Packages changed: Mesa (26.2.1 -> 26.2.2) Mesa-drivers (26.2.1 -> 26.2.2) MicroOS-release (20260904 -> 20260907) NetworkManager cockpit curl (8.21.0 -> 8.22.0) google-noto-fonts (20260801 -> 20260901) kernel-source (7.2.2 -> 7.2.3) libfido2 python-idna (3.18 -> 3.19) === Details === ==== Mesa ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== Mesa-drivers ==== Version update (26.2.1 -> 26.2.2) Subpackages: Mesa-dri Mesa-vulkan-device-select libvulkan_lvp - Adjust crate download URLs to http://static.crates.io/crates: curl/wget receive a 403 when downloading from crates.io/api/ - Update to 26.2.2 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.2 ==== MicroOS-release ==== Version update (20260904 -> 20260907) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== NetworkManager ==== Subpackages: NetworkManager-bluetooth NetworkManager-tui NetworkManager-wwan libnm0 typelib-1_0-NM-1_0 - Add NetworkManager-CVE-2026-10805.patch: dhclient: reject unsafe characters in URLs and hostnames (bsc#1267696, CVE-2026-10805, glfd#NetworkManager/NetworkManager!2426). - Add NetworkManager-CVE-2026-19685.patch: core: 802.1x: reject ca-path for private connections (bsc#1276764, CVE-2026-19685, glfd#NetworkManager/NetworkManager!2513). ==== cockpit ==== Subpackages: cockpit-bridge cockpit-networkmanager cockpit-packagekit cockpit-system cockpit-ws cockpit-ws-selinux - Symlink opensuse's branding to opensuse-leap as they should share the same (bsc#1268639) ==== curl ==== Version update (8.21.0 -> 8.22.0) Subpackages: libcurl4 - Update to 8.22.0: * Security fixes: - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476) - CVE-2026-18924: HTTP/2 server push UAF (bsc#1277477) - CVE-2026-19931: Negotiate ambient user conn reuse (bsc#1277478) - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479) - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480) - CVE-2026-80255: secure cookie attribute bypass with tab (bsc#1277482) - CVE-2026-82209: curl: domain-scoped PSL domain cookie (bsc#1278173) * Changes: - gssapi: add support for Apple GSS Framework - hardening: add API guards - RFC 9421 HTTP Message Signatures support - spnego: block NTLM fallback in SPNEGO negotiation - TLS: drop support for TLS-SRP - vquic: add option to use Apple fast UDP * Bugfixes: - altsvc: continue after unknown parameters - asyn-thrdd: retry link-local ipv6 if missing scope id - autotools: minor fixes and improvements - cd2nroff: fix backslashes for 4-space indent lines - cd2nroff: stricter checks for asterisks for italics - cfilters: fix event-based connection shutdown - conncache: apply multi limits to transfers using a shared pool - connect: only set connect timer on first socket - connection reuse: check SSL configs when doing a scheme upgrade - cookie: cookies set for an exact PSL domain is host-only - cookie: improve TAB handling - cookie: refuse to load cookies set against a PSL domain - FTP: fix TLS session reuse on the data connection - hostip: only cache negative resolves for authoritative answers - http digest: tie peer/credentials on input - http2: make server push transfers inherit share from parent - ldap: reject control characters in URL-decoded filter values - ldap: support empty username and password - md5: replace magic numbers with `MD5_DIGEST_LEN` - mime.c: avoid integer overflow in base64 size calculation - mprintf: acknowledge %F - ngtcp2+openssL: fix early data - ngtcp2: avoid NULL deref in cf_ngtcp2_send - openssl+sectrust: fix session reuse - openssl+sectrust: move session verified set into result check - openssl: avoid conn reuse if provider is used - openssl: avoid strlen() on the data from OpenSSL - openssl: prefer modern API flavors for `EVP_MD_CTX` new/free - openssl: replace stray legacy API variant with `EVP_DigestInit_ex()` - url: fix handling of empty user in NTLM matching - url: fix negotiate/ntlm connection reuse - urlapi: allow URLs to not have userauth (hostname) - urlapi: clear password buffer on error path - vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config * Rebase libcurl-ocloexec.patch ==== google-noto-fonts ==== Version update (20260801 -> 20260901) Subpackages: google-noto-sans-fonts google-noto-sans-symbols-fonts google-noto-sans-symbols2-fonts - Update to 20260901: * Serif Toto: - Improve the Kerning of BREATHY EO - Reverts the change to the dot under TOTO LETTER WA * Sans Miao: Add 9 Miao glyph variants for the Lipo language ==== kernel-source ==== Version update (7.2.2 -> 7.2.3) - Update patches.kernel.org/7.2.1-083-ptp-vmclock-prevent-read-only-mappings-from-bec.patch (bsc#1012628 CVE-2026-80724 bsc#1277850). - Update patches.kernel.org/7.2.2-001-inet-frags-strip-GSO-state-from-fragments-befor.patch (bsc#1012628 CVE-2026-80590 bsc#1277275). suse-add-cves - commit 263d925 - Update config files. - commit a590eb7 - Update config files. - commit f305596 - Linux 7.2.3 (bsc#1012628). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (bsc#1012628). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (bsc#1012628). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (bsc#1012628). - USB: serial: spcp8x5: drop broken carrier detect support (bsc#1012628). - USB: serial: option: fix slab OOB read in interrupt URB callback (bsc#1012628). - ALSA: usb-audio: Complete cleanup after system-resume errors (bsc#1012628). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (bsc#1012628). - ALSA: usb-audio: Fix sample rates for PreSonus AudioBox USB (bsc#1012628). - usb: core: Strengthen error handling in hub_hub_status() (bsc#1012628). - usb: core: Add lock to usb_wakeup_notification() (bsc#1012628). - KVM: s390: vsie: zero stale crypto bits (bsc#1012628). - crypto: qce - Remove unsafe/deprecated algorithms (bsc#1012628). - crypto: mxs-dcp - fix source scatterlist length access (bsc#1012628). - crypto: iaa - fall back to software for multi-entry scatterlists (bsc#1012628). - crypto: qce - fix CCM AAD buffer underallocation (bsc#1012628). - crypto: krb5 - use kfree_sensitive() for derived key buffers (bsc#1012628). - crypto: atmel-tdes - use scatterlist length before DMA mapping (bsc#1012628). - crypto: sun8i-ss - Remove crypto_rng interface (bsc#1012628). - crypto: sun8i-ce - Remove crypto_rng interface (bsc#1012628). - crypto: qcom-rng - Allow zero as a random number (bsc#1012628). - crypto: qcom-rng - Remove crypto_rng interface (bsc#1012628). - crypto: qcom-rng - Enable clock in hwrng case (bsc#1012628). - crypto: virtio - bound the akcipher result length (bsc#1012628). - kunit: irq: Continue increasing hrtimer interval for longer (bsc#1012628). - mm/swap: reject swapon() on filesystem-level encrypted files (bsc#1012628). - netfilter: nf_tables: don't queue packet path object notifications (bsc#1012628). - netfilter: nft_set_pipapo_avx2: add missing vzeroupper (bsc#1012628). - vxlan: keep the last remote linked during FDB flush (bsc#1012628). - batman-adv: reject unrepresentable multicast TVLV offsets (bsc#1012628). - ipv6: seg6: clear IPv4 control block on IPIP decapsulation (bsc#1012628). - net/packet: defer vmalloc TX_RING free until skbs finish (bsc#1012628). - vlan: fix skb_under_panic and races when toggling HW VLAN offload (bsc#1012628). - net: bridge: mcast: fix use-after-free of a master VLAN's multicast context (bsc#1012628). - xfrm: bound nat keepalive state collection (bsc#1012628). - xfrm: fix xfrm_state_construct() auth-trunc leak (bsc#1012628). - xfrm: ah6: validate routing header segments_left (bsc#1012628). - xfrm: avoid lock inversion in nat keepalive work (bsc#1012628). - xfrm: drop ESP-in-TCP packets with no ingress device (bsc#1012628). - tcp: clamp route advmss to TCP_MIN_MSS (bsc#1012628). - xfrm: espintcp: fix UAF during close (bsc#1012628). - net: advertise TCP MSS from the configured MTU, not the learned PMTU (bsc#1012628). - net/tcp-ao: fix use-after-free of current_key on reconnect to another peer (bsc#1012628). - tcp: fix AO info use-after-free in tcp_ao_connect_init() (bsc#1012628). - net/tcp: fix TCP-AO key deletion in VRFs (bsc#1012628). - gtp: serialize PDP context updates (bsc#1012628). - tls: device: fix out-of-bounds write in tls_append_frag() (bsc#1012628). - KVM: SEV: Wire up kvm_x86_ops.gmem_xxx() if and only if CONFIG_KVM_AMD_SEV=y (bsc#1012628). - KVM: SEV: Mark vCPU RUNNABLE after AP_CREATE, even if VMSA is unusable (bsc#1012628). - KVM: SEV: Extract loading of guest-provided VMSA to a separate helper (bsc#1012628). - KVM: SEV: Track the GPA of the guest-controlled VMSA used for SNP guests (bsc#1012628). - KVM: SEV: Drop FOLL_WRITE for encrypted region registration (bsc#1012628). - KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts (bsc#1012628). ... changelog too long, skipping 49 lines ... - commit dcfc956 ==== libfido2 ==== - Drop USE_HIDAPI, as it produces a race condition (bsc#1234010) ==== python-idna ==== Version update (3.18 -> 3.19) - update to 3.19: * Restore the `std3_rules` option, which had no effect since changes to UTS #46 processing in Unicode 16. Note that `uts46_remap()` defaults to enabling STD3 rules, so direct callers will see input containing non-LDH ASCII characters rejected again. * Performance improvements to UTS #46 mapping, particularly for ASCII-only domains. * Test on free-threaded CPython with the GIL disabled and document thread safety. * Expose the Unicode version of the generated tables as `idna.unicode_version`, and show it in `idna --version`. * Add `code`, `text`, `codepoint` and `position` attributes to `IDNAError` so that the failed rule and the offending character can be identified without parsing the exception message. * The deprecated `transitional` argument to `encode()` and `uts46_remap()` is now completely ignored, and gives a deprecation warning for the latter. * Reject A-labels that are not the canonical Punycode encoding of their U-label. * Fix CONTEXTJ violations raising `IDNAError` instead of `InvalidCodepointContext`. * Consistently raise `IDNAError` for empty labels and non-ASCII bytes passed to label helper functions and the incremental codec. * Add property-based tests, extended fuzzing targets, coverage * measurement, and CI checks that the data tables match the generator output. * Various code quality and tooling improvements.