Packages changed: Imath (3.2.2 -> 3.2.3) MicroOS-release (20260828 -> 20260829) PackageKit cockpit (364 -> 365) cockpit-podman (128 -> 129) colord flatpak (1.18.1 -> 1.18.2) libjpeg-turbo libseccomp multipath-tools (0.15~1+230+suse.d36a6a70 -> 0.15.1+227+suse.6644513) procps qpdf (12.3.2 -> 12.4.1) wget === Details === ==== Imath ==== Version update (3.2.2 -> 3.2.3) - version update to 3.2.3 * Vec integer method resolution improved — Replaced  =delete with SFINAE ("Substitution Failure Is Not An Error"), via a new `is_float_like` trait, for `length()`, `normalize()`, `normalizedExc()`, etc on integer-typed Vec2/3/4. This gives clearer compiler diagnostics and allows custom numeric types (with an `is_float_like` specialization) to opt into these methods. `half` is explicitly supported. (#[575](https://github.com/AcademySoftwareFoundation/Imath/pull/575)) * Fixed duplicate installation of `ImathConfig.h` (#[591](https://github.com/AcademySoftwareFoundation/Imath/pull/591)) * Fixed shared library installation path (#[556](https://github.com/AcademySoftwareFoundation/Imath/pull/556)) * Fixed Python module install directory, now derived correctly from `Python3_SITEARCH` instead of a hardcoded/absolute path (#[528](https://github.com/AcademySoftwareFoundation/Imath/pull/528)) * Suppressed a C++23 deprecation warning for `std::float_denorm_style/denorm_present` usage in `numeric_limits` (#[546](https://github.com/AcademySoftwareFoundation/Imath/pull/546)) only) * Simplified CMake minimum-version policy handling by removing explicit CMP0074/CMP0077 settings now implied by the 3.14 minimum (#[526](https://github.com/AcademySoftwareFoundation/Imath/pull/526)) * Documentation fixes: corrected install instructions in README.md, fixed broken links, minor spelling corrections ==== MicroOS-release ==== Version update (20260828 -> 20260829) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== PackageKit ==== Subpackages: PackageKit-backend-dnf5 libpackagekit-glib2-18 typelib-1_0-PackageKitGlib-1_0 - Only make DNF backend available in openSUSE Leap 16+. Add 0%{?is_opensuse} check to make sure it's only available in Leap. ==== cockpit ==== Version update (364 -> 365) Subpackages: cockpit-bridge cockpit-networkmanager cockpit-packagekit cockpit-system cockpit-ws cockpit-ws-selinux - Update to 365 * Translations and dependency updates * Fix btrfs subvolume mount option parsing (rhbz#2483145) ==== cockpit-podman ==== Version update (128 -> 129) - Update to 129 * Bugfixes * Translations and dependency updates ==== colord ==== - Build the ICC print profiles with GLIBC_TUNABLES=glibc.cpu.hwcaps=-FMA,-FMA4 so that they no longer depend on the build host CPU (boo#1217747) ==== flatpak ==== Version update (1.18.1 -> 1.18.2) Subpackages: flatpak-selinux libflatpak0 system-user-flatpak - Update to version 1.18.2: + Bug fixes: - Validate GVariant structure of summaries before using generated variant readers - Fix crash in system helper when iterating cache directories - Avoid corrupted output from non-UTF-8 characters in error messages - Fix portal passing wrong file descriptor when sandbox-expose-fd-ro triggers fd remapping collision - Fix system helper tracking wrong D-Bus sender for pulls - Fix extensions not being populated in the sandbox due to unhandled EAGAIN from openat2 - Fix build failure with GLib versions older than 2.72 - Test infrastructure improvements ==== libjpeg-turbo ==== - update to 3.2.0: * Fixed a regression introduced by 3.2 beta1[9] that broke Arm64EC Windows builds. * Hardened the PNG writer (which is used by djpeg and tj3SaveImage*()) against applications that may erroneously attempt to write sample values that are out of range for the specified output data precision. * Hardened the libjpeg API against hypothetical applications that may erroneously call jpeg_crop_scanline() with buffered-image mode and raw data output enabled. * Fixed a buffer overrun and subsequent segfault in jpegtran that occurred when attempting to use the -crop and -trim options to expand the width of an image narrower than one iMCU, discard partial iMCUs, and fill each block in the expanded region with the DC coefficient of the nearest block in the input image ("flatten.") - deleted sources * libjpeg-turbo-3.1.4.1.tar.gz.sig (not needed) - added sources * libjpeg-turbo-3.2.0.tar.gz.sig ==== libseccomp ==== - `python` build should not install non-Python files. - replace deprecated 'setup.py install' with PEP 517 wheel install ==== multipath-tools ==== Version update (0.15~1+230+suse.d36a6a70 -> 0.15.1+227+suse.6644513) Subpackages: kpartx libmpath0 - Update to version 0.15.1+227+suse.6644513 (see NEWS.md for details) * The `preferredip=`parameter for the `iet` prioritizer has been generalized. See multipath.conf(5) for details. - Upstream fixes for vulnerabilities: * DoS on mulipathd socket by blocking IPC send operations (GHSA-hmcm-9cq4-r2xm bsc#1277199) * DoS on multipathd socket by exhausting connections (GHSA-pvp6-c9p3-25fp bsc#1277203) * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (GHSA-g5mh-253r-jjw5 bsc#1277205) * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (GHSA-pxwh-g75c-95pc 1277208) * kpartx: Heap Out-of-Bounds Read in GPT Header Validation (GHSA-p6rh-9x9j-3hvx, bsc#1277209) * Path traversal in device-mapper-multipath failed_wwids management (GHSA-gr7q-prfc-q636 bsc#1277210) * libmpathpersist PRIN READ FULL STATUS parser — unbounded descriptor rewrite causes root heap overflow (GHSA-hj7j-qr9h-5fv6 bsc#1277212) - Bug fixes: * Fix use-after free error during shutdown (gh#opensvc/multipath-tools#152) * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155) ==== procps ==== Subpackages: libproc2-1 - Add patch procps-ng-4.0.7-sysctl_ipv6.patch (boo#1276206) * Really ignore stable_secret below /proc/sys/net/ipv6/conf ==== qpdf ==== Version update (12.3.2 -> 12.4.1) - Update to version 12.4.1: - Update to 12.4.1: * Avoid generating JSON with leading zeroes when converting real numbers. * Detect and warn in check linearization when the cross-reference (xref) stream reports that the object containing a compressed object is itself a compressed object. * Improve uniformity and accuracy of progress reporting when writing linearized files and files with a large number of object streams. 10 - Update to 12.4.0: * Fix error message when --check encounters a PDF file with no pages. * Remove non-array/empty /Annots entries and non-dictionary annotations from copied pages in QPDFAcroFormDocumentHelper::fixCopiedAnnotations. * Fix failure in QPDFWriter when trailer /ID entries are invalid. * Limit the effect of QPDF::setMaxWarnings to the initial loading of the PDF file to prevent treating subsequent exceptions as recoverable. * Correctly handle page rotation values outside [0, 360] range in QPDFPageObjectHelper::getMatrixForTransformations. * Enforce conservative limits on the depth of direct objects created via QPDFObjectHandle::makeDirect to reduce stack overflow risk. * Enforce conservative limits on pages tree depth to prevent stack overflows. * Detect duplicate entries in the AcroForm field hierarchy earlier. * Rewrite zsh and bash shell completion functions to autogenerate from argument parsing metadata (job.yml) instead of invoking the executable. * Show linearization data even if linearization checks throw an exception. * Add REQUIRE_SHELLS CMake option to fail completion tests if new bash/zsh are missing (enabled by default in maintainer mode). * Deprecate external-libs on Windows in favor of vcpkg. ==== wget ==== - Fix server-controlled unbounded MD5 loop in FTP OPIE [bsc#1276962; CVE-2026-16599] * CVE-2026-16599.patch