Packages changed: MicroOS-release (20260809 -> 20260811) leancrypto ncurses (6.6.20260613 -> 6.6.20260808) openvpn (2.6.14 -> 2.7.5) patterns-kde permissions (1699_20260805 -> 1699_20260806) python-pycairo (1.29.0 -> 1.29.1) rootlesskit (3.0.2 -> 3.1.0) shadow (4.20.0 -> 4.20.2) udisks2 (2.11.1 -> 2.11.2) === Details === ==== MicroOS-release ==== Version update (20260809 -> 20260811) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== leancrypto ==== - Workaround for armv6 build (leancrypto assumes 32-bit is armv7) ==== ncurses ==== Version update (6.6.20260613 -> 6.6.20260808) Subpackages: libncurses6 ncurses-utils terminfo-base - Add ncurses patch 20260808 + various improvements/fixes to test/dup_field.c + correct a check for FORM* in test/tracemunch + correct an ifdef in delscreen when using --enable-reentrant (report by Vassili Courzakis). + modify dup_field to allocate buffers needed for wide-character configuration of dup_field (report by Serhiy Storchaka). + correct masking of wide characters into chtype in winch (report by Serhiy Storchaka). - Add ncurses patch 20260801 + use ansi+csr in aaa+dec -TD + use ansi+idc in hurd, tw100, vt420 -TD + use ansi+erase in tw100 -TD + add vt100+tabs -TD + fix unbounded recursion in winsch if given a parameter which is not a valid character in the current encoding (report/analysis by Serhiy Storchaka). - Add ncurses patch 20260725 + use ansi+cpr in beterm -TD + use ansi+csr in aixterm, att6386, hirez100, iris-ansi -TD + use ansi+idc in vt220-base -TD + add ansi+sc -TD + fixes for compiler warnings/cppcheck. + amend 20260307 change to read_entry.c, to allow reading terminfo compiled in ncurses 6.1 and earlier (reports by Todd Richmond, Sven Joachim, cf: 20180331). - Add ncurses patch 20260718 + drop kbs from vt100+arrows and vt100+apparrows to increase usage -TD + add xterm+24fkeys -TD + fixes to escape comma and backslash consistently with infocmp for - g/-G options. - Add ncurses patch 20260711 + add otty -TD + add vt100+arrows, vt100+apparrows -TD - Add ncurses patch 20260704 + add zutty -TD + modify winch() and winsch() to use wcstombs() to convert 8-bit codes to Unicode when ncurses is configured to support Unicode but is not using UTF-8 encoding (report/analysis by Serhiy Storchaka). + fixes for compiler warnings/cppcheck. + fixes for scan-build, valgrind build/testing. + fix a memory leak in _nc_resolve_uses2 (report/testcase by Yufeng Wu, Zhijie Zhang, Qizhen Xu) + add a check for escaped nul in fmt_complex (report/testcase by Yufeng Wu, Zhijie Zhang, Qizhen Xu). + add a limit-check in _nc_tgetent (report by Utku Yildirim). + add a buffer-limit check in tgetstr. - Port ncurses-6.6.dif, ncurses-5.9-ibm327x.dif, and ncurses-6.5-ghostty.dif - Add ncurses patch 20260627 + add a makefile symbol for the names of the installed libraries to simplify parallel build of more than one configuration (patch by Luca Fancellu). + change misc/Makefile to eliminate "pc-files" stamp target (report by Luca Fancellu). + change internal type for file-descriptor to int, eliminate cast (report by Antonio Nino Diaz). + add xon to several entries, based on manuals and product descriptions -TD + revise adm36, based on manual -TD + add u6, u7, kdch1 to vp3a+ based on manual -TD + add u6, u7, home, cbt to adm20 based on manual -TD - Add ncurses patch 20260620 + add il1 to ibcs2 -TD + add ich1 to several entries, providing for support of non-curses applications via termcap only -TD + add ich/ich1 to teraterm2.3 based on ttsrcp23.zip source-code -TD + add ich/ich1 to x10term based on X.V10R4/xterm source-code -TD + add ich/ich1 to xterm-r6 based on source-code -TD + add ich/ich1 to mterm-ansi and decansi based on source-code -TD + add ich/ich1 to tek4025a, tek4105a, tek4106brl from manual -TD + modify infocmp, tic, and tgetent to omit ich1 (termcap "ic") while providing termcap data when smir/rmir (termcap "im/ei") are given. + reduce warning in tic regarding termcap applications which do not work with smir/rmir combined with ich1. ==== openvpn ==== Version update (2.6.14 -> 2.7.5) Subpackages: openvpn-auth-pam-plugin - Update to version 2.7.5 * Multiple security fixes (CVE-2026-13379, CVE-2026-12996, CVE-2026-13117, CVE-2026-13122, CVE-2026-12932, CVE-2026-11771, CVE-2026-13698) * Improved DCO (Data Channel Offload) support built-in * Better multi-socket event handling * Enhanced DNS configuration handling * Windows openvpnserv improvements and fixes - Add debian packaging files (debian.control, debian.rules, debian.tar.xz, *.dsc) as Source entries - Remove all DCO patches (integrated or superseded in 2.7.5): * 0001-dco-better-naming-for-function-parameters.patch * 0001-dco_linux-extend-netlink-error-cb-with-extra-info.patch * 0001-Handle-missing-DCO-peer-by-restarting-the-session.patch * 0001-dco_linux-Introduce-new-uAPIs.patch * 0001-Implement-ovpn-version-detection.patch * 0001-dco_linux-fix-peer-stats-parsing-with-new-ovpn-kerne.patch * 0001-dco_linux-avoid-bogus-text-when-netlink-message-is-n.patch * 0001-dco-linux-avoid-redefining-ovpn-enums.patch - Change Recommends to ovpn-kmp (simplified) ==== patterns-kde ==== - Remove plasma6-session-x11 from the plasma 6 pattern (boo#1274552) ==== permissions ==== Version update (1699_20260805 -> 1699_20260806) Subpackages: permctl permissions-config - Update to version 1699_20260806: * profiles: add spine cap_net_raw (bsc#1273300) ==== python-pycairo ==== Version update (1.29.0 -> 1.29.1) - Update to 1.29.1: * Update dependencies (libpng, zlib) for the Windows wheels * Fix documentation build with Python 3.15 * Build wheels for Python 3.15 (except for 32bit Windows) * Fix a memory leak in ScaledFont.text_to_glyphs() * Fix some minor reference leaks ==== rootlesskit ==== Version update (3.0.2 -> 3.1.0) - Update to version 3.1.0: * v3.1.0 * feat: support --port-driver=pesto for IPv4 * docs: refresh network driver benchmark table * fix: benchmark pasta, not slirp4netns * fix: correct field names in ParsePortSpec error messages * fix(pasta): block host loopback access from the namespace when `--disable-host-loopback` is set * Build(deps): Bump actions/setup-go from 6 to 7 * chore: update error message when the pasta binary dosen't exist * v3.0.2+dev ==== shadow ==== Version update (4.20.0 -> 4.20.2) Subpackages: libsubid6 login_defs shadow-pw-mgmt - Update to 4.20.2: * lib/: Add missing include. * Remove unused build flag - Drop upstreamed shadow-4.20-stdint.patch ==== udisks2 ==== Version update (2.11.1 -> 2.11.2) Subpackages: libudisks2-0 - Update to 2.11.2 (CVE-2026-7867): * This is a bugfix release with a security fix, several crash and memory leak fixes, and mount options update. * Security fix: - CVE-2026-7867: An unprivileged D-Bus caller could use the 'as-user' Filesystem.Mount() option combined with fstab entries containing 'user' or 'users' mount options to mount on behalf of another user without polkit authorization. * Changes from 2.11.1: - udiskslinuxnvmenamespace: Report cancellation as error in format job - udiskslinuxprovider: Fix memory leak on spurious uevents - udiskslinuxprovider: Initialize GError pointer in sleep signal handler - udisksdaemonutil: Fix missing NULL terminator in resolve_links() - udiskslinuxdriveata: Add missing D-Bus method completion for SecurityEraseUnit - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_resize - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_repair - udiskslinuxfilesystem: Fix missing goto after mount state check in handle_check - udiskslinuxfilesystem: Fix mounted check in filesystem update - udiskslinuxmountoptions: Fix integer overflow in UID/GID option parsing - udiskslinuxmountoptions: Fix static buffer and hardcoded limit in is_uid_in_gid - doap: Update storaged.org https link - udisksmodulemanager: Fix broken module error check - lvm2: Fix NULL dereference in VG create uevent trigger loop - mount options: Sync exfat allowed options with the latest kernel - udiskslinuxfilesystem: Separate real caller identity from as-user target - udiskslinuxfilesystem: Rework fstab mount authorization for as-user - udiskslinuxfilesystem: Log real caller uid for as-user mounts - udisksdaemonutil: Pass as-user target to polkit details - tests: Add security tests for as-user mount authorization - tests: Trigger controller rescan after namespace re-attach in test_ns_detach - tests: Temporarily skip NTFS3 configurable mount options test