Packages changed: ImageMagick (7.1.2.27 -> 7.1.2.28) PackageKit (1.3.5 -> 1.3.6) ca-certificates (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) fwupd (2.1.6 -> 2.1.7) libfastjson libostree (2026.1 -> 2026.2) ntfs-3g_ntfsprogs (2022.10.3 -> 2026.7.7) openSUSE-release (20260728 -> 20260729) rsyslog (8.2502.0 -> 8.2606.0) selinux-policy (20260715 -> 20260727) sssd util-linux (2.42.1 -> 2.42.2) util-linux-systemd (2.42.1 -> 2.42.2) === Details === ==== ImageMagick ==== Version update (7.1.2.27 -> 7.1.2.28) Subpackages: ImageMagick-config-7-SUSE libMagickCore-7_Q16HDRI10 libMagickWand-7_Q16HDRI10 - versn update to 7.1.2.28 * build(deps): bump ubuntu from b7f4819 to 3131b4c in /.devcontainer #8876 * build(deps): bump actions/checkout from 7.0.0 to 7.0.1 #8882 * Fixes for PTIF writer to re-enable default creation of pyramid levels #8884 * build(deps): bump the codeql-action group with 3 updates #8881 * build(deps): bump actions/attest from 4.1.1 to 4.2.0 #8880 * fix: upgrade http:// to https:// in README.md #8867 * Fix memory leak in ASHLAR coder when action fails #8865 * build(deps): bump github/codeql-action/upload-sarif #8862 * build(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0 #8863 * build(deps): bump github/codeql-action/init from 4.36.3 to 4.37.0 #8861 * Fix writing video output to stdout in Windows #8860 * build(deps): bump github/codeql-action/upload-sarif #8851 * build(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3 #8849 * build(deps): bump github/codeql-action/init from 4.36.2 to 4.36.3 #8850 * re-add support for libheif 1.7.0 #8841 * Fix writing video output to stdout in Windows (#8860) #7900 * beta release 3dd3215 * Make sure git is configured properly when updating the website. 2e09a16 * address remote TOCTOU issues 99d821d * eliminate compiler warning 8e835bd * map Windows file identity into st_dev/st_ino. a15976c * eliminate compiler warning c36f9ed * check image file identity da02de3 * normalize the AE metric f85632e * eliminate compiler warning 414297f * support ImageInfo properties member 560f000 * improve formatting 23cfa27 * eliminate compiler warning 2f7deb8 * initialize image info properties ee20b08 * cosmetic d87c54b * revert c5a692a * time-of-check to time-of-use check ef0eb6d * normalize AE metric de81b9a * if path attributes fail relinquish memory 9f18109 * ensure file resource identify is valid bbbf79e * premature reconstruct destruction d110964 * revert similarity image patch 60c110f * if compare:virtual-pixels is present and false then min bounds 11b86af * restore parallelism 33e5931 * include file mode when validating file identity c081559 * eliminate compiler exception 94df319 * define POSIX file type and permission macros 4fcd510 * localize defines d99edfd * define S_IWUSR ed17fb2 * https://github.com/ImageMagick/ImageMagick/issues/8856 2d68170 * reviewed and made subtle corrections to a few composite ops 55e52c4 * Corrected IsPaletteImage check. b93264e * Corrected comment. 10e4271 * https://github.com/ImageMagick/ImageMagick/issues/8858 686729b * eliminate compiler warning a73378f * eliminate compiler warning 55a6aaf * update to the latest ImageMagick documentation 60fcb88 * Restored icon. d551454 * Updated configure. 8714fef * Small memory allocation optimization. 2d4d387 * Updated configure. e0c11e3 * Use max compression for all archives. 8270efa * guarantee round-trip fidelity for IEEE‑754 doubles without printing spurious digits 676d2c3 * No longer inline the method to reduce the local stack size. d53e028 * correct cast from char to quantum 0f86975 * https://github.com/ImageMagick/ImageMagick/issues/8864 549f90b * do not divide by alpha for plus op 31c97dd * revert 5bbda08 * introduce image:frames define 7fd62c7 * eliminate compiler warning 4548c02 * FILE_READ_ATTRIBUTES is preferred over GENERIC_READ 63cc8c7 * Updated the dependencies. 873e31a * safe read/write 20dcf6d * use 1mb chunks 7618f43 * use parens in macro 7a5bc5b * eliminate compiler warning 3744060 * https://github.com/ImageMagick/ImageMagick/issues/8436 f2e478b * avoid division by 0 ec19dcd * cosmetic 62da037 * revert 3e31b7f * increase threads for PHASE metric 5a774ca * fix PDC metric fc48f7d * correct angle 836651e * https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6rvv-36hw-5rgf 297c894 * Read DNG profiles when pinging the image. eeea9da * Cosmetic. 55c96d0 * configure distributed cache max clients and max unathenticated clients e9c84d9 * precompute the phase spectrum for all (u,v) frequency pairs simultaneously, 8470c17 * use virtual memory for phase spectra 4c2e04d * cosmetic 46c11a2 * spatial phase subimage search 073502f * add zlib dependency a5956e8 * restore FFT case 39fa09d * Restored logo vector files. b3c3fba * Exclude logo from the release archive. e40b4d4 * Cosmetic. 8e2561a * improve numerical stability c08cf98 * handle non-square images e5f4934 * thread phase spectra 7211f83 * eliminate compiler warning 8f527e8 * add workload factor define 6825ff5 * eliminate compiler warning 11de3d1 * adapt Fred’s spatial PHASE algorithm f94ceb9 ... changelog too long, skipping 11 lines ... * Write the x and y offset in the tga encoder when the value fit in the unsigned short range. f55e398 ==== PackageKit ==== Version update (1.3.5 -> 1.3.6) Subpackages: PackageKit-backend-zypp PackageKit-gstreamer-plugin PackageKit-gtk3-module PackageKit-lang libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Update to version 1.3.6 (bsc#1267250, CVE-2026-10294): + Bugfixes: - daemon: stop idle progress timer after flushing updates - tests: Actually run the daemon tests on CI using a helper - tests: daemon: Auto-answer interactive prompts from the test - tests: Refactor and reorganize tests - pk-client: Perform any state changes & teardown before g_task_return_*() - package-sack: Fix a double-free issue on PkTask - Ensure we can send SIGQUIT to spawned backends - Prevent a race between the test harness and pk_readline* for input - daemon: Do not accept symlinks as frontend socket - daemon: Return proper error codes for bad SetHints() input - Don't leak TESTDATADIR into production binaries - daemon: Whitelist ONLY_DOWNLOAD for specific transaction roles only - lib: Don't warn on generic D-Bus errors - Send SIGTERM to ask subprocesses to quit, instead of SIGQUIT - daemon: Check errno instead of kill() return values to determine why it failed - pk-client: Fix race between cancellation and TID/proxy assignment + Miscellaneous: - PkTransaction: Simplify the error quark creation - ci: Ensure D-Bus is available and running for all tests - docs: Add error-checking to PK usage example ==== ca-certificates ==== Version update (2+git20260717.2e3a23b -> 2+git20260727.241e0ff) - Update to version 2+git20260727.241e0ff: * certbundle.run: fix case where cafile does not exist ==== fwupd ==== Version update (2.1.6 -> 2.1.7) Subpackages: fwupd-bash-completion fwupd-lang libfwupd3 typelib-1_0-Fwupd-2_0 - Update to version 2.1.7: + This release adds the following features: - Add "well known" AppStream IDs for common BIOS settings - Add MTD lock security attribute - Add support for "externally managed" EFI signature lists - Add systemd-pcrlock plugin and hook up to UEFI updates - Add TCG disk encryption security attribute - Enable more plugins when compiling for Android + This release fixes the following bugs: - Add wrappers for input streams for future Rust implementations - Allow overriding some methods in FwupdClient for a future refactor - Allow plain string versions for some AMD GPUs - Allow suspend-to-ram with encrypted RAM - Always test Dell dock type when connected - Avoid possible out-of-bounds read in when parsing the DFU sector - Do not abort when udisks cannot resolve a device - Do not allow force installs over D-Bus - Do not fail to start when a pre-group comment has no keys set - Fall back to copying the file descriptor contents when not sealed - Fix dropped status updates during updates - Fix FW update for Lenovo TBT5 Smart Dock 7500 - Fix fwupd-refresh.service polkit auth errors - Fix segfault parsing some logitech-hidpp bootloader records - Fix the seal self tests when building on a tmpfs - Fix update failure when the TP IC is in bootloader-only mode - Mark Coreboot VBOOT as obsoleting BootGuard verified - Move more per-class limits to the class instances to reduce RSS - Prepare modem-manager firmware after firehose detach - Reject out-of-range CCGX device mode before indexing versions - Require trusted metadata for device updates - Require trusted metadata when using OnlyTrusted - Skip modem-manager secboot status when unsupported - Use safe reads for synaptics-rmi device responses - Validate GUID-defined section offset against EFI section size + This release adds support for the following hardware: - PixArt PJP360 device ==== libfastjson ==== - Employ a Source URL for the tarball - Modernize some macros ==== libostree ==== Version update (2026.1 -> 2026.2) Subpackages: libostree-1-1 - Update to 2026.2: * Fix GVariant memory leak during opaque whiteout scanning that could cause bootc install to-disk to fail with EBUSY on unmount * Fix a crash for invalid UTF-8 ref names during pull operations * Fix Kernel argument handling was fixed to properly handle quoted values in /proc/cmdline * Correct staged deployment bootconfig merging to preserve options across re-staging ==== ntfs-3g_ntfsprogs ==== Version update (2022.10.3 -> 2026.7.7) Subpackages: ntfs-3g ntfsprogs - Update to version 2026.7.7: * (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616). * Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617). * Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618). * Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569). * Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571). * Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570). * Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572). * Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135). * Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136). - Drop patches fixed upstream: + ntfs3g-unistr-use-after-free.patch + ntfs3g-heap-overflow.patch + 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch + 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch + 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch + 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch + 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch + 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch + 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch ==== openSUSE-release ==== Version update (20260728 -> 20260729) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== rsyslog ==== Version update (8.2502.0 -> 8.2606.0) - dropped separate tarball for rsyslog-doc, now included in main sources (https://www.rsyslog.com/downloads/download-v8-stable/) - upgrade to rsyslog 8.2606 (bsc#1272414 CVE-2026-61548) * 2026-06-23: imtcp: add stream compression support * 2026-06-23: docs: add queue-full troubleshooting * 2026-06-22: mmpstrucdata: document structured-data buffer invariant * 2026-06-21: doc: refine object terminator wording * 2026-06-21: doc: clarify security release handling * 2026-06-21: doc: clarify RainerScript semicolon use * 2026-06-20: rainerscript: escape embedded NULs at C-string boundary * 2026-06-20: doc: explain service sandboxing for helpers * 2026-06-20: doc: address service sandboxing review * 2026-06-20: Apply suggested fix to tools/pmrfc3164.c from Copilot Autofix * 2026-06-19: rainerscript: fold constant comparisons * 2026-06-18: doc: clarify partial config validation * 2026-06-18: config: warn on constant boolean operands * 2026-06-17: parser: honor parseHostnameAndTag in RFC3164 parser * 2026-06-17: core: fix negated exact priority filters * 2026-06-16: rainerscript: keep random result non-negative * 2026-06-16: rainerscript: add cbool function * 2026-06-16: pmrfc3164: honor parseHostnameAndTag at runtime * 2026-06-16: msg: invalidate programname when tag changes * 2026-06-16: imfile: deliver same-file monitors independently * 2026-06-16: glbl: keep debug logfile notice informational * 2026-06-16: doc: modernize GELF forwarding tutorial * 2026-06-15: ommail: add SMTP mode test * 2026-06-15: mmjsonparse: modernize test output paths * 2026-06-14: parser: add optional trailing CR stripping * 2026-06-14: ompgsql: accept long server hostnames * 2026-06-14: dynstats: warn on duplicate bucket names * 2026-06-14: action: warn on duplicate action names * 2026-06-13: omfwd: use matching atomic mutex helper * 2026-06-08: Merge pull request #7014 from rsyslog/cursor/critical-correctness-bugs-480c * 2026-06-05: omazureeventhubs docs: fix underscored parameters * 2026-06-04: runtime: fix YAML promotion OOM ownership * 2026-06-04: omuxsock docs: correct template parameter * 2026-06-04: omhttp: own Splunk profile template names * 2026-06-04: mmjsonparse: reject boundary trailing data * 2026-06-04: mmdblookup: preserve uint64 values * 2026-06-04: mmdblookup: check uint64 fallback formatting * 2026-06-04: impstats docs: fix dotted log parameters * 2026-06-04: impstats docs: clarify parameter name guidance * 2026-06-04: imkafka: stop workers on startup failure * 2026-06-04: imkafka: refine startup stop flag handling * 2026-06-04: doc: match Sphinx duplicate CLI override handling * 2026-06-04: doc: keep stable git docs out of dev mode * 2026-06-04: doc: format stable rst_prolog metadata * 2026-06-04: doc: fix database tutorial SQL template option * 2026-06-03: regexp: avoid per-thread shutdown double-free * 2026-06-03: omkafka: fix NULL topic and add action name to onDestroy flush logs * 2026-06-03: mmsnareparse: honor searchWindow in tabbed trailing scan * 2026-06-03: mmsnareparse: cap tab trailing search by token * 2026-06-03: imfifo: guard absent module config paths * 2026-06-03: imfifo: bind instances to module config * 2026-06-03: imdiag: fix stats reporting gate * 2026-06-03: imdiag: avoid checked cond signal while locked * 2026-06-03: docker: gate collector imtcp module * 2026-06-03: docker: derive single imtcp enable switch * 2026-06-03: docker: default derived imtcp switch in collector * 2026-06-02: yamlconf: clean up include recursion guard * 2026-06-02: tls: propagate wolfSSL send-side read retry * 2026-06-02: tls: keep wolfSSL send retry local * 2026-06-02: tls: bound wolfSSL send-side read retries * 2026-06-02: sidecar: cap UDP burst buffer by total bytes * 2026-06-02: runtime: include limits.h for INT_MAX in yamlconf * 2026-06-02: runtime: guard against recursive YAML includes * 2026-06-02: runtime/queue: reset sizeOnDisk after safe recovery * 2026-06-02: rainerscript: accept optimizer NOP statements * 2026-06-02: omkafka: fix HUP deadlock when doAction holds mut_doAction (#7129) * 2026-06-02: omhttp: avoid retry-ruleset self-stall * 2026-06-02: omhiredis: fix TLS context error log * 2026-06-02: mmpstrucdata: support custom SD containers * 2026-06-02: mmjsonparse: fix find-json ownership and scan bounds * 2026-06-02: mmjsonparse: clear JSON pointer after ownership transfer * 2026-06-02: devtools: fold local review experiment into planner * 2026-06-01: translate: cover script serialization (#7152) * 2026-06-01: dev_env: include lcov in Ubuntu coverage images * 2026-06-01: ChangeLog: update 8.2606 entries * 2026-06-01: Add parse_time_localtz with documentation * 2026-05-31: runtime: join final worker after shutdown wait * 2026-05-31: runtime: harden raw message replacement growth * 2026-05-31: runtime: fix $!all-json serialization locking * 2026-05-31: ratelimit: centralize per-source enforcement * 2026-05-31: parser: fix NetAddr cleanup on mask parse errors * 2026-05-31: omclickhouse: report HTTP response errors * 2026-05-31: omclickhouse: document SQL template option * 2026-05-31: omclickhouse: clean up JSON root on OOM * 2026-05-31: action: avoid committing suspended retry batches * 2026-05-31: Keep transactional action queue messages on shutdown * 2026-05-30: rainerscript: add tocef() and cef_ext_escape() for CEF output * 2026-05-30: doc: clarify queue crash durability limits * 2026-05-30: devtools: add read-only C format check * 2026-05-29: tls: propagate send-side receive retry * 2026-05-29: tls: preserve send-side receive retry state * 2026-05-29: tls: preserve send retry without reconnect * 2026-05-29: tls: keep wolfSSL send-side retry local * 2026-05-29: tls: keep send-side read retries local * 2026-05-29: template: apply style-check formatting * 2026-05-29: style: format msg replacement tests ... changelog too long, skipping 1046 lines ... * 2025-02-20: Fix typo in debug printf of ommysql ==== selinux-policy ==== Version update (20260715 -> 20260727) Subpackages: selinux-policy-targeted - Update to version 20260727: * pwaccessd_t uses nsswitch and newidmapd connects to pwaccessd_t socket (bsc#1271860) * adjust amavis spool path regex for openSUSE (bsc#1268627) * Allow cupsd_t to communicate with fprintd via dbus (bsc#1268366) * Support vfs_snapper to work with samba_share_t (bsc#1265400) * vfs_samba uses dbus to communicate with snapper (bsc#1265400) ==== sssd ==== Subpackages: libnfsidmap-sss libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap - Enable sssd-idp. This provides external Identity Provider (OAuth2/OpenID Connect) support. Also enables the krb5 idp plugin. ==== util-linux ==== Version update (2.42.1 -> 2.42.2) Subpackages: libblkid1 libfdisk1 libmount1 libsmartcols1 libuuid1 util-linux-lang - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ==== util-linux-systemd ==== Version update (2.42.1 -> 2.42.2) Subpackages: lastlog2 liblastlog2-2 - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (for linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - INCOMAPTIBLE CHANGE: LIBMOUNT_FORCE_MOUNT2 is ignored for unprivileged users for safety reasons. - Update to version 2.42.2: * Security fixes: * CVE-2026-53613 - mount(8) TOCTOU race on target path. The SUID mount does not pin the mount target directory, allowing a race between path resolution and the actual mount syscall. A local attacker can swap an ancestor directory component between these steps to redirect a mount to an arbitrary location. (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g) * CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change. The X-mount.owner, X-mount.group, and X-mount.mode options use path-based lchown()/chmod() after mounting. An attacker can swap the target between mount and the ownership/mode change to gain control of arbitrary files. (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh) * CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2. The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered via safe_getenv() in SUID context. A local attacker can force the legacy mount(2) code path, which uses a two-step bind+remount or propagation sequence with a window where security flags (nosuid, noexec,...) are not yet applied. (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx) * CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up). The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the last path component. This update uses openat2(RESOLVE_NO_SYMLINKS) to reject symlinks at any component of the backing file path. (bsc#1268886#c2, bsc#1261606) * libblkid: use-after-free in nested partition probing. The partitions list stores partitions in a contiguous array grown by reallocarray(). When the array is reallocated, all existing blkid_partition pointers become dangling. (bsc#1269583, bsc#1268886#c2, CVE-2026-13595) * fdisk-list: * fix memory leak when partition returns empty string * fix memory leak in partition listing * fsck.minix: bound namelen guessed in get_dirsize * hexdump: fix buffer overflow in color_cond() * libblkid: fix use-after-free in nested partition probing * libfdisk: fix use of on-disk sizeof_partition_entry in GPT * libmount: * add mount ID verification and man page TOCTOU note * use fd_target in hook_idmap for move_mount() * restrict X-mount.subdir for non-root to Linux >= 6.15 * use fd-based fchownat/chmod in hook_owner * ignore X-mount.nocanonicalize for restricted users * add fd_target to context for TOCTOU prevention * fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path * detect fanotify queue overflow in monitor * fix subvolid buffer overflow in get_btrfs_fs_root * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file * lscpu: free cputype ISA string * lslogins: bound lastlog2 tty/host copy to destination size * nsenter: Fix invalid fd check in enter_namespaces * readprofile: replace popen() with fork/exec for .gz map files - Refreshed Add-documentation-on-blacklisted-modules-to-mount-8-.patch. - If needed, display post installation message. - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219).