Packages changed: Mesa (26.2.0 -> 26.2.1) Mesa-drivers (26.2.0 -> 26.2.1) MozillaFirefox (153.0.3 -> 154.0) cairomm1_0 (1.14.5 -> 1.14.6) cfitsio (4.6.4 -> 4.7.0) dLeyna (0.8.3 -> 0.8.4) emacs enchant (2.8.15 -> 2.8.19) evolution-data-server gcab geocode-glib glib-networking gnome-maps (50.3 -> 50.4) graphene gspell gtksourceview4 gtksourceview5 json-glib kf6-kio libgedit-gfls (0.4.1 -> 0.4.2) libgedit-gtksourceview (299.7.0 -> 299.7.1) libostree (2026.3 -> 2026.4) libsoup2 mozilla-nss (3.125 -> 3.126.1) mozjs140 (140.13.0 -> 140.14.0) openSUSE-release (20260821 -> 20260822) perl-CryptX (0.89.0 -> 0.91.0) perl-HTTP-Cookies (6.110.0 -> 6.120.0) perl-HTTP-Message (7.20.0 -> 7.40.0) perl-LWP-Protocol-https (6.150.0 -> 6.170.0) pipewire publicsuffix (20260725 -> 20260814) python-gevent (26.5.0 -> 26.8.0) xdg-dbus-proxy (0.1.7 -> 0.1.8) === Details === ==== Mesa ==== Version update (26.2.0 -> 26.2.1) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.2.1 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.1 - Enable virtio vulkan driver ==== Mesa-drivers ==== Version update (26.2.0 -> 26.2.1) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Update to 26.2.1 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.1 - Enable virtio vulkan driver ==== MozillaFirefox ==== Version update (153.0.3 -> 154.0) Subpackages: MozillaFirefox-branding-upstream MozillaFirefox-translations-common - Mozilla Firefox 154.0 * https://www.firefox.com/en-US/firefox/154.0/releasenotes MFSA 2026-74 (bsc#1274867) * CVE-2026-75874 (bmo#2039972) Sandbox escape in the Remote Settings Client component * CVE-2026-74934 (bmo#2050584) Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 (bmo#2051013) Privilege escalation in the DOM: Networking component * CVE-2026-74936 (bmo#2052688) Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 (bmo#2053337) Use-after-free in the JavaScript: GC component * CVE-2026-74938 (bmo#2053688) Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 (bmo#2054416) Privilege escalation in the DOM: Navigation component * CVE-2026-74940 (bmo#2054842) Use-after-free in the Graphics: Text component * CVE-2026-74941 (bmo#2055056) Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 (bmo#2056571) Privilege escalation in the Remote Settings Client component * CVE-2026-74943 (bmo#2057308) Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 (bmo#2057778) Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 (bmo#2057808) Information disclosure in the Graphics: Text component * CVE-2026-74946 (bmo#2059997) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 (bmo#2060010) Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 (bmo#2060106) Information disclosure in the Graphics component * CVE-2026-74949 (bmo#2060245) Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 (bmo#1880253) Privilege escalation in the Downloads API component * CVE-2026-74951 (bmo#1978587) Clickjacking issue in Firefox for Android * CVE-2026-74952 (bmo#2021757) Privilege escalation in the Application Update component * CVE-2026-74953 (bmo#2022382) Privilege escalation in the Networking: Cookies component * CVE-2026-74954 (bmo#2025732) Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 (bmo#2029265) Privilege escalation in the Request Handling component * CVE-2026-74956 (bmo#2032406) Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 (bmo#2041906) Mitigation bypass in the Safe Browsing component * CVE-2026-74958 (bmo#2045368) Information disclosure in the WebRTC component * CVE-2026-74959 (bmo#2047853) Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 (bmo#2049148) Site isolation issue in the WebExtensions component * CVE-2026-74961 (bmo#2050380) Side-channel in the Web Audio component * CVE-2026-74962 (bmo#2050425) Site isolation issue in the Networking: Cookies component * CVE-2026-74963 (bmo#2050482) Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 (bmo#2053327) Integer overflow in the Graphics component * CVE-2026-74965 (bmo#2053455) Privilege escalation in the Shell Integration component * CVE-2026-74966 (bmo#2054776) Information disclosure in the Form Autofill component * CVE-2026-74967 (bmo#2055697) Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 (bmo#2055738) Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 (bmo#2056065) Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 (bmo#2056558) Site isolation issue in the Graphics component * CVE-2026-74971 (bmo#2057204) Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 (bmo#2059053) Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 (bmo#2060357) Race condition, use-after-free in the Graphics component * CVE-2026-74974 (bmo#2061794) Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74975 (bmo#1842361) Spoofing issue in the Downloads component in Firefox for Android * CVE-2026-74976 (bmo#1952164) JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 (bmo#2028440) Integer overflow in the Graphics component * CVE-2026-74978 (bmo#2036097) Clickjacking issue in the Widget component ... changelog too long, skipping 53 lines ... - refresh mozilla.keyring ==== cairomm1_0 ==== Version update (1.14.5 -> 1.14.6) - Update to version 1.14.6: + Fix memory leak in Context::pop_group() + Documentation: - Fix outdated FSF mailing address in COPYING - Change license info. Lesser GPL 2.1 instead of Library GPL 2 - Meson: Use SPDX expression for license - MSVC-Builds.md: Mention Visual Studio 2026 - MSVC-Builds.md: Update build documentation for NMake - cairomm.h: Add the Basic Usage section + Build system (meson) fixes. ==== cfitsio ==== Version update (4.6.4 -> 4.7.0) - Update to version 4.7.0: * This release includes patches to security vulnerabilities. * New test framework added, containing a collection of unit tests. * Bug fix for parsing octal integer constants in expressions. * Enhanced output from uncompress2mem_from_mem function. * Appended 'fits_' prefix to stream driver function names to reduce chances of potential symbol name conflicts with outside libraries. - Bump min version of cmake in BuildRequires to 3.15 to keep up with upstream. - Add pregenerated documentation as Sources. ==== dLeyna ==== Version update (0.8.3 -> 0.8.4) - Update to version 0.8.4: + Core: Fix compatibility with musl + Renderer: Potentially fix crash if renderer device disappears ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Add patch 04_all_shorthands.patch and 03_all_ruby-flymake.patch * First patch fixes bsc#1275941 with VUL-0: emacs: code execution upon opening arbitrary file * Second patch makes ruby support work with ruby 3.4.5 - Add patch emacs-30.2-bsc1275927.patch to Fix bug 1275927: VUL-0: emacs: zero-click local command execution via TRAMP ==== enchant ==== Version update (2.8.15 -> 2.8.19) Subpackages: enchant-2-backend-hunspell enchant-data libenchant-2-2 - Update to version 2.8.19: + This release adds a provider for WinSpell. + The change in the previous release to update the tests and require the use of C++20 have been reverted. - Changes from version 2.8.18: + This release fixes compatibility with the latest Vala compiler, version 0.56.19. + enchant(1) now assumes UTF-8 input and produces only UTF-8 output. + The macOS spelling checker used to have a hard-wired list of languages it supported. Drop this, and support all languages supported by the system. + Some code clean-up has been done, removing some unused code, and making somr minor improvements to the build system. + The tests have been updated to drop the use of the deprecated codecvt APIs, and instead use u8 string literals. As a result, Enchant’s build system now requires C++20. - Changes from version 2.8.17: + Make enchant silently ignore -C flag, for better Emacs compatibility. - Changes from version 2.8.16: + Fix a bug introduced in 2.8.14: after rejecting a word for not containing at least one letter, enchant(1) would skip the rest of the line. ==== evolution-data-server ==== Subpackages: evolution-data-server-lang libcamel-1_2-67 libebackend-1_2-11 libebook-1_2-21 libebook-contacts-1_2-5 libecal-2_0-3 libedata-book-1_2-27 libedata-cal-2_0-2 libedataserver-1_2-27 libedataserverui-1_2-4 - Add evolution-data-server-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gcab ==== Subpackages: gcab-lang libgcab-1_0-0 - Enable meson installed tests (-D tests=true) and add %check section ==== geocode-glib ==== Subpackages: libgeocode-glib-2-0 typelib-1_0-GeocodeGlib-2_0 - Add geocode-glib-tests subpackage with installed tests for gnome-desktop-testing-runner ==== glib-networking ==== Subpackages: glib-networking-lang - Add glib-networking-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gnome-maps ==== Version update (50.3 -> 50.4) Subpackages: gnome-maps-lang - Update to version 50.4: + Only show furigana (hiragana phonetic) names for places when the user has the language set to Japanese. + Fix showing points for via locations for route searching. + Updated translations. ==== graphene ==== Subpackages: libgraphene-1_0-0 typelib-1_0-Graphene-1_0 - Add graphene-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gspell ==== Subpackages: gspell-lang libgspell-1-3 - Add gspell-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gtksourceview4 ==== Subpackages: gtksourceview4-lang libgtksourceview-4-0 typelib-1_0-GtkSource-4 - Add gtksourceview4-tests subpackage with installed tests for gnome-desktop-testing-runner ==== gtksourceview5 ==== Subpackages: gtksourceview5-lang libgtksourceview-5-0 - Add gtksourceview5-tests subpackage with installed tests for gnome-desktop-testing-runner ==== json-glib ==== Subpackages: json-glib-lang libjson-glib-1_0-0 typelib-1_0-Json-1_0 - Add json-glib-tests subpackage with installed tests for gnome-desktop-testing-runner ==== kf6-kio ==== Subpackages: kf6-kio-lang libKF6KIO6 - Add upstream fix (kde#524239, boo#1275906) * 0001-kfileitemactions-fix-submenu-lifetime-using-main-men.patch ==== libgedit-gfls ==== Version update (0.4.1 -> 0.4.2) Subpackages: libgedit-gfls-1-0 libgedit-gfls-lang - Update to version 0.4.2: + Updated translations. ==== libgedit-gtksourceview ==== Version update (299.7.0 -> 299.7.1) Subpackages: libgedit-gtksourceview-300-5 libgedit-gtksourceview-lang typelib-1_0-GtkSource-300 - Update to version 299.7.1: + Updated translations. ==== libostree ==== Version update (2026.3 -> 2026.4) Subpackages: libostree-1-1 - Update to 2026.4: * Revert the static delta decompression-size safety margin introduced in 2026.3, which turned out to reject legitimate large deltas at apply time -- most visibly, Flathub Firefox updates were failing with Decompressed delta part exceeds configured limit. Both the margin heuristic and the flat 512MiB per-part decompression cap it fed into have been dropped for now. This deliberately reopens a DoS (unbounded decompression of a given delta part) until a precise, per-part exact-size- based replacement lands in a future release. The LZMA decoder memory limit (100 MiB) from that same advisory's fix is unaffected and remains in place (boo#1273918) * core: fixed a bug that caused every other xattr entry to be skipped during validation, letting a crafted xattr array hide unsorted or duplicate entries in odd-indexed slots ==== libsoup2 ==== Subpackages: libsoup-2_4-1 libsoup2-lang - Add libsoup2-CVE-2026-12548.patch: Fix heap out-of-bounds read flaw when parsing multipart HTTP messages. (bsc#1272196, glgo#GNOME/libsoup!524) - Add libsoup2-tests subpackage with installed tests for gnome-desktop-testing-runner ==== mozilla-nss ==== Version update (3.125 -> 3.126.1) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.126.1 * bmo#2054719 - fix content type tag for CMS AuthEnvelopedData plaintext - update to NSS 3.126 * no public releasenotes ==== mozjs140 ==== Version update (140.13.0 -> 140.14.0) - Update to version 140.14.0: + Various security fixes + See https://www.firefox.com/en-US/firefox/140.14.0/releasenotes/ ==== openSUSE-release ==== Version update (20260821 -> 20260822) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== perl-CryptX ==== Version update (0.89.0 -> 0.91.0) - updated to 0.91.0 (0.091) see /usr/share/doc/packages/perl-CryptX/Changes 0.091 2026-08-10 - fix #125 (non-NUL-terminated PVs) - new: Crypt::Mode::XTS - new: Crypt::Digest::BLAKE3 - re-enable SHA1/SHA224/SHA256 hash state cloning - bundled libtomcrypt update branch:develop (commit: a10cad62 2026-08-07) - updated to 0.90.0 (0.090) see /usr/share/doc/packages/perl-CryptX/Changes 0.090 2026-06-17 - new: Crypt::AuthEnc::GCMSIV - new: Crypt::Cipher::ARIA - new: Crypt::Digest::SM3 - new: Crypt::Mac::KMAC - bundled libtomcrypt update branch:develop (commit: a68fa19b 2026-05-19) ==== perl-HTTP-Cookies ==== Version update (6.110.0 -> 6.120.0) - updated to 6.120.0 (6.12) see /usr/share/doc/packages/perl-HTTP-Cookies/Changes 6.12 2026-07-26 02:34:52Z - Honour Max-Age when extracting cookies; it had been silently ignored since 6.10, so Max-Age=0 no longer deleted a cookie and a Max-Age lifetime was never applied (GH#69) (reported by Robert Mueller) - When both Max-Age and Expires are present, let Max-Age take precedence regardless of order, and let a repeated attribute's last value win, per RFC 6265 5.3 (GH#69) ==== perl-HTTP-Message ==== Version update (7.20.0 -> 7.40.0) - updated to 7.40.0 (7.04) see /usr/share/doc/packages/perl-HTTP-Message/Changes 7.04 2026-07-24 00:01:56Z - add RFC 10008 HTTP QUERY method (GH#225) (Daniel Böhmer), see https://datatracker.ietf.org/doc/rfc10008/ 7.03 2026-07-21 20:45:16Z - Fix max_body_size for Content-Encoding: br, which made every brotli response fail to decode whenever a limit was set (GH#229) ==== perl-LWP-Protocol-https ==== Version update (6.150.0 -> 6.170.0) - updated to 6.170.0 (6.17) see /usr/share/doc/packages/perl-LWP-Protocol-https/Changes 6.17 2026-07-23 14:32:07Z - Move the live httpbin.org test from t/example.t to xt/author/example.t so that a transient outage of the external service (e.g. a 503) can no longer fail an end-user install. The test still runs in CI, and now skips (rather than fails) when httpbin.org itself is unhealthy, e.g. returns a 5xx. (GH#100) (Claude Opus 4.8) 6.16 2026-07-23 03:48:07Z - Remove undeclared Try::Tiny dependency from t/diag.t, which could cause the test suite to fail to install on minimal perls (GH#96) (Olaf Alders) ==== pipewire ==== Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-jack pipewire-lang pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Add pipewire-tests subpackage with installed tests for gnome-desktop-testing-runner ==== publicsuffix ==== Version update (20260725 -> 20260814) - Update to version 20260814: * migrate `vps.hrsn.au` to `vps.hrsn.net` (#3121) ==== python-gevent ==== Version update (26.5.0 -> 26.8.0) - update to 26.8.0: * Binary wheels for 3.15 are now built with 3.15rc1. This should be a stable ABI. * Replace concurrent.futures.thread._global_shutdown_lock when patching threads, importing that module if needed. Executor.submit holds it across Thread.start(), so a worker greenlet that forks runs the :func:`os.register_at_fork` handlers it is registered with while another greenlet holds it: a native lock deadlocked, a cooperative one parked the greenlet inside os.fork() (which filelock 3.30 rejects). Like the rest of patch_thread(existing_locks=True), this needs the process to be single threaded when patching. See :issue:`1865`. * Fixed a semaphore acquired and released by a hubless native thread failing to wake greenlets waiting on the semaphore's owning hub. See :issue:`2013`. * Stop the greenlets that communicate() spawned before gevent.subprocess.Popen.__exit__ closes the child's pipes. Leaving the with block while one of them was still parked in a pipe, because an exception was propagating or because the greenlet running the block was killed, raised RuntimeError: reentrant call out of __exit__. That replaced the exception that was really unwinding, and skipped the wait() that reaps the child. A pipe some other greenlet is reading is now left alone rather than raising, which is what communicate() already did. See :issue:`2194`. * Fix repr() of a destroyed hub raising :exc:`AttributeError`. Hub.destroy() deleted the _resolver and _threadpool attributes that Hub.__repr__ reads; it now sets them to None. This also fixes gevent.util.format_run_info(), which renders any destroyed hub that is still reachable. See :issue:`2185`. * Fix a hang at interpreter exit, on Python 3.13 and above, when a non-daemon thread is waiting on a threading._register_atexit hook. The patched threading._shutdown joined those threads before running the hooks, the reverse of the native order. This hung any program holding a live :class:`concurrent.futures.ThreadPoolExecutor`, whose non- daemon workers stop only when its _python_exit hook runs. See :issue:`2188`. * Make gevent.os.close not initialize a hub if one wasn't already present. In that case, it can just directly close the file descriptor. * In a future version (early 2027), gevent.monkey.patch_all will ONLY accept keyword arguments. Currently, you could be calling it with positional arguments, although that has never been the intent or documented way to call it. * Binary wheels for Python 3.15 are now built with 3.15b4. They may not be compatible with older or newer versions of Python. Likewise, binary wheels built by previous gevent releases may not be compatible with 3.15b4 or newer. ==== xdg-dbus-proxy ==== Version update (0.1.7 -> 0.1.8) - Update to version 0.1.8: + Fix broadcast messages bypassing path/interface/member checks + Improvements to the existing testing infrastructure + Add tests for owning names, issuing method calls, receiving messages - Add xdg-dbus-proxy-tests subpackage with installed tests for gnome-desktop-testing-runner