected before modifying receiver buffer state. . Corrected receive-path connection status handling to prevent non-addressed packets from affecting unrelated connection attempts. - FEC Robustness: . Added payload-size validation in FEC clipping operations to prevent out-of-bounds writes when processing oversized payloads. . Introduced minimum-size validation for FEC control packets, eliminating integer-underflow conditions that could occur when processing malformed packets. . Added upper bounds for peer-supplied FEC configuration values and improved error handling to prevent excessive memory allocation during connection establishment. - Bonding Reliability: . Fixed a use-after-free condition in the bonding BACKUP send path. Internal member context tracking now safely handles members removed while locks are temporarily released, preventing dangling references during failover processing. - Application Hardening: . Added validation of remotely supplied filenames in the srt-file-transmit utility. Path separators, parent directory references, and platform-specific path manipulation patterns are now rejected before files are created. + Build and CI Security Enhancements: - Replaced the dynamic Codecov script download mechanism with a pinned and integrity-verified version. - Pinned ABI compatibility checker dependencies to specific versions and removed reliance on mutable default branches. - Improved GitHub workflow supply-chain protection by pinning third-party actions, container images, and external dependencies to known revisions. + Stability Improvements: - Fixed local connection teardown handling following rejected late handshakes, ensuring the local endpoint correctly terminates invalid connection states. - Improved error handling for FEC initialization failures and memory allocation exceptions, providing graceful connection rejection instead of abrupt failures. + Test Coverage: - Additional negative and security-focused test coverage has been added for: . Malformed KMRSP messages. . Encryption downgrade scenarios. . ACK validation. . DROPREQ malformed and reversed ranges. . FEC oversized payloads and invalid configurations. . Connection cleanup and shutdown paths. ==== wicked ==== Subpackages: wicked-service - Fix two OOB reads in ni_capture_inspect_udp_header and improve: [+ 0001-capture-fix-two-OOB-reads-in-ni_capture_inspect_udp.patch] - Reject packets with ip_len < ihl to avoid a size_t underflow of the UDP length, which the checksum truncates to uint16_t (bsc#1274627, CVE-2026-71401). - Set payload_len to the remaining payload, not ip_len, which over-read the DHCP option walker by ihl + 8 bytes past the buffer (bsc#1274627, CVE-2026-71402). - Avoid checksumming packets that fail the length/protocol checks and tidy up the debug messages (bsc#1274627). - Fix underflow check in ni_dhcp4_option_next to handle option code and length separately as the END and PAD options don't have length (bsc#1274627). Thanks to Daniel Birtwhistle for discovering and reporting the issues.