Packages changed: GraphicsMagick ImageMagick MozillaFirefox (152.0.6 -> 153.0) btrfsprogs (7.0 -> 7.1) dracut (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) java-25-openjdk (25.0.3.0 -> 25.0.4.0) kf6-kimageformats libdrm mozilla-nss (3.124 -> 3.125) ngtcp2 (1.22.1 -> 1.24.0) open-vm-tools openSUSE-release (20260722 -> 20260723) perl-HTTP-Date (6.70.0 -> 6.80.0) python-numpy (2.4.4 -> 2.4.6) qemu selinux-policy (20260702 -> 20260715) srt (1.5.5 -> 1.5.6) vim wget yast2-add-on (5.0.0 -> 5.0.2) === Details === ==== GraphicsMagick ==== Subpackages: libGraphicsMagick++-Q16-12 libGraphicsMagick-Q16-3 libGraphicsMagick3-config - added patches CVE-2026-61870: Memory leak in VIFF encoder when allocation fails [bsc#1271293] * GraphicsMagick-CVE-2026-61870.patch ==== ImageMagick ==== Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - remove logo.eps (propriatery licence) ==== MozillaFirefox ==== Version update (152.0.6 -> 153.0) Subpackages: MozillaFirefox-branding-upstream MozillaFirefox-translations-common - Mozilla Firefox 153.0 https://www.firefox.com/en-US/firefox/153.0/releasenotes/ MFSA 2026-68 (bsc#1271649) * CVE-2026-16349 (bmo#2034682) Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 (bmo#2042033) Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 (bmo#2043188) Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 (bmo#2045468) Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 (bmo#2046416) Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 (bmo#2047689) JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 (bmo#2047802) Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 (bmo#2049149) Privilege escalation in the DOM: Workers component * CVE-2026-16366 (bmo#2049181) Privilege escalation in the DOM: Navigation component * CVE-2026-16353 (bmo#2049523) Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 (bmo#2050626) Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 (bmo#2050627) Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 (bmo#2051015) Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 (bmo#2051854) Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 (bmo#2052207) JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 (bmo#2052562) Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 (bmo#2053326) Incorrect boundary conditions in the Graphics component * CVE-2026-16370 (bmo#1996495) Mitigation bypass in the DOM: Networking component * CVE-2026-16371 (bmo#2008369) Privilege escalation in the DOM: Navigation component * CVE-2026-16372 (bmo#2013800) Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 (bmo#2021964) Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 (bmo#2027519) Information disclosure in the Framework component in DevTools * CVE-2026-16375 (bmo#2032140) Site isolation issue in the Networking: HTTP component * CVE-2026-16376 (bmo#2035733) Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 (bmo#2037770) Mitigation bypass in the PDF Viewer component * CVE-2026-16378 (bmo#2038868) Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 (bmo#2039452) Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 (bmo#2040119) Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 (bmo#2040386) Mitigation bypass in the Networking component * CVE-2026-16381 (bmo#2041001) Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 (bmo#2041864) Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 (bmo#2041902) Mitigation bypass in the DOM: Networking component * CVE-2026-16384 (bmo#2041911) Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 (bmo#2041912) Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 (bmo#2041916) Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 (bmo#2043200) Site isolation issue in the Networking component * CVE-2026-16388 (bmo#2043845) Sandbox escape in the DOM: Networking component * CVE-2026-16389 (bmo#2043887) Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 (bmo#2044527) Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 (bmo#2044536) Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 (bmo#2044606) JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 (bmo#2045410) Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 (bmo#2045424) Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 (bmo#2046748) Mitigation bypass in the DOM: Security component ... changelog too long, skipping 76 lines ... mozilla-bmo2041150.patch ==== btrfsprogs ==== Version update (7.0 -> 7.1) Subpackages: btrfsprogs-bash-completion btrfsprogs-udev-rules libbtrfs0 libbtrfsutil1 - update to 7.1 * mkfs: * use GET_CSUMS ioctl (if provided by kernel, 7.2) to reuse existing checksums for --rootdir, works with --reflink to avoid reading file data * fix last block handling for reflink * fix handling of incompressible data extents * fix --rootdir size estimation when using hardlinks * fi mkswapfile: add option to specify page size, useful on ARM64 * check: add option to skip qgroup verification to speed up check * in experimental build, use V2 of tree search ioctl, this can use larger buffer * preliminary fscrypt support * enhance filesystem opening modes with more fine-grained support of partially damaged trees and allow to skip non-essential trees * other: * stability and error handling fixes * CI updates * updated tests * documentation updates ==== dracut ==== Version update (110+suse.41.g38f7c003 -> 110+suse.45.geaec47e4) - Update to version 110+suse.45.geaec47e4: * fix(systemd-networkd): escape values from DHCP options (bsc#1264833, GHSA-x37p-6hhc-6628) * feat(base): add escape function implementing printf %q * fix(systemd-networkd): get DHCP options values from networkctl * fix(kernel-modules): include xhci-pci-prom21 for early USB ==== java-25-openjdk ==== Version update (25.0.3.0 -> 25.0.4.0) Subpackages: java-25-openjdk-headless - Update to upstream tag jdk-25.0.4+7 (July 2026 CPU) * CVEs + CVE-2026-46968 (bsc#1272224) + CVE-2026-46917 (bsc#1272223) + CVE-2026-47010 (bsc#1272225) + CVE-2026-47021 (bsc#1272227) + CVE-2026-47027 (bsc#1272228) + CVE-2026-60147 (bsc#1272237) + CVE-2026-47059 (bsc#1272235) + CVE-2026-47063 (bsc#1272236) + CVE-2026-41254 (bsc#1264994) * Changes + JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail + JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails + JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails + JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel + JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F + JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'. + JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04 + JDK-8213530: Test java/awt/Modal/ToFront/ /DialogToFrontModeless1Test.java fails on Linux + JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails + JDK-8225787: java/awt/Window/GetScreenLocation/ /GetScreenLocationTest.java fails on Ubuntu + JDK-8241066: Shenandoah: fix or cleanup SH::do_full_collection + JDK-8261743: Shenandoah: enable String deduplication with compact heuristics + JDK-8264851: Shenandoah: Rework control loop mechanics to use timed waits + JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process" + JDK-8279196: Test: jdk/jfr/event/gc/stacktrace/ /TestG1OldAllocationPendingStackTrace.java timed out + JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages + JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!" + JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder + JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder + JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux + JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/ /TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE + JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer) + JDK-8325482: Test that distinct seeds produce distinct traces for compiler stress flags + JDK-8335355: Shenandoah: Fix race condition in gc/shenandoah/ /mxbeans/TestPauseNotifications.java + JDK-8339526: C2: store incorrectly removed for clone() transformed to series of loads/stores + JDK-8340182: Java HttpClient does not follow default retry limit of 3 retries + JDK-8341735: Rewrite the build/AbsPathsInImage.java test to not load the entire file at once + JDK-8344345: test/hotspot/gtest/x86/x86-asmtest.py has trailing whitespaces + JDK-8345631: TestRegionSamplingLogging.java [#]generational-rotation intermittent fails + JDK-8347167: Reduce allocation in com.sun.net.httpserver.Headers::normalize + JDK-8347938: Add Support for the Latest ML-KEM and ML-DSA Private Key Encodings + JDK-8351010: Test java/io/File/GetXSpace.java failed: / usable space 56380809216 > free space 14912244940 + JDK-8352914: Shenandoah: Change definition of ShenandoahSharedValue to int32_t to leverage platform atomics + JDK-8353115: GenShen: mixed evacuation candidate regions need accurate live_data + JDK-8354650: [PPC64] Try to reduce register definitions + JDK-8355339: Test java/io/File/GetCanonicalPath.java failed: The specified network name is no longer available + JDK-8357086: os::xxx functions returning memory size should return size_t + JDK-8358600: Template-Framework Library: Template for TestFramework test class + JDK-8358772: Template-Framework Library: Primitive Types + JDK-8359083: Test jdkCheckHtml.java should report SkippedException rather than report fails when miss tidy + JDK-8359223: HttpClient: Remove leftovers from the SecurityManager cleanup + JDK-8359412: Template-Framework Library: Operations and Expressions + JDK-8359433: The final modifier on Windows L&F internal UI ... changelog too long, skipping 361 lines ... + JDK-8386551: Windows build broken because of MSys2/Make update ==== kf6-kimageformats ==== - Add upstream change (kde#523105) * 0001-HEIF-keep-reader-callback-table-alive.patch ==== libdrm ==== Subpackages: libdrm2 libdrm_amdgpu1 libdrm_intel1 libdrm_nouveau2 libdrm_radeon1 - add upstream signing key and validate source signature ==== mozilla-nss ==== Version update (3.124 -> 3.125) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.125 * no public releasenotes yet ==== ngtcp2 ==== Version update (1.22.1 -> 1.24.0) Subpackages: libngtcp2-16 libngtcp2-16-32bit libngtcp2_crypto_gnutls8 libngtcp2_crypto_gnutls8-32bit libngtcp2_crypto_ossl0 - Update to 1.24.0: * crypto: Add openssl libs to cryptotest * Add --disable-crypto configure option * crypto: Add ngtcp2_crypto_ossl_free * examples: Avoid the deprecated nghttp3 APIs * lib: Add recv_stop_sending callback * lib: Add ngtcp2_conn_set_max_stream_data_thresh * lib: Tweak ngtcp2_conn_set_max_stream_data_thresh * Remove max stream data thresh * Rewrite window filter from scratch * lib: Tweak app-limited detection * lib: Simplify app-limited conditions * Bump openssl to v4.0.1 * Bump boringssl * Bump aws-lc to v5.1.0 * Bump picotls * Bump wolfssl to v5.9.2-stable - Update to 1.23.0: * log: Faster logging * Use ULL consistently * Transit to closing state when sending application close * Specify QualifierOrder * Provide generic ngtcp2_max and ngtcp2_min * Add ngtcp2_secure_clear * Clear sensitive secrets and keys after use * Add const version * crypto: Add tests for token validation * Add const and remove duplicated code * Remove stale function declarations * crypto: Deal with overflow when computing token timeout * build(deps): bump actions/github-script from 8 to 9 * Revert "fix: prevent max_idle_timeout multiplication overflow in transport params decode" * Deal with large max_idle_timeout that could overflow in computation * Fix qlog params set stack overflow * Log enhancement * Bump LibreSSL to v4.3.1 by @nak3 in #2161 * pq: Adopt designated initializers * Add missing initialization for fields that are not used for CRYPTO * rst: Rename TCP centric variable names * bbr: Cap maximum drain rounds * GHA: Avoid azure Ubuntu mirror * Bump openssl to v4.0.0 * Bump boringssl * Bump picotls * Bump wolfssl to v5.9.1-stable * Bump aws-lc to v1.73.0 * Bump wolfssl to v5.9.1-stable in interop Dockerfile * lib: Apply absolute upper bound against CRYPTO data offset * Adopt sphinx version-add and version-deprecated directives * ppe: Robust ngtcp2_ppe_padding_size * ppe: Ensure packet protection sample with ngtcp2_ppe_dgram_padding_size * cubic: Add missing is_cwnd_limited reset after exiting slow start * Make bitwise operations robust * Make all private hex constants unsigned * lib: Ensure that unidirectional stream shutdown flags properly set * More unsigned hex integer literals * Fix strict aliasing issue in ngtcp2_get_varint * Net cleanup * Bump boringssl * Bump picotls * Bump libressl to v4.3.2 * Consider static const if possible ==== open-vm-tools ==== Subpackages: libvmtools0 open-vm-tools-desktop - Remove all dependencies on update-desktop-files - open-vm-tools (PED-15231) Remove BuildRequires: update-desktop-files and %suse_update_desktop_file vmware-user-autostart from the spec file. ==== openSUSE-release ==== Version update (20260722 -> 20260723) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== perl-HTTP-Date ==== Version update (6.70.0 -> 6.80.0) - updated to 6.80.0 (6.08) see /usr/share/doc/packages/perl-HTTP-Date/Changes 6.08 2026-07-09 02:04:21Z - [SECURITY] Reject input longer than 64 characters in parse_date() to prevent quadratic regex backtracking (a denial of service) on hostile date strings. Fixes CVE-2026-14741. (Olaf Alders) bsc#1271705 ==== python-numpy ==== Version update (2.4.4 -> 2.4.6) - Update to 2.4.6 * Return rank 0 for empty matrices in matrix_rank * fix heap buffer overflow in timedelta to string casts * fix memory leak in np.zeros when fill-zero loop raises * Don’t call INCREF/DECREF on descr in NpyStringAcquireAllocator ==== qemu ==== Subpackages: qemu-audio-spice qemu-block-curl qemu-block-nfs qemu-block-rbd qemu-chardev-spice qemu-guest-agent qemu-hw-display-qxl qemu-hw-display-virtio-gpu qemu-hw-display-virtio-gpu-pci qemu-hw-display-virtio-vga qemu-hw-usb-host qemu-hw-usb-redirect qemu-hw-usb-smartcard qemu-img qemu-ksm qemu-lang qemu-microvm qemu-pr-helper qemu-seabios qemu-tools qemu-ui-curses qemu-ui-gtk qemu-ui-opengl qemu-ui-spice-app qemu-ui-spice-core qemu-vgabios qemu-vmsr-helper qemu-x86 - Properly fix bsc#1268245: * [openSUSE][RPM] spec: fix missing unversioned ppc64 linker (bsc#1268245) ==== selinux-policy ==== Version update (20260702 -> 20260715) Subpackages: selinux-policy-targeted - fix cleanoldsepoldir.sh to properly handle migration markers when /var/lib/selinux doesn't exists (backported from SLFO_Main codebase) - Update to version 20260715: * Allow snapper_sdbootutil_plugin_t status and stop unit files(bsc#1271391) * Allow sdbootutil_t read and write snapperd_t pipes (bsc#1271391) - Update to version 20260713: * Fix wrong gen_requires in snapper_read_data_files (bsc#1271282) ==== srt ==== Version update (1.5.5 -> 1.5.6) - Update to version 1.5.6: + Security Notice: This release includes important security updates that address two significant CVE vulnerabilities affecting previous versions of the library. Users are strongly encouraged to upgrade to this version as soon as possible to benefit from these fixes and reduce exposure to the associated security risks. + The resolved CVEs are listed below: - CVE-2026-55869: Heap-Based Buffer Overflow in KMREQ Handling - CVE-2026-55868: Encryption State Machine Downgrade + Security Improvements: - Implemented security improvements for KMREQ buffer validation. This fix addresses a vulnerability where received message sizes were not verified against the destination buffer size during the copy process. The update enforces word-aligned validation to prevent overflows when copying to internal arrays. - Added strict validation of KMRSP wire length to prevent stack overflows. - Resolved an OOB read in LOSSREPORT range parsing. The logic previously read a "HI" sequence number word following a "LO" marker without verifying if the "HI" word existed in the wire payload. - Fixed an OOB read vulnerability in DROPREQ payload parsing. The handler now verifies that the wire payload meets the minimum 8-byte length requirement (two 32-bit sequence numbers) before attempting to process the request, preventing reads beyond the packet slot. - Introduced a guard in CRcvBuffer::dropMessage to reject requested drop ranges that extend beyond the end of the receiver buffer. + Important Bug Fixes: - Streamlined the library cleanup sequence by removing redundant post-cleaning of closed sockets. Architecture logic dictates that the Garbage Collector (GC) thread is the primary owner of socket deletion. Once the GC thread is joined, all sockets are considered deleted; further post-checks are unnecessary and avoid potential undefined behavior in cases where the library state might be corrupted. - Fixed a segmentation fault (SEGV) occurring during global or static initialization when ENABLE_HEAVY_LOGGING was active. + Build System Enhancements: - Transitioned the CI/CD pipeline to a robust Linux configuration matrix, serving as the modern replacement for Travis CI. The new system includes various platform and compiler combinations and incorporates specific fixes for MinGW builds and C++11 syntax compatibility. + Documentation Updates: Corrected a typographical error in the documentation regarding the separator used for searchParameters. ==== vim ==== Subpackages: vim-data vim-data-common xxd - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). ==== wget ==== Subpackages: wget-lang - Fix metalink regression from CVE-2026-58469 fix See: commit 7b1cdecc49bc77bde220fc575c8a00386c3f3bcf from https://gitlab.com/gnuwget/wget [bsc#1272219, CVE-2026-58469] * CVE-2026-58469.patch ==== yast2-add-on ==== Version update (5.0.0 -> 5.0.2) - fix invalid entry in changelog ( needed to submit jsc#PED-14507) - 5.0.2 - jsc#PED-14507 - Removed reference to update-desktop-files from spec file - 5.0.1