Packages changed: AppStream (1.2.0 -> 1.2.1) MicroOS-release (20260930 -> 20261001) cups-filters2 fontconfig (2.18.1 -> 2.18.3) gcc16 (16.2.0+git9497 -> 16.2.1+git9713) pcre2 (10.48 -> 10.49) python313 python313-core systemd (261.2 -> 261.3) talloc (2.4.4 -> 2.5.0) tevent (0.17.1 -> 0.17.2) timezone (2026d -> 2026e) vulkan-loader (1.4.357 -> 1.4.363) vulkan-tools (1.4.357 -> 1.4.363) wireplumber (0.5.17 -> 0.5.18) === Details === ==== AppStream ==== Version update (1.2.0 -> 1.2.1) Subpackages: libAppStreamQt3 libappstream5 - Update to version 1.2.1: + Features: - Curl: Include "libcurl" in UA string so AI bot protection hits us less - Compose: Permit changing the downloader user agent - Compose: Try to guess what media we actually downloaded if processing failed - Add support for elogind + Bugfixes: - Meson: Make sed command cross-platform friendly - Meson: Don't use any absolute include path to find libstemmer.h - System-info: Avoid overflow in physical memory total on 32-bit systems - Compose: Flag a missing ffprobe as its own error - Docs: Work around a rare DAPS race condition when building documentation - Resolve or skip failing tests on riscv64 & s390x - Validator: Fix validation of `references` elements - Tests: Relax fontconfig orthography data check for 2.18.3 bug + Miscellaneous: Compose: Move media detection to the worker process ==== MicroOS-release ==== Version update (20260930 -> 20261001) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== cups-filters2 ==== - revert previous change and --enable-universal-cups-filter again because '--disable-universal-cups-filter' does not work because it results a /usr/share/cups/mime/cupsfilters.convs which only has a few text/plain rules for text-only printers (in particular nothing for PDF and image formats), see https://bugzilla.suse.com/show_bug.cgi?id=1283295 ==== fontconfig ==== Version update (2.18.1 -> 2.18.3) Subpackages: libfontconfig1 - add 583.patch to protect against a potential type confusion - Update to 2.18.3 * ci: Add --werror option to the build script * fc-cat: exit with non-zero if not successfully done * Workaround a longstanding use-after-free warning * Fix a null pointer dereference * Add Noto Sans as system-ui for fallback * Drop Noto Sans CJK KR from 60-nonlatin.conf * Correct sat.orth * Add an orth file for Balinese * Update orth files for jv, so, su, tl to use native scripts * Add orth files for scripts used by Noto font families * Update mni.orth to use Meetei Mayek script * Add orth files for Cuneiform languages (akk, sux, hit) * ci: Suppress abidiff false positives for all internal structs * test: Add cache format compatibility tests for orth file additions * Add orth files for ancient scripts (xna, hlu, ecy) * fc-cache: Create backward-compatible cache symlinks for cross-version discovery * ci: Update dependencies * Add implicit rule to update genericfamily property against syntactic-sugar * fc-genconf: Use alias syntactic-sugar instead of the pair of test-edit config * Allow to limit the targeted family for TTC * test: Fix test_genconf.py to avoid unexpected family name in testing conf * ci: Enable -Werror in CI * ci: drop duplicate pipelines * ci: cleanup * ci: gate distro jobs until all tests passed * ci: reduce more duplicate jobs * ci: Update base ci-templates * test: Fix compiler warnings * fc-fontations: Allow unnecessary_transmutes lint in bindgen-generated Rust code * Fix another compiler warnings * ci: Bump FreeBSD version to 14.4 * Fix the compiler warnings on MinGW * Update INSTALL * Fix "FileType is deprecated" * Fix unknown type name locale_t on macOS - Update to 2.18.2 * test: fix unexpected error when something went wrong in pytest * test: Fix a regression for sysroot in test framework * test: Fix a test case failure when BUILDDIR is under /tmp * test: cleanup * Add .gitignore * meson: Add tests-external-fonts option to disable network-dependent tests * Add .editorconfig * test: improve marker handling * test: Fix a fail on subproject build * test: Do not assume all-files-installed before testing * ci: set SOURCE_DATE_EPOCH to the build script * test: unset SOURCE_DATE_EPOCH for some test cases * Use genericfamily for the search of monospace against :spacing=100 * conf.d: Add OpenMoji Color and OpenMoji Black * test: Fix a KeyError * Add a hash table for fonts to generate expected genericfamily * Add Nerd Fonts to the table * doc: Fallback to wkhtmltopdf if no docbook2pdf available * fc-genericfamily: Add Noto fonts * fc-cache: do not generate cache when target directory is in deny list * conf.d/Makefile.am: install 05-macos.conf for macOS only * Add more conditional code for FcLocaleSetCurrent() * Do not ship unnecessary files in archive * fc-genericfamily: Add major missing fonts across multiple categories * Use Special FC_CACHE_VERSION for snapshot * new-version.sh: fix an error * Fix FcNameUnparse regression. * Fix FcNameUnparse regression. - modified patches * fontconfig-autoconf269.patch (refreshed) ==== gcc16 ==== Version update (16.2.0+git9497 -> 16.2.1+git9713) Subpackages: cpp16 libgcc_s1 libgomp1 libstdc++6 - Update to gcc-16 branch head, git9713 * pulls fix for use-after-free in __gnu_pbds::priority_queue. [bsc#1283123] (CVE-2026-102010) - Update to gcc-16 branch head, git9708 * pulls fix for ICE building firefox on arm [bsc#1268791, gcc#125953] * remove gcc16-pr124811.patch and gcc16-znver6-cpuid.patch included in the update ==== pcre2 ==== Version update (10.48 -> 10.49) Subpackages: libpcre2-16-0 libpcre2-8-0 - Update to 10.49: * GHSA-r9hj-j2rw-4q3m: out-of-bounds write in JIT matching with large stack allocations (boo#1283020) ==== python313 ==== - CVE-2026-15310: bound zipfile decompression for bzip2/LZMA/Zstandard (bsc#1277111, gh#python/cpython#156002) CVE-2026-15310-bound-zipfile-decompression.patch ==== python313-core ==== Subpackages: libpython3_13-1_0 python313-base - CVE-2026-15310: bound zipfile decompression for bzip2/LZMA/Zstandard (bsc#1277111, gh#python/cpython#156002) CVE-2026-15310-bound-zipfile-decompression.patch ==== systemd ==== Version update (261.2 -> 261.3) Subpackages: libsystemd0 libudev1 systemd-boot systemd-container udev - pam: use "pam_rootok" in the "auth" stack of our PAM config for systemd-run0 (bsc#1253133) and similarly update our PAM config for systemd-user to replace "pam_deny" with "pam_rootok". Previously SUSE PAM config used for systemd user instances already relied on "pam_deny" for the PAM "auth" management to avoid falling back on the noisy "other" pam service (see bsc#1190515). However "pam_deny" had the drawback to still log the failure at the debug level. SUSE PAM configs now consistently rely on "pam_rootok" to avoid any noisy debug logs, see upstream commit 34e5f14c3496097c4157a5ed8a13ed4c4b1c48a9. - Import commit 3255daee1572366b74fe92f002a3d60ecbb27103 (merge of v261.3) For a complete list of changes, visit: https://github.com/openSUSE/systemd/compare/4925d9f07fc697efccd98a93046ff535b8832445...3255daee1572366b74fe92f002a3d60ecbb27103 - Move systemd-pcrextend from experimental to udev (bsc#1274948) - Move systemd-measure from experimental to udev to fix ukify ==== talloc ==== Version update (2.4.4 -> 2.5.0) - Fix building of the `man` multibuild. - Extend talloc-python3.5-fix-soabi_name.patch to preserve underscores in PYTHON_LIBNAME_SO_ABI_FLAG as well as public library filenames. This keeps the pkg-config Libs entry consistent with the installed libpytalloc-util library and fixes Samba linking without a post-install name substitution. - Declare the python-rpm-macros build dependency explicitly and update the man-page build-cycle comment for the separate multibuild flavor. - Update to 2.5.0 * alloc: Add talloc_asprintf_addsep() * lib:talloc:testsuite remove unread global test_abort_stop * Replace memset_s() with memset_explicit() - Convert the package to _multibuild flavors: the man pages are now built from the "man" flavor of talloc.spec instead of a generated talloc-man.spec, so pre_checkin.sh, talloc-man.spec and talloc-man.changes are gone. No need to maintain duplicate files. - Merge the duplicated %if blocks in the spec file and give the man flavor its own summary and description. - Remove use of obsolete %py3* macros, use only the maintained ones from `python-rpm-macros` package. - Make rpmlint happy. ==== tevent ==== Version update (0.17.1 -> 0.17.2) - Update to 0.17.2 * let tevent_common_have_events() ignore fd events without active flags, in order to avoid tevent_loop_wait() to loop forever with only such events. * ignore fd events without flags in tevent_common_have_events() ==== timezone ==== Version update (2026d -> 2026e) - Update to 2026e: * Manitoba moves to permanent -05 on 2026-10-31 ==== vulkan-loader ==== Version update (1.4.357 -> 1.4.363) - Update to tag SDK-1.4.363.0 * Release VK_INSTANCE_LAYERS in enable_correct_layers_from_settings * Fix whole-wildcard and short prefix globs in determine_filter_type * Speed up vkGet{Instance,Device}ProcAddr lookups * loader: apply settings device configurations to device groups * loader: clamp driver-reported device extension count to caller buffer ==== vulkan-tools ==== Version update (1.4.357 -> 1.4.363) - Update to tag SDK-1.4.363.0 * vulkaninfo: Enable more instance extensions * Add VK_EXT_display_surface_counter instance extension * vulkaninfo: Include extended flags in video format props output ==== wireplumber ==== Version update (0.5.17 -> 0.5.18) Subpackages: libwireplumber-0_5-0 - Update to version 0.5.18: * Additions & Enhancements: - Improved find-best-profile to rank profiles on the availability of their output routes before their priority, so that UCM cards bundling HDMI outputs together with speakers or headphones no longer select a profile whose analog output is unplugged when a monitor is connected - Improved HDMI node descriptions: the monitor name is now taken from hdmi.product.name (set by PipeWire from the current ELD) so that it is correct for displays switched on after the card was set up, the alsa.name suffix is also shown for UCM devices, the ELD-detected channel layout is shown for UCM devices, and the channel suffix is added after monitor.alsa.rules are applied - Improved the ALSA node error recovery to allow at most 3 attempts per device (reset after 60s without errors), instead of looping forever on devices that keep failing after being re-opened * Fixes: - Fixed WpImplModule to load and destroy modules on the client context's thread, avoiding unsafe teardown of modules such as filter-chain with LV2 plugins - Fixed autoswitch-bluetooth-profile in several scenarios: it no longer gets overridden by EnumProfile triggered profile selection, a pending profile restore is cancelled when a headset profile is applied explicitly (fixing HFP capture dying shortly after starting), and filter chains such as EasyEffects are now correctly followed to the Bluetooth loopback source - Fixed a failed node creation or an error raised in a Lua async event hook step freezing the event dispatcher, and made the v4l2 monitor advance its transition when a device is disabled - Fixed software-dsp leaking hidden parent node ids, which caused nodes created later with a reused id to be hidden from every new client - Fixed the linking policy to to bypass find-media-role-target for smart filters and to defer immediate linking for any node with a link-group, avoiding linking cycles when smart filters have media.role set - Fixed prepare-link to destroy dont-reconnect streams when their target is removed, as it was done in 0.4, instead of leaving them unlinked forever - Fixed default-nodes to rank stored nodes by their position in the stack only, so that priority.session no longer overrides the user's most recent selection - Fixed the access scripts to activate permission managers when they load, so that their permissions are ready before any client connects, instead of letting the first short-lived client see hidden devices - Fixed disabling device.restore-profile at runtime, which was still saving profiles - Fixed a use-after-free in module-settings on malformed configuration, and also the active call count in module-modem-manager on reconnect