Packages changed: Mesa (26.2.2 -> 26.2.3) Mesa-drivers (26.2.2 -> 26.2.3) MozillaFirefox (155.0.1 -> 156.0) libX11 libXrender libtpms mozilla-nss (3.127 -> 3.128) openSUSE-release (20260919 -> 20260921) qt6-webengine xxhash (0.8.3 -> 0.8.4) === Details === ==== Mesa ==== Version update (26.2.2 -> 26.2.3) Subpackages: Mesa-libEGL1 Mesa-libGL1 libgbm1 - Update to 26.2.3 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.3 ==== Mesa-drivers ==== Version update (26.2.2 -> 26.2.3) Subpackages: Mesa-dri Mesa-libva Mesa-vulkan-device-select libvulkan_lvp - Update to 26.2.3 bugfix release - -> https://docs.mesa3d.org/relnotes/26.2.3 ==== MozillaFirefox ==== Version update (155.0.1 -> 156.0) Subpackages: MozillaFirefox-branding-upstream MozillaFirefox-translations-common - Mozilla Firefox 156.0 https://www.firefox.com/en-US/firefox/156.0/releasenotes/ MFSA 2026-90 (bsc#1280371) * CVE-2026-92033 (bmo#2047339) Privilege escalation in Firefox for Android * CVE-2026-92005 (bmo#2056051) Use-after-free in the Audio/Video: Web Codecs component * CVE-2026-92006 (bmo#2057121) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92007 (bmo#2058064) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92008 (bmo#2058065) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92009 (bmo#2058066) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92010 (bmo#2058067) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92011 (bmo#2058068) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92012 (bmo#2058069) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92013 (bmo#2058078) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-92015 (bmo#2060235) Privilege escalation in the WebExtensions component * CVE-2026-92034 (bmo#2060295) Site isolation issue in the Graphics component * CVE-2026-92035 (bmo#2061245) Sandbox escape due to incorrect boundary conditions in the Graphics component * CVE-2026-92016 (bmo#2061327) Use-after-free in the Disability Access APIs component * CVE-2026-92017 (bmo#2061777) Privilege escalation in the DOM: Service Workers component * CVE-2026-92018 (bmo#2064287) Sandbox escape in the DOM: Core & HTML component * CVE-2026-92019 (bmo#2065636) Mitigation bypass in the Remote Settings Client component * CVE-2026-92020 (bmo#2066329) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component * CVE-2026-92022 (bmo#2068059) Use-after-free in the DOM: HTML Parser component * CVE-2026-92023 (bmo#2068342) Use-after-free in the XML component * CVE-2026-92024 (bmo#2068354) Use-after-free in the SVG component * CVE-2026-92025 (bmo#2068361) Use-after-free in the DOM: Navigation component * CVE-2026-92026 (bmo#2068378) Use-after-free in the Networking component * CVE-2026-92036 (bmo#2068416) Incorrect boundary conditions in the Networking: HTTP component * CVE-2026-92027 (bmo#2068433) Use-after-free in the DOM: Streams component * CVE-2026-92028 (bmo#2068440) Use-after-free in the DOM: Core & HTML component * CVE-2026-92029 (bmo#2068445) Use-after-free in the SVG component * CVE-2026-92037 (bmo#2068460) Incorrect boundary conditions in the DOM: Animation component * CVE-2026-92038 (bmo#2068952) Mitigation bypass in the Remote Settings Client component * CVE-2026-92039 (bmo#2001265) Mitigation bypass in the DOM: Notifications component * CVE-2026-92040 (bmo#2024248) Use-after-free in the JavaScript: WebAssembly component * CVE-2026-92041 (bmo#2029482) Mitigation bypass in the DOM: Networking component * CVE-2026-92042 (bmo#2049342) Race condition in the DOM: Content Processes component * CVE-2026-92043 (bmo#2050150) Privilege escalation due to incorrect boundary conditions in the Audio/Video component * CVE-2026-92044 (bmo#2051466) Information disclosure in the Networking: HTTP component * CVE-2026-92045 (bmo#2054622) Sandbox escape due to incorrect boundary conditions in the WebRTC component * CVE-2026-92030 (bmo#2058417) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-92046 (bmo#2058618) Use-after-free in the Graphics component * CVE-2026-92047 (bmo#2059021) Privilege escalation in the Crash Reporting component * CVE-2026-92048 (bmo#2061235) Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component * CVE-2026-92049 (bmo#2061295) Use-after-free in the Widget: Win32 component ... changelog too long, skipping 70 lines ... - requires NSS 3.128 ==== libX11 ==== Subpackages: libX11-6 libX11-data libX11-xcb1 - u_xkb-Check-the-keysym-range-in-_XkbReadKeyActions-CVE.patch * libX11 XkbGetMap Reply Heap-based Buffer Overflow (CVE-2026-88806, ZDI-CAN-32061, bsc#1280910) ==== libXrender ==== - u_Check-numSubpixel-against-numScreens-to-avoid-OOB-wr.patch * A malicious server could reply to XRenderQueryFormat with a numSubpixels count greater than the number of screens, causing an OOB write into screen->subpixel which was allocated using numScreens (CVE-2026-88807, ZDI-CAN-32093, bsc#1280911) ==== libtpms ==== - CVE-2026-85769: Fixed heap out-of-bounds read in TPM2 state unmarshalling via unchecked block_skip_read() blocksize (bsc#1279628) - libtpms-CVE-2026-85769.patch ==== mozilla-nss ==== Version update (3.127 -> 3.128) Subpackages: libfreebl3 libsoftokn3 mozilla-nss-certs mozilla-nss-tools - update to NSS 3.128 * bmo#2063360 - Rejoin the table cells the conversion wrapped mid-construct * bmo#2063360 - Generate heading anchors and stop the headings linking to themselves * bmo#2063360 - Unlink the self-linking headings in the release notes * bmo#2063360 - Point documentation cross-references at the dashed anchors * bmo#2063360 - Fix doc-lint in the release process * bmo#2066375 - Make fuzz tasks selectable with try syntax * bmo#2066375 - Build Cryptofuzz in its own CI task * bmo#2066604 - fix EC public key encoding in sftk_PutPubKey * bmo#2066183 - set CKA_ID on imported private keys * bmo#2017925 - Hash prfs need to be evaluated for indicators * bmo#2066327 - rename libcrux gyp target * bmo#2066415 - Update BoGo tests to disable ML_DSA Default test * bmo#2065354 - unify the two clang-format docker images * bmo#2056265 - -trust-cert for TLS BoGo tests * bmo#2056235 - DTLS1.2/1.3 - silently discard invalid records * bmo#2052273 - Adding -trust-cert support for BoGo DTLS tests * bmo#2063443 - nullify dangling pointers in libssl, pk11wrap, and softoken * bmo#2027768 - Fix build failure due to missing gcm stubs if on big endian * bmo#2065354 - clang-format everything * bmo#2065354 - Update clang-format version to 22 * bmo#2054818 - make mach try work with git-cinnabar checkouts * bmo#2054696 - avoid integer overflow in PK11SDR_EncryptWithMechanism * bmo#2056778 - fix slot over-release in PK11_FindCertFromDERCertItem * bmo#2056789 - fix missing BAD_PARAM_CAST in NSC_DeriveKey CKM_DES3_CBC_ENCRYPT_DATA branch * bmo#2064946 - additional ML-DSA ssl gtests * bmo#2064644 - ml_dsat.h: portable comments should use block comment style * bmo#1983320 - ml-dsa tls tests * bmo#2056787 - hold handshake locks longer in SSL_ResetHandshake * bmo#1983320 - ML-DSA tests for Sign/Verify, certificates and pkcs12 * bmo#2056786 - take smime profile lock while updating profile data * bmo#2062824 - add defensive null checks in PK11_Encapsulate and PK11_Decapsulate * bmo#2062822 - nulled slot in pk11_loadPrivKeyWithFlags leads to token object leak * bmo#2062802 - handle ML-KEM in stfk_CopyTokenPrivateKey and stfk_CopyTokenPublicKey * bmo#2062450 - Allow unknown hashAlg with ML-DSA in VFY_VerifyDataDirect * bmo#2062379 - additional ML-KEM tests * bmo#2062375 - handle unknown ML-KEM parameter sets in PK11_ExtractPublicKey * bmo#2062373 - missing CKP_NSS_ML_KEM_768 branches in seckey helper functions * bmo#2062372 - remove unused sftk_kyber_AllocCiphertextItem function * bmo#2060302 - additional ML-DSA tests * bmo#2060358 - add wycheproof tests for ML-KEM and ML-DSA * bmo#2060302 - vendor libcrux ML-DSA and enable the ML-DSA freebl backend * bmo#2060301 - bump libcrux and re-vendor ML-KEM from the combined C extraction * bmo#2027352 - validate IV length for CKM_RC2_CBC in pk11_ParamFromIVWithLen * bmo#1983320 - ml-dsa tls patch * bmo#2056775 - protect nssPKIObject.cryptoContext with a lock - rebase add-relro-linker-option.patch ==== openSUSE-release ==== Version update (20260919 -> 20260921) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== qt6-webengine ==== Subpackages: libQt6WebEngineCore6 libQt6WebEngineQuick6 libQt6WebEngineWidgets6 qt6-webengine-imports - Add upstream patch to fix renderer crash on sites that use encodings other than utf-8 (QTBUG-149435, QTBUG-149946): * Fix-renderer-crash-when-registering-ICU-encoding-names.patch - Add upstream patch to fix huge memory usage due to an ineffective garbage collector (QTBUG-150026): * enable-memory-barriers.patch ==== xxhash ==== Version update (0.8.3 -> 0.8.4) - Update to release 0.8.4 * This release adds vectorized implementations for the RISC-V Vector extension and LoongArch LASX. * Prefer NEON over SVE on AArch64, improving XXH3 speed by 25–40%. * `xxhsum` can now receive a full 64-bit seed through option `-s`. * When processing a list of files, read errors no longer prevent subsequent files from being processed.