------------------------------------------------------------------ --- Changelog.all ----------- Thu Jul 9 16:03:27 UTC 2026 ------ ------------------------------------------------------------------ ------------------------------------------------------------------ ------------------ 2026-7-7 - Jul 7 2026 ------------------- ------------------------------------------------------------------ ++++ chromium: - Chromium 150.0.7871.100: * stability improvements, no further information available ------------------------------------------------------------------ ------------------ 2026-7-6 - Jul 6 2026 ------------------- ------------------------------------------------------------------ ++++ haproxy: - Update to version 3.2.21+git0.dbe43be37: * [RELEASE] Released version 3.2.21 * BUG/MINOR: http-htx: Don't by-pass HTX API when merging cookie values * BUG/MAJOR: htx: Don't swap buffers for empty HTX message with an error * BUG/MINOR: tools: fix invalid character detection in strl2ic() * BUG/MEDIUM: servers: Use a refcount for port_range and free it properly * BUG/MINOR: sample: set SMP_F_CONST on srv_name fetch * BUG/MEDIUM: mux_quic: fix memory leak of rx app_buf on stream free ++++ rust-keylime: - Remove Cargo_toml.patch (merged upstream) - Update openssl to 0.10.81 bsc#1270174, CVE-2026-41676 bsc#1270999, CVE-2026-45784 bsc#1270903, CVE-2026-44662 bsc#1270842, CVE-2026-41898 bsc#1270792, CVE-2026-41681 bsc#1270699, CVE-2026-41678 bsc#1270614, CVE-2026-41677 bsc#1270523, CVE-2026-42327 - Update to version 0.2.9+49: * build(deps): bump uuid from 1.23.3 to 1.23.4 * build(deps): bump syn from 2.0.117 to 2.0.118 * build(deps): bump openssl from 0.10.80 to 0.10.81 * build(deps): bump rand from 0.9.4 to 0.10.1 * Added new regression test into packit-ci.yaml * build(deps): bump actions/checkout from 6 to 7 * build(deps): bump uuid from 1.23.1 to 1.23.3 * build(deps): bump log from 0.4.29 to 0.4.32 * build(deps): bump http from 1.4.0 to 1.4.2 * build(deps): bump codecov/codecov-action from 6 to 7 * build(deps): bump retry-policies from 0.5.1 to 0.5.2 * fix: Remove unused base64::Engine import in context_info tests * build(deps): bump reqwest-middleware from 0.5.1 to 0.5.2 * build(deps): bump serde_json from 1.0.149 to 1.0.150 * build(deps): bump openssl from 0.10.79 to 0.10.80 * agent: Hash agent ID before TPM2_Certify qualifying data * cargo: Bump tss-esapi, picky-asn1-x509, and picky-asn1-der * build(deps): bump openssl from 0.10.78 to 0.10.79 * build(deps): bump once_cell from 1.21.3 to 1.21.4 * build(deps): bump tempfile from 3.23.0 to 3.27.0 * push-model: cache UEFI event log bytes at startup * build(deps): bump quote from 1.0.40 to 1.0.45 * build(deps): bump chrono from 0.4.42 to 0.4.44 * build(deps): bump openssl from 0.10.73 to 0.10.78 * build(deps): bump serde_json from 1.0.143 to 1.0.149 * build(deps): bump syn from 2.0.106 to 2.0.117 * build(deps): bump libc from 0.2.175 to 0.2.184 * build(deps): bump rand from 0.9.2 to 0.9.4 ++++ kf6-kwallet: - Add patches to improve reliability: * 0001-Always-reload-collections-prior-to-secret_service_ge.patch (kde#512135) * 0001-ksecretd-fix-intermittent-Secret-Service-session-key.patch (kde#514194) ++++ product-composer: - update to version 0.9.10 * Implement mechanic to specify supportstatus override file name (default sticks to supportstatus.txt) This can also be used to disable the override. * python license field adjusment ------------------------------------------------------------------ ------------------ 2026-7-3 - Jul 3 2026 ------------------- ------------------------------------------------------------------ ++++ aws-cli-cmd: - Add /etc/ssl as path to share with the container This Fixes bsc#1269510 - Fix typo in spec The %ghost reference contained a superfluous quote sign at the end of the line ++++ az-cli-cmd: - Add /etc/ssl as path to share with the container This Fixes bsc#1269510 - Fix typo in spec The %ghost reference contained a superfluous quote sign at the end of the line ++++ dracut: - Update to version 059+suse.724.gaa87d1594: * fix(fips): handle zipl (bsc#1262515) ++++ openQA: - Update to version 5.1783076943.6691832d: * test: Stabilize `t/05-scheduler-full.t` ++++ os-autoinst: - Update to version 5.1783082953.c3cb41d: * test: Disable unstable `t/28-signalblocker.t` on ppc64le OBS builds * fix: Check also hidden files in checklist plugin * feat(ci): disable Mergify interactive queue controls in PR comments * test: assert pipe size adjustment dynamically * test: assert terminal session boundary safety * refactor: support pretty markers in script_sudo and become_root * fix: mmapi test failures and infinite loop hangs * test: simplify Level 3 pretty marker detection * fix: exclude virt-firmware on all older Leap archs ++++ python-joserfc: - CVE-2026-49852: HS256/HS384/HS512 verify accepts empty/nil HMAC key (bsc#1270234) * added CVE-2026-49852.patch ++++ trivy: - Update to version 0.72.0: * release: v0.72.0 [main] (#10782) * test: close plugin manager in tests cleanup (#10904) * Merge commit from fork * feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893) * fix(misconf): support github_repository_vulnerability_alerts resource (#10680) * feat(java): detect JAR licenses from packaged LICENSE files (#10856) * fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861) * fix(server): propagate package repository class in client/server mode (#10874) * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888) * fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795) * feat(java): detect JAR licenses from the embedded pom.xml (#10851) * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863) * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873) * chore(deps): bump alpine to 3.24.1 (#10868) * docs: fix article typo in plugin developer guide (#10860) * feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848) * docs: fix typos (#10857) * fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843) * feat(secret): support new stateless format for GitHub App installation tokens (#10826) * fix: correct format verbs in diagnostic messages (#10805) * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845) * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830) * docs: fix repository scan heading typo (#10828) * Merge commit from fork * fix: forward ospkg detector options through ospkg.NewScanner (#10811) * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801) * fix(vex): load VEX documents from within the repository directory (#10820) * ci!: migrate docker config to dockers_v2 (#10783) * feat(dotnet): detect bundled runtime in self-contained deployments (#10786) * feat(secret): add OpenAI secret detection rules (#10798) * ci: expect GitHub App bot as backport PR author (#10813) * fix: surface the original analysis error instead of context cancellation (#10793) * chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803) * chore(deps): bump the common group with 4 updates (#10797) * chore(deps): bump the aws group with 4 updates (#10796) * fix: use random suffix for process temp directory instead of PID (#10431) * docs: update signature verification for deb and rpm packages (#10784) * fix(image): lookup origin layer for custom resources in merged layers (#10788) * test: fix flaky containerd integration test (#10760) * ci: bump GoReleaser to v2.16.0 (#10774) * docs: fix broken nixpkgs reference link in installation guide (#10776) * test(java): force offline-scan for client/server integration tests (#10721) * fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777) * fix(spdx): guard against nil root component in SPDX marshaler (#10771) * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768) ------------------------------------------------------------------ ------------------ 2026-7-2 - Jul 2 2026 ------------------- ------------------------------------------------------------------ ++++ blog: - Update to version 2.45 Fix early boot LUKS prompt on s390x and resolve memory corruptions This update addresses several critical issues in the early boot phase, especially on s390x architectures, and hardens the daemon's architecture: - Initrd/Dracut: Properly include `systemd-ask-password-blog.path` in sysinit.target.wants during the initrd phase to ensure LUKS password prompts are captured early in the zipl phase. - Systemd Units: Drop restrictive `ConditionKernelCommandLine=!plymouth.enable=0` to prevent the agent from being disabled by standard mainframe boot parameters. - Memory Corruption: Fix a critical heap corruption by renaming the conflicting `alignof()` macro to `ALIGNED_SIZEOF()` and zeroing allocated memory for `struct request` (memset) to prevent reading uninitialized pointers #5. - Kernel Command Line: Improve `parse_cmdline()` to support boolean parameters without an explicit value (e.g., `blog.silent` defaults to `blog.silent=1`). - New Features: Introduce `blog.silent` to suppress console I/O and `blog.coldboot` to explicitly trigger the early coldstart password query. - Lifecycle: Switch `KillMode=none` to `KillMode=mixed` to comply with modern systemd process lifecycle management. Fixes: gh#bitstreamout/showconsole#5 Fixes: gh#bitstreamout/showconsole#6 Fixes: bsc#1264176 ++++ chromium: - promote Chromium 150 (150.0.7871.46) to stable (boo#1270051) * CVE-2026-13774: Use after free in Extensions * CVE-2026-13775: Use after free in GPU * CVE-2026-14398: Use after free in ANGLE * CVE-2026-13776: Type Confusion in Dawn * CVE-2026-13777: Insufficient validation of untrusted input in iOSWeb * CVE-2026-13778: Use after free in WebUSB * CVE-2026-13779: Use after free in Chromoting * CVE-2026-13780: Insufficient validation of untrusted input in ANGLE * CVE-2026-13781: Insufficient validation of untrusted input in Skia * CVE-2026-14417: Use after free in Dawn * CVE-2026-13782: Use after free in Browser * CVE-2026-13783: Use after free in Views * CVE-2026-13784: Use after free in Views * CVE-2026-14419: Use after free in Skia * CVE-2026-13785: Use after free in Bluetooth * CVE-2026-14420: Out of bounds read and write in Dawn * CVE-2026-13786: Use after free in Ozone * CVE-2026-14427: Heap buffer overflow in Skia * CVE-2026-13787: Use after free in Chromoting * CVE-2026-13788: Use after free in Fullscreen * CVE-2026-14382: Insufficient validation of untrusted input in ANGLE * CVE-2026-13790: Side-channel information leakage in Scroll * CVE-2026-14385: Heap buffer overflow in ANGLE * CVE-2026-13791: Insufficient validation of untrusted input in Downloads * CVE-2026-13792: Use after free in Touchbar * CVE-2026-13793: Insufficient policy enforcement in SVG * CVE-2026-14392: Out of bounds write in Tint * CVE-2026-13794: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14422: Out of bounds read and write in Tint * CVE-2026-13795: Insufficient policy enforcement in Chrome for iOS * CVE-2026-14426: Use after free in V8 * CVE-2026-13796: Integer overflow in Chromecast * CVE-2026-13797: Insufficient validation of untrusted input in Chromecast * CVE-2026-14386: Out of bounds read in ANGLE * CVE-2026-13798: Heap buffer overflow in Chromecast * CVE-2026-13799: Use after free in QUIC * CVE-2026-13800: Inappropriate implementation in Updater * CVE-2026-13801: Integer overflow in Chromecast * CVE-2026-13802: Use after free in Views * CVE-2026-13803: Type Confusion in Chrome Tabs * CVE-2026-13804: Use after free in Chromecast * CVE-2026-13805: Use after free in GFX * CVE-2026-14390: Use after free in ANGLE * CVE-2026-13806: Insufficient validation of untrusted input in Accessibility * CVE-2026-13807: Use after free in Import * CVE-2026-13808: Insufficient data validation in Chrome for iOS * CVE-2026-13809: Side-channel information leakage in Safe Browsing * CVE-2026-13810: Inappropriate implementation in Input * CVE-2026-13811: Use after free in IME * CVE-2026-13812: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13813: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13814: Use after free in Views * CVE-2026-13815: Use after free in Blink * CVE-2026-13816: Insufficient validation of untrusted input in File Input * CVE-2026-14396: Out of bounds read in ANGLE * CVE-2026-13817: Insufficient validation of untrusted input in Glic * CVE-2026-13818: Inappropriate implementation in Passwords * CVE-2026-13819: Out of bounds read in ANGLE * CVE-2026-13820: Out of bounds read in Skia * CVE-2026-14400: Out of bounds write in ANGLE * CVE-2026-14401: Insufficient validation of untrusted input in ANGLE * CVE-2026-14402: Uninitialized Use in ANGLE * CVE-2026-13821: Use after free in Canvas * CVE-2026-13822: Inappropriate implementation in Extensions * CVE-2026-13823: Use after free in Glic * CVE-2026-13824: Insufficient validation of untrusted input in Extensions * CVE-2026-13825: Uninitialized Use in Dawn * CVE-2026-13826: Inappropriate implementation in Autofill * CVE-2026-13827: Use after free in Updater * CVE-2026-13828: Inappropriate implementation in Enterprise * CVE-2026-13829: Insufficient validation of untrusted input in Settings * CVE-2026-13830: Use after free in Chromoting * CVE-2026-13831: Use after free in GPU * CVE-2026-13832: Use after free in Headless * CVE-2026-14411: Insufficient validation of untrusted input in ANGLE * CVE-2026-13833: Uninitialized Use in ANGLE * CVE-2026-14412: Insufficient validation of untrusted input in ANGLE * CVE-2026-14413: Uninitialized Use in ANGLE * CVE-2026-13834: Insufficient validation of untrusted input in ANGLE * CVE-2026-13835: Inappropriate implementation in XML * CVE-2026-13836: Inappropriate implementation in CSS * CVE-2026-13837: Inappropriate implementation in CSS * CVE-2026-13838: Inappropriate implementation in CSS * CVE-2026-13839: Inappropriate implementation in CSS * CVE-2026-13840: Insufficient policy enforcement in Canvas * CVE-2026-13841: Integer overflow in Skia * CVE-2026-13842: Incorrect security UI in Chrome for iOS * CVE-2026-14418: Uninitialized Use in ANGLE * CVE-2026-13843: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13844: Use after free in Updater * CVE-2026-13845: Use after free in DOM * CVE-2026-13846: Use after free in USB * CVE-2026-13847: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13848: Use after free in Forms * CVE-2026-13849: Insufficient validation of untrusted input in Chromoting * CVE-2026-14423: Type Confusion in Tint * CVE-2026-13850: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-14424: Use after free in Dawn * CVE-2026-14425: Use after free in ANGLE * CVE-2026-13851: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14428: Insufficient validation of untrusted input in Dawn * CVE-2026-14429: Insufficient validation of untrusted input in Skia * CVE-2026-14430: Integer overflow in V8 * CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-13853: Use after free in Journeys * CVE-2026-13854: Use after free in Ozone * CVE-2026-14431: Type Confusion in V8 * CVE-2026-13855: Use after free in Ozone * CVE-2026-13856: Insufficient validation of untrusted input in Speech * CVE-2026-13857: Inappropriate implementation in Geometry * CVE-2026-13858: Out of bounds read in FFmpeg * CVE-2026-13859: Inappropriate implementation in ANGLE * CVE-2026-14391: Integer overflow in ANGLE * CVE-2026-13860: Incorrect security UI in Autofill * CVE-2026-14408: Uninitialized Use in Dawn * CVE-2026-14381: Incorrect security UI in WebAppInstalls * CVE-2026-14383: Inappropriate implementation in V8 * CVE-2026-13861: Use after free in Core * CVE-2026-13862: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) * CVE-2026-13863: Insufficient validation of untrusted input in CustomTabs * CVE-2026-13864: Insufficient policy enforcement in WebHID * CVE-2026-13865: Insufficient validation of untrusted input in Enterprise * CVE-2026-13866: Insufficient validation of untrusted input in Input * CVE-2026-13867: Inappropriate implementation in Geolocation * CVE-2026-13868: Inappropriate implementation in Network * CVE-2026-14384: Out of bounds read in ANGLE * CVE-2026-13869: Use after free in Device * CVE-2026-13870: Use after free in WebView * CVE-2026-13871: Insufficient data validation in GuestView * CVE-2026-13872: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-13873: Out of bounds memory access in Layout * CVE-2026-13874: Inappropriate implementation in DataTransfer * CVE-2026-13875: Insufficient validation of untrusted input in GPU * CVE-2026-13876: Inappropriate implementation in Network * CVE-2026-13877: Insufficient validation of untrusted input in ANGLE * CVE-2026-13878: Use after free in Bluetooth * CVE-2026-13879: Use after free in Bluetooth * CVE-2026-13880: Use after free in USB * CVE-2026-13881: Insufficient data validation in WebAppInstalls * CVE-2026-13882: Inappropriate implementation in USB * CVE-2026-13883: Type Confusion in ANGLE * CVE-2026-13884: Heap buffer overflow in Chromecast * CVE-2026-14387: Integer overflow in Skia * CVE-2026-13885: Use after free in Skia * CVE-2026-13886: Policy bypass in Isolated Web Apps * CVE-2026-14388: Out of bounds read in ANGLE * CVE-2026-14389: Integer overflow in Skia * CVE-2026-13887: Insufficient policy enforcement in NFC * CVE-2026-13888: Use after free in Extensions * CVE-2026-13889: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-13890: Out of bounds read in Chromecast * CVE-2026-13891: Insufficient validation of untrusted input in Extensions * CVE-2026-13892: Inappropriate implementation in Chrome for iOS * CVE-2026-13893: Insufficient validation of untrusted input in WebUI * CVE-2026-13894: Insufficient policy enforcement in Network * CVE-2026-13895: Inappropriate implementation in Autofill * CVE-2026-13896: Insufficient policy enforcement in Glic * CVE-2026-13897: Insufficient policy enforcement in Chromecast * CVE-2026-13898: Use after free in Cast Receiver * CVE-2026-13899: Use after free in HTML * CVE-2026-13900: Insufficient validation of untrusted input in Chromecast * CVE-2026-13901: Insufficient validation of untrusted input in Serial * CVE-2026-13902: Inappropriate implementation in Chrome for iOS * CVE-2026-13903: Insufficient policy enforcement in Bluetooth * CVE-2026-13904: Incorrect security UI in Safe Browsing * CVE-2026-13905: Incorrect security UI in Chrome for iOS * CVE-2026-13906: Out of bounds read in Codecs * CVE-2026-13907: Inappropriate implementation in iOSWeb * CVE-2026-13908: Insufficient validation of untrusted input in Omnibox * CVE-2026-13909: Insufficient policy enforcement in DevTools * CVE-2026-13910: Insufficient policy enforcement in WebXR * CVE-2026-13911: Insufficient data validation in Spellcheck * CVE-2026-13912: Incorrect security UI in Safe Browsing * CVE-2026-13913: Insufficient policy enforcement in Autofill * CVE-2026-13914: Inappropriate implementation in Passwords * CVE-2026-13915: Use after free in Chrome for iOS * CVE-2026-13916: Inappropriate implementation in Chrome for iOS * CVE-2026-13917: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13918: Use after free in Chrome for iOS * CVE-2026-13919: Insufficient data validation in Extensions * CVE-2026-14393: Use after free in V8 * CVE-2026-13920: Insufficient validation of untrusted input in Media * CVE-2026-13921: Insufficient validation of untrusted input in DeviceBoundSessionCredentials * CVE-2026-13922: Side-channel information leakage in Paint * CVE-2026-13923: Uninitialized Use in GPU * CVE-2026-14397: Out of bounds write in ANGLE * CVE-2026-13924: Insufficient validation of untrusted input in WebView * CVE-2026-13925: Inappropriate implementation in Downloads * CVE-2026-13926: Insufficient validation of untrusted input in Network * CVE-2026-13927: Insufficient validation of untrusted input in UI * CVE-2026-13928: Insufficient validation of untrusted input in Enterprise * CVE-2026-13929: Insufficient validation of untrusted input in DevTools * CVE-2026-13930: Insufficient policy enforcement in Actor * CVE-2026-13931: Inappropriate implementation in Media * CVE-2026-13932: Inappropriate implementation in Sharing * CVE-2026-13933: Insufficient policy enforcement in Passwords * CVE-2026-13934: Insufficient validation of untrusted input in Dawn * CVE-2026-14399: Uninitialized Use in Dawn * CVE-2026-13935: Side-channel information leakage in ComputePressure * CVE-2026-13936: Inappropriate implementation in Passwords * CVE-2026-13937: Insufficient policy enforcement in Passwords * CVE-2026-13938: Integer overflow in Fonts * CVE-2026-13939: Insufficient validation of untrusted input in WebShare * CVE-2026-13940: Uninitialized Use in Cast * CVE-2026-13941: Inappropriate implementation in SiteSettings * CVE-2026-13942: Insufficient validation of untrusted input in Video Capture * CVE-2026-13943: Uninitialized Use in CSS * CVE-2026-13944: Inappropriate implementation in DataTransfer * CVE-2026-13945: Insufficient policy enforcement in Extensions * CVE-2026-13946: Inappropriate implementation in ScriptInjections * CVE-2026-13947: Uninitialized Use in XR * CVE-2026-13948: Insufficient policy enforcement in Extensions * CVE-2026-13949: Insufficient policy enforcement in Payments * CVE-2026-14404: Inappropriate implementation in PDFium * CVE-2026-13950: Uninitialized Use in GPU * CVE-2026-13951: Policy bypass in USB * CVE-2026-13952: Inappropriate implementation in PerformanceAPIs * CVE-2026-14406: Out of bounds read in V8 * CVE-2026-13953: Inappropriate implementation in SplitView * CVE-2026-13954: Insufficient policy enforcement in XML * CVE-2026-13955: Insufficient validation of untrusted input in CustomTabs * CVE-2026-13956: Incorrect security UI in PageInfo * CVE-2026-13957: Incorrect security UI in Extensions * CVE-2026-13958: Uninitialized Use in Codecs * CVE-2026-14407: Inappropriate implementation in V8 * CVE-2026-13959: Insufficient validation of untrusted input in Blink * CVE-2026-13960: Inappropriate implementation in Passwords * CVE-2026-13961: Insufficient validation of untrusted input in DevTools * CVE-2026-13962: Insufficient data validation in PDF * CVE-2026-13963: Inappropriate implementation in DevTools * CVE-2026-13964: Insufficient policy enforcement in WebView * CVE-2026-13965: Use after free in Oilpan * CVE-2026-13966: Inappropriate implementation in History * CVE-2026-13967: Type Confusion in V8 * CVE-2026-13968: Insufficient validation of untrusted input in DevTools * CVE-2026-13969: Uninitialized Use in UI * CVE-2026-13970: Uninitialized Use in Media * CVE-2026-13971: Uninitialized Use in Skia * CVE-2026-13972: Inappropriate implementation in Paint * CVE-2026-13973: Inappropriate implementation in UI * CVE-2026-13974: Integer overflow in Safe Browsing * CVE-2026-13975: Out of bounds read in ANGLE * CVE-2026-13976: Heap buffer overflow in Storage * CVE-2026-13977: Inappropriate implementation in HTMLParser * CVE-2026-13978: Insufficient policy enforcement in PageInfo * CVE-2026-14414: Insufficient validation of untrusted input in Skia * CVE-2026-13979: Inappropriate implementation in Paint * CVE-2026-13980: Incorrect security UI in Chrome for iOS * CVE-2026-13981: Inappropriate implementation in Chrome for iOS * CVE-2026-13982: Incorrect security UI in Passwords * CVE-2026-13983: Incorrect security UI in Chrome for iOS * CVE-2026-13984: Incorrect security UI in TabStrip * CVE-2026-13985: Inappropriate implementation in MediaCapture * CVE-2026-13986: Inappropriate implementation in Media UI * CVE-2026-13987: Incorrect security UI in Mobile * CVE-2026-13988: Inappropriate implementation in Paint * CVE-2026-13989: Insufficient policy enforcement in PageInfo * CVE-2026-13990: Insufficient validation of untrusted input in DataTransfer * CVE-2026-13991: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-13992: Inappropriate implementation in UI * CVE-2026-13993: Incorrect security UI in WebAppInstalls * CVE-2026-13994: Inappropriate implementation in Credential Management * CVE-2026-13995: Insufficient validation of untrusted input in Autofill * CVE-2026-13996: Incorrect security UI in Permissions * CVE-2026-13997: Incorrect security UI in Extensions * CVE-2026-13998: Incorrect security UI in File Input * CVE-2026-13999: Inappropriate implementation in Extensions * CVE-2026-14000: Inappropriate implementation in XML * CVE-2026-14001: Inappropriate implementation in Network * CVE-2026-14002: Inappropriate implementation in Geolocation * CVE-2026-14003: Insufficient policy enforcement in Extensions * CVE-2026-14004: Inappropriate implementation in CSS * CVE-2026-14005: Use after free in Omnibox * CVE-2026-14006: Use after free in Navigation * CVE-2026-14007: Insufficient policy enforcement in PermissionsPolicy * CVE-2026-14008: Uninitialized Use in WebXR * CVE-2026-14009: Insufficient data validation in Passwords * CVE-2026-14010: Uninitialized Use in Codecs * CVE-2026-14011: Out of bounds read in SurfaceCapture * CVE-2026-14421: Uninitialized Use in Dawn * CVE-2026-14012: Side-channel information leakage in CSS * CVE-2026-14013: Inappropriate implementation in SVG * CVE-2026-14014: Inappropriate implementation in Paint * CVE-2026-14015: Inappropriate implementation in WebRTC * CVE-2026-14016: Insufficient policy enforcement in SVG * CVE-2026-14017: Inappropriate implementation in Navigation * CVE-2026-14018: Use after free in Updater * CVE-2026-14019: Inappropriate implementation in Passwords * CVE-2026-14020: Insufficient validation of untrusted input in WebXR * CVE-2026-14021: Insufficient validation of untrusted input in StorageAccessAPI * CVE-2026-14022: Insufficient validation of untrusted input in Network * CVE-2026-14023: Insufficient validation of untrusted input in SanitizerAPI * CVE-2026-14024: Use after free in Ozone * CVE-2026-14432: Use after free in V8 * CVE-2026-14025: Use after free in Views * CVE-2026-14026: Incorrect security UI in SplitView * CVE-2026-14027: Use after free in SignIn * CVE-2026-14028: Incorrect security UI in Chrome for iOS * CVE-2026-14030: Incorrect security UI in SplitView * CVE-2026-14031: Incorrect security UI in File Input * CVE-2026-14032: Use after free in Bluetooth * CVE-2026-14033: Insufficient policy enforcement in Media * CVE-2026-14034: Inappropriate implementation in WebXR * CVE-2026-14035: Insufficient policy enforcement in Bluetooth * CVE-2026-14036: Insufficient policy enforcement in Bluetooth * CVE-2026-14037: Insufficient policy enforcement in GPU * CVE-2026-14038: Insufficient validation of untrusted input in New Tab Page * CVE-2026-14039: Insufficient policy enforcement in GetUserMedia * CVE-2026-14040: Use after free in BrowserTag * CVE-2026-14041: Insufficient policy enforcement in Serial * CVE-2026-14042: Inappropriate implementation in Isolated Web Apps * CVE-2026-14043: Use after free in GetUserMedia * CVE-2026-14044: Use after free in ANGLE * CVE-2026-14045: Insufficient validation of untrusted input in Network * CVE-2026-14046: Inappropriate implementation in CustomTabs * CVE-2026-14047: Insufficient policy enforcement in Extensions * CVE-2026-14048: Use after free in Chromecast * CVE-2026-14049: Inappropriate implementation in GPU * CVE-2026-14050: Insufficient policy enforcement in Passwords * CVE-2026-14051: Uninitialized Use in GamepadAPI * CVE-2026-14052: Insufficient policy enforcement in FileSystem * CVE-2026-14053: Insufficient policy enforcement in Extensions * CVE-2026-14054: Insufficient policy enforcement in Network * CVE-2026-14055: Insufficient validation of untrusted input in Device Trust * CVE-2026-14056: Insufficient validation of untrusted input in Media * CVE-2026-14057: Insufficient policy enforcement in FedCM * CVE-2026-14058: Policy bypass in Parser * CVE-2026-14059: Insufficient policy enforcement in Related-Website-Sets * CVE-2026-14060: Insufficient validation of untrusted input in Chromoting * CVE-2026-14061: Inappropriate implementation in Dawn * CVE-2026-14062: Inappropriate implementation in Views * CVE-2026-14063: Out of bounds memory access in Chromecast * CVE-2026-14064: Use after free in PageInfo * CVE-2026-14065: Insufficient validation of untrusted input in PageInfo * CVE-2026-14066: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-14067: Use after free in Chrome for iOS * CVE-2026-14068: Inappropriate implementation in Omnibox * CVE-2026-14069: Integer overflow in WebNN * CVE-2026-14070: Uninitialized Use in WebNN * CVE-2026-14071: Side-channel information leakage in WebAudio * CVE-2026-14072: Incorrect security UI in SplitView * CVE-2026-14073: Insufficient policy enforcement in WebXR * CVE-2026-14394: Use after free in V8 * CVE-2026-14395: Out of bounds write in V8 * CVE-2026-14074: Side-channel information leakage in WebAuthentication * CVE-2026-14075: Policy bypass in Chrome for iOS * CVE-2026-14076: Policy bypass in Network * CVE-2026-14077: Incorrect security UI in Select * CVE-2026-14078: Policy bypass in WebRTC * CVE-2026-14079: Policy bypass in Network * CVE-2026-14080: Insufficient validation of untrusted input in TabSwitcher * CVE-2026-14081: Insufficient policy enforcement in DevTools * CVE-2026-14082: Race in Storage * CVE-2026-14083: Insufficient validation of untrusted input in HTML * CVE-2026-14084: Insufficient validation of untrusted input in Chromoting * CVE-2026-14085: Side-channel information leakage in CSS * CVE-2026-14086: Insufficient policy enforcement in HID * CVE-2026-14087: Insufficient validation of untrusted input in WebNN * CVE-2026-14088: Uninitialized Use in Canvas * CVE-2026-14089: Insufficient validation of untrusted input in PopupBlocker * CVE-2026-14090: Out of bounds read in CameraCapture * CVE-2026-14091: Use after free in DevTools * CVE-2026-14092: Insufficient policy enforcement in Privacy * CVE-2026-14093: Use after free in Cast * CVE-2026-14094: Use after free in Installer * CVE-2026-14095: Insufficient validation of untrusted input in Browser * CVE-2026-14403: Use after free in V8 * CVE-2026-14096: Object lifecycle issue in Input * CVE-2026-14097: Inappropriate implementation in WebAppInstalls * CVE-2026-14098: Inappropriate implementation in CSS * CVE-2026-14405: Uninitialized Use in V8 * CVE-2026-14099: Use after free in Chrome for iOS * CVE-2026-14100: Insufficient data validation in NetworkCache * CVE-2026-14101: Insufficient policy enforcement in Sandbox * CVE-2026-14102: Use after free in Passwords * CVE-2026-14103: Use after free in SSL * CVE-2026-14104: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14105: Insufficient policy enforcement in Speech * CVE-2026-14106: Insufficient validation of untrusted input in Text * CVE-2026-14107: Use after free in Scheduling * CVE-2026-14108: Use after free in PDFium * CVE-2026-14109: Insufficient policy enforcement in Mojo * CVE-2026-14110: Inappropriate implementation in DarkMode * CVE-2026-14111: Use after free in WebProtect * CVE-2026-14112: Inappropriate implementation in Enterprise * CVE-2026-14113: Use after free in Updater * CVE-2026-14114: Inappropriate implementation in WebAppInstalls * CVE-2026-14115: Insufficient validation of untrusted input in Cast * CVE-2026-14116: Insufficient validation of untrusted input in DevTools * CVE-2026-14117: Insufficient validation of untrusted input in DevTools * CVE-2026-14118: Insufficient data validation in DevTools * CVE-2026-14119: Type Confusion in Bluetooth * CVE-2026-14120: Inappropriate implementation in DevTools * CVE-2026-14121: Use after free in Chromoting * CVE-2026-14409: Inappropriate implementation in V8 * CVE-2026-14122: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14410: Inappropriate implementation in Skia * CVE-2026-14123: Incorrect security UI in Chrome for iOS * CVE-2026-14124: Inappropriate implementation in CredentialProvider * CVE-2026-14125: Uninitialized Use in ANGLE * CVE-2026-14126: Incorrect security UI in UI * CVE-2026-14127: Inappropriate implementation in Printing * CVE-2026-14128: Insufficient data validation in Chrome for iOS * CVE-2026-14129: Incorrect security UI in PreviewTab * CVE-2026-14130: Incorrect security UI in Omnibox * CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-14132: Inappropriate implementation in WebXR * CVE-2026-14133: Race in History Embeddings * CVE-2026-14134: Inappropriate implementation in Autofill * CVE-2026-14135: Insufficient validation of untrusted input in Network * CVE-2026-14136: Incorrect security UI in Chrome for iOS * CVE-2026-14137: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-14138: Inappropriate implementation in WebAppInstalls * CVE-2026-14139: Inappropriate implementation in TabStrip * CVE-2026-14140: Insufficient validation of untrusted input in Input * CVE-2026-14141: Incorrect security UI in Document Picture-in-Picture * CVE-2026-14142: Inappropriate implementation in Extensions * CVE-2026-14143: Incorrect security UI in Passwords * CVE-2026-14144: Incorrect security UI in Views * CVE-2026-14145: Inappropriate implementation in CSS * CVE-2026-14146: Inappropriate implementation in CSS * CVE-2026-14147: Inappropriate implementation in CSS * CVE-2026-14415: Inappropriate implementation in V8 * CVE-2026-14148: Type Confusion in CSS * CVE-2026-14149: Use after free in Audio * CVE-2026-14416: Out of bounds read in Dawn * CVE-2026-14150: Insufficient validation of untrusted input in Speech * CVE-2026-14151: Inappropriate implementation in AI * CVE-2026-14152: Out of bounds write in ANGLE * CVE-2026-14153: Inappropriate implementation in Glic * CVE-2026-14154: Inappropriate implementation in DevTools * CVE-2026-14155: Insufficient policy enforcement in StorageAccessAPI * CVE-2026-14156: Policy bypass in StorageAccessAPI - dropped patches: * ppc-fedora-fix-rust-linking.patch - Chromium 150.0.7871.46 (beta released 2026-06-24) - modified patches: * chromium-102-regex_pattern-array.patch * chromium-125-compiler.patch * chromium-144-revert-libxml-2.13.patch * ppc-fedora-fix-breakpad-compile.patch * ppc-fedora-dawn-fix-ppc64le-detection.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-value_or.patch - added patches: * chromium-150-toolchain.patch * chromium-150-sysroot.patch * chromium-150-ffmpeg_no_agtm.patch * chromium-150-icubridge_item_length.patch - keeplibs: added: third_party/llvm-libc third_party/perfetto/protos/third_party/android moved: third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/mitt third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/parsel-js third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/rxjs third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/third_party/urlpattern-polyfill - bump BR for rust-bindgen to 0.72 (0.71 ends up with reserved keyword "gen" in boringssl) ++++ curl: - Security fixes: * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402) * CVE-2026-8458: wrong reuse for different services (bsc#1268407) * CVE-2026-8924: traling dot domain super cookie (bsc#1268409) * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413) * CVE-2026-9079: stale proxy password leak (bsc#1268415) * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416) * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417) * CVE-2026-9547: SSH improper host validation (bsc#1268420) * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422) * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427) * Add patches: curl-CVE-2026-8286.patch curl-CVE-2026-8458.patch curl-CVE-2026-8924.patch curl-CVE-2026-8927.patch curl-CVE-2026-9079.patch curl-CVE-2026-9080.patch curl-CVE-2026-9545.patch curl-CVE-2026-9547.patch curl-CVE-2026-10536.patch curl-config2setopts-exit-if-curl_url_set-fails-on-OOM.patch curl-CVE-2026-12064.patch ++++ s390-tools: - Upgrade s390-tool to version 2.43.0 For Linux kernel version: 7.1 s390-tools: Set Rust MSRV to 1.85.0 - Changes of existing tools: * dbginfo.sh: Add IBM appliance specific files * lshwc: Show explicitly selected unnamed counters with --hide * pvattest: Add firmware check version 2 * zipl: Introduce verbosity levels of zipl session (--debug) * zkey: Remove the use of AF_ALG for calculating key verification patterns - Bug Fixes: * ebc: implement --version option for pvics * pvebc: Log services to journal+console * pvics: Fix virt-resize permission error - Removed obsolete patch * s390-tools-pvebc-Log-services-to-journal-plus-console.patch - Ammended the .spec file for `chreipl_helper` (bsc#1266436) * Moved `chreipl_helper*` to the main package * Added `Requires: %{name} = %{version}` in `chreipl-fcp-mpath subpackage` - Re-vendor-ed vendor.tar.zst ++++ openQA: - Clarify resolution of three CVEs * The following CVEs have been fixed (see previous changelog entries that mentioned only the according Bugzilla tickets): - bsc#1259005 - CVE-2026-27904 - bsc#1264376 - CVE-2026-6321 - bsc#1258632 - CVE-2026-26996 - Update to version 5.1782995932.ffeb09be: * feat: throw 404 for nonexistent groups in overview * feat: Avoid logwarn notifications for non-critical auth error * chore(deps): Dependency cron 2026-07-02 * git subrepo pull (merge) external/os-autoinst-common * fix: Check also hidden files in checklist plugin * test: Enable faster re-connects in full scheduler test consistently * test: Avoid silent daemons in verbose mode * test: Allow running `t/43-…-scalability.t` in parallel * test: Allow running `t/05-scheduler-full.t` in parallel * test: Avoid race condition when generating ports in `25-cache.t` * test: Avoid wasting seconds in `40-script_load_dump_templates.t` * refactor: Remove disabled code in `openqa-load-templates` * test: Avoid race condition when generating ports in many tests * chore(deps): Dependency cron 2026-07-01 * fix(ci): format inline comments in workflows to pass yamllint * test: Avoid running into "Address already in use" in fullstack test * feat(ci): pin GitHub Actions by commit hash ++++ xorg-x11-server: - bsc1268893_CVE-2026-55999_0002-fb-mi-glamor-reject-glyphs-with-negative-dimensions.patch * glamor Font Atlas Heap Buffer Overflow (CVE-2026-55999, bsc#1268893) - bsc1268893_CVE-2026-55999_0003-glamor-reject-fonts-with-per-glyph-metrics-exceeding.patch * GLX contextTags Use-After-Free in CommonMakeCurrent() (CVE-2026-55999, bsc#1268893) - U_GLX-Free-the-tag-of-the-old-context-later.patch bsc1268894_CVE-2026-56000_0001-glx-free-old-context-tag-before-allocating-new-one-i.patch * GLX contextTags Use-After-Free in CommonMakeCurrent() (CVE-2026-56000, bsc#1268894) ------------------------------------------------------------------ ------------------ 2026-7-1 - Jul 1 2026 ------------------- ------------------------------------------------------------------ ++++ binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ buildah: - Add patch for CVE-2026-39829, CVE-2026-39830, CVE-2026-46598 (bsc#1266191) * 0005-CVE-2026-39829-CVE-2026-39830-CVE-2026-46598-golang..patch - Add patch for CVE-2026-39821 (bsc#1266648) * 0006-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch - Rebase patches: * 0001-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch * 0002-run-handle-relabeling-bind-mounts-ourselves.patch * 0003-CVE-2025-52881-backport-subset-of-patch-from-runc.patch * 0004-CVE-2025-47913-CVE-2025-47914-ssh-agent-fixes.patch ++++ clamav: - update to 1.5.3 ClamAV 1.5.3 is a patch release with the following fixes: * bsc#1270091, CVE-2026-20217: Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner. * bsc#1270107, CVE-2026-20213: Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write. * bsc#1270089, CVE-2026-20216: Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage. * bsc#1270085, CVE-2026-20214: Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file. * bsc#1270092, CVE-2026-20243: Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling. * bsc#1270088, CVE-2026-20215: Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive. * bsc#1270106, CVE-2026-20244: Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds. * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time-of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolve CVE-2026-41676, bsc#1270138. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ++++ cross-aarch64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-arm-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-avr-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-bpf-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-epiphany-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-hppa-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-hppa64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-i386-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-ia64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-loongarch64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-m68k-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-mips-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-ppc-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-ppc64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-ppc64le-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-pru-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-riscv64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-rx-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-s390-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-s390x-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-sparc-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-sparc64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-spu-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-x86_64-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ cross-xtensa-binutils: - Don't use libalternatives on SLE16. [bsc#1269059] ++++ docker-compose: - Add patch for CVE-2026-33814 (bsc#1265782) * 0003-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch - Add patch for CVE-2026-39821 (bsc#1266625) * 0004-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch - Add patch for CVE-2025-22869 (bsc#1239340) * 0005-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch - Add patch for CVE-2025-0495 (bsc#1239766) * 0006-CVE-2025-0495-fix-localstate-remove-definition-and-i.patch ++++ systemd: - Temporarily add 5005-nss-systemd-avoid-ELF-TLS-for-recursion-guard.patch until it's merged in the SUSE/v257 branch (bsc#1254924) ++++ systemd: - Temporarily add 5005-nss-systemd-avoid-ELF-TLS-for-recursion-guard.patch until it's merged in the SUSE/v257 branch (bsc#1254924) ++++ os-autoinst: - Update to version 5.1782917048.dcc97e9: * fix: Check also hidden files in checklist plugin * feat(ci): disable Mergify interactive queue controls in PR comments * fix(ci): format inline comments in workflows to pass yamllint * feat(ci): pin GitHub Actions by commit hash * test: assert pipe size adjustment dynamically * test: assert terminal session boundary safety * refactor: support pretty markers in script_sudo and become_root * fix: mmapi test failures and infinite loop hangs * test: simplify Level 3 pretty marker detection * fix: exclude virt-firmware on all older Leap archs ++++ python-msgpack: - CVE-2026-57585: Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error potentially leading to a DoS attack (bsc#1269947) * CVE-2026-57585.patch ++++ systemd-mini: - Temporarily add 5005-nss-systemd-avoid-ELF-TLS-for-recursion-guard.patch until it's merged in the SUSE/v257 branch (bsc#1254924) ++++ systemd-mini: - Temporarily add 5005-nss-systemd-avoid-ELF-TLS-for-recursion-guard.patch until it's merged in the SUSE/v257 branch (bsc#1254924) ------------------------------------------------------------------ ------------------ 2026-6-30 - Jun 30 2026 ------------------- ------------------------------------------------------------------ ++++ blog: - Update to version 2.44 Harden blog and use shims units to handle plymouth Disable coldstart requests via epoll Avoid handling fd twice in epoll loop ++++ nodejs22: - Update to 22.23.1: http: avoid stream listeners on idle agent sockets (bsc#1269825) ++++ nodejs24: - Update to 24.18.0 (bsc#1269825) * doc: update blockList stability status to release candidate * fs: support caller-supplied readFile() buffers * http: close pre-request sockets in closeIdleConnections * loader: implement package maps * net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive * tls: add certificateCompression option * vfs: dispatch node:fs/promises to mounted VFS instances * vfs: add minimal node:vfs subsystem - fix_ci_tests.patch: refreshed - ip-address-bsc1268097.patch: dropped upstreamed ++++ openbabel: - Drop test fixtures with incompatible licenses (boo#1269820): * remove test/fuzz/FuzzedDataProvider.h and test/files/fuzz_regress/methane-pointgroup.g09 -- test-only data carrying Apache-2.0-WITH-LLVM-exception and proprietary Gaussian-09 output; never compiled in or shipped, removed to keep the source tree free of incompatible-licensed material * add openbabel-3.2.0-drop-incompatible-fuzz-harnesses.patch to unwire the fuzz harnesses that include the removed header so the test suite keeps building (CVE coverage retained via the fuzz_obconversion_{sdf,smiles} harnesses) ++++ openQA: - Update to version 5.1782822561.fa3defef: * docs: Add paragraph describing suse_notify AMQP service * feat: Link to autoinst-log from details view ++++ openQA: - Update to version 5.1782822561.fa3defef: * docs: Add paragraph describing suse_notify AMQP service * feat: Link to autoinst-log from details view ++++ os-autoinst: - Update to version 5.1782828634.82ceeb1: * docs: document testing custom os-autoinst forks within openQA * fix: mmapi test failures and infinite loop hangs * feat: Also output module information for wait_serial result steps * feat: Add module name and step number to autoinst-log * feat: Log the CASEDIR git url/hash for easy frontend access * fix: exclude virt-firmware on older Leap ppc64 - Update to version 5.1782809557.0ae98f8: * docs: document testing custom os-autoinst forks within openQA * feat: Also output module information for wait_serial result steps * feat: Add module name and step number to autoinst-log * feat: Log the CASEDIR git url/hash for easy frontend access * fix: exclude virt-firmware on older Leap ppc64 * fix: stop deepening when repo is no longer shallow ++++ os-autoinst: - Update to version 5.1782828634.82ceeb1: * docs: document testing custom os-autoinst forks within openQA * fix: mmapi test failures and infinite loop hangs * feat: Also output module information for wait_serial result steps * feat: Add module name and step number to autoinst-log * feat: Log the CASEDIR git url/hash for easy frontend access * fix: exclude virt-firmware on older Leap ppc64 - Update to version 5.1782809557.0ae98f8: * docs: document testing custom os-autoinst forks within openQA * feat: Also output module information for wait_serial result steps * feat: Add module name and step number to autoinst-log * feat: Log the CASEDIR git url/hash for easy frontend access * fix: exclude virt-firmware on older Leap ppc64 * fix: stop deepening when repo is no longer shallow ++++ python-pydata-sphinx-theme: - CVE-2026-13676: fast-uri: failure to canonicalize Unicode/IDN hostnames for HTTP-family URLs allows for bypass (bsc#1269597) * revendor the vendored tarball with updated versions ++++ qemu: - Package infra (service file): * Move all the way back to tar_scm - Update to version 10.0.11 This release includes the fixes for (among others): bsc#1268794 (CVE-2026-48914) Full backport list here: https://lore.kernel.org/qemu-devel/20260627082646.D825717AB67@think4mjt.localdomain/ A selection of them is reported here below: linux-user: Fix AT_PHDR when program headers are relocated into their own segment hw/pci: Replace assert with bounds check and return ppc/pnv_phb3: Error out on invalid config access linux-user/xtensa: fix unlock of uninitialized frame pointer on sigreturn linux-user/xtensa: save/restore FP registers across signal delivery target/xtensa: add cpu_set_fcr/fsr helpers to sync fp_status ui/sdl2: Set GL ES profile before creating initial GL context hw/9pfs: reject . and .. in Twstat rename hw/9pfs: fix abort due to illegal name with Twstat rename gdbstub: Update x86 control register bits target/i386: apply mod to immediate count of an RCL/RCR operation hw/uefi: fix parse_hexstr target/riscv: mask vxrm csrw write to the low 2 bits disas/riscv.c: fix inst_length() target/riscv/cpu_helper.c: add PMA access fault target/riscv/cpu_helper.c: fault with reserved PTE.PBMT val target/riscv/insn_trans/trans_rvzicbo.c.inc: save opcode before helpers disas/riscv.c: add 'cbo' insns to disassembler target/riscv/csr.c: fix mstatus.UXL reserved value target/riscv/csr.c: do not allow mstatus MPV/GVA writes target/riscv/cpu_helper.c: allow LOAD_ADDR_MIS promotion to AMO fault virtio: Allow to fill a whole virtqueue in order libvduse: fix buffer overflow in vduse_queue_read_indirect_desc() libvhost-user: fix buffer overflow in virtqueue_read_indirect_desc() tests/qtest: Add amd-iommu command buffer head wrap test amd_iommu: Update command buffer head ptr in MMIO region after wraparound amd_iommu: restrict command buffer head/tail ranges to ring size linux-user: add preadv2/preadv2 system/rtc: Fix a possible year-2038 integer overflow problem linux-user/strace: add fsmount series of syscalls linux-user: implement fsmount(2) series of syscalls fpu: Handle all rounding modes in partsN_uncanon_normal hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet qed: Don't try to flush during incoming migration qcow2: Fix data loss on zero write with detect-zeroes=unmap iotests/046: Test that discard/write_zeroes wait for dependencies qcow2: Fix corruption on discard during write with COW qemu-io: Add 'aio_discard' command virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (CVE-2026-48914) block/io: fallback to bounce buffer if BLKZEROOUT is not supported because of alignment s390x/pci: Fix interrupt forwarding disable for interpreted devices target/s390x: Make container ids in SysIB_15x 1-based tests/unit: add test-envlist covering setenv/unsetenv name matching util/envlist: fix prefix-match in envlist_unsetenv() name lookup 9pfs: fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004) tests/9pfs: add deep absolute path test tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle errors hw/9pfs: add error handling to v9fs_fix_path() hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return type hw/9pfs: add NULL check in v9fs_path_is_ancestor() hw/9pfs: move G_GNUC_PRINTF to header linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn linux-user/sh4: restore FP rounding mode on sigreturn linux-user/sh4: preserve T/M/Q bits across signal delivery linux-user/mips: save/restore FCSR across signal delivery linux-user/ppc: restore fp_status from FPSCR on sigreturn hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match() hw/net/rocker_of_dpa: Check group ID pointers are not NULL target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1 target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs target/arm: SVE2 FMAXP, FMINP must honour AH=1 block/linux-aio: bound ioq_submit() recursion depth mc146818rtc: Fix get_guest_rtc_ns() overflow bug apic: fix delivery bitmask with modified xAPIC ids lsi53c895a: clear tag byte when processing messages lsi53c895a: fix use-after-free of cancelled request ui: fix validation of VNC extended clipboard data length ui/vnc: fix OOB read updating VNC update frequency stats ui/vnc: fix OOB write in lossy rect worker code ui/vnc: fix OOB write in VNC stats array ui/vnc: fix OOB read access in VNC SASL mechname array ... - Bug and CVE Fixes: * ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279) * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266) * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266) * update Linux headers to v6.16-rc3 (jsc#PED-9266) * i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266) * i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266) * [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023) - Update to latest stable release (10.0.10) This release includes the fixes for (among others): bsc#1268061 (CVE-2026-3886) Full backport list here: https://lore.kernel.org/qemu-devel/20260528061820.CEE521691A9@think4mjt.localdomain/ A selection of them is reported here below: block/graph-lock: fix missed wakeup in bdrv_graph_co_rdunlock() commit: Drain nodes across all of bdrv_commit() block: Add more defaults to DEFAULT_BLOCK_CONF block: Create DEFAULT_BLOCK_CONF macro ide-test: Test reset during TRIM ide-test: Factor out wait_dma_completion() ide: Clean up ide_trim_co_entry() to be idiomatic coroutine code ide: Minimal fix for deadlock between TRIM and drain block: Add flags parameter to blk_*_pdiscard() block: Add blk_co_start/end_request() and BDRV_REQ_NO_QUEUE blkdebug: Add 'delay-ns' option linux-user/sh4: Fix setup_sigtramp to match Linux kernel trampoline pattern linux-user/sh4: Fix target_ucontext tuc_link field type linux-user: Fix AT_EXECFN in AUXV for symlinked programs hw/nvme: fix admin cq msix setup target/arm/hvf: Fix WFI halting to stop idle vCPU spinning tests/functional/qemu_test/asset.py: Don't use setxattr when it doesn't exist hw/remote/machine.c: Mark x-remote machine as OK for AArch64 and AArch32 meson.build: Add -fzero-init-padding-bits=all tests/qtest/iommu-smmuv3-test: Skip if no TCG GICv3 device present ati-vga: fix ati_set_dirty address calculation hw/i2c/microbit_i2c: Don't index off end of twi_read_sequence[] aspeed/hace: Prevent total_req_len overflow aspeed/hace: Fix out-of-bounds read in has_padding() hw/misc/aspeed_sbc: Add bounds checking for OTP write operations hw/display/cirrus_vga: Fix packed-24 color-expansion transparent copies hw/display/cirrus_vga: Fix packed-24 color-expansion transparent pattern fills hw/ufs: Zero reserved bytes in REPORT LUNS response header hw/ufs: Keep MCQ SQs alive while requests are outstanding hw/ufs: Reject zero-depth MCQ queues hw/ufs: Guard MCQ CQ accesses against missing queues hw/ufs: Validate MCQ SQ references before use tests/functional: Make socat wait longer in migration exec test hw/uefi: check auth.hdr_length minimum size hw/uefi: avoid possibly unaligned variable_auth_2 struct field access hw/uefi: verify data size before accessing it in wrap_pkcs7 hw/uefi: add name_size check to uefi_vars_mm_lock_variable() hw/uefi: fix ucs2 string helper functions hw/uefi: verify pio_xfer_offset before calculating buffer checksum hw/uefi: fix buffer overruns ... ++++ qemu-linux-user: - Package infra (service file): * Move all the way back to tar_scm - Update to version 10.0.11 This release includes the fixes for (among others): bsc#1268794 (CVE-2026-48914) Full backport list here: https://lore.kernel.org/qemu-devel/20260627082646.D825717AB67@think4mjt.localdomain/ A selection of them is reported here below: linux-user: Fix AT_PHDR when program headers are relocated into their own segment hw/pci: Replace assert with bounds check and return ppc/pnv_phb3: Error out on invalid config access linux-user/xtensa: fix unlock of uninitialized frame pointer on sigreturn linux-user/xtensa: save/restore FP registers across signal delivery target/xtensa: add cpu_set_fcr/fsr helpers to sync fp_status ui/sdl2: Set GL ES profile before creating initial GL context hw/9pfs: reject . and .. in Twstat rename hw/9pfs: fix abort due to illegal name with Twstat rename gdbstub: Update x86 control register bits target/i386: apply mod to immediate count of an RCL/RCR operation hw/uefi: fix parse_hexstr target/riscv: mask vxrm csrw write to the low 2 bits disas/riscv.c: fix inst_length() target/riscv/cpu_helper.c: add PMA access fault target/riscv/cpu_helper.c: fault with reserved PTE.PBMT val target/riscv/insn_trans/trans_rvzicbo.c.inc: save opcode before helpers disas/riscv.c: add 'cbo' insns to disassembler target/riscv/csr.c: fix mstatus.UXL reserved value target/riscv/csr.c: do not allow mstatus MPV/GVA writes target/riscv/cpu_helper.c: allow LOAD_ADDR_MIS promotion to AMO fault virtio: Allow to fill a whole virtqueue in order libvduse: fix buffer overflow in vduse_queue_read_indirect_desc() libvhost-user: fix buffer overflow in virtqueue_read_indirect_desc() tests/qtest: Add amd-iommu command buffer head wrap test amd_iommu: Update command buffer head ptr in MMIO region after wraparound amd_iommu: restrict command buffer head/tail ranges to ring size linux-user: add preadv2/preadv2 system/rtc: Fix a possible year-2038 integer overflow problem linux-user/strace: add fsmount series of syscalls linux-user: implement fsmount(2) series of syscalls fpu: Handle all rounding modes in partsN_uncanon_normal hw/usb/hcd-ohci: Clean up USBPacket before freeing ISO TD packet qed: Don't try to flush during incoming migration qcow2: Fix data loss on zero write with detect-zeroes=unmap iotests/046: Test that discard/write_zeroes wait for dependencies qcow2: Fix corruption on discard during write with COW qemu-io: Add 'aio_discard' command virtio-blk: add missing VIRTIO_BLK_T_SCSI_CMD size check (CVE-2026-48914) block/io: fallback to bounce buffer if BLKZEROOUT is not supported because of alignment s390x/pci: Fix interrupt forwarding disable for interpreted devices target/s390x: Make container ids in SysIB_15x 1-based tests/unit: add test-envlist covering setenv/unsetenv name matching util/envlist: fix prefix-match in envlist_unsetenv() name lookup 9pfs: fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004) tests/9pfs: add deep absolute path test tests/qtest/libqos: add qvirtqueue_reset_pool() for descriptor pool reset hw/9pfs: let callers of v9fs_path_sprintf() and v9fs_fix_path() handle errors hw/9pfs: add error handling to v9fs_fix_path() hw/9pfs: change V9fsPath.size to size_t and v9fs_path_sprintf() return type hw/9pfs: add NULL check in v9fs_path_is_ancestor() hw/9pfs: move G_GNUC_PRINTF to header linux-user/s390x: restore fpu_status rounding mode from FPC on sigreturn linux-user/sh4: restore FP rounding mode on sigreturn linux-user/sh4: preserve T/M/Q bits across signal delivery linux-user/mips: save/restore FCSR across signal delivery linux-user/ppc: restore fp_status from FPSCR on sigreturn hw/net/rocker_of_dpa: Avoid unaligned accesses in _of_dpa_flow_match() hw/net/rocker_of_dpa: Check group ID pointers are not NULL target/arm: Don't assert if 64-bit EL2 AT insn sees a Domain fault target/arm: Set correct fp flags for FLOGB when FPCR.AH = 1 target/arm: Use FPST_A64_F16 for SVE FCVTLT_hs target/arm: SVE2 FMAXP, FMINP must honour AH=1 block/linux-aio: bound ioq_submit() recursion depth mc146818rtc: Fix get_guest_rtc_ns() overflow bug apic: fix delivery bitmask with modified xAPIC ids lsi53c895a: clear tag byte when processing messages lsi53c895a: fix use-after-free of cancelled request ui: fix validation of VNC extended clipboard data length ui/vnc: fix OOB read updating VNC update frequency stats ui/vnc: fix OOB write in lossy rect worker code ui/vnc: fix OOB write in VNC stats array ui/vnc: fix OOB read access in VNC SASL mechname array ... - Bug and CVE Fixes: * ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279) * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266) * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266) * update Linux headers to v6.16-rc3 (jsc#PED-9266) * i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266) * i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266) * [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023) - Update to latest stable release (10.0.10) This release includes the fixes for (among others): bsc#1268061 (CVE-2026-3886) Full backport list here: https://lore.kernel.org/qemu-devel/20260528061820.CEE521691A9@think4mjt.localdomain/ A selection of them is reported here below: block/graph-lock: fix missed wakeup in bdrv_graph_co_rdunlock() commit: Drain nodes across all of bdrv_commit() block: Add more defaults to DEFAULT_BLOCK_CONF block: Create DEFAULT_BLOCK_CONF macro ide-test: Test reset during TRIM ide-test: Factor out wait_dma_completion() ide: Clean up ide_trim_co_entry() to be idiomatic coroutine code ide: Minimal fix for deadlock between TRIM and drain block: Add flags parameter to blk_*_pdiscard() block: Add blk_co_start/end_request() and BDRV_REQ_NO_QUEUE blkdebug: Add 'delay-ns' option linux-user/sh4: Fix setup_sigtramp to match Linux kernel trampoline pattern linux-user/sh4: Fix target_ucontext tuc_link field type linux-user: Fix AT_EXECFN in AUXV for symlinked programs hw/nvme: fix admin cq msix setup target/arm/hvf: Fix WFI halting to stop idle vCPU spinning tests/functional/qemu_test/asset.py: Don't use setxattr when it doesn't exist hw/remote/machine.c: Mark x-remote machine as OK for AArch64 and AArch32 meson.build: Add -fzero-init-padding-bits=all tests/qtest/iommu-smmuv3-test: Skip if no TCG GICv3 device present ati-vga: fix ati_set_dirty address calculation hw/i2c/microbit_i2c: Don't index off end of twi_read_sequence[] aspeed/hace: Prevent total_req_len overflow aspeed/hace: Fix out-of-bounds read in has_padding() hw/misc/aspeed_sbc: Add bounds checking for OTP write operations hw/display/cirrus_vga: Fix packed-24 color-expansion transparent copies hw/display/cirrus_vga: Fix packed-24 color-expansion transparent pattern fills hw/ufs: Zero reserved bytes in REPORT LUNS response header hw/ufs: Keep MCQ SQs alive while requests are outstanding hw/ufs: Reject zero-depth MCQ queues hw/ufs: Guard MCQ CQ accesses against missing queues hw/ufs: Validate MCQ SQ references before use tests/functional: Make socat wait longer in migration exec test hw/uefi: check auth.hdr_length minimum size hw/uefi: avoid possibly unaligned variable_auth_2 struct field access hw/uefi: verify data size before accessing it in wrap_pkcs7 hw/uefi: add name_size check to uefi_vars_mm_lock_variable() hw/uefi: fix ucs2 string helper functions hw/uefi: verify pio_xfer_offset before calculating buffer checksum hw/uefi: fix buffer overruns ... ++++ stgit: - Legal review: license correction to GPL-2.0-only See the project site for reference. ++++ stgit: - Update to gix 0.85 and enable sha256 feature (bsc#1262997): 0001-Update-to-gix-0.85-and-enable-sha256-feature.patch - Legal review: license correction to GPL-2.0-only See the project site for reference. ------------------------------------------------------------------ ------------------ 2026-6-29 - Jun 29 2026 ------------------- ------------------------------------------------------------------ ++++ apptainer: - Enable building of SUID starter for SLES 15 (jsc#PED-16347). ++++ blog: - Correct latest changes of 2.43 ++++ gstreamer-plugins-good: - Add CVE-2026-53705.patch: wavpackdec: Avoid integer overflow when calculating output buffer size and related fixes (CVE-2026-53705, bsc#1268449) ++++ keybase-client: - CVE-2026-46604: TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset (bsc#1269600) * Add update-golang-image-1.patch and update-golang-image-2.patch to backport upstreams fix. ++++ krb5: - Prevent read overrun in kdb-ldap: * CVE-2026-11850, bsc#1268131 - Add patch 0012-Prevent-read-overrun-in-libkdb_ldap.patch ++++ nilfs-utils: - add CVE-2026-55392.patch (bsc#1268553, CVE-2026-55392) ++++ openQA: - Update to version 5.1782729563.8f5a14b2: * chore(deps): bump js-yaml from 4.1.1 to 4.3.0 * fix(details view): Align video link the same as the bugref actions * test: bail out when worker fails to become active * refactor(test): use shared wait_for in wait_for_worker * test: fix flaky race in t/05-scheduler-full.t ++++ openQA: - Update to version 5.1782729563.8f5a14b2: * chore(deps): bump js-yaml from 4.1.1 to 4.3.0 * fix(details view): Align video link the same as the bugref actions * test: bail out when worker fails to become active * refactor(test): use shared wait_for in wait_for_worker * test: fix flaky race in t/05-scheduler-full.t ++++ python-pydata-sphinx-theme: - Refresh js dependencies: * ws to 7.5.11 (bsc#1268957, CVE-2026-48779) ++++ python-pydata-sphinx-theme: - Refresh js dependencies: * ws to 7.5.11 (bsc#1268957, CVE-2026-48779) ++++ python-pytest-html: - Revendor updating shell-quote and js-yaml deps: - Add patch update-js-deps.patch - CVE-2026-13311: shell-quote: inefficient input parsing can lead to a denial of service (bsc#1269361) - CVE-2026-53550: js-yaml: quadratic complexity when processing a crafted YAML document can lead to CPU exhaustion (bsc#1268818) ++++ python-python-engineio: - Add security prevent-unnecessary-resource-allocation.patch * CVE-2026-48802: remote user can cause the creation of unnecessary background threads in the server through the heartbeat mechanism and cause a DoS (bsc#1269544) * CVE-2026-48809: size of incoming messages is not checked before they are loaded into memory and allows remote users to cause a DoS via excessive memory allocation (bsc#1269545) ++++ zstd-jni: - Added patch: * max-page-size.patch + Build with max-page-size of 64K on ppc64le (bsc#1269480) ------------------------------------------------------------------ ------------------ 2026-6-28 - Jun 28 2026 ------------------- ------------------------------------------------------------------ ++++ cadvisor: - update to 0.60.3: * Move OOM watching out of the lib module into the binary * lib/model: make ContainerStats sub-stats pointers to convey collection presence - update to 0.60.1: * cpuload/netlink: report the real error and skip the reader on cgroup v2 * deploy: add lib/go.mod to the image build's dependency cache - update to 0.60.0: * Exposing additional cgroup v2 memory.stat metrics * lib: introduce github.com/google/cadvisor/lib — a lean, kubelet-focused library module - bump x/net to 0.55 (bsc#1266645, CVE-2026-39821) - update to 0.57.0 (bsc#1260305, CVE-2026-33186): * integration: add more Docker container handler tests * integration: add containerd container handler tests * integration: add Prometheus metrics endpoint tests * fix: support podman `volatile-containers.json` and/or `containers.json` * proposed roadmap for cAdvisor * remove log message when you can't read productName * Refactor Github Action per b/485167538 * fix crio deadlock in getting crio sandbox containers * Add container_creation_time_seconds (previously: container_start_time_seconds); use runtime start time for container_start_time_seconds (podman & docker) * deps: github.com/moby/moby/client v0.4.0, moby/api v1.54.1, containerd/ttrpc v1.2.8 * fix(build): update k8s-staging-test-infra image in integ tests * feat(manager/container): add configurable initial splay and max jitter factors * feat(manager): add constraint data in OOM events * fix: add v-prefixed GHCR image tags for release consistency * build(deps): bump the go_modules group across 2 directories with 1 update * Expose cgroup v2 memory.events as Prometheus metrics * deploy: bump base images to Alpine 3.23 - Update to version 0.56.2: * docker: fix nil pointer dereference when GraphDriver is nil * Update healthcheck.sh * Update entrypoint.sh * docker: migrate to github.com/moby/moby modules * Update containerd, docker, moby, and opencontainers dependencies * update README * Update copyright year in healthcheck.sh * Update copyright year in entrypoint.sh * Added cadvisor boilerplate header to deploy/entrypoint.sh * Added cadvisor boilerplate header to deploy/healthcheck.sh * Add EXPOSE 8080 to document default port * Fix healthcheck to respect custom port flag * Add entrypoint wrapper to preserve -logtostderr flag * add std in summary * fix formatting * Update container/docker/factory.go * Update factory.go * Update factory.go * Update factory.go * Fix for issue #3772 * docs: replace references to docker registry `gcr.io` with `ghcr.io` * Expose s390x CPU Topology to Prometheus - update to 0.55.1: * manager: fix race condition in Stop() using sync.Once * manager: fix race condition in Stop() using sync.Once - update to 0.55.0: * Reduce lock contention in manager package * container/podman: fix `zfsFilesystem` and `zfsParent` being swapped. * devicemapper: use atomic.Value for lock-free cache reads * Reduce lock contention in cache/memory package * zfs: use atomic.Value for lock-free cache reads * fix: docker health check status not updating * align docker and podman implementations * disable CGO for fully static binaries * close stale PRs and Issues * refactor(container): Migrate to std lib context package * add workflow_dispatch to stale github action * plugin factory: remove useless RegisterPlugin log output * feat(summary): add count in percentiles * machine: fixes for unix.Uname use * feat: add LoadTaskProcess api in containerd client * feat: add exit code in container deletion events * feat: add CRI-O integration tests * test: reorganize integration tests and add CRI-O test coverage * refactor: remove duplicate tests from api package and add missing CRI-O tests * fix: update golang.org/x/crypto to v0.45.0 to fix security vulnerabilities * container/(docker|podman): rewrite obtaining IP-address * Upgrade GitHub Actions to latest versions * Upgrade GitHub Actions for Node 24 compatibility * feat: add fs io cost metrics * go.mod: github.com/docker/go-connections v0.6.0 * fs: introduce pluggable filesystem architecture * Apply build tags liberally for supported environments (linux) * Replace godirwalk with os.ReadDir from standard library * feat: add cpu burst metrics - update to 0.54.1: * chore: update cAdvisor image registry and version in DaemonSet * ci: update Ubuntu version to 24.04 in GitHub Actions workflows * chore: re-enable golangci-lint checks and fix violations * container/docker: GetStats: prevent nil-pointer - update to 0.54.0: * Let us try to use ghcr.io for container images * Add a GH action to create release binaries * use qemu/docker to build arch specific binaries * add -buildvcs=false to GH action * fix(3643) add containerd-snapshotter support * Update README.md with latest Docker image version and registry * Rebase to alpine 3.22, install thin-provisioning-tools from main repo * feat: add metric for container health check status (DOCKER- Specific!) * Update golang and deps - update to version 0.54.1: * container/docker: GetStats: prevent nil-pointer * chore: re-enable golangci-lint checks and fix violations * fix: use Docker-embedded containerd socket in integration tests * refactor: remove Mesos container support * ci: add diagnostic logging for docker/containerd debugging * fix: persist containerd client error to prevent nil pointer dereference * ci: update Ubuntu version to 24.04 in GitHub Actions workflows * chore: update cAdvisor image registry and version in DaemonSet * fix: handle nil Health state in docker container handler * ci: update Go version to 1.25 in GitHub Actions workflows * fix: update dependencies to address security vulnerabilities * add health status tests * feat: Update docker container handler to include health status in stats * Rebase to alpine 3.22, install thin-provisioning-tools from main repo * Update README.md Docker image reference * fix(3643) add containerd-snapshotter support * add -buildvcs=false to GH action * use qemu/docker to build arch specific binaries * Add a GH action to create release binaries * Let us try to use ghcr.io for container images (#3699) - update to 0.53.0 (bsc#1257429, CVE-2024-45310, bsc#1267788, CVE-2026-10722): * fix potential hang on containerd client.LoadContainer * Bump dependencies to latest (June 2, 2025) * fix: fix call Errorf with wrong err * Fixed possible data race * Use built-in error wrapping instead of pkg/errors - drop CVE-2025-22868.patch (upstream) ++++ hauler: - update to 2.0.1 (bsc#1269433, CVE-2026-48702): * bump go to 1.26.4 to squash CVE noise * Full v2 Release notes: https://github.com/hauler- dev/hauler/releases/tag/v2.0.0 - update to 2.0.0: * `v2.0.0` is a **major** release. It replaces Hauler's entire OCI plumbing... the ORAS v1 dependency and the in-house cosign fork with a native containerd based implementation, drops the deprecated `v1alpha1` API, and layers on a meaningful set of new capabilities and reliability fixes on top of that new foundation. * **Removed the ORAS v1 dependency** - push/pull is now driven directly by containerd's docker resolver and `google/go- containerregistry`, new `pkg/content/registry.go` (`RegistryTarget`) and `pkg/content/types.go` (`Target` interface, `IoContentWriter`) replaces what ORAS used to own. * **Removed the hauler-maintained cosign fork** - `pkg/cosign` is now a thin verify only wrapper around upstream `sigstore/cosign/v3`. Images are added through a native `s.AddImage()` path in `pkg/store` * **Added OCI 1.1 Referrers support** - signatures, attestations, and SBOMs are discovered both via the classic cosign tag convention (`sha256-.sig` / `.att` / `.sbom`) and the modern Referrers API, then correctly through the OCI layout ------------------------------------------------------------------ ------------------ 2026-6-26 - Jun 26 2026 ------------------- ------------------------------------------------------------------ ++++ chromium: - Chromium 149.0.7827.200 (boo#1269061): * CVE-2026-13281: Integer overflow in Mojo * CVE-2026-13282: Use after free in Payments * CVE-2026-13283: Use after free in AdFilter ++++ haproxy: - Update to version 3.2.20+git0.9d6f82e72: - VUL-0: CVE-2026-55203: haproxy: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557) - VUL-0: CVE-2026-55204: haproxy: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558) * [RELEASE] Released version 3.2.20 * BUG/MINOR: mux_quic: refresh timeout only if I/O performed * BUG/MEDIUM: mux-quic: Drain the given amount of data in qcs_http_reset_buf() * BUG/MEDIUM: mux-spop: Truly drain outgoing data when the stream is closed * BUG/MEDIUM: mux-h2: Truly drain outgoing HTX data when the stream is closed * BUG/MEDIUM: mux-fcgi: Truly drain outgoing HTX data when the stream is closed * DOC: lua: remove incorrect init tags * BUG/MINOR: hq-interop: prevent reset if missing content-length * BUG/MINOR: hq-interop: reject too big content * BUG/MINOR: server: fix add server with consistent hash balancing * BUG/MEDIUM: mux-fcgi: fix uint16_t overflow in drl += drp * BUG/MEDIUM: mux_quic: fix freeze transfer after QCS rxbuf realign * BUG/MINOR: hpack-tbl: add missing NULL check after hpack_dht_defrag() * BUG/MEDIUM: ssl: Don't free the early data buffer too early * BUG/MINOR: mux-h1: Properly resolve file path for 'h1-case-adjust-file' * BUG/MEDIUM: http-ana: Don't ignore L7 retry errors * BUG/MINOR: http-ana: Remove a debugging memset on redirect * BUG/MINOR: cpu-topo: use ha_diag_notice() to report thread creations * MINOR: errors: add ha_diag_notice() to report diag-level notifications * BUG/MINOR: quic: fix Initial length value in sent packets * BUG/MEDIUM: checks: Dequeue checks on purge * BUG/MINOR: acl: report "ACL" not "map" in ACL ID lookup failures * CLEANUP: sessions: simplify the sess_priv_conns pool name * BUG/MINOR: mux_quic: do not interrupt recv on error/incomplete data * BUG/MEDIUM: mux_quic: prevent risk of infinite loop on recv * MINOR: check: Don't dump buffers state in check traces for external checks * BUG/MEDIUM: check: Skip tcpcheck post-config for external checks * BUG/MEDIUM: vars: Properly eval set-var-fmt action for emtpy log-format string * BUG/MINOR: http-act: Properly handle final evaluation in pause action * BUG/MINOR: tasks: Increase the right niced_task counter * BUG/MEDIUM: leastconn: Unlock the write lock on allocation failure * BUG/MINOR: mux-spop: Fix possible off-by-one OOB read in spop_get_varint() * BUG/MINOR: applet: Commit changes into input buffer after sending HTX data * BUG/MEDIUM: mux-h1: Dup connection/upgrade value to parse it when making headers * BUG/MINOR: cache: Fix copy of value when parsing maxage * BUG/MEDIUM: resolvers: Wait a bit before calling the xprt prepare_srv * BUG/MINOR: cache: fix cache tree iteration * BUG/MINOR: threads: set at least grp_max when mtpg is too small * BUG/MINOR: quic: update drs->lost before calling on_ack_recv * BUG/MEDIUM: quic: reset consecutive_losses on exit from recovery period (cubic) * BUG/MEDIUM: quic: reset cwnd in slow_start on persistent congestion (cubic) * BUG/MINOR: quic: fix ack range node pool_free call passing wrong pointer type * BUG/MINOR: mux-h2: Count padding for connection flow control on error path * BUG/MEDIUM: quic: handle ECONNREFUSED on RX side * CLEANUP: qpack: move encoded macros to qpack-t.h to avoid duplication * BUG/MINOR: qpack: fix huff_dec() error handling in qpack_decode_fs() * CLEANUP: qpack: fix copy-paste typo in value Huffman debug string for WLN * BUG/MINOR: qpack: fix sign bit mask in qpack_decode_fs_pfx() * CLEANUP: qpack: fix copy-paste typo in value Huffman debug string * BUG/MINOR: qpack: fix potential null-pointer dereference in qpack_dht_insert() * BUG/MINOR: qpack: Fix index calculation in debug functions * Revert "BUG/MEDIUM: dns: fix long loops in additional records parse on name failure" * BUG/MEDIUM: cpu-topo: Enforce thread-hard-limit on policy * BUG/MINOR: ssl-gencert: validate SNI characters to prevent SAN certificate injection * BUG/MINOR: tcpcheck: Check LDAP response to not read more data than available * BUG/MINOR: mux-spop: Use relative offset to compute contig data in demux buf * BUG/MINOR: mux-fcgi: Use relative offset to compute contig data in demux buf * BUG/MEDIUM: h1-htx: Sanitize parsing to properly handle upgrade requests * MINOR: h1: Add a H1M flag to specify a non-empty 'Upgrade:' header was parsed * MINOR: http: Add function to remove all occurrences of a value in a header * BUG/MEDIUM: mux-fcgi: reject stream ID 0 for application records * BUG/MINOR: quic: reject packet too short for HP decryption * BUG/MINOR: hlua: prevent Lua from passing CR/LF/NUL in HTTP headers * BUG/MEDIUM: auth: fix unconfigured password NULL deref * BUG/MINOR: h3: reject client CANCEL_PUSH frame * BUG/MEDIUM: h3: reject client push stream * BUG/MINOR: addons/51d: NUL-terminate headers before passing them to Trie API * BUG/MINOR: resolvers: switch to a better PRNG for query IDs * BUG/MINOR: ssl-hello: make use of the null-terminated servername * BUG/MINOR: payload: fix the handshake length bounds check smp_client_hello_parse() * BUG/MINOR: base64: return empty string for empty input in base64dec() * BUG/MINOR: http-ext: always check remaining data when reading rfc7239 nodeport * BUG/MEDIUM: acme: protect against risk of null-deref on connection failure * BUG/MINOR: http-fetch: check against the whole token in get_http_auth() * BUG/MINOR: resolvers: relax size checks in authority record parsing * BUG/MINOR: cache: also recognize directives in the form "token=" * BUG/MEDIUM: cache: always verify the primary hash in get_secondary_entry() * BUG/MEDIUM: h1: limit status codes to 3 digits by default * BUG/MEDIUM: h1: drop headers whose names contain invalid chars * BUG/MINOR: sample: limit the be2hex converter's chunk size * BUG/MINOR: init: use more than ha_random64() for the cluster secret * BUG/MINOR: dict: fix refcount race on insert collision * BUG/MINOR: log: look for the end of priority before the end of the buffer * BUG/MINOR: mux-h2: validate HEADERS frame length before reading stream dep * BUG/MINOR: resolvers: fix risk of appending garbage past the domain name * BUG/MINOR: resolvers: fix room for trailing zero in resolv_dn_label_to_str() * BUG/MEDIUM: cache: fix a refcount leak for missed secondary entries * BUG/MEDIUM: tcpcheck/spoe: bound the SPOP error code to valid values * BUG/MEDIUM: log-forward: make sure the month is unsigned * BUG/MEDIUM: hlua: Fix integer underflow when receiving line from lua cosocket * BUG/MINOR: tcpchecks: Limit parsing of agent-check reply to the buffer * BUG/MEDIUM: dict: hold lock while decrementing refcount in dict_entry_unref * BUG/MINOR: quic: fix ODCID lookup from derived value * BUG/MEDIUM: ssl-gencert: Unlock LRU cache if failing to generate certificate * BUG/MEDIUM: resolvers: Fix test on dn label size in resolv_dn_label_to_str() * BUG/MEDIUM: applet: Properly handle receives of size 0 * BUG/MINOR: ocsp: Manage date too far away in the future * BUG/MINOR: server: Properly handle init-state value during haproxy startup * BUG/MINOR: backend: fix balance hash calculation when using hash-type none * BUG/MINOR: h1: Don't mask websocket protocol if multiple protocols used * BUG/MEDIUM: h1: Skip all h2c values from Upgrade headers during parsing * BUG/MINOR: httpclient-cli: Destroy http-client context if failing to start it * BUG/MINOR: jws: Add missing return value check (EVP_PKEY_get_bn_param) * BUG/MINOR: jws: fix OpenSSL 3.0 version check from > to >= * DOC: config: further clarify that resolvers "default" exists * BUG/MINOR: jwt: fix possible memory leak in convert_ecdsa_sig() error path * BUG/MINOR: check: properly report errno in chk_report_conn_err() * BUG/MINOR: session/trace: use distinct flags for SESS_EV_END and _ERR * BUG/MINOR: resolvers: fix leaked dgram and dns_ring struct in parse_resolve_conf() * BUG/MINOR: resolvers: report the expression error in the do-resolve() action parser * BUG/MINOR: dns: fix dangling dgram pointer on dns_dgram_init() failure path * BUG/MINOR: resolvers: fix dangling list pointer in resolvers_new() error paths * BUG/MEDIUM: server/cli: unlock server lock on failure in cli_parse_set_server * BUG/MINOR: servers: use proper source of pool_conn_name in srv_settings_cpy() * CLEANUP: proxy: fix tiny mistakes in parse error messages * BUG/MEDIUM: dns: fix memory leak of sockaddr in dns_session_init() error path * BUG/MEDIUM: resolvers: fix name compression pointer validation in resolv_read_name() * BUG/MEDIUM: dns: fix long loops in additional records parse on name failure * BUG/MINOR: config/dns: properly fail on duplicate nameserver name detection * BUG/MINOR: backend: correct parameter value validation in get_server_ph_post() * BUILD: 51d.c: cleanup, fix preprocessor ifdefs * REGTESTS: Don't try to use real nameservers for testcases * BUG/MEDIUM: applet: Fix transfer of HTX data to the applet * MINOR: htx: Add htx_move_blks() to move blocks from a message to another * BUG/MEDIUM: dict: hold read lock while incrementing refcount in dict_insert * BUG/MEDIUM: mux_quic: adjust qcc_is_dead() to account detached streams * [RELEASE] Released version 3.2.19 * BUG/MEDIUM: tasks: Keep the TASK_RUNNING flag until queued * BUG/MINOR: cfgparse-listen: do not emit extraneous line in rule order warnings * BUG/MEDIUM: servers: Only requeue servers if they are up * BUG/MEDIUM: stick-table: properly check permissions on CLI's set/clear cmd * BUG/MEDIUM: mux-h2: fix the detection of the ext connect support * Revert "BUG/MINOR: mux-h2: condition the processing of 8441 extension to global setting" * Revert "BUG/MEDIUM: cli: fix master CLI connection slot leak on client disconnect" * BUG/MEDIUM: mux-h2: Properly consume padding for DATA frames * [RELEASE] Released version 3.2.18 * BUG/MEDIUM: h1: Enforce the authority validation during H1 request parsing * BUG/MAJOR: http: forbid comma character in authority value * BUG/MINOR: tools: read_line_to_trash() handle empty files without \n * BUG/MEDIUM: h1_htx: Remove reverved block on error during contig chunks parsing * BUG/MINOR: http-fetch: Fix http_auth_bearer() when custom header is used * BUG/MINOR: acme: contact mail should be optional, don't pass ToS bool * BUG/MINOR: h2: only accept :protocol with extended CONNECT * MINOR: mux-h2: add a new message flag to indicate ext connect support * BUG/MINOR: mux-h2: condition the processing of 8441 extension to global setting * BUG/MINOR: h2: add decoding for :protocol in traces * REGTESTS: http-messaging: always send RFC8441 client settings to use ext connect * DOC: acme: document missing acme-vars and provider-name keywords * BUG/MINOR: mworker/cli: check ci_insert() return value in pcli_parse_request() * BUG/MEDIUM: mworker/cli: fix user and operator permission via @@ in master CLI * REGTESTS: add a regtest to validate various NTLM transitions * BUG/MINOR: resolvers: Free opts on parse error in resolv_parse_do_resolve() * BUG/MINOR: resolvers: Free new requester on error when linking a resolution * BUG/MINOR: tcpcheck: Properly report error for http health-checks * BUG/MINOR: dns: always validate the source address in responses * BUG/MAJOR: mux-h2: preset MSGF_BODY_CL on H2_SF_DATA_CLEN in h2c_dec_hdrs() * BUG/MEDIUM: mux-h2: fix the body_len to check when parsing request trailers * BUG/MINOR: pattern: release the reference on failure to load from file * CLEANUP: map/cli: fix some map-related help messages * BUG/MINOR: map: do not leak a map descriptor on load error * BUG/MINOR: acl: fix a possible arg corruption in smp_fetch_acl_parse() * BUG/MEDIUM: cli: fix master CLI connection slot leak on client disconnect * BUG/MINOR: hpack: validate idx > 0 in hpack_valid_idx() * BUG/MINOR: vars: only print first invalid char in fill_desc() * BUG/MINOR: vars: don't store the variable twice with set-var-fmt * BUG/MINOR: vars: make parse_store() return error on var_set() failure * BUG/MINOR: sink: do not free existing sinks on allocation error * [RELEASE] Released version 3.2.17 * BUG/MINOR: acme: skip auth/challenge steps when newOrder returns a certificate * BUG/MEDIUM: acme: fix segfault on newOrder with empty authorizations * BUG/MINOR: http-htx: Don't normalize emtpy path for OPTIONS requests * BUG/MEDIUM: mux-fcgi: Properly handle full buffer for FCGI_PARAM record * BUG/MINOR: payload: prevent integer overflow in distcc token parsing * BUG/MINOR: payload: validate minimum keyshare_len in smp_fetch_ssl_keyshare_groups * BUG/MINOR: fix various typos and spelling mistakes in user-visible messages * BUG/MEDIUM: tasks: Do not loop in task_schedule() if a task is running * BUG/MAJOR: mux-h1: Deal with true 64-bits integer to emit chunks size * BUG/MEDIUM: http-htx: Loop on full host value during scheme based normalization * BUG/MEDIUM: http-htx: Don't use data from HTX message to update authority * BUG/MAJOR: http-htx: Store new host in a chunk for scheme-based normalization * BUILD: 51d: fix bool definition on dummy lib v4 * BUG/MINOR: http_ana: use scf to report term_evts in http_wait_for_request() * BUG/MEDIUM: mux_h1: fix stack buffer overflow in h1_append_chunk_size() * BUG/MINOR: peers: fix wrong flag reported twice for dump_flags * BUG/MINOR: peers: fix logical "and" when checking for local in PEER_APP_ST_STARTING * BUG/MINOR: sample: fix NULL strm dereference in sample_conv_when * BUG/MINOR: sample: fix memory leak in check_when_cond() when ACL is not found * BUG/MINOR: tools: free previously allocated strings on strdup failure in backup_env() * BUG/MINOR: tools: fix memory leak in indent_msg() on out of memory * BUG/MINOR: tools: my_memspn/my_memcspn wrong cast causing incorrect byte reading * DOC: config: Fix log-format example with last rule expressions * BUG/MINOR: ssl: fix memory leaks on realloc failure in ssl_ckch.c * BUG/MINOR: tcpcheck: Allow connection reuse without prior traffic * [RELEASE] Released version 3.2.16 * BUG/MEDIUM: mux-h1: Force close mode for bodyless message announcing a C-L * BUG/MAJOR: mux-h2: detect incomplete transfers on HEADERS frames as well * BUG/MINOR: debug: properly mark the entire libs archive read-only * BUG/MINOR: compression: properly disable request when setting response * CI: github: only enable OS X on development branches * CI: VTest build with git clone + cache * SCRIPTS: build-vtest: allow to set a TMPDIR and a DESTDIR * REGTESTS: Never reuse server connection in server/cli_delete_dynamic_server.vtc * REGTESTS: Never reuse server connection in jwt/jws_verify.vtc * BUG/MINOR: mux-h1: Fix test to skip trailers from chunked messages * BUG/MINOR: mux-h1: Fix condition to send null-chunk for bodyless message * BUG/MINOR: log: also wait for the response when logging response headers * BUG/MINOR: H2: Don't forget to free shared_rx_bufs on failure * BUG/MINOR: h2: Don't look at the exclusive bit for PRIORITY frame * BUG/MINOR: h2: make tune.h2.log-errors actually work * BUG/MEDIUM: tasks: Make sure we don't schedule a task already running * BUG/MINOR: mux-h2: count a proto error when rejecting a stream on parsing error * BUG/MINOR: mux-h2: count a protocol error when failing to parse a trailer * REGTESTS: ssl: mark ssl_dh.vtc as broken * reg-tests/ssl/ssl_dh.vtc: fix syntax error * BUG/MAJOR: sched: protect task->expire on 32-bit platforms * BUG/MINOR: sample: adjust dependencies for channel output bytes counters * MINOR: sample: make RQ/RS stats available everywhere * BUG/MINOR: log: consider format expression dependencies to decide when to log * BUG/MINOR: task: fix uninitialised read in run_tasks_from_lists() * BUG/MEDIUM: mux-h2: ignore conn->owner when deciding if a connection is dead * BUG/MEDIUM: peers: trash of expired entries delayed after fullresync * BUG/MINOR: acme: don't pass NULL into format string * BUG/MEDIUM: htx: Don't count delta twice when block value is replaced * BUG/MEDIUM: htx: Fix function used to change part of a block value when defrag * BUG/MEDIUM: cli: Properly handle too big payload on a command line * BUG/MINOR: log: Fix error message when using unavailable fetch in logfmt * BUG/MINOR: ot: fixed wrong NULL check in flt_ot_parse_cfg_group() * BUG/MINOR: hlua: fix use-after-free of HTTP reason string * BUG/MEDIUM: mux-fcgi: prevent record-length truncation with large bufsize * BUG/MINOR: sample: fix info leak in regsub when exp_replace fails * BUG/MEDIUM: samples: Fix handling of SMP_T_METH samples * BUG/MINOR: spoe: fix pointer arithmetic overflow in spoe_decode_buffer() * BUG/MINOR: resolvers: fix memory leak on AAAA additional records * BUG/MAJOR: slz: always make sure to limit fixed output to less than worst case literals * BUG/MINOR: peers: fix OOB heap write in dictionary cache update * BUG/MINOR: hlua: fix format-string vulnerability in Patref error path * BUG/MINOR: hlua: fix stack overflow in httpclient headers conversion * BUG: hlua: fix stack overflow in httpclient headers conversion * BUG/MEDIUM: jwt: fix heap overflow in ECDSA signature DER conversion * BUG/MEDIUM: payload: validate SNI name_len in req.ssl_sni * BUG/MINOR: http-act: fix a typo in the "pause" action error message * BUG/MEDIUM: mux-h1: Disable 0-copy forwarding when draining the request * DOC: config: fix ambiguous info in log-steps directive description * BUG/MINOR: cfgcond: fail cleanly on missing argument for "feature" * BUG/MINOR: cfgcond: always set the error string on openssl_version checks * BUG/MINOR: cfgcond: properly set the error pointer on evaluation error * BUG/MINOR: quic: fix documentation for transport params decoding * BUG/MINOR: tcpcheck: Use tcpcheck context for expressions parsing * BUG/MINOR: tcpcheck: Don't enable http_needed when parsing HTTP samples * BUG/MINOR: tcpcheck: Remove unexpected flag on tcpcheck rules for httchck option * BUG/MEDIUM: mux-h1: Don't set MSG_MORE on bodyless responses forwarded to client * BUG/MEDIUM: map/cli: map/acl commands warn when accessed without admin level * BUG/MEDIUM: ssl/ocsp: ocsp commands warn when accessed without admin level * BUG/MEDIUM: ssl/cli: tls-keys commands warn when accessed without admin level * SCRIPTS: git-show-backports: list new commits and how to review them with -L * MINOR: mux-h2: report glitches on early RST_STREAM * MINOR: stconn: flag the stream endpoint descriptor when the app has started * BUG/MINOR: stconn: Always declare the SC created from healthchecks as a back SC * BUG/MINOR: quic: close conn on packet reception with incompatible frame * CI: github: fix tag listing by implementing proper API pagination * BUG/MINOR: acme: fix task allocation leaked upon error * BUG/MEDIUM: acme: skip doing challenge if it is already valid * BUG/MINOR: http-ana: Only consider client abort for abortonclose * BUG/MINOR: config: Properly test warnif_misplaced_* return values * BUG/MINOR: acme: permission checks on the CLI * BUILD: tools: potential null pointer dereference in dl_collect_libs_cb * BUG/MINOR: acme/cli: fix argument check and error in 'acme challenge_ready' * BUG/MINOR: acme: replace atol with len-bounded __strl2uic() for retry-after * BUG/MINOR: acme: free() DER buffer on a2base64url error path * MINOR: ncbmbuf: improve itbmap_next() code * BUG/MEDIUM: spoe: Acquire context buffer in applet before consuming a frame * BUG/MINOR: acme: fix incorrect number of arguments allowed in config * BUG/MINOR: acme: wrong labels logic always memprintf errmsg * BUG/MINOR: acme: acme_ctx_destroy() leaks auth->dns * DOC: config: Reorder params for 'tcp-check expect' directive * DOC: config: Add missing 'status-code' param for 'http-check expect' directive * Revert "BUG/MEDIUM: mux-h2: make sure to always report pending errors to the stream" * BUG/MINOR: acme/cli: wrong argument check in 'acme renew' * BUG/MINOR: acme: wrong error when checking for duplicate section * BUG/MINOR: acme: leak of ext_san upon insertion error * BUG/MEDIUM: acme: fix multiple resource leaks in acme_x509_req() * BUILD: sched: fix leftover of debugging test in single-run changes * MINOR: mux-h2: assign a limited frames processing budget * MEDIUM: sched: change scheduler budgets to lower TL_BULK * MEDIUM: sched: do not punish self-waking tasklets if TASK_WOKEN_ANY * MINOR: sched: do not punish self-waking tasklets anymore * MINOR: sched: do not requeue a tasklet into the current queue * MEDIUM: sched: do not run a same task multiple times in series * BUG/MINOR: qpack: fix 62-bit overflow and 1-byte OOB reads in decoding * BUG/MINOR: sock: adjust accept() error messages for ENFILE and ENOMEM * BUG/MINOR: mworker: fix sort order of mworker_proc in 'show proc' * [RELEASE] Released version 3.2.15 * CI: github: treat vX.Y.Z release tags as stable like haproxy-* branches * BUG/MINOR: mworker/cli: fix show proc pagination losing entries on resume * MINOR: mworker/cli: extract worker "show proc" row printer * BUG/MEDIUM: h3: reject unaligned frames except DATA * BUG/MAJOR: h3: check body size with content-length on empty FIN * BUG/MINOR: mux-h2: properly ignore R bit in WINDOW_UPDATE increments * BUG/MINOR: mux-h2: properly ignore R bit in GOAWAY stream ID * BUG/MEDIUM: peers: enforce check on incoming table key type * BUG/MINOR: mworker: don't try to access an initializing process * MINOR: debug: opportunistically load libthread_db.so.1 with set-dumpable=libs * MINOR: debug: copy debug symbols from /usr/lib/debug when present * DEV: gdb: add a new utility to extract libs from a core dump: libs-from-core * MINOR: debug: read all libs in memory when set-dumpable=libs * MINOR: config: support explicit "on" and "off" for "set-dumpable" * MINOR: tools: add a function to load a file into a tar archive * MINOR: tools: add a function to create a tar file header * DEV: gdb: add a utility to find the post-mortem address from a core * BUILD: spoe: Remove unsused variable * BUG/MINOR: spoe: Fix condition to abort processing on client abort * BUG/MINOR: mjson: make mystrtod() length-aware to prevent out-of-bounds reads * BUG/MINOR: stream: Fix crash in stream dump if the current rule has no keyword * BUG/MINOR: proxy: do not forget to validate quic-initial rules * BUG/MINOR: http-ana: Swap L7 buffer with request buffer by hand * BUG/MINOR: h2/h3: Never insert partial headers/trailers in an HTX message * MINOR: htx: Add function to truncate all blocks after a specific block * BUG/MINOR: h2/h3: Only test number of trailers inserted in HTX message * BUG/MEDIUM: spoe: Properly abort processing on client abort * BUG/MINOR: spoe: Properly switch SPOE filter to WAITING_ACK state * BUG/MINOR: sockpair: set FD_CLOEXEC on fd received via SCM_RIGHTS * BUG/MINOR: mworker: avoid passing NULL version in proc list serialization * BUG/MINOR: mworker: set a timeout on the worker socketpair read at startup * BUG/MINOR: mworker: fix typo &= instead of & in proc list serialization * BUG/MINOR: mworker: only match worker processes when looking for unspawned proc * MINOR: memprof: attempt different retry slots for different hashes on collision * MINOR: tools: extend the pointer hashing code to ease manipulations * BUG/MINOR: memprof: avoid a small memory leak in "show profiling" * BUG/MINOR: mworker: always stop the receiving listener * DOC/CLEANUP: config: update mentions of the old "Global parameters" section * DOC: configuration: http-check expect example typo * BUG/MINOR: jws: fix memory leak in jws_b64_signature * BUG/MINOR: tcpcheck: Fix typo in error error message for `http-check expect` * BUG/MINOR: mworker: don't set the PROC_O_LEAVING flag on master process * [RELEASE] Released version 3.2.14 * SCRIPTS: git-show-backports: add a restart-from-last option * SCRIPTS: git-show-backports: hide the common ancestor warning in quiet mode * BUG/MINOR: backend: Don't get proto to use for webscoket if there is no server * BUG/MINOR: ssl-sample: Fix sample_conv_sha2() by checking EVP_Digest* failures * BUG/MEDIUM: mux-fcgi: Use a safe loop to resume each stream eligible for sending * BUG/MAJOR: resolvers: Properly lowered the names found in DNS response * BUG/MAJOR: fcgi: Fix param decoding by properly checking its size * MINOR: filters: Set last_entity when a filter fails on stream_start callback * DEBUG: stream: Display the currently running rule in stream dump * BUG/MINOR: h1-htx: Be sure that H1 response version starts by "HTTP/" * BUG/MEDIUM: qpack: correctly deal with too large decoded numbers * BUG/MINOR: qpack: fix 1-byte OOB read in qpack_decode_fs_pfx() * BUG/MAJOR: qpack: unchecked length passed to huffman decoder * BUG/MEDIUM: hpack: correctly deal with too large decoded numbers * BUG/MEDIUM: stream: Handle TASK_WOKEN_RES as a stream event * BUG/MINOR: promex: fix server iteration when last server is deleted * BUG/MEDIUM: mux-h2: make sure to always report pending errors to the stream * MINOR: mux-h2: add a new setting, "tune.h2.log-errors" to tweak error logging * MINOR: mux-h2: also count glitches on invalid trailers * [RELEASE] Released version 3.2.13 * CLEANUP: mux-h1: Remove unneeded null check * CI: github: disable windows.yml by default on unofficials repo * CI: vtest: move the vtest2 URL to vinyl-cache.org * MINOR: stconn: Add missing SC_FL_NO_FASTFWD flag in sc_show_flags * BUG/MINOR: http-ana: Stop to wait for body on client error/abort * CLEANUP: compression: Remove unused static buffers * BUG/MINOR: flt-trace: Properly compute length of the first DATA block * DEV: term-events: Fix hanshake events decoding * BUG/MEDIUM: applet: Fix test on shut flags for legacy applets (v2) * BUG/MEDIUM: mux-h1: Stop sending vi fast-forward for unexpected states * BUG/MEDIUM: mux-h2/quic: Stop sending via fast-forward if stream is closed * BUG/MEDIUM: h3: reject frontend CONNECT as currently not implemented * BUG/MAJOR: Revert "MEDIUM: mux-quic: add BUG_ON if sending on locally closed QCS" * BUG/MINOR: ssl: error with ssl-f-use when no "crt" * BUG/MINOR: ssl: clarify ssl-f-use errors in post-section parsing * BUG/MINOR: ssl: fix leak in ssl-f-use parser upon error * BUG/MINOR: ssl: double-free on error path w/ ssl-f-use parser * BUG/MINOR: ssl: lack crtlist_dup_ssl_conf() declaration * BUG/MINOR: deviceatlas: set cache_size on hot-reloaded atlas instance * BUG/MINOR: deviceatlas: fix deinit to only finalize when initialized * BUG/MINOR: deviceatlas: fix resource leak on hot-reload compile failure * BUG/MINOR: deviceatlas: fix double-checked locking race in checkinst * BUG/MINOR: deviceatlas: fix cookie vlen using wrong length after extraction * BUG/MINOR: deviceatlas: fix off-by-one in da_haproxy_conv() * BUG/MEDIUM: deviceatlas: fix resource leaks on init error paths * BUG/MINOR: deviceatlas: add NULL checks on strdup() results in config parsers * BUG/MINOR: deviceatlas: add missing return on error in config parsers * DOC: proxy-proto: underline the packed attribute for struct pp2_tlv_ssl * DOC: internals: addd mworker V3 internals ++++ openQA: - Update to version 5.1782486535.1bf71ec4: * fix(details view): Align video link the same as the bugref actions * fix: Correct call to console.error ++++ perl-List-SomeUtils-XS: - added patches CVE-2026-12844: heap buffer overflow in the `pairwise` function [bsc#1269210] * perl-List-SomeUtils-XS-CVE-2026-12844.patch ++++ python-mistune: - CVE-2026-49851: Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text (bsc#1269091) * CVE-2026-49851.patch ++++ stgit: - Update to version 2.6.1: * chore: update changelog for 2.6.1 * chore: update transitive deps * chore: update gix to 0.84 * chore: update tar to 0.4.46 * chore: update serde_json to 1.0.150 * chore: update jiff to 0.2.29 * chore: update curl to 0.4.50 * stgit.el: Fix Index/Work Tree incremental refresh * fix(rebase): Run --exec commands also if the stack base does not change ++++ stgit: - Update to version 2.6.1: * chore: update changelog for 2.6.1 * chore: update transitive deps * chore: update gix to 0.84 * chore: update tar to 0.4.46 * chore: update serde_json to 1.0.150 * chore: update jiff to 0.2.29 * chore: update curl to 0.4.50 * stgit.el: Fix Index/Work Tree incremental refresh * fix(rebase): Run --exec commands also if the stack base does not change ------------------------------------------------------------------ ------------------ 2026-6-25 - Jun 25 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - added patches CVE-2026-56367: ImageMagick contains an integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out-of-bounds read. [bsc#1268645] * ImageMagick-CVE-2026-56367.patch CVE-2026-56368: memory leak in multiple coders that write raw pixel data [bsc#1269064] * ImageMagick-CVE-2026-56368.patch CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected-components:* artifacts with invalid indices [bsc#1269063] * ImageMagick-CVE-2026-56370.patch CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes [bsc#1268879] * ImageMagick-CVE-2026-56371.patch CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files [bsc#1268880] * ImageMagick-CVE-2026-56376.patch GHSA-3j4x-rwrx-xxj9: ImageMagick has a possible use-after-free write in its PDB decoder * ImageMagick-GHSA-3j4x-rwrx-xxj9.patch ++++ alsa: - Fix double-free vulnerability in parse_def() (CVE-2026-56109, bsc#1268853): 0001-conf-add-missing-return-value-check-in-parse_def.patch ++++ assimp: - added patches CVE-2026-10232: heap use-after-free in aiNode::~aiNode due to invalid node tree when processing malformed ASE files [bsc#1267037] * assimp-CVE-2026-10232.patch ++++ blog: - Update to version 2.43 Make sure that if blog is running it is identified as plymouth Latest also add conflicts to systemd-ask-password-console units in the systemd-ask-password-blog units. This should avoid conflicting password agents asking the same question in s390x. ++++ go1.26-openssl: - Packaging improvements: * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd ++++ jackson-annotations: - Update to 2.18.8 * No changes since 2.17.3 ++++ jackson-core: - Update to 2.18.8 * Changes of 2.18.8 + #1611: Apply number-length validator on streaming integer path of async parser * Changes of 2.18.7 + #1570: Fail parsing from 'DataInput' if 'StreamReadConstraints .getMaxDocumentLength()' set (bsc#1268603, GHSA-2m67-wjpj-xhg9) + #1600: Rework 3rd party licenses in jar + #1602: 'UTF8DataInputJsonParser' needs to enforce 'StreamReadConstraints.maxNameLength' limit * Changes of 2.18.6 + #1512: Number-parsing fix for 'UTF8DataInputJsonParser' + #1548: 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer + #1555: Enforce 'StreamReadConstraints.maxNumberLength' for non-blocking (async) parser * Changes of 2.18.5 + #1433: 'JsonParser#getNumberType()' throws 'JsonParseException' when the current token is non-numeric instead of returning null + #1446: Invalid package reference to "java.lang.foreign" from 'com.fasterxml.jackson.core:jackson-core' (from 'FastDoubleParser') * Changes of 2.18.3 + #1391: Fix issue where the parser can read back old number state when parsing later numbers + #1397: Jackson changes additional values to infinite in case of special JSON structures and existing infinite values + #1398: Fix issue that feature COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom characterEscape is used * Changes of 2.18.2 + #1359: Non-surrogate characters being incorrectly combined when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is enabled * Changes of 2.18.1 + #1353: Use fastdoubleparser 1.0.90 * Changes of 2.18. + #223: 'UTF8JsonGenerator' writes supplementary characters as a surrogate pair: should use 4-byte encoding + #1230: Improve performance of 'float' and 'double' parsing from 'TextBuffer' + #1251: 'InternCache' replace synchronized with 'ReentrantLock' - the cache size limit is no longer strictly enforced for performance reasons but we should never go far about the limit + #1252: 'ThreadLocalBufferManager' replace synchronized with 'ReentrantLock' + #1257: Increase InternCache default max size from 100 to 200 + #1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool' + #1264: Rename shaded 'ch.randelshofer:fastdoubleparser' classes to prevent use by downstream consumers + #1271: Deprecate 'LockFreePool' implementation in 2.18 (remove from 3.0) + #1274: 'NUL'-corrupted keys, values on JSON serialization + #1277: Add back Java 22 optimisation in FastDoubleParser + #1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue() /getDecimalValue()' to avoid String allocation + #1305: Make helper methods of 'WriterBasedJsonGenerator' non-final to allow overriding + #1310: Add new 'StreamReadConstraints' ('maxTokenCount') to limit maximum number of Tokens allowed per document# + #1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal' decoding proble - Modified patch: * 0001-Remove-ch.randelshofer.fastdoubleparser.patch + rebase ++++ jackson-databind: - Update to 2.18.8 * Changes of 2.18.8 + #5950: Improve 'UUIDeserializer' error handling + #5951: Improve 'InetSocketAddress' deserialization (bsc#1268899, CVE-2026-54514) + #5969: '@JsonView' by-passed for some "setterless" creator properties + #5971: '@JsonView' by-passed for unwrapped creator parameters + #5974: '@JsonIgnore' on Record property ignored with 'PropertyNamingStrategy' + #5981: 'BasicPolymorphicTypeValidator' setting 'allowIfSubTypeIsArray()' should validate element type (bsc#1268898, CVE-2026-54513) + #5988: 'PolymorphicTypeValidator' needs to validate generic type parameters too (bsc#1268897, CVE-2026-54512) + #5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls' fold case using JVM default locale (Turkish-I bug) * Changes of 2.18.4 + #4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on Record property ignored for deserialization + #5049: Duplicate creator property "b" (index 0 vs 1) on simple java record * Changes of 2.18.3 + #4444: The 'KeyDeserializer' specified in the class with '@JsonDeserialize(keyUsing = ...)' is overwritten by the 'KeyDeserializer' specified in the 'ObjectMapper'. + #4827: Subclassed Throwable deserialization fails since v2.18.0 - no creator index for property 'cause' + #4844: Fix wrapped array handling wrt 'null' by 'StdDeserializer' + #4848: Avoid type pollution in 'StringCollectionDeserializer' + #4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not work with multiple constructors since 2.18 + #4878: When serializing a Map via Converter(StdDelegatingSerializer), a NullPointerException is thrown due to missing key serializer + #4908: Deserialization behavior change with @JsonCreator and @ConstructorProperties between 2.17 and 2.18 + #4917: 'BigDecimal' deserialization issue when using '@JsonCreator' + #4920: Creator properties are ignored on abstract types when collecting bean properties, breaking AsExternalTypeDeserializer + #4922: Failing '@JsonMerge' with a custom Map + #4932: Conversion of 'MissingNode' throws 'JsonProcessingException' * Changes of 2.18.2 + #4733: Wrong serialization of Type Ids for certain types of Enum values + #4742: Deserialization with Builder, External type id, '@JsonCreator' failing + #4777: 'StdValueInstantiator.withArgsCreator' is now set for creators with no arguments + #4783 Possibly wrong behavior of @JsonMerge + #4787: Wrong 'String.format()' in 'StdDelegatingDeserializer' hides actual error + #4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides '@JsonProperty' values + #4790: Fix '@JsonAnySetter' issue with "setter" method (related to #4639) + #4807: Improve 'FactoryBasedEnumDeserializer' to work better with XML module + #4810: Deserialization using '@JsonCreator' with renamed property failing (since 2.18) * Changes of 2.18.1 + #4508: Deserialized JsonAnySetter field in Kotlin data class is null + #4639: @JsonAnySetter on field ignoring unrecognized properties if they are declared before the last recognized properties in JSON + #4718: Should not fail on trying to serialize 'java.time.DateTimeException' + #4724: Deserialization behavior change with Records, '@JsonCreator' and '@JsonValue' between 2.17 and 2.18 + #4727: Eclipse having issues due'module-info' class "lost" on 2.18.0 jars + #4741: When 'Include.NON_DEFAULT' setting is used on POJO, empty values are not included in json if default is 'null' + #4749: Fixed a problem with 'StdDelegatingSerializer#serializeWithType' looking up the serializer with the wrong argument * Changes of 2.18.0 + #562: Allow '@JsonAnySetter' to flow through Creators + #806: Problem with 'NamingStrategy', creator methods with implicit names + #2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and field level '@JsonProperty' + #3120: Return 'ListIterator' from 'ArrayNode.elements()' + #3241: 'constructorDetector' seems to invalidate 'defaultSetterInfo' for nullability + #3439: Java Record '@JsonAnySetter' value is null after deserialization + #4085: '@JsonView' does not work on class-level for records + #4119: Exception when deserialization uses a record with a constructor property with 'access=READ_ONLY' + #4356: 'BeanDeserializerModifier::updateBuilder()' doesn't work for beans with Creator methods + #4407: 'null' type id handling does not work with 'writeTypePrefix()' + #4452: '@JsonProperty' not serializing field names properly on '@JsonCreator' in Record + #4453: Allow JSON Integer to deserialize into a single-arg constructor of parameter type 'double' + #4456: Rework locking in 'DeserializerCache' + #4458: Rework synchronized block from 'BeanDeserializerBase' + #4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()' method is not called on the serializer + #4472: Rework synchronized block in 'TypeDeserializerBase' + #4483: Remove 'final' on method BeanSerializer.serialize() + #4515: Rewrite Bean Property Introspection logic in Jackson 2.x + #4545: Unexpected deserialization behavior with '@JsonCreator', '@JsonProperty' and javac '-parameters' + #4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper .canSerialize()' + #4580: Add 'MapperFeature .SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator properties' declaration order for sorting + #4584: Provide extension point for detecting "primary" Constructor for Kotlin (and similar) data classes + #4602: Possible wrong use of _arrayDelegateDeserializer in BeanDeserializerBase::deserializeFromObjectUsingNonDefault() + #4617: Record property serialization order not preserved + #4626: '@JsonIgnore' on Record property ignored for deserialization, if there is getter override + #4630: '@JsonIncludeProperties', '@JsonIgnoreProperties' ignored when serializing Records, if there is getter override + #4634: '@JsonAnySetter' not working when annotated on both constructor parameter & field + #4678: Java records don't serialize with 'MapperFeature .REQUIRE_SETTERS_FOR_GETTERS' + #4688: Should allow deserializing with no-arg '@JsonCreator(mode = DELEGATING)' + #4694: Deserializing 'BigDecimal' with large number of decimals result in incorrect value + #4699: Add extra 'writeNumber()' method in 'TokenBuffer' + #4709: Add 'JacksonCollectors' with 'toArrayNode()' implementation - Added patch: * jackson-databind-CVE-2026-54515.patch + Fix #5962: Case-insensitive deserialization may use wrong @JsonIgnoreProperties (bsc#1268902, CVE-2026-54515) ++++ jline3: - Added patch: * jline3-GHSA-47qp-hqvx-6r3f.patch + backport of the upstream fix for GHSA-47qp-hqvx-6r3f, bsc#1269021: unauthenticated remote memory exhaustion via unbounded Telnet 'NEW-ENVIRON variables ++++ libnvme: - Update to version 1.11+28.g5a8252b6: * fabrics: permit bi-auth with secure concat TLS (bsc#1262707) ++++ libvirt: - spec: Strengthen dependency on numa-preplace bsc#1268783 ++++ openQA: - Update to version 5.1782418423.92589c9c: * fix: Correct call to console.error ++++ openQA: - Update to version 5.1782418423.92589c9c: * fix: Correct call to console.error ++++ tboot: - add tboot-grub2-fix-version-find-latest.diff (bsc#1266833): recent versions of grub2 no longer provide the `version_find_latest()` utility function, causing errors when `grub2-mkconfig` is called, leading to incomplete boot entries for tboot. Upstream does not yet provide a fix for this problem, thus this is a custom patch providing a drop-in replacement of the missing function. ------------------------------------------------------------------ ------------------ 2026-6-24 - Jun 24 2026 ------------------- ------------------------------------------------------------------ ++++ GraphicsMagick: - added patches CVE-2026-46523: heap-use-after-free via a crafted MSL image [bsc#1268125] * GraphicsMagick-CVE-2026-46523.patch - modified patches * GraphicsMagick-disable-insecure-coders.patch (disable MSL to align with ImageMagick) ++++ libaom: - added patches CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap-based buffer overflow and a process crash [bsc#1268650] * libaom-CVE-2026-56208.patch CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write [bsc#1268651] CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out-of-bounds heap read [bsc#1268653] CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution [bsc#1268655] * libaom-CVE-2026-56209,56210,56211.patch - added sources * .libaom.spec.swp * libaom-3.11.0.tar.zst - remove _service ++++ apache2: - Fix the following bugs / CVEs: * bsc#1267976 / CVE-2026-29167 * bsc#1267977 / CVE-2026-29170 * bsc#1267978 / CVE-2026-34355 * bsc#1267955 / CVE-2026-34356 * bsc#1267956 / CVE-2026-42535 * bsc#1267962 / CVE-2026-42536 * bsc#1267963 / CVE-2026-43951 * bsc#1267965 / CVE-2026-44119 * bsc#1267969 / CVE-2026-44185 * bsc#1267970 / CVE-2026-44186 * bsc#1267971 / CVE-2026-44631 * bsc#1267972 / CVE-2026-48913 * bsc#1267503 / CVE-2026-49975 - Add patch files: * CVE-2026-29167.patch * CVE-2026-29170.patch * CVE-2026-34355.patch * CVE-2026-34356.patch * CVE-2026-42535.patch * CVE-2026-42536.patch * CVE-2026-43951.patch * CVE-2026-44119.patch * CVE-2026-44119-testsuite.patch * CVE-2026-44185.patch * CVE-2026-44186.patch * CVE-2026-44631.patch * CVE-2026-48913.patch * CVE-2026-49975.patch ++++ apache2-devel: - Fix the following bugs / CVEs: * bsc#1267976 / CVE-2026-29167 * bsc#1267977 / CVE-2026-29170 * bsc#1267978 / CVE-2026-34355 * bsc#1267955 / CVE-2026-34356 * bsc#1267956 / CVE-2026-42535 * bsc#1267962 / CVE-2026-42536 * bsc#1267963 / CVE-2026-43951 * bsc#1267965 / CVE-2026-44119 * bsc#1267969 / CVE-2026-44185 * bsc#1267970 / CVE-2026-44186 * bsc#1267971 / CVE-2026-44631 * bsc#1267972 / CVE-2026-48913 * bsc#1267503 / CVE-2026-49975 - Add patch files: * CVE-2026-29167.patch * CVE-2026-29170.patch * CVE-2026-34355.patch * CVE-2026-34356.patch * CVE-2026-42535.patch * CVE-2026-42536.patch * CVE-2026-43951.patch * CVE-2026-44119.patch * CVE-2026-44119-testsuite.patch * CVE-2026-44185.patch * CVE-2026-44186.patch * CVE-2026-44631.patch * CVE-2026-48913.patch * CVE-2026-49975.patch ++++ apache2-event: - Fix the following bugs / CVEs: * bsc#1267976 / CVE-2026-29167 * bsc#1267977 / CVE-2026-29170 * bsc#1267978 / CVE-2026-34355 * bsc#1267955 / CVE-2026-34356 * bsc#1267956 / CVE-2026-42535 * bsc#1267962 / CVE-2026-42536 * bsc#1267963 / CVE-2026-43951 * bsc#1267965 / CVE-2026-44119 * bsc#1267969 / CVE-2026-44185 * bsc#1267970 / CVE-2026-44186 * bsc#1267971 / CVE-2026-44631 * bsc#1267972 / CVE-2026-48913 * bsc#1267503 / CVE-2026-49975 - Add patch files: * CVE-2026-29167.patch * CVE-2026-29170.patch * CVE-2026-34355.patch * CVE-2026-34356.patch * CVE-2026-42535.patch * CVE-2026-42536.patch * CVE-2026-43951.patch * CVE-2026-44119.patch * CVE-2026-44119-testsuite.patch * CVE-2026-44185.patch * CVE-2026-44186.patch * CVE-2026-44631.patch * CVE-2026-48913.patch * CVE-2026-49975.patch ++++ apache2-manual: - Fix the following bugs / CVEs: * bsc#1267976 / CVE-2026-29167 * bsc#1267977 / CVE-2026-29170 * bsc#1267978 / CVE-2026-34355 * bsc#1267955 / CVE-2026-34356 * bsc#1267956 / CVE-2026-42535 * bsc#1267962 / CVE-2026-42536 * bsc#1267963 / CVE-2026-43951 * bsc#1267965 / CVE-2026-44119 * bsc#1267969 / CVE-2026-44185 * bsc#1267970 / CVE-2026-44186 * bsc#1267971 / CVE-2026-44631 * bsc#1267972 / CVE-2026-48913 * bsc#1267503 / CVE-2026-49975 - Add patch files: * CVE-2026-29167.patch * CVE-2026-29170.patch * CVE-2026-34355.patch * CVE-2026-34356.patch * CVE-2026-42535.patch * CVE-2026-42536.patch * CVE-2026-43951.patch * CVE-2026-44119.patch * CVE-2026-44119-testsuite.patch * CVE-2026-44185.patch * CVE-2026-44186.patch * CVE-2026-44631.patch * CVE-2026-48913.patch * CVE-2026-49975.patch ++++ apache2-prefork: - Fix the following bugs / CVEs: * bsc#1267976 / CVE-2026-29167 * bsc#1267977 / CVE-2026-29170 * bsc#1267978 / CVE-2026-34355 * bsc#1267955 / CVE-2026-34356 * bsc#1267956 / CVE-2026-42535 * bsc#1267962 / CVE-2026-42536 * bsc#1267963 / CVE-2026-43951 * bsc#1267965 / CVE-2026-44119 * bsc#1267969 / CVE-2026-44185 * bsc#1267970 / CVE-2026-44186 * bsc#1267971 / CVE-2026-44631 * bsc#1267972 / CVE-2026-48913 * bsc#1267503 / CVE-2026-49975 - Add patch files: * CVE-2026-29167.patch * CVE-2026-29170.patch * CVE-2026-34355.patch * CVE-2026-34356.patch * CVE-2026-42535.patch * CVE-2026-42536.patch * CVE-2026-43951.patch * CVE-2026-44119.patch * CVE-2026-44119-testsuite.patch * CVE-2026-44185.patch * CVE-2026-44186.patch * CVE-2026-44631.patch * CVE-2026-48913.patch * CVE-2026-49975.patch ++++ apache2-utils: - Fix the following bugs / CVEs: * bsc#1267976 / CVE-2026-29167 * bsc#1267977 / CVE-2026-29170 * bsc#1267978 / CVE-2026-34355 * bsc#1267955 / CVE-2026-34356 * bsc#1267956 / CVE-2026-42535 * bsc#1267962 / CVE-2026-42536 * bsc#1267963 / CVE-2026-43951 * bsc#1267965 / CVE-2026-44119 * bsc#1267969 / CVE-2026-44185 * bsc#1267970 / CVE-2026-44186 * bsc#1267971 / CVE-2026-44631 * bsc#1267972 / CVE-2026-48913 * bsc#1267503 / CVE-2026-49975 - Add patch files: * CVE-2026-29167.patch * CVE-2026-29170.patch * CVE-2026-34355.patch * CVE-2026-34356.patch * CVE-2026-42535.patch * CVE-2026-42536.patch * CVE-2026-43951.patch * CVE-2026-44119.patch * CVE-2026-44119-testsuite.patch * CVE-2026-44185.patch * CVE-2026-44186.patch * CVE-2026-44631.patch * CVE-2026-48913.patch * CVE-2026-49975.patch ++++ apache2-worker: - Fix the following bugs / CVEs: * bsc#1267976 / CVE-2026-29167 * bsc#1267977 / CVE-2026-29170 * bsc#1267978 / CVE-2026-34355 * bsc#1267955 / CVE-2026-34356 * bsc#1267956 / CVE-2026-42535 * bsc#1267962 / CVE-2026-42536 * bsc#1267963 / CVE-2026-43951 * bsc#1267965 / CVE-2026-44119 * bsc#1267969 / CVE-2026-44185 * bsc#1267970 / CVE-2026-44186 * bsc#1267971 / CVE-2026-44631 * bsc#1267972 / CVE-2026-48913 * bsc#1267503 / CVE-2026-49975 - Add patch files: * CVE-2026-29167.patch * CVE-2026-29170.patch * CVE-2026-34355.patch * CVE-2026-34356.patch * CVE-2026-42535.patch * CVE-2026-42536.patch * CVE-2026-43951.patch * CVE-2026-44119.patch * CVE-2026-44119-testsuite.patch * CVE-2026-44185.patch * CVE-2026-44186.patch * CVE-2026-44631.patch * CVE-2026-48913.patch * CVE-2026-49975.patch ++++ assimp: - added patches CVE-2026-10200: This affects the function glTFCommon:CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in a heap-based buffer overflow [bsc#1266999] * assimp-CVE-2026-10200.patch ++++ docker: - Ensure correct certificate is used for TSA auth (bsc#1262346, CVE-2026-39984) * 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch - http2: prevent hanging Transport due to bad SETTINGS (bsc#1265782, CVE-2026-33814) * 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch - idna: update from x/text, fix ToUnicode and all-ASCII xn-- labels (bsc#1266625, CVE-2026-39821) * 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch - daemon: Decompress archives before entering container filesystem (bsc#1267827, CVE-2026-41567) * 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch ++++ giflib: - Added patch: * 0001-Fix-CVE-2026-26740-heap-OOB-write-in-EGifGCBToSavedE.patch + fixing bsc#1259836 (CVE-2026-26740): heap out-of-bounds read when processing a specially crafted GIF file containing a GCE block with a truncated extension byte count ++++ hugo: - Update to version 0.163.1 (bsc#1269015, bsc#1269015): * releaser: Bump versions for release of 0.163.1 * build(deps): bump golang.org/x/image from 0.41.0 to 0.42.0 * Fix multi --renderSegments merge behavior * security: Normalize integer IPv4 host encodings in http.urls check * Drop symlinks in os.ReadDir, os.ReadFile, os.Stat and os.FileExists * Update CI workflow to exclude macOS * commands: Fix convert command * releaser: Prepare repository for 0.164.0-DEV * releaser: Bump versions for release of 0.163.0 * pagesfromdata: Use relative path for content adapter template metrics * ci: Re-add macos-latest to the test matrix * build(deps): bump github.com/bits-and-blooms/bitset * build(deps): bump github.com/tetratelabs/wazero * all: Run go fix ./... * images: Deprecate Imaging.Compression and move it down to webp and avif configs * Only support the latest Go version * resources/jsconfig: Remove deprecated baseUrl setting * build(deps): bump github.com/rogpeppe/go-internal from 1.14.1 to 1.15.0 * page: Add IsBranch and deprecate IsNode * images: Force cache invalidation for AVIF target * images: Add a per-format AVIF hint setting * build(deps): bump github.com/getkin/kin-openapi from 0.138.0 to 0.139.0 * images: Make AVIF chroma subsampling content-aware via the hint * Cap AVIF lossy quality at 99 * config: Deprecate the glogal imaging quality setting * images: Make 60 the default quality for AVIF * livereload: Disconnect from websocket server on pageswap * tpl/tplimpl/embedded: Prevent leading newline in sitemap template * images: Recover from memory alloc errors in WASM image processors * images: Add quality setting per image format * all: Adjust tests for deprecated link and image render hook settings * misc: Remove duplicate words in comments * Add some PNG to AVIF golden test cases * releaser: Prepare repository for 0.163.0-DEV * releaser: Bump versions for release of 0.162.1 * modules/npm: Fix false stale warning after npm pack * tpl/tplimpl: Fix X shortcode test * tpl: Skip broken x shortcode test * Revert "tpl/collections: Make dict return nil when no values are provided" * tpl/time: Fix locale-specific month abbreviations * releaser: Bump versions for release of 0.162.0 * Disallow HTML content by default * Add image processing support for AVIF * config: Preserve intentionally empty maps * hugolib: Fix Page.GitInfo for modules with go.mod in a repo subdirectory * hugolib: Merge existing hugo_stats.json when renderSegments is set * all: Replace RWMutex struct caches with ConcurrentMap * tpl/tplimpl: Consolidate and improve embedded template integration tests * parser: Drop empty sub maps from hugo config output * markup/highlight: Allow overriding type and code via options * Fix typo in CONTRIBUTING.md * Remove note on refactoring contributions * Update AI assistance disclosure requirements * build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 * build(deps): bump golang.org/x/image from 0.40.0 to 0.41.0 * hugolib: Use AllTranslated in IsTranslated * tpl: Simplify sitemap template * tpl: Use AllTranslations in sitemap template * tpl/collections: Make dict return nil when no values are provided * Sync Go template package to 1.26.3 * Squashed 'docs/' changes from 0755fb534d..1f8ddb8a52 * resources: Fix the :counter placeholder * Upgrade to Go 1.26.3 * ci: Check embedded template formatting with gotmplfmt * tpl: Run gotmplfmt -w . * build(deps): bump github.com/getkin/kin-openapi from 0.137.0 to 0.138.0 * build(deps): bump github.com/JohannesKaufmann/html-to-markdown/v2 * markup/goldmark/codeblocks: Always split Chroma options into .Options * docs: Update docs.yaml * hugolib: Allow empty params front matter * commands: Fix import from Jekyll * common/hmaps: Merge slice-valued module config into site config * build(deps): bump golang.org/x/image from 0.39.0 to 0.40.0 * tpl: Use GetMatch for both local and global image resources * Revert "markup/tableofcontents: Skip empty TOC levels" * build(deps): bump golang.org/x/tools from 0.44.0 to 0.45.0 * tpl/templates: Reject Defer inside partialCached * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 * common/hexec: Make NODE_PATH a fallback for ESM bare imports * build(deps): bump github.com/pelletier/go-toml/v2 from 2.3.0 to 2.3.1 * config: Allow repeating the root key in /config files * Revise test naming guidelines in AGENTS.md * Update AGENTS.md * js: Return error for missing batch imports * resources/images: Keep smart crop target size * testing: Use synctest where relevant * Fix prevention of direct symlink reads in resources.Get * security: Validate redirects against security.http.urls * markup/tableofcontents: Skip empty TOC levels * Fall back to hugo.buildDate in hugo.BuildDate() in non-vcs builds * agents: Add a note to Ai security researchers * deps: Upgrade to Chroma v2.24.1 * commands: Fix github-dark chromastyles * css: Make css.Build's file-loader URLs absolute to web context root * hugolib: Don't warn about lang/kind/path coming from cascade.params * markup/goldmark: Unwrap inner HTML for plain code blocks * tpl/tplimpl: Extend page image lookup to include global resources * security: Allow hostnames starting with digits in default http.urls * commands: Improve description of command flags * releaser: Prepare repository for 0.162.0-DEV ++++ libaom-devel-doc: - added patches CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap-based buffer overflow and a process crash [bsc#1268650] * libaom-CVE-2026-56208.patch CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write [bsc#1268651] CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out-of-bounds heap read [bsc#1268653] CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution [bsc#1268655] * libaom-CVE-2026-56209,56210,56211.patch - added sources * .libaom.spec.swp * libaom-3.11.0.tar.zst - remove _service ++++ s390-tools: - Applied a patch (bsc#1268516) * s390-tools-pvebc-Log-services-to-journal-plus-console.patch - Re-vendor-ed vendor.tar.zst ++++ s390-tools: - Applied a patch (bsc#1268516) * s390-tools-pvebc-Log-services-to-journal-plus-console.patch - Re-vendor-ed vendor.tar.zst ++++ libslirp: - added patches CVE-2026-9539: An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 [bsc#1268903] * libslirp-CVE-2026-9539.patch ++++ openQA: - Update to version 5.1782295118.57cb8aa0: * chore(deps): Dependency cron 2026-06-24 * feat: Don't rewrite history for test result tabs * chore(deps): Dependency cron 2026-06-23 ++++ openQA: - Update to version 5.1782295118.57cb8aa0: * chore(deps): Dependency cron 2026-06-24 * feat: Don't rewrite history for test result tabs * chore(deps): Dependency cron 2026-06-23 ++++ openQA: - Update to version 5.1782295118.57cb8aa0: * chore(deps): Dependency cron 2026-06-24 * feat: Don't rewrite history for test result tabs * chore(deps): Dependency cron 2026-06-23 ------------------------------------------------------------------ ------------------ 2026-6-23 - Jun 23 2026 ------------------- ------------------------------------------------------------------ ++++ chromium: - Chromium 149.0.7827.196: * stability and performance improvements ++++ nodejs22: - Update to 22.23.0 (CVE-2026-48618, bsc#1268593) tls: normalize hostname for server identity checks (CVE-2026-48933, bsc#1268592) crypto: guard WebCrypto cipher output length (CVE-2026-48615, bsc#1268598) lib,test: redact proxy credentials in tunnel errors (CVE-2026-48619, bsc#1268618) http2: cap originSet size to prevent unbounded memory growth (CVE-2026-48928, bsc#1268605) tls: fix case-sensitive SNI context matching (CVE-2026-48930, bsc#1268606) dns,net: reject hostnames with embedded NUL bytes (CVE-2026-48934, bsc#1268608) tls: bind reusable sessions to authenticated host (CVE-2026-48617, bsc#1268554) permission: handle process.chdir on writereport (CVE-2026-48931, bsc#1268611) http: fix response queue poisoning in http.Agent (CVE-2026-48935, bsc#1268609) permission: disable FileHandle utimes with permission model (CVE-2026-48937, bsc#1268555) http2: servers keep accepting data even after sending a `GOAWAY` frame (CVE-2026-12151, bsc#1268482) undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-6733, bsc#1268479) undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (CVE-2026-9679, bsc#1268477) undici: vulnerable to HTTP header injection via Set-Cookie percent-decoding (CVE-2026-11525, bsc#1268481) undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-27135, bsc#1259853) nghttp2: assertion failure due to missing state validation can lead to DoS - ngtcp2_bsc1262274.patch: (CVE-2026-40170, bsc#1262274) - ngtcp2: qlog parameters_set stack buffer overflow. - pacote-bsc1266318.patch: (CVE-2026-9496, bsc#1266318) - pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS - ip-address-bsc1268097.patch: (CVE-2026-42338, bsc#1268097) - ip-address: Cross-site scripting via improper HTML escaping of untrusted input - fix update-alternatives calling when not being used ++++ nodejs22: - Update to 22.23.0 (CVE-2026-48618, bsc#1268593) tls: normalize hostname for server identity checks (CVE-2026-48933, bsc#1268592) crypto: guard WebCrypto cipher output length (CVE-2026-48615, bsc#1268598) lib,test: redact proxy credentials in tunnel errors (CVE-2026-48619, bsc#1268618) http2: cap originSet size to prevent unbounded memory growth (CVE-2026-48928, bsc#1268605) tls: fix case-sensitive SNI context matching (CVE-2026-48930, bsc#1268606) dns,net: reject hostnames with embedded NUL bytes (CVE-2026-48934, bsc#1268608) tls: bind reusable sessions to authenticated host (CVE-2026-48617, bsc#1268554) permission: handle process.chdir on writereport (CVE-2026-48931, bsc#1268611) http: fix response queue poisoning in http.Agent (CVE-2026-48935, bsc#1268609) permission: disable FileHandle utimes with permission model (CVE-2026-48937, bsc#1268555) http2: servers keep accepting data even after sending a `GOAWAY` frame (CVE-2026-12151, bsc#1268482) undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-6733, bsc#1268479) undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (CVE-2026-9679, bsc#1268477) undici: vulnerable to HTTP header injection via Set-Cookie percent-decoding (CVE-2026-11525, bsc#1268481) undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-27135, bsc#1259853) nghttp2: assertion failure due to missing state validation can lead to DoS - ngtcp2_bsc1262274.patch: (CVE-2026-40170, bsc#1262274) - ngtcp2: qlog parameters_set stack buffer overflow. - pacote-bsc1266318.patch: (CVE-2026-9496, bsc#1266318) - pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS - ip-address-bsc1268097.patch: (CVE-2026-42338, bsc#1268097) - ip-address: Cross-site scripting via improper HTML escaping of untrusted input - fix update-alternatives calling when not being used ++++ nodejs24: - Update to 24.17.0 (CVE-2026-48618, bsc#1268593) tls: normalize hostname for server identity checks (CVE-2026-48933, bsc#1268592) crypto: guard WebCrypto cipher output length (CVE-2026-48615, bsc#1268598) lib,test: redact proxy credentials in tunnel errors (CVE-2026-48619, bsc#1268618) http2: cap originSet size to prevent unbounded memory growth (CVE-2026-48928, bsc#1268605) tls: fix case-sensitive SNI context matching (CVE-2026-48930, bsc#1268606) dns,net: reject hostnames with embedded NUL bytes (CVE-2026-48934, bsc#1268608) tls: bind reusable sessions to authenticated host (CVE-2026-48617, bsc#1268554) permission: handle process.chdir on writereport (CVE-2026-48931, bsc#1268611) http: fix response queue poisoning in http.Agent (CVE-2026-48935, bsc#1268609) permission: disable FileHandle utimes with permission model (CVE-2026-48937, bsc#1268555) http2: servers keep accepting data even after sending a `GOAWAY` frame (CVE-2026-12151, bsc#1268482) undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-6733, bsc#1268479) undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (CVE-2026-9679, bsc#1268477) undici: vulnerable to HTTP header injection via Set-Cookie percent-decoding (CVE-2026-11525, bsc#1268481) undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-2581, bsc#1268480) undici: Denial of Service due to uncontrolled resource consumption (CVE-2026-9678, bsc#1268478) undici: Information disclosure due to improper cache-control header parsing (CVE-2026-27135, bsc#1259853) nghttp2: assertion failure due to missing state validation can lead to DoS - ngtcp2_bsc1262274.patch: (CVE-2026-40170, bsc#1262274) - ngtcp2: qlog parameters_set stack buffer overflow. - pacote-bsc1266318.patch: (CVE-2026-9496, bsc#1266318) - pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS - ip-address-bsc1268097.patch: (CVE-2026-42338, bsc#1268097) - ip-address: Cross-site scripting via improper HTML escaping of untrusted input - fix_ci_tests.patch: rebased - For changes in older versions, see https://github.com/nodejs/node/releases ++++ dhcpcd: - Update to 10.3.2 * options: Ensure ldop is not NULL dereferenced [bsc#1268761, CVE-2025-70102] * DHCP: Don't run double EXPIRE hooks on carrier loss * DHCP: free the state when dropping on state NONE * BSD: don't send uninitialised memory using ps_root_indirectioctl * Fix fallback_time option * IPv4: Ignore DHCP state when building routes * route: Routes may not have an interface assinged * options: Ensure that an overly long bitflag string does not crash * options: Don't assume vsio options have an argument * common: Cast via uintptr_t rather than unsigned long in UNCONST * privsep: Ensure we recv for real after a successful recv MSG_PEEK * DHCP: Add parentheses to macro definitions * ipv6nd: empty IPV6RA_EXPIRE eloop queue when dropping * privsep: enforce message boundaries with MSG_EOR on our messages * Protocols will notify when dhcpcd can exit * DHCP: Don't request T1 and T2 * DHCP: Don't request a lease time * DHCP6: Don't exit if using DHCP4 INFORM in non manager mode * ND: Route Information Option prefix is optional * ipv6: respect slaac hwaddr to really use the hwaddr * When stopping all interfaces at exit and releasing, remove persistance * NetBSD: Delete RTF_CONNECTED route when changing it * privsep: Drain the log when the root process is exiting * eloop: vastly reworked, kqueue and epoll support on by default ++++ dnsmasq: - Update to 2.93: * CVE-2026-12725, bsc#1268764: Heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies. * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. * CVE-2026-2291: Rework storage allocation for domain names. * Obsoletes dnsmasq-CVE-2026-6507.patch * Obsoletes dnsmasq-Fix-FTBFS-nettle-4.0.patch ++++ go-sendxmpp: - Update to 0.16.0: Added: * Add Ox support to http-upload. * Add Ox support for private group chats. * Show error cause if joining MUCs failedi (requires go-xmpp >= v0.3.5). Changed: * Fix --ox-delete-nodes. * Fix receiving of 1-1 messages while joined in a MUC. * Use go-sendxmpp + a random ID as fallback MUC alias. * Strip leading "xmpp:" from recipients. * Strip trailing "?join" from MUC JIDs. * Add context for timeouts in stanza handling. * Check ID for disco items reply (requires go-xmpp >= v0.3.6). * Reduce channel buffer size to 1 where only one item will be returned. * Deprecate legacy PGP. * CVE-2026-1229: The CombinedMult function produces an incorrect value (bsc#1265538) Bump circl to 1.6.3 * CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617) Bump net to 0.56.0 ++++ gssproxy: - Add package runtime requirement to libverto-module-base (bsc#1268795) Require libverto-module-base so that at least one of the event loop backend implementations will be installed alongside the package, otherwise gssproxy cannot start without explicitly installing the libverto-libev1 package. ++++ gstreamer-plugins-bad: - Add gstreamer-plugins-bad-CVE-2026-52719.patch: Validate that enough data is available for the current JPEG segment (CVE-2026-52719.patch bsc#1268401) ++++ helmfile: - Update to version 1.6.0: * fix: resolve symlinked plugin directories in GetPluginVersion. [#2661] * feat: add helmfile doctor command for AI-assisted diff analysis [#2660] * build(deps): bump github.com/helmfile/chartify from 0.26.5 to 0.27.0 #2659 * build(deps): bump github.com/helmfile/vals from 0.44.1 to 0.44.2 [#2658] * build(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 #2657 * feat: parallel kubedog tracking with progress printer and safety valves #2654 * docs: Small documentation indentation fixes #2655 * build(deps): bump helm to v4.2.2 (and v3.21.2 for the v3 track) [#2651], #2656 * build(deps): bump actions/checkout v6 to v7 #2649 * fix: helmfile deps broken for OCI charts with underscores in path #2648 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.103.3 to 1.104.0 * docs: fix duplicated word in hcl_funcs log description #2647 ++++ libica: - Upgrade libica to version 4.4.2 ( bsc#1265598, bsc#1265599, bsc#1265600, bsc#1265601, bsc#1265602, bsc#1265603 ) * [FEATURE] Updates for FIPS 140-3 certification 2026 * [PATCH] Bug fixes - Added a patch * libica-FIPS-SUSE-certification.patch - Removed obsolete pacthes * libica-FIPS-make-it-possible-to-specify-fipshmac-binary.patch * libica-sles15sp5-FIPS-hmac-key.patch * libica-Block-SHA1-mechanism-for-FIPS-140-3.patch * libica-CONFIGURE-Make-the-OpenSSL-FIPS-config-file-name-configurable.patch * libica-Fix-mutex-thread-lock-in-drbg_uninstantiate-function.patch ++++ mupdf: - Build and ship MuPDF as a shared library (make shared=yes) instead of static-only: * New subpackage libmupdf27_2 carries libmupdf.so.27.2 (the SONAME tracks the upstream minor.patch version). * Replaced the static-only mupdf-devel-static with mupdf-devel, which ships the .so symlink and a generated mupdf.pc (upstream provides no pkg-config file). * mupdf-devel obsoletes the dropped mupdf-devel-static so it is cleanly replaced on upgrade (resolves the /usr/include/mupdf header file conflict flagged in staging). - Consumers that statically embedded libmupdf.a (e.g. zathura's pdf-mupdf plugin) failed to load with "undefined symbol: jpeg_resync_to_restart" because openSUSE builds MuPDF against system codec libraries and the static archive does not pull them in; linking against the shared library (which carries those codecs in its own NEEDED) fixes this (boo#1165273). ++++ nano: - Update to version 9.1: * When searching, the viewport is placed snug left where possible. * The ability to read and write files in old Mac format (a lone carriage return as line ending) was removed. * The ^T toggle between WhereIs and GotoLine was dropped. * Fix backups that were missing or had a wrong timestamp when - -backup is active. * On a crash or kill, a .save file is no longer chmodded or chowned to the base file's permissions and owner. * The history code now creates the ~/.local directory with limited access rights (boo#1263437; the referenced CVE-2026-40556 was rejected upstream). * M-Ins and M-Del have become rebindable. ++++ nvidia-open-driver-G07-signed-cuda: - update non-CUDA variant to 595.84 (boo#1268792) ++++ nvidia-open-driver-G07-signed: - update non-CUDA variant to 595.84 (boo#1268792) ++++ openCryptoki: - Upgrade openCryptoki to version 3.27 (jsc#PED-14609) * Add base support for PKCS#11 v3.2. * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final]. * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA-PKCS and RSA-OAEP mechanisms. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism. * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism. * Soft: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured). * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later) * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16). * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types. * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms. * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys. * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types. * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE. * CCA: Add support for additional RSA public exponent values 5, 17, or 257. * p11sak: Add option to list-key command to show EP11 session IDs. * Make the maximum number of token objects supported configurable. * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791. * Bug fixes. - Updated the .spec file (bsc#1268745) * fixed the permissions in `%{buildroot}%{_prefix}/lib/tmpfiles.d/opencryptoki.conf` - Removed obsolete patches: * ocki-3.26-remove-make-install-chgrp.patch * openCryptoki-CVE-2026-22791-commit-e37e912.patch * openCryptoki-CVE-2026-23893-commit-5e6e4b4.patch * openCryptoki-CVE-2026-40253-commit-ed378f4.patch Added a new patch for ver 3.27: * ocki-3.27-remove-make-install-chgrp.patch ++++ podman: - Add patch for CVE-2026-34986 (bsc#1262856): * 0007-CVE-2026-34986-Merge-commit-from-fork.patch - Add patch for CVE-2026-39829, CVE-2026-39830, CVE-2026-42508, CVE-2026-46598 (bsc#1266125) * 0008-CVE-2026-39829-CVE-2026-39830-CVE-2026-42508-CVE-202.patch - Rebase patches: * 0001-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch * 0002-Fix-Remove-appending-rw-as-the-default-mount-option.patch * 0003-CVE-2025-6032-machine-init-fix-tls-check.patch * 0004-CVE-2025-9566-kube-play-don-t-follow-volume-symlinks.patch * 0005-CVE-2025-52881-backport-subset-of-patch-from-runc.patch * 0006-CVE-2025-47913-CVE-2025-47914-ssh-agent-fixes.patch ++++ python-pdm: - CVE-2026-47763: Do not follow symlinks when writing config files. * Add patch CVE-2026-47763-symlinked-config-files.patch (bsc#1268384) - CVE-2026-47763: Do not write to paths outside the scheme dir. * Add patch CVE-2026-47764-no-paths-outside-scheme-directory.patch (bsc#1268385) - CVE-2026-47781: Update plugin installation path to use project_plugins_dir. * Add patch CVE-2026-47781-plugin-installation-path.patch (bsc#1268386) ++++ python-uv: - GHSA-4gg8-gxpx-9rph: arbitrary file write through entry point names allows malicious wheel to place an executable outside of the intended environment and cause arbitrary code execution (bsc#1268681) - GHSA-pjjw-68hj-v9mw: uv arbitrary file deletion through RECORD entries allows malicious or malformed wheel to induce deletion of files outside of the wheel’s installation prefix on uninstall (bsc#1268684) - Add patches: * GHSA-pjjw-68hj-v9mw.01.patch * GHSA-pjjw-68hj-v9mw.02.patch * GHSA-4gg8-gxpx-9rph.patch ++++ warewulf4: - adding correct flag --update-overlays fixing (bsc#1268790) ------------------------------------------------------------------ ------------------ 2026-6-22 - Jun 22 2026 ------------------- ------------------------------------------------------------------ ++++ apache-commons-net: - Upgrade to 3.13.0 * New features + Add DatagramSocketClient.getDefaultTimeoutDuration() and deprecate getDefaultTimeout() + NET-741: Add subnet IPv6 handling with SubnetUtils6 #391 * Fixed Bugs + DaytimeTCPClientTest now should now pass inside most VPNs + Migrate tests to JUnit5 #358, #359 + Fix malformed Javadoc comments + IMAPExportMbox now restores the current thread's interrupt flag when catching InterruptedException + IOUtil.readWrite() now restores the current thread's interrupt flag when catching InterruptedException + TelnetInputStream now restores the current thread's interrupt flag when catching InterruptedException + NET-740: FTP fails to parse listings for Linux vsftpd in Chinese or Japanese #393 + TelnetInputStream.read() doesn't preserve the original InterruptedException as the cause of its InterruptedIOException + FTPClient._storeFile(String, String, InputStream) doesn't always close it's internal socket when an exception is thrown early in processing + ListenerList.removeListener(T) now ignores null input to avoid a NullPointerException + ListenerList.addListener(T) now ignores null input + Fix typo in FTPConnectionClosedException message from FTP .getReply(boolean) + Reimplement Util.copyReader() with IOUtils.copyLarge() + Reimplement Util.copyStream() with IOUtils.copyLarge() + Reimplement Util.copyStream() with IOUtils.copyLarge() + Deprecate Util.copyReader(Reader, Writer) in favor of IOUtils .copyLarge(Reader, Writer) * Changes + Bump org.apache.commons:commons-parent from 85 to 97 #371, [#388], #389 + Bump org.apache.commons:commons-lang3 from 3.18.0 to 3.19.0 + Bump commons-io:commons-io from 2.20.0 to 2.21.0 + Bump Util.DEFAULT_COPY_BUFFER_SIZE from 1 KiB to 8 KiB - Upgrade to 3.12.0 * New features + Add org.apache.commons.net.nntp.Article#getChild() + Add org.apache.commons.net.nntp.Article#getNext() + Add private SubnetAddressStringIterable and private SubnetAddressStringIterator to implement SubnetInfo.iterableAddressStrings() and SubnetInfo.streamAddressStrings() #298 + Add SubnetInfo.iterableAddressStrings() + Add SubnetInfo.streamAddressStrings() + Add FTPCmd.OPTS + Add FTP.opts(String, String) + Add FTP.opts(String...) + Add FTP.setControlEncoding(Charset) + Add --OPTS to FTPClientExample + NET-727: Add accessing options map for TFTP request packet and allow using 'blksize' option #331 + Add org.apache.commons.net.util.ListenerList.isEmpty() + Add org.apache.commons.net.ftp.FTPClient .getSystemTypeOverride() + Add generics to ListenerList + Add module-info.class in the JAR file instead of an Automatic-Module-Name in MANIFEST.MF + Fixed Bugs + Increase message limit in IMAPReply.TAGGED_RESPONSE from 80 to 500 characters + Increase message limit in IMAPReply.UNTAGGED_RESPONSE from 160 to 500 characters + Remove InvalidKeySpecException from AuthenticatingIMAPClient .auth(AUTH_METHOD, String, String) never throws, it's not thrown + Remove InvalidKeySpecException from AuthenticatingIMAPClient .authenticate(AUTH_METHOD, String, String) never throws, it's not thrown + Remove InvalidKeySpecException from ExtendedPOP3Client .auth(AUTH_METHOD, String, String) never throws, it's not thrown + Remove InvalidKeySpecException from org.apache.commons.net.smtp.AuthenticatingSMTPClient .auth(AUTH_METHOD, String, String) never throws, it's not thrown + Fix SpotBugs RCN_REDUNDANT_NULLCHECK_OF_NONNULL_VALUE in SSLSocketUtils + Fix PMD UnnecessaryFullyQualifiedName + Fix PMD UnusedFormalParameter + Fix PMD AvoidBranchingStatementAsLastInLoop in org.apache .commons.net.bsd.RCommandClient + Fix PMD UselessOverridingMethod in org.apache.commons.net .telnet.TelnetClient + Fix PMD UnnecessaryModifier + Deprecate MLSxEntryParser default constructor in favor of MLSxEntryParser.getInstance() + Deprecate direct access to org.apache.commons.net.nntp.Article .kid and next fields + Fix SpotBugs CT_CONSTRUCTOR_THROW in Base64 by implementing finalize() as a noop to avoid finalizer attacks + Add missing Javadoc to ListenerList + Add missing Javadoc to SubnetUtils + Deprecate PrintCommandListeners.PrintCommandListeners() + Deprecate NtpUtils.NtpUtils() + Deprecate FTPFileFilters.FTPFileFilters() + Avoid multiple possible NullPointerException in SocketClient .verifyRemote(Socket) + PrintCommandListener.protocolReplyReceived(ProtocolCommandEvent) doesn't always use an end-of-line + FTPClientExample uses the wrong FTP system type to parse file lines + Base64 does not call super.finalize() + TFTPServer does not call super.finalize() + KeyManagerUtils.loadStore(String, File, String) shouldn't ignore an IOException closing a keystore stream; use try-with-resources + NNTPClient.readNewsgroupListing() can use an ArrayList instead of a Vector + Deprecate org.apache.commons.net.util.Charsets + Performance: NTFTPEntryParser.parseFTPEntry(String) doesn't need to parse timestamps if there is no name + Improve error handling in org.apache.commons.net.ftp.parser .DefaultFTPFileEntryParserFactory .createFileEntryParser(String, FTPClientConfig) + Fail-fast in org.apache.commons.net.PrintCommandListener .PrintCommandListener(PrintWriter, boolean, char, boolean) if the PrintWriter is null + Avoid NullPointerException in org.apache.commons.net .PrintCommandListener.protocolCommandSent(ProtocolCommandEvent) + Avoid NullPointerException in org.apache.commons.net .PrintCommandListener.protocolReplyReceived(ProtocolCommandEvent) * Changes + Bump org.apache.commons:commons-parent from 70 to 85 #261, [#278], #280, #285, #298, #293, #300, #345 + Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 [#268], #273, #281, #354 + Bump commons-io:commons-io from 2.16.1 to 2.20.0 #286, #308 + Bump org.apache.commons:commons-collections4 from 4.5.0-M2 to 4.5.0 #314 + Bump org.apache.ftpserver:ftpserver-core from 1.2.0 to 1.2.1 - Upgrade to 3.11.1 * Fixed Bugs + Allow longer data in pattern IMAPReply.UNTAGGED_RESPONSE + Fix Reproducible Builds issues #259 - Upgrade to 3.11.0 * New features + NET-726: Add protected getters to FTPSClient #204 + Add SubnetUtils.toString() + Add Maven property project.build.outputTimestamp for build reproducibility + Add FTP.DEFLATE_TRANSFER_MODE to support the "deflate" compression format in FTPClient.setFileTransferMode(int) + Add org.apache.commons.net.SocketClient.checkOpenOutputStream() * Fixed Bugs + Precompile regular expression in UnixFTPEntryParser .preParse(List) + Guard against polynomial regular expression used on uncontrolled data in VMSVersioningFTPEntryParser.REGEX + Guard against polynomial regular expression used on uncontrolled data in IMAPReply.TAGGED_RESPONSE + Guard against polynomial regular expression used on uncontrolled data in IMAPReply.UNTAGGED_RESPONSE + NET-730: Cannot connect to FTP server with HTTP proxy + Base 64 Encoding with URL and Filename Safe Alphabet should not chunk per RFC 4648 + Deprecate org.apache.commons.net.util.Charsets.Charsets() for removal + Deprecate org.apache.commons.net.util.TrustManagerUtils .TrustManagerUtils() for removal * Changes + Bump commons-parent from 62 to 70 #238 + Bump org.codehaus.mojo:exec-maven-plugin from 3.1.0 to 3.2.0, [#221] + Bump commons-lang3 from 3.13.0 to 3.14.0 + Bump commons-io from 2.15.0 to 2.16.1 #236, #240 - Upgrade to 3.10.0 * New features + Add and use DatagramSocketClient.setDefaultTimeout(Duration) and deprecate DatagramSocketClient.setDefaultTimeout(int) + Add and use TFTP.DEFAULT_TIMEOUT_DURATION and deprecate org.apache.commons.net.tftp.TFTP.DEFAULT_TIMEOUT + Add and use DatagramSocketClient#getSoTimeoutDuration() + Add and use DatagramSocketClient#setSoTimeout(Duration) + Add and use DatagramSocketClient.checkOpen() + Add TelnetClient.sendAYT(Duration) + TFTPServer implements AutoCloseable + DatagramSocketClient implements AutoCloseable + Add IMAP package tests, include junit-jupiter-params artifact [#166] + Add Base64 missing tests and documentation fixes #161 + Add FTPFile tests and fix Javadoc typos #162 + Add IMAPReply tests and documentation fixes #165 * Fixed Bugs + NET-650: Delegate host resolution to Socket.connect() #138 + Fixes many grammar issues and typos in JavaDoc and code comments #141 + Remove redundant (null) initializations and other clean ups [#155] + TFTPServer.setMaxTimeoutRetries() now throws IllegalArgumentException instead of RuntimeException + TFTPServer.setSocketTimeout() now throws IllegalArgumentException instead of RuntimeException + FTPCommand.checkArray() now throws IllegalStateException instead of RuntimeException + org.apache.commons.net.nntp.Threader now throws IllegalStateException instead of RuntimeException + POP3Command static initializer now throws IllegalStateException instead of RuntimeException + SMTPCommand static initializer now throws IllegalStateException instead of RuntimeException + SubnetUtils.SubnetInfo.getPreviousAddress() now throws IllegalStateException instead of RuntimeException + IMAPExportMbox.MboxListener.chunkReceived(IMAP) now throws UncheckedIOException instead of RuntimeException + IMAPUtils.imapLogin(URI, int, ProtocolCommandListener) now throws IOException instead of RuntimeException while maintaining method signature source compatibility + [StepSecurity] ci: Harden GitHub Actions #156 + NET-722: Javadoc for FtpClient .setControlKeepAliveReplyTimeout(Duration) says timeout is in milliseconds + Change class org.apache.commons.net.ftp.parser .MVSFTPEntryParser to support more datasets #182 + Bulletproof TFTPServerPathTest #173 + Deprecate org.apache.commons.net.util.Base64 in favor of java.util.Base64 + Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.ftp + Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.imap + Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.pop3 + Replace use of org.apache.commons.net.util.Base64 with java.util.Base64 in org.apache.commons.net.smtp * Changes + Bump commons-parent from 54 to 62 #132, #137, #153 + Bump commons-io from 2.11.0 to 2.14.0 + Bump commons-lang3 from 3.12.0 to 3.13.0 ++++ apache-commons-pool2: - Update to 2.13.1 * Fixed Bugs: + POOL-427: The fix for POOL-425 introduced a regression where addObject fails when maxIdle is negative (indicating no limit) - Removed patch: * jakarta-commons-pool-build.patch + not needed with this version - Update to 2.13.0 * New features: + Add org.apache.commons.pool2.PooledObject .nonNull(PooledObject) + Add org.apache.commons.pool2.PooledObject .getObject(PooledObject) + Made statistics collection optional in BaseGenericObjectPool [#429] * Fixed Bugs: + POOL-424: GenericObjectPool.invalidateObject() can leave other threads waiting to borrow hanging. The fix for this issue changes behavior of invalidateObject. This method now always tries to add a new instance to the pool to replace the invalidated and destroyed instance. As a result of this change, abandoned object removal now attemps to replace abandoned objects + POOL-425: GenericObjectPool addObject does not respect maxIdle + POOL-350: Make placement of calls to GKOP reuseCapacity configurable + POOL-290: TestSoftRefOutOfMemory (unit test) can loop infinitely on failure + POOL-419: GenericObjectPool counters and object collections can be corrupted when returnObject and invalidate are invoked concurrently by client threads on the same pooled object + POOL-421: GenericObjectPool addObject should return immediately when there is no capacity to add + POOL-420: The maximum wait time for GenericKeyedObjectPool .borrowObject(*) may exceed configured maximum wait time. This is the same issue as POOL-418, but for GKOP. Also included in this fix is a change to addObject that prevents it from waiting for capacity to create. That method now returns immediately when there is no capcity to add to the pool under the given key + Remove -nouses directive from maven-bundle-plugin. OSGi package imports now state 'uses' definitions for package imports, this doesn't affect JPMS (from org.apache.commons:commons-parent:80) + POOL-418: The maximum wait time for GenericObjectPool .borrowObject(*) may exceed expectations due to a spurious thread wakeup. he remaining duration was incorrectly calculated and the method did not end up waiting long enough. Recompute the remaining duration an additional time when we block when exhausted + Fix site link from the About page to the Download page, see also #387 + Operation on the "idleHighWaterMark" shared variable in "ErodingFactor" class is not atomic [org.apache.commons.pool2.PoolUtils$ErodingFactor] At PoolUtils.java:[line 98] AT_NONATOMIC_OPERATIONS_ON_SHARED_VARIABLE + org.apache.commons.pool2.impl.GenericObjectPool .create(Duration) should normalize a negative duration to zero + Fix potential ConcurrentModificationException in EvictionTimer thread clean-up + Fix potential ConcurrentModificationException in EvictionTimer tasks * Changes: + Bump org.apache.commons:commons-parent from 79 to 93 + [test] Bump commons-lang3 from 3.17.0 to 3.20.0 - Update to 2.12.1 * Fixed Bugs: + Use java.time.Instant precision in org.apache.commons.pool2 .impl.ThrowableCallStack.Snapshot throwable message + GenericObjectPool.borrowObject(Duration) doesn't obey its borrowMaxWait Duration argument when the argument is different from GenericObjectPool.getMaxWaitDuration() + POOL-418: The maximum wait time for GenericObjectPool .borrowObject(*) may exceed expectations due to a spurious thread wakeup + Javadoc is missing its Overview page + Migrate site generation templates to https://maven.apache.org/xsd/xdoc-2.0.xsd * Changes: + Bump org.apache.commons:commons-parent from 62 to 79 + [test] Bump commons-lang3 from 3.13.0 to 3.17.0 + [site] Pickup org.apache.bcel:bcel version from parent POM + [test] Bump org.ow2.asm:asm-util from 9.5 to 9.7.1 - Update to 2.12.0 * New features: + Add PooledObject.getFullDuration() + Add GenericKeyedObjectPool.getKeys() + Add KeyedObjectPool.getKeys() + Add github/codeql-action. + Add BaseGenericObjectPool.Evictor.toString(). + Make BaseGenericObjectPool implement AutoCloseable. + Add BaseGenericObjectPool methods that return Duration and deprecate equivalents that return milliseconds as long + Add BaseObjectPoolConfig.DEFAULT_DURATION_BETWEEN_EVICTION_RUNS and deprecate BaseObjectPoolConfig .DEFAULT_TIME_BETWEEN_EVICTION_RUNS * Fixed Bugs: + POOL-401: Ensure that capacity freed by invalidateObject is available to all keyed pools + POOL-391: Ensure capacity freed by clear is made available to GKOP borrowers + POOL-402: Check blockWhenExhausted in hasBorrowWaiters #116 + Simplify test assertion with similar call but simpler. #131 + POOL-405: NullPointerException GenericKeyedObjectPool .invalidateObject(GenericKeyedObjectPool.java:1343) + POOL-408: Fix a typo related to KeyedPooledObjectFactory on the site and Javadoc + Fail-fast on null input for DefaultPooledObjectInfo .DefaultPooledObjectInfo(PooledObject) with a NullPointerException + POOL-393: Improve BaseGenericObjectPool's JMX Register performance when creating many pools + Null-guard in GenericObjectPool.use(T) like other call sites of GenericObjectPool.getPooledObject(T) + POOL-411: Guard against NPE when deregistering a key at the end of borrow + Make private GenericKeyedObjectPool.ObjectDeque class static + Make private BaseGenericObjectPool.StatsStore class static + [StepSecurity] ci: Harden GitHub Actions #225 + Fix possible NPE in DefaultPooledObjectInfo .getPooledObjectToString() + Fix possible NPE in DefaultPooledObjectInfo .getPooledObjectType() * Changes: + Bump actions/cache from 2.1.6 to 3.0.10 #117, #138, #158, [#174], #178 + Bump actions/checkout from 2.3.4 to 3.0.2 #109, #112, #134 + Bump actions/setup-java from 2 to 3.5.1 + Bump spotbugs from 4.3.0 to 4.7.3 #94, #99, #106, #114, #122, [#129], #137, #155, #168, #187 + Bump spotbugs-maven-plugin from 4.3.0 to 4.7.3.0 #102, #110, [#119], #125, #128, #139, #149, #157, #161, #169, #180, #190 + Bump junit-bom from 5.8.0-M1 to 5.9.1 #96, #100, #103, #120, [#160], #172 + Bump checkstyle from 8.45.1 to 9.3 #97, #104, #111, #121, [#126], #132 + Bump maven-checkstyle-plugin from 3.1.2 to 3.2.0 #166 + Bump maven-pmd-plugin from 3.14.0 to 3.19.0 #101, #153, #170 + Bump pmd from 6.44.0 to 6.52.0 + Bump biz.aQute.bndlib from 5.3.0 to 6.4.1 #105, #118, #135, [#151], #154, #191, #223 + Bump maven-bundle-plugin from 5.1.3 to 5.1.8 #127, #146, #148, [#159], #164 + Bump maven-surefire-plugin from 3.0.0-M7 to 3.0.0-M6 #142, [#152] + Bump asm-util from 9.2 to 9.5 #141, #179, #220 + Bump commons-parent from 52 to 58 #173, #195, #204, #222 + Bump japicmp-maven-plugin from 0.15.3 to 0.16.0 + Bump animal-sniffer-maven-plugin 1.20 to 1.21 + Bump Apache Commons BCEL 6.5.0 to 6.7.0 #194 + Bump commons-lang3 from 3.12.0 to 3.13.0 - Update to 2.11.1 * Fixed Bugs: + Getting a PooledObject's active duration returns a negative duration when the object is borrowed but not returned. Affects: ° PooledObject.getActiveDuration() ° PooledObject.getActiveTime() ° PooledObject.getActiveTimeMillis() + The default implementation of TrackedUse.getLastUsedInstant() uses seconds instead of milliseconds + This interface is not implemented within Apache Commons Pool but affects Apache Commons DBCP + DefaultPooledObject.getIdleTime() drops nanoseconds on Java 9 and greater + Fix field label in BaseGenericObjectPool toString() builder: From timeBetweenEvictionRunsMillis to durationBetweenEvictionRuns + Fix field label in BaseObjectPoolConfig toString() builder: From maxWaitMillis to maxWaitDuration + Fix field label in NoSuchElementException message for GenericObjectPool.borrowObject(Duration): From borrowMaxWaitMillis to borrowMaxWaitDuration + Reimplement DefaultPooledObject.getIdleDuration() using Duration computation + Reimplement BaseGenericObjectPool.maxBorrowWait as a Duration instead of a long + Minors Changes #89 * Changes: + Bump checkstyle from 8.45 to 8.45.1 #93 + Bump spotbugs from 4.2.3 to 4.3.0 and ignore new medium warnings EI_EXPOSE_REP and EI_EXPOSE_REP2 - Update to 2.11.0 * New features: + Track timestamps with Instants instead of longs. There is currently no increased precision on Java 8, but starting with Java 9, the JRE SystemClock precision is increased usually down to microseconds, or tenth of microseconds, depending on the OS, Hardware, and JVM implementation. Add and use: ° DefaultPooledObject.getCreateInstant() ° DefaultPooledObject.getLastUsedInstant() ° PooledObject.getCreateInstant() ° PooledObject.getLastBorrowInstant() ° PooledObject.getLastReturnInstant() ° PooledObject.getLastUsedInstant() ° TrackedUse#getLastUsedInstant() + Add BaseObjectPoolConfig.setEvictorShutdownTimeoutDuration(Duration), deprecate setEvictorShutdownTimeoutMillis(Duration) + Add BaseGenericObjectPool.{get|set}MaxWaitDuration(Duration) and deprecate {get|set}MaxWaitMillis(long) + Add BaseObjectPoolConfig.{get|set}MaxWaitDuration(Duration) and deprecate {get|set}MaxWaitMillis(long) + Add and use Duration APIs instead of ints or longs. ° Add and use Duration APIs in BaseGenericObjectPool: getDurationBetweenEvictionRuns(), getEvictorShutdownTimeoutDuration(), getMinEvictableIdleDuration(), getSoftMinEvictableIdleDuration(), setMaxWait(Duration), setMinEvictableIdle(Duration), setSoftMinEvictableIdle(Duration) ° Add and use Duration APIs in BaseObjectPoolConfig: getDurationBetweenEvictionRuns(), getEvictorShutdownTimeoutDuration(), getMinEvictableIdleDuration(), getSoftMinEvictableIdleDuration() ° Add and use Duration APIs in EvictionConfig: getIdleEvictDuration(), getIdleSoftEvictDuration() ° Add and use Duration APIs in PooledObject: getIdleDuration(), getActiveDuration() ° No need to initialize instance variables to their default values ° Update Javadocs. ° Update toString() implementations with duration labels + POOL-396: Handle validation exceptions during eviction. #85 + POOL-395: Improve exception thrown in GenericObjectPool .borrowObject when pool is exhausted. Added BaseGenericObjectPool.setMessagesStatistics(boolean) + Add and use AbandonedConfig.copy(AbandonedConfig) to fix CPD code duplication issues in GenericKeyedObjectPool and GenericObjectPool + Pull up AbandonedConfig and related methods from GenericKeyedObjectPool and GenericObjectPool to BaseGenericObjectPool (fix for CPD issues). ° BaseGenericObjectPool.getLogAbandoned() ° BaseGenericObjectPool.getRemoveAbandonedOnBorrow() ° BaseGenericObjectPool.getRemoveAbandonedOnMaintenance() ° BaseGenericObjectPool.getRemoveAbandonedTimeout() ° BaseGenericObjectPool.getRemoveAbandonedTimeoutDuration() ° BaseGenericObjectPool.isAbandonedConfig() ° BaseGenericObjectPool.setAbandonedConfig(AbandonedConfig) * Fixed Bugs: + Fix "[WARNING] Old version of checkstyle detected. Consider updating to >= v8.30." Update Checktyle to 8.44 + Make Duration setters use their respective default values when null + Call swallowException(Exception) instead of printing exceptions to the console in GenericKeyedObjectPool .removeAbandoned(AbandonedConfig) and GenericObjectPool .removeAbandoned(AbandonedConfig) + Fix Javadoc link reference #91 + No need to initialize to default values. #90 + Bump org.ow2.asm:asm-util from 9.1 to 9.2 + Bump com.github.spotbugs:spotbugs from 4.2.3 to 4.3.0 + Bump checkstyle from 8.44 to 8.45 #92 - Update to 2.10.0 * New features: + Add and use java.time.Duration APIs timeouts instead of using ints for seconds. + Implement AbandonedConfig for GenericKeyedObjectPool #67 * Fixed Bugs: + Simplify Assertions in tests #77 + Replace C-style array declaration with Java style #80 + Use Objects.equals(); Use Anonymous type; Use method reference instead Lambda; Replace Loop with Collection.removeIf(). #81 + Use diamond operator. #82 + Code clean ups. #83 * Changes: + Bump spotbugs-maven-plugin from 4.0.4 to 4.2.1 #48, #53, #59, [#62] + Bump actions/setup-java from v1.4.2 to v2, #47 + Bump junit from 4.13 to 4.13.1 #50 + Bump biz.aQute.bndlib from 5.1.2 to 5.3.0, #51, #66 + POOL-389: Migrate to JUnit 5 #57 + POOL-389: Minor Improvements #58, #60 + Bump actions/checkout from v2.3.3 to v2.3.4 #54 + Bump maven-pmd-plugin from 3.13.0 to 3.14.0 #55 + Update commons.japicmp.version 0.14.3 -> 0.15.3 + Bump actions/cache from v2 to v2.1.6 #65, #75, #84 + Bump maven-checkstyle-plugin from 3.1.1 to 3.1.2 #61 + Bump asm-util from 9.0 to 9.1 #64 + Bump spotbugs from 4.2.1 to 4.2.3 #68, #73, #74 + Bump junit-bom from 5.7.1 to 5.8.0-M1 #76 + Bump maven-bundle-plugin from 5.1.1 to 5.1.2 #70 + Bump animal-sniffer-maven-plugin from 1.19 to 1.20 - Update to 2.9.0 * Changes: + POOL-387: Object factory destroy method should carry information on activation context + Update spotbugs from 4.0.6 to 4.1.3, #37, #41, #46 + Update actions/checkout from v2.3.1 to v2.3.3 #56, #45 + Update actions/setup-java from v1.4.0 to v1.4.2 #42 + Update optional asm-util from 8.0.1 to 9.0 #44 - Update to 2.8.1 * New features: + POOL-385: Added Automatic-Module-Name to support JPMS #31 * Fixed Bugs: + POOL-386: Refactored EvictionTimer usage tracking to fix POOL-386 and handle abandoned pools. #32 + [Javadoc] Add missing @throws comment in PoolUtils. #27 * Changes: + POOL-384: Update optional library org.ow2.asm:asm-util from 7.2 to 8.0.1 + Update site reports from org.apache.bcel:bcel 6.4.1 to 6.5.0 + Update site reports from maven-pmd-plugin 3.12.0 to 3.13.0 + Update build from biz.aQute.bnd:biz.aQute.bndlib 5.1.0 -> 5.1.2 + Update actions/checkout from v1 to v2.3.1 #33 + Update commons-parent from 50 to 51 #36 + Update Checkstyle plugin from 3.0.0 to 3.1.1 + Update JApiCmp from 0.14.1 to 0.14.3 + Update animal-sniffer-maven-plugin from 1.16 to 1.19 - Update to 2.8.0 * New features: + POOL-378: Deprecate PoolUtils.prefill(ObjectPool, int) in favor of ObjectPool.addObjects(int) + POOL-379: Deprecate PoolUtils.prefill(KeyedObjectPool, K, int) in favor of KeyedObjectPool.addObjects(K, int) + POOL-380: Deprecate PoolUtils.prefill(KeyedObjectPool, Collection, int) in favor of KeyedObjectPool .addObjects(Collection, int) * Fixed Bugs: + POOL-374: org.apache.commons.pool2.impl.GenericKeyedObjectPool .returnObject(K, T) should throw IllegalStateException instead of NullPointerException when a key is not found in the pool map + POOL-376: Fixed regression from original fix for POOL-356 which could result in NPE when destroying objects + POOL-326: Eliminated NPE / ISE exceptions due to keyed pools being prematurely removed + Close BufferedOutputStream in test before calling toString on underlying BufferedOutputStream #26 + [Javadoc] Add missing @throws comment in SoftReferenceObjectPool. #28 * Changes: + POOL-375: Update optional library cglib from 3.2.12 to 3.3.0 + Update site build from Apache Commons BCEL 6.3.1 to 6.4.1 + POOL-377: Update optional library org.ow2.asm:asm-util from 7.1 to 7.2 - Update to 2.7.0 * New features: + POOL-370: Add org.apache.commons.pool2.PooledObject [#]getBorrowedCount() + POOL-371: Add org.apache.commons.pool2.PooledObject [#]setRequireFullStackTrace(boolean) * Fixed Bugs: + POOL-361: Move validation for newly created objects into create(). Fixes #23 * Changes: + POOL-364: Update from Java 7 to Java 8 + POOL-365: Update ASM from 7.0 to 7.1 + POOL-366: Update optional library cglib from 3.2.10 to 3.2.12 + POOL-367: Fix typo in package private method name stopEvitor() -> stopEvictor() #22 - Update to 2.6.2 * Fixed Bugs: + POLL-362: Always null out org.apache.commons.pool2.impl .BaseGenericObjectPool.evictionIterator to match org.apache.commons.pool2.impl.BaseGenericObjectPool.evictor + POLL-363: Evictor Thread prevents Spring Context shutdown in standalone app + POLL-348: The commons-pool-evictor-thread should run as a Deamon - Update to 2.6.1 * Fixed Bugs: + POOL-340: Correct validateObject with concurrent borrowObject + POOL-356: Fix deadlock on massive concurrent requests + POOL-347: Method borrowObject waits for maxWaitMillis over in pool full + POOL-359: NullPointerException closing multiple GenericObjectPools + POOL-326: Threading issue, NullPointerException and IllegalStateException in GenericKeyedObjectPool + POOL-352: CallStackUtils mishandles security manager check (partial fix.) * Changes: + POOL-345: Update optional library cglib from 3.2.6 to 3.2.9 + POOL-346: Move common configuration setter to BaseGenericObjectPool #9 + POOL-349: Update optional library asm-util from 6.2 to 7.0 + POOL-360: Update optional library cglib from 3.2.9 to 3.2.10 - Update to 2.6.0 * Fixed Bugs: + POOL-337: Ensure cancelled eviction tasks are removed from scheduler + POOL-338: GenericObjectPool constructor may throw an exception under OSGi + POOL-324: org.apache.commons.pool2.impl.GenericObjectPool .getFactoryType() throws java.lang.ClassCastException + POOL-344: Delete repeated call startEvictor * Changes: + POOL-336: GenericObjectPool's borrowObject lock if create() fails with Error + POOL-339: Update optional library cglib from 3.2.5 to 3.2.6 + POOL-341: Update optional library asm-util from 6.0 to 6.1.1 + POOL-342: Update optional library asm-util from 6.1.1 to 6.2 - Update to 2.5.0 * New features: + POOL-332: ObjectPool and KeyedObject pool should extend Closeable. + POOL-335: Make abandoned logging stack trace requirements configurable. This also reverts the default behavior introduced by POOL-320. * Changes: + POOL-331: Update from Java 6 to 7. + POOL-333: Update optional dependency asm-util from 5.2 to 6.0 + POOL-334: org.apache.commons.pool2.impl.ThrowableCallStack .Snapshot is missing serialVersionUID - Update to 2.4.3 * New features: + POOL-320: Use more efficient stack walking mechanisms for usage tracking when possible. * Fixed Bugs: + POOL-328: Documentation with repeated words (sources, tests, and examples) + POOL-317: Correction of default value of softMinEvictableIdleTimeMillis in BaseObjectPoolConfig + POOL-309: Fix misspellings from "destory" to "destroy" + POOL-306: Ensure BaseGenericObjectPool .IdentityWrapper#equals() follows the expected contract for equals() + POOL-303: Ensure that threads do not block indefinitely if more than maxTotal threads try to borrow an object at the same time and the factory fails to create any objects. + POOL-310: Ensure that threads using GKOP do not block indefinitely if more than maxTotal threads try to borrow objects with different keys at the same time and the factory destroys objects on return + Ensure that any class name used for evictionPolicyClassName represents a class that implements EvictionPolicy. + POOL-315: Add a configurable delay (default 10 seconds) to wait when shutting down an Evictor to allow the associated thread time to complete and current evictions and to terminate + Ensure that a call to GKOP preparePool() takes account of other threads that might create objects concurrently, particularly the Evictor. * Changes: + POOL-280: Small refactoring of borrowObject() to reduce code duplication + POOL-307: Replace inefficient use of keySet with entrySet in GKOP + POOL-322: Update optional cglib library from 3.1 to 3.2.5. + POOL-323: Update optional OW2 ASM from 5.0.4 to 5.2. ++++ arp-scan: - Add arp-scan-EACCES-as-ENOENT.patch: treat EACCES like ENOENT when stat'ing the MAC/vendor mapping file (ieee-oui.txt / mac-vendor.txt) in the current directory, so arp-scan falls through to the system datadir instead of failing with "Permission denied" (boo#1210703, gh#royhills/arp-scan#120) - Drop obsolete RPM group ++++ blog: - Update to version 2.42 Fix possible memory leaks, eliminate type punning, and resolve I/O blocking This update implements a series of systemic improvements to stability, security, and performance: 1. Memory Safety & Leak Resolution: - Implemented lcons_shutdown destructor to automatically purge the console list and close FDs on exit. - Fixed password buffer leak by using in closeIO, correctly matching the mmap allocation in shm_malloc. - Added cleanup for pwprompt in closeIO. 2. Elimination of Dangerous Type Punning: - Replaced the unreliable &cons->node pattern with a type-safe list_t lcons sentinel across the codebase. - Added __attribute__((may_alias)) to list_t in listing.h to prevent compiler strict aliasing optimizations from corrupting list traversals. 3. I/O Responsiveness & Stability: - Removed tcdrain() from the high-frequency epoll_console_in path to eliminate daemon freezes during heavy output. - Updated consinitIO to ensure CON_SERIAL devices remain in O_NONBLOCK mode, preventing freezes on slow serial lines. - Extended the tcdrain skip-list in closeIO to include CON_SERIAL, ensuring a hang-free shutdown. 4. Architectural Improvements: - Redesigned shm_malloc to use a tiered mapping strategy: prefers file-backed shared memory in /dev/shm with a graceful fallback to MAP_ANONYMOUS. - Optimized listing.h with always_inline attributes, __builtin_prefetch for cache efficiency, and list poisoning for safer debugging. ++++ containerd: - update to 1.7.33 (bsc#1262266, CVE-2026-35469, bsc#1268355, CVE-2026-46680, bsc#1268430, CVE-2026-53488, bsc#1268441, CVE-2026-47262): * https://github.com/containerd/containerd/releases/tag/v1.7.33 * https://github.com/containerd/containerd/releases/tag/v1.7.32 * https://github.com/containerd/containerd/releases/tag/v1.7.31 * https://github.com/containerd/containerd/releases/tag/v1.7.30 - drop 0003-CVE-2026-34986-Bump-go-jose-to-v3.0.5.patch (upstream) ++++ coturn: - Update to version 4.14.0 New * No more dependency on prometheus-client-c * HTTPS support for prometheus client (optional) * TLS support for redis - now compatible with managed redis (optional). * Rate limiting "401 Unauthorized" responses - reduces reflection attacks off the coturn server. This is an experimental feature - not fully tested on production scale deployment and massive DDoS attacks. New prometheus counters should help shed some light on real life behavior and performance. The feature is off by default. What's Changed * validate hmackey length in sqlite_get_user_key before hex decode. * Add out-of-tree patch to restore deprecated OpenSSL 1.1.1. * Add optional TLS transport for Redis connections. * Fix relay threads override. * Flush prometheus hot-path counters once per second to kill lock contention. * fix signed-char index out-of-bounds read in base64_decode. * Build Prometheus exporter from vendored local sources. * Prom https. * Fix realm quota data race and warnings. * Add per-source rate-limiting of UDP 401 Unauthorized responses ++++ glibc-cross-aarch64-src: - resolv-sprintrrf-unkown-types.patch: resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435, bsc#1263656, BZ #34033) - resolv-sprintrrf-inet-ntop-check.patch: resolv: Check for inet_ntop failure in ns_sprintrrf - resolv-sprintrrf-buffer-overreads.patch: resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238, bsc#1263658, BZ #34069) ++++ glibc-cross-ppc64le-src: - resolv-sprintrrf-unkown-types.patch: resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435, bsc#1263656, BZ #34033) - resolv-sprintrrf-inet-ntop-check.patch: resolv: Check for inet_ntop failure in ns_sprintrrf - resolv-sprintrrf-buffer-overreads.patch: resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238, bsc#1263658, BZ #34069) ++++ glibc-cross-riscv64-src: - resolv-sprintrrf-unkown-types.patch: resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435, bsc#1263656, BZ #34033) - resolv-sprintrrf-inet-ntop-check.patch: resolv: Check for inet_ntop failure in ns_sprintrrf - resolv-sprintrrf-buffer-overreads.patch: resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238, bsc#1263658, BZ #34069) ++++ glibc-cross-s390x-src: - resolv-sprintrrf-unkown-types.patch: resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435, bsc#1263656, BZ #34033) - resolv-sprintrrf-inet-ntop-check.patch: resolv: Check for inet_ntop failure in ns_sprintrrf - resolv-sprintrrf-buffer-overreads.patch: resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238, bsc#1263658, BZ #34069) ++++ glibc: - resolv-sprintrrf-unkown-types.patch: resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435, bsc#1263656, BZ #34033) - resolv-sprintrrf-inet-ntop-check.patch: resolv: Check for inet_ntop failure in ns_sprintrrf - resolv-sprintrrf-buffer-overreads.patch: resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238, bsc#1263658, BZ #34069) ++++ glibc-utils-src: - resolv-sprintrrf-unkown-types.patch: resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435, bsc#1263656, BZ #34033) - resolv-sprintrrf-inet-ntop-check.patch: resolv: Check for inet_ntop failure in ns_sprintrrf - resolv-sprintrrf-buffer-overreads.patch: resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238, bsc#1263658, BZ #34069) ++++ libssh2_org: - Security Fixes: * CVE-2026-55200: out-of-Bounds write via Unchecked packet_length in transport.c (bsc#1268531) * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530) * Add patches: libssh2_org-CVE-2026-55200.patch libssh2_org-CVE-2026-55199.patch ++++ xar: - Switch to the maintained Apple xar lineage (build 503, versioned 1.8.0.0.503): the mackyle 1.6.1 fork this package tracked has been dead since 2012, and Debian, Fedora and Gentoo all moved to Apple's xar (apple-oss-distributions/xar). This resolves the long-standing NULL-pointer dereferences in xar_get_path() and xar_unserialize() when parsing malformed archives: * CVE-2017-11124 (boo#1047875) * CVE-2017-11125 (boo#1047874) * CVE-2018-17093 (boo#1108595) * CVE-2018-17094 (boo#1108596) - Drop the obsolete mackyle-fork patches: ext2.patch, openssl-checks.patch, xar-fix-prototype.patch - Add the Gentoo-tracked Linux build patch set for the Apple lineage: xar-1.6.1-ext2.patch, xar-1.8-safe_dirname.patch, xar-1.8-arm-ppc.patch, xar-1.8-openssl-1.1.patch, xar-1.8.0.0.452-linux.patch, xar-1.8.0.0.487-non-darwin.patch, xar-1.8.0.0.487-variable-sized-object.patch, xar-1.8.0.0.498-impl-decls.patch - Add xar-1.8.0.0.503-linux-F_GETPATH.patch: resolve an fd's path via /proc/self/fd on Linux, where the macOS-only F_GETPATH fcntl used by the new xar_fdopen_digest_verify() is unavailable ++++ openQA: - Update to version 5.1782133597.39cd80e0: * refactor: Calculate module category headings in frontend * chore(deps): Dependency cron 2026-06-20 * test: Make parallel execution of the fullstack test more reliable * ci: disable Mergify interactive queue controls in PR comments * feat(worker): enable direct execution with podman * fix(worker): add --init and --rm flags for containerized engine * feat(worker): support containerized os-autoinst worker engine * test: refactor archive download tests for maintainability * feat: implement category-specific ZIP downloads for jobs * chore(deps): Dependency cron 2026-06-19 ++++ openQA: - Update to version 5.1782133597.39cd80e0: * refactor: Calculate module category headings in frontend * chore(deps): Dependency cron 2026-06-20 * test: Make parallel execution of the fullstack test more reliable * ci: disable Mergify interactive queue controls in PR comments * feat(worker): enable direct execution with podman * fix(worker): add --init and --rm flags for containerized engine * feat(worker): support containerized os-autoinst worker engine * test: refactor archive download tests for maintainability * feat: implement category-specific ZIP downloads for jobs * chore(deps): Dependency cron 2026-06-19 ++++ openQA: - Update to version 5.1782133597.39cd80e0: * refactor: Calculate module category headings in frontend * chore(deps): Dependency cron 2026-06-20 * test: Make parallel execution of the fullstack test more reliable * ci: disable Mergify interactive queue controls in PR comments * feat(worker): enable direct execution with podman * fix(worker): add --init and --rm flags for containerized engine * feat(worker): support containerized os-autoinst worker engine * test: refactor archive download tests for maintainability * feat: implement category-specific ZIP downloads for jobs * chore(deps): Dependency cron 2026-06-19 ++++ os-autoinst: - Update to version 5.1782140090.fe34efb: * fix: exclude virt-firmware on older Leap ppc64 * style: enforce signatures in anonymous subroutines * fix: stop deepening when repo is no longer shallow * ci: disable Mergify interactive queue controls in PR comments * style(perlcritic): Add Modules::ProhibitConditionalUseStatements * refactor: improve t/01-test_needle.t structure and style ++++ os-autoinst: - Update to version 5.1782140090.fe34efb: * fix: exclude virt-firmware on older Leap ppc64 * style: enforce signatures in anonymous subroutines * fix: stop deepening when repo is no longer shallow * ci: disable Mergify interactive queue controls in PR comments * style(perlcritic): Add Modules::ProhibitConditionalUseStatements * refactor: improve t/01-test_needle.t structure and style ++++ archmage: - Add archmage-fix-bytes-regex.patch: fix "archmage -c pdf" crashing with "cannot use a string pattern on a bytes-like object" by using bytes regex patterns on the bytes content (boo#1178542) - Register the archmage.1 man page as an update-alternatives slave so the shipped /usr/share/man/man1/archmage.1.gz symlink is managed (boo#1202977) ++++ python-biopython: - add CVE-2025-68463.patch (bsc#1255465, CVE-2025-68463) ++++ python-py7zr: - CVE-2026-23879: crafted malicious symbolic link chains in an archive can lead to an arbitrary file write (bsc#1268669) * added CVE-2026-23879.patch - CVE-2026-55195: unchecked extraction size can cause a denial of service (bsc#1268665) * added CVE-2026-55195.patch - CVE-2026-55206: crafted .7z archive with a large numstreams value can cause a denial of service (bsc#1268666) * added CVE-2026-55206.patch ++++ python-zeroconf: - CVE-2026-47180: zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service (bsc#1268341) - CVE-2026-47183: zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion (bsc#1268342) - CVE-2026-47184: zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood (bsc#1268343) - CVE-2026-48045: python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood (bsc#1268388) - CVE-2026-48487: python-zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet (bsc#1268235) - Add patches: * 0001-feat-implement-heapq-for-tracking-cache-expire-times.patch * 0001-fix-ensure-cache-does-not-return-stale-created-and-t.patch * CVE-2026-47180.patch * CVE-2026-47183.patch * CVE-2026-47184.patch * CVE-2026-48045.patch * CVE-2026-48487.patch ++++ transmission: - Add transmission-CVE-2026-38978.patch: add clickjack safeguards when serving http responses (bsc#1267404 CVE-2026-38978). ++++ tar: - Fix CVE-2026-5704.patch causing errors when extracting certain archives generated by rpm2archive which contain hard links - Refresh fix-dereference.patch ------------------------------------------------------------------ ------------------ 2026-6-21 - Jun 21 2026 ------------------- ------------------------------------------------------------------ ++++ bitcoin: - Reference the tracking bugs for CVEs already fixed in current bitcoin (the affected versions all predate the shipped release): * CVE-2018-20587 (boo#1125092) * CVE-2019-15947 (boo#1149711) * CVE-2020-14198 (boo#1181786) * CVE-2021-3195 (boo#1181784) * CVE-2023-37192 (boo#1217678) * CVE-2024-35202 (boo#1231507) ++++ hamlib: - Update to 4.7.2: * Fix IC-7600/IC-7610 clock commands * Icom: Add CWR to modes eligible for DSP filtering * Kenwood: New model Hamgeek uSGX * Various fixes for Skywatcher, DX-SR8, FT-710, FTX-1, IC-705, X6100 * rigctld: Fix send_raw stack out-of-bounds write and uninitialized memory CVE-2026-54634 (boo#1268628) * rigctld: Fix stack/heap overflow primitive in read_string_generic + auth bypass in rigctld + weak password handling (boo#1268629) ++++ mbedtls: - Update to 3.6.6 (LTS maintenance update from 3.6.1); security fixes accumulated across the 3.6.2-3.6.6 releases: * CVE-2024-49195 (boo#1231708): buffer underrun in pkwrite when writing an opaque key pair * CVE-2025-27809 (boo#1240051): certificate verification accepted arbitrary hostnames * CVE-2025-27810 (boo#1240052): possible authentication bypass on failed memory allocation / hardware errors * CVE-2025-47917 (boo#1246783): misleading memory management in mbedtls_x509_string_to_names() * CVE-2025-48965 (boo#1246784): NULL pointer dereference after mbedtls_asn1_store_named_data() * CVE-2025-49087 (boo#1246973): timing side channel in PKCS#7 padding removal * CVE-2025-49600 (boo#1245808): unchecked return values in LMS verification allow signature bypass via fault injection * CVE-2025-49601 (boo#1245809): out-of-bounds read in mbedtls_lms_import_public_key() * CVE-2025-52496 (boo#1245810): race in AES-NI support detection can lead to AES key extraction or GCM forgery * CVE-2025-52497 (boo#1245811): one-byte heap underflow when parsing PEM-encrypted material * CVE-2025-54764 (boo#1252341): timing attacks in RSA operations * CVE-2025-59438 (boo#1252454): padding-oracle attack via timing of cipher error reporting * CVE-2026-25833: PSA RNG state duplicated across fork() * CVE-2026-25834: TLS 1.3 HelloRetryRequest man-in-the-middle session-resumption downgrade * CVE-2026-25835: RNG state duplicated when application/VM state is cloned ++++ mbedtls-2: - Reference the tracking bugs for the already-listed CVE fixes: * CVE-2024-45157 (boo#1230310) * CVE-2025-27809 (boo#1240051) * CVE-2025-27810 (boo#1240052) ++++ openbabel: - Reference the tracking bugs for the security issues already fixed in the 3.2.0 update: * CVE-2022-* OSS-Fuzz/TALOS batch (boo#1217676) * CVE-2026-2704 (boo#1258501), CVE-2026-2705 (boo#1258507), CVE-2026-3408 (boo#1259041) ++++ lrzip: - Update to version 0.660: * Do not clean up thread structures in decompression failure conditions, fixing a use-after-free in lzma_decompress_buf() and a NULL pointer dereference in ucompthread() on corrupt/malicious archives (CVE-2025-15570, boo#1258016; CVE-2025-15571, boo#1258023) * Handle -L given without a parameter, fixing a NULL pointer dereference (CVE-2025-9396, boo#1248598) * Add write bounds checking in libzpaq and sanity checks for maliciously encoded headers and oversized allocations * Various STDIO, portability and build fixes (OpenBSD support, non-x86 zpaq, autoconf warnings); drop Doxygen doc build - Switch Source to the upstream GitHub release tarball (0.660 is not published on ck.kolivas.org) and run autoreconf at build time - Drop fixasmstack.patch (merged upstream) ++++ ofono: - Reference the tracking bugs for the SMS/STK/USSD decoder security fixes applied upstream across the 2.14-2.17 updates: * SMS decoder stack buffer overflows: CVE-2023-2794 (boo#1218292), CVE-2023-4232 (boo#1218293), CVE-2023-4233 (boo#1218294), CVE-2023-4234 (boo#1218295), CVE-2023-4235 (boo#1218296) * SMS PDU / message-list parsing overflows and OOB read: CVE-2024-7537 (boo#1228903), CVE-2024-7547 (boo#1228917) * AT-command / USSD response parsing overflows: CVE-2024-7538 (boo#1228904), CVE-2024-7539 (boo#1228905) * Uninitialized-memory information disclosure: CVE-2024-7540 (boo#1228906), CVE-2024-7541 (boo#1228907), CVE-2024-7542 (boo#1228908) * STK command PDU heap overflows: CVE-2024-7543 (boo#1228910), CVE-2024-7544 (boo#1228913), CVE-2024-7545 (boo#1228914), CVE-2024-7546 (boo#1228916) ++++ trivy: - update vendored containerd to 2.3.2: + CVE-2026-50195 (bsc#1268399) + CVE-2026-53488 (bsc#1268400) + CVE-2026-53492 (bsc#1268403) + CVE-2026-53489 (bsc#1268404) + CVE-2026-47262 (bsc#1268440) ++++ trivy: - update vendored containerd to 2.3.2: + CVE-2026-50195 (bsc#1268399) + CVE-2026-53488 (bsc#1268400) + CVE-2026-53492 (bsc#1268403) + CVE-2026-53489 (bsc#1268404) + CVE-2026-47262 (bsc#1268440) ------------------------------------------------------------------ ------------------ 2026-6-20 - Jun 20 2026 ------------------- ------------------------------------------------------------------ ++++ helm: - update to 3.21.2: * chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) * fixes b52e276 (Matheus Pimenta) * chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) ------------------------------------------------------------------ ------------------ 2026-6-19 - Jun 19 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - added patches CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder [bsc#1268101] * ImageMagick-CVE-2026-45664.patch ++++ apache-commons-configuration2: - Upgrade to version 2.15.1 * Fixed Bugs + CONFIGURATION-856: The artifact commons-io:commons-io is a normal dependency + Avoid NPE when combined location strategy sub strategies is immutable list (#639) * Changes + Bump org.apache.commons:commons-parent from 99 to 100 ++++ apache-commons-daemon: - Upgrade to 1.6.1 * Bug Fixes: + Remove -nouses directive from maven-bundle-plugin. OSGi package imports now state 'uses' definitions for package imports, this doesn't affect JPMS (from org.apache.commons:commons-parent:80) + Document --enable-preview + Fix first appearance of --enable-native-access + Procrun. Fix redirection issues on some OS versions by using recommended method to redirect stdout and stderr. Fixes DAEMON-398. + Procrun. Fix updating of startup mode to 'Automatic (delayed)' being incorrectly processed as an update to 'Manual'. Fixes DAEMON-439. + Procrun. Fix timeout handling #238. Fixes DAEMON-468. + Procrun. Replace RTF version of license header with plain text version of full license in about box for monitor application. Fixes DAEMON-472. + Procrun. Service should be marked as stopped if the service worker crashes. Fixes DAEMON-475. + jsvc. Fix compilation warnings. + jsvc. Fix a regression in 1.5.1 that exposed long standing bugs around the locking and unlocking of pid files. Also fix the locking/unlocking bugs. + Detaches from console when the service stops #307. Fixes DAEMON-477. + jsvc. Correct a packaging error in the 1.6.0 native source tarball for *nix systems. Thanks to Michael Osipov. * New Features: + Add support for --enable-native-access Java startup option in jsvc. Fixes DAEMON-471. + Add tests for prunsrv on Windows #260. + Add Java API compatibility report to the site (JApiCmp). + Procun. Build binaries for Windows using the static hybrid CRT strategy by default. + jsvc. Use FreeBSD's setproctitle(3) to pass -procname similar to daemon(8). + procrun. Add ARM64 support for Windows binaries. Fixes DAEMON-462. * Update dependencies: + Bump org.apache.commons:commons-parent from 78 to 91 #253, [#255], #287. + Update to use new ASF logo + Bump org.apache.commons:commons-parent from 93 to 99. + jsvc. Consistently use strerror(3) for log output. ++++ blog: - Update to version 2.41 * The __attribute__((noreturn)) for error() in libconsole.h added * The variable err with 0 initialized in thread_poll() * The variable cp.parity with {0} initialized in readpw() * feat(blogd): handle pending systemd password requests on coldstart * Initialize console pointer list as well * Check peer credentials before reading command * Make isinteger() string check usable for all architectures * Add some comments about warnings and translation for S390 ++++ dracut: - Update to version 059+suse.722.gdd9d67ff5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ++++ dracut: - Update to version 059+suse.722.gdd9d67ff5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ++++ libnfs: - Add libnfs-CVE-2026-53689.patch: ZDR: check the string size for sanity (bsc#1268135 CVE-2026-53689). ++++ systemd: - Add 0004-mount-make-sys-kernel-debug.mount-opt-in-rather-than.patch (jsc#PED-8812) ++++ systemd: - Add 0004-mount-make-sys-kernel-debug.mount-opt-in-rather-than.patch (jsc#PED-8812) Only done for SLES 16.1 for now. ++++ openQA: - Update to version 5.1781832185.5ddf5343: * fix: fix user namespace mapping errors in podman * chore(mergify): Update the number of required checks * fix: use webui cache for download all archives * chore(deps): Dependency cron 2026-06-18 * refactor: Extract changing prio and computing sign * fix: Fix typos in `t/api/04-jobs.t` and `t/config.t` * feat: Throttle jobs not using Git-URL as `CASEDIR` * ci: Change repo paths for SLE-15-SP7 in consistency with os-autoinst * fix: Avoid unresolvable openQA-devel-test package for SLE-SP7 * feat: improve detection of unexpanded variables in clone-job * feat: support expanding variables in openqa-clone-job ++++ openQA: - Update to version 5.1781832185.5ddf5343: * fix: fix user namespace mapping errors in podman * chore(mergify): Update the number of required checks * fix: use webui cache for download all archives * chore(deps): Dependency cron 2026-06-18 * refactor: Extract changing prio and computing sign * fix: Fix typos in `t/api/04-jobs.t` and `t/config.t` * feat: Throttle jobs not using Git-URL as `CASEDIR` * ci: Change repo paths for SLE-15-SP7 in consistency with os-autoinst * fix: Avoid unresolvable openQA-devel-test package for SLE-SP7 * feat: improve detection of unexpanded variables in clone-job * feat: support expanding variables in openqa-clone-job ++++ openQA: - Update to version 5.1781832185.5ddf5343: * fix: fix user namespace mapping errors in podman * chore(mergify): Update the number of required checks * fix: use webui cache for download all archives * chore(deps): Dependency cron 2026-06-18 * refactor: Extract changing prio and computing sign * fix: Fix typos in `t/api/04-jobs.t` and `t/config.t` * feat: Throttle jobs not using Git-URL as `CASEDIR` * ci: Change repo paths for SLE-15-SP7 in consistency with os-autoinst * fix: Avoid unresolvable openQA-devel-test package for SLE-SP7 * feat: improve detection of unexpanded variables in clone-job * feat: support expanding variables in openqa-clone-job ++++ pacemaker: - libcrmcommon: Add additional checks to pcmk__remote_message_xml. (CVE-2026-10649, bsc#1268381, rh#2462817, gh#ClusterLabs/pacemaker#4133) * bsc#1268381-0006-Med-libcrmcommon-Add-additional-checks-to-pcmk__remo.patch - libcrmcommon: Fix an integer overflow in pcmk__remote_send_xml. (CVE-2026-10649, bsc#1268381, rh#2462817, gh#ClusterLabs/pacemaker#4133) * bsc#1268381-0004-High-libcrmcommon-Fix-an-integer-overflow-in-pcmk__r.patch - libcrmcommon: Limit the max size of a remote message. (CVE-2026-10649, bsc#1268381, rh#2462817, gh#ClusterLabs/pacemaker#4133) * bsc#1268381-0003-High-libcrmcommon-Limit-the-max-size-of-a-remote-mes.patch - libcrmcommon: Fix integer overflow in remote message code. (CVE-2026-10649, bsc#1268381, rh#2462817, gh#ClusterLabs/pacemaker#4133) * bsc#1268381-0002-High-libcrmcommon-Fix-integer-overflow-in-remote-mes.patch - libcrmcommon: Add sanity checks to localized_remote_header. (CVE-2026-10649, bsc#1268381, rh#2462817, gh#ClusterLabs/pacemaker#4133) * bsc#1268381-0001-Med-libcrmcommon-Add-sanity-checks-to-localized_remo.patch ++++ perl-Config-IniFiles: - added patches CVE-2026-11527: versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle [bsc#1268236] * perl-Config-IniFiles-CVE-2026-11527.patch ++++ perl-DBI: - added patches CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer [bsc#1267957] * perl-DBI-CVE-2026-9698.patch ++++ python-python-multipart: - CVE-2026-53537: multipart/form-data with extended parameters can lead to file or parameter smuggling (bsc#1268506) * added CVE-2026-53537.patch - CVE-2026-53538: urlencoded requests containing semicolons can lead to form field smuggling (bsc#1268496) * added CVE-2026-53538-CVE-2026-53539.patch - CVE-2026-53539: small crafted body can cause a denial of service (bsc#1268500) * added CVE-2026-53538-CVE-2026-53539.patch - CVE-2026-53540: crafted request buffers can lead to degrading availability (bsc#1268488) * added CVE-2026-53540.patch ++++ systemd-mini: - Add 0004-mount-make-sys-kernel-debug.mount-opt-in-rather-than.patch (jsc#PED-8812) ++++ systemd-mini: - Add 0004-mount-make-sys-kernel-debug.mount-opt-in-rather-than.patch (jsc#PED-8812) Only done for SLES 16.1 for now. ++++ trento-web: - Release 3.1.2 [#]# What's Changed * Fix loading checks execution detail when catalog is still loading (#4377) @balanza * Enforce using erlang26 on SLES15 (#4411) @balanza * Health summary - Application instances health (#4382) @balanza * Fix version 3.1.0 changelog typos (#4415) @balanza * *Full Changelog**: https://github.com/trento-project/web/compare/3.1.1...3.1.2 ++++ trivy: - Update to version 0.71.2: * release: v0.71.2 [release/v0.71] (#10871) * fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870) * chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867) ++++ trivy: - Update to version 0.71.2: * release: v0.71.2 [release/v0.71] (#10871) * fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870) * chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867) ++++ warewulf4: - updated go-jose to fix CVE-2026-34986 (bsc#1262810) - chi is fixed in the upstream project ++++ warewulf4: - updated go-jose to fix CVE-2026-34986 (bsc#1262810) - chi is fixed in the upstream project ++++ zstd-jni: - Update to v1.5.7.11 * no structured changelog provided by upstream ------------------------------------------------------------------ ------------------ 2026-6-18 - Jun 18 2026 ------------------- ------------------------------------------------------------------ ++++ containerd: - Add patch for CVE-2026-34986 (bsc#1262948) * 0003-CVE-2026-34986-Bump-go-jose-to-v3.0.5.patch - Add patch for CVE-2026-39821 (bsc#1266640) * 0004-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch - Add patch for CVE-2026-33814 (bsc#1265794) * 0005-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch ++++ docker-stable: - fix for Privilege validation bypass during plugin Backport of (bsc#1265907, CVE-2026-33997) * 0021-CVE-2026-33997-fix-for-Privilege-validation-bypass-d.patch - fix for Authz zero length regression Backport of (bsc#1265929, CVE-2026-34040) * 0022-CVE-2026-34040-fix-for-Authz-zero-length-regression.patch - grpc: enforce strict path checking for incoming requests on the server Backport of (bsc#1260279, CVE-2026-33186) * 0023-CVE-2026-33186-grpc-enforce-strict-path-checking-for.patch - http2: prevent hanging Transport due to bad SETTINGS Backport of (bsc#1265782, CVE-2026-33814) * 0024-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch - idna: update from x/text, fix ToUnicode and all-ASCII xn-- labels Backport of (bsc#1266625, CVE-2026-39821) * 0025-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch - daemon: Decompress archives before entering container filesystem Backport of (bsc#1267827, CVE-2026-41567) * 0026-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch ++++ gimp: - Add gimp-CVE-2026-40917.patch: plug-ins: Clean up ICNS file loading (bsc#1262199, CVE-2026-40917). ++++ glab: - Update to version 1.103.0: * Features - b39a801c: feat(container-registry): add container registry repository and tag commands (Jeroen Monteban jeroen.monteban@mgb.ch) - ea9fd25a: feat(packages): add packages command group with list (Oscar Tovar otovar@gitlab.com) - 1dd20b11: feat(stack): make switch interactive (Ahmed Abdelbaset a7med3bdulbaset@gmail.com) - 7b9703ab: feat(stacked-diffs): add --no-verify to 'stack amend' command (Kev Kloss kkloss@gitlab.com) - 6e4e3284: feat(stacked-diffs): add --no-verify to 'stack save' command (Kev Kloss kkloss@gitlab.com) - 481f63fb: feat: Handle glab mr checkout failure when there are non fast-forwarding conflicts (Gabriel Mazzetto gabriel@gitlab.com) - 84fd9f33: feat: compile arm64 windows bianry (Andrei Zubov azubov@gitlab.com) * Bug Fixes - 91eb7aad: fix(ci): set release token inline so project GITLAB_TOKEN can't shadow it (Jay McCure jmccure@gitlab.com) - 10561d78: fix(mcp): add content to structuredContent (Florian Imdahl git@ffflorian.de) - bcf700bd: fix(orbit): install dependency-free Linux build to fix glibc version errors (Dmitry Gruzd dgruzd@gitlab.com) - 0a119c02: fix(stacks): share stacks across worktrees (Ahmed Abdelbaset a7med3bdulbaset@gmail.com) - e3236d94: fix(update): give post-upgrade and skill nudges breathing room (Kai Armstrong karmstrong@gitlab.com) * Documentation - 913e5d9d: docs(api): add GLAB_DEBUG_HTTP example for debugging requests (Kai Armstrong karmstrong@gitlab.com) - 3a983d41: docs(variable): add synopsis and examples to variable commands (Brendan Lynch blynch@gitlab.com) - 98e70a25: docs: Remove manual (default false) flag annotations (Brendan Lynch blynch@gitlab.com) - 6c71e24c: docs: add troubleshooting guide for invalid_client OAuth error (Stan Hu stanhu@gmail.com) - e73a8cde: docs: move troubleshooting guide to the generated CLI docs page (Brendan Lynch blynch@gitlab.com) * Dependencies - 7779ffec: chore(deps): bump go to v1.26.4 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 39cda83f: chore(deps): update dependency @commitlint/cli to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f434057f: chore(deps): update dependency @commitlint/lint to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - c583440d: chore(deps): update module charm.land/bubbletea/v2 to v2.0.7 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a1898d01: chore(deps): update module github.com/docker/cli to v29.5.1+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - f1b74aae: chore(deps): update module github.com/docker/cli to v29.5.2+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6131acf7: chore(deps): update module github.com/docker/cli to v29.5.3+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - 9b83a7ff: chore(deps): update module github.com/docker/docker-credential-helpers to v0.9.8 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 0767cd08: chore(deps): update module github.com/mattn/go-colorable to v0.1.15 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 765b526d: chore(deps): update module github.com/mattn/go-runewidth to v0.0.24 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 756377a6: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 55a4f6b3: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 34a8e5b0: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) - e500b3f4: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.39.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bda16f22: chore(deps): update module golang.org/x/sync to v0.21.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - a27fa5a4: chore(deps): update module golang.org/x/term to v0.44.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 79575672: chore(deps): update module golang.org/x/text to v0.38.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 4c0cc23d: chore(ci): automate weekly release via pipeline schedule (Jay McCure jmccure@gitlab.com) - d0d9bc3e: chore: Refactor mr_checkout removing global var and moving dependencies to struct (Gabriel Mazzetto gabriel@gitlab.com) - 47eeadad: chore: Update MR review instructions YAML (Brendan Lynch blynch@gitlab.com) - b5ac12f9: chore: add support for modern linux-x64 duo cli binary (Andrei Zubov azubov@gitlab.com) - 7d26ca46: ci: update code-intelligence job to fix job failures (Oscar Tovar otovar@gitlab.com) - 45b9fcc3: ci: wire ci/cd inputs to release variables (Oscar Tovar otovar@gitlab.com) * Others - 080c4e2c: test: add archived field to label list JSON expectation (Tomas Vik tvik@gitlab.com) ++++ os-autoinst: - Update to version 5.1781797043.0fb1077: * test: assert Level 3 pretty serial markers * fix: fallback pretty marker console to 'sut' * test: fix color test resilience to NO_COLOR * fix: stop QMP wait hangs on early QEMU exits * fix: stop autodie unlink crashes in qemu backend * fix: cleanly recreate virtio console pipe if already exists * fix: suppress spurious virtio console unlink warnings * test: reliably assert pipe size adjustments ++++ os-autoinst: - Update to version 5.1781797043.0fb1077: * test: assert Level 3 pretty serial markers * fix: fallback pretty marker console to 'sut' * test: fix color test resilience to NO_COLOR * fix: stop QMP wait hangs on early QEMU exits * fix: stop autodie unlink crashes in qemu backend * fix: cleanly recreate virtio console pipe if already exists * fix: suppress spurious virtio console unlink warnings * test: reliably assert pipe size adjustments ++++ patterns-base: - Fix SLE pattern will be selected over Leap pattern, bsc#1252847 * Add a '+leap' to the version number ++++ patterns-gnome: - Fix SLE pattern will be selected over Leap pattern, bsc#1252847 * Add a '+leap' to the version number ++++ patterns-server: - Fix SLE pattern will be selected over Leap pattern, bsc#1252847 * Add a 'leap' to the version number ++++ product-composer: - update to version 0.9.9 * fix crash when using discard_artifacts with single files ++++ python-starlette: - CVE-2026-48817: arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr` (bsc#1268389) * added CVE-2026-48817.patch - CVE-2026-54282: request path that lacks a leading forward slash can lead to request.url.hostname manipulation (bsc#1268520) * added CVE-2026-54282.patch - CVE-2026-54283: urlencoded request body with an oversized data can lead to a denial of service (bsc#1268517) * added CVE-2026-54283.patch ++++ python-tornado6: - CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395) - CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396) - CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) (bsc#1268397) Add patches: * CVE-2026-49853.patch * CVE-2026-49854.patch * CVE-2026-49855.patch ++++ selinux-policy: - Update to version 20250627+git385.2b2068bc0: * Allow wireguard to setup DNS using dns_hatchet (bsc#1243148) * Add fs_dontaudit_relabelfrom_tmpfs_files() interface * Add sysnet_mount_file() interface * Add sysnet_dontaudit_file_relabelto() interface * Dontaudit tlp_t requesting dac_read_search (bsc#1265386) ------------------------------------------------------------------ ------------------ 2026-6-17 - Jun 17 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - disable DPC support at build time CVE-2026-47166 [bsc#1268113], CVE-2026-46693 [bsc#1268117] ++++ MozillaThunderbird: - Enable clang_build to allow building with the latest versions of llvm/clang due to them dropping support for update-alternatives. ++++ alloy: - Update to version 1.17.0: * Features Add GraphQL server and gql subcommand otelcol: Add Nginx receiver otelcol.exporter.prometheus: Convert classic histograms to NHCB database_observability: Various enhancements for MySQL and Postgres faro.receiver: Support gzip-compressed request bodies Update to Beyla 3.9.8 * Bug Fixes Address Critical CVE's From Scanner security: Update x/crypto, x/net, jackc/pgx/v5, and obi cluster: Fix nodes failing to join the cluster with TLS enabled loki.process: Fix potential deadlocks and limit stage shutdown Update go to v1.26.4 * CVE-2026-44740: Fix potential DoS via infinite loops, panics or resource consumption by bumping go-git/go-billy/v5 to 5.9.0 (bsc#1267333) * CVE-2026-45678: Fix Postgres BIND parsing by bumping go.opentelemetry.io/obi to 0.9.0 (bsc#1267481) * CVE-2026-45682: Fix memory leak in OpenTelemetry eBPF instrumentation by bumping go.opentelemetry.io/obi to 0.9.0 (bsc#1267485) * CVE-2026-45686: Fix integer overflow in memcached text protocol parser by bumping go.opentelemetry.io/obi to version 0.9.0 (bsc#1267489) * CVE-2026-45685: Fix DoS in MongoDB TCP parser by bumping go.opentelemetry.io/obi to 0.9.0 (bsc#1267488) - Drop patches: * 0001-Bump-sql_exporter.patch * 0002-Bump-Apache-Thrift.patch * 0003-Bump-jackc-pgx.patch - Update to version 1.16.3: * Bug Fixes cluster: Fix nodes failing to join the cluster when TLS is enabled - Update to version 1.16.2: * Bug Fixes loki.process: No longer mutate rules in stage.truncate causing every config update to reload pipeline when this stage is used loki.process: Potential deadlock on update with stage and receiver changes otelcol.exporter.awss3: Add missing unique_key_func_name attribute security: Address Critical CVE's From Scanner security: Update x/crypto and x/net for CVEs: CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835 (bsc#1266196) CVE-2026-39821: Fix validation bypass and privilege escalation by bumping x/net/idna (bsc#1266654) security: Fix multiple issues when parsing HTML files: CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506 (bsc#1267185) CVE-2026-33532: Remove dependency on vulnerable yaml library (bsc#1260981) ++++ chromium: - Use version suffix for llvm/clang commands - Chromium 149.0.7827.155 (boo#1268373): * CVE-2026-12437: Use after free in WebShare * CVE-2026-12438: Inappropriate implementation in WebView * CVE-2026-12439: Use after free in Digital Credentials * CVE-2026-12440: Use after free in DigitalCredentials * CVE-2026-12441: Use after free in File Input * CVE-2026-12442: Use after free in Passwords * CVE-2026-12443: Use after free in Web Authentication * CVE-2026-12444: Out of bounds read in Chromoting * CVE-2026-12445: Use after free in Extensions * CVE-2026-12446: Insufficient data validation in Passwords * CVE-2026-12447: Heap buffer overflow in WebRTC * CVE-2026-12448: Inappropriate implementation in WebView * CVE-2026-12449: Use after free in Chromoting * CVE-2026-12450: Inappropriate implementation in Media * CVE-2026-12451: Use after free in DigitalCredentials * CVE-2026-12452: Use after free in Downloads * CVE-2026-12453: Insufficient validation of untrusted input in Input * CVE-2026-12454: Race in Safe Browsing * CVE-2026-12455: Use after free in Tab Strip * CVE-2026-12456: Insufficient validation of untrusted input in Extensions * CVE-2026-12457: Insufficient data validation in Extensions * CVE-2026-12458: Incorrect security UI in Passwords * CVE-2026-12459: Inappropriate implementation in Serial * CVE-2026-12460: Insufficient policy enforcement in File System Access * CVE-2026-12461: Out of bounds read in WebRTC * CVE-2026-12462: Use after free in Media * CVE-2026-12463: Inappropriate implementation in Views * CVE-2026-12464: Use after free in Browser * CVE-2026-12465: Insufficient validation of untrusted input in Metrics * CVE-2026-12466: Heap buffer overflow in WebRTC * CVE-2026-12467: Use after free in Extensions * CVE-2026-12468: Inappropriate implementation in Updater * CVE-2026-12469: Uninitialized Use in GPU ++++ chromium: - Use version suffix for llvm/clang commands - added patches: * chromium-149-strip-path.patch - Chromium 149.0.7827.155 (boo#1268373): * CVE-2026-12437: Use after free in WebShare * CVE-2026-12438: Inappropriate implementation in WebView * CVE-2026-12439: Use after free in Digital Credentials * CVE-2026-12440: Use after free in DigitalCredentials * CVE-2026-12441: Use after free in File Input * CVE-2026-12442: Use after free in Passwords * CVE-2026-12443: Use after free in Web Authentication * CVE-2026-12444: Out of bounds read in Chromoting * CVE-2026-12445: Use after free in Extensions * CVE-2026-12446: Insufficient data validation in Passwords * CVE-2026-12447: Heap buffer overflow in WebRTC * CVE-2026-12448: Inappropriate implementation in WebView * CVE-2026-12449: Use after free in Chromoting * CVE-2026-12450: Inappropriate implementation in Media * CVE-2026-12451: Use after free in DigitalCredentials * CVE-2026-12452: Use after free in Downloads * CVE-2026-12453: Insufficient validation of untrusted input in Input * CVE-2026-12454: Race in Safe Browsing * CVE-2026-12455: Use after free in Tab Strip * CVE-2026-12456: Insufficient validation of untrusted input in Extensions * CVE-2026-12457: Insufficient data validation in Extensions * CVE-2026-12458: Incorrect security UI in Passwords * CVE-2026-12459: Inappropriate implementation in Serial * CVE-2026-12460: Insufficient policy enforcement in File System Access * CVE-2026-12461: Out of bounds read in WebRTC * CVE-2026-12462: Use after free in Media * CVE-2026-12463: Inappropriate implementation in Views * CVE-2026-12464: Use after free in Browser * CVE-2026-12465: Insufficient validation of untrusted input in Metrics * CVE-2026-12466: Heap buffer overflow in WebRTC * CVE-2026-12467: Use after free in Extensions * CVE-2026-12468: Inappropriate implementation in Updater * CVE-2026-12469: Uninitialized Use in GPU ++++ google-guest-agent: - Drop CVE-2026-33186.patch, merged upstream ++++ google-osconfig-agent: - Packaging improvements: * Remove define github project name components no longer needed * Define shortname corresponding to binary name when different from package name. Use shortname where applicable to normalize common lines across Go app packages, similar to name macro. * Drop BuildRequires: golang-packaging. The original macros for file movements into GOPATH are obsolete with Go modules. Macro go_nostrip is no longer needed with current binutils and Go. * Remove go_nostrip macro which is no longer recommended * Re-enable binary stripping and debuginfo boo#1210938 * Remove goprep macro which is no longer recommended * Build PIE with pattern that may become recommended procedure: %%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build A go toolchain buildmode default config would be preferable but none exist at this time. * Drop export CGO_ENABLED="0". Use the default unless there is a defined requirement or benefit. * For this package, we were seeing the expected error "-buildmode=pie requires external (cgo) linking, but cgo is not enabled" when using buildmode=pie and CGO_ENABLED=0. The error manifested only on s390x and i586 architectures, which was not expected. Resolve by using default CGO_ENABLED. * Remove ldflags -s (Omit symbol table and debug info) and -w (Omit DWARF symbol table). This information is used to produce separate debuginfo packages and binaries are stripped for reduced size by GNU strip during RPM build. * Remove ldflags -X entry for embedding build version metadata. This information is embedded in binaries with go1.18+ and available via go version -m or runtime/debug.ReadBuildInfo(). * Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable * Raise minimum golang API version to 1.25.5 to match go.mod file * Use explicit upstream GitHub homepage in URL field * Use single invocation of %setup with -a1 to unpack both tarballs ++++ helmfile: - Update to version 1.5.5: * fix: restore s3:: vhost-style remote source support (#2643) by @yxxhero in #2644 * feat: add helm 4 --server-side flag support for diff and bump helm-diff to v3.15.10 by @yxxhero in #2645 ++++ mcp-server-trento: - Release 1.1.1 [#]# What's Changed * Fix unhandled array parameters (#131) @balanza * *Full Changelog**: https://github.com/trento-project/mcp-server/compare/1.1.0...1.1.1 ++++ migrate-sles-to-sles4sap: - The migrate-sles-to-sles4sap package need to adapt SLE16 (bsc#1265271) - Use /etc/os-release instead of /etc/products.d/baseproduct - The script checks which package /etc/os-release belongs to to identify the operating system - Remove perl-XML-Twig from dependency. We do not use xml_grep anymore ++++ nvidia-open-driver-G07-signed-cuda: - changes to build also against the nvidia kernel, which is planned to be available for SLE16.1-aarch64 ++++ nvidia-open-driver-G07-signed: - changes to build also against the nvidia kernel, which is planned to be available for SLE16.1-aarch64 ++++ openQA: - Update to version 5.1781712973.4c20e5c1: * test: make search API tests robust * fix: resolve openqa-llm-server crash on startup * chore(deps): Dependency cron 2026-06-17 * feat: Improve job archive generation efficiency and UI * feat: Efficiently serve job archives via web server redirect * feat: Add 'Download All' ZIP archive button to job downloads page ++++ openQA: - Update to version 5.1781712973.4c20e5c1: * test: make search API tests robust * fix: resolve openqa-llm-server crash on startup * chore(deps): Dependency cron 2026-06-17 * feat: Improve job archive generation efficiency and UI * feat: Efficiently serve job archives via web server redirect * feat: Add 'Download All' ZIP archive button to job downloads page ++++ openQA: - Update to version 5.1781712973.4c20e5c1: * test: make search API tests robust * fix: resolve openqa-llm-server crash on startup * chore(deps): Dependency cron 2026-06-17 * feat: Improve job archive generation efficiency and UI * feat: Efficiently serve job archives via web server redirect * feat: Add 'Download All' ZIP archive button to job downloads page ++++ os-autoinst: - Update to version 5.1781702821.22ced0d: * ci: Avoid unresolvable os-autoinst-openvswitch-test package for SLE-SP7 * fix: Avoid unresolvable os-autoinst-devel-test package for SLE-SP7 * feat: expose detect_serial_marker_capability as public * chore(mergify): adjust expectations to current OBS checks * style(perlcritic): Add BuiltinFunctions::RequireBlockGrep ++++ os-autoinst: - Update to version 5.1781702821.22ced0d: * ci: Avoid unresolvable os-autoinst-openvswitch-test package for SLE-SP7 * fix: Avoid unresolvable os-autoinst-devel-test package for SLE-SP7 * feat: expose detect_serial_marker_capability as public * chore(mergify): adjust expectations to current OBS checks * style(perlcritic): Add BuiltinFunctions::RequireBlockGrep ++++ product-composer: - update to version 0.9.8 * Support/fix checksums configurations per flavor ++++ product-composer: - update to version 0.9.8 * Support/fix checksums configurations per flavor ++++ trento-agent: - Release 3.1.1 [#]# What's Changed * Bump golang.org/x/net to v0.55.0 (#593) @balanza * Bump contracts ref (#595) @balanza * Bump github.com/tidwall/gjson from 1.18.0 to 1.19.0 (#596) @balanza * Bump golang.org/x/mod from 0.34.0 to 0.36.0 (#597) @balanza * Bump gopkg.in/ini.v1 from 1.67.1 to 1.67.2 (#598) @balanza * *Full Changelog**: https://github.com/trento-project/agent/compare/3.1.0...3.1.1 ++++ trento-checks: - Release 1.3.1 [#]# What's Changed * Changing description ofcheck 9FAAD0 (#73) @balanza * *Full Changelog**: https://github.com/trento-project/checks/compare/1.3.0...1.3.1 ++++ trento-web: - Release 3.1.1 [#]# What's Changed * Update analytics docs link profile form (#4376) @balanza * Flip activity log `from_date` and `to_date` logic (#4378) @balanza * Fix cluster registered broadcast (#4379) @balanza * Updated License in spec file (#4380) @balanza * Export version in rpm packages to use same value during compilation (#4381) @balanza * Normalize query string to list (#4383) @balanza * *Full Changelog**: https://github.com/trento-project/web/compare/3.1.0...3.1.1 ------------------------------------------------------------------ ------------------ 2026-6-16 - Jun 16 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - added patches CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge–response authentication model [bsc#1268114] * ImageMagick-CVE-2026-47165.patch - added patches CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder [bsc#1268102] * ImageMagick-CVE-2026-45358.patch CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder [bsc#1268124] * ImageMagick-CVE-2026-46521.patch CVE-2026-46523: heap-use-after-free via a crafted MSL image [bsc#1268125] * ImageMagick-CVE-2026-46523.patch CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check [bsc#1268123] * ImageMagick-CVE-2026-46557.patch CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 [bsc#1268121] * ImageMagick-CVE-2026-46559.patch CVE-2026-48734: Stack Overflow in MVG decoder [bsc#1268122] * ImageMagick-CVE-2026-48734.patch CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation [bsc#1268105] * ImageMagick-CVE-2026-53463.patch ++++ google-osconfig-agent: - Update to version 20260615.01 * Upgrade golang.org/x/crypto & golang.org/x/net (#1006) (bsc#1266171, CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835) (bsc#1266603, CVE-2026-39821) - from version 20260615.00 * Add unit tests for ospatch_apt_upgrade.go (#938) ++++ helmfile: - Update to version 1.5.4: * build(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 by @dependabot[bot] in #2629 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.23 to 1.32.24 by @dependabot[bot] in #2627 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.103.2 to 1.103.3 by @dependabot[bot] in #2628 * fix: Fix broken trackLogs functionality in Kubedog tracker by @ggillies in #2630 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.24 to 1.32.25 by @dependabot[bot] in #2632 * Bump Helm support to 4.2.1 and 3.21.1 by @Copilot in #2635 * build(deps): bump github.com/helmfile/vals from 0.44.0 to 0.44.1 by @dependabot[bot] in #2637 * build(deps): bump github.com/helmfile/chartify from 0.26.4 to 0.26.5 by @dependabot[bot] in #2636 * Add App.WithFileSystem by @toyamagu-2021 in #2638 * fix: include release values in .Values for patch template rendering by @yxxhero in #2556 * build(deps): bump helm-diff to v3.15.9 by @yxxhero in #2642 * feat: add support for helm 4 --server-side upgrade flag by @yxxhero in #2641 ++++ libtcnative-1-0: - Update to 1.3.8 * Changes + Fix a memory leak when parsing certificates + Fix two potential memory leaks on error paths identified by Copilot + Fix post handshake authentication when Tomcat is configured with a trust store using JSSE style configuration + Correct expected size of tickets when calling SSLContext.setSessionTicketKeys ++++ libtcnative-2-0: - Upgrade to version 2.0.15 * Changes + Fix a memory leak when parsing certificates + Fix two potential memory leaks on error paths identified by Copilot + Fix post handshake authentication Tomcat is configured with a trust store using JSSE style configuration + Correct expected size of tickets when calling SSLContext.setSessionTicketKeys ++++ openQA: - Update to version 5.1781621316.6d025b35: * refactor: set clean monikers for Mojo services * feat: use encrypted session cookies * chore(deps): Dependency cron 2026-06-13 * docs: Mention how to enable UEFI and recently added variables * docs: fix broken badge syntax in README.md * feat(apparmor): add current worker profile as generated by aa-logprof * feat(apparmor): add current worker requirements in /proc and /sys * chore(deps): Dependency cron 2026-06-12 * git subrepo pull (merge) external/os-autoinst-common * docs: Fix wrapping in "Job Priority Throttling" section * fix(apparmor): Allow worker profile to use virt-fw-vars * fix(livelog): Prevent timeouts due to nginx buffering * fix: avoid initial delay when replying from livestream * chore(deps): Dependency cron 2026-06-10 * chore(deps): Dependency cron 2026-06-09 * test: Skip earlier in tests_dependencies.t * fix: Use reload-or-restart for openQA auto restart worker slots * fix: Update codecov orb to latest version 6.0.0 fixing PGP error * chore(deps): Dependency cron 2026-06-06 * fix: Support invent.kde.org and 'work_items' in bug URL handling * ci(mergify): prevent annoying conflict messages * docs: Rewrite medium version globbing in more user-facing style * docs: Mention globbing in "Spawning multiple jobs …" and "Medium types" * feat(scheduling): Allow globbing in version specifications * fix: Set correct settings for scheduling example test * refactor: Fix comment regarding `test_preset` INI section ++++ openQA: - Update to version 5.1781621316.6d025b35: * refactor: set clean monikers for Mojo services * feat: use encrypted session cookies * chore(deps): Dependency cron 2026-06-13 * docs: Mention how to enable UEFI and recently added variables * docs: fix broken badge syntax in README.md * feat(apparmor): add current worker profile as generated by aa-logprof * feat(apparmor): add current worker requirements in /proc and /sys * chore(deps): Dependency cron 2026-06-12 * git subrepo pull (merge) external/os-autoinst-common * docs: Fix wrapping in "Job Priority Throttling" section * fix(apparmor): Allow worker profile to use virt-fw-vars * fix(livelog): Prevent timeouts due to nginx buffering * fix: avoid initial delay when replying from livestream * chore(deps): Dependency cron 2026-06-10 * chore(deps): Dependency cron 2026-06-09 * test: Skip earlier in tests_dependencies.t * fix: Use reload-or-restart for openQA auto restart worker slots * fix: Update codecov orb to latest version 6.0.0 fixing PGP error * chore(deps): Dependency cron 2026-06-06 * fix: Support invent.kde.org and 'work_items' in bug URL handling * ci(mergify): prevent annoying conflict messages * docs: Rewrite medium version globbing in more user-facing style * docs: Mention globbing in "Spawning multiple jobs …" and "Medium types" * feat(scheduling): Allow globbing in version specifications * fix: Set correct settings for scheduling example test * refactor: Fix comment regarding `test_preset` INI section ++++ openQA: - Update to version 5.1781621316.6d025b35: * refactor: set clean monikers for Mojo services * feat: use encrypted session cookies * chore(deps): Dependency cron 2026-06-13 * docs: Mention how to enable UEFI and recently added variables * docs: fix broken badge syntax in README.md * feat(apparmor): add current worker profile as generated by aa-logprof * feat(apparmor): add current worker requirements in /proc and /sys * chore(deps): Dependency cron 2026-06-12 * git subrepo pull (merge) external/os-autoinst-common * docs: Fix wrapping in "Job Priority Throttling" section * fix(apparmor): Allow worker profile to use virt-fw-vars * fix(livelog): Prevent timeouts due to nginx buffering * fix: avoid initial delay when replying from livestream * chore(deps): Dependency cron 2026-06-10 * chore(deps): Dependency cron 2026-06-09 * test: Skip earlier in tests_dependencies.t * fix: Use reload-or-restart for openQA auto restart worker slots * fix: Update codecov orb to latest version 6.0.0 fixing PGP error * chore(deps): Dependency cron 2026-06-06 * fix: Support invent.kde.org and 'work_items' in bug URL handling * ci(mergify): prevent annoying conflict messages * docs: Rewrite medium version globbing in more user-facing style * docs: Mention globbing in "Spawning multiple jobs …" and "Medium types" * feat(scheduling): Allow globbing in version specifications * fix: Set correct settings for scheduling example test * refactor: Fix comment regarding `test_preset` INI section ++++ os-autoinst: - Update to version 5.1781620242.0160257: * fix: Fix comment about OVMF firmware locations * fix(test): fix Test::More precedence in autotest * git subrepo pull (merge) --force external/os-autoinst-common * feat: Avoid silent fallback to MS certs with `UEFI_PFLASH_CERTS` * fix: Fix enrolling cert in UEFI firmware vars for SecureBoot ++++ os-autoinst: - Update to version 5.1781620242.0160257: * fix: Fix comment about OVMF firmware locations * fix(test): fix Test::More precedence in autotest * git subrepo pull (merge) --force external/os-autoinst-common * feat: Avoid silent fallback to MS certs with `UEFI_PFLASH_CERTS` * fix: Fix enrolling cert in UEFI firmware vars for SecureBoot ++++ os-autoinst: - Update to version 5.1781620242.0160257: * fix: Fix comment about OVMF firmware locations * fix(test): fix Test::More precedence in autotest * git subrepo pull (merge) --force external/os-autoinst-common * feat: Avoid silent fallback to MS certs with `UEFI_PFLASH_CERTS` * fix: Fix enrolling cert in UEFI firmware vars for SecureBoot ++++ python-WebOb: - CVE-2026-44889: Location header normalization during redirect leads to open redirect (bsc#1268324) * added CVE-2026-44889.patch ++++ tar: - Fix tar changing dir permissions temporarily even when using --no-overwrite-dir * no-overwrite-dir-fix.patch - Fix CVE-2026-5704, crafted archives can be used to to hide file injection (bsc#1261900) * CVE-2026-5704.patch - Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450) * fix-dereference.patch - Fix extraction failure for paths like "a/./b" caused by the gnulib openat2 implementation (bsc#1267189) * openat2-fix-dotlike-failure.patch ------------------------------------------------------------------ ------------------ 2026-6-15 - Jun 15 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - added patches CVE-2026-42326: Information disclosure via malicious IPTC input file [bsc#1268092] * ImageMagick-CVE-2026-42326.patch CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder [bsc#1268094] * ImageMagick-CVE-2026-45031.patch CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value [bsc#1268095] * ImageMagick-CVE-2026-45359.patch CVE-2026-45624: Data exposure due to image processing vulnerability [bsc#1268096] * ImageMagick-CVE-2026-45624.patch CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images [bsc#1268112] * ImageMagick-CVE-2026-46520.patch CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder [bsc#1268126] * ImageMagick-CVE-2026-46522.patch CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute-cache service [bsc#1268120] * ImageMagick-CVE-2026-46692.patch CVE-2026-48724: Heap Buffer Underwrite in Floyd-Steinberg depth dithering [bsc#1268116] * ImageMagick-CVE-2026-48724.patch CVE-2026-48733: Infinite Loop in subimage-search with crafted image [bsc#1268119] * ImageMagick-CVE-2026-48733.patch CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems [bsc#1268111] * ImageMagick-CVE-2026-48994.patch CVE-2026-49218: denial of service due to a missing check in the DCM decoder [bsc#1268110] * ImageMagick-CVE-2026-49218.patch CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory [bsc#1268108] * ImageMagick-CVE-2026-53460.patch CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder [bsc#1268107] * ImageMagick-CVE-2026-53461.patch CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser [bsc#1268103] * ImageMagick-CVE-2026-53464.patch ++++ coturn: - Update to version 4.13.1 * null-terminate server_name in stun_is_challenge_response_str. * Canonicalize all IPv4-in-IPv6 encodings before peer-IP checks. * Auto-deny coturn's own database backend endpoints as relay peers. * Deny link-local / ULA / site-local relay peers by default. ++++ curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) * Add patch: curl-http-prefer-chunked-encoding-over-Content-Length-0.patch ++++ curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) * Add patch: curl-http-prefer-chunked-encoding-over-Content-Length-0.patch ++++ dealers-choice: - dealers-choice 0.0.15: * regression fix: joining a hand in progress no longer crashes the client * deckhandler: shuffle and recycle the discard pile when the deck runs out mid-draw, fixing duplicate cards dealt in multi-player draw games * pokeval: fix California lowball tie-breaks ++++ lldpd: - Add libcap-devel to BuildRequires to build with support for libpcap. This will allow the monitor process to drop its privileges instead of running as root, improving security. ++++ sg3_utils: - Update to version 1.48~20221101+7.f75279c0: * sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823) * rescan-scsi-bus.sh: quote $id_serial in findmultipath call (bsc#1268201) ++++ python-Markdown: - Add fix-incompatible-html-tags.patch upstream patch to fix tests with latest python version. (bsc#1268243, gh#Python-Markdown/markdown#1548) ++++ stgit: - Update to version 2.6.0: * chore: update changelog for 2.6.0 * fix(import): respect --name verbatim, ignoring stgit.namelength * test(refresh): use test_when_finished for status.renames cleanup * expect over unwrap for test * bugfix: issue #615, add Copied variant to Status enum and move panic to a copied status, add integration test * docs: Update copyright year * chore: update gix to 0.83 (CVE-2026-40034, bsc#1266429) * chore: update compatible transitive dependencies * chore: update winnow to 1.0.3 * chore: update jiff to 0.2.24 * ci: drop dead CARGO_TARGET_*_STRIP env vars from package build * ci: soft-pin cargo-deb to ^3.0 * ci: bump cargo-generate-rpm pin to ^0.20.0 * ci: bump GitHub Actions to Node 24 runtimes * chore: update winnow to 1.0.1 * chore: update clap to 4.6.1 * chore: update gix to 0.81 * chore: bump MSRV to 1.85 * chore: update transitive deps * chore: update winnow to 0.7.15 * chore: update thiserror to 2.0.18 * chore: update tempfile to 3.27.0 * chore: update tar to 0.4.45 * chore: update serde_json to 1.0.149 * chore: update jiff to 0.2.23 * chore: update indexmap to 2.14.0 * chore: update flate2 to 1.1.9 * chore: update ctrlc to 3.5.2 * chore: update clap to 4.5.61 * chore: update anyhow to 1.0.102 * chore: update anstyle to 1.0.14 ++++ stgit: - Update to version 2.6.0: * chore: update changelog for 2.6.0 * fix(import): respect --name verbatim, ignoring stgit.namelength * test(refresh): use test_when_finished for status.renames cleanup * expect over unwrap for test * bugfix: issue #615, add Copied variant to Status enum and move panic to a copied status, add integration test * docs: Update copyright year * chore: update gix to 0.83 (CVE-2026-40034, bsc#1266429) * chore: update compatible transitive dependencies * chore: update winnow to 1.0.3 * chore: update jiff to 0.2.24 * ci: drop dead CARGO_TARGET_*_STRIP env vars from package build * ci: soft-pin cargo-deb to ^3.0 * ci: bump cargo-generate-rpm pin to ^0.20.0 * ci: bump GitHub Actions to Node 24 runtimes * chore: update winnow to 1.0.1 * chore: update clap to 4.6.1 * chore: update gix to 0.81 * chore: bump MSRV to 1.85 * chore: update transitive deps * chore: update winnow to 0.7.15 * chore: update thiserror to 2.0.18 * chore: update tempfile to 3.27.0 * chore: update tar to 0.4.45 * chore: update serde_json to 1.0.149 * chore: update jiff to 0.2.23 * chore: update indexmap to 2.14.0 * chore: update flate2 to 1.1.9 * chore: update ctrlc to 3.5.2 * chore: update clap to 4.5.61 * chore: update anyhow to 1.0.102 * chore: update anstyle to 1.0.14 ++++ stgit: - Update to version 2.6.0: * chore: update changelog for 2.6.0 * fix(import): respect --name verbatim, ignoring stgit.namelength * test(refresh): use test_when_finished for status.renames cleanup * expect over unwrap for test * bugfix: issue #615, add Copied variant to Status enum and move panic to a copied status, add integration test * docs: Update copyright year * chore: update gix to 0.83 (CVE-2026-40034, bsc#1266429) * chore: update compatible transitive dependencies * chore: update winnow to 1.0.3 * chore: update jiff to 0.2.24 * ci: drop dead CARGO_TARGET_*_STRIP env vars from package build * ci: soft-pin cargo-deb to ^3.0 * ci: bump cargo-generate-rpm pin to ^0.20.0 * ci: bump GitHub Actions to Node 24 runtimes * chore: update winnow to 1.0.1 * chore: update clap to 4.6.1 * chore: update gix to 0.81 * chore: bump MSRV to 1.85 * chore: update transitive deps * chore: update winnow to 0.7.15 * chore: update thiserror to 2.0.18 * chore: update tempfile to 3.27.0 * chore: update tar to 0.4.45 * chore: update serde_json to 1.0.149 * chore: update jiff to 0.2.23 * chore: update indexmap to 2.14.0 * chore: update flate2 to 1.1.9 * chore: update ctrlc to 3.5.2 * chore: update clap to 4.5.61 * chore: update anyhow to 1.0.102 * chore: update anstyle to 1.0.14 ++++ strace: - Update to strace 7.1 * Implemented wall-clock-aware columns (wall-total, wall-min, wall-max, wall-avg) for the -c/--summary-only report, allowing wall-clock and system CPU times to be displayed side by side in a single run. * Included out-of-range syscalls in the -c/--summary-only report. * Updated decoding of sched_getattr syscall. * Implemented decoding of FS_IOC_SHUTDOWN, PIDFD_GET_INFO, and PIDFD_GET_*_NAMESPACE ioctl commands. * Implemented decoding of IFLA_BR_FDB_N_LEARNED, IFLA_BR_FDB_MAX_LEARNED, and IFLA_BR_STP_MODE netlink attributes. * Updated lists of CLONE_*, FSMOUNT_*, KT_*, KVM_*, LANDLOCK_*, NETDEV_*, NL80211_*, and PIDFD_* constants. * Updated lists of ioctl commands from Linux 7.1. * Implement EPERM diagnostics and give a hint about yama (jsc#PED-15928). ++++ trivy: - update to 0.71.1: * fix(oci): validate artifact filename * fix: forward ospkg detector options through ospkg.NewScanner * fix(vex): load VEX documents from within the repository directory * fix: surface the original analysis error instead of context cancellation * ci: expect GitHub App bot as backport PR author ++++ trivy: - update to 0.71.1 (bsc#1269269, CVE-2026-55092): * fix(oci): validate artifact filename * fix: forward ospkg detector options through ospkg.NewScanner * fix(vex): load VEX documents from within the repository directory * fix: surface the original analysis error instead of context cancellation * ci: expect GitHub App bot as backport PR author ++++ warewulf4: - updating to v4.7.0 with following security fixes * fixed CVE-2026-39821 (bsc#1266483) * fixed CVE-2026-33814 (bsc#1265653) - v4.7.0 with significant changes relative to the v4.6.x series which are: * New wwctl unset command * Refactored server routes (URLs) * New /files/ route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - changes from v4.6.5: * new wwctl overlay info command * fixed wwctl image import --update option * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - remove slurm-overlay package ++++ warewulf4: - updating to v4.7.0 with following security fixes * fixed CVE-2026-39821 (bsc#1266483) * fixed CVE-2026-33814 (bsc#1265653) - v4.7.0 with significant changes relative to the v4.6.x series which are: * New wwctl unset command * Refactored server routes (URLs) * New /files/ route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions - changes from v4.6.5: * new wwctl overlay info command * fixed wwctl image import --update option * cross-arch support for wwclient * improved IPv6 support * improved support for bonded interfaces * renamed debian.interfaces overlay to ifupdown * new systemd-networkd overlay * warewulf-dracut fixes, including "provision-to-disk" fixes - remove slurm-overlay package ------------------------------------------------------------------ ------------------ 2026-6-14 - Jun 14 2026 ------------------- ------------------------------------------------------------------ ++++ coturn: - Update to version 4.13.0 * Wrap atomic everywhere. * Fix sendmmsg stride bug in multiplex-peer UDP batch flush. * Reap TURN permissions/channels via a per-thread sweep instead of per-object timers. * Add --udp-sendmmsg-log to observe egress sendmmsg/UDP-GSO batching. * Expose recvmmsg/sendmmsg UDP batch sizes as Prometheus metrics * Restrict recvmmsg fast path to shared fan-in sockets (make --udp-recvmmsg useful standalone). * Enable --udp-recvmmsg by default on Linux. * Security hardening: port parsing, admin brute-force throttle, credential log redaction, constant-time compare, OAuth bounds checks, permission cap (#1932). * Add continuous latency mode to stunclient. * Fix test_redis_format link failure. * Fix configure MANPREFIX typo. * Fix missing sqlite3 dependendcy. * Fix UDP receive buffer ownership. ------------------------------------------------------------------ ------------------ 2026-6-13 - Jun 13 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaThunderbird: - Mozilla Thunderbird 140.12.0 ESR MFSA 2026-61 (bsc#1268071) * CVE-2026-12289 (bmo#2023443) Privilege escalation in the Graphics: WebRender component * CVE-2026-12290 (bmo#2024852) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12291 (bmo#2036929) Use-after-free in the Networking: HTTP component * CVE-2026-12292 (bmo#2038465) Incorrect boundary conditions in the Web Audio component * CVE-2026-12294 (bmo#2039873) Sandbox escape in the DOM: Workers component * CVE-2026-12295 (bmo#2040160) Sandbox escape in the DOM: Navigation component * CVE-2026-12298 (bmo#2041981) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12296 (bmo#2040515) Sandbox escape in the Security: Process Sandboxing component * CVE-2026-12297 (bmo#2041610) Sandbox escape due to incorrect boundary conditions in the Networking component * CVE-2026-12299 (bmo#2043139) JIT miscompilation in the DOM: Core & HTML component * CVE-2026-12329 (bmo#2044738) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12302 (bmo#2034489) Mitigation bypass in the DOM: Security component * CVE-2026-12304 (bmo#2034944) Same-origin policy bypass in the Networking: Cookies component * CVE-2026-12305 (bmo#2037290) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12306 (bmo#2037323) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12307 (bmo#2038133) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12308 (bmo#2038302) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12309 (bmo#2038476) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12310 (bmo#2039707) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12311 (bmo#2040177) Information disclosure, sandbox escape in the Security: Process Sandboxing component * CVE-2026-12312 (bmo#2040383) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12313 (bmo#2040477) Information disclosure, sandbox escape in the Security: Process Sandboxing component * CVE-2026-12314 (bmo#2041856) Memory safety bug fixed in Thunderbird ESR 140.12 * CVE-2026-12315 (bmo#2042058) Mitigation bypass in the DOM: Security component * CVE-2026-12330 (bmo#2029326) Incorrect boundary conditions in the Internationalization component * CVE-2026-12324 (bmo#2038444) Incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-12325 (bmo#2039443) Denial-of-service in the Graphics: ImageLib component * CVE-2026-12327 (bmo#2011842, bmo#2023902, bmo#2025512, bmo#2027312, bmo#2029444, bmo#2036571, bmo#2036900, bmo#2036936, bmo#2037995, bmo#2038551, bmo#2040717, bmo#2042724) Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 * CVE-2026-12328 (bmo#2029402, bmo#2038477, bmo#2039726, bmo#2041373, bmo#2042268, bmo#2042451, bmo#2042782, bmo#2042858, bmo#2042929, bmo#2042965, bmo#2043213) Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152 ++++ ansible-core: - Security fix for CVE-2026-11332 (bsc#1267822): argument injection in ansible-galaxy role install; pass role requirements as positional arguments to 'git clone' (add '--' separator). git-format-patch backport of gh#ansible/ansible#87078 (commit 5ae948f, stable-2.21). * add ansible-core-CVE-2026-11332.patch ++++ chromium: - added patches: * disable-ai.patch (re-add since now ported to 149) - added configs: * disable-ai.json (both parts taken from fedora package) ++++ chromium: - added patches: * disable-ai.patch (re-add since now ported to 149) - added configs: * disable-ai.json (both parts taken from fedora package) ++++ coredns: - Update to version 1.14.4: * plugin/proxyproto: Prevent nil pointer dereference when dropping malformed PROXY packets * Bump dependencies * plugin/cache: allow cache TTLs above default 3600s * plugin/dnssec: sign each RRset with the zone that owns its name, not the query zone * dnsserver: use http.LocalAddrContextKey for DoH local address * build: add loong64 arch support * core: bound HTTP/3 request header size for DoH3 * fix: reject invalid any and local config * plugin/forward: add hostname resolution support for TO endpoints * fix(kubernetes): remove debug fmt.Println from multicluster zone validation * feat(core): expose TLS ConnectionState (SNI) for DoQ * fix: use descriptive error for unknown block options in health and log plugins * plugin/forward: Forward NODATA responses to Next handler * fix: reject unknown chaos block options * fix: reject unknown trace and dnstap block options * fix: reject unknown ready plugin properties * pkg/tls: remove duplicate cipher suites * fix(azure): apply `access` mode to every zone in the same block * feat(secondary): add fallthrough support * fix(cache): prefer positive cache over SERVFAIL in ncache * plugin/file: trigger reload of zones based on mtime * plugin/dnstap: feature: added incoming connection support * plugin/file: canonicalize escape form in owner names * feat(cache): add optional verify timeout to serve_stale ++++ helm: - Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 [#32152] * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates - chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 - chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 - chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 - chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 - chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 - chore(deps): bump github.com/distribution/distribution/v3 - chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 - chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 - chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 - chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 - chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 - chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 ++++ helm: - Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 [#32152] * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates - chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 - chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 - chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 - chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 - chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 - chore(deps): bump github.com/distribution/distribution/v3 - chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 - chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 - chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 - chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 - chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 - chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 ++++ helm: - Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 [#32152] * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates - chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 - chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 - chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 - chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 - chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 - chore(deps): bump github.com/distribution/distribution/v3 - chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 - chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 - chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 - chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 - chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 - chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 ------------------------------------------------------------------ ------------------ 2026-6-12 - Jun 12 2026 ------------------- ------------------------------------------------------------------ ++++ GraphicsMagick: - fixed off by one [bsc#1265048] - modified patches * GraphicsMagick-CVE-2026-42050.patch (refreshed) ++++ GraphicsMagick: - fixed off by one [bsc#1265048] - modified patches * GraphicsMagick-CVE-2026-42050.patch (refreshed) ++++ chromium: - Chromium 149.0.7827.114 (boo#1268158): * CVE-2026-12007: Use after free Core * CVE-2026-12008: Use after free DigitalCredentials * CVE-2026-12009: Insufficient validation of untrusted input Accessibility * CVE-2026-12010: Heap buffer overflow GPU * CVE-2026-12011: Use after free WebMIDI * CVE-2026-12012: Use after free Network * CVE-2026-12013: Use after free Media * CVE-2026-12014: Use after free Cast * CVE-2026-12015: Use after free Autofill * CVE-2026-12016: Insufficient validation of untrusted input DevTools * CVE-2026-12017: Insufficient validation of untrusted input Extensions * CVE-2026-12018: Inappropriate implementation Mojo * CVE-2026-12019: Out of bounds write Codecs * CVE-2026-12020: Use after free Autofill * CVE-2026-12022: Race Safe Browsing * CVE-2026-12023: Use after free GPU * CVE-2026-12024: Insufficient policy enforcement DevTools * CVE-2026-12025: Insufficient validation of untrusted input Network * CVE-2026-12026: Out of bounds read Video * CVE-2026-12027: Insufficient policy enforcement Headless * CVE-2026-12028: Use after free GPU * CVE-2026-12029: Use after free Video * CVE-2026-12030: Heap buffer overflow GPU * CVE-2026-12031: Inappropriate implementation Views * CVE-2026-12032: Inappropriate implementation Passwords * CVE-2026-12033: Out of bounds read VideoCapture * CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming * CVE-2026-12035: Use after free Views ++++ chromium: - Chromium 149.0.7827.114 (boo#1268158): * CVE-2026-12007: Use after free Core * CVE-2026-12008: Use after free DigitalCredentials * CVE-2026-12009: Insufficient validation of untrusted input Accessibility * CVE-2026-12010: Heap buffer overflow GPU * CVE-2026-12011: Use after free WebMIDI * CVE-2026-12012: Use after free Network * CVE-2026-12013: Use after free Media * CVE-2026-12014: Use after free Cast * CVE-2026-12015: Use after free Autofill * CVE-2026-12016: Insufficient validation of untrusted input DevTools * CVE-2026-12017: Insufficient validation of untrusted input Extensions * CVE-2026-12018: Inappropriate implementation Mojo * CVE-2026-12019: Out of bounds write Codecs * CVE-2026-12020: Use after free Autofill * CVE-2026-12022: Race Safe Browsing * CVE-2026-12023: Use after free GPU * CVE-2026-12024: Insufficient policy enforcement DevTools * CVE-2026-12025: Insufficient validation of untrusted input Network * CVE-2026-12026: Out of bounds read Video * CVE-2026-12027: Insufficient policy enforcement Headless * CVE-2026-12028: Use after free GPU * CVE-2026-12029: Use after free Video * CVE-2026-12030: Heap buffer overflow GPU * CVE-2026-12031: Inappropriate implementation Views * CVE-2026-12032: Inappropriate implementation Passwords * CVE-2026-12033: Out of bounds read VideoCapture * CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming * CVE-2026-12035: Use after free Views ++++ chromium: - Chromium 149.0.7827.114 (boo#1268158): * CVE-2026-12007: Use after free Core * CVE-2026-12008: Use after free DigitalCredentials * CVE-2026-12009: Insufficient validation of untrusted input Accessibility * CVE-2026-12010: Heap buffer overflow GPU * CVE-2026-12011: Use after free WebMIDI * CVE-2026-12012: Use after free Network * CVE-2026-12013: Use after free Media * CVE-2026-12014: Use after free Cast * CVE-2026-12015: Use after free Autofill * CVE-2026-12016: Insufficient validation of untrusted input DevTools * CVE-2026-12017: Insufficient validation of untrusted input Extensions * CVE-2026-12018: Inappropriate implementation Mojo * CVE-2026-12019: Out of bounds write Codecs * CVE-2026-12020: Use after free Autofill * CVE-2026-12022: Race Safe Browsing * CVE-2026-12023: Use after free GPU * CVE-2026-12024: Insufficient policy enforcement DevTools * CVE-2026-12025: Insufficient validation of untrusted input Network * CVE-2026-12026: Out of bounds read Video * CVE-2026-12027: Insufficient policy enforcement Headless * CVE-2026-12028: Use after free GPU * CVE-2026-12029: Use after free Video * CVE-2026-12030: Heap buffer overflow GPU * CVE-2026-12031: Inappropriate implementation Views * CVE-2026-12032: Inappropriate implementation Passwords * CVE-2026-12033: Out of bounds read VideoCapture * CVE-2026-12034: Insufficient validation of untrusted input Linux Toolkit Theming * CVE-2026-12035: Use after free Views ++++ gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-aarch64-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-aarch64-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-amdgcn-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-arm-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-arm-none-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-avr-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-bpf-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-hppa-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-nvptx-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-ppc64-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-ppc64le-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-ppc64le-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-pru-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-riscv64-elf-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-riscv64-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-riscv64-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-rx-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-s390x-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-s390x-gcc15-bootstrap: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ cross-x86_64-gcc15: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ gcc15-testresults: - Update to GCC 15.3 release * remove included gcc15-bsc1257463.patch ++++ glycin-loaders: - Refresh dependencies (bsc#1248035 bsc#1249010 CVE-2025-55159 CVE-2025-58160). ++++ golang-github-prometheus-alertmanager: - CVE-2026-39821: Fix validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266615) - Drop 0002-Bump-x-net.patch ++++ google-cloud-sap-agent: - Update to version 3.15 * Remove LoggingClient error failure for hanadiskrestore and hanadiskbackup. * Add checks for unexpected arguments in hanadiskbackup and hanadiskrestore. * Update SAP Agent version to 3.15. * Refactor grubBootLoaderX5 to check for BLS support via grub2-mkconfig help. * Update all go dependencies * Check grub2-mkconfig for BLS support on X4 instances. * Add tenant SID collection to supportbundle. * Update golang.org/x/net dependency. This is to address (#444) (bsc#1266604, CVE-2026-39821) * Fork tuned.conf to tuned-x5.conf for X5 series configurations * Enable configureX5 in configureinstance. * Create skeleton implementation and tests for X5 configureinstance support. * Enable detection of x5 machine types in configureinstance - Drop CVE-2026-33186.patch, merged upstream - Drop CVE-2026-33814.patch, merged upstream - Drop CVE-2026-34986.patch, merged upstream ++++ google-osconfig-agent: - Update to version 20260611.00 * Add unit tests for policies/policies.go PART 5 (#998) - from version 20260610.00 * Add unit tests for policies/policies.go PART 4 (#997) - from version 20260609.02 * squash commits (#936) - from version 20260609.01 * Add unit tests for policies/policies.go PART 3 (#996) - from version 20260609.00 * Add unit tests for policies/policies.go PART 2 (#991) - from version 20260602.01 * Align format of dates and timestamp collected across Windows packages (#973) - from version 20260602.00 * Add unit tests for config/config,go (#979) - from version 20260528.00 * Bump github.com/containerd/containerd (#990) - from version 20260521.00 * Cover agentconfig functionality by unit tests (#925) - from version 20260520.04 * Add unit tests for policies/googet.go (#961) * Bump github.com/go-git/go-git/v5 (#987) - from version 20260520.02 * Add unit tests for policies/yum.go (#952) * Add unit tests for policies/apt.go PART 3 (#951) - from version 20260520.00 * Add unit tests for policies/zypper.go (#953) - from version 20260519.00 * Add unit tests for policies/policies.go PART 1 (#949) - from version 20260513.01 * Bump github.com/go-git/go-git/v5 (#981), this also updates golang.org/x/net to v0.53.0 (bsc#1265762, CVE-2026-33814) - from version 20260513.00 * upgrade a few packages (#980) - from version 20260512.02 * Add/improve unit tests for agentendpoint/exec_task.go (#933) - from version 20260512.01 * Cover google_update.go by unit tests (#941) - from version 20260512.00 * Change zone for arm64 builds because of stockout (#978) ++++ hostapd: - bsc#1268083 - hostapd segmentation fault during fast restart cycles. [+ nl80211_NULL_pointer_check_for_link.patch] ++++ product-composer: - update to version 0.9.7 * Support of unpack rpms to agama images * Support of removal of global build_options per flavor ++++ product-composer: - update to version 0.9.7 * Support of unpack rpms to agama images * Support of removal of global build_options per flavor ++++ python-PyJWT: - CVE-2026-48526: JWK JSON accepted as HMAC secret (algorithm confusion) (bsc#1266802) - CVE-2026-48523: Algorithm allow-list bypass with PyJWK / PyJWKClient (bsc#1266799) - CVE-2026-48525: DoS via base64 decode of unused payload segment when b64=false (bsc#1266801) - CVE-2026-48522: PyJWKClient accepts non-HTTP(S) URIs (bsc#1266798) - CVE-2026-48524: PyJWKClient cache wiped on fetch error (bsc#1266800) - added security-fixes.patch to fix above vulnerabilities ++++ yt-dlp: - Update to version 2026.06.09 * Fixed [CVE-2026-50019]: File Downloader cookie leak with curl * Fixed [CVE-2026-50023]: Dangerous file type creation via insufficient filename sanitization * Fixed [CVE-2026-50574]: Arbitrary code execution via manifest downloads with aria2c * Added lockfile and pinned extras * Removed url, desktop and webloc from safe extensions * Extract supplemental codecs from DASH manifests * abematv: Extract subtitles * ard: Support new ardsounds domain * monstercat: Support older URLs * pornhub: Support browser impersonation * reddit: Fix unauthenticated extraction * rtp: Support multi-part episodes and --no-playlist * s4c: Extract more metadata * soop: Adapt extractors to new domain * soundcloud: Support --extractor-retries for original formats * twitch: Remove dead rechat subtitles * twitter: Fix view_count extraction * external: aria2c: Remove support for m3u8/dash protocols * ffmpegmetadata: Avoid erroneous ISO 639 conversions ++++ zypper: - Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software. - version 1.14.98 ------------------------------------------------------------------ ------------------ 2026-6-11 - Jun 11 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaFirefox: - Firefox Extended Support Release 140.12.0 ESR Placeholder changelog-entry (bsc#1268071) ++++ freeipmi: - Fix memory corruption in ipmi-oem-dell.c and ipmi-oem-fujitsu.c bsc#1267605 - CVE-2026-50031 A freeipmi_dell_mem_corruption.fix A freeipmi_fujitsu_buffer_overflow.fix ++++ go1.21: - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. ++++ go1.22: - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. ++++ go1.23: - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. ++++ go1.24: - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. ++++ go1.25: - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. ++++ go1.26: - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. ++++ go1.26-openssl: - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. ++++ golang-github-prometheus-alertmanager: - Fix email tests for Go >= 1.25.11 ++++ golang-github-prometheus-alertmanager: - Fix email tests for Go >= 1.25.11 * Add 0003-Fix-email-test.patch ++++ gtk-vnc: - bsc#1266272 - "virt-manager" is crashing. bsc#1266372 - virt-manager SIGSEGV after few minutes in on_primary_owner_change (.... at ../src/vncdisplay.c:1944 009-let-GLib-manage-the-lifecycle-of-VncDisplay-GObject.patch ++++ libselinux: - Backport patch for restorecon to log error on readonly fs (bsc#1232226) - Added patch: restorecon-Only-log-error-on-readonly-fs-bsc-1232226.patch ++++ systemd: - Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117) ++++ systemd: - Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117) ++++ libvirt: - qemu: Fix invocation of numa-preplace when hugepages requested, but page size not specified bsc#1266364 ++++ loupe: - Update to version 48.2: + Fixed: - Check if the is-hidden property is available before reading it. - Considerably increased speed for listing other images in folders, especially for remote locations. This allows for switching to other images to become available much quicker. - Fix panics, probably occuring when using an action like 'copy', and then closing the window. The crash causes all other windows to close. - The creation date for images that don't provide a timezone was displayed as if the recorded date and time was in UTC. - Zooming in would not work via the zoom menu, if the resulting zoom state would still fit the image inside the window. + Changed: - Track the location in source code of errors trying to get the root window. - Migrate to xz compression and manual service run - Refresh dependencies (bsc#1249009 CVE-2025-58160). ++++ systemd-mini: - Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117) ++++ systemd-mini: - Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117) ------------------------------------------------------------------ ------------------ 2026-6-10 - Jun 10 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - amend CVE-2026-40169 and CVE-2026-42050 fixes [bsc#1265048] - modified patches * ImageMagick-CVE-2026-40169.patch (refreshed) * ImageMagick-CVE-2026-42050.patch (refreshed) ++++ SAPHanaSR-angi: - Version bump to 1.3.4 * Technology preview - Support for DR passive cluster in scale-up performance-optimised setup * XSA standalone node in Mx-setup (one master, one XSA worker) is now in state 'supported' * new tool: SAPHanaSR-showStatus see man page SAPHanaSR-showStatus.8 for information * new man page: SAPHanaSR_multi-target.7 SAPHanaSR_with_DR_HA.7 SAPHanaSR_with_DR_HA_setup.7 SAPHanaSR-showStatus.8 SAPHanaSR-ScaleUp-CostOpt.7 SAPHanaSR-ScaleUp-PerfOpt.7 * update man pages: SAPHanaController-scale-out.7 SAPHanaController-scale-up.7 SAPHanaSR-ScaleOut-XSA.7 SAPHanaSR-ScaleOut.7 SAPHanaSR-ScaleOut_basic_cluster.7 SAPHanaSR-angi-scenarios.7 SAPHanaSR-angi.7 SAPHanaSR.7 SAPHanaSR_basic_cluster.7 SAPHanaSR_maintenance_examples.7 ocf_suse_SAPHanaTopology.7 susCostOpt.py.7 susHanaSR.py.7 SAPHanaSR-alert-fencing.8 SAPHanaSR-manageProvider.8 SAPHanaSR-showAttr.8 - Hint: Versions 1.3.1, 1.3.2 and 1.3.3 were used for POCs with partners and a few customers for some new features. All changes of this 'internal' versions are now integrated in this common released version 1.3.4 ++++ aaa_base: - Update to version 84.87+git20260610.3b5a868c: * Add missing "=" in alljava.csh (boo#1267423) ++++ agama-yast: - always send all params to product activation as new suseconnect-ng do not transfer it from announce system (bsc#1268015) ++++ kernel-64kb: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-azure: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-default: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-rt: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ cyrus-imapd: - Adapt license ++++ python-kiwi: - Fix rereading DASD partition table with partprobe On s390 and with a DASD disk the rereading of the partition table can only be done properly with partprobe. This commit changes the dracut code to Require parted and partprobe only for DASD disks on s390. In addition this commit prevents the active device locking for parted and partprobe when called in the context of a DASD device. The reason for this change is because of a patch in libparted which applies flock() itself in this condition. For details see: https://build.opensuse.org/projects/Base:System/packages/parted/files/libparted-make-BLKRRPART-more-robust.patch?expand=1 This change however does not exist in the upstream version of parted which is causing problems that are hard to solve by kiwi. However, a dead-lock condition should be avoided and I think it's still better to have this change in kiwi and convince people to upstream the above parted fix, rather than living with a dead-lock condition due to double locking in kiwi. This Fixes bsc#1263973 ++++ dtb-aarch64: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ enc: - CVE-2026-1229: Fix incorrect value (bsc#1265533) Bump circl to 1.6.3 ++++ glib-networking: - Add CVE-2026-10028.patch: tls: detect cycles when setting issuer property (CVE-2026-10028, bsc#1267979, glgo#GNOME/glib-networking!279) ++++ helmfile: - Update to version 1.5.3: * build(deps): bump github.com/gookit/color from 1.5.4 to 1.6.1 by @dependabot[bot] in #2608 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.17 to 1.32.18 by @dependabot[bot] in #2610 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.101.0 to 1.102.0 by @dependabot[bot] in #2612 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.102.0 to 1.102.1 by @dependabot[bot] in #2613 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.18 to 1.32.20 by @dependabot[bot] in #2614 * fix: support array of maps in set/setTemplate values by @yxxhero in #2615 * fix: remove naked return by returning expected values by @ceriath in #2617 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.102.1 to 1.103.0 by @dependabot[bot] in #2619 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.20 to 1.32.21 by @dependabot[bot] in #2618 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.103.0 to 1.103.1 by @dependabot[bot] in #2620 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.21 to 1.32.22 by @dependabot[bot] in #2621 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.103.1 to 1.103.2 by @dependabot[bot] in #2622 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.22 to 1.32.23 by @dependabot[bot] in #2623 * Bump helm-diff to v3.15.8 across runtime defaults and execution environments by @Copilot in #2624 * build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 by @dependabot[bot] in #2625 ++++ helmfile: - Update to version 1.5.3: * build(deps): bump github.com/gookit/color from 1.5.4 to 1.6.1 by @dependabot[bot] in #2608 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.17 to 1.32.18 by @dependabot[bot] in #2610 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.101.0 to 1.102.0 by @dependabot[bot] in #2612 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.102.0 to 1.102.1 by @dependabot[bot] in #2613 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.18 to 1.32.20 by @dependabot[bot] in #2614 * fix: support array of maps in set/setTemplate values by @yxxhero in #2615 * fix: remove naked return by returning expected values by @ceriath in #2617 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.102.1 to 1.103.0 by @dependabot[bot] in #2619 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.20 to 1.32.21 by @dependabot[bot] in #2618 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.103.0 to 1.103.1 by @dependabot[bot] in #2620 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.21 to 1.32.22 by @dependabot[bot] in #2621 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.103.1 to 1.103.2 by @dependabot[bot] in #2622 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.22 to 1.32.23 by @dependabot[bot] in #2623 * Bump helm-diff to v3.15.8 across runtime defaults and execution environments by @Copilot in #2624 * build(deps): bump golang.org/x/sync from 0.20.0 to 0.21.0 by @dependabot[bot] in #2625 ++++ kernel-source: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-docs: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-kvmsmall: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-obs-build: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-obs-qa: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-syms: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ kernel-zfcpdump: - Update patches.suse/KVM-arm64-Reassign-nested_mmus-array-behind-mmu_lock.patch (git-fixes CVE-2026-46317 bsc#1268018). - Update patches.suse/KVM-arm64-vgic-its-Drop-the-translation-cache-refere.patch (git-fixes CVE-2026-46316 bsc#1267875). - commit c70d539 ++++ ldns: - patch_cve_2026-10846.diff: insufficient validation of DNS responses (bsc#1267670, CVE-2026-10846) ++++ suseconnect-ng: - Update version to 1.22.1: - library: Allow clients to disable the token handling mechanism (jsc#SCC-801) - Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) ++++ neonmodem: - Update golang.org/x/net dependency to v0.55.0 due to bsc#1267193 ++++ ovmf: - Add ovmf-OvmfPkg-OvmfPkgX64-Add-SevLaunchSecret-and-QemuHashT.patch (bsc#1266809) - 4b1711d431a7 OvmfPkg/MemFd: add AmdSev changes, switch AmdSev build to include added PcdSevLaunchSecretBase and PcdQemuHashTableBase entries to the MEMFD section. However, this could not be applied to edk2-stable202502, so this minimal patch was backported to edk2-stable202502. Testing shows that booting an SEV-SNP guest works fine, and running snpguest generate measurement now succeeds. ++++ policycoreutils: - Reintroduce sandbox package (bsc#1266226) and a couple quality of life improvements: add policycoreutils-sandbox-fix-cleanup.patch add sandbox-sandbox-fix-saving-file-changes.patch ++++ rubygem-agama-yast: - always send all params to product activation as new suseconnect-ng do not transfer it from announce system (bsc#1268015) ------------------------------------------------------------------ ------------------ 2026-6-9 - Jun 9 2026 ------------------- ------------------------------------------------------------------ ++++ alloy: - CVE-2026-41889: Fix SQL injection by bumping github.com/jackc/pgx to version 5.9.2 (bsc#1265440) - add patch 0003-Bump-jackc-pgx.patch ++++ chromium: - Chromium 149.0.7827.102 (boo#1267911): * CVE-2026-11628: Use after free in Ozone * CVE-2026-11629: Use after free in Ozone * CVE-2026-11630: Use after free in File Input * CVE-2026-11631: Use after free in Aura * CVE-2026-11632: Use after free in TabStrip * CVE-2026-11633: Use after free in Bluetooth * CVE-2026-11634: Use after free in Gamepad * CVE-2026-11635: Use after free in Bluetooth * CVE-2026-11636: Use after free in Autofill * CVE-2026-11637: Use after free in Views * CVE-2026-11638: Use after free in Printing * CVE-2026-11639: Use after free in Compositing * CVE-2026-11640: Integer overflow in libyuv * CVE-2026-11641: Use after free in Bluetooth * CVE-2026-11642: Use after free in Web Apps * CVE-2026-11643: Use after free in Proxy * CVE-2026-11644: Use after free in Views * CVE-2026-11645: Out of bounds memory access in V8 * CVE-2026-11646: Use after free in ViewTransitions * CVE-2026-11647: Use after free in Printing * CVE-2026-11648: Use after free in FullScreen * CVE-2026-11649: Use after free in V8 * CVE-2026-11650: Use after free in V8 * CVE-2026-11651: Use after free in Network * CVE-2026-11652: Use after free in Extensions * CVE-2026-11653: Insufficient validation of untrusted input in Extensions * CVE-2026-11654: Use after free in CameraCapture * CVE-2026-11655: Integer overflow in Media * CVE-2026-11656: Use after free in ServiceWorker * CVE-2026-11657: Use after free in Payments * CVE-2026-11658: Insufficient validation of untrusted input in Extensions * CVE-2026-11659: Insufficient validation of untrusted input in UI * CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11661: Use after free in Views * CVE-2026-11662: Type Confusion in Bindings * CVE-2026-11663: Use after free in Skia * CVE-2026-11664: Use after free in Payments * CVE-2026-11665: Out of bounds read in Dawn * CVE-2026-11666: Insufficient validation of untrusted input in Input * CVE-2026-11667: Out of bounds read in WebRTC * CVE-2026-11668: Uninitialized Use in Codecs * CVE-2026-11669: Integer overflow in Media * CVE-2026-11670: Use after free in PDF * CVE-2026-11671: Use after free in Navigation * CVE-2026-11672: Out of bounds write in GPU * CVE-2026-11673: Use after free in InterestGroups * CVE-2026-11674: Use after free in Guest View * CVE-2026-11675: Insufficient validation of untrusted input in Skia * CVE-2026-11676: Insufficient validation of untrusted input in Dawn * CVE-2026-11677: Race in Network * CVE-2026-11678: Integer overflow in libyuv * CVE-2026-11679: Use after free in Codecs * CVE-2026-11680: Use after free in Media * CVE-2026-11681: Use after free in Ozone * CVE-2026-11682: Insufficient validation of untrusted input in Views * CVE-2026-11683: Use after free in WebCodecs * CVE-2026-11684: Insufficient policy enforcement in Network * CVE-2026-11685: Insufficient data validation in MediaCapture * CVE-2026-11686: Insufficient validation of untrusted input in Dawn * CVE-2026-11687: Use after free in Dawn * CVE-2026-11688: Object lifecycle issue in SVG * CVE-2026-11689: Insufficient validation of untrusted input in Passwords * CVE-2026-11690: Out of bounds read and write in Media * CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11692: Use after free in Read Anything * CVE-2026-11693: Inappropriate implementation in Plugins * CVE-2026-11694: Use after free in ServiceWorker * CVE-2026-11695: Inappropriate implementation in Passwords * CVE-2026-11696: Uninitialized Use in Video * CVE-2026-11697: Insufficient validation of untrusted input in UI * CVE-2026-11698: Use after free in Bluetooth * CVE-2026-11699: Use after free in Bluetooth * CVE-2026-11700: Use after free in Tracing * CVE-2026-11701: Insufficient validation of untrusted input in Guest View ++++ chromium: - Chromium 149.0.7827.102 (boo#1267911): * CVE-2026-11628: Use after free in Ozone * CVE-2026-11629: Use after free in Ozone * CVE-2026-11630: Use after free in File Input * CVE-2026-11631: Use after free in Aura * CVE-2026-11632: Use after free in TabStrip * CVE-2026-11633: Use after free in Bluetooth * CVE-2026-11634: Use after free in Gamepad * CVE-2026-11635: Use after free in Bluetooth * CVE-2026-11636: Use after free in Autofill * CVE-2026-11637: Use after free in Views * CVE-2026-11638: Use after free in Printing * CVE-2026-11639: Use after free in Compositing * CVE-2026-11640: Integer overflow in libyuv * CVE-2026-11641: Use after free in Bluetooth * CVE-2026-11642: Use after free in Web Apps * CVE-2026-11643: Use after free in Proxy * CVE-2026-11644: Use after free in Views * CVE-2026-11645: Out of bounds memory access in V8 * CVE-2026-11646: Use after free in ViewTransitions * CVE-2026-11647: Use after free in Printing * CVE-2026-11648: Use after free in FullScreen * CVE-2026-11649: Use after free in V8 * CVE-2026-11650: Use after free in V8 * CVE-2026-11651: Use after free in Network * CVE-2026-11652: Use after free in Extensions * CVE-2026-11653: Insufficient validation of untrusted input in Extensions * CVE-2026-11654: Use after free in CameraCapture * CVE-2026-11655: Integer overflow in Media * CVE-2026-11656: Use after free in ServiceWorker * CVE-2026-11657: Use after free in Payments * CVE-2026-11658: Insufficient validation of untrusted input in Extensions * CVE-2026-11659: Insufficient validation of untrusted input in UI * CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11661: Use after free in Views * CVE-2026-11662: Type Confusion in Bindings * CVE-2026-11663: Use after free in Skia * CVE-2026-11664: Use after free in Payments * CVE-2026-11665: Out of bounds read in Dawn * CVE-2026-11666: Insufficient validation of untrusted input in Input * CVE-2026-11667: Out of bounds read in WebRTC * CVE-2026-11668: Uninitialized Use in Codecs * CVE-2026-11669: Integer overflow in Media * CVE-2026-11670: Use after free in PDF * CVE-2026-11671: Use after free in Navigation * CVE-2026-11672: Out of bounds write in GPU * CVE-2026-11673: Use after free in InterestGroups * CVE-2026-11674: Use after free in Guest View * CVE-2026-11675: Insufficient validation of untrusted input in Skia * CVE-2026-11676: Insufficient validation of untrusted input in Dawn * CVE-2026-11677: Race in Network * CVE-2026-11678: Integer overflow in libyuv * CVE-2026-11679: Use after free in Codecs * CVE-2026-11680: Use after free in Media * CVE-2026-11681: Use after free in Ozone * CVE-2026-11682: Insufficient validation of untrusted input in Views * CVE-2026-11683: Use after free in WebCodecs * CVE-2026-11684: Insufficient policy enforcement in Network * CVE-2026-11685: Insufficient data validation in MediaCapture * CVE-2026-11686: Insufficient validation of untrusted input in Dawn * CVE-2026-11687: Use after free in Dawn * CVE-2026-11688: Object lifecycle issue in SVG * CVE-2026-11689: Insufficient validation of untrusted input in Passwords * CVE-2026-11690: Out of bounds read and write in Media * CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11692: Use after free in Read Anything * CVE-2026-11693: Inappropriate implementation in Plugins * CVE-2026-11694: Use after free in ServiceWorker * CVE-2026-11695: Inappropriate implementation in Passwords * CVE-2026-11696: Uninitialized Use in Video * CVE-2026-11697: Insufficient validation of untrusted input in UI * CVE-2026-11698: Use after free in Bluetooth * CVE-2026-11699: Use after free in Bluetooth * CVE-2026-11700: Use after free in Tracing * CVE-2026-11701: Insufficient validation of untrusted input in Guest View ++++ chromium: - Chromium 149.0.7827.102 (boo#1267911): * CVE-2026-11628: Use after free in Ozone * CVE-2026-11629: Use after free in Ozone * CVE-2026-11630: Use after free in File Input * CVE-2026-11631: Use after free in Aura * CVE-2026-11632: Use after free in TabStrip * CVE-2026-11633: Use after free in Bluetooth * CVE-2026-11634: Use after free in Gamepad * CVE-2026-11635: Use after free in Bluetooth * CVE-2026-11636: Use after free in Autofill * CVE-2026-11637: Use after free in Views * CVE-2026-11638: Use after free in Printing * CVE-2026-11639: Use after free in Compositing * CVE-2026-11640: Integer overflow in libyuv * CVE-2026-11641: Use after free in Bluetooth * CVE-2026-11642: Use after free in Web Apps * CVE-2026-11643: Use after free in Proxy * CVE-2026-11644: Use after free in Views * CVE-2026-11645: Out of bounds memory access in V8 * CVE-2026-11646: Use after free in ViewTransitions * CVE-2026-11647: Use after free in Printing * CVE-2026-11648: Use after free in FullScreen * CVE-2026-11649: Use after free in V8 * CVE-2026-11650: Use after free in V8 * CVE-2026-11651: Use after free in Network * CVE-2026-11652: Use after free in Extensions * CVE-2026-11653: Insufficient validation of untrusted input in Extensions * CVE-2026-11654: Use after free in CameraCapture * CVE-2026-11655: Integer overflow in Media * CVE-2026-11656: Use after free in ServiceWorker * CVE-2026-11657: Use after free in Payments * CVE-2026-11658: Insufficient validation of untrusted input in Extensions * CVE-2026-11659: Insufficient validation of untrusted input in UI * CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11661: Use after free in Views * CVE-2026-11662: Type Confusion in Bindings * CVE-2026-11663: Use after free in Skia * CVE-2026-11664: Use after free in Payments * CVE-2026-11665: Out of bounds read in Dawn * CVE-2026-11666: Insufficient validation of untrusted input in Input * CVE-2026-11667: Out of bounds read in WebRTC * CVE-2026-11668: Uninitialized Use in Codecs * CVE-2026-11669: Integer overflow in Media * CVE-2026-11670: Use after free in PDF * CVE-2026-11671: Use after free in Navigation * CVE-2026-11672: Out of bounds write in GPU * CVE-2026-11673: Use after free in InterestGroups * CVE-2026-11674: Use after free in Guest View * CVE-2026-11675: Insufficient validation of untrusted input in Skia * CVE-2026-11676: Insufficient validation of untrusted input in Dawn * CVE-2026-11677: Race in Network * CVE-2026-11678: Integer overflow in libyuv * CVE-2026-11679: Use after free in Codecs * CVE-2026-11680: Use after free in Media * CVE-2026-11681: Use after free in Ozone * CVE-2026-11682: Insufficient validation of untrusted input in Views * CVE-2026-11683: Use after free in WebCodecs * CVE-2026-11684: Insufficient policy enforcement in Network * CVE-2026-11685: Insufficient data validation in MediaCapture * CVE-2026-11686: Insufficient validation of untrusted input in Dawn * CVE-2026-11687: Use after free in Dawn * CVE-2026-11688: Object lifecycle issue in SVG * CVE-2026-11689: Insufficient validation of untrusted input in Passwords * CVE-2026-11690: Out of bounds read and write in Media * CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11692: Use after free in Read Anything * CVE-2026-11693: Inappropriate implementation in Plugins * CVE-2026-11694: Use after free in ServiceWorker * CVE-2026-11695: Inappropriate implementation in Passwords * CVE-2026-11696: Uninitialized Use in Video * CVE-2026-11697: Insufficient validation of untrusted input in UI * CVE-2026-11698: Use after free in Bluetooth * CVE-2026-11699: Use after free in Bluetooth * CVE-2026-11700: Use after free in Tracing * CVE-2026-11701: Insufficient validation of untrusted input in Guest View ++++ chromium: - Chromium 149.0.7827.102 (boo#1267911): * CVE-2026-11628: Use after free in Ozone * CVE-2026-11629: Use after free in Ozone * CVE-2026-11630: Use after free in File Input * CVE-2026-11631: Use after free in Aura * CVE-2026-11632: Use after free in TabStrip * CVE-2026-11633: Use after free in Bluetooth * CVE-2026-11634: Use after free in Gamepad * CVE-2026-11635: Use after free in Bluetooth * CVE-2026-11636: Use after free in Autofill * CVE-2026-11637: Use after free in Views * CVE-2026-11638: Use after free in Printing * CVE-2026-11639: Use after free in Compositing * CVE-2026-11640: Integer overflow in libyuv * CVE-2026-11641: Use after free in Bluetooth * CVE-2026-11642: Use after free in Web Apps * CVE-2026-11643: Use after free in Proxy * CVE-2026-11644: Use after free in Views * CVE-2026-11645: Out of bounds memory access in V8 * CVE-2026-11646: Use after free in ViewTransitions * CVE-2026-11647: Use after free in Printing * CVE-2026-11648: Use after free in FullScreen * CVE-2026-11649: Use after free in V8 * CVE-2026-11650: Use after free in V8 * CVE-2026-11651: Use after free in Network * CVE-2026-11652: Use after free in Extensions * CVE-2026-11653: Insufficient validation of untrusted input in Extensions * CVE-2026-11654: Use after free in CameraCapture * CVE-2026-11655: Integer overflow in Media * CVE-2026-11656: Use after free in ServiceWorker * CVE-2026-11657: Use after free in Payments * CVE-2026-11658: Insufficient validation of untrusted input in Extensions * CVE-2026-11659: Insufficient validation of untrusted input in UI * CVE-2026-11660: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11661: Use after free in Views * CVE-2026-11662: Type Confusion in Bindings * CVE-2026-11663: Use after free in Skia * CVE-2026-11664: Use after free in Payments * CVE-2026-11665: Out of bounds read in Dawn * CVE-2026-11666: Insufficient validation of untrusted input in Input * CVE-2026-11667: Out of bounds read in WebRTC * CVE-2026-11668: Uninitialized Use in Codecs * CVE-2026-11669: Integer overflow in Media * CVE-2026-11670: Use after free in PDF * CVE-2026-11671: Use after free in Navigation * CVE-2026-11672: Out of bounds write in GPU * CVE-2026-11673: Use after free in InterestGroups * CVE-2026-11674: Use after free in Guest View * CVE-2026-11675: Insufficient validation of untrusted input in Skia * CVE-2026-11676: Insufficient validation of untrusted input in Dawn * CVE-2026-11677: Race in Network * CVE-2026-11678: Integer overflow in libyuv * CVE-2026-11679: Use after free in Codecs * CVE-2026-11680: Use after free in Media * CVE-2026-11681: Use after free in Ozone * CVE-2026-11682: Insufficient validation of untrusted input in Views * CVE-2026-11683: Use after free in WebCodecs * CVE-2026-11684: Insufficient policy enforcement in Network * CVE-2026-11685: Insufficient data validation in MediaCapture * CVE-2026-11686: Insufficient validation of untrusted input in Dawn * CVE-2026-11687: Use after free in Dawn * CVE-2026-11688: Object lifecycle issue in SVG * CVE-2026-11689: Insufficient validation of untrusted input in Passwords * CVE-2026-11690: Out of bounds read and write in Media * CVE-2026-11691: Insufficient validation of untrusted input in New Tab Page * CVE-2026-11692: Use after free in Read Anything * CVE-2026-11693: Inappropriate implementation in Plugins * CVE-2026-11694: Use after free in ServiceWorker * CVE-2026-11695: Inappropriate implementation in Passwords * CVE-2026-11696: Uninitialized Use in Video * CVE-2026-11697: Insufficient validation of untrusted input in UI * CVE-2026-11698: Use after free in Bluetooth * CVE-2026-11699: Use after free in Bluetooth * CVE-2026-11700: Use after free in Tracing * CVE-2026-11701: Insufficient validation of untrusted input in Guest View ++++ cloud-regionsrv-client: - Update to version 11.0.3 + Write instance data cache file after cleaning the cache when the update server fails (bsc#1265930) + Create the cache directory when populating the cache (bsc#1267739) ++++ dealers-choice: - dealers-choice 0.0.14 - Drop 0001-server-skip-buffered-MSG_PING_RESPONSE-at-game-start.patch (fixed upstream) * Replace SDL2_net with tcpme (thin POSIX/Winsock wrapper) + Game-play display overhaul: relative seating (local bottom-centre, opponents clockwise), a bottom dashboard, an anchor-based layout system, and SVG card suits + Configurable game-play action hotkeys via a press-to-bind Hotkeys screen (#102) + The seat that opens each betting round is marked in its nameplate (#264) + Optional timestamped diagnostic logging (--log-file): server slow-send / high-ping / slow-action warnings and client frame-stall / slow-audio warnings, all gated by --verbose (#307) * regression fix: discard-phase timeout now reports 0 cards drawn (#265) * Fix OpenBSD build (#270) * server: skip stray MSG_PING_RESPONSE frames buffered from the lobby, fixing a spurious disconnect on slow/emulated hardware * Move deckhandler and pokeval inline (no longer meson subprojects) * rank-aware wild tiebreak for THREE/FOUR_OF_A_KIND, FULL_HOUSE, FIVE_OF_A_KIND * wild-aware tiebreak for PAIR and TWO_PAIR * fix wild kicker comparison for THREE/FOUR_OF_A_KIND at equal trip/quad value * wild-aware tiebreak for STRAIGHT / STRAIGHT_FLUSH * substitute wild = ACE_HIGH for FLUSH tiebreak * rank-aware PAIR/TWO_PAIR tiebreak in update_best_5card (Omaha / 7-card picker) * route update_best_wild same-rank tiebreak through the wild-aware compare * bugfix: run audio init on a background thread with silent fallback, so a blocked audio backend can't freeze the window * Bump GAME_PROTOCOL_VERSION from 9 to 10 ++++ dealers-choice: - dealers-choice 0.0.14 - Drop 0001-server-skip-buffered-MSG_PING_RESPONSE-at-game-start.patch (fixed upstream) * Replace SDL2_net with tcpme (thin POSIX/Winsock wrapper) + Game-play display overhaul: relative seating (local bottom-centre, opponents clockwise), a bottom dashboard, an anchor-based layout system, and SVG card suits + Configurable game-play action hotkeys via a press-to-bind Hotkeys screen (#102) + The seat that opens each betting round is marked in its nameplate (#264) + Optional timestamped diagnostic logging (--log-file): server slow-send / high-ping / slow-action warnings and client frame-stall / slow-audio warnings, all gated by --verbose (#307) * regression fix: discard-phase timeout now reports 0 cards drawn (#265) * Fix OpenBSD build (#270) * server: skip stray MSG_PING_RESPONSE frames buffered from the lobby, fixing a spurious disconnect on slow/emulated hardware * Move deckhandler and pokeval inline (no longer meson subprojects) * rank-aware wild tiebreak for THREE/FOUR_OF_A_KIND, FULL_HOUSE, FIVE_OF_A_KIND * wild-aware tiebreak for PAIR and TWO_PAIR * fix wild kicker comparison for THREE/FOUR_OF_A_KIND at equal trip/quad value * wild-aware tiebreak for STRAIGHT / STRAIGHT_FLUSH * substitute wild = ACE_HIGH for FLUSH tiebreak * rank-aware PAIR/TWO_PAIR tiebreak in update_best_5card (Omaha / 7-card picker) * route update_best_wild same-rank tiebreak through the wild-aware compare * bugfix: run audio init on a background thread with silent fallback, so a blocked audio backend can't freeze the window * Bump GAME_PROTOCOL_VERSION from 9 to 10 ++++ elemental: - Update to v2.3.1: * c47d91b Adapt labels to pass containers checks in OBS * 88015da set to released-stage to released as SL Micro 6.2 is GA * 6f8ca5a Fix specfile dependencies ++++ junit5: - Build also the modules junit-platform-engine and junit-platform-launcher within the flavour bootstrap. This does not pull in other dependencies and allows the majority of consumers of junit5 build early against the junit5-minimal package ++++ junit5-minimal: - Build also the modules junit-platform-engine and junit-platform-launcher within the flavour bootstrap. This does not pull in other dependencies and allows the majority of consumers of junit5 build early against the junit5-minimal package ++++ pcg-c: - pcg 0.94.2 - Fix signed integer overflow UB in `pcg_advance_lcg_8` and `pcg_advance_lcg_16`: C's integer promotion rules convert `uint8_t`/`uint16_t` operands to signed `int` before arithmetic; large 16-bit products exceed `INT32_MAX`, triggering undefined behavior caught by UBSan. Cast through the next-wider unsigned type to keep all multiplications in unsigned arithmetic. - When built as a Meson subproject, install nothing and skip the tests/samples. - Honour `-Ddefault_library=static` on non-Windows builds (previously always shared). - Add a `build_samples` option (default off) to build the sample programs. - Raise the declared Meson minimum to 0.58.0 to match features already in use (silences a setup-time warning). ++++ open-vmdk: - Add Legal-Review-Notice for pytest/configs/EULA.txt, which is only pytest test fixture data and is not shipped in the binary RPM. ++++ python-paramiko: - CVE-2026-44405: data integrity compromise due to allowed SHA-1 algorithm use (bsc#1264225) * added CVE-2026-44405.patch ++++ python-Django: - Add security patches: * CVE-2026-6873: Signed cookie salt namespace collision (bsc#1267578) * CVE-2026-6873.patch * CVE-2026-7666: Potential unencrypted email transmission via STARTTLS in the SMTP backend (bsc#1267579) * CVE-2026-7666.patch * CVE-2026-8404: Potential exposure of private data via case-sensitive Cache-Control directives (bsc#1267580) * CVE-2026-8404.patch * CVE-2026-35193: Potential exposure of private data via missing Vary: Authorization (bsc#1267576) * CVE-2026-35193.patch * CVE-2026-48587: Potential exposure of private data via whitespace padding in Vary header (bsc#1267577) * CVE-2026-48587.patch ------------------------------------------------------------------ ------------------ 2026-6-8 - Jun 8 2026 ------------------- ------------------------------------------------------------------ ++++ apptainer: - Update apptainer to version v1.5.1 * Security fix (bsc#1267982): Fix for CVE-2026-48785 / GHSA-cr2j-534f-mf3g. Incorrect path matching for limit container paths directive. This is only applicable to SUID installations that have paths listed in limit container paths that are string prefixes of other paths which are not desired to be included in the list. For example, if /scratch is in the list but `/scratch2` also exists and contains container images, previously the latter would match but now only images under the exactly matching `/scratch` are included. Other changes: * Work around segmentation fault sometimes seen while `mksquashfs` under proot is creating a SIF file. * Update bundled PRoot to version 5.4.0-rootless.3 in order to fix a problem where SIF files could be corrupted when `mksquashfs` died with a signal. The proot command was not passing back an error exit code. * Updated bundled `squashfuse_ll` to version 0.6.2 in order to fix a crash sometimes seen with apptainer in unprivileged docker. * Update bundled fuse2fs to version 1.47.4 instead of patching the bugs in 1.47.3. * Fix a crash that happened when `/etc/resolv.conf` was a symlink while building from a definition file using the localimage bootstrap. * Support hosts that have an /etc/resolv.conf symlink pointing to `../run` in addition to `/run`. * Change the download-dependencies script to skip downloading the PRoot source code on architectures that it is known to not support (that is: ppc*, s390*, and riscv*). In those situations Apptainer will skip trying to compile and run proot. As a result original owners and groups of files will not be preserved in SIF images built by unprivileged users, as was the case for all architectures prior to 1.5.0. * Fix panic encountered during progress bar update while pulling image. * Fix fakeroot overwriting root's username in `/etc/passwd` with the host user's name, a regression introduced in v1.5.0. * Add nonested flag for --mount specifications to prevent individual bind mounts from being passed to nested containers via `APPTAINER_BIND`. Example: `--mount type=bind,source=/data,destination=/mnt,nonested`. - Changes from version v1.5.0: New Features & Functionalities * Add support for a subset of the Container Device Interface (CDI) standard through new `--device` and `--cdi-dirs run/shell/exec` options. Honors environment variable settings, bind mounts, and device files listed in CDI specification files. * Add support for selective mounting of Intel(R) Gaudi accelerators. This feature is only for use in combination with a minimal /dev directory, selected either with the `--contain` flag or by configuring mount dev with the minimal option; otherwise all the devices are available anyway. This feature is enabled via the `--intel-hpu option` and by specifying the HABANA_VISIBLE_DEVICES environment variable, which should contain a comma-separated list of device IDs (e.g., "1,2,3") or "all" to import all of them. The default if `HABANA_VISIBLE_DEVICES` is not set is "all". * Add support for downloading SIF images from an IPFS peer-to-peer cluster using an HTTP gateway (similar to the existing support for IPFS in the curl tool). The address of the gateway can be set in the `IPFS_GATEWAY` environment variable or read from ~/.ipfs/gateway or /etc/ipfs/gateway. * Add `--no-env` action and instance option and corresponding `APPTAINER_NOENV` environment variable that can provide a comma-separated list of environment variables to skip importing from the host environment into the container. * Add `--data` build option which creates a SIF file with a squashfs data partition instead of a code partition, given an existing squashfs file as the source. * If `PREPEND_LD_LIBRARY_PATH` is set in the container environment (through an `--env` option, an `APPTAINERENV_` prefix from the host, or in the container definition) then prepend that string to `:$LD_LIBRARY_PATH`. Likewise if `APPEND_LD_LIBRARY_PATH` is set in the container environment then append that string to `$LD_LIBRARY_PATH:`. This is only done when `LD_LIBRARY_PATH` is set, although if the container is based on glibc, when `LD_LIBRARY_PATH` is not set it will first be filled with the default library search path as found through ldconfig. * Create reproducible SIF images, if the environment variable `SOURCE_DATE_EPOCH` has been set (as a Unix timestamp given as seconds since the beginning of 1970, in the UTC timezone). Also add `--reproducible` flag to build and pull from `oras://` sources. This sets `SOURCE_DATE_EPOCH` automatically from the image "created" time. * Support hosts that have `/etc/resolv.conf` pointing to a symlink under /run, such as those hosts that are running systemd-resolved. In this case, the symlink is copied into the container and the parent directory of the target of the symlink is bind-mounted from the host. The result is that even if the target of the symlink is replaced with a new file, the container sees the update in `/etc/resolv.conf`. * Add `/etc/resolv.conf` to the list of host paths that can be prevented from automatic import into the container with the `--no-mount` option. * Preserve owner and group information on files in containers downloaded from OCI registries when building SIF files, even for unprivileged users. This takes advantage of the fact that the library (umoci) that downloads containers preserves owner and group information in an extended attribute. Adds bundled tool proot which is modified from the upstream tool by the rootless-containers project to make the owner and group appear to be in the ordinary `stat()` information. That tool is now used when invoking mksquashfs to create the filesystem partition in a SIF file. It can be disabled with the hidden build option `--ignore-proot`. * When unsquashing an image while running under a root-mapped user namespace (such as when using fakeroot without subuid mapping), insert another namespace mapping back to the original user so unsquashfs doesn't try (and fail) to change the owner and group information on the unpacked files. * Record image digest metadata (sha256 from RepoDigests), for OCI registry images. Also add the image name (ref) of the image from "docker", with registry and tag. This is useful for traceability, when using docker.io or a tag like latest. Unfortunately the feature does not work with "docker-archive" or "docker-daemon". * Apptainer now supports the `loong64` architecture. Changed defaults / behaviours * If libraries are bound in to `/.singularity.d/libs` (such as with GPU options like `--nv`) and the container is based on glibc and `LD_LIBRARY_PATH` is not already set, it is now set to the default library search path. Since `/.singularity.d/libs` is appended to `LD_LIBRARY_PATH`, this makes libraries installed in the container take precedence over libraries bound in from the host. This reduces the chances of mismatched glibc versions. However, if there are indeed libraries on the host that need to take precedence over libraries in the container, that can be forced with `PREPEND_LD_LIBRARY_PATH=/.singularity.d/libs`. * Change the default arm variant to v7, and stop using the GOARM environment variable. The variables GOOS, GOARCH and GOARM are only used when building. * The oras transport now supports architectures beyond amd64. Images downloaded from oras without using the cache are now checksummed. A progress bar is shown during the process. Add support for APPTAINER_TMPDIR to the commands apptainer overlay create and apptainer plugin compile. Bug Fixes: * Make the root default capabilities configuration option apply only to the real root user as documented and not to a fakeroot user. * Fix long-time bug in importing environment variables from oci containers (defined by `ENV` in their definition file) with shell characters in them. It now escapes them with single backslashes instead of double backslashes so they behave like they do in podman and docker. * The username in `/etc/passwd` inside a container now always corresponds to the username of the user on the host even if an entry with the same UID is found in the container. * When apptainer reinvokes itself on behalf of the run-help command, it passes through `LD_LIBRARY_PATH`. This makes it work correctly when it was installed with `install-unprivileged.sh` on a host operating system that's different than the one the installed binaries were built on. ++++ apptainer: - Update apptainer to version v1.5.1 * Security fix (bsc#1267982): Fix for CVE-2026-48785 / GHSA-cr2j-534f-mf3g. Incorrect path matching for limit container paths directive. This is only applicable to SUID installations that have paths listed in limit container paths that are string prefixes of other paths which are not desired to be included in the list. For example, if /scratch is in the list but `/scratch2` also exists and contains container images, previously the latter would match but now only images under the exactly matching `/scratch` are included. * Security fix for CVE-2026-2303 (bsc#1270529): Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver. The dependency on mongo-driver has been removed with this version of apptainer. Other changes: * Work around segmentation fault sometimes seen while `mksquashfs` under proot is creating a SIF file. * Update bundled PRoot to version 5.4.0-rootless.3 in order to fix a problem where SIF files could be corrupted when `mksquashfs` died with a signal. The proot command was not passing back an error exit code. * Updated bundled `squashfuse_ll` to version 0.6.2 in order to fix a crash sometimes seen with apptainer in unprivileged docker. * Update bundled fuse2fs to version 1.47.4 instead of patching the bugs in 1.47.3. * Fix a crash that happened when `/etc/resolv.conf` was a symlink while building from a definition file using the localimage bootstrap. * Support hosts that have an /etc/resolv.conf symlink pointing to `../run` in addition to `/run`. * Change the download-dependencies script to skip downloading the PRoot source code on architectures that it is known to not support (that is: ppc*, s390*, and riscv*). In those situations Apptainer will skip trying to compile and run proot. As a result original owners and groups of files will not be preserved in SIF images built by unprivileged users, as was the case for all architectures prior to 1.5.0. * Fix panic encountered during progress bar update while pulling image. * Fix fakeroot overwriting root's username in `/etc/passwd` with the host user's name, a regression introduced in v1.5.0. * Add nonested flag for --mount specifications to prevent individual bind mounts from being passed to nested containers via `APPTAINER_BIND`. Example: `--mount type=bind,source=/data,destination=/mnt,nonested`. - Changes from version v1.5.0: New Features & Functionalities * Add support for a subset of the Container Device Interface (CDI) standard through new `--device` and `--cdi-dirs run/shell/exec` options. Honors environment variable settings, bind mounts, and device files listed in CDI specification files. * Add support for selective mounting of Intel(R) Gaudi accelerators. This feature is only for use in combination with a minimal /dev directory, selected either with the `--contain` flag or by configuring mount dev with the minimal option; otherwise all the devices are available anyway. This feature is enabled via the `--intel-hpu option` and by specifying the HABANA_VISIBLE_DEVICES environment variable, which should contain a comma-separated list of device IDs (e.g., "1,2,3") or "all" to import all of them. The default if `HABANA_VISIBLE_DEVICES` is not set is "all". * Add support for downloading SIF images from an IPFS peer-to-peer cluster using an HTTP gateway (similar to the existing support for IPFS in the curl tool). The address of the gateway can be set in the `IPFS_GATEWAY` environment variable or read from ~/.ipfs/gateway or /etc/ipfs/gateway. * Add `--no-env` action and instance option and corresponding `APPTAINER_NOENV` environment variable that can provide a comma-separated list of environment variables to skip importing from the host environment into the container. * Add `--data` build option which creates a SIF file with a squashfs data partition instead of a code partition, given an existing squashfs file as the source. * If `PREPEND_LD_LIBRARY_PATH` is set in the container environment (through an `--env` option, an `APPTAINERENV_` prefix from the host, or in the container definition) then prepend that string to `:$LD_LIBRARY_PATH`. Likewise if `APPEND_LD_LIBRARY_PATH` is set in the container environment then append that string to `$LD_LIBRARY_PATH:`. This is only done when `LD_LIBRARY_PATH` is set, although if the container is based on glibc, when `LD_LIBRARY_PATH` is not set it will first be filled with the default library search path as found through ldconfig. * Create reproducible SIF images, if the environment variable `SOURCE_DATE_EPOCH` has been set (as a Unix timestamp given as seconds since the beginning of 1970, in the UTC timezone). Also add `--reproducible` flag to build and pull from `oras://` sources. This sets `SOURCE_DATE_EPOCH` automatically from the image "created" time. * Support hosts that have `/etc/resolv.conf` pointing to a symlink under /run, such as those hosts that are running systemd-resolved. In this case, the symlink is copied into the container and the parent directory of the target of the symlink is bind-mounted from the host. The result is that even if the target of the symlink is replaced with a new file, the container sees the update in `/etc/resolv.conf`. * Add `/etc/resolv.conf` to the list of host paths that can be prevented from automatic import into the container with the `--no-mount` option. * Preserve owner and group information on files in containers downloaded from OCI registries when building SIF files, even for unprivileged users. This takes advantage of the fact that the library (umoci) that downloads containers preserves owner and group information in an extended attribute. Adds bundled tool proot which is modified from the upstream tool by the rootless-containers project to make the owner and group appear to be in the ordinary `stat()` information. That tool is now used when invoking mksquashfs to create the filesystem partition in a SIF file. It can be disabled with the hidden build option `--ignore-proot`. * When unsquashing an image while running under a root-mapped user namespace (such as when using fakeroot without subuid mapping), insert another namespace mapping back to the original user so unsquashfs doesn't try (and fail) to change the owner and group information on the unpacked files. * Record image digest metadata (sha256 from RepoDigests), for OCI registry images. Also add the image name (ref) of the image from "docker", with registry and tag. This is useful for traceability, when using docker.io or a tag like latest. Unfortunately the feature does not work with "docker-archive" or "docker-daemon". * Apptainer now supports the `loong64` architecture. Changed defaults / behaviours * If libraries are bound in to `/.singularity.d/libs` (such as with GPU options like `--nv`) and the container is based on glibc and `LD_LIBRARY_PATH` is not already set, it is now set to the default library search path. Since `/.singularity.d/libs` is appended to `LD_LIBRARY_PATH`, this makes libraries installed in the container take precedence over libraries bound in from the host. This reduces the chances of mismatched glibc versions. However, if there are indeed libraries on the host that need to take precedence over libraries in the container, that can be forced with `PREPEND_LD_LIBRARY_PATH=/.singularity.d/libs`. * Change the default arm variant to v7, and stop using the GOARM environment variable. The variables GOOS, GOARCH and GOARM are only used when building. * The oras transport now supports architectures beyond amd64. Images downloaded from oras without using the cache are now checksummed. A progress bar is shown during the process. Add support for APPTAINER_TMPDIR to the commands apptainer overlay create and apptainer plugin compile. Bug Fixes: * Make the root default capabilities configuration option apply only to the real root user as documented and not to a fakeroot user. * Fix long-time bug in importing environment variables from oci containers (defined by `ENV` in their definition file) with shell characters in them. It now escapes them with single backslashes instead of double backslashes so they behave like they do in podman and docker. * The username in `/etc/passwd` inside a container now always corresponds to the username of the user on the host even if an entry with the same UID is found in the container. * When apptainer reinvokes itself on behalf of the run-help command, it passes through `LD_LIBRARY_PATH`. This makes it work correctly when it was installed with `install-unprivileged.sh` on a host operating system that's different than the one the installed binaries were built on. ++++ kernel-64kb: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-azure: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-default: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-rt: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ dtb-aarch64: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ glab: - Update to version 1.102.0: * Features - 044e5b03: feat(api): forward DUO_WORKFLOW_WORKFLOW_ID as X-Gitlab-Duo-Workflow-Id header (Eduardo Bonet ebonet@gitlab.com) - 12cfcf44: feat(api): forward GITLAB_DUO_SESSION_ID as X-Gitlab-Duo-Session-Id header (Eduardo Bonet ebonet@gitlab.com) - d64700ce: feat(repo): add prune command to delete merged local branches (Kai Armstrong karmstrong@gitlab.com) - e1cd4cf0: feat(skills): notify when installed skills have updates (Kai Armstrong karmstrong@gitlab.com) - fadd3939: feat(whatsnew): add command and post-upgrade banner (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - d914d050: fix(api): URL-encode magic placeholder substitutions (Kai Armstrong karmstrong@gitlab.com) - 98a00775: fix(binarymgr): sort packages by semver client-side (Kai Armstrong karmstrong@gitlab.com) * Documentation - 65169664: docs(duo): expand MR review instructions from 3 to 17 blocks (Kai Armstrong karmstrong@gitlab.com) - 38602dd2: docs(iteration): add synopsis and examples to iteration commands (Brendan Lynch blynch@gitlab.com) - 2f6cb6d5: docs(mr): add synopsis and examples to mr commands (Brendan Lynch blynch@gitlab.com) - 40d9474f: docs(opentofu): add synopsis and examples to opentofu commands (Brendan Lynch blynch@gitlab.com) - a9fe77fd: docs(release): add synopsis and examples to release commands (Brendan Lynch blynch@gitlab.com) - ecd623cb: docs(repo): add synopsis and fix usage notation in repo commands (Brendan Lynch blynch@gitlab.com) - d788de5e: docs(snippet): add synopsis and examples to snippet commands (Brendan Lynch blynch@gitlab.com) - 49f80867: docs(todo): add synopsis and examples to todo commands (Brendan Lynch blynch@gitlab.com) - 42fb614b: docs: Format quoted command references as code in env vars table (Ben Bodenmiller bbodenmiller@gmail.com) - c9507bbf: docs: add synopsis and examples to issue and incident commands (Brendan Lynch blynch@gitlab.com) - eb4fec3f: docs: add synopsis and examples to misc standalone commands (Brendan Lynch blynch@gitlab.com) - 5f87ec4c: docs: document GLAB_NO_PROMPT and mark NO_PROMPT deprecated (Ben Bodenmiller bbodenmiller@gmail.com) - f4b2593b: docs: fix flag punctuation and example formatting (quick wins) (Brendan Lynch blynch@gitlab.com) - d9a6681e: docs: update AGENTS.md with comprehensive agent instructions (Brendan Lynch blynch@gitlab.com) - 2e64fa29: docs: update README environment variables (Brendan Lynch blynch@gitlab.com) - 6734e7ab: docs: update env vars table to use GLAB_ prefixed names (Kate Grechishkina khrechyshkina@gitlab.com) * Dependencies - d8ca77c7: chore(deps): update dependency @commitlint/config-conventional to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 21f186ce: chore(deps): update dependency @commitlint/read to ^21.0.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - d4a4afeb: chore(lint): enable 19 new linters and address violations (Kai Armstrong karmstrong@gitlab.com) - 19c91cc9: refactor(config): canonical schema with config set validation (Kai Armstrong karmstrong@gitlab.com) - 98cbeebf: refactor(config): do not use StubConfig in tests (Timo Furrer tfurrer@gitlab.com) - 1e5735ef: refactor(config): follow ups (Timo Furrer tfurrer@gitlab.com) - bced871c: refactor(config): give each Config its own persistence directory (Timo Furrer tfurrer@gitlab.com) - a95fae2a: refactor(config): remove global config stubbers (Timo Furrer tfurrer@gitlab.com) - 769e47ec: refactor(glrepo): inject config instead of reaching for the global (Timo Furrer tfurrer@gitlab.com) - refactor patch glab-disable_update_check.patch to have it apply to the current code base ++++ gosec: - Update to version 2.27.1: * Downgrade google lib to avoid min Go version bump (#1687) * Downgrade the jsonschema dep to v0.13.0 due to incompatibility with anthropick-sdk-go (#1686) * Update all dependencies (#1685) * Downgrade the github.com/invopop/jsonschema v0.13.0 to solve incopatibility with anthropic-sdk (#1683) * Update all dependencies (#1682) * Update vulnerabilities alerts for indirect dependencies * Pin dependencies (#1681) * Skip pining for my repos * Update renovate configuration * Fix typo * Update branch config in renovate config * Migrate config renovate.json (#1678) * Update renovate to refresh the branch creation * Update the renovate branch prefix * Update renovate config to pin the actions dependencies by digests (#1676) * Migrate the html remport to react v19. (#1675) * Manually update version to fix renovate (#1674) * feat: integrate Atlas Cloud provider (#1672) * Refactor error position parsing to support path with colon. (#1673) * Add two options to require rule ID and justificaiton for inline annotations (#1671) * Fix false positive in G118 when cancel is stored in a slice/map (#1670) * chore(go): update supported Go versions to 1.25.10 and 1.26.3 (#1669) * Harden the github workflows and action (#1665) * Fix justification delimiter in annotation format doc (#1661) * Update all dependencies (#1664) * Update action to use gosec version v2.26.1 (#1660) ++++ graphite2: - added patches CVE-2026-50593: Out-of-bounds write via Graphite actions [bsc#1267733] * graphite2-CVE-2026-50593.patch ++++ kernel-source: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-docs: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-kvmsmall: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-obs-build: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-obs-qa: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-syms: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ kernel-zfcpdump: - config: remove DEBUG_FS_DISALLOW_MOUNT DEBUG_FS_DISALLOW_MOUNT was removed by the following SUSE commit: 5697d6916a00 debugfs: Remove broken no-mount mode (bsc#1265186) Clean up config files by deleting CONFIG_DEBUG_FS_DISALLOW_MOUNT - commit 3cc7250 - KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). - commit b3cd8ff - KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). - commit e33b225 - KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (git-fixes). - commit 02c6192 - ALSA: aloop: Fix peer runtime UAF during format-change stop (CVE-2026-46090 bsc#1267531). - ALSA: aloop: Use guard() for spin locks (CVE-2026-46090 bsc#1267531). - commit fedd5b0 - perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415 CVE-2026-43150) - commit 100fc92 - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - commit ec5fd83 - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - accel/ivpu: Add bounds checks for firmware log indices (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - commit 83128fd ++++ libinput-extra: - Add libinput-cve-2026-50265.patch: sanitize phys before printing it (bsc#1267852 CVE-2026-50265 CVE-2026-50292 glfdo#libinput/libinput#1296). ++++ libinput: - Add libinput-cve-2026-50265.patch: sanitize phys before printing it (bsc#1267852 CVE-2026-50265 CVE-2026-50292 glfdo#libinput/libinput#1296). ++++ libzypp: - A .repo files "path=" entry must not refer to a location outside the repo (bsc#1267874, CVE-2026-44942) A "path=" entry may solely denote a sub-directory of the baseurl where the metadata are located. A relative path trying to access data outside the baseurl is reported and sanitized. - version 17.38.13 (35) ++++ perl-Cpanel-JSON-XS: - updated to 4.420.0 (4.42) see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes 4.42 2026-06-27 (rurban) - Ensure encode with a type spec hashref does not change the hashref argument (GH #240) - Fix -e docs: "written" → "read" (GH #239, reported by Ron Savage). - Fix Boolean eq overload matching undef (GH #207, reported by fd-t). Cpanel::JSON::XS::Boolean overloaded eq would match undef as equal to false because undef stringifies to "". Added defined() guard. - Fix error messages showing overloaded stringification for blessed objects (GH #191, reported by karenetheridge). Error messages now use ClassName=TYPE(addr) format, bypassing any "" overload. - Fix type_all_string overriding allow_blessed/convert_blessed (GH #175, reported by alpha6). With type_all_string + allow_blessed, blessed objects are now encoded as null (not stringified as HASH address). - Fix infinite recursion when encode is called from a "" overload (GH #128, reported by pbrthemaster). The recursion guard temporarily clears convert_blessed and allow_stringify flags on the JSON object before calling the overload, preventing re-entrant encode loops. - Fix $obj->new creating a broken object (GH #93, reported by cpansprout). When new() is called on an existing object (e.g. $json->new->new), the class name is now extracted from the object's stash rather than using the stringified reference. - Change allow_nonref default to true (GH #241, matching JSON::PP and JSON::XS 4.0+ and the insecure RFC 7159). encode and decode now accept non-reference values by default. decode_json() with an explicit 0/1 second argument still works. allow_nonref(0) to disable scalars-only for secure JSON. - Fix minor t/12_blessed.t typo. - Fix GH #112: encode large whole-number NV values without .0 on 32-bit Perl (values exceeding UV_MAX that Perl stores as float). - Fix GH #197: prefer IOK over pNOK when encoding values where IV is accurate but NV is imprecise (SvNOK not set). ++++ perl-DBI: - added patches CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow [bsc#1267849] * perl-DBI-CVE-2026-10879.patch ++++ perl-HTML-Parser: - added patches CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities [bsc#1267606] * perl-HTML-Parser-CVE-2026-8829.patch ++++ perl-Protocol-HTTP2: - added patches CVE-2026-10725: denial of service due to absence of inbound HPACK header-list size limit (HTTP/2 Bomb attack) [bsc#1267857] * perl-Protocol-HTTP2-CVE-2026-10725.patch ++++ tree-sitter-ruby: - Use correct tree-sitter dirname instead of tree_sitter (bsc#1267461). - Remove empty tree-sitter-ruby-0.23.1-dependencies.patch. - Remove redundant Neovim workaround - Fix order of entries in the changelog. ------------------------------------------------------------------ ------------------ 2026-6-6 - Jun 6 2026 ------------------- ------------------------------------------------------------------ ++++ dnscrypt-proxy: - Update to version 2.1.16 * The "tls_cipher_suite" option is now a no-op. Modern TLS stacks no longer expose cipher suite selection in a meaningful way, and the option had become misleading * A log size of 0 no longer means "unlimited"; it now correctly disables rotation by size * A new "tls_prefer_rsa" option has been added to prefer RSA cipher suites during the TLS handshake, useful on systems without hardware AES * The IP allow/block plugins now support CIDR ranges in addition to single addresses and prefix matching * Forwarding rules now support `$RESOLVCONF:` to pick up upstream resolvers from a resolv.conf-style file, complementing the existing `$DHCP` syntax * Servers that hit a transient high RTT could previously stay penalized forever and never come back into rotation; their RTT estimate now decays so they can recover * Servers are no longer penalized for slow responses when the response is actually being served from the stale cache * The HTTP transport now handles `Alt-Svc: clear` properly and reuses HTTP connections more aggressively * The cache TTL is now an explicit, configurable parameter rather than being derived implicitly * The ""-resolve"" command now reports incomplete DNSSEC support instead of silently treating partial signatures as a success * "jsdelivr is now offered as an alternative source URL for resolver lists, providing more redundancy when the primary mirrors are unreachable - boo#1260280: vendored google.golang.org/grpc v1.80.0 - boo#1265785: vendored golang.org/x/net v0.54.0 ------------------------------------------------------------------ ------------------ 2026-6-5 - Jun 5 2026 ------------------- ------------------------------------------------------------------ ++++ agama-yast: - Fixed using a custom password-protected installation repository (bsc#1258701) ++++ agama-yast: - Fixed using a custom password-protected installation repository (bsc#1258701) ++++ kernel-64kb: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-azure: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-default: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-rt: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-aarch64-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-aarch64-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-amdgcn-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-arm-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-arm-none-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-avr-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-bpf-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-hppa-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-nvptx-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-ppc64-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-ppc64le-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-ppc64le-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-pru-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-riscv64-elf-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-riscv64-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-riscv64-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-rx-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-s390x-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-s390x-gcc15-bootstrap: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ cross-x86_64-gcc15: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ dtb-aarch64: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ gcc15-testresults: - Update to GCC 15 branch head, 15.2.1+git11263, GCC 15.3 RC1 - Drop -fhardened from RPM_OPT_FLAGS ++++ grafana: - CVE-2026-39821: Fix validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) * Added 0009-Bump-golang.org-x-net.patch ++++ grafana: - CVE-2026-39821: Fix validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) * Fix multiple issues when parsing HTML files (bsc#1267153): CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506 * Added 0009-Bump-golang.org-x-net.patch ++++ kernel-source: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-docs: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-kvmsmall: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-obs-build: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-obs-qa: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-syms: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ kernel-zfcpdump: - netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (CVE-2026-43026 bsc#1263932). - commit 8e1a72c - xfs: don't irele after failing to iget in xfs_attri_recover_work (CVE-2026-43063 bsc#1264196). - commit c357138 - xfs: stop reclaim before pushing AIL during unmount (CVE-2026-31455 bsc#1262615). - commit 1c66a53 - nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (CVE-2026-43394 bsc#1265081). - commit c214b89 - btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (CVE-2026-43393 bsc#1264723). - commit 07e9329 - Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" (bsc#1264842 CVE-2025-71300) - commit 3f93f34 - pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724 CVE-2026-31655) - commit 5f829ce - xfs: scrub: unlock dquot before early return in quota scrub (CVE-2026-31556 bsc#1263062). - commit 21140af - selftests/bpf: Test access from RO map from xdp_store_bytes (CVE-2026-45886 bsc#1266810). - commit cefe3fc - bpf: Fix bpf_xdp_store_bytes proto for read-only arg (CVE-2026-45886 bsc#1266810). - commit 432d546 - xfs: save ailp before dropping the AIL lock in push callbacks (CVE-2026-31454 bsc#1262624). - commit 8c595ea - bpf: Fix regsafe() for pointers to packet (CVE-2026-43030 bsc#1264000). - commit 18dc85e - bpf: Fix tcx/netkit detach permissions when prog fd isn't given (CVE-2026-45932 bsc#1266827). - commit 8aff7da - spi: fix resource leaks on device setup failure (bsc#1266696 CVE-2026-46083) - commit bc027b4 - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - commit e5e351d - selftests/bpf: __not_msg() tag for test_loader framework (CVE-2026-43009 bsc#1264014). - commit 0877ac8 - btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652,CVE-2026-46159). - commit df3cd12 ++++ sqlite3: - Update to version 3.53.2: * Fixes for problems in 3.53.0 reported by users. * bsc#1268013, CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension. * bsc#1268012, CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension. * See the check-in timeline for details: https://sqlite.org/src/timeline?from=version-3.53.1&to=version-3.53.2 ++++ libzypp: - Repo "keyhint" must denote a filename, no path (bsc#1267426, CVE-2026-44941) - version 17.38.12 (35) ++++ os-autoinst: - Update to version 5.1780506677.7bacdcd: * test: enable pretty serial markers in full-stack test * test: replace Core 7.2 ISO with bash-remastered version * test: add script to remaster Core ISO with bash * feat!: fail by default if always_rollback is not supported * fix: Clean up the last VM disks to avoid disk image creation failure * fix: script_run - type command and marker together on serial console * fix: fail explicitly on test module basename collisions ++++ os-autoinst: - Update to version 5.1780506677.7bacdcd: * test: enable pretty serial markers in full-stack test * test: replace Core 7.2 ISO with bash-remastered version * test: add script to remaster Core ISO with bash * feat!: fail by default if always_rollback is not supported * fix: Clean up the last VM disks to avoid disk image creation failure * fix: script_run - type command and marker together on serial console * fix: fail explicitly on test module basename collisions ++++ os-autoinst: - Update to version 5.1780506677.7bacdcd: * test: enable pretty serial markers in full-stack test * test: replace Core 7.2 ISO with bash-remastered version * test: add script to remaster Core ISO with bash * feat!: fail by default if always_rollback is not supported * fix: Clean up the last VM disks to avoid disk image creation failure * fix: script_run - type command and marker together on serial console * fix: fail explicitly on test module basename collisions ++++ rubygem-agama-yast: - Fixed using a custom password-protected installation repository (bsc#1258701) ++++ rubygem-agama-yast: - Fixed using a custom password-protected installation repository (bsc#1258701) ------------------------------------------------------------------ ------------------ 2026-6-4 - Jun 4 2026 ------------------- ------------------------------------------------------------------ ++++ agama: - Consider the old init scripts location for backward compatibility (gh#agama-project/agama#3564). ++++ ansible-sap-infrastructure: - 1.4.0 - Minor Changes: - sap_vm_provision - Rework role with best practices to align with project - sap_vm_provision - Update ibmcloud PowerVS image dictionaries - sap_vm_provision - Add MS Azure disclaimer about reliability of azure collection - sap_vm_temp_vip - Refactor variables and improve logic for skipping hosts - Bugfixes: - sap_vm_provision - Fix deprecated network parameter for amazon.aws.ec2_instance - sap_vm_provision - Fix adding /etc/hosts for all in play not just itself - sap_vm_temp_vip - Fix NoneType broadcast variable ++++ ansible-sap-install: - 1.9.2: - Bugfixes: - sap_ha_pacemaker_cluster - Fix issue 1203 sudo dash - sap_storage_setup - Add option to mount generic NFS mounts - sap_swpm - Remove ansible.posix dependency - 1.9.1: - Bugfixes: - sap_general_preconfigure - Ansible 2.24 compatibility - sap_ha_pacemaker_cluster - Ansible 2.24 compatibility - sap_hana_preconfigure - Ansible 2.24 compatibility - sap_hana_preconfigure/RHEL - Correctly set tsx in all cases - sap_maintain_etc_hosts, sap_hana_install, sap_install_media_detect - Ansible 2.24 compatibility - sap_netweaver_preconfigure - Ansible 2.24 compatibility - sap_storage_setup, sap_hostagent, anydb - Ansible 2.24 compatibility ++++ ansible-sap-launchpad: - 1.3.2 - Bugfixes: - all - Replace inject vars with ansible_facts for 2.20 ++++ ansible-sap-playbooks: - 1.4.0 - Minor Changes: - collection: Add MS Azure disclaimer about reliability of azure collection - all: Fix all linting errors and update facts for 2.20 - all: Refactor product dictionary to reuse same contents when possible - all: Update ibmcloud image dictionaries - all: Add S4HANA and S4HANA FND 2025 software lists - hana: Update SAP HANA versions and add throttle for rsync - ibmcloud_powervs: Update variables for better clarity ++++ assimp: - added patches CVE-2025-11277: large mWidth and mHeight dimensions can lead to integer overflow and a heap-based buffer overflow [bsc#1251019] * assimp-CVE-2025-11277.patch ++++ kernel-64kb: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-azure: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-default: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-rt: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ dpdk: - Update to version 24.11.6 - docs: fix build issue due to missing spacing between paragraphs - Revert “net: fix packet type for stacked VLAN” ++++ dtb-aarch64: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ elemental-register: - Update to v1.9.2: * 71d1fb9c Local node labels (#984) * ce6acda9 Bump golang.org/x/net to v0.55.0 includes fixes for: - bsc#1266789 bsc#1265921 bsc#1267197 bsc#1267168 bsc#1251679 * 060958b7 Bump golangci/golangci-lint-action * 3b4b6699 use a real UUID for the machine registration ID * d33faa01 Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186) * 6dceb411 Deterministic endpoints for MachineRegistrations (#975) ++++ go1.21: - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.21 dependency on update-alternatives fixes bsc#1264390 ++++ go1.22: - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.22 dependency on update-alternatives fixes bsc#1264391 ++++ go1.23: - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.23 dependency on update-alternatives fixes bsc#1264392 ++++ go1.24: - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.24 dependency on update-alternatives fixes bsc#1264393 ++++ go1.25: - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.25 dependency on update-alternatives fixes bsc#1264394 ++++ go1.26: - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.26 dependency on update-alternatives fixes bsc#1264395 ++++ go1.26-openssl: - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs boo#1245878 * Drop go1.26 dependency on update-alternatives fixes bsc#1264395 ++++ java-17-openj9: - Make post scripts less noisy (bsc#1267355) ++++ java-17-openjdk: - Make post scripts less noisy (bsc#1267355) ++++ java-21-openj9: - Make post scripts less noisy (bsc#1267355) ++++ java-21-openjdk: - Make post scripts less noisy (bsc#1267355) ++++ java-25-openjdk: - Make post scripts less noisy (bsc#1267355) ++++ kernel-source: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-docs: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-kvmsmall: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-obs-build: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-obs-qa: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-syms: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ kernel-zfcpdump: - kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170) Message was supposed to give us a hint that these KMP's will have issue when user try to ftrace them. But it turns out to be just source confusion and worry. - commit 4c4b0f7 - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - commit 9d46ce6 - KVM: SVM: Provide helpers to set the error code (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 119f538 - KVM: SVM: Convert plain error code numbers to defines (git-fixes). - Refresh patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch. - commit 9b24d74 - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - commit 49f92d6 - KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). - commit 2377b0b - KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). - commit d2e5128 - KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git-fixes). - commit 21583d5 - KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git-fixes). - commit 7b47a53 - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - commit a198651 - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - commit 527f6a1 - KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git-fixes). - commit debb8d0 - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - commit 94b31bc - KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). - commit 757ab1d - KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git-fixes). - commit ab073d6 - KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). - commit 1a3998f - KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). - commit f79d28d - KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). - commit 7e820d3 - KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). - commit 2f4a230 - KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). - commit 03d5c57 - KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). - commit d778225 - KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). - commit 8ec8a38 - gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984 bsc#1267214). - commit 78b7449 - mctp: route: hold key->lock in mctp_flow_prepare_output() (CVE-2026-43455 bsc#1264765). - net: mctp: Ensure keys maintain only one ref to corresponding dev (CVE-2026-43455 bsc#1264765). - commit 43372c3 ++++ libica: - Amended the .spec file (bsc#1265607) * Included `--enable-internal-tests` flag in `%configure` - Updated the `libica-FIPS-make-it-possible-to-specify-fipshmac-binary.patch` * Changed the `hexkey` to non-zero value - Applied a patch to block SHA1 mechanism for FIPS 140-3 (bsc#1260938) * libica-Block-SHA1-mechanism-for-FIPS-140-3.patch ++++ libica: - Amended the .spec file (bsc#1265607) * Included `--enable-internal-tests` flag in `%configure` - Updated the `libica-FIPS-make-it-possible-to-specify-fipshmac-binary.patch` * Changed the `hexkey` to non-zero value - Applied a patch to block SHA1 mechanism for FIPS 140-3 (bsc#1260938) * libica-Block-SHA1-mechanism-for-FIPS-140-3.patch ++++ libvirt: - Add EPYC-Turin CPU model jsc#PED-13322 ++++ openQA: - Update to version 5.1780561853.63760953: * fix(rpm): eliminate systemd on-disk warnings during worker upgrade * chore(deps): Dependency cron 2026-06-04 * ci: Run OBS scm checks only for master branch * fix(systemd): activate inactive workers and reload active ones safely * chore(deps): Dependency cron 2026-06-03 * test(full-stack): remove redundant ISO size check to be flexible ++++ openQA: - Update to version 5.1780561853.63760953: * fix(rpm): eliminate systemd on-disk warnings during worker upgrade * chore(deps): Dependency cron 2026-06-04 * ci: Run OBS scm checks only for master branch * fix(systemd): activate inactive workers and reload active ones safely * chore(deps): Dependency cron 2026-06-03 * test(full-stack): remove redundant ISO size check to be flexible ++++ openQA: - Update to version 5.1780561853.63760953: * fix(rpm): eliminate systemd on-disk warnings during worker upgrade * chore(deps): Dependency cron 2026-06-04 * ci: Run OBS scm checks only for master branch * fix(systemd): activate inactive workers and reload active ones safely * chore(deps): Dependency cron 2026-06-03 * test(full-stack): remove redundant ISO size check to be flexible ++++ osc: - 1.27.1 - Command-line: - Fix 'osc maintaner' not to error out before it prints maintainers in git - Library: - Fix a regression in Gitea 1.26 where we need to send '{}' instead of an empty body in POST requests ------------------------------------------------------------------ ------------------ 2026-6-3 - Jun 3 2026 ------------------- ------------------------------------------------------------------ ++++ webkit2gtk3-soup2: - Update to version 2.52.4 (bsc#1267506 bsc#1267507 bsc#1267508 bsc#1267509 bsc#1267510 bsc#1267511 bsc#1267512 bsc#1267513 bsc#1267514 bsc#1267515 bsc#1267516 bsc#1267517 bsc#1267518 bsc#1267519 bsc#1267520 bsc#1267521): + Add support for half-width fonts. + Improve content filter compilation by avoiding file copies. + Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. + Improve how the CMake build system checks whether libatomic is required. + Fix painting scrollbars when their width changes. + Fix playback of certain YouTube videos with low frame rates. + Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. + Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. + Fix the build with USE_GSTREAMER_WEBRTC=OFF. + Fix the build with USE_GBM=OFF. + Fix several crashes and rendering issues. + Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVe-2026-43660. + Changes in version .52.3; + Add support for the "scrollbar-color" CSS property. + Fix some emoji glyphs being rendered as missing glyph boxes. + Fix JavaScriptCore crashes on architectures other than x86_64. + Fix the build on s390x. + Changes in version 2.52.2: + Improve handling of real-time threads. + Fix scrollbar rendering glitches visible in some GPU configurations. + Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. + Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). + Fix the build with USE_GTK4=OFF. - Drop webkit2gtk3-aarch64-build-fix.patch and webkitgtk-gtk3-build-fix.patch: fixed upstream. - Add webkitgtk-ppc64le-build-fix.patch: fix the build when system malloc is enabled. ++++ webkit2gtk3: - Update to version 2.52.4 (bsc#1267506 bsc#1267507 bsc#1267508 bsc#1267509 bsc#1267510 bsc#1267511 bsc#1267512 bsc#1267513 bsc#1267514 bsc#1267515 bsc#1267516 bsc#1267517 bsc#1267518 bsc#1267519 bsc#1267520 bsc#1267521): + Add support for half-width fonts. + Improve content filter compilation by avoiding file copies. + Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. + Improve how the CMake build system checks whether libatomic is required. + Fix painting scrollbars when their width changes. + Fix playback of certain YouTube videos with low frame rates. + Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. + Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. + Fix the build with USE_GSTREAMER_WEBRTC=OFF. + Fix the build with USE_GBM=OFF. + Fix several crashes and rendering issues. + Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVe-2026-43660. + Changes in version .52.3; + Add support for the "scrollbar-color" CSS property. + Fix some emoji glyphs being rendered as missing glyph boxes. + Fix JavaScriptCore crashes on architectures other than x86_64. + Fix the build on s390x. + Changes in version 2.52.2: + Improve handling of real-time threads. + Fix scrollbar rendering glitches visible in some GPU configurations. + Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. + Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). + Fix the build with USE_GTK4=OFF. - Drop webkit2gtk3-aarch64-build-fix.patch and webkitgtk-gtk3-build-fix.patch: fixed upstream. - Add webkitgtk-ppc64le-build-fix.patch: fix the build when system malloc is enabled. ++++ webkit2gtk4: - Update to version 2.52.4 (bsc#1267506 bsc#1267507 bsc#1267508 bsc#1267509 bsc#1267510 bsc#1267511 bsc#1267512 bsc#1267513 bsc#1267514 bsc#1267515 bsc#1267516 bsc#1267517 bsc#1267518 bsc#1267519 bsc#1267520 bsc#1267521): + Add support for half-width fonts. + Improve content filter compilation by avoiding file copies. + Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. + Improve how the CMake build system checks whether libatomic is required. + Fix painting scrollbars when their width changes. + Fix playback of certain YouTube videos with low frame rates. + Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. + Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. + Fix the build with USE_GSTREAMER_WEBRTC=OFF. + Fix the build with USE_GBM=OFF. + Fix several crashes and rendering issues. + Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVe-2026-43660. + Changes in version .52.3; + Add support for the "scrollbar-color" CSS property. + Fix some emoji glyphs being rendered as missing glyph boxes. + Fix JavaScriptCore crashes on architectures other than x86_64. + Fix the build on s390x. + Changes in version 2.52.2: + Improve handling of real-time threads. + Fix scrollbar rendering glitches visible in some GPU configurations. + Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. + Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). + Fix the build with USE_GTK4=OFF. - Drop webkit2gtk3-aarch64-build-fix.patch and webkitgtk-gtk3-build-fix.patch: fixed upstream. - Add webkitgtk-ppc64le-build-fix.patch: fix the build when system malloc is enabled. ++++ amazon-ssm-agent: - Update to version 3.3.4624.0 * Bump golang.org/x/crypto from v0.51.0 to v0.52.0 (bsc#1266200, CVE-2026-39827, CVE-2026-39828, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598) * Bump golang.org/x/net from v0.54.0 to v0.55.0 * Enforce directory boundary in BuildSafePath * Fix visibility issue with Bottlerocket OS in document output * Update go-git from v5.17.1 to v5.19.1 (bsc#1264952, CVE-2026-41506), this also updates go-billy from v5.8.0 to v5.9.0 (bsc#1267332, CVE-2026-44740) - Drop CVE-2025-22869.patch, merged upstream - Drop CVE-2025-22870.patch, merged upstream - Drop CVE-2025-47913.patch, merged upstream - Drop CVE-2026-25934.patch, merged upstream - Drop CVE-2026-41506.patch, merged upstream ++++ assimp: - added patches CVE-2026-10197: Affected is the function glTF2Importer:ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp. manipulation results in null pointer dereference [bsc#1266996] * assimp-CVE-2026-10197.patch CVE-2026-10199: Affected by this issue is the function glTF2:LazyDict in the library glTF2Asset.h. Manipulation of the argument operator[] leads to null pointer dereference [bsc#1266998] * assimp-CVE-2026-10199.patch ++++ aws-cli-cmd: - Adapt HOME sharing to be more useful So far the HOME directory of the calling user was mapped into the container to appear as the HOME of the root user (/root) inside of the container because it's effectively the only user present inside of the container. However, from a usabilty perspective this is not a good setup because any home based file reference on the host has a different path inside of the container which is confusing for users. This commit makes sure that the host path references matches with the path inside the container. This Fixes bsc#1266045 ++++ aws-cli-cmd: - Adapt HOME sharing to be more useful So far the HOME directory of the calling user was mapped into the container to appear as the HOME of the root user (/root) inside of the container because it's effectively the only user present inside of the container. However, from a usabilty perspective this is not a good setup because any home based file reference on the host has a different path inside of the container which is confusing for users. This commit makes sure that the host path references matches with the path inside the container. This Fixes bsc#1266045 ++++ az-cli-cmd: - Adapt HOME sharing to be more useful So far the HOME directory of the calling user was mapped into the container to appear as the HOME of the root user (/root) inside of the container because it's effectively the only user present inside of the container. However, from a usabilty perspective this is not a good setup because any home based file reference on the host has a different path inside of the container which is confusing for users. This commit makes sure that the host path references matches with the path inside the container. This Fixes bsc#1266045 ++++ az-cli-cmd: - Adapt HOME sharing to be more useful So far the HOME directory of the calling user was mapped into the container to appear as the HOME of the root user (/root) inside of the container because it's effectively the only user present inside of the container. However, from a usabilty perspective this is not a good setup because any home based file reference on the host has a different path inside of the container which is confusing for users. This commit makes sure that the host path references matches with the path inside the container. This Fixes bsc#1266045 ++++ kernel-64kb: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-azure: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-default: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-rt: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ python-kiwi: - Do not hardcode dracut omit module in live builder This is a relict from the old days when the pure presence of multipath in a live ISO caused issues at boot time. kiwi should not maintain a hardcoded list of dracut modules except for those that are mandatory for live boot, if there should be any special setting needed it should come from an overlay setup in /etc/dracut.conf.d/*.conf as part of the image description. This is related to bsc#1260340 ++++ dtb-aarch64: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ elemental-toolkit: - Update to v2.3.4: * 974af043 Bump golang.org/x/net to v0.55.0 (bsc#1267168 bsc#1251679) * ae39c90f Bump golang.org/x/crypto to v0.52.0 (bsc#1266187) ++++ gleam: - Update to 1.17.0: * Fixed security vulnerabilities: - Restrict custom documentation page `path` and `source` values so `gleam docs build` cannot escape the docs output directory or project root (bsc#1267396, CVE-2026-32685) - Restrict publication tarball creation so they cannot contain files from outside the project root (bsc#1267397, CVE-2026-42795) - Stricter deserialisation rules for files internal the build directory to reject corrupted data (bsc#1267398, CVE-2026-43965) * All features and bug fixes are extensively highlighted with examples in the upstream blog post at https://gleam.run/news/single-file-gleam-beam-programs-with-escript/ and changelog at https://github.com/gleam-lang/gleam/blob/v1.17.0/CHANGELOG.md some of the highlights include: - Various JavaScript code generation fixes and optimization - Various compiler error handling improvements - Ability to use the `todo` keyword in constants - Improved handling of Git monorepos during package management - Ability to create escripts from Gleam programs - Various language server improvements like reference highlighting, record hovering and code actions ++++ go1.26-openssl: - Update to version 1.26.3 cut from the go1.25-fips-release branch at the revision tagged go1.26.3-1-openssl-fips. Refs jsc#SLE-18320 * Rebase to 1.26.3 ++++ hplip: - hp-plugin: fix plugin installation from local file (lp#2154206) * add pluginhandler-fix-plugin-installation-from-local-fil.patch ++++ keybase-client: - Update to version 6.6.3 * Various bug fixes - Drop update-go-crypto.patch which has been adopted upstream. - Drop update-go-net.patch which has been adopted upstream. ++++ kernel-source: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-docs: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-kvmsmall: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-obs-build: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-obs-qa: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-syms: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ kernel-zfcpdump: - io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (CVE-2026-31774 bsc#1264040). - commit c76e91c - ima: return error early if file xattr cannot be changed (bsc#1261041). - commit abe4d77 - RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (CVE-2026-46181 bsc#1266826). - bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970 bsc#1267205). - commit 83cafaf - x86: shadow stacks: proper error handling for mmap lock (bsc#1264484 CVE-2026-43109). - commit eb1188f - thermal: core: Fix thermal zone governor cleanup issues (CVE-2026-46021 bsc#1267220). - commit fc6c27a ++++ mozjs128: - Add mozjs128-CVE-2025-70103.patch: libjxl: take EC into account when checking required PNM input length (bsc#1266463 CVE-2025-70103). ++++ python-semanage: - Depend on libso before make pywrap is executed to avoid race conditions (bsc#1266385) - Add patch: 1266385-libsemanage-Require-LIBSO-before-SWIGSO-and-SWIGRUBY.patch - Add CFLAGS to %make_install call for consistency with %make_build ++++ syft: - Update to version 1.45.0: * Added Features - Add support for ZapAddOns as jar files [#4654 #4932 @douglasclarke] - MySQL binary classifier should distinguish between MySQL Cluster (ndb) and MySQL [#3297 #4907 @witchcraze] - Catalog ingress-nginx binary [#4818 #4857 @witchcraze] * Bug Fixes - Support helm binary various versions [#4820 #4922 @witchcraze] - Support julia binary various versions [#4867 #4945 @witchcraze] - Support deno binary old versions [#4865 #4939 @witchcraze] - Compressed kernel modules are not scanned by the linux-kernel-cataloger [#4721 #4740 @will-bates11] - Yarn Berry lockfile parser incorrectly deduplicates packages with multiple resolutions [#4691 #4838 @calumleslie] - Possible misdetection of AWS-LC as OpenSSL 1.1.1 [#4539 #4882 @witchcraze] - Support elixir binary rc versions [#4819 #4851 @ChrisJr404] - Exclude path ending with a slash are discarded [#4839 #4892 @ChrisJr404] - Incorrect CPE for .NET Runtime [#4738 #4743 @PGrayCS] - fix parsing of debian/copyright files [#4708 #4754 @Bahtya] - Grype ignores python requirements in arbitrary equality (===) format [#4834 #4835 @cyphercodes] - valkey is detected as both of valkey and redis [#4591 #4619 @witchcraze] - TypeByName missing "nuget" case causes UnknownPkg when reading SPDX SBOMs [#4837 #4848 @ChrisJr404] * Additional Changes - hoist name normalization regexp to package level [#4926 @matiasinsaurralde] - bump the actions-minor-patch group across 1 directory with 6 updates [#4946 @dependabot] - bump the actions-minor-patch group across 2 directories with 2 updates [#4936 @dependabot] - bump the actions-minor-patch group across 1 directory with 4 updates [#4927 @dependabot] - bump the actions-minor-patch group across 1 directory with 2 updates [#4920 @dependabot] - bump the actions-minor-patch group across 1 directory with 2 updates [#4897 @dependabot] - update CPE dictionary index [#4831 @anchore-oss-update-bot] * Dependencies - chore(deps): bump github.com/containerd/containerd/v2 (#4935) - chore(deps): update anchore dependencies (#4821) - chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 (#4930) - chore(deps): update CPE dictionary index (#4925) - chore(deps): update CPE dictionary index (#4909) - chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 (#4911) ++++ xmrig: - Update to version 6.26.0: * Add RandomX v2 support, including commitments and stratum submit changes * Add RISC-V support: JIT compiler, hardware/vector AES and vectorized RandomX code paths * Solo mining: add support for the Monero FCMP++ hardfork * Add VAES-512 support for Zen5 and Zen4 (Hawk Point) CPU detection * Linux: add transparent huge pages support and improve automatic huge pages on systems without NUMA * Numerous ARM64/aarch64 build and JIT improvements * Initial Haiku OS support and improved LibreSSL support * Many smaller fixes and optimizations across the 6.23.x, 6.24.x and 6.25.x releases - Enable building on riscv64 now that upstream supports RISC-V ++++ znc: - Update to version 1.10.2: * Fix build when only part of Boost was found * modperl: avoid newAV_alloc_x, which required a newer Perl * Pass CClient to the OnClientGetSASLMechanisms callback * Translation updates - Drop znc-swig-4.4.patch (SWIG 4.4 support merged upstream) - Build with the Ninja generator - Mark the znc-doc subpackage as noarch ------------------------------------------------------------------ ------------------ 2026-6-2 - Jun 2 2026 ------------------- ------------------------------------------------------------------ ++++ aaa_base: - Update to version 84.87+git20260602.e901e17e: * Fix a typo + follow symlinks in alljava ++++ aaa_base: - Update to version 84.87+git20260602.e901e17e: * Fix a typo + follow symlinks in alljava ++++ kernel-64kb: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-64kb: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-azure: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-azure: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-default: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-default: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-rt: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-rt: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ dtb-aarch64: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ dtb-aarch64: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ erlang: - CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449) * fix-CVE-2026-42789.patch - CVE-2026-42790: Name Constraints and Subject CommonName fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466) * fix-CVE-2026-42790.patch - CVE-2026-42791: OCSP response verification in the `public_key` application does not check the validity period of the OCSP responder certificate and allows for OCSP response response forgery (bsc#1266448) * fix-CVE-2026-42791.patch - CVE-2025-4748: erlang,erlang26: improper limitation of a pathname may lead to path traversal (bsc#1244642) * fix-CVE-2025-4748.patch ++++ libheif: - version update to 1.23.0: * add API functions to read and write metadata: ambient viewing environment nominal diffuse white luminance * adds a output_image_nclx_profile_passthrough option to heif_decoding_options * CVE-2026-50142 (GHSA-jvmp-j3cw-84mh) - unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check) - fixes [bsc#1267455] ++++ glab: - Update to version 1.101.0: * Features - 98e075fb: feat(ci): add --force flag to glab ci cancel job (Filip Aleksic faleksic@gitlab.com) - 56083b99: feat(mr note create): add --resolvable flag (Silviu Marchis silviu.marchis@sygnum.com) - 3a8da34f: feat(orbit): add Windows support for orbit local (Bohdan Parkhomchuk bparkhomchuk@gitlab.com) - 1b8ac8a6: feat(orbit): add glab orbit setup guided onboarding command (Kai Armstrong karmstrong@gitlab.com) - 7c5c41f3: feat(stack): add --skip-mr-creation flag to stack sync command (Gary Holtz gholtz@gitlab.com) - 8a9f818d: feat: Display progress during glab mr checkout (Gabriel Mazzetto gabriel@gitlab.com) * Bug Fixes - 1db48d89: fix(ci): align ci delete and ci list default pagination (Kai Armstrong karmstrong@gitlab.com) * Documentation - 04deff1d: docs(config): add synopsis and improve examples for config commands (Brendan Lynch blynch@gitlab.com) - a4b6dc76: docs(deploy-key): add synopsis and examples to deploy-key commands (Brendan Lynch blynch@gitlab.com) - 700695f5: docs(gpg-key): add synopsis and examples to gpg-key commands (Brendan Lynch blynch@gitlab.com) - 684df227: docs(label): add synopsis and examples to label commands (Brendan Lynch blynch@gitlab.com) - c1a8d0e7: docs(milestone): add synopsis and examples to milestone commands (Brendan Lynch blynch@gitlab.com) - b1bff4ba: docs(schedule): add synopsis and examples to schedule commands (Brendan Lynch blynch@gitlab.com) - 9e7f7b38: docs(securefile): add synopsis and examples to securefile commands (Brendan Lynch blynch@gitlab.com) - 44ca2124: docs(ssh-key): add synopsis and examples to ssh-key commands (Brendan Lynch blynch@gitlab.com) - ac004c5d: docs: clarify --all and --per-page pagination behavior (Brendan Lynch blynch@gitlab.com) * Dependencies - dce8a8d0: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.6.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - baf77b6b: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.34.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8cd1295e: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.36.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 349287c5: chore(deps): update module golang.org/x/crypto to v0.52.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 58f32068: chore: Ensure git exit error codes are wrapped as Error (Gabriel Mazzetto gabriel@gitlab.com) - 220d0473: chore: Extract GitRunner into internal/git/git_runner (Gabriel Mazzetto gabriel@gitlab.com) * Others - 12b11497: test(iostreams): isolate NO_COLOR in detectIsColorEnabled default case (Filip Aleksic faleksic@gitlab.com) ++++ go1.25: - go1.25.11 (released 2026-06-02) includes security fixes to the crypto/x509, mime, and net/textproto packages, as well as bug fixes to the compiler and the runtime. Refs boo#1244485 go1.25 release tracking CVE-2026-42504 CVE-2026-42507 CVE-2026-27145 * go#79229 go#79217 boo#1267442 security: fix CVE-2026-42504 mime: quadratic complexity in WordDecoder.DecodeHeader * go#79425 go#79346 boo#1267444 security: fix CVE-2026-42507 net/textproto: arbitrary input are included in errors without any escaping * go#79700 go#79694 boo#1267450 security: fix CVE-2026-27145 crypto/x509: split candidate hostname only once * go#79190 cmd/compile: Bug in rewrite rules for AMD64 causes SHL instruction overflow and miscompilation * go#79698 runtime/race: change in 93a4f03 leads to a failed build on Amazon Linux 2 and arm64 ++++ go1.26: - go1.26.4 (released 2026-06-02) includes security fixes to the crypto/x509, mime, and net/textproto packages, as well as bug fixes to the compiler, the runtime, the go fix command, and the crypto/fips140 package. Refs boo#1255111 go1.26 release tracking CVE-2026-42504 CVE-2026-42507 CVE-2026-27145 * go#79230 go#79217 boo#1267442 security: fix CVE-2026-42504 mime: quadratic complexity in WordDecoder.DecodeHeader * go#79426 go#79346 boo#1267444 security: fix CVE-2026-42507 net/textproto: arbitrary input are included in errors without any escaping * go#79701 go#79694 boo#1267450 security: fix CVE-2026-27145 crypto/x509: split candidate hostname only once * go#79191 cmd/compile: Bug in rewrite rules for AMD64 causes SHL instruction overflow and miscompilation * go#79226 crypto/internal/fips140/drbg: backport CL 774221 to Go 1.26 * go#79349 cmd/fix: x/tools/go/analysis/passes/modernize: slicescontains hoists needle expression, changing side effect count * go#79686 runtime/race: change in 93a4f03 leads to a failed build on Amazon Linux 2 and arm64 ++++ go1.26-openssl: - go1.26.4 (released 2026-06-02) includes security fixes to the crypto/x509, mime, and net/textproto packages, as well as bug fixes to the compiler, the runtime, the go fix command, and the crypto/fips140 package. Refs boo#1255111 go1.26 release tracking CVE-2026-42504 CVE-2026-42507 CVE-2026-27145 * go#79230 go#79217 boo#1267442 security: fix CVE-2026-42504 mime: quadratic complexity in WordDecoder.DecodeHeader * go#79426 go#79346 boo#1267444 security: fix CVE-2026-42507 net/textproto: arbitrary input are included in errors without any escaping * go#79701 go#79694 boo#1267450 security: fix CVE-2026-27145 crypto/x509: split candidate hostname only once * go#79191 cmd/compile: Bug in rewrite rules for AMD64 causes SHL instruction overflow and miscompilation * go#79226 crypto/internal/fips140/drbg: backport CL 774221 to Go 1.26 * go#79349 cmd/fix: x/tools/go/analysis/passes/modernize: slicescontains hoists needle expression, changing side effect count * go#79686 runtime/race: change in 93a4f03 leads to a failed build on Amazon Linux 2 and arm64 ++++ grafana: - Update to version 11.6.14+security-04: Security: * CVE-2026-28374: Fix insecure direct object reference in Annotations API (bsc#1265290) * CVE-2026-28376: Fix unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) * CVE-2026-28383: Fix unbounded memory allocation in Grafana plugin resources (bsc#1265286) * CVE-2026-28380: Fix broken access control in Snapshot API (bsc#1265287) * CVE-2026-33376: Fix Auth Proxy IPv6 whitelist bypass (bsc#1265285) * CVE-2026-28379: Fix viewer-triggered race condition in Grafana Live (bsc#1265288) * CVE-2026-33377: Fix dashboard Editor Privilege Escalation (bsc#1265284) * CVE-2026-33378: Fix OOM exception in Grafana Data Source Plugin (bsc#1265283) * CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) * CVE-2026-33380: Fix vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server’s filesystem (bsc#1265282) ++++ grafana: - Update to version 11.6.14+security-04: Security: * CVE-2026-28374: Fix insecure direct object reference in Annotations API (bsc#1265290) * CVE-2026-28376: Fix unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) * CVE-2026-28383: Fix unbounded memory allocation in Grafana plugin resources (bsc#1265286) * CVE-2026-28380: Fix broken access control in Snapshot API (bsc#1265287) * CVE-2026-33376: Fix Auth Proxy IPv6 whitelist bypass (bsc#1265285) * CVE-2026-28379: Fix viewer-triggered race condition in Grafana Live (bsc#1265288) * CVE-2026-33377: Fix dashboard Editor Privilege Escalation (bsc#1265284) * CVE-2026-33378: Fix OOM exception in Grafana Data Source Plugin (bsc#1265283) * CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) * CVE-2026-33380: Fix vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server’s filesystem (bsc#1265282) ++++ hwinfo: - merge gh#openSUSE/hwinfo#181 - fix redundant conditions in smbios memory device map - 25.4 - merge gh#openSUSE/hwinfo#182 - fix memory leaks (bsc#1267348) - merge gh#openSUSE/hwinfo#180 - fix(core): free modinfo_ext instead of modinfo in hd_free_hd_data - merge gh#openSUSE/hwinfo#179 - Fix: fix sizeof in joystick allocation to use struct size instead of pointer size (bsc#1267348) ++++ kernel-source: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-source: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-docs: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-docs: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-kvmsmall: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-kvmsmall: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-obs-build: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-obs-build: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-obs-qa: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-obs-qa: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-syms: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-syms: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-zfcpdump: - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ kernel-zfcpdump: - slip: reject VJ receive packets on instances with no rstate array (CVE-2026-45842 bsc#1266400) - commit 38a2f5a - drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (CVE-2026-31562 bsc#1263058) - commit 32df08b - media: mediatek: vcodec: fix use-after-free in encoder release path (CVE-2026-31584 bsc#1263180) - commit b6ee0ee - thermal: core: Fix thermal zone device registration error path (CVE-2026-43332 bsc#1265114) - commit 071fb81 - rnbd-srv: Zero the rsp buffer before using it (CVE-2026-43184 bsc#1264622) - commit 2328379 - xfrm_user: fix info leak in build_report() (CVE-2026-31671 bsc#1263115) - commit 242dd53 - net: lan966x: fix page pool leak in error paths (CVE-2026-31645 bsc#1263794) - commit 538760a - batman-adv: avoid OGM aggregation when skb tailroom is insufficient (CVE-2026-31683 bsc#1263594) - commit 11e7f44 - bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (CVE-2026-45846 bsc#1266394) - commit ff7db37 - netconsole: avoid OOB reads, msg is not nul-terminated (CVE-2026-43197 bsc#1264609) - commit 3a848f9 - net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (CVE-2026-43040 bsc#1264091) - commit 9299501 - debugfs: Fix default access mode config check (bsc#1265186). - commit 64dc22e - debugfs: Remove broken no-mount mode (bsc#1265186). - commit 5697d69 - debugfs: Remove redundant access mode checks (bsc#1265186). - commit 3bbda02 - Update patches.suse/smb-client-reject-userspace-cifs-spnego-descriptions.patch (bsc#1266238 CVE-2026-46243). - commit 9550304 - ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927 CVE-2026-46094). - commit 99aecd7 - writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883 CVE-2026-31703). - commit 2118f65 - ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255 CVE-2026-43068). - commit 84d369d - mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579 CVE-2026-31648). - commit fa1a630 - ext4: avoid infinite loops caused by residual data (bsc#1262622 CVE-2026-31448). - commit b253df0 - ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245 CVE-2026-43066). - commit 94473f3 - ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243 CVE-2026-43065). - commit 9392a17 - ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619 CVE-2026-31446). - commit 8d4620e - ext4: fix e4b bitmap inconsistency reports (bsc#1266914 CVE-2026-45942). - commit ed6da65 - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) - commit 1d9af81 - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) - commit d3c330f - Bluetooth: serialize accept_q access (git-fixes). - Refresh patches.suse/Bluetooth-fix-UAF-in-l2cap_sock_cleanup_listen-vs-l2.patch. - commit 649e53f - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - commit 5fdf340 - RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (CVE-2026-46114 bsc#1266972) - commit aa23e21 - RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (CVE-2026-45856 bsc#1266720) - commit 3432226 - RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (CVE-2026-46176 bsc#1266816) - commit 568bd06 - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Reject zero max_num_queues from MANA_QUERY_VPORT_CONFIG (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - commit 36776be ++++ openvswitch: - Update ovn to 25.03.3 - Fixes heap over-read in ICMP error response generation (CVE-2026-5265) (bsc#1262498). - Fixes heap over-read in OVN DHCPv6 client ID processing (CVE-2026-5367) (bsc#1262499). - Bug fixes - Add support for special port_security prefix "VRRPv3". This prefix allows CMS to allow all required traffic for a VRRPv3 virtual router behind LSP. See ovn-nb(5) man page for more details. - Fixed support for fragmented traffic in the userspace datapath. Added the "acl_ct_translation" NB_Global option to enable connection tracking based L4 field translation for stateful ACLs. When enabled allows proper handling of IP fragmentation in userspace datapaths. This option may break hardware offloading and is disabled by default. - Added disable_garp_rarp option to logical_router table in order to disable GARP/RARP announcements by all the peer ports of this logical router. ++++ xar: - Spec cleanup: * Add explicit gcc and make BuildRequires * Convert the library -devel BuildRequires to their pkgconfig() form (libacl, bzip2, libxml-2.0, zlib) * Drop obsolete Group tags ++++ openQA: - Update to version 5.1780410522.ad58d974: * feat(tests): enable parallel-safe fullstack and developer mode tests * fix: ignore transient 'database is locked' errors in cache service * git subrepo pull (merge) --force external/os-autoinst-common * Revert "fix: avoid permission denied on cgroup creation for v2" * feat: add run-test-env target to start all local services * fix: add functional API keys for local test environment * fix: use absolute paths for local test environment * feat: Improve CLI retry error feedback with detailed messages * fix: avoid permission denied on cgroup creation for v2 * ci: Auto-import keys to avoid interactive prompt for devel_openQA * docs: require atomic commits in agent guidelines * fix: include file paths in worker logging errors * chore(AGENTS.md): add rules for ensuring valid commits * fix: only report job limit in UI when globally reached * docs: Clarify wording in "Spawning multiple jobs …" * docs: Fix wrapping in "Medium Types" section * docs: Fix wrapping and use of blank lines in "Spawning multiple jobs …" ++++ openQA: - Update to version 5.1780410522.ad58d974: * feat(tests): enable parallel-safe fullstack and developer mode tests * fix: ignore transient 'database is locked' errors in cache service * git subrepo pull (merge) --force external/os-autoinst-common * Revert "fix: avoid permission denied on cgroup creation for v2" * feat: add run-test-env target to start all local services * fix: add functional API keys for local test environment * fix: use absolute paths for local test environment * feat: Improve CLI retry error feedback with detailed messages * fix: avoid permission denied on cgroup creation for v2 * ci: Auto-import keys to avoid interactive prompt for devel_openQA * docs: require atomic commits in agent guidelines * fix: include file paths in worker logging errors * chore(AGENTS.md): add rules for ensuring valid commits * fix: only report job limit in UI when globally reached * docs: Clarify wording in "Spawning multiple jobs …" * docs: Fix wrapping in "Medium Types" section * docs: Fix wrapping and use of blank lines in "Spawning multiple jobs …" ++++ openQA: - Update to version 5.1780410522.ad58d974: * feat(tests): enable parallel-safe fullstack and developer mode tests * fix: ignore transient 'database is locked' errors in cache service * git subrepo pull (merge) --force external/os-autoinst-common * Revert "fix: avoid permission denied on cgroup creation for v2" * feat: add run-test-env target to start all local services * fix: add functional API keys for local test environment * fix: use absolute paths for local test environment * feat: Improve CLI retry error feedback with detailed messages * fix: avoid permission denied on cgroup creation for v2 * ci: Auto-import keys to avoid interactive prompt for devel_openQA * docs: require atomic commits in agent guidelines * fix: include file paths in worker logging errors * chore(AGENTS.md): add rules for ensuring valid commits * fix: only report job limit in UI when globally reached * docs: Clarify wording in "Spawning multiple jobs …" * docs: Fix wrapping in "Medium Types" section * docs: Fix wrapping and use of blank lines in "Spawning multiple jobs …" ++++ os-autoinst: - Update to version 5.1780410333.aed07e0: * fix(test): use linuxboot_dma.bin in 18-backend-qemu.t * feat: consolidate tidy targets into CMake * fix: fail explicitly on test module basename collisions * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests ++++ os-autoinst: - Update to version 5.1780410333.aed07e0: * fix(test): use linuxboot_dma.bin in 18-backend-qemu.t * feat: consolidate tidy targets into CMake * fix: fail explicitly on test module basename collisions * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests ++++ os-autoinst: - Update to version 5.1780410333.aed07e0: * fix(test): use linuxboot_dma.bin in 18-backend-qemu.t * feat: consolidate tidy targets into CMake * fix: fail explicitly on test module basename collisions * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests ++++ rpcbind: Update to rpcbind 1.2.9 (bsc#1267212) https://lore.kernel.org/linux-nfs/5cad3ab4-d24a-45fa-b1e9-d57b2c47a5e4@redhat.com/ rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist() * rpcbind: Stop unauthenticated oversized allocation in PMAPPROC_CALLIT decode * rpcbind: fix memory leak in read_warmstart() * rpcbind: fix memory leaks in network_init() * rpcbind: fix memory leak in init_transport() - Update to rpcbind 1.2.8 https://lore.kernel.org/linux-nfs/b553cc5a-46eb-453b-80f0-cfe69ccb7b21@redhat.com/ * Added -v (print version and compile flags) * rpcinfo: Removed a number of "old-style function definition" warnings * man/rpcbind: Update list of options * Comment out ListenStream=@/run/rpcbind.sock * [nfs/nfs-utils/rpcbind] rpcbind: avoid dereferencing NULL from realloc() * systemd/rpcbind.service.in: Add various hardenings options * man/rpcbind: Add Files section to manpage * Moved rpcbind.lock and default configs to /run instead of /var/run - systemd: Upstream added systemd EnvironmentFile: 1) /etc/rpcbind.conf 2) /etc/default/rpcbind 3) /etc/sysconfig/rpcbind (the only one originally used in openSUSE patch for boo#1117217) - systemd: Add 'systemd-tmpfiles-setup.service' into 'Wants' and 'After' targets (originally openSUSE patch for boo#1117217 added 'After=sysinit.target') - Removed patches (accepted upstream): * 0001-systemd-rpcbind.service-Fix-ordering-add-etc-sysconf.patch * 0001-systemd-rpcbind.service-Add-hardening-bsc-1181400.patch * 0001-change-lockingdir-to-run.patch ++++ scap-security-guide: - Add Hummingbird product support - updated to 0.1.81 (jsc#ECO-3319) - Create SLE16 ANSSI profiles - Update SLE15 STIG version to V2R7 - Update SLE12 STIG version to V3R5 - Update SLEM5 STIG version to V1R3 - Add Claude Code skills for content development workflows - Create Claude Skill for creating new products - Various updates for SLE 12/15 ++++ sshfs: - Update to 3.7.6: - Added new maintainer: abhinavagarwal07 Abhinav Agarwal - CVE-2026-47187: Fixed critical vulnerability - Symlink Escape: Rogue SFTP Server to Local File Read/Write), credit to abhinavagarwal07 (bsc#1267017) - New -o contain_symlinks and -o no_contain_symlinks to control symlink containment behavior - CVE-2026-48711: Fixed high severity vulnerability - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), credit to abhinavagarwal07 (bsc#1267016) - Fixed null-deref warning in tokenize_on_space, promote strict-warnings to required - Added a number of tests in CI, including rename, chmod, fsync, statvfs values, error paths, option coverage - Fixed malformed SFTP reply handling ++++ tor: - Update to 0.4.9.9 * Major bugfixes (compression, security): - Fix a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. TROVE-2026-022. Fixes bug 41275; bugfix on 0.3.1.1-alpha. - Fix an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. TROVE-2026-021. Fixes bug 41274; bugfix on 0.2.6.1-alpha. * Major bugfixes (conflux, security): - Fix a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. TROVE-2026-017. Fixes bug 41263; bugfix on 0.4.8.1-alpha. * Major bugfixes (security, TROVE-2026-019): - Avoid out-of-bounds read/write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. Fixes bug 41267; bugfix on 0.2.8.2-alpha. * Major bugfixes (client stability, TROVE-2026-013, TROVE-2026-015): - Protect against a client-side assert that can happen if a malicious onion service gets the client to load its carefully crafted onion descriptor. Fixes bugs 41259 and 41261; bugfix on 0.3.1.1-alpha. * Major bugfixes (code safety): - Avoid a dangerous situation in router_find_exact_exit_enclave() where we could have reached an assert if bridges or relays claim an IP address of 0.0.0.0. Fixes bug 41276; bugfix on 0.4.5.1-alpha. * Major bugfixes (conflux, shutdown): - Fix a use-after-free in the shutdown path when freeing conflux circuits. cfx_add_leg() shares stream list pointers across legs without NULLing the old leg, so circuit_free_all() would free the lists via one leg and then access freed memory via another. TROVE- 2026-016. Fixes bug 41262; bugfix on 0.4.8.1-alpha. * Major bugfixes (DNSPort, TROVE-2026-018): - Fix a client-side crash that would happen if we decide to stop reading on a RESOLVE request that came from the DNSPort or controller. This crash could happen naturally under heavy load and with poor luck, but since 0.4.7.2-alpha it could be induced by the exit relay via a flow control request. Fixes bug 41265; bugfix on 0.2.0.1-alpha. * Major bugfixes (memory safety, TROVE-2026-014): - Avoid a heap-use-after-free mistake that can happen in the conflux subsystem, and which can be induced at either the client or the exit relay. Fixes bug 41260; bugfix on 0.4.8.1-alpha. * Major bugfixes (onion services, TROVE-2026-020): - Avoid a possible divide by zero crash on onion services that have the proof-of-work (PoW) defense enabled. This bug could be hit by extreme bad luck or maybe by the help of an attacker crafting just the right circumstances. Fixes bug 41270; bugfix on 0.4.8.1-alpha. ------------------------------------------------------------------ ------------------ 2026-6-1 - Jun 1 2026 ------------------- ------------------------------------------------------------------ ++++ 7zip: - Update to 26.01: * linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression. * new -spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. - spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk (*) character in {dir_path} will not be replaced by the archive name. - spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. - spor : 7-Zip will replace asterisk (*) character in the path specified in the -o{dir_path} with the archive name. This is the default option. * some bugs were fixed. * Security fixes: bsc#1267858 (CVE-2026-48092) bsc#1267862 (CVE-2026-48104) bsc#1267861 (CVE-2026-48103) bsc#1267860 (CVE-2026-48102) bsc#1267859 (CVE-2026-48101) bsc#1267864 (CVE-2026-48112) bsc#1267863 (CVE-2026-48111) bsc#1267421 (CVE-2026-48095) ++++ rust: - Update to version 1.96.0 - for details see the rust1.96 package ++++ chromium: - Chromium 149 (149.0.7827.53) stable (boo#1267706): * CVE-2026-10881: Out of bounds read and write in ANGLE * CVE-2026-10882: Use after free in Network * CVE-2026-10883: Out of bounds write in ANGLE * CVE-2026-10884: Use after free in Chromecast * CVE-2026-10885: Use after free in Chrome for iOS * CVE-2026-10886: Use after free in FileSystem * CVE-2026-10887: Use after free in Chromoting * CVE-2026-10888: Use after free in Cast Streaming * CVE-2026-10889: Out of bounds read in ANGLE * CVE-2026-10890: Use after free in Cast * CVE-2026-10891: Use after free in GFX * CVE-2026-10892: Out of bounds write in GPU * CVE-2026-10893: Use after free in Chromoting * CVE-2026-10894: Use after free in Printing * CVE-2026-10895: Use after free in Ozone * CVE-2026-10896: Use after free in Chrome for iOS * CVE-2026-10897: Out of bounds write in GPU * CVE-2026-10898: Stack buffer overflow in GPU * CVE-2026-10899: Use after free in Ozone * CVE-2026-10900: Use after free in Passwords * CVE-2026-10901: Use after free in Passwords * CVE-2026-10902: Use after free in Ozone * CVE-2026-10903: Use after free in WebRTC * CVE-2026-10904: Inappropriate implementation in V8 * CVE-2026-10905: Use after free in Network * CVE-2026-10906: Use after free in WebAuthentication * CVE-2026-10907: Out of bounds write in ANGLE * CVE-2026-10908: Use after free in FullScreen * CVE-2026-10909: Use after free in Dawn * CVE-2026-10910: Type Confusion in V8 * CVE-2026-10911: Insufficient validation of untrusted input in Media * CVE-2026-10912: Insufficient validation of untrusted input in Extensions * CVE-2026-10913: Use after free in ANGLE * CVE-2026-10914: Use after free in ANGLE * CVE-2026-10915: Use after free in Core * CVE-2026-10916: Insufficient validation of untrusted input in DevTools * CVE-2026-10917: Insufficient validation of untrusted input in Media * CVE-2026-10918: Use after free in Viz * CVE-2026-10919: Use after free in ANGLE * CVE-2026-10920: Insufficient validation of untrusted input in WebShare * CVE-2026-10921: Integer overflow in Dawn * CVE-2026-10922: Insufficient validation of untrusted input in DevTools * CVE-2026-10923: Use after free in WebAppInstalls * CVE-2026-10924: Integer overflow in Chromecast * CVE-2026-10925: Out of bounds write in Skia * CVE-2026-10926: Use after free in Cast * CVE-2026-10927: Out of bounds read in Dawn * CVE-2026-10928: Script injection in Headless * CVE-2026-10929: Heap buffer overflow in ANGLE * CVE-2026-10930: Out of bounds read in ANGLE * CVE-2026-10931: Use after free in FileSystem * CVE-2026-10932: Use after free in UI * CVE-2026-10933: Use after free in Audio * CVE-2026-10934: Use after free in Autofill * CVE-2026-10935: Inappropriate implementation in V8 * CVE-2026-10936: Type Confusion in V8 * CVE-2026-10937: Inappropriate implementation in Passwords * CVE-2026-10938: Insufficient validation of untrusted input in Input * CVE-2026-10939: Use after free in WebRTC * CVE-2026-10940: Race in Codecs * CVE-2026-10941: Out of bounds memory access in Skia * CVE-2026-10942: Insufficient validation of untrusted input in UI * CVE-2026-10943: Use after free in WebRTC * CVE-2026-10944: Insufficient policy enforcement in Autofill * CVE-2026-10945: Use after free in PDF * CVE-2026-10946: Heap buffer overflow in Media * CVE-2026-10947: Use after free in WebRTC * CVE-2026-10948: Use after free in WebRTC * CVE-2026-10949: Heap buffer overflow in Video * CVE-2026-10950: Insufficient policy enforcement in Autofill * CVE-2026-10951: Use after free in Autofill * CVE-2026-10952: Use after free in Chrome for iOS * CVE-2026-10953: Use after free in Core * CVE-2026-10954: Use after free in Actor * CVE-2026-10955: Type Confusion in ANGLE * CVE-2026-10956: Use after free in MimeHandlerView * CVE-2026-10957: Use after free in Glic * CVE-2026-10958: Use after free in Chrome for iOS * CVE-2026-10959: Use after free in Input * CVE-2026-10960: Uninitialized Use in Codecs * CVE-2026-10961: Use after free in Chrome for iOS * CVE-2026-10962: Type Confusion in Media * CVE-2026-10963: Integer overflow in V8 * CVE-2026-10964: Integer overflow in V8 * CVE-2026-10965: Integer overflow in DevTools * CVE-2026-10966: Insufficient validation of untrusted input in Codecs * CVE-2026-10967: Use after free in SurfaceCapture * CVE-2026-10968: Insufficient validation of untrusted input in Dawn * CVE-2026-10969: Insufficient validation of untrusted input in Extensions * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups * CVE-2026-10971: Insufficient validation of untrusted input in Printing * CVE-2026-10972: Use after free in Ozone * CVE-2026-10973: Uninitialized Use in Dawn * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE * CVE-2026-10975: Use after free in WebRTC * CVE-2026-10976: Uninitialized Use in Dawn * CVE-2026-10977: Uninitialized Use in Skia * CVE-2026-10978: Use after free in Chromoting * CVE-2026-10979: Out of bounds read in ANGLE * CVE-2026-10980: Insufficient validation of untrusted input in DevTools * CVE-2026-10981: Insufficient validation of untrusted input in Codecs * CVE-2026-10982: Use after free in WebXR * CVE-2026-10983: Insufficient validation of untrusted input in Dawn * CVE-2026-10984: Inappropriate implementation in Accessibility * CVE-2026-10985: Out of bounds read in Skia * CVE-2026-10986: Integer overflow in Media * CVE-2026-10987: Integer overflow in V8 * CVE-2026-10988: Use after free in Views * CVE-2026-10989: Inappropriate implementation in V8 * CVE-2026-10990: Use after free in Glic * CVE-2026-10991: Use after free in V8 * CVE-2026-10992: Insufficient data validation in Animation * CVE-2026-10993: Heap buffer overflow in Skia * CVE-2026-10994: Uninitialized Use in ANGLE * CVE-2026-10995: Heap buffer overflow in TabStrip * CVE-2026-10996: Inappropriate implementation in Workers * CVE-2026-10997: Insufficient policy enforcement in Extensions * CVE-2026-10998: Out of bounds read in Media * CVE-2026-10999: Out of bounds memory access in ANGLE * CVE-2026-11000: Use after free in Fonts * CVE-2026-11001: Incorrect security UI in Payments * CVE-2026-11002: Use after free in Autofill * CVE-2026-11003: Use after free in WebRTC * CVE-2026-11004: Out of bounds read in ANGLE * CVE-2026-11005: Out of bounds read in ANGLE * CVE-2026-11006: Out of bounds read in Dawn * CVE-2026-11007: Insufficient validation of untrusted input in WebView * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11009: Use after free in USB * CVE-2026-11010: Use after free in WebShare * CVE-2026-11011: Insufficient policy enforcement in Password Manager * CVE-2026-11012: Use after free in Serial * CVE-2026-11013: Insufficient validation of untrusted input in Network * CVE-2026-11014: Insufficient policy enforcement in Extensions * CVE-2026-11015: Out of bounds read in WebGPU * CVE-2026-11016: Insufficient validation of untrusted input in Network * CVE-2026-11017: Inappropriate implementation in Link Preview * CVE-2026-11018: Insufficient policy enforcement in Actor * CVE-2026-11019: Inappropriate implementation in Payments * CVE-2026-11020: Inappropriate implementation in Extensions * CVE-2026-11021: Insufficient validation of untrusted input in GPU * CVE-2026-11022: Insufficient validation of untrusted input in DevTools * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11024: Stack buffer overflow in Skia * CVE-2026-11025: Insufficient policy enforcement in Navigation * CVE-2026-11026: Insufficient policy enforcement in Extensions * CVE-2026-11027: Insufficient validation of untrusted input in Glic * CVE-2026-11028: Use after free in Media * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop * CVE-2026-11030: Use after free in Network * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager * CVE-2026-11032: Insufficient data validation in Password Manager * CVE-2026-11033: Uninitialized Use in WebML * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs * CVE-2026-11036: Inappropriate implementation in DOM * CVE-2026-11037: Out of bounds write in Codecs * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity * CVE-2026-11039: Uninitialized Use in Skia * CVE-2026-11040: Use after free in ANGLE * CVE-2026-11041: Insufficient validation of untrusted input in Media * CVE-2026-11042: Use after free in Views * CVE-2026-11043: Out of bounds write in ANGLE * CVE-2026-11044: Integer overflow in ANGLE * CVE-2026-11045: Insufficient validation of untrusted input in GPU * CVE-2026-11046: Insufficient validation of untrusted input in Media * CVE-2026-11047: Insufficient validation of untrusted input in Base * CVE-2026-11048: Inappropriate implementation in Extensions * CVE-2026-11049: Use after free in Password Manager * CVE-2026-11050: Use after free in V8 * CVE-2026-11051: Out of bounds read in ANGLE * CVE-2026-11052: Type Confusion in GPU * CVE-2026-11053: VULNERABILITY in WebRTC * CVE-2026-11054: Use after free in WebRTC * CVE-2026-11055: Use after free in ANGLE * CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-11057: Uninitialized Use in Skia * CVE-2026-11058: Integer overflow in CredentialProvider * CVE-2026-11059: Use after free in Blink * CVE-2026-11060: Use after free in Media * CVE-2026-11061: Out of bounds read in ANGLE * CVE-2026-11062: Insufficient policy enforcement in Extensions * CVE-2026-11063: Insufficient validation of untrusted input in WebNN * CVE-2026-11064: Uninitialized Use in GPU * CVE-2026-11065: Use after free in ANGLE * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE * CVE-2026-11067: Uninitialized Use in Dawn * CVE-2026-11068: Use after free in WebSockets * CVE-2026-11069: Insufficient validation of untrusted input in Cast * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting * CVE-2026-11071: Use after free in Base * CVE-2026-11072: Use after free in WebView * CVE-2026-11073: Use after free in WebGL * CVE-2026-11074: Use after free in WebRTC * CVE-2026-11075: Out of bounds read in V8 * CVE-2026-11076: Type Confusion in CSS * CVE-2026-11077: Out of bounds read in Dawn * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem * CVE-2026-11079: Insufficient validation of untrusted input in Codecs * CVE-2026-11080: Use after free in WebView * CVE-2026-11081: Policy bypass in Canvas * CVE-2026-11082: Use after free in GPU * CVE-2026-11083: Inappropriate implementation in Password Manager * CVE-2026-11084: Inappropriate implementation in Password Manager * CVE-2026-11085: Integer overflow in GPU * CVE-2026-11086: Insufficient validation of untrusted input in Dawn * CVE-2026-11087: Uninitialized Use in ANGLE * CVE-2026-11088: Integer overflow in ANGLE * CVE-2026-11089: Uninitialized Use in Media * CVE-2026-11090: Uninitialized Use in ANGLE * CVE-2026-11091: Inappropriate implementation in Dawn * CVE-2026-11092: Insufficient policy enforcement in DevTools * CVE-2026-11093: Insufficient validation of untrusted input in Printing * CVE-2026-11094: Use after free in Codecs * CVE-2026-11095: Insufficient validation of untrusted input in Codecs * CVE-2026-11096: Out of bounds read in WebRTC * CVE-2026-11097: Inappropriate implementation in WebView * CVE-2026-11098: Insufficient validation of untrusted input in GPU * CVE-2026-11099: Vulnerability in Skia * CVE-2026-11100: Use after free in File Input * CVE-2026-11101: Uninitialized Use in Dawn * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps * CVE-2026-11103: Inappropriate implementation in Installer * CVE-2026-11104: Uninitialized Use in ANGLE * CVE-2026-11105: Insufficient validation of untrusted input in WebUI * CVE-2026-11106: Inappropriate implementation in Media * CVE-2026-11107: Inappropriate implementation in Downloads * CVE-2026-11108: Inappropriate implementation in NFC * CVE-2026-11109: Uninitialized Use in ANGLE * CVE-2026-11110: Uninitialized Use in ANGLE * CVE-2026-11111: Out of bounds read in ANGLE * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE * CVE-2026-11114: Use after free in Device Trust * CVE-2026-11115: Use after free in Updater * CVE-2026-11116: Use after free in Chromoting * CVE-2026-11117: Use after free in Views * CVE-2026-11118: Use after free in WebRTC * CVE-2026-11119: Insufficient validation of untrusted input in GPU * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting * CVE-2026-11121: Insufficient validation of untrusted input in Skia * CVE-2026-11122: Inappropriate implementation in Keyboard * CVE-2026-11123: Uninitialized Use in ANGLE * CVE-2026-11124: Heap buffer overflow in Skia * CVE-2026-11125: Use after free in Compositing * CVE-2026-11126: Insufficient validation of untrusted input in DevTools * CVE-2026-11127: Inappropriate implementation in WebAPKs * CVE-2026-11128: Insufficient validation of untrusted input in Web Share * CVE-2026-11129: Inappropriate implementation in Extensions * CVE-2026-11130: Use after free in Media * CVE-2026-11131: Use after free in Autofill * CVE-2026-11132: Policy bypass in Paint * CVE-2026-11133: Insufficient policy enforcement in Paint * CVE-2026-11134: Insufficient data validation in Media * CVE-2026-11135: Insufficient policy enforcement in Autofill * CVE-2026-11136: Use after free in Canvas * CVE-2026-11137: Uninitialized Use in ANGLE * CVE-2026-11138: Uninitialized Use in ANGLE * CVE-2026-11139: Policy bypass in Paint * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast * CVE-2026-11141: Uninitialized Use in Audio * CVE-2026-11142: Policy bypass in Paint * CVE-2026-11143: Heap buffer overflow in Extensions * CVE-2026-11144: Use after free in Media * CVE-2026-11145: Race in Geolocation * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting * CVE-2026-11147: Use after free in WebML * CVE-2026-11148: Inappropriate implementation in Payments * CVE-2026-11149: Insufficient validation of untrusted input in Extensions * CVE-2026-11150: Inappropriate implementation in XML * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager * CVE-2026-11152: Object lifecycle issue in Dawn * CVE-2026-11153: Side-channel information leakage in Forms * CVE-2026-11154: Use after free in Dawn * CVE-2026-11155: Insufficient policy enforcement in CSS * CVE-2026-11156: Inappropriate implementation in CSS * CVE-2026-11157: Script injection in Accessibility * CVE-2026-11158: Insufficient validation of untrusted input in Downloads * CVE-2026-11159: Uninitialized Use in Skia * CVE-2026-11160: Out of bounds read in Input * CVE-2026-11161: Insufficient data validation in DataTransfer * CVE-2026-11162: Insufficient policy enforcement in CSS * CVE-2026-11163: Use after free in Messages * CVE-2026-11164: Use after free in Blink * CVE-2026-11165: Use after free in WebMIDI * CVE-2026-11166: Inappropriate implementation in SVG * CVE-2026-11167: Inappropriate implementation in WebView * CVE-2026-11168: Insufficient policy enforcement in Extensions * CVE-2026-11169: Inappropriate implementation in XML * CVE-2026-11170: Inappropriate implementation in Chromoting * CVE-2026-11171: Integer overflow in Blink * CVE-2026-11172: Incorrect security UI in Contact Picker * CVE-2026-11173: Out of bounds write in V8 * CVE-2026-11174: Insufficient policy enforcement in Site Isolation * CVE-2026-11175: Incorrect security UI in Messages * CVE-2026-11176: Inappropriate implementation in Media * CVE-2026-11177: Use after free in Omnibox * CVE-2026-11178: Policy bypass in WebView * CVE-2026-11179: Inappropriate implementation in ORB * CVE-2026-11180: Policy bypass in SVG * CVE-2026-11181: Inappropriate implementation in Media Session * CVE-2026-11182: Inappropriate implementation in SVG * CVE-2026-11183: Out of bounds read in GWP-ASan * CVE-2026-11184: Insufficient policy enforcement in Actor * CVE-2026-11185: Use after free in V8 * CVE-2026-11186: Inappropriate implementation in CSS * CVE-2026-11187: Insufficient policy enforcement in Glic * CVE-2026-11188: Use after free in USB * CVE-2026-11189: Insufficient validation of untrusted input in DevTools * CVE-2026-11190: Insufficient policy enforcement in Extensions * CVE-2026-11191: Out of bounds memory access in ANGLE * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager * CVE-2026-11193: Insufficient policy enforcement in Password Manager * CVE-2026-11194: Inappropriate implementation in Network * CVE-2026-11195: Inappropriate implementation in MHTML * CVE-2026-11196: Type Confusion in XML * CVE-2026-11197: Insufficient policy enforcement in Workers * CVE-2026-11198: Insufficient validation of untrusted input in Codecs * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC * CVE-2026-11200: Inappropriate implementation in WebRTC * CVE-2026-11201: Use after free in ServiceWorker * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11203: Policy bypass in GPU * CVE-2026-11204: Inappropriate implementation in Signin * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11206: Policy bypass in ServiceWorker * CVE-2026-11207: Insufficient validation of untrusted input in Autofill * CVE-2026-11208: Use after free in Codecs * CVE-2026-11209: Insufficient policy enforcement in Passwords * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing * CVE-2026-11211: Integer overflow in V8 * CVE-2026-11212: Insufficient policy enforcement in DevTools * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode * CVE-2026-11214: Inappropriate implementation in Chrome for iOS * CVE-2026-11215: Inappropriate implementation in Cronet * CVE-2026-11216: Incorrect security UI in File Input * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames * CVE-2026-11218: Inappropriate implementation in PlatformIntegration * CVE-2026-11219: Insufficient data validation in Navigation * CVE-2026-11220: Insufficient validation of untrusted input in Navigation * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock * CVE-2026-11222: Incorrect security UI in Tab Strip * CVE-2026-11223: Insufficient validation of untrusted input in Network * CVE-2026-11224: Use after free in Chromoting * CVE-2026-11225: Incorrect security UI in WebUI * CVE-2026-11226: Insufficient policy enforcement in PreviewTab * CVE-2026-11227: Incorrect security UI in Tab Hover Cards * CVE-2026-11228: Incorrect security UI in File Input * CVE-2026-11229: Insufficient policy enforcement in Enterprise * CVE-2026-11230: Use after free in Extensions * CVE-2026-11231: Inappropriate implementation in Safe Browsing * CVE-2026-11232: Inappropriate implementation in TabGroups * CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs * CVE-2026-11235: Insufficient validation of untrusted input in Compositing * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth * CVE-2026-11237: Insufficient validation of untrusted input in Media * CVE-2026-11238: Inappropriate implementation in DevTools * CVE-2026-11239: Insufficient validation of untrusted input in Extensions * CVE-2026-11240: Insufficient validation of untrusted input in Loader * CVE-2026-11241: Insufficient validation of untrusted input in Cast * CVE-2026-11242: Insufficient validation of untrusted input in Plugins * CVE-2026-11243: Incorrect security UI in Downloads * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-11245: Inappropriate implementation in Payments * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB * CVE-2026-11247: Insufficient policy enforcement in CustomTabs * CVE-2026-11248: Policy bypass in Google Lens * CVE-2026-11249: Use after free in Network * CVE-2026-11250: Inappropriate implementation in DevTools * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager * CVE-2026-11252: Policy bypass in Content Settings * CVE-2026-11253: Race in Permissions * CVE-2026-11254: Inappropriate implementation in Permissions * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API * CVE-2026-11256: Out of bounds read in GPU * CVE-2026-11257: Inappropriate implementation in Browser * CVE-2026-11258: Inappropriate implementation in File System Access * CVE-2026-11259: Insufficient validation of untrusted input in Cast * CVE-2026-11260: Policy bypass in Permissions * CVE-2026-11261: Insufficient validation of untrusted input in PDF * CVE-2026-11262: Use after free in TabStrip * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication * CVE-2026-11264: Policy bypass in Content Security Policy * CVE-2026-11265: Insufficient data validation in Autofill * CVE-2026-11266: Policy bypass in SafeBrowsing * CVE-2026-11267: Insufficient policy enforcement in Extensions * CVE-2026-11268: Uninitialized Use in ANGLE * CVE-2026-11269: Inappropriate implementation in Extensions * CVE-2026-11270: Inappropriate implementation in UI * CVE-2026-11271: Incorrect security UI in Passwords * CVE-2026-11272: Insufficient validation of untrusted input in Reading List * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox * CVE-2026-11274: Inappropriate implementation in DOM Distiller * CVE-2026-11275: Insufficient policy enforcement in Page Info * CVE-2026-11276: Inappropriate implementation in Cast * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11278: Inappropriate implementation in CustomTabs * CVE-2026-11279: Out of bounds read in DevTools * CVE-2026-11280: Insufficient validation of untrusted input in Signin * CVE-2026-11281: Integer overflow in Chromoting * CVE-2026-11282: Policy bypass in Sandbox * CVE-2026-11283: Policy bypass in Shortcuts * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11286: Insufficient validation of untrusted input in Wallet * CVE-2026-11287: Insufficient validation of untrusted input in Navigation * CVE-2026-11288: Policy bypass in CSS * CVE-2026-11289: Side-channel information leakage in Paint * CVE-2026-11290: Integer overflow in WebView * CVE-2026-11291: Policy bypass in Android Autofill * CVE-2026-11292: Policy bypass in Blink * CVE-2026-11293: Use after free in Input * CVE-2026-11294: Inappropriate implementation in Passwords * CVE-2026-11295: Inappropriate implementation in WebView * CVE-2026-11296: Inappropriate implementation in ImageCapture * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11299: Out of bounds read in Fonts * CVE-2026-11300: Inappropriate implementation in Permissions * CVE-2026-11301: Out of bounds read in LiveCaption * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11303: Use after free in PDFium * CVE-2026-11304: Use after free in PDFium * CVE-2026-11305: Use after free in PDFium * CVE-2026-11306: Use after free in PDFium * CVE-2026-11307: Use after free in PDFium * CVE-2026-11308: Inappropriate implementation in Extensions * CVE-2026-11309: Insufficient policy enforcement in History ++++ chromium: - Chromium 149 (149.0.7827.53) stable (boo#1267706): * CVE-2026-10881: Out of bounds read and write in ANGLE * CVE-2026-10882: Use after free in Network * CVE-2026-10883: Out of bounds write in ANGLE * CVE-2026-10884: Use after free in Chromecast * CVE-2026-10885: Use after free in Chrome for iOS * CVE-2026-10886: Use after free in FileSystem * CVE-2026-10887: Use after free in Chromoting * CVE-2026-10888: Use after free in Cast Streaming * CVE-2026-10889: Out of bounds read in ANGLE * CVE-2026-10890: Use after free in Cast * CVE-2026-10891: Use after free in GFX * CVE-2026-10892: Out of bounds write in GPU * CVE-2026-10893: Use after free in Chromoting * CVE-2026-10894: Use after free in Printing * CVE-2026-10895: Use after free in Ozone * CVE-2026-10896: Use after free in Chrome for iOS * CVE-2026-10897: Out of bounds write in GPU * CVE-2026-10898: Stack buffer overflow in GPU * CVE-2026-10899: Use after free in Ozone * CVE-2026-10900: Use after free in Passwords * CVE-2026-10901: Use after free in Passwords * CVE-2026-10902: Use after free in Ozone * CVE-2026-10903: Use after free in WebRTC * CVE-2026-10904: Inappropriate implementation in V8 * CVE-2026-10905: Use after free in Network * CVE-2026-10906: Use after free in WebAuthentication * CVE-2026-10907: Out of bounds write in ANGLE * CVE-2026-10908: Use after free in FullScreen * CVE-2026-10909: Use after free in Dawn * CVE-2026-10910: Type Confusion in V8 * CVE-2026-10911: Insufficient validation of untrusted input in Media * CVE-2026-10912: Insufficient validation of untrusted input in Extensions * CVE-2026-10913: Use after free in ANGLE * CVE-2026-10914: Use after free in ANGLE * CVE-2026-10915: Use after free in Core * CVE-2026-10916: Insufficient validation of untrusted input in DevTools * CVE-2026-10917: Insufficient validation of untrusted input in Media * CVE-2026-10918: Use after free in Viz * CVE-2026-10919: Use after free in ANGLE * CVE-2026-10920: Insufficient validation of untrusted input in WebShare * CVE-2026-10921: Integer overflow in Dawn * CVE-2026-10922: Insufficient validation of untrusted input in DevTools * CVE-2026-10923: Use after free in WebAppInstalls * CVE-2026-10924: Integer overflow in Chromecast * CVE-2026-10925: Out of bounds write in Skia * CVE-2026-10926: Use after free in Cast * CVE-2026-10927: Out of bounds read in Dawn * CVE-2026-10928: Script injection in Headless * CVE-2026-10929: Heap buffer overflow in ANGLE * CVE-2026-10930: Out of bounds read in ANGLE * CVE-2026-10931: Use after free in FileSystem * CVE-2026-10932: Use after free in UI * CVE-2026-10933: Use after free in Audio * CVE-2026-10934: Use after free in Autofill * CVE-2026-10935: Inappropriate implementation in V8 * CVE-2026-10936: Type Confusion in V8 * CVE-2026-10937: Inappropriate implementation in Passwords * CVE-2026-10938: Insufficient validation of untrusted input in Input * CVE-2026-10939: Use after free in WebRTC * CVE-2026-10940: Race in Codecs * CVE-2026-10941: Out of bounds memory access in Skia * CVE-2026-10942: Insufficient validation of untrusted input in UI * CVE-2026-10943: Use after free in WebRTC * CVE-2026-10944: Insufficient policy enforcement in Autofill * CVE-2026-10945: Use after free in PDF * CVE-2026-10946: Heap buffer overflow in Media * CVE-2026-10947: Use after free in WebRTC * CVE-2026-10948: Use after free in WebRTC * CVE-2026-10949: Heap buffer overflow in Video * CVE-2026-10950: Insufficient policy enforcement in Autofill * CVE-2026-10951: Use after free in Autofill * CVE-2026-10952: Use after free in Chrome for iOS * CVE-2026-10953: Use after free in Core * CVE-2026-10954: Use after free in Actor * CVE-2026-10955: Type Confusion in ANGLE * CVE-2026-10956: Use after free in MimeHandlerView * CVE-2026-10957: Use after free in Glic * CVE-2026-10958: Use after free in Chrome for iOS * CVE-2026-10959: Use after free in Input * CVE-2026-10960: Uninitialized Use in Codecs * CVE-2026-10961: Use after free in Chrome for iOS * CVE-2026-10962: Type Confusion in Media * CVE-2026-10963: Integer overflow in V8 * CVE-2026-10964: Integer overflow in V8 * CVE-2026-10965: Integer overflow in DevTools * CVE-2026-10966: Insufficient validation of untrusted input in Codecs * CVE-2026-10967: Use after free in SurfaceCapture * CVE-2026-10968: Insufficient validation of untrusted input in Dawn * CVE-2026-10969: Insufficient validation of untrusted input in Extensions * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups * CVE-2026-10971: Insufficient validation of untrusted input in Printing * CVE-2026-10972: Use after free in Ozone * CVE-2026-10973: Uninitialized Use in Dawn * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE * CVE-2026-10975: Use after free in WebRTC * CVE-2026-10976: Uninitialized Use in Dawn * CVE-2026-10977: Uninitialized Use in Skia * CVE-2026-10978: Use after free in Chromoting * CVE-2026-10979: Out of bounds read in ANGLE * CVE-2026-10980: Insufficient validation of untrusted input in DevTools * CVE-2026-10981: Insufficient validation of untrusted input in Codecs * CVE-2026-10982: Use after free in WebXR * CVE-2026-10983: Insufficient validation of untrusted input in Dawn * CVE-2026-10984: Inappropriate implementation in Accessibility * CVE-2026-10985: Out of bounds read in Skia * CVE-2026-10986: Integer overflow in Media * CVE-2026-10987: Integer overflow in V8 * CVE-2026-10988: Use after free in Views * CVE-2026-10989: Inappropriate implementation in V8 * CVE-2026-10990: Use after free in Glic * CVE-2026-10991: Use after free in V8 * CVE-2026-10992: Insufficient data validation in Animation * CVE-2026-10993: Heap buffer overflow in Skia * CVE-2026-10994: Uninitialized Use in ANGLE * CVE-2026-10995: Heap buffer overflow in TabStrip * CVE-2026-10996: Inappropriate implementation in Workers * CVE-2026-10997: Insufficient policy enforcement in Extensions * CVE-2026-10998: Out of bounds read in Media * CVE-2026-10999: Out of bounds memory access in ANGLE * CVE-2026-11000: Use after free in Fonts * CVE-2026-11001: Incorrect security UI in Payments * CVE-2026-11002: Use after free in Autofill * CVE-2026-11003: Use after free in WebRTC * CVE-2026-11004: Out of bounds read in ANGLE * CVE-2026-11005: Out of bounds read in ANGLE * CVE-2026-11006: Out of bounds read in Dawn * CVE-2026-11007: Insufficient validation of untrusted input in WebView * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11009: Use after free in USB * CVE-2026-11010: Use after free in WebShare * CVE-2026-11011: Insufficient policy enforcement in Password Manager * CVE-2026-11012: Use after free in Serial * CVE-2026-11013: Insufficient validation of untrusted input in Network * CVE-2026-11014: Insufficient policy enforcement in Extensions * CVE-2026-11015: Out of bounds read in WebGPU * CVE-2026-11016: Insufficient validation of untrusted input in Network * CVE-2026-11017: Inappropriate implementation in Link Preview * CVE-2026-11018: Insufficient policy enforcement in Actor * CVE-2026-11019: Inappropriate implementation in Payments * CVE-2026-11020: Inappropriate implementation in Extensions * CVE-2026-11021: Insufficient validation of untrusted input in GPU * CVE-2026-11022: Insufficient validation of untrusted input in DevTools * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11024: Stack buffer overflow in Skia * CVE-2026-11025: Insufficient policy enforcement in Navigation * CVE-2026-11026: Insufficient policy enforcement in Extensions * CVE-2026-11027: Insufficient validation of untrusted input in Glic * CVE-2026-11028: Use after free in Media * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop * CVE-2026-11030: Use after free in Network * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager * CVE-2026-11032: Insufficient data validation in Password Manager * CVE-2026-11033: Uninitialized Use in WebML * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs * CVE-2026-11036: Inappropriate implementation in DOM * CVE-2026-11037: Out of bounds write in Codecs * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity * CVE-2026-11039: Uninitialized Use in Skia * CVE-2026-11040: Use after free in ANGLE * CVE-2026-11041: Insufficient validation of untrusted input in Media * CVE-2026-11042: Use after free in Views * CVE-2026-11043: Out of bounds write in ANGLE * CVE-2026-11044: Integer overflow in ANGLE * CVE-2026-11045: Insufficient validation of untrusted input in GPU * CVE-2026-11046: Insufficient validation of untrusted input in Media * CVE-2026-11047: Insufficient validation of untrusted input in Base * CVE-2026-11048: Inappropriate implementation in Extensions * CVE-2026-11049: Use after free in Password Manager * CVE-2026-11050: Use after free in V8 * CVE-2026-11051: Out of bounds read in ANGLE * CVE-2026-11052: Type Confusion in GPU * CVE-2026-11053: VULNERABILITY in WebRTC * CVE-2026-11054: Use after free in WebRTC * CVE-2026-11055: Use after free in ANGLE * CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-11057: Uninitialized Use in Skia * CVE-2026-11058: Integer overflow in CredentialProvider * CVE-2026-11059: Use after free in Blink * CVE-2026-11060: Use after free in Media * CVE-2026-11061: Out of bounds read in ANGLE * CVE-2026-11062: Insufficient policy enforcement in Extensions * CVE-2026-11063: Insufficient validation of untrusted input in WebNN * CVE-2026-11064: Uninitialized Use in GPU * CVE-2026-11065: Use after free in ANGLE * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE * CVE-2026-11067: Uninitialized Use in Dawn * CVE-2026-11068: Use after free in WebSockets * CVE-2026-11069: Insufficient validation of untrusted input in Cast * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting * CVE-2026-11071: Use after free in Base * CVE-2026-11072: Use after free in WebView * CVE-2026-11073: Use after free in WebGL * CVE-2026-11074: Use after free in WebRTC * CVE-2026-11075: Out of bounds read in V8 * CVE-2026-11076: Type Confusion in CSS * CVE-2026-11077: Out of bounds read in Dawn * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem * CVE-2026-11079: Insufficient validation of untrusted input in Codecs * CVE-2026-11080: Use after free in WebView * CVE-2026-11081: Policy bypass in Canvas * CVE-2026-11082: Use after free in GPU * CVE-2026-11083: Inappropriate implementation in Password Manager * CVE-2026-11084: Inappropriate implementation in Password Manager * CVE-2026-11085: Integer overflow in GPU * CVE-2026-11086: Insufficient validation of untrusted input in Dawn * CVE-2026-11087: Uninitialized Use in ANGLE * CVE-2026-11088: Integer overflow in ANGLE * CVE-2026-11089: Uninitialized Use in Media * CVE-2026-11090: Uninitialized Use in ANGLE * CVE-2026-11091: Inappropriate implementation in Dawn * CVE-2026-11092: Insufficient policy enforcement in DevTools * CVE-2026-11093: Insufficient validation of untrusted input in Printing * CVE-2026-11094: Use after free in Codecs * CVE-2026-11095: Insufficient validation of untrusted input in Codecs * CVE-2026-11096: Out of bounds read in WebRTC * CVE-2026-11097: Inappropriate implementation in WebView * CVE-2026-11098: Insufficient validation of untrusted input in GPU * CVE-2026-11099: Vulnerability in Skia * CVE-2026-11100: Use after free in File Input * CVE-2026-11101: Uninitialized Use in Dawn * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps * CVE-2026-11103: Inappropriate implementation in Installer * CVE-2026-11104: Uninitialized Use in ANGLE * CVE-2026-11105: Insufficient validation of untrusted input in WebUI * CVE-2026-11106: Inappropriate implementation in Media * CVE-2026-11107: Inappropriate implementation in Downloads * CVE-2026-11108: Inappropriate implementation in NFC * CVE-2026-11109: Uninitialized Use in ANGLE * CVE-2026-11110: Uninitialized Use in ANGLE * CVE-2026-11111: Out of bounds read in ANGLE * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE * CVE-2026-11114: Use after free in Device Trust * CVE-2026-11115: Use after free in Updater * CVE-2026-11116: Use after free in Chromoting * CVE-2026-11117: Use after free in Views * CVE-2026-11118: Use after free in WebRTC * CVE-2026-11119: Insufficient validation of untrusted input in GPU * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting * CVE-2026-11121: Insufficient validation of untrusted input in Skia * CVE-2026-11122: Inappropriate implementation in Keyboard * CVE-2026-11123: Uninitialized Use in ANGLE * CVE-2026-11124: Heap buffer overflow in Skia * CVE-2026-11125: Use after free in Compositing * CVE-2026-11126: Insufficient validation of untrusted input in DevTools * CVE-2026-11127: Inappropriate implementation in WebAPKs * CVE-2026-11128: Insufficient validation of untrusted input in Web Share * CVE-2026-11129: Inappropriate implementation in Extensions * CVE-2026-11130: Use after free in Media * CVE-2026-11131: Use after free in Autofill * CVE-2026-11132: Policy bypass in Paint * CVE-2026-11133: Insufficient policy enforcement in Paint * CVE-2026-11134: Insufficient data validation in Media * CVE-2026-11135: Insufficient policy enforcement in Autofill * CVE-2026-11136: Use after free in Canvas * CVE-2026-11137: Uninitialized Use in ANGLE * CVE-2026-11138: Uninitialized Use in ANGLE * CVE-2026-11139: Policy bypass in Paint * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast * CVE-2026-11141: Uninitialized Use in Audio * CVE-2026-11142: Policy bypass in Paint * CVE-2026-11143: Heap buffer overflow in Extensions * CVE-2026-11144: Use after free in Media * CVE-2026-11145: Race in Geolocation * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting * CVE-2026-11147: Use after free in WebML * CVE-2026-11148: Inappropriate implementation in Payments * CVE-2026-11149: Insufficient validation of untrusted input in Extensions * CVE-2026-11150: Inappropriate implementation in XML * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager * CVE-2026-11152: Object lifecycle issue in Dawn * CVE-2026-11153: Side-channel information leakage in Forms * CVE-2026-11154: Use after free in Dawn * CVE-2026-11155: Insufficient policy enforcement in CSS * CVE-2026-11156: Inappropriate implementation in CSS * CVE-2026-11157: Script injection in Accessibility * CVE-2026-11158: Insufficient validation of untrusted input in Downloads * CVE-2026-11159: Uninitialized Use in Skia * CVE-2026-11160: Out of bounds read in Input * CVE-2026-11161: Insufficient data validation in DataTransfer * CVE-2026-11162: Insufficient policy enforcement in CSS * CVE-2026-11163: Use after free in Messages * CVE-2026-11164: Use after free in Blink * CVE-2026-11165: Use after free in WebMIDI * CVE-2026-11166: Inappropriate implementation in SVG * CVE-2026-11167: Inappropriate implementation in WebView * CVE-2026-11168: Insufficient policy enforcement in Extensions * CVE-2026-11169: Inappropriate implementation in XML * CVE-2026-11170: Inappropriate implementation in Chromoting * CVE-2026-11171: Integer overflow in Blink * CVE-2026-11172: Incorrect security UI in Contact Picker * CVE-2026-11173: Out of bounds write in V8 * CVE-2026-11174: Insufficient policy enforcement in Site Isolation * CVE-2026-11175: Incorrect security UI in Messages * CVE-2026-11176: Inappropriate implementation in Media * CVE-2026-11177: Use after free in Omnibox * CVE-2026-11178: Policy bypass in WebView * CVE-2026-11179: Inappropriate implementation in ORB * CVE-2026-11180: Policy bypass in SVG * CVE-2026-11181: Inappropriate implementation in Media Session * CVE-2026-11182: Inappropriate implementation in SVG * CVE-2026-11183: Out of bounds read in GWP-ASan * CVE-2026-11184: Insufficient policy enforcement in Actor * CVE-2026-11185: Use after free in V8 * CVE-2026-11186: Inappropriate implementation in CSS * CVE-2026-11187: Insufficient policy enforcement in Glic * CVE-2026-11188: Use after free in USB * CVE-2026-11189: Insufficient validation of untrusted input in DevTools * CVE-2026-11190: Insufficient policy enforcement in Extensions * CVE-2026-11191: Out of bounds memory access in ANGLE * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager * CVE-2026-11193: Insufficient policy enforcement in Password Manager * CVE-2026-11194: Inappropriate implementation in Network * CVE-2026-11195: Inappropriate implementation in MHTML * CVE-2026-11196: Type Confusion in XML * CVE-2026-11197: Insufficient policy enforcement in Workers * CVE-2026-11198: Insufficient validation of untrusted input in Codecs * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC * CVE-2026-11200: Inappropriate implementation in WebRTC * CVE-2026-11201: Use after free in ServiceWorker * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11203: Policy bypass in GPU * CVE-2026-11204: Inappropriate implementation in Signin * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11206: Policy bypass in ServiceWorker * CVE-2026-11207: Insufficient validation of untrusted input in Autofill * CVE-2026-11208: Use after free in Codecs * CVE-2026-11209: Insufficient policy enforcement in Passwords * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing * CVE-2026-11211: Integer overflow in V8 * CVE-2026-11212: Insufficient policy enforcement in DevTools * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode * CVE-2026-11214: Inappropriate implementation in Chrome for iOS * CVE-2026-11215: Inappropriate implementation in Cronet * CVE-2026-11216: Incorrect security UI in File Input * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames * CVE-2026-11218: Inappropriate implementation in PlatformIntegration * CVE-2026-11219: Insufficient data validation in Navigation * CVE-2026-11220: Insufficient validation of untrusted input in Navigation * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock * CVE-2026-11222: Incorrect security UI in Tab Strip * CVE-2026-11223: Insufficient validation of untrusted input in Network * CVE-2026-11224: Use after free in Chromoting * CVE-2026-11225: Incorrect security UI in WebUI * CVE-2026-11226: Insufficient policy enforcement in PreviewTab * CVE-2026-11227: Incorrect security UI in Tab Hover Cards * CVE-2026-11228: Incorrect security UI in File Input * CVE-2026-11229: Insufficient policy enforcement in Enterprise * CVE-2026-11230: Use after free in Extensions * CVE-2026-11231: Inappropriate implementation in Safe Browsing * CVE-2026-11232: Inappropriate implementation in TabGroups * CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs * CVE-2026-11235: Insufficient validation of untrusted input in Compositing * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth * CVE-2026-11237: Insufficient validation of untrusted input in Media * CVE-2026-11238: Inappropriate implementation in DevTools * CVE-2026-11239: Insufficient validation of untrusted input in Extensions * CVE-2026-11240: Insufficient validation of untrusted input in Loader * CVE-2026-11241: Insufficient validation of untrusted input in Cast * CVE-2026-11242: Insufficient validation of untrusted input in Plugins * CVE-2026-11243: Incorrect security UI in Downloads * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-11245: Inappropriate implementation in Payments * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB * CVE-2026-11247: Insufficient policy enforcement in CustomTabs * CVE-2026-11248: Policy bypass in Google Lens * CVE-2026-11249: Use after free in Network * CVE-2026-11250: Inappropriate implementation in DevTools * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager * CVE-2026-11252: Policy bypass in Content Settings * CVE-2026-11253: Race in Permissions * CVE-2026-11254: Inappropriate implementation in Permissions * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API * CVE-2026-11256: Out of bounds read in GPU * CVE-2026-11257: Inappropriate implementation in Browser * CVE-2026-11258: Inappropriate implementation in File System Access * CVE-2026-11259: Insufficient validation of untrusted input in Cast * CVE-2026-11260: Policy bypass in Permissions * CVE-2026-11261: Insufficient validation of untrusted input in PDF * CVE-2026-11262: Use after free in TabStrip * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication * CVE-2026-11264: Policy bypass in Content Security Policy * CVE-2026-11265: Insufficient data validation in Autofill * CVE-2026-11266: Policy bypass in SafeBrowsing * CVE-2026-11267: Insufficient policy enforcement in Extensions * CVE-2026-11268: Uninitialized Use in ANGLE * CVE-2026-11269: Inappropriate implementation in Extensions * CVE-2026-11270: Inappropriate implementation in UI * CVE-2026-11271: Incorrect security UI in Passwords * CVE-2026-11272: Insufficient validation of untrusted input in Reading List * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox * CVE-2026-11274: Inappropriate implementation in DOM Distiller * CVE-2026-11275: Insufficient policy enforcement in Page Info * CVE-2026-11276: Inappropriate implementation in Cast * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11278: Inappropriate implementation in CustomTabs * CVE-2026-11279: Out of bounds read in DevTools * CVE-2026-11280: Insufficient validation of untrusted input in Signin * CVE-2026-11281: Integer overflow in Chromoting * CVE-2026-11282: Policy bypass in Sandbox * CVE-2026-11283: Policy bypass in Shortcuts * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11286: Insufficient validation of untrusted input in Wallet * CVE-2026-11287: Insufficient validation of untrusted input in Navigation * CVE-2026-11288: Policy bypass in CSS * CVE-2026-11289: Side-channel information leakage in Paint * CVE-2026-11290: Integer overflow in WebView * CVE-2026-11291: Policy bypass in Android Autofill * CVE-2026-11292: Policy bypass in Blink * CVE-2026-11293: Use after free in Input * CVE-2026-11294: Inappropriate implementation in Passwords * CVE-2026-11295: Inappropriate implementation in WebView * CVE-2026-11296: Inappropriate implementation in ImageCapture * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11299: Out of bounds read in Fonts * CVE-2026-11300: Inappropriate implementation in Permissions * CVE-2026-11301: Out of bounds read in LiveCaption * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11303: Use after free in PDFium * CVE-2026-11304: Use after free in PDFium * CVE-2026-11305: Use after free in PDFium * CVE-2026-11306: Use after free in PDFium * CVE-2026-11307: Use after free in PDFium * CVE-2026-11308: Inappropriate implementation in Extensions * CVE-2026-11309: Insufficient policy enforcement in History ++++ chromium: - Chromium 149 (149.0.7827.53) stable (boo#1267706): * CVE-2026-10881: Out of bounds read and write in ANGLE * CVE-2026-10882: Use after free in Network * CVE-2026-10883: Out of bounds write in ANGLE * CVE-2026-10884: Use after free in Chromecast * CVE-2026-10885: Use after free in Chrome for iOS * CVE-2026-10886: Use after free in FileSystem * CVE-2026-10887: Use after free in Chromoting * CVE-2026-10888: Use after free in Cast Streaming * CVE-2026-10889: Out of bounds read in ANGLE * CVE-2026-10890: Use after free in Cast * CVE-2026-10891: Use after free in GFX * CVE-2026-10892: Out of bounds write in GPU * CVE-2026-10893: Use after free in Chromoting * CVE-2026-10894: Use after free in Printing * CVE-2026-10895: Use after free in Ozone * CVE-2026-10896: Use after free in Chrome for iOS * CVE-2026-10897: Out of bounds write in GPU * CVE-2026-10898: Stack buffer overflow in GPU * CVE-2026-10899: Use after free in Ozone * CVE-2026-10900: Use after free in Passwords * CVE-2026-10901: Use after free in Passwords * CVE-2026-10902: Use after free in Ozone * CVE-2026-10903: Use after free in WebRTC * CVE-2026-10904: Inappropriate implementation in V8 * CVE-2026-10905: Use after free in Network * CVE-2026-10906: Use after free in WebAuthentication * CVE-2026-10907: Out of bounds write in ANGLE * CVE-2026-10908: Use after free in FullScreen * CVE-2026-10909: Use after free in Dawn * CVE-2026-10910: Type Confusion in V8 * CVE-2026-10911: Insufficient validation of untrusted input in Media * CVE-2026-10912: Insufficient validation of untrusted input in Extensions * CVE-2026-10913: Use after free in ANGLE * CVE-2026-10914: Use after free in ANGLE * CVE-2026-10915: Use after free in Core * CVE-2026-10916: Insufficient validation of untrusted input in DevTools * CVE-2026-10917: Insufficient validation of untrusted input in Media * CVE-2026-10918: Use after free in Viz * CVE-2026-10919: Use after free in ANGLE * CVE-2026-10920: Insufficient validation of untrusted input in WebShare * CVE-2026-10921: Integer overflow in Dawn * CVE-2026-10922: Insufficient validation of untrusted input in DevTools * CVE-2026-10923: Use after free in WebAppInstalls * CVE-2026-10924: Integer overflow in Chromecast * CVE-2026-10925: Out of bounds write in Skia * CVE-2026-10926: Use after free in Cast * CVE-2026-10927: Out of bounds read in Dawn * CVE-2026-10928: Script injection in Headless * CVE-2026-10929: Heap buffer overflow in ANGLE * CVE-2026-10930: Out of bounds read in ANGLE * CVE-2026-10931: Use after free in FileSystem * CVE-2026-10932: Use after free in UI * CVE-2026-10933: Use after free in Audio * CVE-2026-10934: Use after free in Autofill * CVE-2026-10935: Inappropriate implementation in V8 * CVE-2026-10936: Type Confusion in V8 * CVE-2026-10937: Inappropriate implementation in Passwords * CVE-2026-10938: Insufficient validation of untrusted input in Input * CVE-2026-10939: Use after free in WebRTC * CVE-2026-10940: Race in Codecs * CVE-2026-10941: Out of bounds memory access in Skia * CVE-2026-10942: Insufficient validation of untrusted input in UI * CVE-2026-10943: Use after free in WebRTC * CVE-2026-10944: Insufficient policy enforcement in Autofill * CVE-2026-10945: Use after free in PDF * CVE-2026-10946: Heap buffer overflow in Media * CVE-2026-10947: Use after free in WebRTC * CVE-2026-10948: Use after free in WebRTC * CVE-2026-10949: Heap buffer overflow in Video * CVE-2026-10950: Insufficient policy enforcement in Autofill * CVE-2026-10951: Use after free in Autofill * CVE-2026-10952: Use after free in Chrome for iOS * CVE-2026-10953: Use after free in Core * CVE-2026-10954: Use after free in Actor * CVE-2026-10955: Type Confusion in ANGLE * CVE-2026-10956: Use after free in MimeHandlerView * CVE-2026-10957: Use after free in Glic * CVE-2026-10958: Use after free in Chrome for iOS * CVE-2026-10959: Use after free in Input * CVE-2026-10960: Uninitialized Use in Codecs * CVE-2026-10961: Use after free in Chrome for iOS * CVE-2026-10962: Type Confusion in Media * CVE-2026-10963: Integer overflow in V8 * CVE-2026-10964: Integer overflow in V8 * CVE-2026-10965: Integer overflow in DevTools * CVE-2026-10966: Insufficient validation of untrusted input in Codecs * CVE-2026-10967: Use after free in SurfaceCapture * CVE-2026-10968: Insufficient validation of untrusted input in Dawn * CVE-2026-10969: Insufficient validation of untrusted input in Extensions * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups * CVE-2026-10971: Insufficient validation of untrusted input in Printing * CVE-2026-10972: Use after free in Ozone * CVE-2026-10973: Uninitialized Use in Dawn * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE * CVE-2026-10975: Use after free in WebRTC * CVE-2026-10976: Uninitialized Use in Dawn * CVE-2026-10977: Uninitialized Use in Skia * CVE-2026-10978: Use after free in Chromoting * CVE-2026-10979: Out of bounds read in ANGLE * CVE-2026-10980: Insufficient validation of untrusted input in DevTools * CVE-2026-10981: Insufficient validation of untrusted input in Codecs * CVE-2026-10982: Use after free in WebXR * CVE-2026-10983: Insufficient validation of untrusted input in Dawn * CVE-2026-10984: Inappropriate implementation in Accessibility * CVE-2026-10985: Out of bounds read in Skia * CVE-2026-10986: Integer overflow in Media * CVE-2026-10987: Integer overflow in V8 * CVE-2026-10988: Use after free in Views * CVE-2026-10989: Inappropriate implementation in V8 * CVE-2026-10990: Use after free in Glic * CVE-2026-10991: Use after free in V8 * CVE-2026-10992: Insufficient data validation in Animation * CVE-2026-10993: Heap buffer overflow in Skia * CVE-2026-10994: Uninitialized Use in ANGLE * CVE-2026-10995: Heap buffer overflow in TabStrip * CVE-2026-10996: Inappropriate implementation in Workers * CVE-2026-10997: Insufficient policy enforcement in Extensions * CVE-2026-10998: Out of bounds read in Media * CVE-2026-10999: Out of bounds memory access in ANGLE * CVE-2026-11000: Use after free in Fonts * CVE-2026-11001: Incorrect security UI in Payments * CVE-2026-11002: Use after free in Autofill * CVE-2026-11003: Use after free in WebRTC * CVE-2026-11004: Out of bounds read in ANGLE * CVE-2026-11005: Out of bounds read in ANGLE * CVE-2026-11006: Out of bounds read in Dawn * CVE-2026-11007: Insufficient validation of untrusted input in WebView * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11009: Use after free in USB * CVE-2026-11010: Use after free in WebShare * CVE-2026-11011: Insufficient policy enforcement in Password Manager * CVE-2026-11012: Use after free in Serial * CVE-2026-11013: Insufficient validation of untrusted input in Network * CVE-2026-11014: Insufficient policy enforcement in Extensions * CVE-2026-11015: Out of bounds read in WebGPU * CVE-2026-11016: Insufficient validation of untrusted input in Network * CVE-2026-11017: Inappropriate implementation in Link Preview * CVE-2026-11018: Insufficient policy enforcement in Actor * CVE-2026-11019: Inappropriate implementation in Payments * CVE-2026-11020: Inappropriate implementation in Extensions * CVE-2026-11021: Insufficient validation of untrusted input in GPU * CVE-2026-11022: Insufficient validation of untrusted input in DevTools * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11024: Stack buffer overflow in Skia * CVE-2026-11025: Insufficient policy enforcement in Navigation * CVE-2026-11026: Insufficient policy enforcement in Extensions * CVE-2026-11027: Insufficient validation of untrusted input in Glic * CVE-2026-11028: Use after free in Media * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop * CVE-2026-11030: Use after free in Network * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager * CVE-2026-11032: Insufficient data validation in Password Manager * CVE-2026-11033: Uninitialized Use in WebML * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs * CVE-2026-11036: Inappropriate implementation in DOM * CVE-2026-11037: Out of bounds write in Codecs * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity * CVE-2026-11039: Uninitialized Use in Skia * CVE-2026-11040: Use after free in ANGLE * CVE-2026-11041: Insufficient validation of untrusted input in Media * CVE-2026-11042: Use after free in Views * CVE-2026-11043: Out of bounds write in ANGLE * CVE-2026-11044: Integer overflow in ANGLE * CVE-2026-11045: Insufficient validation of untrusted input in GPU * CVE-2026-11046: Insufficient validation of untrusted input in Media * CVE-2026-11047: Insufficient validation of untrusted input in Base * CVE-2026-11048: Inappropriate implementation in Extensions * CVE-2026-11049: Use after free in Password Manager * CVE-2026-11050: Use after free in V8 * CVE-2026-11051: Out of bounds read in ANGLE * CVE-2026-11052: Type Confusion in GPU * CVE-2026-11053: VULNERABILITY in WebRTC * CVE-2026-11054: Use after free in WebRTC * CVE-2026-11055: Use after free in ANGLE * CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-11057: Uninitialized Use in Skia * CVE-2026-11058: Integer overflow in CredentialProvider * CVE-2026-11059: Use after free in Blink * CVE-2026-11060: Use after free in Media * CVE-2026-11061: Out of bounds read in ANGLE * CVE-2026-11062: Insufficient policy enforcement in Extensions * CVE-2026-11063: Insufficient validation of untrusted input in WebNN * CVE-2026-11064: Uninitialized Use in GPU * CVE-2026-11065: Use after free in ANGLE * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE * CVE-2026-11067: Uninitialized Use in Dawn * CVE-2026-11068: Use after free in WebSockets * CVE-2026-11069: Insufficient validation of untrusted input in Cast * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting * CVE-2026-11071: Use after free in Base * CVE-2026-11072: Use after free in WebView * CVE-2026-11073: Use after free in WebGL * CVE-2026-11074: Use after free in WebRTC * CVE-2026-11075: Out of bounds read in V8 * CVE-2026-11076: Type Confusion in CSS * CVE-2026-11077: Out of bounds read in Dawn * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem * CVE-2026-11079: Insufficient validation of untrusted input in Codecs * CVE-2026-11080: Use after free in WebView * CVE-2026-11081: Policy bypass in Canvas * CVE-2026-11082: Use after free in GPU * CVE-2026-11083: Inappropriate implementation in Password Manager * CVE-2026-11084: Inappropriate implementation in Password Manager * CVE-2026-11085: Integer overflow in GPU * CVE-2026-11086: Insufficient validation of untrusted input in Dawn * CVE-2026-11087: Uninitialized Use in ANGLE * CVE-2026-11088: Integer overflow in ANGLE * CVE-2026-11089: Uninitialized Use in Media * CVE-2026-11090: Uninitialized Use in ANGLE * CVE-2026-11091: Inappropriate implementation in Dawn * CVE-2026-11092: Insufficient policy enforcement in DevTools * CVE-2026-11093: Insufficient validation of untrusted input in Printing * CVE-2026-11094: Use after free in Codecs * CVE-2026-11095: Insufficient validation of untrusted input in Codecs * CVE-2026-11096: Out of bounds read in WebRTC * CVE-2026-11097: Inappropriate implementation in WebView * CVE-2026-11098: Insufficient validation of untrusted input in GPU * CVE-2026-11099: Vulnerability in Skia * CVE-2026-11100: Use after free in File Input * CVE-2026-11101: Uninitialized Use in Dawn * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps * CVE-2026-11103: Inappropriate implementation in Installer * CVE-2026-11104: Uninitialized Use in ANGLE * CVE-2026-11105: Insufficient validation of untrusted input in WebUI * CVE-2026-11106: Inappropriate implementation in Media * CVE-2026-11107: Inappropriate implementation in Downloads * CVE-2026-11108: Inappropriate implementation in NFC * CVE-2026-11109: Uninitialized Use in ANGLE * CVE-2026-11110: Uninitialized Use in ANGLE * CVE-2026-11111: Out of bounds read in ANGLE * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE * CVE-2026-11114: Use after free in Device Trust * CVE-2026-11115: Use after free in Updater * CVE-2026-11116: Use after free in Chromoting * CVE-2026-11117: Use after free in Views * CVE-2026-11118: Use after free in WebRTC * CVE-2026-11119: Insufficient validation of untrusted input in GPU * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting * CVE-2026-11121: Insufficient validation of untrusted input in Skia * CVE-2026-11122: Inappropriate implementation in Keyboard * CVE-2026-11123: Uninitialized Use in ANGLE * CVE-2026-11124: Heap buffer overflow in Skia * CVE-2026-11125: Use after free in Compositing * CVE-2026-11126: Insufficient validation of untrusted input in DevTools * CVE-2026-11127: Inappropriate implementation in WebAPKs * CVE-2026-11128: Insufficient validation of untrusted input in Web Share * CVE-2026-11129: Inappropriate implementation in Extensions * CVE-2026-11130: Use after free in Media * CVE-2026-11131: Use after free in Autofill * CVE-2026-11132: Policy bypass in Paint * CVE-2026-11133: Insufficient policy enforcement in Paint * CVE-2026-11134: Insufficient data validation in Media * CVE-2026-11135: Insufficient policy enforcement in Autofill * CVE-2026-11136: Use after free in Canvas * CVE-2026-11137: Uninitialized Use in ANGLE * CVE-2026-11138: Uninitialized Use in ANGLE * CVE-2026-11139: Policy bypass in Paint * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast * CVE-2026-11141: Uninitialized Use in Audio * CVE-2026-11142: Policy bypass in Paint * CVE-2026-11143: Heap buffer overflow in Extensions * CVE-2026-11144: Use after free in Media * CVE-2026-11145: Race in Geolocation * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting * CVE-2026-11147: Use after free in WebML * CVE-2026-11148: Inappropriate implementation in Payments * CVE-2026-11149: Insufficient validation of untrusted input in Extensions * CVE-2026-11150: Inappropriate implementation in XML * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager * CVE-2026-11152: Object lifecycle issue in Dawn * CVE-2026-11153: Side-channel information leakage in Forms * CVE-2026-11154: Use after free in Dawn * CVE-2026-11155: Insufficient policy enforcement in CSS * CVE-2026-11156: Inappropriate implementation in CSS * CVE-2026-11157: Script injection in Accessibility * CVE-2026-11158: Insufficient validation of untrusted input in Downloads * CVE-2026-11159: Uninitialized Use in Skia * CVE-2026-11160: Out of bounds read in Input * CVE-2026-11161: Insufficient data validation in DataTransfer * CVE-2026-11162: Insufficient policy enforcement in CSS * CVE-2026-11163: Use after free in Messages * CVE-2026-11164: Use after free in Blink * CVE-2026-11165: Use after free in WebMIDI * CVE-2026-11166: Inappropriate implementation in SVG * CVE-2026-11167: Inappropriate implementation in WebView * CVE-2026-11168: Insufficient policy enforcement in Extensions * CVE-2026-11169: Inappropriate implementation in XML * CVE-2026-11170: Inappropriate implementation in Chromoting * CVE-2026-11171: Integer overflow in Blink * CVE-2026-11172: Incorrect security UI in Contact Picker * CVE-2026-11173: Out of bounds write in V8 * CVE-2026-11174: Insufficient policy enforcement in Site Isolation * CVE-2026-11175: Incorrect security UI in Messages * CVE-2026-11176: Inappropriate implementation in Media * CVE-2026-11177: Use after free in Omnibox * CVE-2026-11178: Policy bypass in WebView * CVE-2026-11179: Inappropriate implementation in ORB * CVE-2026-11180: Policy bypass in SVG * CVE-2026-11181: Inappropriate implementation in Media Session * CVE-2026-11182: Inappropriate implementation in SVG * CVE-2026-11183: Out of bounds read in GWP-ASan * CVE-2026-11184: Insufficient policy enforcement in Actor * CVE-2026-11185: Use after free in V8 * CVE-2026-11186: Inappropriate implementation in CSS * CVE-2026-11187: Insufficient policy enforcement in Glic * CVE-2026-11188: Use after free in USB * CVE-2026-11189: Insufficient validation of untrusted input in DevTools * CVE-2026-11190: Insufficient policy enforcement in Extensions * CVE-2026-11191: Out of bounds memory access in ANGLE * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager * CVE-2026-11193: Insufficient policy enforcement in Password Manager * CVE-2026-11194: Inappropriate implementation in Network * CVE-2026-11195: Inappropriate implementation in MHTML * CVE-2026-11196: Type Confusion in XML * CVE-2026-11197: Insufficient policy enforcement in Workers * CVE-2026-11198: Insufficient validation of untrusted input in Codecs * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC * CVE-2026-11200: Inappropriate implementation in WebRTC * CVE-2026-11201: Use after free in ServiceWorker * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11203: Policy bypass in GPU * CVE-2026-11204: Inappropriate implementation in Signin * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11206: Policy bypass in ServiceWorker * CVE-2026-11207: Insufficient validation of untrusted input in Autofill * CVE-2026-11208: Use after free in Codecs * CVE-2026-11209: Insufficient policy enforcement in Passwords * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing * CVE-2026-11211: Integer overflow in V8 * CVE-2026-11212: Insufficient policy enforcement in DevTools * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode * CVE-2026-11214: Inappropriate implementation in Chrome for iOS * CVE-2026-11215: Inappropriate implementation in Cronet * CVE-2026-11216: Incorrect security UI in File Input * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames * CVE-2026-11218: Inappropriate implementation in PlatformIntegration * CVE-2026-11219: Insufficient data validation in Navigation * CVE-2026-11220: Insufficient validation of untrusted input in Navigation * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock * CVE-2026-11222: Incorrect security UI in Tab Strip * CVE-2026-11223: Insufficient validation of untrusted input in Network * CVE-2026-11224: Use after free in Chromoting * CVE-2026-11225: Incorrect security UI in WebUI * CVE-2026-11226: Insufficient policy enforcement in PreviewTab * CVE-2026-11227: Incorrect security UI in Tab Hover Cards * CVE-2026-11228: Incorrect security UI in File Input * CVE-2026-11229: Insufficient policy enforcement in Enterprise * CVE-2026-11230: Use after free in Extensions * CVE-2026-11231: Inappropriate implementation in Safe Browsing * CVE-2026-11232: Inappropriate implementation in TabGroups * CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs * CVE-2026-11235: Insufficient validation of untrusted input in Compositing * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth * CVE-2026-11237: Insufficient validation of untrusted input in Media * CVE-2026-11238: Inappropriate implementation in DevTools * CVE-2026-11239: Insufficient validation of untrusted input in Extensions * CVE-2026-11240: Insufficient validation of untrusted input in Loader * CVE-2026-11241: Insufficient validation of untrusted input in Cast * CVE-2026-11242: Insufficient validation of untrusted input in Plugins * CVE-2026-11243: Incorrect security UI in Downloads * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-11245: Inappropriate implementation in Payments * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB * CVE-2026-11247: Insufficient policy enforcement in CustomTabs * CVE-2026-11248: Policy bypass in Google Lens * CVE-2026-11249: Use after free in Network * CVE-2026-11250: Inappropriate implementation in DevTools * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager * CVE-2026-11252: Policy bypass in Content Settings * CVE-2026-11253: Race in Permissions * CVE-2026-11254: Inappropriate implementation in Permissions * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API * CVE-2026-11256: Out of bounds read in GPU * CVE-2026-11257: Inappropriate implementation in Browser * CVE-2026-11258: Inappropriate implementation in File System Access * CVE-2026-11259: Insufficient validation of untrusted input in Cast * CVE-2026-11260: Policy bypass in Permissions * CVE-2026-11261: Insufficient validation of untrusted input in PDF * CVE-2026-11262: Use after free in TabStrip * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication * CVE-2026-11264: Policy bypass in Content Security Policy * CVE-2026-11265: Insufficient data validation in Autofill * CVE-2026-11266: Policy bypass in SafeBrowsing * CVE-2026-11267: Insufficient policy enforcement in Extensions * CVE-2026-11268: Uninitialized Use in ANGLE * CVE-2026-11269: Inappropriate implementation in Extensions * CVE-2026-11270: Inappropriate implementation in UI * CVE-2026-11271: Incorrect security UI in Passwords * CVE-2026-11272: Insufficient validation of untrusted input in Reading List * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox * CVE-2026-11274: Inappropriate implementation in DOM Distiller * CVE-2026-11275: Insufficient policy enforcement in Page Info * CVE-2026-11276: Inappropriate implementation in Cast * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11278: Inappropriate implementation in CustomTabs * CVE-2026-11279: Out of bounds read in DevTools * CVE-2026-11280: Insufficient validation of untrusted input in Signin * CVE-2026-11281: Integer overflow in Chromoting * CVE-2026-11282: Policy bypass in Sandbox * CVE-2026-11283: Policy bypass in Shortcuts * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11286: Insufficient validation of untrusted input in Wallet * CVE-2026-11287: Insufficient validation of untrusted input in Navigation * CVE-2026-11288: Policy bypass in CSS * CVE-2026-11289: Side-channel information leakage in Paint * CVE-2026-11290: Integer overflow in WebView * CVE-2026-11291: Policy bypass in Android Autofill * CVE-2026-11292: Policy bypass in Blink * CVE-2026-11293: Use after free in Input * CVE-2026-11294: Inappropriate implementation in Passwords * CVE-2026-11295: Inappropriate implementation in WebView * CVE-2026-11296: Inappropriate implementation in ImageCapture * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11299: Out of bounds read in Fonts * CVE-2026-11300: Inappropriate implementation in Permissions * CVE-2026-11301: Out of bounds read in LiveCaption * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11303: Use after free in PDFium * CVE-2026-11304: Use after free in PDFium * CVE-2026-11305: Use after free in PDFium * CVE-2026-11306: Use after free in PDFium * CVE-2026-11307: Use after free in PDFium * CVE-2026-11308: Inappropriate implementation in Extensions * CVE-2026-11309: Insufficient policy enforcement in History ++++ chromium: - Chromium 149 (149.0.7827.53) stable (boo#1267706): * CVE-2026-10881: Out of bounds read and write in ANGLE * CVE-2026-10882: Use after free in Network * CVE-2026-10883: Out of bounds write in ANGLE * CVE-2026-10884: Use after free in Chromecast * CVE-2026-10885: Use after free in Chrome for iOS * CVE-2026-10886: Use after free in FileSystem * CVE-2026-10887: Use after free in Chromoting * CVE-2026-10888: Use after free in Cast Streaming * CVE-2026-10889: Out of bounds read in ANGLE * CVE-2026-10890: Use after free in Cast * CVE-2026-10891: Use after free in GFX * CVE-2026-10892: Out of bounds write in GPU * CVE-2026-10893: Use after free in Chromoting * CVE-2026-10894: Use after free in Printing * CVE-2026-10895: Use after free in Ozone * CVE-2026-10896: Use after free in Chrome for iOS * CVE-2026-10897: Out of bounds write in GPU * CVE-2026-10898: Stack buffer overflow in GPU * CVE-2026-10899: Use after free in Ozone * CVE-2026-10900: Use after free in Passwords * CVE-2026-10901: Use after free in Passwords * CVE-2026-10902: Use after free in Ozone * CVE-2026-10903: Use after free in WebRTC * CVE-2026-10904: Inappropriate implementation in V8 * CVE-2026-10905: Use after free in Network * CVE-2026-10906: Use after free in WebAuthentication * CVE-2026-10907: Out of bounds write in ANGLE * CVE-2026-10908: Use after free in FullScreen * CVE-2026-10909: Use after free in Dawn * CVE-2026-10910: Type Confusion in V8 * CVE-2026-10911: Insufficient validation of untrusted input in Media * CVE-2026-10912: Insufficient validation of untrusted input in Extensions * CVE-2026-10913: Use after free in ANGLE * CVE-2026-10914: Use after free in ANGLE * CVE-2026-10915: Use after free in Core * CVE-2026-10916: Insufficient validation of untrusted input in DevTools * CVE-2026-10917: Insufficient validation of untrusted input in Media * CVE-2026-10918: Use after free in Viz * CVE-2026-10919: Use after free in ANGLE * CVE-2026-10920: Insufficient validation of untrusted input in WebShare * CVE-2026-10921: Integer overflow in Dawn * CVE-2026-10922: Insufficient validation of untrusted input in DevTools * CVE-2026-10923: Use after free in WebAppInstalls * CVE-2026-10924: Integer overflow in Chromecast * CVE-2026-10925: Out of bounds write in Skia * CVE-2026-10926: Use after free in Cast * CVE-2026-10927: Out of bounds read in Dawn * CVE-2026-10928: Script injection in Headless * CVE-2026-10929: Heap buffer overflow in ANGLE * CVE-2026-10930: Out of bounds read in ANGLE * CVE-2026-10931: Use after free in FileSystem * CVE-2026-10932: Use after free in UI * CVE-2026-10933: Use after free in Audio * CVE-2026-10934: Use after free in Autofill * CVE-2026-10935: Inappropriate implementation in V8 * CVE-2026-10936: Type Confusion in V8 * CVE-2026-10937: Inappropriate implementation in Passwords * CVE-2026-10938: Insufficient validation of untrusted input in Input * CVE-2026-10939: Use after free in WebRTC * CVE-2026-10940: Race in Codecs * CVE-2026-10941: Out of bounds memory access in Skia * CVE-2026-10942: Insufficient validation of untrusted input in UI * CVE-2026-10943: Use after free in WebRTC * CVE-2026-10944: Insufficient policy enforcement in Autofill * CVE-2026-10945: Use after free in PDF * CVE-2026-10946: Heap buffer overflow in Media * CVE-2026-10947: Use after free in WebRTC * CVE-2026-10948: Use after free in WebRTC * CVE-2026-10949: Heap buffer overflow in Video * CVE-2026-10950: Insufficient policy enforcement in Autofill * CVE-2026-10951: Use after free in Autofill * CVE-2026-10952: Use after free in Chrome for iOS * CVE-2026-10953: Use after free in Core * CVE-2026-10954: Use after free in Actor * CVE-2026-10955: Type Confusion in ANGLE * CVE-2026-10956: Use after free in MimeHandlerView * CVE-2026-10957: Use after free in Glic * CVE-2026-10958: Use after free in Chrome for iOS * CVE-2026-10959: Use after free in Input * CVE-2026-10960: Uninitialized Use in Codecs * CVE-2026-10961: Use after free in Chrome for iOS * CVE-2026-10962: Type Confusion in Media * CVE-2026-10963: Integer overflow in V8 * CVE-2026-10964: Integer overflow in V8 * CVE-2026-10965: Integer overflow in DevTools * CVE-2026-10966: Insufficient validation of untrusted input in Codecs * CVE-2026-10967: Use after free in SurfaceCapture * CVE-2026-10968: Insufficient validation of untrusted input in Dawn * CVE-2026-10969: Insufficient validation of untrusted input in Extensions * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups * CVE-2026-10971: Insufficient validation of untrusted input in Printing * CVE-2026-10972: Use after free in Ozone * CVE-2026-10973: Uninitialized Use in Dawn * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE * CVE-2026-10975: Use after free in WebRTC * CVE-2026-10976: Uninitialized Use in Dawn * CVE-2026-10977: Uninitialized Use in Skia * CVE-2026-10978: Use after free in Chromoting * CVE-2026-10979: Out of bounds read in ANGLE * CVE-2026-10980: Insufficient validation of untrusted input in DevTools * CVE-2026-10981: Insufficient validation of untrusted input in Codecs * CVE-2026-10982: Use after free in WebXR * CVE-2026-10983: Insufficient validation of untrusted input in Dawn * CVE-2026-10984: Inappropriate implementation in Accessibility * CVE-2026-10985: Out of bounds read in Skia * CVE-2026-10986: Integer overflow in Media * CVE-2026-10987: Integer overflow in V8 * CVE-2026-10988: Use after free in Views * CVE-2026-10989: Inappropriate implementation in V8 * CVE-2026-10990: Use after free in Glic * CVE-2026-10991: Use after free in V8 * CVE-2026-10992: Insufficient data validation in Animation * CVE-2026-10993: Heap buffer overflow in Skia * CVE-2026-10994: Uninitialized Use in ANGLE * CVE-2026-10995: Heap buffer overflow in TabStrip * CVE-2026-10996: Inappropriate implementation in Workers * CVE-2026-10997: Insufficient policy enforcement in Extensions * CVE-2026-10998: Out of bounds read in Media * CVE-2026-10999: Out of bounds memory access in ANGLE * CVE-2026-11000: Use after free in Fonts * CVE-2026-11001: Incorrect security UI in Payments * CVE-2026-11002: Use after free in Autofill * CVE-2026-11003: Use after free in WebRTC * CVE-2026-11004: Out of bounds read in ANGLE * CVE-2026-11005: Out of bounds read in ANGLE * CVE-2026-11006: Out of bounds read in Dawn * CVE-2026-11007: Insufficient validation of untrusted input in WebView * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11009: Use after free in USB * CVE-2026-11010: Use after free in WebShare * CVE-2026-11011: Insufficient policy enforcement in Password Manager * CVE-2026-11012: Use after free in Serial * CVE-2026-11013: Insufficient validation of untrusted input in Network * CVE-2026-11014: Insufficient policy enforcement in Extensions * CVE-2026-11015: Out of bounds read in WebGPU * CVE-2026-11016: Insufficient validation of untrusted input in Network * CVE-2026-11017: Inappropriate implementation in Link Preview * CVE-2026-11018: Insufficient policy enforcement in Actor * CVE-2026-11019: Inappropriate implementation in Payments * CVE-2026-11020: Inappropriate implementation in Extensions * CVE-2026-11021: Insufficient validation of untrusted input in GPU * CVE-2026-11022: Insufficient validation of untrusted input in DevTools * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11024: Stack buffer overflow in Skia * CVE-2026-11025: Insufficient policy enforcement in Navigation * CVE-2026-11026: Insufficient policy enforcement in Extensions * CVE-2026-11027: Insufficient validation of untrusted input in Glic * CVE-2026-11028: Use after free in Media * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop * CVE-2026-11030: Use after free in Network * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager * CVE-2026-11032: Insufficient data validation in Password Manager * CVE-2026-11033: Uninitialized Use in WebML * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs * CVE-2026-11036: Inappropriate implementation in DOM * CVE-2026-11037: Out of bounds write in Codecs * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity * CVE-2026-11039: Uninitialized Use in Skia * CVE-2026-11040: Use after free in ANGLE * CVE-2026-11041: Insufficient validation of untrusted input in Media * CVE-2026-11042: Use after free in Views * CVE-2026-11043: Out of bounds write in ANGLE * CVE-2026-11044: Integer overflow in ANGLE * CVE-2026-11045: Insufficient validation of untrusted input in GPU * CVE-2026-11046: Insufficient validation of untrusted input in Media * CVE-2026-11047: Insufficient validation of untrusted input in Base * CVE-2026-11048: Inappropriate implementation in Extensions * CVE-2026-11049: Use after free in Password Manager * CVE-2026-11050: Use after free in V8 * CVE-2026-11051: Out of bounds read in ANGLE * CVE-2026-11052: Type Confusion in GPU * CVE-2026-11053: VULNERABILITY in WebRTC * CVE-2026-11054: Use after free in WebRTC * CVE-2026-11055: Use after free in ANGLE * CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-11057: Uninitialized Use in Skia * CVE-2026-11058: Integer overflow in CredentialProvider * CVE-2026-11059: Use after free in Blink * CVE-2026-11060: Use after free in Media * CVE-2026-11061: Out of bounds read in ANGLE * CVE-2026-11062: Insufficient policy enforcement in Extensions * CVE-2026-11063: Insufficient validation of untrusted input in WebNN * CVE-2026-11064: Uninitialized Use in GPU * CVE-2026-11065: Use after free in ANGLE * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE * CVE-2026-11067: Uninitialized Use in Dawn * CVE-2026-11068: Use after free in WebSockets * CVE-2026-11069: Insufficient validation of untrusted input in Cast * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting * CVE-2026-11071: Use after free in Base * CVE-2026-11072: Use after free in WebView * CVE-2026-11073: Use after free in WebGL * CVE-2026-11074: Use after free in WebRTC * CVE-2026-11075: Out of bounds read in V8 * CVE-2026-11076: Type Confusion in CSS * CVE-2026-11077: Out of bounds read in Dawn * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem * CVE-2026-11079: Insufficient validation of untrusted input in Codecs * CVE-2026-11080: Use after free in WebView * CVE-2026-11081: Policy bypass in Canvas * CVE-2026-11082: Use after free in GPU * CVE-2026-11083: Inappropriate implementation in Password Manager * CVE-2026-11084: Inappropriate implementation in Password Manager * CVE-2026-11085: Integer overflow in GPU * CVE-2026-11086: Insufficient validation of untrusted input in Dawn * CVE-2026-11087: Uninitialized Use in ANGLE * CVE-2026-11088: Integer overflow in ANGLE * CVE-2026-11089: Uninitialized Use in Media * CVE-2026-11090: Uninitialized Use in ANGLE * CVE-2026-11091: Inappropriate implementation in Dawn * CVE-2026-11092: Insufficient policy enforcement in DevTools * CVE-2026-11093: Insufficient validation of untrusted input in Printing * CVE-2026-11094: Use after free in Codecs * CVE-2026-11095: Insufficient validation of untrusted input in Codecs * CVE-2026-11096: Out of bounds read in WebRTC * CVE-2026-11097: Inappropriate implementation in WebView * CVE-2026-11098: Insufficient validation of untrusted input in GPU * CVE-2026-11099: Vulnerability in Skia * CVE-2026-11100: Use after free in File Input * CVE-2026-11101: Uninitialized Use in Dawn * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps * CVE-2026-11103: Inappropriate implementation in Installer * CVE-2026-11104: Uninitialized Use in ANGLE * CVE-2026-11105: Insufficient validation of untrusted input in WebUI * CVE-2026-11106: Inappropriate implementation in Media * CVE-2026-11107: Inappropriate implementation in Downloads * CVE-2026-11108: Inappropriate implementation in NFC * CVE-2026-11109: Uninitialized Use in ANGLE * CVE-2026-11110: Uninitialized Use in ANGLE * CVE-2026-11111: Out of bounds read in ANGLE * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE * CVE-2026-11114: Use after free in Device Trust * CVE-2026-11115: Use after free in Updater * CVE-2026-11116: Use after free in Chromoting * CVE-2026-11117: Use after free in Views * CVE-2026-11118: Use after free in WebRTC * CVE-2026-11119: Insufficient validation of untrusted input in GPU * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting * CVE-2026-11121: Insufficient validation of untrusted input in Skia * CVE-2026-11122: Inappropriate implementation in Keyboard * CVE-2026-11123: Uninitialized Use in ANGLE * CVE-2026-11124: Heap buffer overflow in Skia * CVE-2026-11125: Use after free in Compositing * CVE-2026-11126: Insufficient validation of untrusted input in DevTools * CVE-2026-11127: Inappropriate implementation in WebAPKs * CVE-2026-11128: Insufficient validation of untrusted input in Web Share * CVE-2026-11129: Inappropriate implementation in Extensions * CVE-2026-11130: Use after free in Media * CVE-2026-11131: Use after free in Autofill * CVE-2026-11132: Policy bypass in Paint * CVE-2026-11133: Insufficient policy enforcement in Paint * CVE-2026-11134: Insufficient data validation in Media * CVE-2026-11135: Insufficient policy enforcement in Autofill * CVE-2026-11136: Use after free in Canvas * CVE-2026-11137: Uninitialized Use in ANGLE * CVE-2026-11138: Uninitialized Use in ANGLE * CVE-2026-11139: Policy bypass in Paint * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast * CVE-2026-11141: Uninitialized Use in Audio * CVE-2026-11142: Policy bypass in Paint * CVE-2026-11143: Heap buffer overflow in Extensions * CVE-2026-11144: Use after free in Media * CVE-2026-11145: Race in Geolocation * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting * CVE-2026-11147: Use after free in WebML * CVE-2026-11148: Inappropriate implementation in Payments * CVE-2026-11149: Insufficient validation of untrusted input in Extensions * CVE-2026-11150: Inappropriate implementation in XML * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager * CVE-2026-11152: Object lifecycle issue in Dawn * CVE-2026-11153: Side-channel information leakage in Forms * CVE-2026-11154: Use after free in Dawn * CVE-2026-11155: Insufficient policy enforcement in CSS * CVE-2026-11156: Inappropriate implementation in CSS * CVE-2026-11157: Script injection in Accessibility * CVE-2026-11158: Insufficient validation of untrusted input in Downloads * CVE-2026-11159: Uninitialized Use in Skia * CVE-2026-11160: Out of bounds read in Input * CVE-2026-11161: Insufficient data validation in DataTransfer * CVE-2026-11162: Insufficient policy enforcement in CSS * CVE-2026-11163: Use after free in Messages * CVE-2026-11164: Use after free in Blink * CVE-2026-11165: Use after free in WebMIDI * CVE-2026-11166: Inappropriate implementation in SVG * CVE-2026-11167: Inappropriate implementation in WebView * CVE-2026-11168: Insufficient policy enforcement in Extensions * CVE-2026-11169: Inappropriate implementation in XML * CVE-2026-11170: Inappropriate implementation in Chromoting * CVE-2026-11171: Integer overflow in Blink * CVE-2026-11172: Incorrect security UI in Contact Picker * CVE-2026-11173: Out of bounds write in V8 * CVE-2026-11174: Insufficient policy enforcement in Site Isolation * CVE-2026-11175: Incorrect security UI in Messages * CVE-2026-11176: Inappropriate implementation in Media * CVE-2026-11177: Use after free in Omnibox * CVE-2026-11178: Policy bypass in WebView * CVE-2026-11179: Inappropriate implementation in ORB * CVE-2026-11180: Policy bypass in SVG * CVE-2026-11181: Inappropriate implementation in Media Session * CVE-2026-11182: Inappropriate implementation in SVG * CVE-2026-11183: Out of bounds read in GWP-ASan * CVE-2026-11184: Insufficient policy enforcement in Actor * CVE-2026-11185: Use after free in V8 * CVE-2026-11186: Inappropriate implementation in CSS * CVE-2026-11187: Insufficient policy enforcement in Glic * CVE-2026-11188: Use after free in USB * CVE-2026-11189: Insufficient validation of untrusted input in DevTools * CVE-2026-11190: Insufficient policy enforcement in Extensions * CVE-2026-11191: Out of bounds memory access in ANGLE * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager * CVE-2026-11193: Insufficient policy enforcement in Password Manager * CVE-2026-11194: Inappropriate implementation in Network * CVE-2026-11195: Inappropriate implementation in MHTML * CVE-2026-11196: Type Confusion in XML * CVE-2026-11197: Insufficient policy enforcement in Workers * CVE-2026-11198: Insufficient validation of untrusted input in Codecs * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC * CVE-2026-11200: Inappropriate implementation in WebRTC * CVE-2026-11201: Use after free in ServiceWorker * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11203: Policy bypass in GPU * CVE-2026-11204: Inappropriate implementation in Signin * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11206: Policy bypass in ServiceWorker * CVE-2026-11207: Insufficient validation of untrusted input in Autofill * CVE-2026-11208: Use after free in Codecs * CVE-2026-11209: Insufficient policy enforcement in Passwords * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing * CVE-2026-11211: Integer overflow in V8 * CVE-2026-11212: Insufficient policy enforcement in DevTools * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode * CVE-2026-11214: Inappropriate implementation in Chrome for iOS * CVE-2026-11215: Inappropriate implementation in Cronet * CVE-2026-11216: Incorrect security UI in File Input * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames * CVE-2026-11218: Inappropriate implementation in PlatformIntegration * CVE-2026-11219: Insufficient data validation in Navigation * CVE-2026-11220: Insufficient validation of untrusted input in Navigation * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock * CVE-2026-11222: Incorrect security UI in Tab Strip * CVE-2026-11223: Insufficient validation of untrusted input in Network * CVE-2026-11224: Use after free in Chromoting * CVE-2026-11225: Incorrect security UI in WebUI * CVE-2026-11226: Insufficient policy enforcement in PreviewTab * CVE-2026-11227: Incorrect security UI in Tab Hover Cards * CVE-2026-11228: Incorrect security UI in File Input * CVE-2026-11229: Insufficient policy enforcement in Enterprise * CVE-2026-11230: Use after free in Extensions * CVE-2026-11231: Inappropriate implementation in Safe Browsing * CVE-2026-11232: Inappropriate implementation in TabGroups * CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs * CVE-2026-11235: Insufficient validation of untrusted input in Compositing * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth * CVE-2026-11237: Insufficient validation of untrusted input in Media * CVE-2026-11238: Inappropriate implementation in DevTools * CVE-2026-11239: Insufficient validation of untrusted input in Extensions * CVE-2026-11240: Insufficient validation of untrusted input in Loader * CVE-2026-11241: Insufficient validation of untrusted input in Cast * CVE-2026-11242: Insufficient validation of untrusted input in Plugins * CVE-2026-11243: Incorrect security UI in Downloads * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-11245: Inappropriate implementation in Payments * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB * CVE-2026-11247: Insufficient policy enforcement in CustomTabs * CVE-2026-11248: Policy bypass in Google Lens * CVE-2026-11249: Use after free in Network * CVE-2026-11250: Inappropriate implementation in DevTools * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager * CVE-2026-11252: Policy bypass in Content Settings * CVE-2026-11253: Race in Permissions * CVE-2026-11254: Inappropriate implementation in Permissions * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API * CVE-2026-11256: Out of bounds read in GPU * CVE-2026-11257: Inappropriate implementation in Browser * CVE-2026-11258: Inappropriate implementation in File System Access * CVE-2026-11259: Insufficient validation of untrusted input in Cast * CVE-2026-11260: Policy bypass in Permissions * CVE-2026-11261: Insufficient validation of untrusted input in PDF * CVE-2026-11262: Use after free in TabStrip * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication * CVE-2026-11264: Policy bypass in Content Security Policy * CVE-2026-11265: Insufficient data validation in Autofill * CVE-2026-11266: Policy bypass in SafeBrowsing * CVE-2026-11267: Insufficient policy enforcement in Extensions * CVE-2026-11268: Uninitialized Use in ANGLE * CVE-2026-11269: Inappropriate implementation in Extensions * CVE-2026-11270: Inappropriate implementation in UI * CVE-2026-11271: Incorrect security UI in Passwords * CVE-2026-11272: Insufficient validation of untrusted input in Reading List * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox * CVE-2026-11274: Inappropriate implementation in DOM Distiller * CVE-2026-11275: Insufficient policy enforcement in Page Info * CVE-2026-11276: Inappropriate implementation in Cast * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11278: Inappropriate implementation in CustomTabs * CVE-2026-11279: Out of bounds read in DevTools * CVE-2026-11280: Insufficient validation of untrusted input in Signin * CVE-2026-11281: Integer overflow in Chromoting * CVE-2026-11282: Policy bypass in Sandbox * CVE-2026-11283: Policy bypass in Shortcuts * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11286: Insufficient validation of untrusted input in Wallet * CVE-2026-11287: Insufficient validation of untrusted input in Navigation * CVE-2026-11288: Policy bypass in CSS * CVE-2026-11289: Side-channel information leakage in Paint * CVE-2026-11290: Integer overflow in WebView * CVE-2026-11291: Policy bypass in Android Autofill * CVE-2026-11292: Policy bypass in Blink * CVE-2026-11293: Use after free in Input * CVE-2026-11294: Inappropriate implementation in Passwords * CVE-2026-11295: Inappropriate implementation in WebView * CVE-2026-11296: Inappropriate implementation in ImageCapture * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11299: Out of bounds read in Fonts * CVE-2026-11300: Inappropriate implementation in Permissions * CVE-2026-11301: Out of bounds read in LiveCaption * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11303: Use after free in PDFium * CVE-2026-11304: Use after free in PDFium * CVE-2026-11305: Use after free in PDFium * CVE-2026-11306: Use after free in PDFium * CVE-2026-11307: Use after free in PDFium * CVE-2026-11308: Inappropriate implementation in Extensions * CVE-2026-11309: Insufficient policy enforcement in History ++++ chromium: - Chromium 149 (149.0.7827.53) stable (boo#1267706): * CVE-2026-10881: Out of bounds read and write in ANGLE * CVE-2026-10882: Use after free in Network * CVE-2026-10883: Out of bounds write in ANGLE * CVE-2026-10884: Use after free in Chromecast * CVE-2026-10885: Use after free in Chrome for iOS * CVE-2026-10886: Use after free in FileSystem * CVE-2026-10887: Use after free in Chromoting * CVE-2026-10888: Use after free in Cast Streaming * CVE-2026-10889: Out of bounds read in ANGLE * CVE-2026-10890: Use after free in Cast * CVE-2026-10891: Use after free in GFX * CVE-2026-10892: Out of bounds write in GPU * CVE-2026-10893: Use after free in Chromoting * CVE-2026-10894: Use after free in Printing * CVE-2026-10895: Use after free in Ozone * CVE-2026-10896: Use after free in Chrome for iOS * CVE-2026-10897: Out of bounds write in GPU * CVE-2026-10898: Stack buffer overflow in GPU * CVE-2026-10899: Use after free in Ozone * CVE-2026-10900: Use after free in Passwords * CVE-2026-10901: Use after free in Passwords * CVE-2026-10902: Use after free in Ozone * CVE-2026-10903: Use after free in WebRTC * CVE-2026-10904: Inappropriate implementation in V8 * CVE-2026-10905: Use after free in Network * CVE-2026-10906: Use after free in WebAuthentication * CVE-2026-10907: Out of bounds write in ANGLE * CVE-2026-10908: Use after free in FullScreen * CVE-2026-10909: Use after free in Dawn * CVE-2026-10910: Type Confusion in V8 * CVE-2026-10911: Insufficient validation of untrusted input in Media * CVE-2026-10912: Insufficient validation of untrusted input in Extensions * CVE-2026-10913: Use after free in ANGLE * CVE-2026-10914: Use after free in ANGLE * CVE-2026-10915: Use after free in Core * CVE-2026-10916: Insufficient validation of untrusted input in DevTools * CVE-2026-10917: Insufficient validation of untrusted input in Media * CVE-2026-10918: Use after free in Viz * CVE-2026-10919: Use after free in ANGLE * CVE-2026-10920: Insufficient validation of untrusted input in WebShare * CVE-2026-10921: Integer overflow in Dawn * CVE-2026-10922: Insufficient validation of untrusted input in DevTools * CVE-2026-10923: Use after free in WebAppInstalls * CVE-2026-10924: Integer overflow in Chromecast * CVE-2026-10925: Out of bounds write in Skia * CVE-2026-10926: Use after free in Cast * CVE-2026-10927: Out of bounds read in Dawn * CVE-2026-10928: Script injection in Headless * CVE-2026-10929: Heap buffer overflow in ANGLE * CVE-2026-10930: Out of bounds read in ANGLE * CVE-2026-10931: Use after free in FileSystem * CVE-2026-10932: Use after free in UI * CVE-2026-10933: Use after free in Audio * CVE-2026-10934: Use after free in Autofill * CVE-2026-10935: Inappropriate implementation in V8 * CVE-2026-10936: Type Confusion in V8 * CVE-2026-10937: Inappropriate implementation in Passwords * CVE-2026-10938: Insufficient validation of untrusted input in Input * CVE-2026-10939: Use after free in WebRTC * CVE-2026-10940: Race in Codecs * CVE-2026-10941: Out of bounds memory access in Skia * CVE-2026-10942: Insufficient validation of untrusted input in UI * CVE-2026-10943: Use after free in WebRTC * CVE-2026-10944: Insufficient policy enforcement in Autofill * CVE-2026-10945: Use after free in PDF * CVE-2026-10946: Heap buffer overflow in Media * CVE-2026-10947: Use after free in WebRTC * CVE-2026-10948: Use after free in WebRTC * CVE-2026-10949: Heap buffer overflow in Video * CVE-2026-10950: Insufficient policy enforcement in Autofill * CVE-2026-10951: Use after free in Autofill * CVE-2026-10952: Use after free in Chrome for iOS * CVE-2026-10953: Use after free in Core * CVE-2026-10954: Use after free in Actor * CVE-2026-10955: Type Confusion in ANGLE * CVE-2026-10956: Use after free in MimeHandlerView * CVE-2026-10957: Use after free in Glic * CVE-2026-10958: Use after free in Chrome for iOS * CVE-2026-10959: Use after free in Input * CVE-2026-10960: Uninitialized Use in Codecs * CVE-2026-10961: Use after free in Chrome for iOS * CVE-2026-10962: Type Confusion in Media * CVE-2026-10963: Integer overflow in V8 * CVE-2026-10964: Integer overflow in V8 * CVE-2026-10965: Integer overflow in DevTools * CVE-2026-10966: Insufficient validation of untrusted input in Codecs * CVE-2026-10967: Use after free in SurfaceCapture * CVE-2026-10968: Insufficient validation of untrusted input in Dawn * CVE-2026-10969: Insufficient validation of untrusted input in Extensions * CVE-2026-10970: Insufficient validation of untrusted input in InterestGroups * CVE-2026-10971: Insufficient validation of untrusted input in Printing * CVE-2026-10972: Use after free in Ozone * CVE-2026-10973: Uninitialized Use in Dawn * CVE-2026-10974: Insufficient validation of untrusted input in ANGLE * CVE-2026-10975: Use after free in WebRTC * CVE-2026-10976: Uninitialized Use in Dawn * CVE-2026-10977: Uninitialized Use in Skia * CVE-2026-10978: Use after free in Chromoting * CVE-2026-10979: Out of bounds read in ANGLE * CVE-2026-10980: Insufficient validation of untrusted input in DevTools * CVE-2026-10981: Insufficient validation of untrusted input in Codecs * CVE-2026-10982: Use after free in WebXR * CVE-2026-10983: Insufficient validation of untrusted input in Dawn * CVE-2026-10984: Inappropriate implementation in Accessibility * CVE-2026-10985: Out of bounds read in Skia * CVE-2026-10986: Integer overflow in Media * CVE-2026-10987: Integer overflow in V8 * CVE-2026-10988: Use after free in Views * CVE-2026-10989: Inappropriate implementation in V8 * CVE-2026-10990: Use after free in Glic * CVE-2026-10991: Use after free in V8 * CVE-2026-10992: Insufficient data validation in Animation * CVE-2026-10993: Heap buffer overflow in Skia * CVE-2026-10994: Uninitialized Use in ANGLE * CVE-2026-10995: Heap buffer overflow in TabStrip * CVE-2026-10996: Inappropriate implementation in Workers * CVE-2026-10997: Insufficient policy enforcement in Extensions * CVE-2026-10998: Out of bounds read in Media * CVE-2026-10999: Out of bounds memory access in ANGLE * CVE-2026-11000: Use after free in Fonts * CVE-2026-11001: Incorrect security UI in Payments * CVE-2026-11002: Use after free in Autofill * CVE-2026-11003: Use after free in WebRTC * CVE-2026-11004: Out of bounds read in ANGLE * CVE-2026-11005: Out of bounds read in ANGLE * CVE-2026-11006: Out of bounds read in Dawn * CVE-2026-11007: Insufficient validation of untrusted input in WebView * CVE-2026-11008: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11009: Use after free in USB * CVE-2026-11010: Use after free in WebShare * CVE-2026-11011: Insufficient policy enforcement in Password Manager * CVE-2026-11012: Use after free in Serial * CVE-2026-11013: Insufficient validation of untrusted input in Network * CVE-2026-11014: Insufficient policy enforcement in Extensions * CVE-2026-11015: Out of bounds read in WebGPU * CVE-2026-11016: Insufficient validation of untrusted input in Network * CVE-2026-11017: Inappropriate implementation in Link Preview * CVE-2026-11018: Insufficient policy enforcement in Actor * CVE-2026-11019: Inappropriate implementation in Payments * CVE-2026-11020: Inappropriate implementation in Extensions * CVE-2026-11021: Insufficient validation of untrusted input in GPU * CVE-2026-11022: Insufficient validation of untrusted input in DevTools * CVE-2026-11023: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-11024: Stack buffer overflow in Skia * CVE-2026-11025: Insufficient policy enforcement in Navigation * CVE-2026-11026: Insufficient policy enforcement in Extensions * CVE-2026-11027: Insufficient validation of untrusted input in Glic * CVE-2026-11028: Use after free in Media * CVE-2026-11029: Insufficient validation of untrusted input in Drag and Drop * CVE-2026-11030: Use after free in Network * CVE-2026-11031: Insufficient validation of untrusted input in Password Manager * CVE-2026-11032: Insufficient data validation in Password Manager * CVE-2026-11033: Uninitialized Use in WebML * CVE-2026-11034: Insufficient validation of untrusted input in Tab Group Sync * CVE-2026-11035: Insufficient validation of untrusted input in Custom Tabs * CVE-2026-11036: Inappropriate implementation in DOM * CVE-2026-11037: Out of bounds write in Codecs * CVE-2026-11038: Insufficient validation of untrusted input in Subresource Integrity * CVE-2026-11039: Uninitialized Use in Skia * CVE-2026-11040: Use after free in ANGLE * CVE-2026-11041: Insufficient validation of untrusted input in Media * CVE-2026-11042: Use after free in Views * CVE-2026-11043: Out of bounds write in ANGLE * CVE-2026-11044: Integer overflow in ANGLE * CVE-2026-11045: Insufficient validation of untrusted input in GPU * CVE-2026-11046: Insufficient validation of untrusted input in Media * CVE-2026-11047: Insufficient validation of untrusted input in Base * CVE-2026-11048: Inappropriate implementation in Extensions * CVE-2026-11049: Use after free in Password Manager * CVE-2026-11050: Use after free in V8 * CVE-2026-11051: Out of bounds read in ANGLE * CVE-2026-11052: Type Confusion in GPU * CVE-2026-11053: VULNERABILITY in WebRTC * CVE-2026-11054: Use after free in WebRTC * CVE-2026-11055: Use after free in ANGLE * CVE-2026-11056: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-11057: Uninitialized Use in Skia * CVE-2026-11058: Integer overflow in CredentialProvider * CVE-2026-11059: Use after free in Blink * CVE-2026-11060: Use after free in Media * CVE-2026-11061: Out of bounds read in ANGLE * CVE-2026-11062: Insufficient policy enforcement in Extensions * CVE-2026-11063: Insufficient validation of untrusted input in WebNN * CVE-2026-11064: Uninitialized Use in GPU * CVE-2026-11065: Use after free in ANGLE * CVE-2026-11066: Insufficient validation of untrusted input in ANGLE * CVE-2026-11067: Uninitialized Use in Dawn * CVE-2026-11068: Use after free in WebSockets * CVE-2026-11069: Insufficient validation of untrusted input in Cast * CVE-2026-11070: Insufficient validation of untrusted input in Chromoting * CVE-2026-11071: Use after free in Base * CVE-2026-11072: Use after free in WebView * CVE-2026-11073: Use after free in WebGL * CVE-2026-11074: Use after free in WebRTC * CVE-2026-11075: Out of bounds read in V8 * CVE-2026-11076: Type Confusion in CSS * CVE-2026-11077: Out of bounds read in Dawn * CVE-2026-11078: Insufficient validation of untrusted input in FileSystem * CVE-2026-11079: Insufficient validation of untrusted input in Codecs * CVE-2026-11080: Use after free in WebView * CVE-2026-11081: Policy bypass in Canvas * CVE-2026-11082: Use after free in GPU * CVE-2026-11083: Inappropriate implementation in Password Manager * CVE-2026-11084: Inappropriate implementation in Password Manager * CVE-2026-11085: Integer overflow in GPU * CVE-2026-11086: Insufficient validation of untrusted input in Dawn * CVE-2026-11087: Uninitialized Use in ANGLE * CVE-2026-11088: Integer overflow in ANGLE * CVE-2026-11089: Uninitialized Use in Media * CVE-2026-11090: Uninitialized Use in ANGLE * CVE-2026-11091: Inappropriate implementation in Dawn * CVE-2026-11092: Insufficient policy enforcement in DevTools * CVE-2026-11093: Insufficient validation of untrusted input in Printing * CVE-2026-11094: Use after free in Codecs * CVE-2026-11095: Insufficient validation of untrusted input in Codecs * CVE-2026-11096: Out of bounds read in WebRTC * CVE-2026-11097: Inappropriate implementation in WebView * CVE-2026-11098: Insufficient validation of untrusted input in GPU * CVE-2026-11099: Vulnerability in Skia * CVE-2026-11100: Use after free in File Input * CVE-2026-11101: Uninitialized Use in Dawn * CVE-2026-11102: Inappropriate implementation in Isolated Web Apps * CVE-2026-11103: Inappropriate implementation in Installer * CVE-2026-11104: Uninitialized Use in ANGLE * CVE-2026-11105: Insufficient validation of untrusted input in WebUI * CVE-2026-11106: Inappropriate implementation in Media * CVE-2026-11107: Inappropriate implementation in Downloads * CVE-2026-11108: Inappropriate implementation in NFC * CVE-2026-11109: Uninitialized Use in ANGLE * CVE-2026-11110: Uninitialized Use in ANGLE * CVE-2026-11111: Out of bounds read in ANGLE * CVE-2026-11112: Insufficient validation of untrusted input in Chromoting * CVE-2026-11113: Insufficient validation of untrusted input in ANGLE * CVE-2026-11114: Use after free in Device Trust * CVE-2026-11115: Use after free in Updater * CVE-2026-11116: Use after free in Chromoting * CVE-2026-11117: Use after free in Views * CVE-2026-11118: Use after free in WebRTC * CVE-2026-11119: Insufficient validation of untrusted input in GPU * CVE-2026-11120: Insufficient validation of untrusted input in Enterprise Reporting * CVE-2026-11121: Insufficient validation of untrusted input in Skia * CVE-2026-11122: Inappropriate implementation in Keyboard * CVE-2026-11123: Uninitialized Use in ANGLE * CVE-2026-11124: Heap buffer overflow in Skia * CVE-2026-11125: Use after free in Compositing * CVE-2026-11126: Insufficient validation of untrusted input in DevTools * CVE-2026-11127: Inappropriate implementation in WebAPKs * CVE-2026-11128: Insufficient validation of untrusted input in Web Share * CVE-2026-11129: Inappropriate implementation in Extensions * CVE-2026-11130: Use after free in Media * CVE-2026-11131: Use after free in Autofill * CVE-2026-11132: Policy bypass in Paint * CVE-2026-11133: Insufficient policy enforcement in Paint * CVE-2026-11134: Insufficient data validation in Media * CVE-2026-11135: Insufficient policy enforcement in Autofill * CVE-2026-11136: Use after free in Canvas * CVE-2026-11137: Uninitialized Use in ANGLE * CVE-2026-11138: Uninitialized Use in ANGLE * CVE-2026-11139: Policy bypass in Paint * CVE-2026-11140: Insufficient validation of untrusted input in Chromecast * CVE-2026-11141: Uninitialized Use in Audio * CVE-2026-11142: Policy bypass in Paint * CVE-2026-11143: Heap buffer overflow in Extensions * CVE-2026-11144: Use after free in Media * CVE-2026-11145: Race in Geolocation * CVE-2026-11146: Insufficient validation of untrusted input in Chromoting * CVE-2026-11147: Use after free in WebML * CVE-2026-11148: Inappropriate implementation in Payments * CVE-2026-11149: Insufficient validation of untrusted input in Extensions * CVE-2026-11150: Inappropriate implementation in XML * CVE-2026-11151: Insufficient validation of untrusted input in Password Manager * CVE-2026-11152: Object lifecycle issue in Dawn * CVE-2026-11153: Side-channel information leakage in Forms * CVE-2026-11154: Use after free in Dawn * CVE-2026-11155: Insufficient policy enforcement in CSS * CVE-2026-11156: Inappropriate implementation in CSS * CVE-2026-11157: Script injection in Accessibility * CVE-2026-11158: Insufficient validation of untrusted input in Downloads * CVE-2026-11159: Uninitialized Use in Skia * CVE-2026-11160: Out of bounds read in Input * CVE-2026-11161: Insufficient data validation in DataTransfer * CVE-2026-11162: Insufficient policy enforcement in CSS * CVE-2026-11163: Use after free in Messages * CVE-2026-11164: Use after free in Blink * CVE-2026-11165: Use after free in WebMIDI * CVE-2026-11166: Inappropriate implementation in SVG * CVE-2026-11167: Inappropriate implementation in WebView * CVE-2026-11168: Insufficient policy enforcement in Extensions * CVE-2026-11169: Inappropriate implementation in XML * CVE-2026-11170: Inappropriate implementation in Chromoting * CVE-2026-11171: Integer overflow in Blink * CVE-2026-11172: Incorrect security UI in Contact Picker * CVE-2026-11173: Out of bounds write in V8 * CVE-2026-11174: Insufficient policy enforcement in Site Isolation * CVE-2026-11175: Incorrect security UI in Messages * CVE-2026-11176: Inappropriate implementation in Media * CVE-2026-11177: Use after free in Omnibox * CVE-2026-11178: Policy bypass in WebView * CVE-2026-11179: Inappropriate implementation in ORB * CVE-2026-11180: Policy bypass in SVG * CVE-2026-11181: Inappropriate implementation in Media Session * CVE-2026-11182: Inappropriate implementation in SVG * CVE-2026-11183: Out of bounds read in GWP-ASan * CVE-2026-11184: Insufficient policy enforcement in Actor * CVE-2026-11185: Use after free in V8 * CVE-2026-11186: Inappropriate implementation in CSS * CVE-2026-11187: Insufficient policy enforcement in Glic * CVE-2026-11188: Use after free in USB * CVE-2026-11189: Insufficient validation of untrusted input in DevTools * CVE-2026-11190: Insufficient policy enforcement in Extensions * CVE-2026-11191: Out of bounds memory access in ANGLE * CVE-2026-11192: Insufficient validation of untrusted input in Password Manager * CVE-2026-11193: Insufficient policy enforcement in Password Manager * CVE-2026-11194: Inappropriate implementation in Network * CVE-2026-11195: Inappropriate implementation in MHTML * CVE-2026-11196: Type Confusion in XML * CVE-2026-11197: Insufficient policy enforcement in Workers * CVE-2026-11198: Insufficient validation of untrusted input in Codecs * CVE-2026-11199: Insufficient validation of untrusted input in WebRTC * CVE-2026-11200: Inappropriate implementation in WebRTC * CVE-2026-11201: Use after free in ServiceWorker * CVE-2026-11202: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11203: Policy bypass in GPU * CVE-2026-11204: Inappropriate implementation in Signin * CVE-2026-11205: Insufficient validation of untrusted input in Chrome for iOS * CVE-2026-11206: Policy bypass in ServiceWorker * CVE-2026-11207: Insufficient validation of untrusted input in Autofill * CVE-2026-11208: Use after free in Codecs * CVE-2026-11209: Insufficient policy enforcement in Passwords * CVE-2026-11210: Insufficient policy enforcement in Safe Browsing * CVE-2026-11211: Integer overflow in V8 * CVE-2026-11212: Insufficient policy enforcement in DevTools * CVE-2026-11213: Insufficient validation of untrusted input in Reading Mode * CVE-2026-11214: Inappropriate implementation in Chrome for iOS * CVE-2026-11215: Inappropriate implementation in Cronet * CVE-2026-11216: Incorrect security UI in File Input * CVE-2026-11217: Insufficient policy enforcement in Fenced Frames * CVE-2026-11218: Inappropriate implementation in PlatformIntegration * CVE-2026-11219: Insufficient data validation in Navigation * CVE-2026-11220: Insufficient validation of untrusted input in Navigation * CVE-2026-11221: Insufficient validation of untrusted input in PointerLock * CVE-2026-11222: Incorrect security UI in Tab Strip * CVE-2026-11223: Insufficient validation of untrusted input in Network * CVE-2026-11224: Use after free in Chromoting * CVE-2026-11225: Incorrect security UI in WebUI * CVE-2026-11226: Insufficient policy enforcement in PreviewTab * CVE-2026-11227: Incorrect security UI in Tab Hover Cards * CVE-2026-11228: Incorrect security UI in File Input * CVE-2026-11229: Insufficient policy enforcement in Enterprise * CVE-2026-11230: Use after free in Extensions * CVE-2026-11231: Inappropriate implementation in Safe Browsing * CVE-2026-11232: Inappropriate implementation in TabGroups * CVE-2026-11233: Insufficient validation of untrusted input in FoldableAPIs * CVE-2026-11234: Insufficient policy enforcement in FoldableAPIs * CVE-2026-11235: Insufficient validation of untrusted input in Compositing * CVE-2026-11236: Insufficient policy enforcement in Web Bluetooth * CVE-2026-11237: Insufficient validation of untrusted input in Media * CVE-2026-11238: Inappropriate implementation in DevTools * CVE-2026-11239: Insufficient validation of untrusted input in Extensions * CVE-2026-11240: Insufficient validation of untrusted input in Loader * CVE-2026-11241: Insufficient validation of untrusted input in Cast * CVE-2026-11242: Insufficient validation of untrusted input in Plugins * CVE-2026-11243: Incorrect security UI in Downloads * CVE-2026-11244: Insufficient validation of untrusted input in WebAuthentication * CVE-2026-11245: Inappropriate implementation in Payments * CVE-2026-11246: Insufficient validation of untrusted input in IndexedDB * CVE-2026-11247: Insufficient policy enforcement in CustomTabs * CVE-2026-11248: Policy bypass in Google Lens * CVE-2026-11249: Use after free in Network * CVE-2026-11250: Inappropriate implementation in DevTools * CVE-2026-11251: Insufficient validation of untrusted input in Password Manager * CVE-2026-11252: Policy bypass in Content Settings * CVE-2026-11253: Race in Permissions * CVE-2026-11254: Inappropriate implementation in Permissions * CVE-2026-11255: Insufficient validation of untrusted input in Storage Access API * CVE-2026-11256: Out of bounds read in GPU * CVE-2026-11257: Inappropriate implementation in Browser * CVE-2026-11258: Inappropriate implementation in File System Access * CVE-2026-11259: Insufficient validation of untrusted input in Cast * CVE-2026-11260: Policy bypass in Permissions * CVE-2026-11261: Insufficient validation of untrusted input in PDF * CVE-2026-11262: Use after free in TabStrip * CVE-2026-11263: Insufficient policy enforcement in WebAuthentication * CVE-2026-11264: Policy bypass in Content Security Policy * CVE-2026-11265: Insufficient data validation in Autofill * CVE-2026-11266: Policy bypass in SafeBrowsing * CVE-2026-11267: Insufficient policy enforcement in Extensions * CVE-2026-11268: Uninitialized Use in ANGLE * CVE-2026-11269: Inappropriate implementation in Extensions * CVE-2026-11270: Inappropriate implementation in UI * CVE-2026-11271: Incorrect security UI in Passwords * CVE-2026-11272: Insufficient validation of untrusted input in Reading List * CVE-2026-11273: Insufficient validation of untrusted input in Omnibox * CVE-2026-11274: Inappropriate implementation in DOM Distiller * CVE-2026-11275: Insufficient policy enforcement in Page Info * CVE-2026-11276: Inappropriate implementation in Cast * CVE-2026-11277: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11278: Inappropriate implementation in CustomTabs * CVE-2026-11279: Out of bounds read in DevTools * CVE-2026-11280: Insufficient validation of untrusted input in Signin * CVE-2026-11281: Integer overflow in Chromoting * CVE-2026-11282: Policy bypass in Sandbox * CVE-2026-11283: Policy bypass in Shortcuts * CVE-2026-11284: Side-channel information leakage in PerformanceAPIs * CVE-2026-11285: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11286: Insufficient validation of untrusted input in Wallet * CVE-2026-11287: Insufficient validation of untrusted input in Navigation * CVE-2026-11288: Policy bypass in CSS * CVE-2026-11289: Side-channel information leakage in Paint * CVE-2026-11290: Integer overflow in WebView * CVE-2026-11291: Policy bypass in Android Autofill * CVE-2026-11292: Policy bypass in Blink * CVE-2026-11293: Use after free in Input * CVE-2026-11294: Inappropriate implementation in Passwords * CVE-2026-11295: Inappropriate implementation in WebView * CVE-2026-11296: Inappropriate implementation in ImageCapture * CVE-2026-11297: Insufficient validation of untrusted input in Reader Mode * CVE-2026-11298: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11299: Out of bounds read in Fonts * CVE-2026-11300: Inappropriate implementation in Permissions * CVE-2026-11301: Out of bounds read in LiveCaption * CVE-2026-11302: Insufficient policy enforcement in Chrome for iOS * CVE-2026-11303: Use after free in PDFium * CVE-2026-11304: Use after free in PDFium * CVE-2026-11305: Use after free in PDFium * CVE-2026-11306: Use after free in PDFium * CVE-2026-11307: Use after free in PDFium * CVE-2026-11308: Inappropriate implementation in Extensions * CVE-2026-11309: Insufficient policy enforcement in History ++++ kernel-64kb: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-64kb: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-azure: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-azure: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-default: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-default: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-rt: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-rt: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ dtb-aarch64: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ dtb-aarch64: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ google-guest-agent: - Update to version 20260529.00 * Dependency updates (#616) (bsc#1266603, CVE-2026-39821) (bsc#1266171, CVE-2026-39827, CVE-2026-39834, CVE-2026-39828, CVE-2026-39829, CVE-2026-39831, CVE-2026-42508, CVE-2026-39833, CVE-2026-39830, CVE-2026-39832, CVE-2026-46597, CVE-2026-46598, CVE-2026-46595, CVE-2026-39835) - from version 20260522.00 * Fix improper umask calculation on socket creation (#614) - from version 20260520.01 * Update OWNERS (#609) ++++ hyperfine: - 1.20.0 requires rust 1.88 - build on all architectures ++++ kernel-source: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-source: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-docs: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-docs: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-kvmsmall: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-kvmsmall: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-obs-build: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-obs-build: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-obs-qa: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-obs-qa: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-syms: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-syms: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-zfcpdump: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ kernel-zfcpdump: - dm: fix a buffer overflow in ioctl processing (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - scsi: devinfo: Add BLIST_SKIP_IO_HINTS for Iomega ZIP (git-fixes). - scsi: mpi3mr: Clear reset history on ready and recheck state after timeout (git-fixes). - scsi: ufs: core: Fix shift out of bounds when MAXQ=32 (git-fixes). - commit e61e502 - net: mvpp2: guard flow control update with global_tx_fc in buffer switching (CVE-2026-23438 bsc#1261619) - commit 276a96c - net: bonding: fix NULL deref in bond_debug_rlb_hash_show (CVE-2026-31546 bsc#1263006) - commit 4cb3ae6 - net: macb: fix use-after-free access to PTP clock (CVE-2026-31396 bsc#1261791) - commit b6d2420 - RDMA/rxe: Fix race condition in QP timer handlers (CVE-2026-45910 bsc#1266889) - commit dee2812 - RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898 bsc#1266888) - commit df19d9d - RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711) - commit 4885dd0 - cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (CVE-2026-23327 bsc#1260548) - commit 1acac91 - net: gro: fix outer network offset (CVE-2026-23254 bsc#1259884) - commit 239e6d1 - smb: client: Don't log plaintext credentials in cifs_set_cifscreds (CVE-2026-23303 bsc#1260502) - commit a1c8e29 - team: avoid NETDEV_CHANGEMTU event when unregistering slave (CVE-2026-43234 bsc#1264409). - commit 0f4d02d - tipc: fix divide-by-zero in tipc_sk_filter_connect() (CVE-2026-43411 bsc#1264672) - commit 9b26d10 - HID: bpf: prevent buffer overflow in hid_hw_request (CVE-2026-31401 bsc#1261603) - commit ab69573 - RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901) - commit dab2394 - esp: fix skb leak with espintcp and async crypto (CVE-2026-31518 bsc#1262606) - commit 3a456fe - net: stmmac: Prevent NULL deref when RX memory exhausted (CVE-2026-46110 bsc#1266759). - net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (CVE-2026-46110 bsc#1266759). - net/mlx5: Fix switchdev mode rollback in case of failure (CVE-2026-43012 bsc#1264016). - net/mlx5: lag: Check for LAG device before creating debugfs (CVE-2026-43013 bsc#1264011). - net: ethernet: mtk_ppe: avoid NULL deref when gmac0 is disabled (CVE-2026-31736 bsc#1263908). - commit 5178a8b - kabi: arm: io: Export ioremap_prot() symbol v2 (CVE-2026-23346 bsc#1260529 bsc#1266993) First version of this kABI fix missed that ioremap_prot() now accept only user-space mappings which breaks any out of tree KMP's which used the function for legitimate kernel IO mappings. Lets fix this by allowing kernel mappings and at same time properly handle user-space mappings [1] 9625623795d3 ("kabi: arm: io: Export ioremap_prot() symbol (CVE-2026-23346 bsc#1260529)") - commit fb001f3 - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - commit d66e959 - btrfs: do not mark inode incompressible after inline attempt fails (git-fixes). - commit b9ec6e8 ++++ mariadb: - Update to 11.8.8: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8 https://mariadb.com/docs/release-notes/community-server/changelogs/11.8/11.8.8 * fixes for the following security vulnerabilities: 11.8.8: CVE-2026-49261 CVE-2026-48165 (bsc#1266814) CVE-2026-48163 (bsc#1266815) ++++ openbabel: - Update to version 3.2.0: * Add an L-BFGS optimizer, used by default for gen3d and conformer searches * New macrocycle ring builder (Dale codes) for better initial 3D geometry of large rings * Add KET (Ketcher JSON) and ChemicalJSON (.cjson) format support * Drop Python 2 support; Python 3.13 supported * Faster, vectorized distance-geometry implementation * Full CMake 4 compatibility and modernized build * Backwards compatible with 3.0 and 3.1 * Fix many crash and memory-safety bugs found via OSS-Fuzz and TALOS, including the following security issues: CVE-2022-37331 (boo#1217676), CVE-2022-41793, CVE-2022-42885, CVE-2022-43467, CVE-2022-43607, CVE-2022-44451, CVE-2022-46280, CVE-2022-46289, CVE-2022-46290, CVE-2022-46291, CVE-2022-46292, CVE-2022-46294, CVE-2022-46295, CVE-2025-10994, CVE-2025-10995, CVE-2025-10996, CVE-2025-10997, CVE-2025-10998, CVE-2025-10999, CVE-2025-11000, CVE-2026-2704 (boo#1258501), CVE-2026-2705 (boo#1258507) and CVE-2026-3408 (boo#1259041) - Shared library soname bumped to libopenbabel8 (SOVERSION 8) - Drop patches now fixed upstream: * openbabel-3.1.1-test-python3-escape-chars.patch * openbabel-3.1.1-test-python3-imports.patch * openbabel-3.1.1-version-number.patch * openbabel-3.1.1-gcc-12.patch * openbabel-3.1.1-std-binary-function.patch * openbabel-3.1.1-std-bind1st.patch * openbabel-3.1.1-std-bind2nd.patch * openbabel-cmake-4.patch * openbabel-cmake-4-exports.patch ++++ ofono: - Spec cleanup: * Add the explicit gcc and make BuildRequires * Point URL at the upstream kernel.org git (01.org is defunct) ++++ openQA: - Update to version 5.1780322162.c1836389: * refactor: Use more readable regex in `process-docs` * refactor: Turn `process-docs` into proper style-checked Perl script * feat: Add Makefile target to tidy Shell code * docs: Fix links in documentation generated via `generate-docs` * fix(openqa-clone-job): Allow empty API key/secret for auth.method=None * fix(spec): Supplement bash-completion subpackage against bash-completion * docs: Fix broken list under "Further systemd …" and wrap consistently * docs: Fix example config for `git_auto_commit` * docs: Wrap lines consistently under "Terms and variables …" * docs: Fix wrapping in "Triggering tests …" section and below * docs: Remove Git conflict markers that were missed by b51c609679 * feat: watch worker auto-restart systemd drop-ins for reloads ++++ openQA: - Update to version 5.1780322162.c1836389: * refactor: Use more readable regex in `process-docs` * refactor: Turn `process-docs` into proper style-checked Perl script * feat: Add Makefile target to tidy Shell code * docs: Fix links in documentation generated via `generate-docs` * fix(openqa-clone-job): Allow empty API key/secret for auth.method=None * fix(spec): Supplement bash-completion subpackage against bash-completion * docs: Fix broken list under "Further systemd …" and wrap consistently * docs: Fix example config for `git_auto_commit` * docs: Wrap lines consistently under "Terms and variables …" * docs: Fix wrapping in "Triggering tests …" section and below * docs: Remove Git conflict markers that were missed by b51c609679 * feat: watch worker auto-restart systemd drop-ins for reloads ++++ openQA: - Update to version 5.1780322162.c1836389: * refactor: Use more readable regex in `process-docs` * refactor: Turn `process-docs` into proper style-checked Perl script * feat: Add Makefile target to tidy Shell code * docs: Fix links in documentation generated via `generate-docs` * fix(openqa-clone-job): Allow empty API key/secret for auth.method=None * fix(spec): Supplement bash-completion subpackage against bash-completion * docs: Fix broken list under "Further systemd …" and wrap consistently * docs: Fix example config for `git_auto_commit` * docs: Wrap lines consistently under "Terms and variables …" * docs: Fix wrapping in "Triggering tests …" section and below * docs: Remove Git conflict markers that were missed by b51c609679 * feat: watch worker auto-restart systemd drop-ins for reloads ++++ openssh: - Add patch rebased from upstream to add missing askpass check for proxy-mode multiplexing sessions (CVE-2026-35388, bsc#1261441): * openssh-cve-2026-35388-askpass-multiplexing.patch - Update patch to fix a possible information disclosure or denial of service due to uninitialized variables in gssapi patches (CVE-2026-3497, bsc#1259642) : * openssh-8.0p1-gssapi-keyex.patch ++++ os-autoinst: - Update to version 5.1780332012.6ee8da2: * chore(AGENTS.md): phrase tidying as mandatory * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests * chore: video_stream: accept ustreamer version 8 ++++ os-autoinst: - Update to version 5.1780332012.6ee8da2: * chore(AGENTS.md): phrase tidying as mandatory * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests * chore: video_stream: accept ustreamer version 8 ++++ os-autoinst: - Update to version 5.1780332012.6ee8da2: * chore(AGENTS.md): phrase tidying as mandatory * feat(mouse_drag): use the clickpoints * test: allow to configure full-stack test output directory * test: allow shortening long typing in full-stack tests * chore: video_stream: accept ustreamer version 8 ++++ python-pip: - CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite(bsc#1266669) Add patch CVE-2026-8643.patch ++++ trivy: - Update to version 0.71.0 (bsc#1267268, CVE-2026-44740): * release: v0.71.0 [main] (#10638) * ci: use only the first line of commit message in release-please workflow (#10766) * feat: add WithDriver and WithProvider options to ospkg detector (#10740) * chore(deps): bump github.com/google/go-containerregistry to v0.21.6 (#10741) * refactor(secret): normalize configPath once in Init (#10702) * feat(secret): add Maven rules to detect passwords and passphrases in settings.xml and settings-security.xml files (#10704) * chore(deps): bump the common group across 1 directory with 25 updates (#10758) * chore: migrate from gomodguard to gomodguard_v2 (#10739) * chore(deps): bump the docker group across 1 directory with 2 updates (#10709) * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.302.0 to 1.303.0 in the aws group (#10752) * ci: scope GitHub App tokens to minimum required permissions (#10755) * chore(deps): upgrade go-redis from v8 to v9 (#10736) * fix(misconf): fix rendering of nested values in terraform plan lists (#10746) * fix(misconf): skip resources with no after changes (#10352) * fix(misconf): reject nil plays during playbook parsing (#10273) * fix(nodejs): silently skip subdirectory package.json files with invalid names (#10609) * fix(misconf): skip null cty values in AsMapValue to prevent panic (#10723) * refactor(misconf): replace custom Helm archive parsing with Helm SDK loaders (#10718) * chore(deps): bump github.com/containerd/containerd/v2 to v2.3.1 (#10738) * chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 (#10686) * fix(report): don't produce trailing comma in gitlab.tpl links array (#10728) * fix(cloudformation): propagate AWS::EC2::Instance MetadataOptions (#10731) * chore(deps): upgrade github.com/cenkalti/backoff dependency to v5 (#10705) * chore: bump golangci-lint to v2.12 (#10726) * feat(spdx): add SHA-512 hash algorithm support to SPDX serializer (#10719) * feat(sbom): support for CycloneDX 1.7 (#10715) * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.300.0 to 1.302.0 in the aws group (#10708) * chore: migrate from helm.sh/helm/v3 to helm.sh/helm/v4 (#10678) * fix(image): correctly reconstruct RUN instructions built without BuildKit (#10714) * feat(java): support from settings.xml (#10692) * fix(java): surface 429 from a remote Maven repository as a fatal error when scanning pom.xml files (#10693) * chore: bump go to 1.26.3 (#10683) * fix(nodejs): handle legacy license formats in npm lockfile parser (#10684) * fix(secret): correctly skip secret-scanner config file from scanning (#10666) * feat(ubuntu): detect Ubuntu 26.04 LTS (#10592) * refactor(nodejs): deduplicate license traversal across package managers (#10681) * fix: overwrite OS packages PURLs after overwrite OS (#10298) * feat(secret): add Azure secret detection rules (#10562) * fix(misconf): prevent path traversal in Terraform filesystem functions (#10664) * feat(secret): add a way to customize skipped folders, files and exts (#10550) * ci: migrate PAT tokens to GitHub App (#10628) * chore(deps): bump the aws group across 1 directory with 6 updates (#10598) * chore(deps): bump the docker group across 1 directory with 3 updates (#10596) * chore(deps): bump the github-actions group across 2 directories with 9 updates (#10608) * chore(deps): bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 (#10641) * chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 (#10648) * ci: migrate PAT tokens to GITHUB_TOKEN for reusable-release workflow (#10655) * feat(seal): add vendor support for language file detection. (#10297) * fix(misconf): make identifiers in ignore rules case-insensitive (#10375) * fix: pull instead of clone when test repo already exists (#10636) * docs: document how to disable check.trivy.dev connections (#10623) * docs(misconf): fix typo in misconfiguration config (#10619) * ci: remove secrets from run block (#10590) * docs: fix typos (#10605) * refactor(deps): replace archived go-homedir with os.UserHomeDir (#10484) * chore(deps): Bump `go-ini` and fix the import path. (#10489) * chore(deps): bump the github-actions group across 2 directories with 9 updates (#10495) * chore(deps): bump github.com/aquasecurity/testdocker (#10543) * docs: convert README demonstration videos to mp4 (#10419) * chore(deps): upgrade vm scan dependency for bug fix (#10575) * docs(nodejs): clarify package.json behavior in image scanning (#10572) * chore(deps): replace xeipuuv/gojsonschema and invopop/jsonschema with google/jsonschema-go (#10528) * chore(deps): bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0 (#10554) * chore(deps): bump alpine to 3.23.4 (#10552) * ci(helm): bump Trivy version to 0.70.0 for Trivy Helm Chart 0.22.0 (#10547) ++++ trivy: - Update to version 0.71.0 (bsc#1267268, CVE-2026-44740, bsc#1268356, CVE-2026-46680): * release: v0.71.0 [main] (#10638) * ci: use only the first line of commit message in release-please workflow (#10766) * feat: add WithDriver and WithProvider options to ospkg detector (#10740) * chore(deps): bump github.com/google/go-containerregistry to v0.21.6 (#10741) * refactor(secret): normalize configPath once in Init (#10702) * feat(secret): add Maven rules to detect passwords and passphrases in settings.xml and settings-security.xml files (#10704) * chore(deps): bump the common group across 1 directory with 25 updates (#10758) * chore: migrate from gomodguard to gomodguard_v2 (#10739) * chore(deps): bump the docker group across 1 directory with 2 updates (#10709) * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.302.0 to 1.303.0 in the aws group (#10752) * ci: scope GitHub App tokens to minimum required permissions (#10755) * chore(deps): upgrade go-redis from v8 to v9 (#10736) * fix(misconf): fix rendering of nested values in terraform plan lists (#10746) * fix(misconf): skip resources with no after changes (#10352) * fix(misconf): reject nil plays during playbook parsing (#10273) * fix(nodejs): silently skip subdirectory package.json files with invalid names (#10609) * fix(misconf): skip null cty values in AsMapValue to prevent panic (#10723) * refactor(misconf): replace custom Helm archive parsing with Helm SDK loaders (#10718) * chore(deps): bump github.com/containerd/containerd/v2 to v2.3.1 (#10738) * chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 (#10686) * fix(report): don't produce trailing comma in gitlab.tpl links array (#10728) * fix(cloudformation): propagate AWS::EC2::Instance MetadataOptions (#10731) * chore(deps): upgrade github.com/cenkalti/backoff dependency to v5 (#10705) * chore: bump golangci-lint to v2.12 (#10726) * feat(spdx): add SHA-512 hash algorithm support to SPDX serializer (#10719) * feat(sbom): support for CycloneDX 1.7 (#10715) * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.300.0 to 1.302.0 in the aws group (#10708) * chore: migrate from helm.sh/helm/v3 to helm.sh/helm/v4 (#10678) * fix(image): correctly reconstruct RUN instructions built without BuildKit (#10714) * feat(java): support from settings.xml (#10692) * fix(java): surface 429 from a remote Maven repository as a fatal error when scanning pom.xml files (#10693) * chore: bump go to 1.26.3 (#10683) * fix(nodejs): handle legacy license formats in npm lockfile parser (#10684) * fix(secret): correctly skip secret-scanner config file from scanning (#10666) * feat(ubuntu): detect Ubuntu 26.04 LTS (#10592) * refactor(nodejs): deduplicate license traversal across package managers (#10681) * fix: overwrite OS packages PURLs after overwrite OS (#10298) * feat(secret): add Azure secret detection rules (#10562) * fix(misconf): prevent path traversal in Terraform filesystem functions (#10664) * feat(secret): add a way to customize skipped folders, files and exts (#10550) * ci: migrate PAT tokens to GitHub App (#10628) * chore(deps): bump the aws group across 1 directory with 6 updates (#10598) * chore(deps): bump the docker group across 1 directory with 3 updates (#10596) * chore(deps): bump the github-actions group across 2 directories with 9 updates (#10608) * chore(deps): bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 (#10641) * chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 (#10648) * ci: migrate PAT tokens to GITHUB_TOKEN for reusable-release workflow (#10655) * feat(seal): add vendor support for language file detection. (#10297) * fix(misconf): make identifiers in ignore rules case-insensitive (#10375) * fix: pull instead of clone when test repo already exists (#10636) * docs: document how to disable check.trivy.dev connections (#10623) * docs(misconf): fix typo in misconfiguration config (#10619) * ci: remove secrets from run block (#10590) * docs: fix typos (#10605) * refactor(deps): replace archived go-homedir with os.UserHomeDir (#10484) * chore(deps): Bump `go-ini` and fix the import path. (#10489) * chore(deps): bump the github-actions group across 2 directories with 9 updates (#10495) * chore(deps): bump github.com/aquasecurity/testdocker (#10543) * docs: convert README demonstration videos to mp4 (#10419) * chore(deps): upgrade vm scan dependency for bug fix (#10575) * docs(nodejs): clarify package.json behavior in image scanning (#10572) * chore(deps): replace xeipuuv/gojsonschema and invopop/jsonschema with google/jsonschema-go (#10528) * chore(deps): bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0 (#10554) * chore(deps): bump alpine to 3.23.4 (#10552) * ci(helm): bump Trivy version to 0.70.0 for Trivy Helm Chart 0.22.0 (#10547) ++++ trivy: - Update to version 0.71.0 (bsc#1267268, CVE-2026-44740, bsc#1268356, CVE-2026-46680, bsc#1269271, CVE-2026-54448): * release: v0.71.0 [main] (#10638) * ci: use only the first line of commit message in release-please workflow (#10766) * feat: add WithDriver and WithProvider options to ospkg detector (#10740) * chore(deps): bump github.com/google/go-containerregistry to v0.21.6 (#10741) * refactor(secret): normalize configPath once in Init (#10702) * feat(secret): add Maven rules to detect passwords and passphrases in settings.xml and settings-security.xml files (#10704) * chore(deps): bump the common group across 1 directory with 25 updates (#10758) * chore: migrate from gomodguard to gomodguard_v2 (#10739) * chore(deps): bump the docker group across 1 directory with 2 updates (#10709) * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.302.0 to 1.303.0 in the aws group (#10752) * ci: scope GitHub App tokens to minimum required permissions (#10755) * chore(deps): upgrade go-redis from v8 to v9 (#10736) * fix(misconf): fix rendering of nested values in terraform plan lists (#10746) * fix(misconf): skip resources with no after changes (#10352) * fix(misconf): reject nil plays during playbook parsing (#10273) * fix(nodejs): silently skip subdirectory package.json files with invalid names (#10609) * fix(misconf): skip null cty values in AsMapValue to prevent panic (#10723) * refactor(misconf): replace custom Helm archive parsing with Helm SDK loaders (#10718) * chore(deps): bump github.com/containerd/containerd/v2 to v2.3.1 (#10738) * chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 (#10686) * fix(report): don't produce trailing comma in gitlab.tpl links array (#10728) * fix(cloudformation): propagate AWS::EC2::Instance MetadataOptions (#10731) * chore(deps): upgrade github.com/cenkalti/backoff dependency to v5 (#10705) * chore: bump golangci-lint to v2.12 (#10726) * feat(spdx): add SHA-512 hash algorithm support to SPDX serializer (#10719) * feat(sbom): support for CycloneDX 1.7 (#10715) * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.300.0 to 1.302.0 in the aws group (#10708) * chore: migrate from helm.sh/helm/v3 to helm.sh/helm/v4 (#10678) * fix(image): correctly reconstruct RUN instructions built without BuildKit (#10714) * feat(java): support from settings.xml (#10692) * fix(java): surface 429 from a remote Maven repository as a fatal error when scanning pom.xml files (#10693) * chore: bump go to 1.26.3 (#10683) * fix(nodejs): handle legacy license formats in npm lockfile parser (#10684) * fix(secret): correctly skip secret-scanner config file from scanning (#10666) * feat(ubuntu): detect Ubuntu 26.04 LTS (#10592) * refactor(nodejs): deduplicate license traversal across package managers (#10681) * fix: overwrite OS packages PURLs after overwrite OS (#10298) * feat(secret): add Azure secret detection rules (#10562) * fix(misconf): prevent path traversal in Terraform filesystem functions (#10664) * feat(secret): add a way to customize skipped folders, files and exts (#10550) * ci: migrate PAT tokens to GitHub App (#10628) * chore(deps): bump the aws group across 1 directory with 6 updates (#10598) * chore(deps): bump the docker group across 1 directory with 3 updates (#10596) * chore(deps): bump the github-actions group across 2 directories with 9 updates (#10608) * chore(deps): bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 (#10641) * chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 (#10648) * ci: migrate PAT tokens to GITHUB_TOKEN for reusable-release workflow (#10655) * feat(seal): add vendor support for language file detection. (#10297) * fix(misconf): make identifiers in ignore rules case-insensitive (#10375) * fix: pull instead of clone when test repo already exists (#10636) * docs: document how to disable check.trivy.dev connections (#10623) * docs(misconf): fix typo in misconfiguration config (#10619) * ci: remove secrets from run block (#10590) * docs: fix typos (#10605) * refactor(deps): replace archived go-homedir with os.UserHomeDir (#10484) * chore(deps): Bump `go-ini` and fix the import path. (#10489) * chore(deps): bump the github-actions group across 2 directories with 9 updates (#10495) * chore(deps): bump github.com/aquasecurity/testdocker (#10543) * docs: convert README demonstration videos to mp4 (#10419) * chore(deps): upgrade vm scan dependency for bug fix (#10575) * docs(nodejs): clarify package.json behavior in image scanning (#10572) * chore(deps): replace xeipuuv/gojsonschema and invopop/jsonschema with google/jsonschema-go (#10528) * chore(deps): bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0 (#10554) * chore(deps): bump alpine to 3.23.4 (#10552) * ci(helm): bump Trivy version to 0.70.0 for Trivy Helm Chart 0.22.0 (#10547) ++++ yq: - Fix multiple CVEs: * CVE-2026-27136 (GO-2026-5030) CVE-2026-25681 (GO-2026-5029) CVE-2026-25680 (GO-2026-5028) CVE-2026-42502 (GO-2026-5027) CVE-2026-42506 (GO-2026-5025) (bsc#1267053) * CVE-2026-39821 (GO-2026-5026) (bsc#1267199) ------------------------------------------------------------------ ------------------ 2026-5-31 - May 31 2026 ------------------- ------------------------------------------------------------------ ++++ kernel-64kb: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-64kb: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-azure: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-azure: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-default: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-default: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-rt: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-rt: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ python-kiwi: - Drop parted requirement for msdos partitioner parted was used in kiwi at one place to set the active flag on a partition in the DOS table. This action can also be done via sfdisk and drops the parted requirement from the kiwi builder code ++++ dtb-aarch64: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ dtb-aarch64: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-source: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-source: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-docs: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-docs: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-kvmsmall: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-kvmsmall: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-obs-build: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-obs-build: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-obs-qa: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-obs-qa: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-syms: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-syms: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-zfcpdump: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ++++ kernel-zfcpdump: - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: gadget: f_fs: serialize DMABUF cancel against request completion (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: typec: ucsi: Don't update power_supply on power role change if not connected (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). - usb: cdns3: plat: fix leaked usb2_phy initialization on usb3_phy acquisition failure (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - tty: serial: samsung: Remove redundant port lock acquisition in rx helpers (git-fixes). - serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ (git-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - parport: Fix race between port and client registration (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: adc: mt6359: fix unchecked return value in mt6358_read_imp (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() (git-fixes). - iio: adc: npcm: fix unbalanced clk_disable_unprepare() (git-fixes). - iio: gyro: adis16260: fix division by zero in write_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - commit b935350 ------------------------------------------------------------------ ------------------ 2026-5-30 - May 30 2026 ------------------- ------------------------------------------------------------------ ++++ uwsgi: - Allow building with JDK that uses libalternatives instead of update-alternatives ++++ kernel-64kb: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-64kb: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-azure: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-azure: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-default: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-default: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-rt: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-rt: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ dtb-aarch64: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ dtb-aarch64: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-source: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-source: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-docs: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-docs: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-kvmsmall: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-kvmsmall: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-obs-build: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-obs-build: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-obs-qa: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-obs-qa: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-syms: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-syms: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-zfcpdump: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ kernel-zfcpdump: - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - commit 029ff01 - Refresh patches.suse/selftests-bpf-Add-more-precision-tracking-tests-for-.patch. (CVE-2026-43009 bsc#1264014) - commit 56216f8 ++++ libdb_java-4_8: - Allow building with JDK that uses libalternatives instead of update-alternatives ++++ subversion: - Allow building with JDK that uses libalternatives instead of update-alternatives ++++ minicom: - Add 0002-dial-Fix-use-of-check_io_frontend.patch - Add 0003-window-Consider-that-wcwidth-can-return-1-on-invalid.patch ------------------------------------------------------------------ ------------------ 2026-5-29 - May 29 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - in default security policy, allow reading from symbolic links [bsc#1265373] - modified sources * ImageMagick-SUSE-security-policy.xml ++++ LibVNCServer: - added patches CVE-2026-44988: missing validation of rectangle width in tight gradient decoding can lead to server-triggered out-of-bounds write [bsc#1266459] * LibVNCServer-CVE-2026-44988.patch ++++ aaa_base: - Update to version 84.87+git20260529.c4391e5: * $status -> $? * Simplifying the sh part too * Addressing review comments and simplifying a bit * Handle javas managed by libalternatives and by update-alternatives alike ++++ aaa_base: - Update to version 84.87+git20260529.c4391e5: * $status -> $? * Simplifying the sh part too * Addressing review comments and simplifying a bit * Handle javas managed by libalternatives and by update-alternatives alike ++++ aaa_base: - Update to version 84.87+git20260529.c4391e5: * $status -> $? * Simplifying the sh part too * Addressing review comments and simplifying a bit * Handle javas managed by libalternatives and by update-alternatives alike ++++ apptainer: - Fix CVE-2026-39821 (GO-2026-5026) (bsc#1266656) Update golang.org/x/net to 0.55.0. ++++ apptainer: - Fix CVE-2026-39821 (GO-2026-5026) (bsc#1266656) Update golang.org/x/net to 0.55.0. ++++ apptainer: - Fix CVE-2026-39821 (GO-2026-5026) (bsc#1266656) Update golang.org/x/net to 0.55.0. ++++ rust1.96: - Add rust1.96 - Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.96.0 ++++ chromium: - Chromium 149.0.7827.53 - added patches: * chromium-149-profile_no_const.patch try to complete deconstifying the use of Profile* started in upstream 2ac4e0f090a26f86e9ffa4bc6c22743911b9be35 * ppc-fedora-0003-third_party-libvpx-Add-ppc64-vsx-files.patch * ppc-libvpx-add-missing-prototype.patch - removed patches: * chromium-141-glibc-2.42-SYS_SECCOMP.patch * fix_building_widevinecdm_with_chromium.patch * disable-ai.patch: known rebase conflicts on 149 - modified patches: * chromium-125-compiler.patch (context) * chromium-143-revert_rust_is_multiple_of.patch (drop one hunk) * chromium-146-value_or.patch (drop one hunk, add one hunk) * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch (regenerated) * ppc-fedora-0002-regenerate-xnn-buildgn.patch (regenerated) * chromium-146-ignore-for-ubsan.patch (redone) * chromium-148-no_dep_on_intree_rustc_binary.patch * ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch * ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch (regenerated, disable code to regenerate at build for now) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now - keeplibs: added: third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/esm/third_party/urlpattern-polyfill - bump BR for gn to 0.20260429 for expand_directory - fixes reading mode (boo#1265854) ++++ chromium: - Chromium 149.0.7827.53 - added patches: * chromium-149-profile_no_const.patch try to complete deconstifying the use of Profile* started in upstream 2ac4e0f090a26f86e9ffa4bc6c22743911b9be35 * ppc-fedora-0003-third_party-libvpx-Add-ppc64-vsx-files.patch * ppc-libvpx-add-missing-prototype.patch - removed patches: * chromium-141-glibc-2.42-SYS_SECCOMP.patch * fix_building_widevinecdm_with_chromium.patch * disable-ai.patch: known rebase conflicts on 149 - modified patches: * chromium-125-compiler.patch (context) * chromium-143-revert_rust_is_multiple_of.patch (drop one hunk) * chromium-146-value_or.patch (drop one hunk, add one hunk) * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch (regenerated) * ppc-fedora-0002-regenerate-xnn-buildgn.patch (regenerated) * chromium-146-ignore-for-ubsan.patch (redone) * chromium-148-no_dep_on_intree_rustc_binary.patch * ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch * ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch (regenerated, disable code to regenerate at build for now) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now - keeplibs: added: third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/esm/third_party/urlpattern-polyfill - bump BR for gn to 0.20260429 for expand_directory - fixes reading mode (boo#1265854) ++++ chromium: - Chromium 149.0.7827.53 - added patches: * chromium-149-profile_no_const.patch try to complete deconstifying the use of Profile* started in upstream 2ac4e0f090a26f86e9ffa4bc6c22743911b9be35 * ppc-fedora-0003-third_party-libvpx-Add-ppc64-vsx-files.patch * ppc-libvpx-add-missing-prototype.patch - removed patches: * chromium-141-glibc-2.42-SYS_SECCOMP.patch * fix_building_widevinecdm_with_chromium.patch * disable-ai.patch: known rebase conflicts on 149 - modified patches: * chromium-125-compiler.patch (context) * chromium-143-revert_rust_is_multiple_of.patch (drop one hunk) * chromium-146-value_or.patch (drop one hunk, add one hunk) * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch (regenerated) * ppc-fedora-0002-regenerate-xnn-buildgn.patch (regenerated) * chromium-146-ignore-for-ubsan.patch (redone) * chromium-148-no_dep_on_intree_rustc_binary.patch * ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch * ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch (regenerated, disable code to regenerate at build for now) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now - keeplibs: added: third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/esm/third_party/urlpattern-polyfill - bump BR for gn to 0.20260429 for expand_directory - fixes reading mode (boo#1265854) ++++ chromium: - Chromium 149.0.7827.53 - added patches: * chromium-149-profile_no_const.patch try to complete deconstifying the use of Profile* started in upstream 2ac4e0f090a26f86e9ffa4bc6c22743911b9be35 * ppc-fedora-0003-third_party-libvpx-Add-ppc64-vsx-files.patch * ppc-libvpx-add-missing-prototype.patch - removed patches: * chromium-141-glibc-2.42-SYS_SECCOMP.patch * fix_building_widevinecdm_with_chromium.patch * disable-ai.patch: known rebase conflicts on 149 - modified patches: * chromium-125-compiler.patch (context) * chromium-143-revert_rust_is_multiple_of.patch (drop one hunk) * chromium-146-value_or.patch (drop one hunk, add one hunk) * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch (regenerated) * ppc-fedora-0002-regenerate-xnn-buildgn.patch (regenerated) * chromium-146-ignore-for-ubsan.patch (redone) * chromium-148-no_dep_on_intree_rustc_binary.patch * ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch * ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch (regenerated, disable code to regenerate at build for now) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now - keeplibs: added: third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/esm/third_party/urlpattern-polyfill - bump BR for gn to 0.20260429 for expand_directory - fixes reading mode (boo#1265854) ++++ chromium: - Chromium 149.0.7827.53 - added patches: * chromium-149-profile_no_const.patch try to complete deconstifying the use of Profile* started in upstream 2ac4e0f090a26f86e9ffa4bc6c22743911b9be35 * ppc-fedora-0003-third_party-libvpx-Add-ppc64-vsx-files.patch * ppc-libvpx-add-missing-prototype.patch - removed patches: * chromium-141-glibc-2.42-SYS_SECCOMP.patch * fix_building_widevinecdm_with_chromium.patch * disable-ai.patch: known rebase conflicts on 149 - modified patches: * chromium-125-compiler.patch (context) * chromium-143-revert_rust_is_multiple_of.patch (drop one hunk) * chromium-146-value_or.patch (drop one hunk, add one hunk) * ppc-fedora-0002-third_party-libvpx-Remove-bad-ppc64-config.patch (regenerated) * ppc-fedora-0002-regenerate-xnn-buildgn.patch (regenerated) * chromium-146-ignore-for-ubsan.patch (redone) * chromium-148-no_dep_on_intree_rustc_binary.patch * ppc-fedora-0001-Implement-support-for-ppc64-on-Linux.patch * ppc-fedora-0001-Add-PPC64-support-for-boringssl.patch * ppc-fedora-0001-Add-pregenerated-config-for-libaom-on-ppc64.patch (regenerated, disable code to regenerate at build for now) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now - keeplibs: added: third_party/devtools-frontend/src/front_end/third_party/puppeteer/package/lib/esm/third_party/urlpattern-polyfill - bump BR for gn to 0.20260429 for expand_directory - fixes reading mode (boo#1265854) ++++ cloudflared: - Update version to 2026.5.2 * Add more information to proxy-dns removal message * Update tail command to use /management/logs endpoint * Add cloudflared management token command * Fix bugs * Update golang.org/x/net to 0.55.0 (boo#1266794, boo#1265920, CVE-2026-39821 CVE-2026-33814) - Drop update-crypto.patch, fixed by upstream ++++ kernel-64kb: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-64kb: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-azure: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-azure: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-default: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-default: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-rt: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-rt: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ dtb-aarch64: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ dtb-aarch64: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ girara: - Cleanup spec file with spec-cleaner - Drop dependency on girara-devel from the devel-doc subpackage (a -doc package should not require -devel) ++++ shadowsocks-v2ray-plugin: - Update version to 5.49.0 * Update v2ray-core to 5.49.0 * Update grpc to 1.81.1 (boo#1260328 and CVE-2026-33186) ++++ jansi: - Allow building with JDK that uses libalternatives instead of update-alternatives ++++ java-17-openj9: - Use libalternatives instead of update-alternatives for distributions where libalternatives is available ++++ java-17-openjdk: - Use libalternatives instead of update-alternatives for distributions where libalternatives is available (bsc#1264396) ++++ java-21-openj9: - Use libalternatives instead of update-alternatives for distributions where libalternatives is available ++++ java-21-openjdk: - Use libalternatives instead of update-alternatives for distributions where libalternatives is available (bsc#1264397) ++++ java-25-openjdk: - Use libalternatives instead of update-alternatives for distributions where libalternatives is available (bsc#1264398) ++++ jline3: - Allow building with JDK that uses libalternatives instead of update-alternatives ++++ jline3: - Allow building with JDK that uses libalternatives instead of update-alternatives ++++ keybase-client: - Add update-go-crypto.patch to address boo#1266158. - Add update-go-net.patch to address boo#1266596. ++++ keybase-client: - Add update-go-crypto.patch to address boo#1266158. - Add update-go-net.patch to address boo#1266596. ++++ kernel-source: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-source: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-docs: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-docs: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-kvmsmall: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-kvmsmall: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-obs-build: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-obs-build: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-obs-qa: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-obs-qa: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-syms: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-syms: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-zfcpdump: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ kernel-zfcpdump: - wifi: iwlwifi: mvm: don't send a 6E related command when not supported (CVE-2026-43325 bsc#1265110). - commit 84701d2 - btrfs: reserve enough transaction items for qgroup ioctls (CVE-2026-43338 bsc#1264716). - commit 062af51 - KVM: nSVM: Avoid incorrect injection of SVM_EXIT_CR0_SEL_WRITE (git-fixes). - commit fe5c353 - KVM: nSVM: Propagate SVM_EXIT_CR0_SEL_WRITE correctly for LMSW emulation (git-fixes). - commit b576a59 - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - commit 0acb9df - KVM: x86: Return the VM's configured APIC bus frequency when queried (git-fixes). - commit b075ab1 - selftests/bpf: add test for nullable PTR_TO_BUF access (CVE-2026-43333 bsc#1264726). - commit 5c9ba0e - bpf: reject direct access to nullable PTR_TO_BUF pointers (CVE-2026-43333 bsc#1264726). - commit 05c4059 ++++ libzypp: - Fix potential crash on malformed or malicious repository metadata (fixes #740) - version 17.38.11 (35) ++++ mcphost: - Fix CVE-2026-39821 (GO-2026-5026) (bsc#1266572) CVE-2026-27136 (GO-2026-5030) CVE-2026-25681 (GO-2026-5029) CVE-2026-25680 (GO-2026-5028) CVE-2026-42502 (GO-2026-5027) CVE-2026-42506 (GO-2026-5025) (bsc#1267109) Update golang.org/x/net to 0.55.0. ++++ perl-HTTP-Daemon: - added patches CVE-2026-8450: HTTP:Daemon versions before 6.17 for Perl allow OS command injection via send_file() [bsc#1266370] * perl-HTTP-Daemon-CVE-2026-8450.patch ++++ python-starlette: - CVE-2026-48710: Missing Host header validation poisons request.url.path, bypassing path-based security checks (bsc#1266369) * added CVE-2026-48710.patch ++++ python-starlette: - CVE-2026-48710: Missing Host header validation poisons request.url.path, bypassing path-based security checks (bsc#1266369) * added CVE-2026-48710.patch ++++ rqlite: - Update to version 10.2.0: * Support verifying mTLS peer Common Name * Console supports restore from SQLite data * Console "count rows" respects current Tables Expand/Collapse state * Console supports dropping indexes * Further Console app improvements ++++ selinux-policy: - Update to version 20250627+git378.e27ad25be: * Allow systemd-tmpfiles to adjust resource limits (bsc#1266328) ++++ selinux-policy: - Update to version 20250627+git378.e27ad25be: * Allow systemd-tmpfiles to adjust resource limits (bsc#1266328) ------------------------------------------------------------------ ------------------ 2026-5-28 - May 28 2026 ------------------- ------------------------------------------------------------------ ++++ amazon-ecs-init: - Update to version 1.103.2 * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/fsx from 1.53.1 to 1.65.10 in /agent (#4966) * Enhancement - Add semgrep security scan for command injection (#4959) * Enhancement - Bump golang.org/x/tools from 0.39.0 to 0.45.0 in /ecs-agent (#4965), also updates x/net to 0.54.0 (bsc#1266652, CVE-2026-39821) * Enhancement - Add integration test for credential refresher (#4961) * Enhancement - Bump golang.org/x/tools from 0.42.0 to 0.45.0 in /agent (#4873) * Enhancement - Update Go version to 1.25.10 (#4960) * Enhancement - Bump go.etcd.io/bbolt from 1.3.9 to 1.4.3 in /ecs-agent (#4872) * Enhancement - update credentials-fetcher retry comments/tests (#4954) * Enhancement - Enhancement - Add retry mechanism to credentialsfetcher (#4948) * Enhancement - Add IMDS credential refresher (#4953) * Bugfix - fix flaky tests depending on timers (#4955) - from version 1.103.1 * Feature - Implement IMDS scanner for task credential retrieval, in the shared library (#4945) * Feature - Add config/capability for IMDS-based task credential retrieval (disabled for now) (#4938) * Feature - Add IMDS credential scanner interface and capability constant for IMDS-based task credential retrieval (#4937) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs from 1.47.3 to 1.65.0 in /agent (#4921) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.63.1 to 1.97.3 in /ecs-init (#4923) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.79.2 to 1.97.3 in /agent (#4924) * Enhancement - Bump go.opentelemetry.io/otel/exporters/otlp/ otlptrace/ otlptracehttp from 1.32.0 to 1.43.0 in /agent (#4926) * Enhancement - Truncate log values to make agent logs less verbose (#4940) - Drop CVE-2026-33814.patch, merged upstream ++++ amazon-ssm-agent: - Update to version 3.3.4515.0 * Bump golang.org/x/net from v0.48.0 to v0.53.0 (bsc#1266781, CVE-2026-39821) * Quit if sysprep failed and log its current state * Remove attached legacy cloudwatch plugin packages * Upgrade Go version to 1.25.10 * Use BuildSafePath wherever it is applicable - from version 3.3.4364.0 * Add OOM killer protection to systemd service files * Apply more sanitation to file and registry inventory gatherers * Bump go-git to v5.17.1 * Deprecate legacy cloudwatch plugin * Preserve network error details in credential refresher SSM API failures * Upgrade Go version to 1.25.9 ++++ kernel-64kb: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-64kb: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-azure: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-azure: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-default: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-default: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-rt: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-rt: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ distribution: - use vendor.tar.zst generation - update x/net to v0.55.0 ( bsc#1266629, CVE-2026-39821, bsc#1265788, CVE-2026-33814) - update x/crypto to 0.52.0 (CVE-2026-39827, CVE-2026-39834,CVE-2026-39828,CVE-2026-39829,CVE-2026-39831, CVE-2026-42508,CVE-2026-39833,CVE-2026-39830,CVE-2026-39832, CVE-2026-46597,CVE-2026-46598,CVE-2026-46595,CVE-2026-39835) ++++ dtb-aarch64: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ dtb-aarch64: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ frr: - Update to frr-10.2.6 (https://frrouting.org/release/10.2.6/) providing bug fixes including the following security fixes: - bgpd: improve packet parsing for EVPN and ENCAP/VNC (CVE-2026-5107,bsc#1261013,gh#FRRouting/frr#21098) - ospfd: harden TE/SR TLV iteration against malformed lengths (bsc#1263859,CVE-2026-28532,gh#FRRouting/frr#21002) - bgpd: fix off-by-one error in FlowSpec operator array bounds check (bsc#1263863,CVE-2026-37457,gh#FRRouting/frr#21054) - Removed obsolete patch included in the 10.2.6 release: [- 0004-bgpd-improve-packet-parsing-for-EVPN-and-ENCAP-VNC.patch] - Apply fix for a Denial of Service (DoS): - bgpd: Validate MP_REACH_NLRI attribute against incorrect next-hop (bsc#1263974,CVE-2026-37458,gh#FRRouting/frr#21075) [+ 0004-bgpd-Validate-MP_REACH_NLRI-attribute-against-incorr.patch] ++++ libjxl-gtk: - Add libjxl-CVE-2025-70103.patch: take EC into accound when checking required PNM inmput length (bsc#1266460 CVE-2025-70103). ++++ gitea-tea: - Fix access to sha256 repositories * Use-git-command-instead-of-go-git-1005.patch ++++ glab: - Update to version 1.100.0: * Features - 02f8ae0a: feat(api): expand Coding-Agent detection list (Sam Wiskow swiskow@gitlab.com) - 1f462ed8: feat(ci status): keep --live polling through transient pipeline states (Kai Armstrong karmstrong@gitlab.com) - ae28d6dd: feat(issue): allow work_items URLs (Jay McCure jmccure@gitlab.com) - 35926816: feat(stack): add Body() method to StackRef and fix subject/body parsing in MR creation (Gary Holtz gholtz@gitlab.com) - 4f5f192a: feat(stack): add glab stack infer command to create stack layers from a commit range (Gary Holtz gholtz@gitlab.com) - ddf45787: feat(update): nudge is install-aware and agent-aware (Sam Wiskow swiskow@gitlab.com) - 0db2448f: feat: Introduce repo remote add command (Gabriel Mazzetto gabriel@gitlab.com) - e6a25a75: feat: add detection for Gemini CLI (Isaac Dawson idawson@gitlab.com) - 1f49782a: feat: add global --jq flag for filtering JSON output (Kai Armstrong karmstrong@gitlab.com) * Bug Fixes - b98561dc: fix(ci view): harden bridge/child-pipeline navigation against crashes (Kai Armstrong karmstrong@gitlab.com) - 979568c6: fix(cmd): remove workaround (Filip Aleksic faleksic@gitlab.com) - 1aa323e5: fix(infer): build branch chain via cherry-pick with conflict rollback (Gary Holtz gholtz@gitlab.com) - 6fa36242: fix(pager): set LESS=FRX unless hyperlinks are forced (Kai Armstrong karmstrong@gitlab.com) - df2a507f: fix(test): align TestAcceptableZipFile path check with friendlyPath output (Filip Aleksic faleksic@gitlab.com) - 2deffd68: fix: update link for creating new legacy personal access token (Evan Read eread@gitlab.com) * Documentation - 6270cd3d: docs: improve glab ci command docs 2 (Brendan Lynch blynch@gitlab.com) - 75ac9bce: docs: improve help text for glab cluster commands (Brendan Lynch blynch@gitlab.com) - 30fa9fd8: docs: update glab SKILL.md with comments section and API content-type guidance (Thomas Schmidt tschmidt@gitlab.com) * Dependencies - 6642b29e: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.31.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 08c5f240: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.32.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 9879b156: chore(deps): update versions (Filip Aleksic faleksic@gitlab.com) * Maintenance - 38f97c78: chore(ci): improve check docs job (Filip Aleksic faleksic@gitlab.com) - 6c452a46: chore(code): remove dead code (Filip Aleksic faleksic@gitlab.com) - 4e80e10c: refactor: route command JSON output through PrintJSON helper (Kai Armstrong karmstrong@gitlab.com) ++++ gsasl: - DIGEST-MD5: Fix NULL pointer dereference in parser; (CVE-2026-48829); (bsc#1266371); Add patch 0004-CVE-2026-48829.patch ++++ gvfs: - Add gvfs-fix-udisks2-crash.patch: Fix crash of cancelled pending operation. (bsc#1261625, glgo#GNOME/gvfs!326) ++++ htop: - Modernise spec file: * Drop deprecated %suse_update_desktop_file call and the matching update-desktop-files BuildRequires (upstream ships a valid desktop file already). * Add explicit BuildRequires on gcc and make — no longer pulled in by the default OBS build root. ++++ ignition: - Add CVE-2026-33814.patch * Fixes [bsc#1265751] ++++ javapackages-tools: - Outside of the ancient distros (< SLE-15-SP5) for the Python packaging use the modern style of %pyproject_* macros (soo#python/_ObsPrj#491). ++++ javapackages-tools-extras: - Outside of the ancient distros (< SLE-15-SP5) for the Python packaging use the modern style of %pyproject_* macros (soo#python/_ObsPrj#491). ++++ keybase-client: - Update to version 6.6.2 * Improve git default branch handling - Drop update-go-image.patch as the dependency was updated upstream. - Fix accidental inclusion of old vendor directory in the source archive. - Drop downgrade-miekg-dns.patch as it was only a workaround for the old vendor directory. ++++ keybase-client: - Update to version 6.6.2 * Improve git default branch handling - Drop update-go-image.patch as the dependency was updated upstream. - Fix accidental inclusion of old vendor directory in the source archive. - Drop downgrade-miekg-dns.patch as it was only a workaround for the old vendor directory. ++++ kernel-source: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-source: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-docs: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-docs: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-kvmsmall: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-kvmsmall: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-obs-build: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-obs-build: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-obs-qa: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-obs-qa: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-syms: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-syms: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-zfcpdump: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ kernel-zfcpdump: - xfrm: prevent policy_hthresh.work from racing with netns teardown (CVE-2026-31516 bsc#1262755). - commit ec34473 - mptcp: pm: in-kernel: always set ID as avail when rm endp (CVE-2026-43252 bsc#1264300). - commit 89a78a5 - net/ipv6: ioam6: prevent schema length wraparound in trace fill (CVE-2026-43341 bsc#1265044). - commit e6f9144 - btrfs: fix transaction abort on set received ioctl due to item overflow (CVE-2026-43359 bsc#1264719). - commit 2cf8c07 - btrfs: fix transaction abort when snapshotting received subvolumes (CVE-2026-43361 bsc#1264722). - commit 44cbaf6 - btrfs: fix transaction abort on file creation due to name hash collision (CVE-2026-43360 bsc#1264720). - commit 1bd108a - slip: bound decode() reads against the compressed packet length (CVE-2026-45843 bsc#1266395). - commit ffc4b45 - s390/entry: Scrub r12 register on kernel entry (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261590,bsc#1262771,CVE-2026-31483). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261590,bsc#1262771,CVE-2026-31483). - commit d252494 - tracing: Fix potential deadlock in cpu hotplug with osnoise (CVE-2026-31480 bsc#1262634). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - commit 5767a84 - bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584 CVE-2026-23359). - commit 82c3529 - wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (CVE-2026-23444 bsc#1266307). - commit f26d039 - bcache: fix uninitialized closure object (git-fixes). - commit c4a3456 ++++ mapserver: - Update to releasee 8.6.3 * SLD parser: fix out of bounds access on SLD with only a Rule with a ElseFilter but without a symbolizer [CVE-2026-33721, boo#1260869] [CVE-2026-45104, boo#1266663] ++++ libjxl: - Add libjxl-CVE-2025-70103.patch: take EC into accound when checking required PNM inmput length (bsc#1266460 CVE-2025-70103). ++++ libsolv: - fix solv_chksum_free segfault when called with a NULL pointer - bump version to 0.7.39 ++++ maven-surefire-plugins: - Upgrade to 3.5.6 * New features and improvements + Introduce reportTestTimestamp option and include timestamp for test sets and test cases * Bug Fixes + Issue #2613 Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug + Ensure that the statistics filename is calculated only once. + Add flakes attribute to use in testsuite report + [BACKPORT 3.5.x] [SUREFIRE-2049] - Fix SHUTDOWN type lost during command serialization. + fix: null guard for context map * Maintenance + 3.5.x/bug/cherry pick embedded mode its + Use surefire 3.5.5 by project itself for testing + Follow Oracle javadoc guidelines * Dependency updates + Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 + Bump commons-io:commons-io from 2.21.0 to 2.22.0 - Modified patches: * 0001-Port-to-TestNG-7.4.0.patch * 0002-Unshade-surefire.patch + rediff * maven-surefire-bootstrap-resources.patch + regenerate from non-bootstrap build ++++ maven-surefire: - Upgrade to 3.5.6 * New features and improvements + Introduce reportTestTimestamp option and include timestamp for test sets and test cases * Bug Fixes + Issue #2613 Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug + Ensure that the statistics filename is calculated only once. + Add flakes attribute to use in testsuite report + [BACKPORT 3.5.x] [SUREFIRE-2049] - Fix SHUTDOWN type lost during command serialization. + fix: null guard for context map * Maintenance + 3.5.x/bug/cherry pick embedded mode its + Use surefire 3.5.5 by project itself for testing + Follow Oracle javadoc guidelines * Dependency updates + Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 + Bump commons-io:commons-io from 2.21.0 to 2.22.0 - Modified patches: * 0001-Port-to-TestNG-7.4.0.patch * 0002-Unshade-surefire.patch + rediff * maven-surefire-bootstrap-resources.patch + regenerate from non-bootstrap build ++++ maven-surefire-provider-junit5: - Upgrade to 3.5.6 * New features and improvements + Introduce reportTestTimestamp option and include timestamp for test sets and test cases * Bug Fixes + Issue #2613 Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug + Ensure that the statistics filename is calculated only once. + Add flakes attribute to use in testsuite report + [BACKPORT 3.5.x] [SUREFIRE-2049] - Fix SHUTDOWN type lost during command serialization. + fix: null guard for context map * Maintenance + 3.5.x/bug/cherry pick embedded mode its + Use surefire 3.5.5 by project itself for testing + Follow Oracle javadoc guidelines * Dependency updates + Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 + Bump commons-io:commons-io from 2.21.0 to 2.22.0 - Modified patches: * 0001-Port-to-TestNG-7.4.0.patch * 0002-Unshade-surefire.patch + rediff * maven-surefire-bootstrap-resources.patch + regenerate from non-bootstrap build ++++ nvidia-open-driver-G07-signed-cuda: - linux-7.0.patch * adjust driver to changes of screen_info with Kernel 7.0, which broke the driver completely (boo#1263825); see also https://forums.developer.nvidia.com/t/linux-driver-595-71-05-still-tries-to-use-screen-info-struct-which-was-refactored-in-7-0-kernel/370825 - update non-CUDA variant to 595.80 (boo#1266660) - update CUDA variant to 610.43.02 - kernel-5.14.patch not needed; removed therefore ++++ nvidia-open-driver-G07-signed-cuda: - linux-7.0.patch * adjust driver to changes of screen_info with Kernel 7.0, which broke the driver completely (boo#1263825); see also https://forums.developer.nvidia.com/t/linux-driver-595-71-05-still-tries-to-use-screen-info-struct-which-was-refactored-in-7-0-kernel/370825 - update non-CUDA variant to 595.80 (boo#1266660) - update CUDA variant to 610.43.02 - kernel-5.14.patch not needed; removed therefore ++++ nvidia-open-driver-G07-signed: - linux-7.0.patch * adjust driver to changes of screen_info with Kernel 7.0, which broke the driver completely (boo#1263825); see also https://forums.developer.nvidia.com/t/linux-driver-595-71-05-still-tries-to-use-screen-info-struct-which-was-refactored-in-7-0-kernel/370825 - update non-CUDA variant to 595.80 (boo#1266660) - update CUDA variant to 610.43.02 - kernel-5.14.patch not needed; removed therefore ++++ nvidia-open-driver-G07-signed: - linux-7.0.patch * adjust driver to changes of screen_info with Kernel 7.0, which broke the driver completely (boo#1263825); see also https://forums.developer.nvidia.com/t/linux-driver-595-71-05-still-tries-to-use-screen-info-struct-which-was-refactored-in-7-0-kernel/370825 - update non-CUDA variant to 595.80 (boo#1266660) - update CUDA variant to 610.43.02 - kernel-5.14.patch not needed; removed therefore ++++ openSUSE-build-key: - extended to openSUSE 4096bit RSA key for 4 more years. gpg-pubkey-29b700a4-6a17fa38.asc ++++ openSUSE-build-key: - extended to openSUSE 4096bit RSA key for 4 more years. gpg-pubkey-29b700a4-6a17fa38.asc ++++ os-autoinst: - Update to version 5.1779973703.70686ac: * ci: Use CI container in fullstack test as well * feat: Log details about relevant port if cmd srv cannot be started * refactor: Move function to get port details to OS utils * refactor: Use Feature::Compat::Try consistently * perf: use sourcing for efficient pretty serial marker activation * fix: Fix condition for devel/deps packages * feat: use efficient OA_NO_MARKER skip flag for pretty serial markers * refactor: use __oa_prompt shell function for pretty serial markers * feat: warn on manual serial terminal redirection in script_run ++++ os-autoinst: - Update to version 5.1779973703.70686ac: * ci: Use CI container in fullstack test as well * feat: Log details about relevant port if cmd srv cannot be started * refactor: Move function to get port details to OS utils * refactor: Use Feature::Compat::Try consistently * perf: use sourcing for efficient pretty serial marker activation * fix: Fix condition for devel/deps packages * feat: use efficient OA_NO_MARKER skip flag for pretty serial markers * refactor: use __oa_prompt shell function for pretty serial markers * feat: warn on manual serial terminal redirection in script_run ++++ os-autoinst: - Update to version 5.1779973703.70686ac: * ci: Use CI container in fullstack test as well * feat: Log details about relevant port if cmd srv cannot be started * refactor: Move function to get port details to OS utils * refactor: Use Feature::Compat::Try consistently * perf: use sourcing for efficient pretty serial marker activation * fix: Fix condition for devel/deps packages * feat: use efficient OA_NO_MARKER skip flag for pretty serial markers * refactor: use __oa_prompt shell function for pretty serial markers * feat: warn on manual serial terminal redirection in script_run ++++ perl-Cpanel-JSON-XS: - updated to 4.410.0 (4.41) see /usr/share/doc/packages/perl-Cpanel-JSON-XS/Changes 4.41 2026-05-27 (rurban) - Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) (patch by Paul Johnson) bsc#1267547 - Fix dupkeys_as_arrayref type confusion (CVE-2026-9334) (patch by Paul Johnson) bsc#1267546 - Fix incr_parse single-quote string delimiter (GH #245, reported by Paul Johnson) - Fix a one-byte out-of-bounds heap read reachable via allow_barekey on truncated input (GH #244, reported by Paul Johnson) ++++ python-aiohttp: - CVE-2026-22815: insufficient header/trailer handling can cause a denial of service (bsc#1261320) * added CVE-2026-22815.patch - CVE-2026-34513: unbounded DNS cache can cause a denial of service (bsc#1261321) * added CVE-2026-34513.patch - CVE-2026-34514: content_type parameter manipulation can lead to header Injection (bsc#1261322) * added CVE-2026-34514.patch - CVE-2026-34516: excessive multipart headers can cause a denial of service (bsc#1261329) * added CVE-2026-34516.patch - CVE-2026-34517: large multipart form fields can cause a denial of service (bsc#1261331) * added CVE-2026-34517.patch - CVE-2026-34518: retained Cookie and Proxy-Authorization headers during redirects can lead to information disclosure (bsc#1261332) * added CVE-2026-34518.patch - CVE-2026-34519: reason parameter can be use to perform header injection (bsc#1261334) * added CVE-2026-34519.patch - CVE-2026-34520: improper character handling can lead to header injection (bsc#1261335) * added CVE-2026-34520.patch - CVE-2026-34525: multiple Host headers can potentially lead to security bypass (bsc#1261343) * added CVE-2026-34525.patch and CVE-2026-34525-2.patch - CVE-2026-34993: arbitrary code execution via loading untrusted input in CookieJar.load() (bsc#1267471) * added CVE-2026-34993.patch - CVE-2026-47265: cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect (bsc#1267561) * added CVE-2026-47265.patch ++++ rqlite: - update go-net depdendency to address IDN Punycode validation bypass CVE-2026-39821 boo#1266544 ++++ strongswan: - CVE-2026-47895: Fixed a double-free vulnerability when destroying certain cloned identities. When cloning identities with empty encoded chunks (e.g., ID_ANY), the clone's encoded chunk was not properly initialized, leading to a double-free when both the original and cloned identities were destroyed (bsc#1266360). [+ FIX-CVE-2026-47895-Double-Free-When-Destroying-Certain-Cloned-Identities.patch] ++++ tomcat: - Update to Tomcat 9.0.118 * Fixed CVEs: + CVE-2026-43515: Security constraints not correctly applied (bsc#1265168) + CVE-2026-43514: AJP secret compared in non-constant time (bsc#1265167) + CVE-2026-43513: LockOutRealm treats user names as case-sensitive (bsc#1265166) + CVE-2026-43512: Digest authenticator will authenticate any unknown user (bsc#1265145) + CVE-2026-42498: WebSocket authentication header exposure (bsc#1265165) + CVE-2026-41293: HTTP/2 request headers not validated (bsc#1265163) + CVE-2026-41284: Unbounded read in WebDAV LOCK and PROPFIND handling (bsc#1265162) * Catalina + Add: Enhance version.sh and version.bat to display APR, Tomcat Native, and OpenSSL version information (both APR and FFM implementations), along with version compatibility warnings and third-party library version information. (csutherl) + Code: Refactor generation of the remote user element in the access log to remove unnecessary code. (markt) + Fix: Fix a regression in the previous release that meant ?- could appear in the access log rather than ? when the query string was present but empty. (markt) + Fix: Failed precondition should make WebDAV DELETE fail. #982 submitted by Mahmoud Alarby. (remm) + Fix: Align the escaping in ExtendedAccessLogValve with the other AccessLogValve implementations. (markt) + Fix: 70000: fix duplication of special headers in the response after commit, following fix for 69967. (remm) + Fix: Correct the handling of URIs mapped to a security constraint that only specifies the special ** role for all authenticated users. Requests without authentication were receiving 403 responses rather than 401 responses. (markt) + Fix: Fix a race condition in StandardContext.getServletContext() that could cause the jakarta.servlet.context.tempdir attribute to be lost during a context reload. Make the context field volatile and use locking to ensure only one ApplicationContext instance is created. (dsoumis) + Fix: Update the Windows authentication (kerberos) documentation to reflect that both Java and Windows are removing / have removed support for RC4-HMAC. The guide now uses AES256-SHA1. (markt) + Fix: Add a new initialisation parameter for WebDAV, maxRequestBodySize which limits the size of a WebDAV request body for LOCK and PROPFIND. The default value is 4096 bytes. (markt) + Add: Add a new caseSensitive attribute to the LockOutRealm that controls the manner in which user names are treated when making locking decisions. The default is false, meaning user names are treated in a case insensitive manner. (markt) + Fix: Correct the handling of invalid users with DIGEST authentication. (markt) + Fix: Ensure RealmBase finds all matching extension based security constraints. (markt) * Coyote + Fix: Avoid various edge cases if Content-Length is set via setHeader(String,String) or addHeader(String,String) with an invalid value by always clearing the previous value whether the new value is valid or not and ignoring any invalid new value. (markt) + Code: Refactor the calculation of the real index in the HPACK dynamic header table implementation to reduce code duplication. (markt) + Fix: Fix various minor issues with some HTTP/2 stream error messages for HTTP/2. (markt) + Fix: Consistently reject URIs containing NULL bytes when normalizing. (markt) + Fix: Fix a few minor memory leaks on error paths reading TLS keys and certificates when using FFM. (markt) + Fix: Refactor clean-up after HTTP/2 headers have been processed to aid GC after a stream reset. (markt) + Fix: Align HTTP/2 trailer fields with HTTP/1.1 and filter out any fields not permitted in trailers. (markt) + Fix: Free private keys after use in FFM based connector configuration. (markt) + Fix: Correct an unlikely edge-case parsing bug in the HTTP/2 HPACK header decoding that could result in a valid header triggering an unexpected connection close. (markt) + Fix: Refactor HTTP/2 HPACK encoding so header field names are only converted to lower case once during the encoding process. (markt) + Fix: Refactor HTTP/2 header field validation so it occurs earlier. Extend validation to check for disallowed characters as well as upper case characters. (markt) + Fix: Add TLS 1.3 groups added in OpenSSL 4.0. (remm) + Fix: Add validation that the HTTP/2 :scheme pseudo-header is consistent with the use (or not) of TLS. (markt) + Fix: Correct the validation of pseudo headers and CONNECT requests to align Tomcat's behaviour with RFC 9113, section 8.5. (markt) + Fix: Fix a potential integer overflow when allocating capacity from a connection level window update to individual HTTP/2 streams. Based on #996 by Mike Tingey Jr. (markt) + Fix: Switch AJP secret comparison to a constant time algorithm. (markt) * WebSocket + Fix: Fix the initial connection to a WebSocket end point where the connection is made via a proxy that requires DIGEST authentication. (markt) * Other + Fix: 69993: Update the URL to the CDDL 1.0 license. (markt) + Add: Add warning when OpenSSL binary is not found. (csutherl) + Add: Add check for Tomcat Native library, and log warning when it's not found to make it easier to see when it's not used by the suite. (csutherl) + Update: Update Byte Buddy to 1.18.8. (markt) + Update: Update Bouncy Castle to 1.84. (markt) + Update: Improvements to French translations. (remm) + Update: Improvements to Japanese translations provided by tak7iji. (markt) ++++ tomcat10: - Update to Tomcat 10.1.55 * Fixed CVEs: + CVE-2026-43515: Security constraints not correctly applied (bsc#1265168) + CVE-2026-43514: AJP secret compared in non-constant time (bsc#1265167) + CVE-2026-43513: LockOutRealm treats user names as case-sensitive (bsc#1265166) + CVE-2026-43512: Digest authenticator will authenticate any unknown user (bsc#1265145) + CVE-2026-42498: WebSocket authentication header exposure (bsc#1265165) + CVE-2026-41293: HTTP/2 request headers not validated (bsc#1265163) + CVE-2026-41284: Unbounded read in WebDAV LOCK and PROPFIND handling (bsc#1265162) * Catalina + Add: Enhance version.sh and version.bat to display APR, Tomcat Native, and OpenSSL version information (both APR and FFM implementations), along with version compatibility warnings and third-party library version information. (csutherl) + Code: Refactor generation of the remote user element in the access log to remove unnecessary code. (markt) + Fix: Fix a regression in the previous release that meant ?- could appear in the access log rather than ? when the query string was present but empty. (markt) + Fix: Failed precondition should make WebDAV DELETE fail. #982 submitted by Mahmoud Alarby. (remm) + Fix: Align the escaping in ExtendedAccessLogValve with the other AccessLogValve implementations. (markt) + Fix: 70000: fix duplication of special headers in the response after commit, following fix for 69967. (remm) + Fix: Correct the handling of URIs mapped to a security constraint that only specifies the special ** role for all authenticated users. Requests without authentication were receiving 403 responses rather than 401 responses. (markt) + Fix: Fix a race condition in StandardContext.getServletContext() that could cause the jakarta.servlet.context.tempdir attribute to be lost during a context reload. Make the context field volatile and use locking to ensure only one ApplicationContext instance is created. (dsoumis) + Fix: Update the Windows authentication (kerberos) documentation to reflect that both Java and Windows are removing / have removed support for RC4-HMAC. The guide now uses AES256-SHA1. (markt) + Fix: Add a new initialisation parameter for WebDAV, maxRequestBodySize which limits the size of a WebDAV request body for LOCK and PROPFIND. The default value is 4096 bytes. (markt) + Add: Add a new caseSensitive attribute to the LockOutRealm that controls the manner in which user names are treated when making locking decisions. The default is false, meaning user names are treated in a case insensitive manner. (markt) + Fix: Correct the handling of invalid users with DIGEST authentication. (markt) + Fix: Ensure RealmBase finds all matching extension based security constraints. (markt) * Coyote + Fix: Avoid various edge cases if Content-Length is set via setHeader(String,String) or addHeader(String,String) with an invalid value by always clearing the previous value whether the new value is valid or not and ignoring any invalid new value. (markt) + Code: Refactor the calculation of the real index in the HPACK dynamic header table implementation to reduce code duplication. (markt) + Fix: Fix various minor issues with some HTTP/2 stream error messages for HTTP/2. (markt) + Fix: Consistently reject URIs containing NULL bytes when normalizing. (markt) + Fix: Fix a few minor memory leaks on error paths reading TLS keys and certificates when using FFM. (markt) + Fix: Refactor clean-up after HTTP/2 headers have been processed to aid GC after a stream reset. (markt) + Fix: Align HTTP/2 trailer fields with HTTP/1.1 and filter out any fields not permitted in trailers. (markt) + Fix: Free private keys after use in FFM based connector configuration. (markt) + Fix: Correct an unlikely edge-case parsing bug in the HTTP/2 HPACK header decoding that could result in a valid header triggering an unexpected connection close. (markt) + Fix: Refactor HTTP/2 HPACK encoding so header field names are only converted to lower case once during the encoding process. (markt) + Fix: Refactor HTTP/2 header field validation so it occurs earlier. Extend validation to check for disallowed characters as well as upper case characters. (markt) + Fix: Add TLS 1.3 groups added in OpenSSL 4.0. (remm) + Fix: Add validation that the HTTP/2 :scheme pseudo-header is consistent with the use (or not) of TLS. (markt) + Fix: Correct the validation of pseudo headers and CONNECT requests to align Tomcat's behaviour with RFC 9113, section 8.5. (markt) + Fix: Fix a potential integer overflow when allocating capacity from a connection level window update to individual HTTP/2 streams. Based on #996 by Mike Tingey Jr. (markt) + Fix: Switch AJP secret comparison to a constant time algorithm. (markt) * WebSocket + Fix: Fix the initial connection to a WebSocket end point where the connection is made via a proxy that requires DIGEST authentication. (markt) * Other + Fix: 69993: Update the URL to the CDDL 1.0 license. (markt) + Add: Add warning when OpenSSL binary is not found. (csutherl) + Add: Add check for Tomcat Native library, and log warning when it's not found to make it easier to see when it's not used by the suite. (csutherl) + Update: Update Byte Buddy to 1.18.8. (markt) + Update: Update Bouncy Castle to 1.84. (markt) + Update: Improvements to French translations. (remm) + Update: Improvements to Japanese translations provided by tak7iji. (markt) ++++ tomcat11: - Update to Tomcat 11.0.22 * Fixed CVEs: + CVE-2026-43515: Security constraints not correctly applied (bsc#1265168) + CVE-2026-43514: AJP secret compared in non-constant time (bsc#1265167) + CVE-2026-43513: LockOutRealm treats user names as case-sensitive (bsc#1265166) + CVE-2026-43512: Digest authenticator will authenticate any unknown user (bsc#1265145) + CVE-2026-42498: WebSocket authentication header exposure (bsc#1265165) + CVE-2026-41293: HTTP/2 request headers not validated (bsc#1265163) + CVE-2026-41284: Unbounded read in WebDAV LOCK and PROPFIND handling (bsc#1265162) * Catalina + Add: Enhance version.sh and version.bat to display APR, Tomcat Native, and OpenSSL version information (both APR and FFM implementations), along with version compatibility warnings and third-party library version information. (csutherl) + Code: Refactor generation of the remote user element in the access log to remove unnecessary code. (markt) + Fix: Fix a regression in the previous release that meant ?- could appear in the access log rather than ? when the query string was present but empty. (markt) + Fix: Failed precondition should make WebDAV DELETE fail. #982 submitted by Mahmoud Alarby. (remm) + Fix: Align the escaping in ExtendedAccessLogValve with the other AccessLogValve implementations. (markt) + Fix: 70000: fix duplication of special headers in the response after commit, following fix for 69967. (remm) + Fix: Correct the handling of URIs mapped to a security constraint that only specifies the special ** role for all authenticated users. Requests without authentication were receiving 403 responses rather than 401 responses. (markt) + Fix: Fix a race condition in StandardContext.getServletContext() that could cause the jakarta.servlet.context.tempdir attribute to be lost during a context reload. Make the context field volatile and use locking to ensure only one ApplicationContext instance is created. (dsoumis) + Fix: Update the Windows authentication (kerberos) documentation to reflect that both Java and Windows are removing / have removed support for RC4-HMAC. The guide now uses AES256-SHA1. (markt) + Fix: Add a new initialisation parameter for WebDAV, maxRequestBodySize which limits the size of a WebDAV request body for LOCK and PROPFIND. The default value is 4096 bytes. (markt) + Add: Add a new caseSensitive attribute to the LockOutRealm that controls the manner in which user names are treated when making locking decisions. The default is false, meaning user names are treated in a case insensitive manner. (markt) + Fix: Correct the handling of invalid users with DIGEST authentication. (markt) + Fix: Ensure RealmBase finds all matching extension based security constraints. (markt) * Coyote + Fix: Avoid various edge cases if Content-Length is set via setHeader(String,String) or addHeader(String,String) with an invalid value by always clearing the previous value whether the new value is valid or not and ignoring any invalid new value. (markt) + Code: Refactor the calculation of the real index in the HPACK dynamic header table implementation to reduce code duplication. (markt) + Fix: Fix various minor issues with some HTTP/2 stream error messages for HTTP/2. (markt) + Fix: Consistently reject URIs containing NULL bytes when normalizing. (markt) + Fix: Fix a few minor memory leaks on error paths reading TLS keys and certificates when using FFM. (markt) + Fix: Refactor clean-up after HTTP/2 headers have been processed to aid GC after a stream reset. (markt) + Fix: Align HTTP/2 trailer fields with HTTP/1.1 and filter out any fields not permitted in trailers. (markt) + Fix: Free private keys after use in FFM based connector configuration. (markt) + Fix: Correct an unlikely edge-case parsing bug in the HTTP/2 HPACK header decoding that could result in a valid header triggering an unexpected connection close. (markt) + Fix: Refactor HTTP/2 HPACK encoding so header field names are only converted to lower case once during the encoding process. (markt) + Fix: Refactor HTTP/2 header field validation so it occurs earlier. Extend validation to check for disallowed characters as well as upper case characters. (markt) + Fix: Add TLS 1.3 groups added in OpenSSL 4.0. (remm) + Fix: Add validation that the HTTP/2 :scheme pseudo-header is consistent with the use (or not) of TLS. (markt) + Fix: Correct the validation of pseudo headers and CONNECT requests to align Tomcat's behaviour with RFC 9113, section 8.5. (markt) + Fix: Fix a potential integer overflow when allocating capacity from a connection level window update to individual HTTP/2 streams. Based on #996 by Mike Tingey Jr. (markt) + Fix: Switch AJP secret comparison to a constant time algorithm. (markt) * WebSocket + Fix: Fix the initial connection to a WebSocket end point where the connection is made via a proxy that requires DIGEST authentication. (markt) * Other + Fix: 69993: Update the URL to the CDDL 1.0 license. (markt) + Add: Add warning when OpenSSL binary is not found. (csutherl) + Add: Add check for Tomcat Native library, and log warning when it's not found to make it easier to see when it's not used by the suite. (csutherl) + Update: Update Byte Buddy to 1.18.8. (markt) + Update: Update Bouncy Castle to 1.84. (markt) + Update: Improvements to French translations. (remm) + Update: Improvements to Japanese translations provided by tak7iji. (markt) ++++ vorbis-tools: - Fix buffer underflow in the `ogg123` utility in function `remotethread` of `remote.c` (CVE-2026-34253, bsc#1265361): 0001-Do-not-assume-fgets-result-is-non-empty.patch 0002-ogg123-Handle-EOF-error-in-remote-interface.patch ------------------------------------------------------------------ ------------------ 2026-5-27 - May 27 2026 ------------------- ------------------------------------------------------------------ ++++ bind: - Upgrade to release 9.20.23 https://downloads.isc.org/isc/bind9/9.20.23/doc/arm/html/notes.html Security-Fixes: * Amplification vulnerabilities via self-pointed glue records. (CVE-2026-3592) [bsc#1265592] * server memory exhaustion during GSS-API TKEY negotiation. (CVE-2026-3039) [bsc#1265591] * Unbounded resend loop in BIND 9 resolver (CVE-2026-5950) [bsc#1265596] * SIG(0) validation during query flood may lead to undefined behavior. (CVE-2026-5947) [bsc#1265595] * Invalid handling of CLASS != IN. (CVE-2026-5946) [bsc#1265594] * Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation (CVE-2026-3593) [bsc#1265593] ++++ chromium: - Chromium 148.0.7778.215 (boo#1266471): * CVE-2026-9872: Out of bounds write in GPU * CVE-2026-9873: Use after free in Network * CVE-2026-9874: Use after free in Dawn * CVE-2026-9875: Out of bounds read in WebGL * CVE-2026-9876: Use after free in WebGL * CVE-2026-9877: Use after free in ANGLE * CVE-2026-9878: Use after free in ANGLE * CVE-2026-9879: Out of bounds write in ANGLE * CVE-2026-9880: Insufficient validation of untrusted input in WebGL * CVE-2026-9881: Use after free in Bluetooth * CVE-2026-9882: Integer overflow in ANGLE * CVE-2026-9883: Use after free in Base * CVE-2026-9884: Use after free in Browser * CVE-2026-9885: Insufficient validation of untrusted input in UI * CVE-2026-9886: Use after free in Base * CVE-2026-9887: Use after free in Proxy * CVE-2026-9888: Use after free in WebView * CVE-2026-9889: Out of bounds read and write in Dawn * CVE-2026-9890: Use after free in XR * CVE-2026-9891: Use after free in Extensions * CVE-2026-9892: Inappropriate implementation in Skia * CVE-2026-9893: Use after free in Skia * CVE-2026-9894: Use after free in GPU * CVE-2026-9895: Out of bounds read in GPU * CVE-2026-9896: Out of bounds write in V8 * CVE-2026-9897: Use after free in DOM * CVE-2026-9898: Insufficient validation of untrusted input in GPU * CVE-2026-9899: Use after free in ANGLE * CVE-2026-9900: Out of bounds write in ANGLE * CVE-2026-9901: Use after free in ANGLE * CVE-2026-9902: Use after free in Accessibility * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation * CVE-2026-9904: Use after free in ANGLE * CVE-2026-9905: Use after free in Accessibility * CVE-2026-9906: Out of bounds write in GPU * CVE-2026-9907: Out of bounds read in Dawn * CVE-2026-9908: Out of bounds read in ANGLE * CVE-2026-9909: Integer overflow in Skia * CVE-2026-9910: Out of bounds memory access in ANGLE * CVE-2026-9911: Integer overflow in ANGLE * CVE-2026-9912: Inappropriate implementation in GPU * CVE-2026-9913: Inappropriate implementation in ANGLE * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE * CVE-2026-9915: Heap buffer overflow in ANGLE * CVE-2026-9916: Out of bounds write in ANGLE * CVE-2026-9917: Uninitialized Use in WebGL * CVE-2026-9918: Inappropriate implementation in Tint * CVE-2026-9919: Out of bounds read in WebGL * CVE-2026-9920: Uninitialized Use in GPU * CVE-2026-9921: Uninitialized Use in WebGL * CVE-2026-9922: Use after free in GPU * CVE-2026-9923: Use after free in Skia * CVE-2026-9924: Heap buffer overflow in ANGLE * CVE-2026-9925: Use after free in ANGLE * CVE-2026-9926: Heap buffer overflow in ANGLE * CVE-2026-9927: Use after free in ANGLE * CVE-2026-9928: Out of bounds read in ANGLE * CVE-2026-9929: Inappropriate implementation in WebGL * CVE-2026-9930: Out of bounds write in Dawn * CVE-2026-9931: Use after free in GPU * CVE-2026-9932: Use after free in ANGLE * CVE-2026-9933: Use after free in Input * CVE-2026-9934: Use after free in Aura * CVE-2026-9935: Uninitialized Use in ANGLE * CVE-2026-9936: Use after free in GFX * CVE-2026-9937: Use after free in UI * CVE-2026-9938: Inappropriate implementation in V8 * CVE-2026-9939: Heap buffer overflow in WebCodecs * CVE-2026-9940: Heap buffer overflow in ANGLE * CVE-2026-9941: Use after free in ANGLE * CVE-2026-9942: Uninitialized Use in ANGLE * CVE-2026-9943: Out of bounds read in WebGL * CVE-2026-9944: Uninitialized Use in ANGLE * CVE-2026-9945: Use after free in Media * CVE-2026-9946: Use after free in ANGLE * CVE-2026-9947: Use after free in XML * CVE-2026-9948: Use after free in Views * CVE-2026-9949: Use after free in Core * CVE-2026-9950: Insufficient validation of untrusted input in iOS * CVE-2026-9951: Use after free in UI * CVE-2026-9952: Use after free in WebAudio * CVE-2026-9953: Out of bounds read in ANGLE * CVE-2026-9954: Use after free in TabStrip * CVE-2026-9955: Inappropriate implementation in iOS * CVE-2026-9956: Use after free in iOS * CVE-2026-9957: Use after free in PDF * CVE-2026-9958: Use after free in PDFium * CVE-2026-9959: Race in WebRTC * CVE-2026-9960: Integer overflow in PDFium * CVE-2026-9961: Use after free in SurfaceCapture * CVE-2026-9962: Use after free in WebRTC * CVE-2026-9963: Uninitialized Use in iOS * CVE-2026-9964: Use after free in Bluetooth * CVE-2026-9965: Out of bounds write in ANGLE * CVE-2026-9966: Integer overflow in XML * CVE-2026-9967: Out of bounds write in GPU * CVE-2026-9968: Integer overflow in V8 * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE * CVE-2026-9970: Use after free in WebGL * CVE-2026-9971: Inappropriate implementation in iOS * CVE-2026-9972: Uninitialized Use in Gamepad * CVE-2026-9973: Out of bounds write in V8 * CVE-2026-9974: Out of bounds write in GPU * CVE-2026-9975: Out of bounds read and write in ANGLE * CVE-2026-9976: Inappropriate implementation in USB * CVE-2026-9977: Insufficient validation of untrusted input in WebShare * CVE-2026-9978: Use after free in Glic * CVE-2026-9979: Insufficient validation of untrusted input in Input * CVE-2026-9980: Insufficient validation of untrusted input in Printing * CVE-2026-9981: Inappropriate implementation in Skia * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE * CVE-2026-9983: Type Confusion in Skia * CVE-2026-9984: Use after free in UI * CVE-2026-9985: Insufficient validation of untrusted input in Media * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-9988: Use after free in WebRTC * CVE-2026-9989: Inappropriate implementation in Media * CVE-2026-9990: Use after free in WebAppInstalls * CVE-2026-9991: Inappropriate implementation in Media * CVE-2026-9992: Use after free in Network * CVE-2026-9993: Use after free in Views * CVE-2026-9994: Use after free in Core * CVE-2026-9995: Use after free in WebXR * CVE-2026-9996: Out of bounds read in WebRTC * CVE-2026-9997: Use after free in Input * CVE-2026-9998: Integer overflow in Skia * CVE-2026-9999: Inappropriate implementation in ANGLE * CVE-2026-10000: Use after free in Passwords * CVE-2026-10001: Use after free in PerformanceManager * CVE-2026-10002: Use after free in PDFium * CVE-2026-10003: Use after free in Views * CVE-2026-10004: Insufficient validation of untrusted input in Passwords * CVE-2026-10005: Use after free in WebAppInstalls * CVE-2026-10006: Race in WebAudio * CVE-2026-10007: Use after free in SVG * CVE-2026-10008: Uninitialized Use in GPU * CVE-2026-10009: Integer overflow in Skia * CVE-2026-10010: Inappropriate implementation in Input * CVE-2026-10011: Inappropriate implementation in Skia * CVE-2026-10012: Use after free in Skia * CVE-2026-10013: Use after free in WebCodecs * CVE-2026-10014: Use after free in WebMIDI * CVE-2026-10015: Integer overflow in WTF * CVE-2026-10016: Use after free in DOM * CVE-2026-10017: Out of bounds read in Headless * CVE-2026-10018: Integer overflow in ANGLE * CVE-2026-10019: Integer overflow in ANGLE * CVE-2026-10020: Insufficient validation of untrusted input in Skia * CVE-2026-10021: Insufficient validation of untrusted input in USB * CVE-2026-10022: Type Confusion in V8 ++++ chromium: - Chromium 148.0.7778.215 (boo#1266471): * CVE-2026-9872: Out of bounds write in GPU * CVE-2026-9873: Use after free in Network * CVE-2026-9874: Use after free in Dawn * CVE-2026-9875: Out of bounds read in WebGL * CVE-2026-9876: Use after free in WebGL * CVE-2026-9877: Use after free in ANGLE * CVE-2026-9878: Use after free in ANGLE * CVE-2026-9879: Out of bounds write in ANGLE * CVE-2026-9880: Insufficient validation of untrusted input in WebGL * CVE-2026-9881: Use after free in Bluetooth * CVE-2026-9882: Integer overflow in ANGLE * CVE-2026-9883: Use after free in Base * CVE-2026-9884: Use after free in Browser * CVE-2026-9885: Insufficient validation of untrusted input in UI * CVE-2026-9886: Use after free in Base * CVE-2026-9887: Use after free in Proxy * CVE-2026-9888: Use after free in WebView * CVE-2026-9889: Out of bounds read and write in Dawn * CVE-2026-9890: Use after free in XR * CVE-2026-9891: Use after free in Extensions * CVE-2026-9892: Inappropriate implementation in Skia * CVE-2026-9893: Use after free in Skia * CVE-2026-9894: Use after free in GPU * CVE-2026-9895: Out of bounds read in GPU * CVE-2026-9896: Out of bounds write in V8 * CVE-2026-9897: Use after free in DOM * CVE-2026-9898: Insufficient validation of untrusted input in GPU * CVE-2026-9899: Use after free in ANGLE * CVE-2026-9900: Out of bounds write in ANGLE * CVE-2026-9901: Use after free in ANGLE * CVE-2026-9902: Use after free in Accessibility * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation * CVE-2026-9904: Use after free in ANGLE * CVE-2026-9905: Use after free in Accessibility * CVE-2026-9906: Out of bounds write in GPU * CVE-2026-9907: Out of bounds read in Dawn * CVE-2026-9908: Out of bounds read in ANGLE * CVE-2026-9909: Integer overflow in Skia * CVE-2026-9910: Out of bounds memory access in ANGLE * CVE-2026-9911: Integer overflow in ANGLE * CVE-2026-9912: Inappropriate implementation in GPU * CVE-2026-9913: Inappropriate implementation in ANGLE * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE * CVE-2026-9915: Heap buffer overflow in ANGLE * CVE-2026-9916: Out of bounds write in ANGLE * CVE-2026-9917: Uninitialized Use in WebGL * CVE-2026-9918: Inappropriate implementation in Tint * CVE-2026-9919: Out of bounds read in WebGL * CVE-2026-9920: Uninitialized Use in GPU * CVE-2026-9921: Uninitialized Use in WebGL * CVE-2026-9922: Use after free in GPU * CVE-2026-9923: Use after free in Skia * CVE-2026-9924: Heap buffer overflow in ANGLE * CVE-2026-9925: Use after free in ANGLE * CVE-2026-9926: Heap buffer overflow in ANGLE * CVE-2026-9927: Use after free in ANGLE * CVE-2026-9928: Out of bounds read in ANGLE * CVE-2026-9929: Inappropriate implementation in WebGL * CVE-2026-9930: Out of bounds write in Dawn * CVE-2026-9931: Use after free in GPU * CVE-2026-9932: Use after free in ANGLE * CVE-2026-9933: Use after free in Input * CVE-2026-9934: Use after free in Aura * CVE-2026-9935: Uninitialized Use in ANGLE * CVE-2026-9936: Use after free in GFX * CVE-2026-9937: Use after free in UI * CVE-2026-9938: Inappropriate implementation in V8 * CVE-2026-9939: Heap buffer overflow in WebCodecs * CVE-2026-9940: Heap buffer overflow in ANGLE * CVE-2026-9941: Use after free in ANGLE * CVE-2026-9942: Uninitialized Use in ANGLE * CVE-2026-9943: Out of bounds read in WebGL * CVE-2026-9944: Uninitialized Use in ANGLE * CVE-2026-9945: Use after free in Media * CVE-2026-9946: Use after free in ANGLE * CVE-2026-9947: Use after free in XML * CVE-2026-9948: Use after free in Views * CVE-2026-9949: Use after free in Core * CVE-2026-9950: Insufficient validation of untrusted input in iOS * CVE-2026-9951: Use after free in UI * CVE-2026-9952: Use after free in WebAudio * CVE-2026-9953: Out of bounds read in ANGLE * CVE-2026-9954: Use after free in TabStrip * CVE-2026-9955: Inappropriate implementation in iOS * CVE-2026-9956: Use after free in iOS * CVE-2026-9957: Use after free in PDF * CVE-2026-9958: Use after free in PDFium * CVE-2026-9959: Race in WebRTC * CVE-2026-9960: Integer overflow in PDFium * CVE-2026-9961: Use after free in SurfaceCapture * CVE-2026-9962: Use after free in WebRTC * CVE-2026-9963: Uninitialized Use in iOS * CVE-2026-9964: Use after free in Bluetooth * CVE-2026-9965: Out of bounds write in ANGLE * CVE-2026-9966: Integer overflow in XML * CVE-2026-9967: Out of bounds write in GPU * CVE-2026-9968: Integer overflow in V8 * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE * CVE-2026-9970: Use after free in WebGL * CVE-2026-9971: Inappropriate implementation in iOS * CVE-2026-9972: Uninitialized Use in Gamepad * CVE-2026-9973: Out of bounds write in V8 * CVE-2026-9974: Out of bounds write in GPU * CVE-2026-9975: Out of bounds read and write in ANGLE * CVE-2026-9976: Inappropriate implementation in USB * CVE-2026-9977: Insufficient validation of untrusted input in WebShare * CVE-2026-9978: Use after free in Glic * CVE-2026-9979: Insufficient validation of untrusted input in Input * CVE-2026-9980: Insufficient validation of untrusted input in Printing * CVE-2026-9981: Inappropriate implementation in Skia * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE * CVE-2026-9983: Type Confusion in Skia * CVE-2026-9984: Use after free in UI * CVE-2026-9985: Insufficient validation of untrusted input in Media * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-9988: Use after free in WebRTC * CVE-2026-9989: Inappropriate implementation in Media * CVE-2026-9990: Use after free in WebAppInstalls * CVE-2026-9991: Inappropriate implementation in Media * CVE-2026-9992: Use after free in Network * CVE-2026-9993: Use after free in Views * CVE-2026-9994: Use after free in Core * CVE-2026-9995: Use after free in WebXR * CVE-2026-9996: Out of bounds read in WebRTC * CVE-2026-9997: Use after free in Input * CVE-2026-9998: Integer overflow in Skia * CVE-2026-9999: Inappropriate implementation in ANGLE * CVE-2026-10000: Use after free in Passwords * CVE-2026-10001: Use after free in PerformanceManager * CVE-2026-10002: Use after free in PDFium * CVE-2026-10003: Use after free in Views * CVE-2026-10004: Insufficient validation of untrusted input in Passwords * CVE-2026-10005: Use after free in WebAppInstalls * CVE-2026-10006: Race in WebAudio * CVE-2026-10007: Use after free in SVG * CVE-2026-10008: Uninitialized Use in GPU * CVE-2026-10009: Integer overflow in Skia * CVE-2026-10010: Inappropriate implementation in Input * CVE-2026-10011: Inappropriate implementation in Skia * CVE-2026-10012: Use after free in Skia * CVE-2026-10013: Use after free in WebCodecs * CVE-2026-10014: Use after free in WebMIDI * CVE-2026-10015: Integer overflow in WTF * CVE-2026-10016: Use after free in DOM * CVE-2026-10017: Out of bounds read in Headless * CVE-2026-10018: Integer overflow in ANGLE * CVE-2026-10019: Integer overflow in ANGLE * CVE-2026-10020: Insufficient validation of untrusted input in Skia * CVE-2026-10021: Insufficient validation of untrusted input in USB * CVE-2026-10022: Type Confusion in V8 ++++ chromium: - Chromium 148.0.7778.215 (boo#1266471): * CVE-2026-9872: Out of bounds write in GPU * CVE-2026-9873: Use after free in Network * CVE-2026-9874: Use after free in Dawn * CVE-2026-9875: Out of bounds read in WebGL * CVE-2026-9876: Use after free in WebGL * CVE-2026-9877: Use after free in ANGLE * CVE-2026-9878: Use after free in ANGLE * CVE-2026-9879: Out of bounds write in ANGLE * CVE-2026-9880: Insufficient validation of untrusted input in WebGL * CVE-2026-9881: Use after free in Bluetooth * CVE-2026-9882: Integer overflow in ANGLE * CVE-2026-9883: Use after free in Base * CVE-2026-9884: Use after free in Browser * CVE-2026-9885: Insufficient validation of untrusted input in UI * CVE-2026-9886: Use after free in Base * CVE-2026-9887: Use after free in Proxy * CVE-2026-9888: Use after free in WebView * CVE-2026-9889: Out of bounds read and write in Dawn * CVE-2026-9890: Use after free in XR * CVE-2026-9891: Use after free in Extensions * CVE-2026-9892: Inappropriate implementation in Skia * CVE-2026-9893: Use after free in Skia * CVE-2026-9894: Use after free in GPU * CVE-2026-9895: Out of bounds read in GPU * CVE-2026-9896: Out of bounds write in V8 * CVE-2026-9897: Use after free in DOM * CVE-2026-9898: Insufficient validation of untrusted input in GPU * CVE-2026-9899: Use after free in ANGLE * CVE-2026-9900: Out of bounds write in ANGLE * CVE-2026-9901: Use after free in ANGLE * CVE-2026-9902: Use after free in Accessibility * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation * CVE-2026-9904: Use after free in ANGLE * CVE-2026-9905: Use after free in Accessibility * CVE-2026-9906: Out of bounds write in GPU * CVE-2026-9907: Out of bounds read in Dawn * CVE-2026-9908: Out of bounds read in ANGLE * CVE-2026-9909: Integer overflow in Skia * CVE-2026-9910: Out of bounds memory access in ANGLE * CVE-2026-9911: Integer overflow in ANGLE * CVE-2026-9912: Inappropriate implementation in GPU * CVE-2026-9913: Inappropriate implementation in ANGLE * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE * CVE-2026-9915: Heap buffer overflow in ANGLE * CVE-2026-9916: Out of bounds write in ANGLE * CVE-2026-9917: Uninitialized Use in WebGL * CVE-2026-9918: Inappropriate implementation in Tint * CVE-2026-9919: Out of bounds read in WebGL * CVE-2026-9920: Uninitialized Use in GPU * CVE-2026-9921: Uninitialized Use in WebGL * CVE-2026-9922: Use after free in GPU * CVE-2026-9923: Use after free in Skia * CVE-2026-9924: Heap buffer overflow in ANGLE * CVE-2026-9925: Use after free in ANGLE * CVE-2026-9926: Heap buffer overflow in ANGLE * CVE-2026-9927: Use after free in ANGLE * CVE-2026-9928: Out of bounds read in ANGLE * CVE-2026-9929: Inappropriate implementation in WebGL * CVE-2026-9930: Out of bounds write in Dawn * CVE-2026-9931: Use after free in GPU * CVE-2026-9932: Use after free in ANGLE * CVE-2026-9933: Use after free in Input * CVE-2026-9934: Use after free in Aura * CVE-2026-9935: Uninitialized Use in ANGLE * CVE-2026-9936: Use after free in GFX * CVE-2026-9937: Use after free in UI * CVE-2026-9938: Inappropriate implementation in V8 * CVE-2026-9939: Heap buffer overflow in WebCodecs * CVE-2026-9940: Heap buffer overflow in ANGLE * CVE-2026-9941: Use after free in ANGLE * CVE-2026-9942: Uninitialized Use in ANGLE * CVE-2026-9943: Out of bounds read in WebGL * CVE-2026-9944: Uninitialized Use in ANGLE * CVE-2026-9945: Use after free in Media * CVE-2026-9946: Use after free in ANGLE * CVE-2026-9947: Use after free in XML * CVE-2026-9948: Use after free in Views * CVE-2026-9949: Use after free in Core * CVE-2026-9950: Insufficient validation of untrusted input in iOS * CVE-2026-9951: Use after free in UI * CVE-2026-9952: Use after free in WebAudio * CVE-2026-9953: Out of bounds read in ANGLE * CVE-2026-9954: Use after free in TabStrip * CVE-2026-9955: Inappropriate implementation in iOS * CVE-2026-9956: Use after free in iOS * CVE-2026-9957: Use after free in PDF * CVE-2026-9958: Use after free in PDFium * CVE-2026-9959: Race in WebRTC * CVE-2026-9960: Integer overflow in PDFium * CVE-2026-9961: Use after free in SurfaceCapture * CVE-2026-9962: Use after free in WebRTC * CVE-2026-9963: Uninitialized Use in iOS * CVE-2026-9964: Use after free in Bluetooth * CVE-2026-9965: Out of bounds write in ANGLE * CVE-2026-9966: Integer overflow in XML * CVE-2026-9967: Out of bounds write in GPU * CVE-2026-9968: Integer overflow in V8 * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE * CVE-2026-9970: Use after free in WebGL * CVE-2026-9971: Inappropriate implementation in iOS * CVE-2026-9972: Uninitialized Use in Gamepad * CVE-2026-9973: Out of bounds write in V8 * CVE-2026-9974: Out of bounds write in GPU * CVE-2026-9975: Out of bounds read and write in ANGLE * CVE-2026-9976: Inappropriate implementation in USB * CVE-2026-9977: Insufficient validation of untrusted input in WebShare * CVE-2026-9978: Use after free in Glic * CVE-2026-9979: Insufficient validation of untrusted input in Input * CVE-2026-9980: Insufficient validation of untrusted input in Printing * CVE-2026-9981: Inappropriate implementation in Skia * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE * CVE-2026-9983: Type Confusion in Skia * CVE-2026-9984: Use after free in UI * CVE-2026-9985: Insufficient validation of untrusted input in Media * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-9988: Use after free in WebRTC * CVE-2026-9989: Inappropriate implementation in Media * CVE-2026-9990: Use after free in WebAppInstalls * CVE-2026-9991: Inappropriate implementation in Media * CVE-2026-9992: Use after free in Network * CVE-2026-9993: Use after free in Views * CVE-2026-9994: Use after free in Core * CVE-2026-9995: Use after free in WebXR * CVE-2026-9996: Out of bounds read in WebRTC * CVE-2026-9997: Use after free in Input * CVE-2026-9998: Integer overflow in Skia * CVE-2026-9999: Inappropriate implementation in ANGLE * CVE-2026-10000: Use after free in Passwords * CVE-2026-10001: Use after free in PerformanceManager * CVE-2026-10002: Use after free in PDFium * CVE-2026-10003: Use after free in Views * CVE-2026-10004: Insufficient validation of untrusted input in Passwords * CVE-2026-10005: Use after free in WebAppInstalls * CVE-2026-10006: Race in WebAudio * CVE-2026-10007: Use after free in SVG * CVE-2026-10008: Uninitialized Use in GPU * CVE-2026-10009: Integer overflow in Skia * CVE-2026-10010: Inappropriate implementation in Input * CVE-2026-10011: Inappropriate implementation in Skia * CVE-2026-10012: Use after free in Skia * CVE-2026-10013: Use after free in WebCodecs * CVE-2026-10014: Use after free in WebMIDI * CVE-2026-10015: Integer overflow in WTF * CVE-2026-10016: Use after free in DOM * CVE-2026-10017: Out of bounds read in Headless * CVE-2026-10018: Integer overflow in ANGLE * CVE-2026-10019: Integer overflow in ANGLE * CVE-2026-10020: Insufficient validation of untrusted input in Skia * CVE-2026-10021: Insufficient validation of untrusted input in USB * CVE-2026-10022: Type Confusion in V8 ++++ chromium: - Chromium 148.0.7778.215 (boo#1266471): * CVE-2026-9872: Out of bounds write in GPU * CVE-2026-9873: Use after free in Network * CVE-2026-9874: Use after free in Dawn * CVE-2026-9875: Out of bounds read in WebGL * CVE-2026-9876: Use after free in WebGL * CVE-2026-9877: Use after free in ANGLE * CVE-2026-9878: Use after free in ANGLE * CVE-2026-9879: Out of bounds write in ANGLE * CVE-2026-9880: Insufficient validation of untrusted input in WebGL * CVE-2026-9881: Use after free in Bluetooth * CVE-2026-9882: Integer overflow in ANGLE * CVE-2026-9883: Use after free in Base * CVE-2026-9884: Use after free in Browser * CVE-2026-9885: Insufficient validation of untrusted input in UI * CVE-2026-9886: Use after free in Base * CVE-2026-9887: Use after free in Proxy * CVE-2026-9888: Use after free in WebView * CVE-2026-9889: Out of bounds read and write in Dawn * CVE-2026-9890: Use after free in XR * CVE-2026-9891: Use after free in Extensions * CVE-2026-9892: Inappropriate implementation in Skia * CVE-2026-9893: Use after free in Skia * CVE-2026-9894: Use after free in GPU * CVE-2026-9895: Out of bounds read in GPU * CVE-2026-9896: Out of bounds write in V8 * CVE-2026-9897: Use after free in DOM * CVE-2026-9898: Insufficient validation of untrusted input in GPU * CVE-2026-9899: Use after free in ANGLE * CVE-2026-9900: Out of bounds write in ANGLE * CVE-2026-9901: Use after free in ANGLE * CVE-2026-9902: Use after free in Accessibility * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation * CVE-2026-9904: Use after free in ANGLE * CVE-2026-9905: Use after free in Accessibility * CVE-2026-9906: Out of bounds write in GPU * CVE-2026-9907: Out of bounds read in Dawn * CVE-2026-9908: Out of bounds read in ANGLE * CVE-2026-9909: Integer overflow in Skia * CVE-2026-9910: Out of bounds memory access in ANGLE * CVE-2026-9911: Integer overflow in ANGLE * CVE-2026-9912: Inappropriate implementation in GPU * CVE-2026-9913: Inappropriate implementation in ANGLE * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE * CVE-2026-9915: Heap buffer overflow in ANGLE * CVE-2026-9916: Out of bounds write in ANGLE * CVE-2026-9917: Uninitialized Use in WebGL * CVE-2026-9918: Inappropriate implementation in Tint * CVE-2026-9919: Out of bounds read in WebGL * CVE-2026-9920: Uninitialized Use in GPU * CVE-2026-9921: Uninitialized Use in WebGL * CVE-2026-9922: Use after free in GPU * CVE-2026-9923: Use after free in Skia * CVE-2026-9924: Heap buffer overflow in ANGLE * CVE-2026-9925: Use after free in ANGLE * CVE-2026-9926: Heap buffer overflow in ANGLE * CVE-2026-9927: Use after free in ANGLE * CVE-2026-9928: Out of bounds read in ANGLE * CVE-2026-9929: Inappropriate implementation in WebGL * CVE-2026-9930: Out of bounds write in Dawn * CVE-2026-9931: Use after free in GPU * CVE-2026-9932: Use after free in ANGLE * CVE-2026-9933: Use after free in Input * CVE-2026-9934: Use after free in Aura * CVE-2026-9935: Uninitialized Use in ANGLE * CVE-2026-9936: Use after free in GFX * CVE-2026-9937: Use after free in UI * CVE-2026-9938: Inappropriate implementation in V8 * CVE-2026-9939: Heap buffer overflow in WebCodecs * CVE-2026-9940: Heap buffer overflow in ANGLE * CVE-2026-9941: Use after free in ANGLE * CVE-2026-9942: Uninitialized Use in ANGLE * CVE-2026-9943: Out of bounds read in WebGL * CVE-2026-9944: Uninitialized Use in ANGLE * CVE-2026-9945: Use after free in Media * CVE-2026-9946: Use after free in ANGLE * CVE-2026-9947: Use after free in XML * CVE-2026-9948: Use after free in Views * CVE-2026-9949: Use after free in Core * CVE-2026-9950: Insufficient validation of untrusted input in iOS * CVE-2026-9951: Use after free in UI * CVE-2026-9952: Use after free in WebAudio * CVE-2026-9953: Out of bounds read in ANGLE * CVE-2026-9954: Use after free in TabStrip * CVE-2026-9955: Inappropriate implementation in iOS * CVE-2026-9956: Use after free in iOS * CVE-2026-9957: Use after free in PDF * CVE-2026-9958: Use after free in PDFium * CVE-2026-9959: Race in WebRTC * CVE-2026-9960: Integer overflow in PDFium * CVE-2026-9961: Use after free in SurfaceCapture * CVE-2026-9962: Use after free in WebRTC * CVE-2026-9963: Uninitialized Use in iOS * CVE-2026-9964: Use after free in Bluetooth * CVE-2026-9965: Out of bounds write in ANGLE * CVE-2026-9966: Integer overflow in XML * CVE-2026-9967: Out of bounds write in GPU * CVE-2026-9968: Integer overflow in V8 * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE * CVE-2026-9970: Use after free in WebGL * CVE-2026-9971: Inappropriate implementation in iOS * CVE-2026-9972: Uninitialized Use in Gamepad * CVE-2026-9973: Out of bounds write in V8 * CVE-2026-9974: Out of bounds write in GPU * CVE-2026-9975: Out of bounds read and write in ANGLE * CVE-2026-9976: Inappropriate implementation in USB * CVE-2026-9977: Insufficient validation of untrusted input in WebShare * CVE-2026-9978: Use after free in Glic * CVE-2026-9979: Insufficient validation of untrusted input in Input * CVE-2026-9980: Insufficient validation of untrusted input in Printing * CVE-2026-9981: Inappropriate implementation in Skia * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE * CVE-2026-9983: Type Confusion in Skia * CVE-2026-9984: Use after free in UI * CVE-2026-9985: Insufficient validation of untrusted input in Media * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-9988: Use after free in WebRTC * CVE-2026-9989: Inappropriate implementation in Media * CVE-2026-9990: Use after free in WebAppInstalls * CVE-2026-9991: Inappropriate implementation in Media * CVE-2026-9992: Use after free in Network * CVE-2026-9993: Use after free in Views * CVE-2026-9994: Use after free in Core * CVE-2026-9995: Use after free in WebXR * CVE-2026-9996: Out of bounds read in WebRTC * CVE-2026-9997: Use after free in Input * CVE-2026-9998: Integer overflow in Skia * CVE-2026-9999: Inappropriate implementation in ANGLE * CVE-2026-10000: Use after free in Passwords * CVE-2026-10001: Use after free in PerformanceManager * CVE-2026-10002: Use after free in PDFium * CVE-2026-10003: Use after free in Views * CVE-2026-10004: Insufficient validation of untrusted input in Passwords * CVE-2026-10005: Use after free in WebAppInstalls * CVE-2026-10006: Race in WebAudio * CVE-2026-10007: Use after free in SVG * CVE-2026-10008: Uninitialized Use in GPU * CVE-2026-10009: Integer overflow in Skia * CVE-2026-10010: Inappropriate implementation in Input * CVE-2026-10011: Inappropriate implementation in Skia * CVE-2026-10012: Use after free in Skia * CVE-2026-10013: Use after free in WebCodecs * CVE-2026-10014: Use after free in WebMIDI * CVE-2026-10015: Integer overflow in WTF * CVE-2026-10016: Use after free in DOM * CVE-2026-10017: Out of bounds read in Headless * CVE-2026-10018: Integer overflow in ANGLE * CVE-2026-10019: Integer overflow in ANGLE * CVE-2026-10020: Insufficient validation of untrusted input in Skia * CVE-2026-10021: Insufficient validation of untrusted input in USB * CVE-2026-10022: Type Confusion in V8 ++++ chromium: - Chromium 148.0.7778.215 (boo#1266471): * CVE-2026-9872: Out of bounds write in GPU * CVE-2026-9873: Use after free in Network * CVE-2026-9874: Use after free in Dawn * CVE-2026-9875: Out of bounds read in WebGL * CVE-2026-9876: Use after free in WebGL * CVE-2026-9877: Use after free in ANGLE * CVE-2026-9878: Use after free in ANGLE * CVE-2026-9879: Out of bounds write in ANGLE * CVE-2026-9880: Insufficient validation of untrusted input in WebGL * CVE-2026-9881: Use after free in Bluetooth * CVE-2026-9882: Integer overflow in ANGLE * CVE-2026-9883: Use after free in Base * CVE-2026-9884: Use after free in Browser * CVE-2026-9885: Insufficient validation of untrusted input in UI * CVE-2026-9886: Use after free in Base * CVE-2026-9887: Use after free in Proxy * CVE-2026-9888: Use after free in WebView * CVE-2026-9889: Out of bounds read and write in Dawn * CVE-2026-9890: Use after free in XR * CVE-2026-9891: Use after free in Extensions * CVE-2026-9892: Inappropriate implementation in Skia * CVE-2026-9893: Use after free in Skia * CVE-2026-9894: Use after free in GPU * CVE-2026-9895: Out of bounds read in GPU * CVE-2026-9896: Out of bounds write in V8 * CVE-2026-9897: Use after free in DOM * CVE-2026-9898: Insufficient validation of untrusted input in GPU * CVE-2026-9899: Use after free in ANGLE * CVE-2026-9900: Out of bounds write in ANGLE * CVE-2026-9901: Use after free in ANGLE * CVE-2026-9902: Use after free in Accessibility * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation * CVE-2026-9904: Use after free in ANGLE * CVE-2026-9905: Use after free in Accessibility * CVE-2026-9906: Out of bounds write in GPU * CVE-2026-9907: Out of bounds read in Dawn * CVE-2026-9908: Out of bounds read in ANGLE * CVE-2026-9909: Integer overflow in Skia * CVE-2026-9910: Out of bounds memory access in ANGLE * CVE-2026-9911: Integer overflow in ANGLE * CVE-2026-9912: Inappropriate implementation in GPU * CVE-2026-9913: Inappropriate implementation in ANGLE * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE * CVE-2026-9915: Heap buffer overflow in ANGLE * CVE-2026-9916: Out of bounds write in ANGLE * CVE-2026-9917: Uninitialized Use in WebGL * CVE-2026-9918: Inappropriate implementation in Tint * CVE-2026-9919: Out of bounds read in WebGL * CVE-2026-9920: Uninitialized Use in GPU * CVE-2026-9921: Uninitialized Use in WebGL * CVE-2026-9922: Use after free in GPU * CVE-2026-9923: Use after free in Skia * CVE-2026-9924: Heap buffer overflow in ANGLE * CVE-2026-9925: Use after free in ANGLE * CVE-2026-9926: Heap buffer overflow in ANGLE * CVE-2026-9927: Use after free in ANGLE * CVE-2026-9928: Out of bounds read in ANGLE * CVE-2026-9929: Inappropriate implementation in WebGL * CVE-2026-9930: Out of bounds write in Dawn * CVE-2026-9931: Use after free in GPU * CVE-2026-9932: Use after free in ANGLE * CVE-2026-9933: Use after free in Input * CVE-2026-9934: Use after free in Aura * CVE-2026-9935: Uninitialized Use in ANGLE * CVE-2026-9936: Use after free in GFX * CVE-2026-9937: Use after free in UI * CVE-2026-9938: Inappropriate implementation in V8 * CVE-2026-9939: Heap buffer overflow in WebCodecs * CVE-2026-9940: Heap buffer overflow in ANGLE * CVE-2026-9941: Use after free in ANGLE * CVE-2026-9942: Uninitialized Use in ANGLE * CVE-2026-9943: Out of bounds read in WebGL * CVE-2026-9944: Uninitialized Use in ANGLE * CVE-2026-9945: Use after free in Media * CVE-2026-9946: Use after free in ANGLE * CVE-2026-9947: Use after free in XML * CVE-2026-9948: Use after free in Views * CVE-2026-9949: Use after free in Core * CVE-2026-9950: Insufficient validation of untrusted input in iOS * CVE-2026-9951: Use after free in UI * CVE-2026-9952: Use after free in WebAudio * CVE-2026-9953: Out of bounds read in ANGLE * CVE-2026-9954: Use after free in TabStrip * CVE-2026-9955: Inappropriate implementation in iOS * CVE-2026-9956: Use after free in iOS * CVE-2026-9957: Use after free in PDF * CVE-2026-9958: Use after free in PDFium * CVE-2026-9959: Race in WebRTC * CVE-2026-9960: Integer overflow in PDFium * CVE-2026-9961: Use after free in SurfaceCapture * CVE-2026-9962: Use after free in WebRTC * CVE-2026-9963: Uninitialized Use in iOS * CVE-2026-9964: Use after free in Bluetooth * CVE-2026-9965: Out of bounds write in ANGLE * CVE-2026-9966: Integer overflow in XML * CVE-2026-9967: Out of bounds write in GPU * CVE-2026-9968: Integer overflow in V8 * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE * CVE-2026-9970: Use after free in WebGL * CVE-2026-9971: Inappropriate implementation in iOS * CVE-2026-9972: Uninitialized Use in Gamepad * CVE-2026-9973: Out of bounds write in V8 * CVE-2026-9974: Out of bounds write in GPU * CVE-2026-9975: Out of bounds read and write in ANGLE * CVE-2026-9976: Inappropriate implementation in USB * CVE-2026-9977: Insufficient validation of untrusted input in WebShare * CVE-2026-9978: Use after free in Glic * CVE-2026-9979: Insufficient validation of untrusted input in Input * CVE-2026-9980: Insufficient validation of untrusted input in Printing * CVE-2026-9981: Inappropriate implementation in Skia * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE * CVE-2026-9983: Type Confusion in Skia * CVE-2026-9984: Use after free in UI * CVE-2026-9985: Insufficient validation of untrusted input in Media * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-9988: Use after free in WebRTC * CVE-2026-9989: Inappropriate implementation in Media * CVE-2026-9990: Use after free in WebAppInstalls * CVE-2026-9991: Inappropriate implementation in Media * CVE-2026-9992: Use after free in Network * CVE-2026-9993: Use after free in Views * CVE-2026-9994: Use after free in Core * CVE-2026-9995: Use after free in WebXR * CVE-2026-9996: Out of bounds read in WebRTC * CVE-2026-9997: Use after free in Input * CVE-2026-9998: Integer overflow in Skia * CVE-2026-9999: Inappropriate implementation in ANGLE * CVE-2026-10000: Use after free in Passwords * CVE-2026-10001: Use after free in PerformanceManager * CVE-2026-10002: Use after free in PDFium * CVE-2026-10003: Use after free in Views * CVE-2026-10004: Insufficient validation of untrusted input in Passwords * CVE-2026-10005: Use after free in WebAppInstalls * CVE-2026-10006: Race in WebAudio * CVE-2026-10007: Use after free in SVG * CVE-2026-10008: Uninitialized Use in GPU * CVE-2026-10009: Integer overflow in Skia * CVE-2026-10010: Inappropriate implementation in Input * CVE-2026-10011: Inappropriate implementation in Skia * CVE-2026-10012: Use after free in Skia * CVE-2026-10013: Use after free in WebCodecs * CVE-2026-10014: Use after free in WebMIDI * CVE-2026-10015: Integer overflow in WTF * CVE-2026-10016: Use after free in DOM * CVE-2026-10017: Out of bounds read in Headless * CVE-2026-10018: Integer overflow in ANGLE * CVE-2026-10019: Integer overflow in ANGLE * CVE-2026-10020: Insufficient validation of untrusted input in Skia * CVE-2026-10021: Insufficient validation of untrusted input in USB * CVE-2026-10022: Type Confusion in V8 ++++ chromium: - Chromium 148.0.7778.215 (boo#1266471): * CVE-2026-9872: Out of bounds write in GPU * CVE-2026-9873: Use after free in Network * CVE-2026-9874: Use after free in Dawn * CVE-2026-9875: Out of bounds read in WebGL * CVE-2026-9876: Use after free in WebGL * CVE-2026-9877: Use after free in ANGLE * CVE-2026-9878: Use after free in ANGLE * CVE-2026-9879: Out of bounds write in ANGLE * CVE-2026-9880: Insufficient validation of untrusted input in WebGL * CVE-2026-9881: Use after free in Bluetooth * CVE-2026-9882: Integer overflow in ANGLE * CVE-2026-9883: Use after free in Base * CVE-2026-9884: Use after free in Browser * CVE-2026-9885: Insufficient validation of untrusted input in UI * CVE-2026-9886: Use after free in Base * CVE-2026-9887: Use after free in Proxy * CVE-2026-9888: Use after free in WebView * CVE-2026-9889: Out of bounds read and write in Dawn * CVE-2026-9890: Use after free in XR * CVE-2026-9891: Use after free in Extensions * CVE-2026-9892: Inappropriate implementation in Skia * CVE-2026-9893: Use after free in Skia * CVE-2026-9894: Use after free in GPU * CVE-2026-9895: Out of bounds read in GPU * CVE-2026-9896: Out of bounds write in V8 * CVE-2026-9897: Use after free in DOM * CVE-2026-9898: Insufficient validation of untrusted input in GPU * CVE-2026-9899: Use after free in ANGLE * CVE-2026-9900: Out of bounds write in ANGLE * CVE-2026-9901: Use after free in ANGLE * CVE-2026-9902: Use after free in Accessibility * CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation * CVE-2026-9904: Use after free in ANGLE * CVE-2026-9905: Use after free in Accessibility * CVE-2026-9906: Out of bounds write in GPU * CVE-2026-9907: Out of bounds read in Dawn * CVE-2026-9908: Out of bounds read in ANGLE * CVE-2026-9909: Integer overflow in Skia * CVE-2026-9910: Out of bounds memory access in ANGLE * CVE-2026-9911: Integer overflow in ANGLE * CVE-2026-9912: Inappropriate implementation in GPU * CVE-2026-9913: Inappropriate implementation in ANGLE * CVE-2026-9914: Insufficient validation of untrusted input in ANGLE * CVE-2026-9915: Heap buffer overflow in ANGLE * CVE-2026-9916: Out of bounds write in ANGLE * CVE-2026-9917: Uninitialized Use in WebGL * CVE-2026-9918: Inappropriate implementation in Tint * CVE-2026-9919: Out of bounds read in WebGL * CVE-2026-9920: Uninitialized Use in GPU * CVE-2026-9921: Uninitialized Use in WebGL * CVE-2026-9922: Use after free in GPU * CVE-2026-9923: Use after free in Skia * CVE-2026-9924: Heap buffer overflow in ANGLE * CVE-2026-9925: Use after free in ANGLE * CVE-2026-9926: Heap buffer overflow in ANGLE * CVE-2026-9927: Use after free in ANGLE * CVE-2026-9928: Out of bounds read in ANGLE * CVE-2026-9929: Inappropriate implementation in WebGL * CVE-2026-9930: Out of bounds write in Dawn * CVE-2026-9931: Use after free in GPU * CVE-2026-9932: Use after free in ANGLE * CVE-2026-9933: Use after free in Input * CVE-2026-9934: Use after free in Aura * CVE-2026-9935: Uninitialized Use in ANGLE * CVE-2026-9936: Use after free in GFX * CVE-2026-9937: Use after free in UI * CVE-2026-9938: Inappropriate implementation in V8 * CVE-2026-9939: Heap buffer overflow in WebCodecs * CVE-2026-9940: Heap buffer overflow in ANGLE * CVE-2026-9941: Use after free in ANGLE * CVE-2026-9942: Uninitialized Use in ANGLE * CVE-2026-9943: Out of bounds read in WebGL * CVE-2026-9944: Uninitialized Use in ANGLE * CVE-2026-9945: Use after free in Media * CVE-2026-9946: Use after free in ANGLE * CVE-2026-9947: Use after free in XML * CVE-2026-9948: Use after free in Views * CVE-2026-9949: Use after free in Core * CVE-2026-9950: Insufficient validation of untrusted input in iOS * CVE-2026-9951: Use after free in UI * CVE-2026-9952: Use after free in WebAudio * CVE-2026-9953: Out of bounds read in ANGLE * CVE-2026-9954: Use after free in TabStrip * CVE-2026-9955: Inappropriate implementation in iOS * CVE-2026-9956: Use after free in iOS * CVE-2026-9957: Use after free in PDF * CVE-2026-9958: Use after free in PDFium * CVE-2026-9959: Race in WebRTC * CVE-2026-9960: Integer overflow in PDFium * CVE-2026-9961: Use after free in SurfaceCapture * CVE-2026-9962: Use after free in WebRTC * CVE-2026-9963: Uninitialized Use in iOS * CVE-2026-9964: Use after free in Bluetooth * CVE-2026-9965: Out of bounds write in ANGLE * CVE-2026-9966: Integer overflow in XML * CVE-2026-9967: Out of bounds write in GPU * CVE-2026-9968: Integer overflow in V8 * CVE-2026-9969: Insufficient validation of untrusted input in ANGLE * CVE-2026-9970: Use after free in WebGL * CVE-2026-9971: Inappropriate implementation in iOS * CVE-2026-9972: Uninitialized Use in Gamepad * CVE-2026-9973: Out of bounds write in V8 * CVE-2026-9974: Out of bounds write in GPU * CVE-2026-9975: Out of bounds read and write in ANGLE * CVE-2026-9976: Inappropriate implementation in USB * CVE-2026-9977: Insufficient validation of untrusted input in WebShare * CVE-2026-9978: Use after free in Glic * CVE-2026-9979: Insufficient validation of untrusted input in Input * CVE-2026-9980: Insufficient validation of untrusted input in Printing * CVE-2026-9981: Inappropriate implementation in Skia * CVE-2026-9982: Insufficient validation of untrusted input in ANGLE * CVE-2026-9983: Type Confusion in Skia * CVE-2026-9984: Use after free in UI * CVE-2026-9985: Insufficient validation of untrusted input in Media * CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide * CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls * CVE-2026-9988: Use after free in WebRTC * CVE-2026-9989: Inappropriate implementation in Media * CVE-2026-9990: Use after free in WebAppInstalls * CVE-2026-9991: Inappropriate implementation in Media * CVE-2026-9992: Use after free in Network * CVE-2026-9993: Use after free in Views * CVE-2026-9994: Use after free in Core * CVE-2026-9995: Use after free in WebXR * CVE-2026-9996: Out of bounds read in WebRTC * CVE-2026-9997: Use after free in Input * CVE-2026-9998: Integer overflow in Skia * CVE-2026-9999: Inappropriate implementation in ANGLE * CVE-2026-10000: Use after free in Passwords * CVE-2026-10001: Use after free in PerformanceManager * CVE-2026-10002: Use after free in PDFium * CVE-2026-10003: Use after free in Views * CVE-2026-10004: Insufficient validation of untrusted input in Passwords * CVE-2026-10005: Use after free in WebAppInstalls * CVE-2026-10006: Race in WebAudio * CVE-2026-10007: Use after free in SVG * CVE-2026-10008: Uninitialized Use in GPU * CVE-2026-10009: Integer overflow in Skia * CVE-2026-10010: Inappropriate implementation in Input * CVE-2026-10011: Inappropriate implementation in Skia * CVE-2026-10012: Use after free in Skia * CVE-2026-10013: Use after free in WebCodecs * CVE-2026-10014: Use after free in WebMIDI * CVE-2026-10015: Integer overflow in WTF * CVE-2026-10016: Use after free in DOM * CVE-2026-10017: Out of bounds read in Headless * CVE-2026-10018: Integer overflow in ANGLE * CVE-2026-10019: Integer overflow in ANGLE * CVE-2026-10020: Insufficient validation of untrusted input in Skia * CVE-2026-10021: Insufficient validation of untrusted input in USB * CVE-2026-10022: Type Confusion in V8 ++++ kernel-64kb: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-64kb: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-azure: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-azure: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-default: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-default: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-rt: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-rt: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ domtrip: - Initial packaging with version 1.5.1 ++++ dtb-aarch64: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ dtb-aarch64: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ evince: - Update to version 48.2 (bsc#1265880 CVE-2026-46529): + shell: Quote strings in arguments used when calling ev_spawn - Add evince-revert-djvulibre-version-bump.patch: allow building with djvulibre 3.5.28. ++++ girara: - Update to version 2026.02.04: * Fix installation of headers - Added girara.keyring - Updates from version 2026.02.03: * SONAME bump: libgirara-gtk3-5 -> libgirara5 * Move Gtk+-specific parts to zathura - Updates from version 2026.01.30: * SONAME bump: libgirara-gtk3-4 -> libgirara-gtk3-5 * Remove viewport and replace GtkScrolledWindow in view with GtkStack * Display shortcut info if no function is passed * Remove unused functions * Various fixes and improvements - Updates from version 0.4.5: * Swith to glib-based testing framework * Various fixes and improvements ++++ hauler: - update x/net to v0.55.0 (bsc#1266602, CVE-2026-39821) ++++ hauler: - update x/net to v0.55.0 (bsc#1266602, CVE-2026-39821, bsc#1267150, CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506) ++++ helm: - update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ++++ helm: - update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ++++ helm: - update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ++++ kernel-source: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-source: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-docs: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-docs: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-kvmsmall: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-kvmsmall: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-obs-build: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-obs-build: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-obs-qa: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-obs-qa: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-syms: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-syms: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-zfcpdump: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ kernel-zfcpdump: - fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437 CVE-2026-43112). - commit 7f5ff04 - bcache: fix cached_dev.sb_bio use-after-free and crash (CVE-2026-3150 bsc#1263169). - scsi: target: tcm_loop: Drain commands in target_reset handler (CVE-2026-43054 bsc#1264063). - scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (CVE-2026-31464 bsc#1262656). - scsi: qla2xxx: Completely fix fcport double free (CVE-2026-43414 bsc#1264669). - commit c9145a1 - smb: client: fix OOB reads parsing symlink error response (bsc#1263769 CVE-2026-31613). - commit 3ab8543 - smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774 CVE-2026-31614). - commit e5f975e - smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989 CVE-2026-43362). - commit 13921d6 - usb: typec: ucsi: skip connector validation before init (CVE-2026-31729 bsc#1264112). - commit aa7142a - rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001 CVE-2026-43499). - commit 0d559b9 - tracing: Fix WARN_ON in tracing_buffers_mmap_close (CVE-2026-23380 bsc#1260539). - commit 91dbd7b - module: Fix kernel panic when a symbol st_shndx is out of bounds (CVE-2026-31521 bsc#1263102). - commit bd11f0e - s390/mm: Add missing secure storage access fixups for donated memory (CVE-2026-31568,bsc#1263068). - commit da1caad - s390/pfault: Fix virtual vs physical address confusion (bsc#1262754). - commit 0e7ec9a - cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path (bsc#1264832 CVE-2026-43328). - commit eaaf9be - mm/userfaultfd: fix hugetlb fault mutex hash calculation (CVE-2026-31575 bsc#1263067). - commit 6137b29 - RDMA/efa: Fix possible deadlock (git-fixes) - commit 1696c14 - RDMA/efa: Fix use of completion ctx after free (CVE-2026-31493 bsc#1262668) - commit 533c918 - RDMA/efa: Improve admin completion context state machine (git-fixes) - commit d54fb87 - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes) - commit 04f0f27 - RDMA/efa: Extend admin timeout error print (git-fixes) - commit 7f61f89 - usb: typec: ucsi: validate connector number in ucsi_notify_common() (CVE-2026-31729 bsc#1264112). - commit fd2e020 ++++ libsoup2: - Add libsoup2-CVE-2026-1801.patch: Use CRLF as line boundary when parsing chunk encoding data (bsc#1257649 CVE-2026-1801 glgo#GNOME/libsoup#481). ++++ libsoup: - Add libsoup-CVE-2026-4271.patch: Protect message io while reading and writing (bsc#1259767, CVE-2026-4271, glgo#GNOME/libsoup#496). ++++ libyang: - added patches CVE-2026-44673: integer overflow in `lyb_read_string()` of `src/parser_lyb.c` leads to heap buffer overflow when parsing a maliciously crafted LYB binary blob [bsc#1265330] * libyang-CVE-2026-44673.patch - added patches CVE-2026-41401: use-after-free in `lyd_parser_set_data_flags` when processing crafted YANG XML documents with specific metadata attributes [bsc#1266316] * libyang-CVE-2026-41401.patch ++++ libzypp: - Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded. - zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5). - version 17.38.10 (35) ++++ nginx: - Add CVE-2026-9256.patch: Fixes heap buffer overflow via overlapping captures in ngx_http_rewrite_module that could lead to arbitrary code execution (bsc#1266215) ++++ osc: - 1.27.0 - Command-line: - Change 'osc fork' to work through a local checkout that need to be reviewed and pushed by a user - Change 'git-obs pr create' to use '--source' and '--target' options instead of separate options for owner, repo, and branch - Change 'osc rmkpac' to require fragment with branch name in --scmsync url - Add 'git-obs pr new-package-request' command - Add '--allow-maintainer-edit' option to 'git-obs pr create' and enable it by default - Add '--linkrev' option to 'osc co' command, now we can run 'osc co prj/pac --linkrev=base to get to the exact sources for a revision - Add link revision to the 'osc info' output for a package - Add 'git-obs file maintainership migrate' command - Make 'osc up --expand-link' a no-op on non-linked packages - Suggest running 'git push' in 'git-obs pr create' when the local checkout differs from the server - Avoid making shallow clones in 'git-obs staging' commands, they cannot be pushed to different remotes - Fix 'git-obs pr create' to allow creating pull requests between repos in the same fork tree - Fix 'git-obs staging remove' to push changes to the correct remote matching with the PR head - Fix 'git-obs pr create' when creating a PR in a repo with no parent - Fix 'git-obs staging group' by fetching the whole branch instead of --depth=1 - Fix crash in 'git-obs pr dump' by adding '-c core.commitGraph=false' to 'git clone --dissociate' - Fix crash in 'osc buildlog' when repo and arch are not specified - Fix crash in 'git-obs pr dump' when timeline contains a null entry - Fix crash when running 'osc meta pkg' in a project checkout - Clarify error message in 'git-obs pr dump' by providing submodule name - Remove a misleading error message when a package doesn't exist during 'osc rq show --diff' - Library: - Introduce branch_id: add Branch.parse_id(), add GitObsCommand.add_argument_owner_repo_branch() - Improve gitea_api.Git to properly detect bare git repos - Add gitea_api.PullRequest.merged_at property - Add gitea_api.Git.ls_tree() method - Add gitea_api.Git methods for working with githooks - Add Manifest.get_package_paths_bare_git() that can resolve existing packages in a project in bare git repo - Add 'exclude_none' option to skip dictionary entries without a value to BaseModel.dict() - Change BaseModel.to_string() to take optional arguments: exclude_none, sort_keys, indent - Improve LocalGitStore to handle bare git repos and also specified git refs - Enable querying bare git repos and specified refs in gitea_api.Git.get_submodules() - Use the correct exception class for 404 in gitea_api.Branch.get() - Fix creating 'parent' and 'fork' remotes in Repo.clone() - Fix FutureWarning caused by calling urllib3 HTTPSConnection.set_cert() in v2+ - Accept extra kwargs in OscArgumentParser._get_formatter for Python 3.15 argparse change - Fix Repo.get_label_ids() to use pagination to retrieve all results - Fix Repo.clone_or_update() by passing 'branch' argument to the underlying clone() - Fix comparison operators in gitea_api.Repo - Fix crash in Package.info() when working with a git package, raise an exception as expected - Fix @ignore_http_errors decorator by properly handling HTTPError exception - Change 'Repo.clone()' to use existing GIT_SSH_COMMAND env if provided, only append new args. - Do case insensitive PR ID match in PullRequest.remove_pr_references() ++++ patterns-base: - make kernel_livepatching pattern visible (bsc#1263084) ++++ python-apache-libcloud: - Fix tests compatibility with latest Python 3.13 (bsc#1258223, bsc#1261918) - Added: * fix-tests-python313.patch ++++ python-pytest-html: - CVE-2026-9277: shell-quote: improper escaping of newlines (bsc#1266254) Update the vendored shell-quote to 1.8.4 node_modules ++++ python-pytest-html: - CVE-2026-9277: shell-quote: improper escaping of newlines (bsc#1266254) Update the vendored shell-quote to 1.8.4 node_modules ++++ trivy: - update x/net to v0.55.0 ( bsc#1266495, CVE-2026-39821 bsc#1267047, CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506) ++++ trivy: - update x/net to v0.55.0 ( bsc#1266495, CVE-2026-39821 bsc#1267047, CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506) ++++ trivy: - update x/net to v0.55.0 ( bsc#1266495, CVE-2026-39821 bsc#1267047, CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506) ++++ wicked: - Update to version 0.6.79 - Fix an indirect remote shell command injection via unsanitized dhcp strings and leaseinfo dump (bsc#1265221,CVE-2026-44932): - Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before. - Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833. - Discard string values containing single-quotes in other options. - Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78. ++++ xorg-x11-server: - bsc1266294_CVE-2026-XXXX1_0007-dix-increase-XLFDMAXFONTNAMELEN-to-match-libXfont2-s.patch * Font Alias Stack-based Buffer Overflow (ZDI-CAN-30136, bsc#1266294) - bsc1266295_CVE-2026-XXXX2_0001-sync-fix-deletion-of-counters-and-fences.patch * XSYNC Use-After-Free in miSyncDestroyFence() (ZDI-CAN-30159, ZDI-CAN-30163, bsc#1266295, bsc#1266298) - bsc1266296_CVE-2026-XXXX3_0003-xkb-reject-key-types-with-num_levels-exceeding-XkbMa.patch * XKB Key Types Stack-based Buffer Overflow (ZDI-CAN-30160, bsc#1266296) - bsc1266297_CVE-2026-XXXX4_0004-xkb-clamp-nMaps-to-mapWidths-buffer-size-in-CheckKey.patch * XKB SetMap Request Stack-based Buffer Overflow (ZDI-CAN-30161, bsc#1266297) - bsc1266299_CVE-2026-XXXX6_0002-sync-restart-trigger-list-iteration-in-SyncChangeCou.patch * XSYNC Use-After-Free in SyncChangeCounter() (ZDI-CAN-30164, bsc#1266299) - bsc1266300_CVE-2026-XXXX7_0005-glx-fix-reversed-length-check-in-ChangeDrawableAttri.patch * GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write (ZDI-CAN-30165, bsc#1266300) - bsc1266301_CVE-2026-XXXX8_0006-saver-re-fetch-screen-private-after-CheckScreenPriva.patch * CreateSaverWindow Use-After-Free Information Disclosure (ZDI-CAN-30168, bsc#1266301) - bsc1266302_CVE-2026-XXXX9_0001-dri2-Use-booleans-for-fake-front-buffer-tracking-in-.patch bsc1266302_CVE-2026-XXXX9_0002-dri2-Deduplicate-attachments-in-do_get_buffer.patch * DRI2 DRIGetBuffers/DRIGetBuffersWithFormat Out-Of-Bounds Write (CVE-2026-XXXX9, bsc#1266302) ++++ xorg-x11-server: - bsc1266294_CVE-2026-XXXX1_0007-dix-increase-XLFDMAXFONTNAMELEN-to-match-libXfont2-s.patch * Font Alias Stack-based Buffer Overflow (ZDI-CAN-30136, bsc#1266294) - bsc1266295_CVE-2026-XXXX2_0001-sync-fix-deletion-of-counters-and-fences.patch * XSYNC Use-After-Free in miSyncDestroyFence() (ZDI-CAN-30159, ZDI-CAN-30163, bsc#1266295, bsc#1266298) - bsc1266296_CVE-2026-XXXX3_0003-xkb-reject-key-types-with-num_levels-exceeding-XkbMa.patch * XKB Key Types Stack-based Buffer Overflow (ZDI-CAN-30160, bsc#1266296) - bsc1266297_CVE-2026-XXXX4_0004-xkb-clamp-nMaps-to-mapWidths-buffer-size-in-CheckKey.patch * XKB SetMap Request Stack-based Buffer Overflow (ZDI-CAN-30161, bsc#1266297) - bsc1266299_CVE-2026-XXXX6_0002-sync-restart-trigger-list-iteration-in-SyncChangeCou.patch * XSYNC Use-After-Free in SyncChangeCounter() (ZDI-CAN-30164, bsc#1266299) - bsc1266300_CVE-2026-XXXX7_0005-glx-fix-reversed-length-check-in-ChangeDrawableAttri.patch * GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write (ZDI-CAN-30165, bsc#1266300) - bsc1266301_CVE-2026-XXXX8_0006-saver-re-fetch-screen-private-after-CheckScreenPriva.patch * CreateSaverWindow Use-After-Free Information Disclosure (ZDI-CAN-30168, bsc#1266301) - bsc1266302_CVE-2026-XXXX9_0001-dri2-Use-booleans-for-fake-front-buffer-tracking-in-.patch bsc1266302_CVE-2026-XXXX9_0002-dri2-Deduplicate-attachments-in-do_get_buffer.patch * DRI2 DRIGetBuffers/DRIGetBuffersWithFormat Out-Of-Bounds Write (CVE-2026-XXXX9, bsc#1266302) ++++ xwayland: - bsc1266294_CVE-2026-XXXX1_0007-dix-increase-XLFDMAXFONTNAMELEN-to-match-libXfont2-s.patch * Font Alias Stack-based Buffer Overflow (ZDI-CAN-30136, bsc#1266294) - bsc1266295_CVE-2026-XXXX2_0001-sync-fix-deletion-of-counters-and-fences.patch * XSYNC Use-After-Free in miSyncDestroyFence() (ZDI-CAN-30159, ZDI-CAN-30163, bsc#1266295, bsc#1266298) - bsc1266296_CVE-2026-XXXX3_0003-xkb-reject-key-types-with-num_levels-exceeding-XkbMa.patch * XKB Key Types Stack-based Buffer Overflow (ZDI-CAN-30160, bsc#1266296) - bsc1266297_CVE-2026-XXXX4_0004-xkb-clamp-nMaps-to-mapWidths-buffer-size-in-CheckKey.patch * XKB SetMap Request Stack-based Buffer Overflow (ZDI-CAN-30161, bsc#1266297) - bsc1266299_CVE-2026-XXXX6_0002-sync-restart-trigger-list-iteration-in-SyncChangeCou.patch * XSYNC Use-After-Free in SyncChangeCounter() (ZDI-CAN-30164, bsc#1266299) - bsc1266300_CVE-2026-XXXX7_0005-glx-fix-reversed-length-check-in-ChangeDrawableAttri.patch * GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write (ZDI-CAN-30165, bsc#1266300) - bsc1266301_CVE-2026-XXXX8_0006-saver-re-fetch-screen-private-after-CheckScreenPriva.patch * CreateSaverWindow Use-After-Free Information Disclosure (ZDI-CAN-30168, bsc#1266301) ------------------------------------------------------------------ ------------------ 2026-5-26 - May 26 2026 ------------------- ------------------------------------------------------------------ ++++ Leap-release: - Removed %sle_version from the macros.lep (bsc#1238724) - Added %is_opensuse to the macros.lep ++++ MozillaThunderbird: - Mozilla Thunderbird 140.11.1 ESR * There are no Thunderbird changes requiring release notes in this release ++++ kernel-64kb: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-64kb: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-azure: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-azure: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-default: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-default: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-rt: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-rt: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ dtb-aarch64: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ dtb-aarch64: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ libheif: - version update to 1.22.2: * build issues with OpenJPEG plugin (#1813) * non-plain C in header (#1812) * CVE-2026-49271 (GHSA-r7qj-cg5r-r6vf) - Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder * CVE TBD (GHSA-5hqq-636x-r3cr) - Out-of-bounds write in inline mask region API when source mask exceeds declared region - deleted patches * libheif-fix-tests-no-HEVC.patch (upstreamed) - fixes [bsc#1266281] [bsc#1266282] CVE-2026-49271 ++++ google-cloud-sap-agent: - Update to version 3.14 (bsc#1265991) * Update Daemon Restart method to pass the correct cancel function to the new handler. * Remove redundant error logging in HANA disk restore. * Fetch and rename Logical Volume during HANA disk restore. * Add usage metrics for CMEK disk restore. * Add multi-region and global KMS keys location checks. * Convert HANA SID to uppercase in hanadiskbackup and hanadiskrestore. * Log warning instead of erroring out on KMS key get failure. * Initialize GCE client in status onetime command. * Validate presence of KMS key in hanadiskrestore. * Add SID parameter to HANA backup/restore path functions. * Add KMS key location validation for HANA disk restore. * Update agent version to 3.14. * Fixes an issue if there is a whitespace around an argument passed in * Add validation to prevent using both CSEK and KMS keys in hanadiskrestore. * Handle disk recreation in HANA disk restore when IOPS, throughput, size, or KMS key are specified. * Refactor disk restore and configuration logic. * Add support for CMEK encryption of restored disks. * Remove obsolete TODOs. ++++ himmelblau: - Update to version 2.3.11+git1.116c6763: * cargo audit * Version 2.3.11 * Update cargo vet audits for backport * Reject auth when token spn local part differs from requested account_id; (CVE-2026-45108), (bsc#1266662). * Update libhimmelblau to latest version * deps(rust): bump the all-cargo-updates group with 19 updates * cargo vet * Version 2.3.10 * nss/pam: bail out early when SYSTEMD_ACTIVATION_UNIT points to himmelblau * selinux: allow unconfined_service_t to search himmelblaud_t dirs * Remove 0001-selinux-allow-unconfined_service_t-to-search-himmelb.patch (fixed upstream). ++++ kernel-source: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-source: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-docs: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-docs: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-kvmsmall: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-kvmsmall: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-obs-build: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-obs-build: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-obs-qa: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-obs-qa: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-syms: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-syms: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-zfcpdump: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ kernel-zfcpdump: - smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - commit 997890a - iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603 CVE-2023-20585). - commit ccaf2dd - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (lenovo-ec-sensors): Fix EC "MCHP" signature validation logic (git-fixes). - hwmon: (lenovo-ec-sensors): Convert to devm_request_region() (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/surface: aggregator_registry: omit battery & AC nodes on Surface Laptop 7 (git-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: qup: fix error pointer deref after DMA setup failure (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: ep93xx: fix error pointer deref after DMA setup failure (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix MLE defragmentation (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes). - firmware: arm_ffa: Fix per-vcpu self notifications handling in workqueue (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - media: i2c: og01a1b: Fix V4L2 subdevice data initialization on probe (git-fixes). - media: i2c: og01a1b: Replace client->dev usage (stable-fixes). - commit b7519f6 - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - commit f8d8f84 - drm/amdgpu: fix spelling typos (stable-fixes). - commit 5152bc7 - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - Refresh patches.suse/drm-amdgpu-mes11-implement-detect-and-reset-callback.patch. - Refresh patches.suse/drm-amdgpu-mes12-implement-detect-and-reset-callback.patch. - commit 593cd3d - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: btmtk: accept too short WMT FUNC_CTRL events (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - Revert "ACPI: CPPC: Adjust debug messages in amd_set_max_freq_ratio() to warn" (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - ASoC: SOF: ipc3: Use standard dev_dbg API (stable-fixes). - commit 9748735 - arm64: tlb: Flush walk cache when unsharing PMD tables (git-fixes) - commit adbb70c - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - commit 79d4d40 - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - commit 8e6e1e7 - virt: sev-guest: Explicitly leak pages in unknown state (git-fixes). - commit 33b865c - firmware: arm_ffa: Align RxTx buffer size before mapping (git-fixes) - commit 94c6e3b ++++ libsolv: - made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] - fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] - added limit checks in multiple places to catch overflows - reduce the size of the language id cache - fixed Debian canon selection - fixed dbpath detection in repo_rpmdb_librpm - reduced stack usage in repo page compression (needed for musl) - bump version to 0.7.38 ++++ openQA: - Update to version 5.1779808735.8c9bd805: * docs: Fix link to "Conducting tests" section * refactor: Use Feature::Compat::Try consistently * ci: Build packages for SLE 15 SP7 instead of SP6 which reached EOL * ci: Remove package builds for Leap 15.6 as it reached EOL * fix: make TESTS selection work again (regression from cd76f31f3) * feat: add Nginx proxy template for local LLM load balancing * feat: add openQA-llm-server sub-package for local LLM support * feat(pyproject): Streamline summary with spec file * fix: Fix wording in summary of rpm package * feat: Apply formatting of Python code also to documentation snippets * feat: Change `openqa-label-all` to satisfy ruff checks * test: Add target to run format Python code * test: Add targets to run static Python checks * feat: Add `pyproject.toml` as in other repositories * feat(needle-editor): Validate that there is at least one match area * docs: Reference "Asset handling" section directly * fix: Fix some wrong uses of "check out" * docs: Fix broken references in further places * docs: Fix wrapping in section about importing production data * docs: Fix broken references in several documentation files * test(isos post): Assert behavior when specifying parameters twice * refactor(isos post): Use `$validation` consistently * fix(spec): add RPM Group tag to all subpackages * style: Include core perlcritic rules as well * fix: resolve 'Too many open files' by clearing AssetPack FD cache * fix: work around DBD::Pg bug regarding INSERT ON CONFLICT row count * refactor: Remove superfluous Test::MockModule instance * refactor: Use a hash instead of string eval * refactor: Use Syntax::Keyword::Try instead of eval * style: Enforce perlcritic policies regarding eval * fix: allow worker to start without API keys * refactor: Split scheduler tests to avoid failing complexity check * feat: Distinguish parallel jobs in info when cluster cannot be assigned * fix: Reword misleading message about "incomplete parallel cluster" * fix(docs): remove zero-length draw.io marker file * fix(branding): add placeholder content to empty sponsorbox template * test: fix "Too many open files" in t/api/03-auth.t * fix: fix security vulnerability in Auth::check and minor typo * test: fix hmac_sha1_sum calculation in auth tests * docs: fix typo in Auth controller * refactor: use DEFAULT_ADMIN constant for admin username * feat: switch bootstrap to 'None' authentication provider * fix(packaging): avoid repeating package name in Summary * fix(packaging): replace obsolete packageand() with boolean Supplements * fix(build): install openqa-cli.yaml without executable bit * style: Enforce perlcritic policy Community::EmptyReturn * ci: Remove `perl-TAP-Harness-JUnit` from devel container again * ci: Use distinct container introduced by f33029623 * chore: Use `https://download.opensuse.org` consistently * feat(worker): Pass reason to web UI when skipping job due to self-check * feat(worker): Prevent skipping directly chained jobs due to self-checks * fix(build): add executable bit to dbicdh migration scripts * refactor: Remove @EXPORT and add %EXPORT_TAGS * refactor: Move @EXPORT to @EXPORT_OK * refactor: Remove unused var @EXPORT * style: Add no critic * style: Enforce perlcritic policy ProhibitAutomaticExportation * refactor: Remove non-existing functions from export list * feat: Require Perl::Critic >= 1.156.0 * style: Enforce perlcritic policy Subroutines::ProhibitManyArgs * feat: support configurable secrets hiding in UI and API * chore(deps): Dependency cron 2026-05-16 * chore(deps): Dependency cron 2026-05-15 * chore(deps): Dependency cron 2026-05-14 * refactor(create_admin): switch to Getopt::Long::Descriptive * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUniversalIsa * test: Prevent unhandled output after b278ab6dfd3 * style: Enforce perlcritic policy regarding open() * ci: Add distinct container image for CI * style: Enforce perlcritic policy Subroutines::ProhibitReturnSort * style: Enforce perlcritic policy ProhibitReadlineInForLoop * style: Enforce perlcritic policy Community::POSIXImports * style: Enforce perlcritic policy ClassHierarchies::ProhibitOneArgBless * chore(deps): Dependency cron 2026-05-13 * fix: parse URL-derived settings for cloned jobs * style: Enforce perlcritic policy TestingAndDebugging::ProhibitNoWarnings * ci(dependabot): apply deps update cooldown to prevent PR fatigue * refactor: Improve global variables in SeleniumTest * style: Enforce perlcritic policy Variables::ProhibitPackageVars * style: Enforce perlcritic policy Community::ConditionalImplicitReturn * test: Add `python3-ruff` for static checks of Python scripts * style: Enforce perlcritic policy CodeLayout::ProhibitHardTabs * test(worker-engine): Cover all lines of `set_engine_exec` * chore(ci): Avoid running into authenticity error * chore(ci): Allow running caching jobs in parallel * chore(ci): Log installed rpm packages after removing explicit tracking * chore(ci): Simplify CI runtime using devel container image * chore(Makefile): Avoid depending on the `which` utility * fix(apparmor): allow /usr/bin/getopt needed for os-autoinst-scripts * style: Enforce perlcritic policy ProhibitConditionalUseStatements * style: Enforce perlcritic policy Subroutines::ProhibitExcessComplexity * style: enforce perlcritic policy ProhibitCascadingIfElse * perf(cleanup): replace N+1 per-group queries with single batch query * style: Enforce perlcritic ProhibitQuotesAsQuotelikeOperatorDelimiters * style: Enforce perlcritic policy RequirePackageMatchesPodName * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUselessTopic * feat(api): filter job statistics by group globs * test: stabilize test_containers_compose * test: use IfNotPresent pull policy for postgres init container * fix(tools): handle pandoc TeX math misinterpretation in API docs * fix(docs): link to the correct cleanup section * style: Enforce perlcritic policy Miscellanea::ProhibitUselessNoCritic * style: Rewrite some for loops in foreach style * style: Enforce erlcritic policy Modules::ProhibitExcessMainComplexity * feat(cli): generate shell completions from openqa-cli.yaml * fix(test overview): Bring query for "Aborted" in-line with accounting * chore(deps): Dependency cron 2026-05-11 * ci: fix "conflicts with file" problems * fix: update fast-uri to address security vulnerabilities (boo#1264376) * docs: Fix wrapping in users guide after Markdown conversion * feat: add scheduling skip reasons to the webUI ++++ openQA: - Update to version 5.1779808735.8c9bd805: * docs: Fix link to "Conducting tests" section * refactor: Use Feature::Compat::Try consistently * ci: Build packages for SLE 15 SP7 instead of SP6 which reached EOL * ci: Remove package builds for Leap 15.6 as it reached EOL * fix: make TESTS selection work again (regression from cd76f31f3) * feat: add Nginx proxy template for local LLM load balancing * feat: add openQA-llm-server sub-package for local LLM support * feat(pyproject): Streamline summary with spec file * fix: Fix wording in summary of rpm package * feat: Apply formatting of Python code also to documentation snippets * feat: Change `openqa-label-all` to satisfy ruff checks * test: Add target to run format Python code * test: Add targets to run static Python checks * feat: Add `pyproject.toml` as in other repositories * feat(needle-editor): Validate that there is at least one match area * docs: Reference "Asset handling" section directly * fix: Fix some wrong uses of "check out" * docs: Fix broken references in further places * docs: Fix wrapping in section about importing production data * docs: Fix broken references in several documentation files * test(isos post): Assert behavior when specifying parameters twice * refactor(isos post): Use `$validation` consistently * fix(spec): add RPM Group tag to all subpackages * style: Include core perlcritic rules as well * fix: resolve 'Too many open files' by clearing AssetPack FD cache * fix: work around DBD::Pg bug regarding INSERT ON CONFLICT row count * refactor: Remove superfluous Test::MockModule instance * refactor: Use a hash instead of string eval * refactor: Use Syntax::Keyword::Try instead of eval * style: Enforce perlcritic policies regarding eval * fix: allow worker to start without API keys * refactor: Split scheduler tests to avoid failing complexity check * feat: Distinguish parallel jobs in info when cluster cannot be assigned * fix: Reword misleading message about "incomplete parallel cluster" * fix(docs): remove zero-length draw.io marker file * fix(branding): add placeholder content to empty sponsorbox template * test: fix "Too many open files" in t/api/03-auth.t * fix: fix security vulnerability in Auth::check and minor typo * test: fix hmac_sha1_sum calculation in auth tests * docs: fix typo in Auth controller * refactor: use DEFAULT_ADMIN constant for admin username * feat: switch bootstrap to 'None' authentication provider * fix(packaging): avoid repeating package name in Summary * fix(packaging): replace obsolete packageand() with boolean Supplements * fix(build): install openqa-cli.yaml without executable bit * style: Enforce perlcritic policy Community::EmptyReturn * ci: Remove `perl-TAP-Harness-JUnit` from devel container again * ci: Use distinct container introduced by f33029623 * chore: Use `https://download.opensuse.org` consistently * feat(worker): Pass reason to web UI when skipping job due to self-check * feat(worker): Prevent skipping directly chained jobs due to self-checks * fix(build): add executable bit to dbicdh migration scripts * refactor: Remove @EXPORT and add %EXPORT_TAGS * refactor: Move @EXPORT to @EXPORT_OK * refactor: Remove unused var @EXPORT * style: Add no critic * style: Enforce perlcritic policy ProhibitAutomaticExportation * refactor: Remove non-existing functions from export list * feat: Require Perl::Critic >= 1.156.0 * style: Enforce perlcritic policy Subroutines::ProhibitManyArgs * feat: support configurable secrets hiding in UI and API * chore(deps): Dependency cron 2026-05-16 * chore(deps): Dependency cron 2026-05-15 * chore(deps): Dependency cron 2026-05-14 * refactor(create_admin): switch to Getopt::Long::Descriptive * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUniversalIsa * test: Prevent unhandled output after b278ab6dfd3 * style: Enforce perlcritic policy regarding open() * ci: Add distinct container image for CI * style: Enforce perlcritic policy Subroutines::ProhibitReturnSort * style: Enforce perlcritic policy ProhibitReadlineInForLoop * style: Enforce perlcritic policy Community::POSIXImports * style: Enforce perlcritic policy ClassHierarchies::ProhibitOneArgBless * chore(deps): Dependency cron 2026-05-13 * fix: parse URL-derived settings for cloned jobs * style: Enforce perlcritic policy TestingAndDebugging::ProhibitNoWarnings * ci(dependabot): apply deps update cooldown to prevent PR fatigue * refactor: Improve global variables in SeleniumTest * style: Enforce perlcritic policy Variables::ProhibitPackageVars * style: Enforce perlcritic policy Community::ConditionalImplicitReturn * test: Add `python3-ruff` for static checks of Python scripts * style: Enforce perlcritic policy CodeLayout::ProhibitHardTabs * test(worker-engine): Cover all lines of `set_engine_exec` * chore(ci): Avoid running into authenticity error * chore(ci): Allow running caching jobs in parallel * chore(ci): Log installed rpm packages after removing explicit tracking * chore(ci): Simplify CI runtime using devel container image * chore(Makefile): Avoid depending on the `which` utility * fix(apparmor): allow /usr/bin/getopt needed for os-autoinst-scripts * style: Enforce perlcritic policy ProhibitConditionalUseStatements * style: Enforce perlcritic policy Subroutines::ProhibitExcessComplexity * style: enforce perlcritic policy ProhibitCascadingIfElse * perf(cleanup): replace N+1 per-group queries with single batch query * style: Enforce perlcritic ProhibitQuotesAsQuotelikeOperatorDelimiters * style: Enforce perlcritic policy RequirePackageMatchesPodName * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUselessTopic * feat(api): filter job statistics by group globs * test: stabilize test_containers_compose * test: use IfNotPresent pull policy for postgres init container * fix(tools): handle pandoc TeX math misinterpretation in API docs * fix(docs): link to the correct cleanup section * style: Enforce perlcritic policy Miscellanea::ProhibitUselessNoCritic * style: Rewrite some for loops in foreach style * style: Enforce erlcritic policy Modules::ProhibitExcessMainComplexity * feat(cli): generate shell completions from openqa-cli.yaml * fix(test overview): Bring query for "Aborted" in-line with accounting * chore(deps): Dependency cron 2026-05-11 * ci: fix "conflicts with file" problems * fix: update fast-uri to address security vulnerabilities (boo#1264376) * docs: Fix wrapping in users guide after Markdown conversion * feat: add scheduling skip reasons to the webUI ++++ openQA: - Update to version 5.1779808735.8c9bd805: * docs: Fix link to "Conducting tests" section * refactor: Use Feature::Compat::Try consistently * ci: Build packages for SLE 15 SP7 instead of SP6 which reached EOL * ci: Remove package builds for Leap 15.6 as it reached EOL * fix: make TESTS selection work again (regression from cd76f31f3) * feat: add Nginx proxy template for local LLM load balancing * feat: add openQA-llm-server sub-package for local LLM support * feat(pyproject): Streamline summary with spec file * fix: Fix wording in summary of rpm package * feat: Apply formatting of Python code also to documentation snippets * feat: Change `openqa-label-all` to satisfy ruff checks * test: Add target to run format Python code * test: Add targets to run static Python checks * feat: Add `pyproject.toml` as in other repositories * feat(needle-editor): Validate that there is at least one match area * docs: Reference "Asset handling" section directly * fix: Fix some wrong uses of "check out" * docs: Fix broken references in further places * docs: Fix wrapping in section about importing production data * docs: Fix broken references in several documentation files * test(isos post): Assert behavior when specifying parameters twice * refactor(isos post): Use `$validation` consistently * fix(spec): add RPM Group tag to all subpackages * style: Include core perlcritic rules as well * fix: resolve 'Too many open files' by clearing AssetPack FD cache * fix: work around DBD::Pg bug regarding INSERT ON CONFLICT row count * refactor: Remove superfluous Test::MockModule instance * refactor: Use a hash instead of string eval * refactor: Use Syntax::Keyword::Try instead of eval * style: Enforce perlcritic policies regarding eval * fix: allow worker to start without API keys * refactor: Split scheduler tests to avoid failing complexity check * feat: Distinguish parallel jobs in info when cluster cannot be assigned * fix: Reword misleading message about "incomplete parallel cluster" * fix(docs): remove zero-length draw.io marker file * fix(branding): add placeholder content to empty sponsorbox template * test: fix "Too many open files" in t/api/03-auth.t * fix: fix security vulnerability in Auth::check and minor typo * test: fix hmac_sha1_sum calculation in auth tests * docs: fix typo in Auth controller * refactor: use DEFAULT_ADMIN constant for admin username * feat: switch bootstrap to 'None' authentication provider * fix(packaging): avoid repeating package name in Summary * fix(packaging): replace obsolete packageand() with boolean Supplements * fix(build): install openqa-cli.yaml without executable bit * style: Enforce perlcritic policy Community::EmptyReturn * ci: Remove `perl-TAP-Harness-JUnit` from devel container again * ci: Use distinct container introduced by f33029623 * chore: Use `https://download.opensuse.org` consistently * feat(worker): Pass reason to web UI when skipping job due to self-check * feat(worker): Prevent skipping directly chained jobs due to self-checks * fix(build): add executable bit to dbicdh migration scripts * refactor: Remove @EXPORT and add %EXPORT_TAGS * refactor: Move @EXPORT to @EXPORT_OK * refactor: Remove unused var @EXPORT * style: Add no critic * style: Enforce perlcritic policy ProhibitAutomaticExportation * refactor: Remove non-existing functions from export list * feat: Require Perl::Critic >= 1.156.0 * style: Enforce perlcritic policy Subroutines::ProhibitManyArgs * feat: support configurable secrets hiding in UI and API * chore(deps): Dependency cron 2026-05-16 * chore(deps): Dependency cron 2026-05-15 * chore(deps): Dependency cron 2026-05-14 * refactor(create_admin): switch to Getopt::Long::Descriptive * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUniversalIsa * test: Prevent unhandled output after b278ab6dfd3 * style: Enforce perlcritic policy regarding open() * ci: Add distinct container image for CI * style: Enforce perlcritic policy Subroutines::ProhibitReturnSort * style: Enforce perlcritic policy ProhibitReadlineInForLoop * style: Enforce perlcritic policy Community::POSIXImports * style: Enforce perlcritic policy ClassHierarchies::ProhibitOneArgBless * chore(deps): Dependency cron 2026-05-13 * fix: parse URL-derived settings for cloned jobs * style: Enforce perlcritic policy TestingAndDebugging::ProhibitNoWarnings * ci(dependabot): apply deps update cooldown to prevent PR fatigue * refactor: Improve global variables in SeleniumTest * style: Enforce perlcritic policy Variables::ProhibitPackageVars * style: Enforce perlcritic policy Community::ConditionalImplicitReturn * test: Add `python3-ruff` for static checks of Python scripts * style: Enforce perlcritic policy CodeLayout::ProhibitHardTabs * test(worker-engine): Cover all lines of `set_engine_exec` * chore(ci): Avoid running into authenticity error * chore(ci): Allow running caching jobs in parallel * chore(ci): Log installed rpm packages after removing explicit tracking * chore(ci): Simplify CI runtime using devel container image * chore(Makefile): Avoid depending on the `which` utility * fix(apparmor): allow /usr/bin/getopt needed for os-autoinst-scripts * style: Enforce perlcritic policy ProhibitConditionalUseStatements * style: Enforce perlcritic policy Subroutines::ProhibitExcessComplexity * style: enforce perlcritic policy ProhibitCascadingIfElse * perf(cleanup): replace N+1 per-group queries with single batch query * style: Enforce perlcritic ProhibitQuotesAsQuotelikeOperatorDelimiters * style: Enforce perlcritic policy RequirePackageMatchesPodName * style: Enforce perlcritic policy BuiltinFunctions::ProhibitUselessTopic * feat(api): filter job statistics by group globs * test: stabilize test_containers_compose * test: use IfNotPresent pull policy for postgres init container * fix(tools): handle pandoc TeX math misinterpretation in API docs * fix(docs): link to the correct cleanup section * style: Enforce perlcritic policy Miscellanea::ProhibitUselessNoCritic * style: Rewrite some for loops in foreach style * style: Enforce erlcritic policy Modules::ProhibitExcessMainComplexity * feat(cli): generate shell completions from openqa-cli.yaml * fix(test overview): Bring query for "Aborted" in-line with accounting * chore(deps): Dependency cron 2026-05-11 * ci: fix "conflicts with file" problems * fix: update fast-uri to address security vulnerabilities (boo#1264376) * docs: Fix wrapping in users guide after Markdown conversion * feat: add scheduling skip reasons to the webUI ++++ product-composer: - fix sle 15 patch to support older python modules - enable test suite during build ++++ product-composer: - fix sle 15 patch to support older python modules - enable test suite during build ++++ selinux-policy: - Update to version 20250627+git376.3e51f6aea: * Vibecode Gitlab CI smoke test for Leap 16.0+ * Add diffutils explicitly to .gitlab-ci * Fix gitlab CI * Allow virtqemud_t to call and transition into udev * Dontaudit ps to read proc (bsc#1257527) * Dontaudit ps permissions that tlp_t does not need (bsc#1257527) * TLP uses ps aux to check for different services (bsc#1257527) ++++ selinux-policy: - Update to version 20250627+git376.3e51f6aea: * Vibecode Gitlab CI smoke test for Leap 16.0+ * Add diffutils explicitly to .gitlab-ci * Fix gitlab CI * Allow virtqemud_t to call and transition into udev * Dontaudit ps to read proc (bsc#1257527) * Dontaudit ps permissions that tlp_t does not need (bsc#1257527) * TLP uses ps aux to check for different services (bsc#1257527) ------------------------------------------------------------------ ------------------ 2026-5-25 - May 25 2026 ------------------- ------------------------------------------------------------------ ++++ agama-web-ui: - Update shell-quote dependency (CVE-2026-9277, bsc#1266256). - Update other dependencies reported by "npm audit". ++++ kernel-64kb: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-64kb: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-64kb: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-azure: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-azure: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-azure: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-default: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-default: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-default: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-rt: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-rt: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-rt: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ coturn: - Update to version 4.12.0 * Update khash to the latest version (#1919). * Update readme to match latest changes (#1920). * Update docs for drop-invalid-packets and response-origin-only-with-rfc5780. * Multiplexpeer (#1916). * Fix TTL/TOS type conversion (#1915). * turnutils_uclient: sender thread pool + UDP-GSO send batching + recv_pps reporting (#1913). * Fix memory leak introduced by recvmmsg path (#1912). * turnutils_uclient: multi-threaded listener (recv) pool. * examples/turnserver.conf: update description of cli option. * turnutils_uclient: Linux recvmmsg receive path + larger SO_RCVBUF (#1910). * Add UDP-GSO send path (--udp-gso) (#1907). * turnutils_peer: Linux fast path with drain loop, recvmmsg/sendmmsg, U… (#1908). * Relay recvmmsg (#1906). * fuzzing: use hex escapes for HTTP EOH dictionary entry. * Sync turnserver man page with current CLI options (#1903). * Remove stale --ne option from turnserver --help (#1904). * Restore CodeQL permissions, category, and manual build mode. ++++ dtb-aarch64: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ dtb-aarch64: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ dtb-aarch64: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ libheif: - added patches https://github.com/strukturag/libheif/commit/5780da88104270ef316c764c2c2945e0c43af624 * libheif-fix-tests-no-HEVC.patch ++++ vim: - Update to v9.2.0530. - Fix for SG#71948, bsc#1262395: * vim-9.1.1732-fix-inc-detection.patch: Fix for incorrectly detecting scientific parameter files as bitbake recipies. - Upstream fixed the following bugs / CVEs: * bsc#1264706 CVE-2026-42307 * bsc#1265360 CVE-2026-46483 * bsc#1264708 CVE-2026-45130 * bsc#1264707 CVE-2026-44656 * bsc#1265349 CVE-2026-43961 - Changes: * 9.2.0530: WinBar row vertical separator not refreshed on window change * 9.2.0529: GTK4: clipboard returns empty after a foreign app takes the selection * 9.2.0528: possible overflow in XIM resource handling * 9.2.0527: Possible double free in fill_partial_and_closure() * 9.2.0526: missing out-of-memory check in ex_substitute() * 9.2.0525: spell: memory leak in spell_read_dic() * 9.2.0524: spell: buffer overflow with many affix or compound flags * 9.2.0523: tests: no test for using shellescape() in combination with :! * 9.2.0522: event_nr2name() in autocmd.c can be improved * 9.2.0521: GTK4: cannot resize shell after the window is shown * 9.2.0520: Reversed text opacity in popup when termguicolor is set * 9.2.0519: GTK4: GUI tabline is not displayed correctly * 9.2.0518: GTK4: input method cannot compose text * 9.2.0517: quickfix: can set quickfixtextfunc in restricted/sandbox mode * 9.2.0516: socketserver: spurious error when servername is taken * 9.2.0515: virtualedit=insert doesn't work during change operation * 9.2.0514: GTK4: build errors when socketserver is enabled * 9.2.0513: [security]: memory safety issues in spellfile.c * 9.2.0512: clientserver uses binary protocol * 9.2.0511: configure: when GTK4 is used also links in X11 libs * 9.2.0510: setline() mapping may trigger autoindent * 9.2.0509: term.c: compile error when LOG_TRN is enabled * 9.2.0508: completion: cannot complete user cmd :K with 'ignorecase' * 9.2.0507: Vim9 class: public/protected member name clash uses same error * 9.2.0506: home_replace() function can be improved * 9.2.0505: GTK4: text looks blurry on HiDPI displays * 9.2.0504: configure: requires X11 libraries for GTK4 build * 9.2.0503: Makefile: Missing dependencies for new GTK4 source files * 9.2.0502: runtime(netrw): bookmark handling can be improved * 9.2.0501: GTK4: there is no GTK4 UI available * 9.2.0500: filetype: some html files wrongly recognized as htmlangular * 9.2.0499: modeline: allow to disable modelines with modelinestrict * 9.2.0498: potential heap buffer overflow in if_xcmdsrv.c * 9.2.0497: Cannot jump to remote tags * 9.2.0496: [security]: Code Injection in cucumber filetype plugin * 9.2.0495: [security]: runtime(netrw): code injection via NetrwBookHistSave() * 9.2.0494: User commands cannot handle single args with spaces * 9.2.0493: popup: missing Popup, PopupBorder and PopupTitle hi groups * 9.2.0492: popup: decoration wrongly drawn with clipping on border * 9.2.0491: VMS: various build issues * 9.2.0490: matchfuzzy() can crash on long multi-word patterns * 9.2.0489: filetype: some Objective-C files are not recognized * 9.2.0488: statusline: status line highlight blends into adjacent vsep cells * 9.2.0487: viminfo: possible signed int overflow in register array * 9.2.0486: out-of-bound read when recovering swap files * 9.2.0485: clipboard provider callback can be called recursively * 9.2.0484: TextPutPre triggers clipboard provider callback twice * 9.2.0483: popup: terminal embedded in an opacity popup freezes Vim on input * 9.2.0482: runtime(osc52): triggered twice with TextPutPoste autocmd * 9.2.0481: runtime(netrw): command injection possible via maps * 9.2.0480: [security]: runtime(netrw): code injection via mf command * 9.2.0479: [security]: runtime(tar): command injection in tar plugin * 9.2.0478: channel: redundant str/length assignments in channel_part_info() * 9.2.0477: popup: leftover content after popup_free under layout change * 9.2.0476: pattern completion leaks memory on alloc failures * 9.2.0475: runtime(netrw): bookmark paths not normalized * 9.2.0474: MS-Windows: hard to tell which Visual Studio version was selected with MSVC * 9.2.0473: Pasting ". register without autocommands breaks TextPut* * 9.2.0472: popup: column jitters when scrolled outside viewport * 9.2.0471: vimvars di_key initialized at runtime * 9.2.0470: No way to hook into put commands * 9.2.0469: popup: textprop-anchored popups bleed past host window edges * 9.2.0468: popups: not correctly updated from a CmdlineChanged autocommand * 9.2.0467: multi-line statusline loses highlighting attributes * 9.2.0466: popup: redraw can use stale blended cells * 9.2.0465: modeline: foldmarker cannot be set with modelinestrict * 9.2.0464: runtime(netrw): bookmarking directory uses current dir * 9.2.0463: Not able to use legacy expression evaluation in a vim9script maps * 9.2.0462: MS-Windows: workaround for assert error on GUI * 9.2.0461: Corrupted undofile causes use-after-free * 9.2.0460: did_set_shellpipe_redir() in wrong file * 9.2.0459: tests: test_termcodes fails (after v9.2.0456) * 9.2.0458: Crash with invalid shellredir/shellpipe value * 9.2.0457: Compile warning about unused variable * 9.2.0456: stray p character displayed on some terms * 9.2.0455: 'findfunc' only allows extra info for cmdline completion * 9.2.0454: tests: no test that "abbr" in customlist completion is shown * 9.2.0453: vertical separator of statusline blend into active statusline * 9.2.0452: screen.c popup opacity blend logic is duplicated * 9.2.0451: 'findfunc' can't return extra info for cmdline completion * 9.2.0450: [security]: heap buffer overflow in spellfile.c read_compound() * 9.2.0449: Make proto fails in non GTK builds * 9.2.0448: Vim9: dangling cmdline pointer after skip_expr_cctx() * 9.2.0447: cindent does not ignore comments * 9.2.0446: runtime(netrw): off-by-one bug in s:NetrwUnMarkFile() * 9.2.0445: win_fix_scroll() called before win_comp_pos() in command_height() * 9.2.0444: Cannot set 'path' option via modeline * 9.2.0443: GUI: cancelling save dialog overwrites or discards unnamed buffer * 9.2.0442: completion: i_CTRL-X_CTRL-V doesn't use dict from customlist * 9.2.0441: statusline: click handler not called on multi-line statusline * 9.2.0440: MS-Windows: cursor flicker during update_screen() * 9.2.0439: completion: info popup not removed in cmdline mode * 9.2.0438: tests: test_plugin_termdebug is flaky * 9.2.0437: MS-Windows: cursor flicker in vtp mode * 9.2.0436: Buffer overflow when parsing overlong errorformat lines * 9.2.0435: [security]: backticks in 'path' may cause shell execution on completion * 9.2.0434: cscope: filename interpreted by /bin/sh * 9.2.0433: customlist completion cannot supply pum metadata * 9.2.0432: blob to string conversion can be improved * 9.2.0431: blob encoding can be improved * 9.2.0430: tests: Test_shortmess_F3() is flaky on MS-Windows * 9.2.0429: tests: flaky screendump Test_smoothscroll_incsearch() * 9.2.0428: popup: no opacity support for completepopup/previewpopup * 9.2.0427: popup: opacity blend may leaks white bg color * 9.2.0426: tests: still some flaky screendump tests * 9.2.0425: Cannot silence undo/redo messages * 9.2.0424: popup: flicker when wildtrigger() refreshes the popup menu * 9.2.0423: popup: wrapped cmdline truncated with wildoptions=pum * 9.2.0422: popup: leave stray char when scrollbar changes * 9.2.0421: vimball: can smuggle Vimscript into VimballRecord file * 9.2.0420: channel: cannot handle binary data via channel callbacks * 9.2.0419: popup: rendering issues * 9.2.0418: wildcards in expanded env vars reinterpreted by glob * 9.2.0417: completion: no support for "noinsert" with 'wildmode' * 9.2.0416: Unix: filename completion splits at space for single-file Ex commands * 9.2.0415: Wrong behavior when executing register that ends in Insert mode * 9.2.0414: Flicker when drawing window separator and pum is shown * 9.2.0413: Scrolling wrong with 'splitkeep' when changing 'cmdheight' * 9.2.0412: channel: term_start() out_cb/err_cb no longer deliver raw chunks * 9.2.0411: tabpanel: no Vim script functions for the tabpanel * 9.2.0410: test suite races when run with parallel make * 9.2.0409: memory leaks in copy_substring_from_pos() * 9.2.0408: Insert-mode edits can corrupt undo * 9.2.0407: tabpanel: A few issues with the tabpanel * 9.2.0406: VisualNOS not used when Wayland selection ownership lost * 9.2.0405: when jumping to tags, will open URLs * 9.2.0404: redraw_listener_add() does not check secure flag * 9.2.0403: Vim9: def function sandbox bypass * 9.2.0402: pum: opacity not applied to wildmenu pum * 9.2.0401: tests: still a few flaky tests * 9.2.0400: sandbox callbacks selected through 'complete' * 9.2.0399: MS-Windows: compile warning in strptime.c ++++ jq: - Add patch CVE-2026-32316.patch (CVE-2026-32316, bsc#1262044) - Add patch CVE-2026-33947.patch (CVE-2026-33947, bsc#1262069) - Add patch CVE-2026-39956.patch (CVE-2026-39956, bsc#1262070) - Add patch CVE-2026-39979.patch (CVE-2026-39979, bsc#1262071) - Add patch CVE-2026-40164.patch (CVE-2026-40164, bsc#1262072) - Add patch CVE-2026-40612.patch (CVE-2026-40612, bsc#1265060) - Add patch CVE-2026-41256.patch (CVE-2026-41256, bsc#1265061) - Add patch CVE-2026-41257.patch (CVE-2026-41257, bsc#1265062) - Add patch CVE-2026-43894.patch (CVE-2026-43894, bsc#1265070) ++++ kernel-source: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-source: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-source: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-docs: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-docs: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-docs: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-kvmsmall: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-kvmsmall: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-kvmsmall: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-obs-build: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-obs-build: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-obs-build: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-obs-qa: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-obs-qa: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-obs-qa: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-syms: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-syms: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-syms: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-zfcpdump: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-zfcpdump: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ kernel-zfcpdump: - net: gro: don't merge zcopy skbs (git-fixes). - net: skbuff: propagate shared-frag marker through frag-transfer helpers (CVE-2026-43503 bsc#1265960). - net: skbuff: preserve shared-frag marker during coalescing (CVE-2026-46300 bsc#1265209). - commit 68f8e8b - Revert "net: skbuff: propagate shared-frag marker through pskb_copy()" This reverts commit f71c96250de20f4edf1c4beeb9d8b973a9ad6943. - commit aaf0bdb ++++ s390-tools: - Upgrade s390-tools to version 2.42.1 (jsc#PED-14586, bsc#1266206, bsc#1258947) For Linux kernel version: 7.0 - Changes of existing tools: * cpumf/pai: Improve -m XXX argument verification * pvattest: Add -i -o option variant for check * pvattest: Show perform -i & -o option in help * pvebc: Disable unit logging to /boot * pvsecret: Add -i -o option variants - Bug Fixes: * cpumf/pai: Remove unnecessary const parameter definition * pv: Fix error description * pvebc: Fix dependency for non EBC guests * pvebc: Fix kernel module dependencies * zipl: Don't modify job->data.dump and job->data.mvdump sequentially - Added new (EBC) services in the .spec file * sel-ebc-boot-mount.service * sel-ebc-override-crypttab.service * sel-ebc-paes-enforce.service * sel-ebc-pvebc.service --- *** Version 2.42.0 includes *** --- - Add new tools / libraries: * Enable zsh and bash autocompletion for various tools * pvebc: Resolve ASR integrity structure for EBC * pvics: Generate SEL guests from base images - Remove: * tape390_display and tape390_crypt removed due to long gone hardware support * znetcontrolunits: Remove znetcontrolunits library - Changes of existing tools: * cpumf/pai: Install SIGINT/SIGTERM handler for graceful termination * dbginfo.sh: Add command zmemtopo * libutil/util_fmt: Add support for JSON Lines text format * lstape: Remove 3480 and 3590 tape support * lsznet: Remove support for lcs device type * pvsecret: Add support for ASR integrity structure for EBC * zfcpdbf: Print plogi and prli within open port response as payload * zfcpdbf: Trace all fsf status read buffer fields under HBA * zipl/boot: Add secure boot option to the dump programm * zkey, libekmfweb, libseckey, libkmipclient: Adjust for OpenSSL v4.0.0 API changes and deprecations - Bug Fixes: * hyptop/opts: Fix long command line option abbreviations * libutil/util_autocomp: Fix default file completion * zipl/boot: Fix stage3 secure boot trailer placement - Remove obsolete pacthes: * s390-tools-hyptop-opts-Replace-sort_field-option-with-sort.patch * s390-tools-hyptop-opts-Fix-long-command-line-option-abbreviations.patch - Updated read_values.c (bsc#1263041, bsc#1263992) * Includes /proc/sysinfo fallback to prevent the qclib "Unable to open configuration, return_code =-2" errors. - Re-venor-ed vendor.tar.zst ++++ s390-tools: - Upgrade s390-tools to version 2.42.1 (jsc#PED-14586, bsc#1266206, bsc#1258947) For Linux kernel version: 7.0 - Changes of existing tools: * cpumf/pai: Improve -m XXX argument verification * pvattest: Add -i -o option variant for check * pvattest: Show perform -i & -o option in help * pvebc: Disable unit logging to /boot * pvsecret: Add -i -o option variants - Bug Fixes: * cpumf/pai: Remove unnecessary const parameter definition * pv: Fix error description * pvebc: Fix dependency for non EBC guests * pvebc: Fix kernel module dependencies * zipl: Don't modify job->data.dump and job->data.mvdump sequentially - Added new (EBC) services in the .spec file * sel-ebc-boot-mount.service * sel-ebc-override-crypttab.service * sel-ebc-paes-enforce.service * sel-ebc-pvebc.service --- *** Version 2.42.0 includes *** --- - Add new tools / libraries: * Enable zsh and bash autocompletion for various tools * pvebc: Resolve ASR integrity structure for EBC * pvics: Generate SEL guests from base images - Remove: * tape390_display and tape390_crypt removed due to long gone hardware support * znetcontrolunits: Remove znetcontrolunits library - Changes of existing tools: * cpumf/pai: Install SIGINT/SIGTERM handler for graceful termination * dbginfo.sh: Add command zmemtopo * libutil/util_fmt: Add support for JSON Lines text format * lstape: Remove 3480 and 3590 tape support * lsznet: Remove support for lcs device type * pvsecret: Add support for ASR integrity structure for EBC * zfcpdbf: Print plogi and prli within open port response as payload * zfcpdbf: Trace all fsf status read buffer fields under HBA * zipl/boot: Add secure boot option to the dump programm * zkey, libekmfweb, libseckey, libkmipclient: Adjust for OpenSSL v4.0.0 API changes and deprecations - Bug Fixes: * hyptop/opts: Fix long command line option abbreviations * libutil/util_autocomp: Fix default file completion * zipl/boot: Fix stage3 secure boot trailer placement - Remove obsolete pacthes: * s390-tools-hyptop-opts-Replace-sort_field-option-with-sort.patch * s390-tools-hyptop-opts-Fix-long-command-line-option-abbreviations.patch - Updated read_values.c (bsc#1263041, bsc#1263992) * Includes /proc/sysinfo fallback to prevent the qclib "Unable to open configuration, return_code =-2" errors. - Re-venor-ed vendor.tar.zst ++++ s390-tools: - Upgrade s390-tools to version 2.42.1 (jsc#PED-14586, bsc#1266206, bsc#1258947) For Linux kernel version: 7.0 - Changes of existing tools: * cpumf/pai: Improve -m XXX argument verification * pvattest: Add -i -o option variant for check * pvattest: Show perform -i & -o option in help * pvebc: Disable unit logging to /boot * pvsecret: Add -i -o option variants - Bug Fixes: * cpumf/pai: Remove unnecessary const parameter definition * pv: Fix error description * pvebc: Fix dependency for non EBC guests * pvebc: Fix kernel module dependencies * zipl: Don't modify job->data.dump and job->data.mvdump sequentially - Added new (EBC) services in the .spec file * sel-ebc-boot-mount.service * sel-ebc-override-crypttab.service * sel-ebc-paes-enforce.service * sel-ebc-pvebc.service --- *** Version 2.42.0 includes *** --- - Add new tools / libraries: * Enable zsh and bash autocompletion for various tools * pvebc: Resolve ASR integrity structure for EBC * pvics: Generate SEL guests from base images - Remove: * tape390_display and tape390_crypt removed due to long gone hardware support * znetcontrolunits: Remove znetcontrolunits library - Changes of existing tools: * cpumf/pai: Install SIGINT/SIGTERM handler for graceful termination * dbginfo.sh: Add command zmemtopo * libutil/util_fmt: Add support for JSON Lines text format * lstape: Remove 3480 and 3590 tape support * lsznet: Remove support for lcs device type * pvsecret: Add support for ASR integrity structure for EBC * zfcpdbf: Print plogi and prli within open port response as payload * zfcpdbf: Trace all fsf status read buffer fields under HBA * zipl/boot: Add secure boot option to the dump programm * zkey, libekmfweb, libseckey, libkmipclient: Adjust for OpenSSL v4.0.0 API changes and deprecations - Bug Fixes: * hyptop/opts: Fix long command line option abbreviations * libutil/util_autocomp: Fix default file completion * zipl/boot: Fix stage3 secure boot trailer placement - Remove obsolete pacthes: * s390-tools-hyptop-opts-Replace-sort_field-option-with-sort.patch * s390-tools-hyptop-opts-Fix-long-command-line-option-abbreviations.patch - Updated read_values.c (bsc#1263041, bsc#1263992) * Includes /proc/sysinfo fallback to prevent the qclib "Unable to open configuration, return_code =-2" errors. - Re-venor-ed vendor.tar.zst ++++ objectweb-asm: - Upgrade to version 9.10.1 * bug fixes + 318045: The retrofitter should also remove the (forRemoval) from the @Deprecated annotation associated with fields ++++ plexus-classworlds: - Upgrade to version 2.12.0 * Bug fixes + Fix loadGlob using OR instead of AND for glob matching ++++ putty: - Update to release 0.84 * Fixed a remotely triggerable double-free in RSA key exchange. * Fixed a remotely triggerable crash (assertion failure - program termination) in NIST ECDSA signature verification. * Fixed marking of Telnet and Rlogin session data with a trust sigil after you authenticated to a proxy (possibly allowing a server to spoof a repeat proxy password prompt). * New ability to run a specified command before starting the connection, e.g. to perform wake-on-LAN or a port knock. * Display 'pre-edit text', showing the progress of using multiple keystrokes to compose a single Unicode character. * Improved support for to running the GUI tools on Wayland (fixed startup issues and tuned performance). * Configuring a SSH certificate authority used to fail unless you manually made a config directory, now fixed. * Fixed a spurious "Network error: Socket is not connected" when authenticating to some HTTP proxies. ++++ python-idna: - CVE-2026-45409: Specially crafted inputs to idna.encode() can bypass earlier security fix(bsc#1265413) Add patch CVE-2026-45409.patch ++++ roundcubemail: - update to 1.6.16 This is a security update to the LTS version 1.6 of Roundcube Webmail. It provides fixes to recently reported security vulnerabilities: + Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog, reported by zazy + Fix CSS injection bypass in HTML sanitizer via SVG , reported by wooseokdotkim + Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass, reported by skull + Fix SSRF bypass via specific local address URLs + Fix local/private URL fetch bypass when remote resources were not allowed, reported by Orange Cyberdefense Vulnerability Disclosure Team + Fix bypass of remote image blocking via CSS var(), reported by Geame + Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass, reported by valent1 + Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option, reported by Glendaenri This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating! CHANGELOG + Fix potential too long value in IMAP ID command (#10136) + Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog [CVE-2026-48849] [bsc#1266337] + Security: Fix CSS injection bypass in HTML sanitizer via SVG [CVE-2026-48848] [bsc#1266336] + Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass [CVE-2026-48842] [bsc#1266329] + Security: Fix SSRF bypass via specific local address URLs [CVE-2026-48843] [bsc#1266331] + Security: Fix bypass of remote image blocking via CSS var() [CVE-2026-48846] [bsc#1266334] + Security: Fix local/private URL fetch bypass when remote resources were not allowed [CVE-2026-48845] [bsc#1266333] + Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass [CVE-2026-48847] [bsc#1266335] + Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option [CVE-2026-48844] [bsc#1266332] ------------------------------------------------------------------ ------------------ 2026-5-24 - May 24 2026 ------------------- ------------------------------------------------------------------ ++++ yq: - update to v4.53.2 * Add system(command; args) operator (disabled by default). * TOML encoder: prefer readable table sections over inline tables. * Fix TOML encoder to quote keys containing special characters. * Add string slicing support. * Fix findInArray misuse on MappingNodes in equality and contains. * Fix panic on negative slice indices that underflow after adjustment. * Fix stack overflow from circular alias in traverse. * Fix panic and OOM in repeatString for large repeat counts. - update to v4.52.5 * Fix: reset TOML decoder state between files. * Fix: preserve original filename when using --front-matter. - Integrate vulnchecker support into %check stage (optional: set `%%_with_vulncheck 1`). - Fix CVE-2026-33814 (bsc#1266248): * update golang.org/x/net to v0.53.0. - Add Fix-testcase-for-32bit-platforms.patch: This fixes the test suite for 32-bit. ------------------------------------------------------------------ ------------------ 2026-5-23 - May 23 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaThunderbird: - Refresh thunderbird-glibc-2.43.patch and re-enable its application on systems with glibc >= 2.43 ++++ apptainer: - Add improved handling of suid-starter: * Add system group `apptainer` * Make sure, only users belonging to this group are able to run the application. * Document this in a README and point user to it if execution fails. Building of the 'suid-root' starter is still optional. ++++ apptainer: - Add improved handling of suid-starter: * Add system group `apptainer` * Make sure, only users belonging to this group are able to run the application. * Document this in a README and point user to it if execution fails. Building of the 'suid-root' starter is still optional. ++++ apptainer: - Add improved handling of suid-starter: * Add system group `apptainer` * Make sure, only users belonging to this group are able to run the application. * Document this in a README and point user to it if execution fails. Building of the 'suid-root' starter is still optional. ++++ ffmpeg-4: - Add ffmpeg-4-CVE-2025-10256.patch: Backport a2546248 from upstream, Add check for the return value of av_malloc_array() to avoid potential NULL pointer dereference. (CVE-2025-10256, bsc#1249431) ++++ ffmpeg-4: - Add ffmpeg-4-CVE-2025-10256.patch: Backport a2546248 from upstream, Add check for the return value of av_malloc_array() to avoid potential NULL pointer dereference. (CVE-2025-10256, bsc#1249431) ++++ perl-Crypt-PasswdMD5: - updated to 1.430.0 (1.43) see /usr/share/doc/packages/perl-Crypt-PasswdMD5/Changelog.ini [V 1.43] Date=2026-05-23T08:14:00 Deploy.Action=Upgrade Deploy.Reason=Security Comments= < - Updated the Git Repository - Updated copyright year - Minimum Perl version is v5.6.0 - Added missing prerequisites, fixes RT#116392 - Security: Use system randomness source to generate the salt CVE-2026-47372 bsc#1265927 - Security: Use constant-time comparison of hashes CVE-2026-47373 bsc#1265912 - Deprecated module - Updated README ++++ powerpc-utils: - NUMA aware CPU hotplug (bsc#1263891 ltc#213837) * 0001-drmgr-Update-cpuless_lmb_count-NUMA-counter-during-L.patch * 0002-drmgr-Remove-only-available-LMBs-from-CPU-less-NUMA-.patch * 0003-drmgr-Move-numa_topology-code-to-common_numa.c.patch * 0004-drmgr-Move-read-lmb-size-property-code-to-common_ofd.patch * 0005-drmgr-Add-get_next_cpu-to-identify-the-removable-CPU.patch * 0006-drmgr-Allocate-CPU-bitmap-for-each-NUMA-node.patch * 0007-drmgr-Add-NUMA-configuration-update-for-CPU-remove.patch * 0008-drmgr-Add-NUMA-based-CPU-removal.patch * 0009-drmgr-Allow-signals-mentioned-in-new-sigset_t.patch * 0010-drmgr-Add-timeout-signal-handling-for-NUMA-memory-RE.patch (bsc#1265903 ltc#216658) * 0011-drmgr-Do-not-remove-LMBs-when-the-timer-expires.patch ++++ python-PyPDF2: - CVE-2026-41312: python-pypdf: crafed PDF can lead to resources exhaustion (bsc#1262675) CVE-2026-41314: python-pypdf: manipulated FlateDecode image dimensions can lead to RAM exhaustion (bsc#1262669) Add CVE-2026-413XX.patch - CVE-2026-41168: python-pypdf: crafed PDF with cross-reference streams can lead to long runtimes (bsc#1262676) Add CVE-2026-41168.patch ++++ rqlite: - Update to version 10.1.0: * Add Schema management page to Console app * Display node TLS state in console's Cluster panel - includes changes from 10.0.6: * Limit number of redirects followed on cluster-join * fix HTTP auth reporting ------------------------------------------------------------------ ------------------ 2026-5-20 - May 20 2026 ------------------- ------------------------------------------------------------------ ++++ amazon-ecs-init: - Add CVE-2026-33814.patch to fix hanging Transport in http2 code due to bad SETTINGS frame (bsc#1265843, CVE-2026-33814) ++++ apache2: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-devel: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-devel: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-event: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-event: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-manual: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-manual: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-prefork: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-prefork: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-utils: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-utils: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-worker: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ apache2-worker: * Fix bsc#1263952 / CVE-2026-33857. * Fix bsc#1263954 / CVE-2026-33007. * Fix bsc#1264163 / CVE-2026-28780. * Fix bsc#1264150 / CVE-2026-29168. * Add patch files: - CVE-2026-33857.patch - CVE-2026-33007.patch - CVE-2026-28780.patch - CVE-2026-29168.patch ++++ atril: - Update to version 1.28.4 (bsc#1265880 CVE-2026-46519): * Build fixes * Fix tests imported from XReader * Fix tests with AT-SPI2 >= 2.53 * Improve search system * pdf: Always use poppler_document_save to avoid data loss * Use properties for can-zoom-in and -out * libview: Allow zooming to the limits of the scale * shell: Fix Max zoom in UI - Migrate to xz compression and manual service run. ++++ kernel-64kb: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-64kb: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-64kb: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-azure: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-azure: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-azure: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-default: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-default: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-default: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-rt: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-rt: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-rt: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ cockpit: - Add CVE-2026-4802.patch to backport upstreams fix for bsc#1265040/CVE-2026-4802 ++++ crypto-policies: - Remove crypto-policies-Allow-sshd-in-FIPS-mode-using-DEFAULT.patch to allow X25519 as required for sntrup761x25519-sha512@openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) Rebase crypto-policies-Allow-openssl-other-policies-in-FIPS-mode.patch ++++ dtb-aarch64: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ dtb-aarch64: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ dtb-aarch64: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ freerdp: - Update to version 3.26.0: + CVE fixes: * CVE-2026-40033 (bsc#1266317) * CVE-2026-44420 (bsc#1267008) * CVE-2026-44421 (bsc#1267009) * CVE-2026-44422 (bsc#1267010) * CVE-2026-45700 (bsc#1267011) * Monitor https://github.com/FreeRDP/FreeRDP/security/advisories for updates + Bug and security fixes release + Changes: * cmake: Findyuv: Use correct pkgconfig name (#12666) * Remove deallocator attribute from rfx_message_free (#12681) * [winpr,utils] improve winpr/ntlm.h (#12677) * rdpecam-v4l: stop the capture thread when streaming is cleared (#12690) * fix(winpr,ncrypt): support PIV retired key slots for smartcard logon (#12684) * [core,instance] fix deprecation guards (#12691) * [ci,alt-arch] enable internal MD4, MD5 and RC4 (#12692) * Add VideoToolbox H.264 support for ffmpeg (#12694) * [client,common] add /args-from:file: syntax (#12697) * [ci,freebsd] update freebsd builds (#12698, #12700, #12701, #12702) * [client, android] UI modernization, SQLCipher and more (#12685, #12686, #12687, #12730, * #12731, #12736, #12737, #12688) * [cmake,deps] use alias target for sso-mib (#12706) * [core,settings] add auto reconnect triggered flag (#12709) * Force YUV420P when videotoolbox is used (#12711) * Release cleanups (#12712) * [gdi,gfx] fix bounds checks and proxy unit tests (#12713) * Improved input checks (#12714) * [winpr,utils] add unit tests for command line parser (#12716) * Cmdline fixes (#12717) * [codec,planar] fix bounds checks (#12718) * [client,common] add freerdp_client_settings_parse_command_line_argume… (#12724) * [winpr,sspi] clean up ntlm code (#12732) - Update to version 3.25.0: + CVE fixes: * CVE-2026-40254 (bsc#1262743) + Bug and security fixes release: * Experimental AV1 support has been added. This currently works only with FreeRDP based servers. * Most notably there is now support for [MS-RDPEWA] (FIDO2 redirection) * Android client received a (small) facelift * Improved SDL3 client drawing performance * Console output support for SDL3 (windows) and windows native client * RDP proxy now supports NSCodec and RFX modes. * RDP PRoxy now has smartcard emulation and SAM file support (via config file) * Smartcard KSP support for NLA authentication + Changes: * [winpr,wlog] add WLog_SetGlobalPrefix (#12497) * [channels,video] fix wrong cast (#12511) * [codec,openh264] reject encoder ABI mismatch on runtime-loaded library (#12510) * [client,sdl] create a copy of rdpPointer (#12512) * [codec,video] properly pass intermediate format (#12518) * [utils, signal] lazily initialize Windows CRITICAL_SECTION to match POSIX static mutex behavior (#12520) * winpr: improve libunwind backtraces (#12530) * [server,shadow] remember selected caps (#12528) * Zero credential data before free in NLA and NTLM context (#12532) * [server,proxy] ignore missing client in input channel (#12536) * [server,proxy] ignore rdpdr messages (#12537) * [winpr,sspi] improve kerberos logging (#12538) * Codec fixes (#12542) * [winpr,sspi] Fix context nullptr handling (#12543) * Dev 3.24.3 dev0 (#12545) * Fix memory leak in gdi_create_bitmap() on gdi_CreateBitmap failure (libfreerdp/gdi/graphics.c) (#12547) * Fix memory leak in vgids_read_do_fkt() on Stream_New failure (libfreerdp/emu/scard/smartcard_virtual_gids.c) (#12548) * Proxy config improve (#12549) * Proxy config improve (#12550) * [client,sdl] clamp cursor hotspot (#12553) * RFC: Research/av1 codec extension (#12527) * [winpr,kerberos] fix krb_log_context_encryption (#12555) * [client,sdl] fix global init return check (#12558) * Fix remote credential with windows11h2 (#12560) * Proxy scard auth improvements (#12561) * [winpr,sspi] guard krb5_get_etype_info (#12562) * [utils,smartcard] fix STATUS_BUFFER_TOO_SMALL (#12564) * [client,common] do not manipulate security settings for smartcard-logon (#12567) * [channels,audin] fix regression for microphone (#12570) * [client,sdl] add SDL_KMOD_MODE and SDL_KMOD_LEVEL5 (#12569) * Fix unbound strlen on slotDescription (#12571) * build: Update FindFFmpeg.cmake to support Apple frameworks with 'lib' prefix (#12565) * [channels,rdpewa] add WebAuthn virtual channel support (#12572) * [core] fix freerdp_get_nla_sspi_error always returning 0 on client (#12574) * [ci] enable rdpewa channel (#12576) * small refactoring (#12578) * Rdpewa unify notifications (#12581) * [client,sdl] fix crash when clicking 'cancel' on PIN popup (#12580) * [channels,drive] refine bounds checks (#12584) * fix: smartcard logon with ECC keys and minidriver-assigned container names (#12585) * Various papercuts (#12583) * fix: console output on Windows client (#12573) * [winpr,crt] dump stack on aligned memory errors (#12588) * [client,x11] keep scancode input for Ctrl/Alt/Super combinations in /kbd:unicode mode (#12590) * [codec,progressive] fix underflow guard in progressive_rfx_quant_sub (#12592) * fix: wfreerdp floatbar visibility (#12594) * [winpr,json] return a copy from WINPR_JSON_Print* (#12595) * [client,sdl] drop WITH_DEBUG_SDL_EVENTS (#12599) * Ncrypt and asn1 cleanup (#12604) * Video channel fix (#12593) * [codec,h264] fix media foundation backend (#12606) * fix(sdl): detect Hyprland and river in tryFallback() (#12608) * Proxy stress fixes (#12597) * Add new fuzzer tests (#12613) * fix(sdl): use SDL_Renderer instead of software surfaces (#12607) * fix(sdl): BFS neighbor walk pop/begin mismatch in addOrUpdateDisplay (#12614) * fix(sdl): promote first monitor as primary when subset excludes primary (#12618) * [ci,android] default to only aarch64 (#12622) * Fix process exit code on non-pidfd platforms (macOS, BSD)#12534) (#12586) * warning cleanups (#12626) * fix: prevent PostQuitMessage in RemoteApp WM_DESTROY handler (#12629) * [winpr,ntlm] fix message cleanup across the SSPI lifecycle (#12609) * Code bug fixes (#12632) * Oss fixes (#12633) * [client,android] add an option to enable keeping screen on when connected (#12630) * [client, android] Fix layout overlaps, migrate to AndroidX, and update UI components (#12628) * Proxy config tests (#12636) * Proxy config optional targethost (#12637) * [client,sdl] set SDL_HINT_SCREENSAVER_INHIBIT_ACTIVITY_NAME (#12639) * Nightly deb fix (#12640, #12641, #12649, #12650, #12642, #12643) * [winpr,input] fix korean keyboard mapping (#12646) * [client,sdl] set hints before SDL_Init (#12644) * Sdl inhibit option (#12647) * [client,X11] fix residual race in xf_clipboard_formats_free (#12648) * (sdl3): Fix oversized window on HiDPI Wayland (#12635) * [cache,bitmap] fix off-by-one in bitmap_cache_put bounds check (#12651) * [winpr,sspi] free fields buffer immediately (#12654) * [codec,dsp] fix fencepost error in dsp_ima_clamp_step (#12655) ++++ libheif: - update to 1.22.0: * This is a large release with substantial new functionality, mainly focusing on generalized image formats (e.g., multi- spectral images) and a reworked implementation of ISO/IEC 23001-17 (lossless image codec). * HDR up to 64 bpp * Multi-component images with arbitrary component layouts (multi-spectral images, arbitrary non-visual data) * Filter-array (Bayer / mosaic) images, with debayering in color transformation pipeline * Metadata: chroma-sample location (cloc), sample non- uniformity (snuc), sensor bad-pixel map (sbpm), polarization pattern (splz) * heif-dec can now convert to WebP (thanks to @torusrxxx). * heif-enc can now accept input from WebP, HEIF, pure raw files (including floating point pixel data), and CMYK JPEG (converted to RGB). * TIFF input can now read many TIFF formats used in geospatial imaging, like: 16-bit, signed integers, float samples, tiled TIFFs, GeoTIFF overview images, CMYK JPEG, YCbCr-as-JPEG. TIFFs with image tiling and multi-resolution layers are now reproduced as HEIFs when converted. * PNG decoder/encoder: cICP, cLLI, and mDCV chunk support (#1697). * heif-dec: auto-correct option to fix known input errors (e.g. mismatched NCLX/VUI). * Image, Track, Sequence samples, image component GIMI content IDs * Embedding of Turtle (.ttl) metadata files; automatic parsing of GIMI content IDs from Turtle * AOM encoder plugin now auto-selects IQ tune mode * mini-box syntax updated to the current HEIF version 4 draft (thanks @bradh for the initial implementation) * unif brand (globally-unique-ID) support * OMAF (omnidirectional images): indicate ISO/IEC 23000-22 spherical/omnidirectional image projection * alpha bit-depth tracked through the color-conversion pipeline * CVE-2026-32738 (GHSA-7f2h-cmpf-v9ww) : Heap OOB Read / SEGV Crash via Zero samples_per_chunk in stsc (bsc#1265874) * CVE-2026-32739 (GHSA-j9g7-q9hv-gq8c) : Infinite Loop DoS in stts Sample Duration Lookup (bsc#1265875) * CVE-2026-32740 (GHSA-frfr-f3vg-2g6j) : Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing (bsc#1265876) * CVE-2026-32741 (GHSA-j3w5-7whq-p37q) : heap buffer overflow in decode_mask_image() (bsc#1265877) * CVE-2026-32814 (GHSA-4m8r-34pg-rvwc) : Uninitialized Heap Memory Information Leak via Failed Grid Tiles (bsc#1265878) * CVE-2026-32882 (GHSA-hg7q-rjr2-8x46) : Heap Buffer OOB Read in overlay compositing due to wrong alpha stride (bsc#1265879) * CVE-2026-41069 (GHSA-p82x-fpmv-576r) : Out-of-bounds vector access leading to invalid dereference (bsc#1265979) * CVE-2026-41071 (GHSA-xj92-xjff-h8w3) : Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count (bsc#1265980) * CVE-2026-47178 (GHSA-5x55-x5pf-9c6g) : Heap Out Of Bounds Write in unci subsystem (bsc#1265981) * CVE-2026-47247 (GHSA-2vh6-whr3-cmq3) : Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation (bsc#1265982) * CVE-2026-47251 (GHSA-p6q9-fhf2-vj9v) : Incomplete fix for (bsc#1265983) CVE-2026-3949: integer overflow bypass in vvdec_push_data2 * CVE-2026-47254 (GHSA-wqjg-4x9g-6cvg) : Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Access (bsc#1265987) * CVE-2026-47709 (GHSA-4h72-vqgp-9376) : NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe (bsc#1265988) * CVE-2026-47714 (GHSA-h4wm-6wwf-qvhx) : Integer overflow in inline mask size calculation causes undersized buffer allocation (bsc#1265989) * CVE-2026-48029 (GHSA-6x5f-qchq-cxqv) : heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile- coordinate underflow (bsc#1265990) * (GHSA-95jx-g5vf-cpp8) : Integer Overflow in SampleAuxInfoReader Offset Calculation (bsc#1265992) * (GHSA-p4r6-6972-g26m) : Incorrect byte-count initialization in BitstreamRange constructor allows container-boundary check bypass (bsc#1265995) * (GHSA-jh2w-m72q-q595) : Out-of-bounds read and assertion- based DoS in EXIF parsing (find_exif_tag / read32) with short EXIF TIFF payload (bsc#1265996) * (GHSA-9h96-c44j-jpq9) : Heap buffer overflow via uint32_t stride overflow in image plane allocation (bsc#1265997) * ## Build / CI * requires C++20 * oss-fuzz integration overhauled * fuzzers for tile API, generic API surface, and per-codec encoders - drop libheif-CVE-2026-3950.patch, libheif-CVE-2026-3949.patch: upstream ++++ google-cloud-sap-agent: - Add CVE-2026-33814.patch to fix hanging Transport in http2 code due to bad SETTINGS frame (bsc#1265764, CVE-2026-33814) ++++ hauler: - update x/net to v0.53.0 to address CVE-2026-33814 (bsc#1265765) ++++ hauler: - update x/net to v0.53.0 to address CVE-2026-33814 (bsc#1265765) ++++ hauler: - update x/net to v0.53.0 to address CVE-2026-33814 (bsc#1265765) ++++ hwinfo: - merge gh#openSUSE/hwinfo#178 - fix memory leaks in pci and pppoe modules (bsc#1265908) - avoid NULL pointer in ADD2LOG() call - 25.3 ++++ hwinfo: - merge gh#openSUSE/hwinfo#178 - fix memory leaks in pci and pppoe modules (bsc#1265908) - avoid NULL pointer in ADD2LOG() call - 25.3 ++++ kernel-source: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-source: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-source: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-docs: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-docs: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-docs: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-kvmsmall: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-kvmsmall: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-kvmsmall: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-obs-build: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-obs-build: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-obs-build: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-obs-qa: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-obs-qa: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-obs-qa: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-syms: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-syms: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-syms: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-zfcpdump: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-zfcpdump: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ kernel-zfcpdump: - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018 CVE-2026-23271). - commit 1c3b58a - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - commit c0de598 - xfs: avoid dereferencing log items after push callbacks (CVE-2026-31453 bsc#1262617). - commit 682fb9c - kernel-binary: prevent uncompressed vmlinux from inflating rpm size requirements define %__spec_install_post to truncate the uncompressed vmlinux to 0 bytes after find-debuginfo.sh and brp-* scripts run. This prevents rpmbuild from baking the %ghost file size into the FILESIZES header, which can cause installation failures on smaller /boot partitions. Fixes: bsc#1265456 - commit 222edac - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626 CVE-2026-43494). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - commit dc2b91c - ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (git-fixes). - commit 02b019a ++++ openjpeg2: - Add openjpeg2-cve-2025-54874-short-header-oob.patch (CVE-2025-54874, bsc#1247650). ++++ papers: - Update to version 48.10 (bsc#1265880): + escape link arguments before spawning a new process (related to CVE-2026-46529 of Evince) ++++ nginx: - Add CVE-2026-42945.patch: Fix heap buffer overflow via crafted HTTP requests in ngx_http_rewrite_module (bsc#1265232) - Add CVE-2026-42946.patch: Fix excessive memory allocation and data overread in ngx_http_scgi_module/ngx_http_uwsgi_module (bsc#1265233) - Add CVE-2026-42934.patch: Fix heap buffer overread in the worker process within ngx_http_charset_module (bsc#1265231) - Add CVE-2026-40701.patch: Fix heap use-after-free in the worker process when ssl_verify_client and ssl_ocsp are set (bsc#1265229) - Add CVE-2026-32647.patch: Prevent worker memory over-read or over-write via malicious MP4 files (bsc#1260420) - Add CVE-2026-27651.patch: Fix denial of service via undisclosed requests when ngx_mail_auth_http_module is active (bsc#1260415) ++++ nginx: - Add CVE-2026-42945.patch: Fix heap buffer overflow via crafted HTTP requests in ngx_http_rewrite_module (bsc#1265232) - Add CVE-2026-42946.patch: Fix excessive memory allocation and data overread in ngx_http_scgi_module/ngx_http_uwsgi_module (bsc#1265233) - Add CVE-2026-42934.patch: Fix heap buffer overread in the worker process within ngx_http_charset_module (bsc#1265231) - Add CVE-2026-40701.patch: Fix heap use-after-free in the worker process when ssl_verify_client and ssl_ocsp are set (bsc#1265229) - Add CVE-2026-32647.patch: Prevent worker memory over-read or over-write via malicious MP4 files (bsc#1260420) - Add CVE-2026-27651.patch: Fix denial of service via undisclosed requests when ngx_mail_auth_http_module is active (bsc#1260415) ++++ openssh: - Add patch to fix a potential issue when validating mac or ciphers (bsc#1264568): * fix-mac-validation-strsep-logic-bug.patch ++++ salt: - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Added: * use-non-vendored-tornado-with-python-3.11.patch ++++ salt-test: - Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) - Added: * use-non-vendored-tornado-with-python-3.11.patch ++++ trento-web: - Release 3.1.0 [#]# What's Changed * Update NodeJS dependency to v24 (#4039) @skrech * FIx flaky check result test (#4303) @balanza * Fix flaky about page test (#4304) @balanza * Fix flaky suma settings test (#4305) @balanza * Stabilize HANA database details deregistration (#4309) @vicenteqa * Update reference to gen rmq (#4306) @chargio * Fix flaky notification box test (#4302) @balanza * Fix flaky patch list test (#4301) @balanza * Update Phoenix to 1.7.23 (#4273) @balanza * fix: use dynamic future date in SettingsPage API key expiration test (#4298) @[copilot-swe-agent[bot]](https://github.com/apps/copilot-swe-agent) * Stabilize hosts overview navigation tests (#4291) @vicenteqa * Fix flaky test on user form (#4294) @balanza * Fix flaky test on personal access token (#4293) @balanza * Fix wanda versioning (#4278) @balanza * Fix flaky tests hana db details & host details (#4286) @vicenteqa * [TRNT-4358] Remove wrong headers (#4276) @antgamdia * Send warning to #proj-trento-bots when failure rate of flaky tests analysis jobs exceeds a threshold. (#4275) @vicenteqa * Persist the number of elements when clicking again on the same page (#4272) @balanza * [TRNT-4358] Add license headers (#4237) @antgamdia * Add agent version filter in the host overview page (#4217) @balanza * Fix timezone flaky test (#4270) @nelsonkopliku * Fix polyfilled warning in frontend UT (#4256) @arbulu89 * Remove not needed act usage from tests to silence warning (#4253) @arbulu89 * Prune events cron job (#4244) @balanza * Fix test modal component not wrapped in `act` warning (#4255) @arbulu89 * Fix copy button usage warning in test (#4252) @arbulu89 * Add timings file for cypress split plugin (#4241) @vicenteqa * Fix CheckResultDetailPage.test warnings (#4243) @arbulu89 * Refactor selector warnings (#4235) @arbulu89 * Refactor table filter tests (#4220) @arbulu89 * Adapt e2e tests for remote instance (#4210) @vicenteqa * Fix misused waitFor (#4224) @balanza * Fix flaky async test (#4223) @balanza * Add component versioning (#4155) @balanza * Detect majority maker nodes (#4188) @balanza * Separate elixir test and coveralls upload (#4221) @balanza * modify cron for scheduled flaky tests jobs (#4199) @vicenteqa * Ai onboarding e2e (#4166) @nelsonkopliku * AI onboarding UI: show current config (#4160) @nelsonkopliku * Remove saptune operation forbidden msg (#4157) @arbulu89 * [TRNT-4326] Add cleanup in Dockerfile (#4156) @antgamdia * Preserve pagination (#4114) @balanza * Fix log level on production config (#4141) @balanza * [TRNT-4317] Pin GHA to SHA instead of tags (#4139) @antgamdia * Preserve table filters on browser history (#4101) @balanza * Host metrics API (#4096) @balanza * Updated dependencies to avoid old phoenix view (#4104) @chargio * Add test release job (#4090) @balanza * Add missing heartbeat config key (#4089) @balanza * [TRNT-4227] Add additional labels to the container image (#4050) @antgamdia * Host heartbeat config (#4082) @balanza * Fix flaky test: should not be able to login with deleted user (#4076) @vicenteqa * Make flaky tests analysis data flow to dashboard (#4065) @vicenteqa * Reusable workflow for flaky tests analysis jobs (#4037) @vicenteqa * Add hana-scale-up-multi-tier photofinish scenario (#4018) @skrech * Expected exporters (#3988) @balanza * Add last reboot info (#3950) @balanza * Check lockfile integrity (#3957) @balanza * Update lockfile (#3951) @balanza * Add last login e2e tests (#3936) @arbulu89 * Host last reboot (#3932) @balanza * Fix typo in changelog (#3937) @balanza [#]## Features * Load OS CA certificates when calling wanda (#4297) @nelsonkopliku * Display empty swap chart when data is not available (#4289) @arbulu89 * Analytics Modal Docs Link (#4267) @jagabomb * Analytics - Mask events data (#4287) @arbulu89 * Ai assistant UI core (#4245) @nelsonkopliku * Add Filesystem type filter to File System Capacity chart (#4274) @arbulu89 * Add navigation links for clusters, SAP systems and databases in tables (#4269) @arbulu89 * [TRNT-4339] Add timezone awareness (#4242) @antgamdia * Improve SAP link tooltip (#4222) @arbulu89 * Reword forbidden operation modal texts (#4216) @arbulu89 * Group operation abilities by resource (#4212) @arbulu89 * Unify select component (#4192) @arbulu89 * Validate operation request site parameter in database operation policy (#4211) @arbulu89 * Improve database start/stop operation policies to handle multi-tier setup (#4172) @arbulu89 * Add resources links in operation forbidden modal (#4162) @arbulu89 * Ai onboarding UI create/update (#4163) @nelsonkopliku * Remove unnecessary LLMRegistry.get_model_provider/1 function (#4168) @nelsonkopliku * Create/update AI Configuration (#4147) @nelsonkopliku * Expose AI configuration in profile (#4143) @nelsonkopliku * Basic AI config functions (#4140) @nelsonkopliku * Rename cluster start stop op frontend text (#4161) @arbulu89 * Operation request failed (#4133) @arbulu89 * Add basic AI provider/models configuration (#4127) @nelsonkopliku * Multi tier database start/stop operations (#4081) @arbulu89 * Save system replication tier when the instance is stopped (#4103) @arbulu89 * Improve database operation forbidden usage whe heartbeat is not passing (#4094) @arbulu89 * Filesystem chart UI (#4095) @nelsonkopliku * Operations forbidden button based on heartbeat (#4085) @arbulu89 * Operations heartbeat passing required (#4080) @arbulu89 * Force to send cluster operation to host with passing heartbeat (#4078) @arbulu89 * Expose filesystem usage metrics (#4079) @nelsonkopliku * Set default Unknown value to system replicaiton in cluster discovery (#4070) @arbulu89 * Prom query filesystem metrics (#4072) @nelsonkopliku * Consolidate http client usage in Prometheus API (#4064) @nelsonkopliku * Update prometheus references in local docker compose (#4054) @nelsonkopliku * Parse operation completed errors (#4043) @arbulu89 * Make prometheus reverse proxy upstream variable (#4044) @nelsonkopliku * Show cluster state (#4032) @arbulu89 * update template to point to docs (#4020) @EMaksy * Replace npm install with npm ci (#4004) @EMaksy * SSO enabled profile update (#3985) @arbulu89 * Enable analytics and add e2e tests (#3975) @arbulu89 * Operation 2 stage modal (#3976) @nelsonkopliku * Cluster resources refresh operation frontend usage (#3970) @arbulu89 * Handle Prometheus push mode (#3972) @balanza * Operations hardcoded routing (#3971) @arbulu89 * Analytics - Add Google Tag Manager usage (#3877) @arbulu89 * Cluster resource refresh (#3963) @arbulu89 * Improve details about still running instances for reboot operation (#3964) @nelsonkopliku * Revisit saptune operations policy (#3962) @nelsonkopliku * Rephrase operations disclaimer message (#3958) @nelsonkopliku * Add last login at timestamp (#3930) @arbulu89 [#]## Bug Fixes * Fix refresh token flow execution in frontend (#4249) @arbulu89 * Use clustered SAP system/database instances to create SAP system link (#4234) @arbulu89 * Update sles subscription on host deregister (#4213) @arbulu89 * Make sure heartbeat interval is runtime env (#4120) @nelsonkopliku * Fix SR failing discovery with more than 2 nodes (#3990) @skrech * Analytics Storybook Fix (#3983) @jagabomb * CI - Fix PR-ENV docker-network-name (#3982) @skrech * CI - Correct ansible args on PR-ENV (#3980) @skrech * Analytics Eula Modal Fix (#3973) @jagabomb [#]## Maintenance * Fix npm11/node24 resolution problem with optional peerDep (#4321) @skrech * Set late in the day scheduled execution and specify timezone for flaky tests jobs (#4308) @vicenteqa * [TRNT-4376] Align DB dependencies (#4290) @antgamdia * Turn off AI features (#4277) @nelsonkopliku * Addded a short version tag for OBS container image packaging (#4288) @skrech * [TRNT-4358] Add license headers linter (#4236) @antgamdia * [TRNT-4358] Update LICENSE to match Apache-2.0 verbatim text (#4240) @antgamdia * Fix storybook PLACES not found warning (#4268) @arbulu89 * Apply eslint rules to prefer arrow functions in test folder (#4219) @vicenteqa * Exclude common workflows from cooldown and group them into single PR (#4189) @skrech * [TRNT-1598] Extract versions to env in CI (#4170) @antgamdia * Group dependabot eslint updates & Add e2e deps to dependabot config (#4177) @vicenteqa * Fix flaky tests jobs schedules (#4175) @vicenteqa * Build pr env image with pr branch (#4158) @arbulu89 * Fix publish-containers config on release workflow (#4159) @skrech * Fix wrong conditions for demo deploy (#4153) @skrech * New release process (#4146) @skrech * Common obs-sync and switch to git-flow for rolling builds (#4142) @skrech * Implements dependabot cooldown (#4134) @gagandeepb * Use common publish-containers workflow in CI (#4102) @skrech * Disable prometheus in demo (#4100) @nelsonkopliku * [TRNT-4227] Add missing arg in dockerfile (#4087) @antgamdia * Set trento_prometheus_auth in PR env CI (#4071) @arbulu89 * Preserve flaky-tests directory on gh-pages deployment (#4068) @vicenteqa * Remove compile time usage of UTC as default value (#4060) @arbulu89 * Workaround api_docs_checks linter to use previous version (#4066) @arbulu89 * Add State value in ha_cluster_discovery photofinish payloads (#4040) @arbulu89 * Cluster state e2e tests (#4036) @arbulu89 * Add prometheus hosts for ansible PR usage (#4035) @arbulu89 * Make docker-compose SElinux-compatible (#3986) @skrech * Increase the :pool_size when running tests (#3991) @skrech * Analytics Storybook Fix (#3983) @jagabomb * Package analytics GTM_ID value (#3987) @arbulu89 * Bump BCI references to 15.7 (#3984) @nelsonkopliku * CI - Fix PR-ENV docker-network-name (#3982) @skrech * CI - Correct ansible args on PR-ENV (#3980) @skrech * [TRNT-4139] Update unversioned paths in API calls (#3956) @antgamdia * Fix package-lock.json after last PR (#3960) @skrech [#]## Dependencies
163 changes * Bump fast-uri from 3.1.0 to 3.1.2 in /assets (#4280) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the common-workflows group with 3 updates (#4311) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump cypress-io/github-action from 7.1.9 to 7.1.10 (#4316) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump fast-uri from 3.1.0 to 3.1.2 in /test/e2e (#4279) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/plugin-transform-modules-systemjs from 7.29.0 to 7.29.4 in /test/e2e (#4284) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump globals from 17.5.0 to 17.6.0 in /test/e2e (#4315) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/preset-env from 7.29.2 to 7.29.3 in /assets (#4310) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the eslint group in /test/e2e with 2 updates (#4314) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 16.6.0 to 16.6.3 (#4318) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump prettier from 3.8.1 to 3.8.3 in /assets (#4263) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.4 to 5.0.5 (#4258) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.5.0 to 2.6.0 (#4259) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/github-script from 8.0.0 to 9.0.0 (#4227) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.3.3 to 10.3.6 in /assets (#4230) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump axios from 1.15.0 to 1.16.1 in /assets (#4271) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump prettier from 3.8.1 to 3.8.3 in /test/e2e (#4261) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump npm from 11.12.1 to 11.13.0 in /test/e2e (#4282) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/plugin-transform-modules-systemjs from 7.29.0 to 7.29.4 in /assets (#4285) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump autoprefixer from 10.4.27 to 10.5.0 in /assets (#4260) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the eslint group across 1 directory with 2 updates (#4262) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 16.1.0 to 16.6.0 (#4283) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.364.6 to 1.369.3 in /assets (#4265) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the common-workflows group with 3 updates (#4281) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump systeminformation from 5.31.5 to 5.31.6 in /test/e2e (#4296) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump protobufjs from 7.5.5 to 7.5.8 in /assets (#4295) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the cypress group across 1 directory with 3 updates (#4179) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump postcss from 8.4.49 to 8.5.12 in /test/e2e (#4248) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump postcss from 8.5.8 to 8.5.12 in /assets (#4247) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#4231) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the eslint group across 1 directory with 3 updates (#4181) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.3.3 to 10.3.4 in /assets (#4206) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.4 to 0.28.0 in /assets (#4205) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-docs from 10.3.3 to 10.3.4 in /assets (#4204) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 4.0.0 to 4.1.0 (#4203) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump totp-generator from 1.0.0 to 2.0.1 in /test/e2e (#4202) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 16.0.0 to 16.1.0 (#4201) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump protobufjs from 7.5.4 to 7.5.5 in /assets (#4198) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.364.3 to 1.364.4 in /assets (#4191) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dompurify from 3.3.2 to 3.4.0 in /assets (#4193) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/core from 7.28.5 to 7.29.0 in /assets (#4185) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump npm from 10.9.6 to 11.12.1 in /test/e2e (#4184) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump date-fns from 3.3.1 to 4.1.0 in /test/e2e (#4183) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/preset-env from 7.29.0 to 7.29.2 in /assets (#4180) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump prettier from 2.6.2 to 3.8.1 in /test/e2e (#4182) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump openapi-diff from 2.0.1 to 2.1.7 (#4194) @antgamdia * Bump the common-workflows group with 3 updates (#4190) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump follow-redirects from 1.15.11 to 1.16.0 in /assets (#4176) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump postcss from 8.5.6 to 8.5.8 in /assets (#4150) @[dependabot[bot]](https://github.com/apps/dependabot) * Updating mix dependencies for liveview to 1.1 (#4173) @chargio * Bump axios from 1.13.5 to 1.15.0 in /assets (#4167) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.0.0 to 1.5.1 (#4151) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump jest from 30.2.0 to 30.3.0 in /assets (#4152) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.23 to 4.18.1 in /test/e2e (#4145) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.23 to 4.18.1 in /assets (#4144) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump babel-jest from 30.2.0 to 30.3.0 in /assets (#4137) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/compat from 2.0.2 to 2.0.3 in /assets (#4136) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump semver from 7.7.3 to 7.7.4 in /assets (#4135) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/setup-buildx-action from 3 to 4 (#4062) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 15.3.0 to 16.0.0 in /assets (#4128) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump jaxxstorm/action-install-gh-release from 2.1.0 to 3.0.0 (#4132) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-jest from 29.12.2 to 29.15.1 in /assets (#4131) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.358.1 to 1.364.2 in /assets (#4130) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @faker-js/faker from 10.3.0 to 10.4.0 in /assets (#4129) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump brace-expansion from 1.1.12 to 1.1.13 in /test/e2e (#4126) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.13.0 to 7.13.2 in /assets (#4124) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-error-boundary from 6.0.0 to 6.1.1 in /assets (#4123) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump minimatch in /test/e2e (#4125) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.2.6 to 10.3.3 in /assets (#4122) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump serialize-javascript and terser-webpack-plugin in /assets (#4121) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump babel-loader from 10.0.0 to 10.1.1 in /assets (#4118) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump jest-environment-jsdom from 30.2.0 to 30.3.0 in /assets (#4116) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump axios-auth-refresh from 3.3.6 to 5.0.2 in /assets (#4117) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-webpack5-compiler-babel from 4.0.0 to 4.0.1 in /assets (#4115) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump release-drafter/release-drafter from 6 to 7 (#4099) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump autoprefixer from 10.4.21 to 10.4.27 in /assets (#4108) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.3 to 0.27.4 in /assets (#4111) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-storybook from 10.2.8 to 10.3.3 in /assets (#4110) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump picomatch from 2.3.1 to 2.3.2 in /assets (#4112) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dawidd6/action-ansible-playbook from 7 to 9 (#4107) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump picomatch in /test/e2e (#4105) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 15.2.0 to 16.0.0 (#4109) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump stefanzweifel/git-auto-commit-action from 5 to 7 (#4093) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.2.6 to 10.2.15 in /assets (#4058) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump flatted from 3.2.5 to 3.4.2 in /test/e2e (#4091) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/build-push-action from 6 to 7 (#4074) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.336.4 to 1.358.1 in /assets (#4059) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 15.0.0 to 15.2.0 in /assets (#4057) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-docs from 10.2.4 to 10.2.15 in /assets (#4056) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 3.7.0 to 4.0.0 (#4055) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.2.6 to 10.2.8 in /assets (#4023) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump geekyeggo/delete-artifact from 5 to 6 (#4086) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump flatted from 3.3.3 to 3.4.2 in /assets (#4092) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dorny/paths-filter from 3 to 4 (#4083) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dompurify from 3.3.1 to 3.3.2 in /assets (#4067) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/checkout from 4 to 6 (#4073) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump tar and npm in /test/e2e (#4077) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 7 to 8 (#4046) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 6 to 7 (#4045) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.2 to 0.27.3 in /assets (#4031) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump storybook from 10.2.8 to 10.2.13 in /assets (#4047) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump minimatch from 3.1.2 to 3.1.5 in /assets (#4049) @[dependabot[bot]](https://github.com/apps/dependabot) * Make prettier npm dev dependency explicit (#4053) @arbulu89 * Remove unused eslint-prettier-cli (#4052) @arbulu89 * Fix npm yaml dependency missmatch (#4051) @arbulu89 * Bump ajv from 6.12.6 to 6.14.0 in /test/e2e (#4038) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 15.0.0 to 15.2.0 (#4041) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump qs from 6.14.1 to 6.14.2 in /test/e2e (#4033) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/compat from 2.0.0 to 2.0.2 in /assets (#4024) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump axios from 1.13.2 to 1.13.5 in /assets (#4027) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @faker-js/faker from 10.2.0 to 10.3.0 in /assets (#4025) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-storybook from 10.2.3 to 10.2.8 in /assets (#4026) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump webpack from 5.94.0 to 5.105.0 in /test/e2e (#4016) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-dom from 19.2.3 to 19.2.4 in /assets (#4009) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-jest from 29.9.0 to 29.12.2 in /assets (#4014) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @testing-library/react from 16.3.0 to 16.3.2 in /assets (#4013) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump webpack from 5.102.1 to 5.105.0 in /assets (#4017) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @faker-js/faker from 9.9.0 to 10.2.0 in /assets (#4010) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump html-webpack-plugin from 5.6.5 to 5.6.6 in /assets (#4015) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-webpack5-compiler-babel from 3.0.6 to 4.0.0 in /assets (#4002) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.2.3 to 10.2.6 in /assets (#4011) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump storybook from 10.2.5 to 10.2.6 in /assets (#4012) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 13.3.4 to 15.0.0 in /assets (#4003) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/preset-env from 7.28.5 to 7.29.0 in /assets (#4008) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 13.3.5 to 15.0.0 (#3998) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.2.3 to 10.2.4 in /assets (#3999) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump fishery from 2.3.1 to 2.4.0 in /assets (#4007) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.3 to 2.5.0 (#4006) @[dependabot[bot]](https://github.com/apps/dependabot) * Replace npm install with npm ci (#4004) @EMaksy * Bump @storybook/addon-docs from 10.1.11 to 10.2.4 in /assets (#4000) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-react-hooks from 5.2.0 to 7.0.1 in /assets (#3994) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.0.8 to 10.2.3 in /assets (#3995) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.309.1 to 1.336.4 in /assets (#3996) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-storybook from 10.0.8 to 10.2.3 in /assets (#3997) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dawidd6/action-ansible-playbook from 6 to 7 (#3992) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.12.0 to 7.13.0 in /assets (#3993) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/plugin-transform-modules-commonjs from 7.27.1 to 7.28.6 in /assets (#3966) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump tailwindcss from 3.4.18 to 3.4.19 in /assets (#3965) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 3.6.0 to 3.7.0 (#3989) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump cypress-io/github-action from 6 to 7 (#3979) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.21 to 4.17.23 in /assets (#3978) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.21 to 4.17.23 in /test/e2e (#3977) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/js from 9.39.1 to 9.39.2 in /assets (#3946) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-dom from 19.2.0 to 19.2.3 in /assets (#3944) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump preact from 10.27.2 to 10.28.2 in /assets (#3952) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump qs and @cypress/request in /test/e2e (#3955) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.0 to 0.27.2 in /assets (#3945) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.11.0 to 7.12.0 in /assets (#3954) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.2 to 2.4.3 (#3953) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-docs from 10.0.8 to 10.1.10 in /assets (#3943) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump storybook from 10.0.8 to 10.1.10 in /assets (#3941) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 13.3.4 to 13.3.5 (#3949) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dawidd6/action-ansible-playbook from 5 to 6 (#3947) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump mdast-util-to-hast from 13.2.0 to 13.2.1 in /assets (#3934) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/metadata-action from 5.9.0 to 5.10.0 (#3933) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.1 to 2.4.2 (#3935) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 4 to 5 (#3938) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 5 to 6 (#3939) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 6 to 7 (#3940) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.9.5 to 7.9.6 in /assets (#3928) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-jest from 29.1.0 to 29.2.1 in /assets (#3927) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.297.0 to 1.298.0 in /assets (#3926) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/compat from 1.4.1 to 2.0.0 in /assets (#3922) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 13.3.3 to 13.3.4 in /assets (#3921) @[dependabot[bot]](https://github.com/apps/dependabot)
* *Full Changelog**: https://github.com/trento-project/web/compare/3.0.0...3.1.0 ++++ trento-web: - Release 3.1.0 [#]# What's Changed * Update NodeJS dependency to v24 (#4039) @skrech * FIx flaky check result test (#4303) @balanza * Fix flaky about page test (#4304) @balanza * Fix flaky suma settings test (#4305) @balanza * Stabilize HANA database details deregistration (#4309) @vicenteqa * Update reference to gen rmq (#4306) @chargio * Fix flaky notification box test (#4302) @balanza * Fix flaky patch list test (#4301) @balanza * Update Phoenix to 1.7.23 (#4273) @balanza * fix: use dynamic future date in SettingsPage API key expiration test (#4298) @[copilot-swe-agent[bot]](https://github.com/apps/copilot-swe-agent) * Stabilize hosts overview navigation tests (#4291) @vicenteqa * Fix flaky test on user form (#4294) @balanza * Fix flaky test on personal access token (#4293) @balanza * Fix wanda versioning (#4278) @balanza * Fix flaky tests hana db details & host details (#4286) @vicenteqa * [TRNT-4358] Remove wrong headers (#4276) @antgamdia * Send warning to #proj-trento-bots when failure rate of flaky tests analysis jobs exceeds a threshold. (#4275) @vicenteqa * Persist the number of elements when clicking again on the same page (#4272) @balanza * [TRNT-4358] Add license headers (#4237) @antgamdia * Add agent version filter in the host overview page (#4217) @balanza * Fix timezone flaky test (#4270) @nelsonkopliku * Fix polyfilled warning in frontend UT (#4256) @arbulu89 * Remove not needed act usage from tests to silence warning (#4253) @arbulu89 * Prune events cron job (#4244) @balanza * Fix test modal component not wrapped in `act` warning (#4255) @arbulu89 * Fix copy button usage warning in test (#4252) @arbulu89 * Add timings file for cypress split plugin (#4241) @vicenteqa * Fix CheckResultDetailPage.test warnings (#4243) @arbulu89 * Refactor selector warnings (#4235) @arbulu89 * Refactor table filter tests (#4220) @arbulu89 * Adapt e2e tests for remote instance (#4210) @vicenteqa * Fix misused waitFor (#4224) @balanza * Fix flaky async test (#4223) @balanza * Add component versioning (#4155) @balanza * Detect majority maker nodes (#4188) @balanza * Separate elixir test and coveralls upload (#4221) @balanza * modify cron for scheduled flaky tests jobs (#4199) @vicenteqa * Ai onboarding e2e (#4166) @nelsonkopliku * AI onboarding UI: show current config (#4160) @nelsonkopliku * Remove saptune operation forbidden msg (#4157) @arbulu89 * [TRNT-4326] Add cleanup in Dockerfile (#4156) @antgamdia * Preserve pagination (#4114) @balanza * Fix log level on production config (#4141) @balanza * [TRNT-4317] Pin GHA to SHA instead of tags (#4139) @antgamdia * Preserve table filters on browser history (#4101) @balanza * Host metrics API (#4096) @balanza * Updated dependencies to avoid old phoenix view (#4104) @chargio * Add test release job (#4090) @balanza * Add missing heartbeat config key (#4089) @balanza * [TRNT-4227] Add additional labels to the container image (#4050) @antgamdia * Host heartbeat config (#4082) @balanza * Fix flaky test: should not be able to login with deleted user (#4076) @vicenteqa * Make flaky tests analysis data flow to dashboard (#4065) @vicenteqa * Reusable workflow for flaky tests analysis jobs (#4037) @vicenteqa * Add hana-scale-up-multi-tier photofinish scenario (#4018) @skrech * Expected exporters (#3988) @balanza * Add last reboot info (#3950) @balanza * Check lockfile integrity (#3957) @balanza * Update lockfile (#3951) @balanza * Add last login e2e tests (#3936) @arbulu89 * Host last reboot (#3932) @balanza * Fix typo in changelog (#3937) @balanza [#]## Features * Load OS CA certificates when calling wanda (#4297) @nelsonkopliku * Display empty swap chart when data is not available (#4289) @arbulu89 * Analytics Modal Docs Link (#4267) @jagabomb * Analytics - Mask events data (#4287) @arbulu89 * Ai assistant UI core (#4245) @nelsonkopliku * Add Filesystem type filter to File System Capacity chart (#4274) @arbulu89 * Add navigation links for clusters, SAP systems and databases in tables (#4269) @arbulu89 * [TRNT-4339] Add timezone awareness (#4242) @antgamdia * Improve SAP link tooltip (#4222) @arbulu89 * Reword forbidden operation modal texts (#4216) @arbulu89 * Group operation abilities by resource (#4212) @arbulu89 * Unify select component (#4192) @arbulu89 * Validate operation request site parameter in database operation policy (#4211) @arbulu89 * Improve database start/stop operation policies to handle multi-tier setup (#4172) @arbulu89 * Add resources links in operation forbidden modal (#4162) @arbulu89 * Ai onboarding UI create/update (#4163) @nelsonkopliku * Remove unnecessary LLMRegistry.get_model_provider/1 function (#4168) @nelsonkopliku * Create/update AI Configuration (#4147) @nelsonkopliku * Expose AI configuration in profile (#4143) @nelsonkopliku * Basic AI config functions (#4140) @nelsonkopliku * Rename cluster start stop op frontend text (#4161) @arbulu89 * Operation request failed (#4133) @arbulu89 * Add basic AI provider/models configuration (#4127) @nelsonkopliku * Multi tier database start/stop operations (#4081) @arbulu89 * Save system replication tier when the instance is stopped (#4103) @arbulu89 * Improve database operation forbidden usage whe heartbeat is not passing (#4094) @arbulu89 * Filesystem chart UI (#4095) @nelsonkopliku * Operations forbidden button based on heartbeat (#4085) @arbulu89 * Operations heartbeat passing required (#4080) @arbulu89 * Force to send cluster operation to host with passing heartbeat (#4078) @arbulu89 * Expose filesystem usage metrics (#4079) @nelsonkopliku * Set default Unknown value to system replicaiton in cluster discovery (#4070) @arbulu89 * Prom query filesystem metrics (#4072) @nelsonkopliku * Consolidate http client usage in Prometheus API (#4064) @nelsonkopliku * Update prometheus references in local docker compose (#4054) @nelsonkopliku * Parse operation completed errors (#4043) @arbulu89 * Make prometheus reverse proxy upstream variable (#4044) @nelsonkopliku * Show cluster state (#4032) @arbulu89 * update template to point to docs (#4020) @EMaksy * Replace npm install with npm ci (#4004) @EMaksy * SSO enabled profile update (#3985) @arbulu89 * Enable analytics and add e2e tests (#3975) @arbulu89 * Operation 2 stage modal (#3976) @nelsonkopliku * Cluster resources refresh operation frontend usage (#3970) @arbulu89 * Handle Prometheus push mode (#3972) @balanza * Operations hardcoded routing (#3971) @arbulu89 * Analytics - Add Google Tag Manager usage (#3877) @arbulu89 * Cluster resource refresh (#3963) @arbulu89 * Improve details about still running instances for reboot operation (#3964) @nelsonkopliku * Revisit saptune operations policy (#3962) @nelsonkopliku * Rephrase operations disclaimer message (#3958) @nelsonkopliku * Add last login at timestamp (#3930) @arbulu89 [#]## Bug Fixes * Fix refresh token flow execution in frontend (#4249) @arbulu89 * Use clustered SAP system/database instances to create SAP system link (#4234) @arbulu89 * Update sles subscription on host deregister (#4213) @arbulu89 * Make sure heartbeat interval is runtime env (#4120) @nelsonkopliku * Fix SR failing discovery with more than 2 nodes (#3990) @skrech * Analytics Storybook Fix (#3983) @jagabomb * CI - Fix PR-ENV docker-network-name (#3982) @skrech * CI - Correct ansible args on PR-ENV (#3980) @skrech * Analytics Eula Modal Fix (#3973) @jagabomb [#]## Maintenance * Fix npm11/node24 resolution problem with optional peerDep (#4321) @skrech * Set late in the day scheduled execution and specify timezone for flaky tests jobs (#4308) @vicenteqa * [TRNT-4376] Align DB dependencies (#4290) @antgamdia * Turn off AI features (#4277) @nelsonkopliku * Addded a short version tag for OBS container image packaging (#4288) @skrech * [TRNT-4358] Add license headers linter (#4236) @antgamdia * [TRNT-4358] Update LICENSE to match Apache-2.0 verbatim text (#4240) @antgamdia * Fix storybook PLACES not found warning (#4268) @arbulu89 * Apply eslint rules to prefer arrow functions in test folder (#4219) @vicenteqa * Exclude common workflows from cooldown and group them into single PR (#4189) @skrech * [TRNT-1598] Extract versions to env in CI (#4170) @antgamdia * Group dependabot eslint updates & Add e2e deps to dependabot config (#4177) @vicenteqa * Fix flaky tests jobs schedules (#4175) @vicenteqa * Build pr env image with pr branch (#4158) @arbulu89 * Fix publish-containers config on release workflow (#4159) @skrech * Fix wrong conditions for demo deploy (#4153) @skrech * New release process (#4146) @skrech * Common obs-sync and switch to git-flow for rolling builds (#4142) @skrech * Implements dependabot cooldown (#4134) @gagandeepb * Use common publish-containers workflow in CI (#4102) @skrech * Disable prometheus in demo (#4100) @nelsonkopliku * [TRNT-4227] Add missing arg in dockerfile (#4087) @antgamdia * Set trento_prometheus_auth in PR env CI (#4071) @arbulu89 * Preserve flaky-tests directory on gh-pages deployment (#4068) @vicenteqa * Remove compile time usage of UTC as default value (#4060) @arbulu89 * Workaround api_docs_checks linter to use previous version (#4066) @arbulu89 * Add State value in ha_cluster_discovery photofinish payloads (#4040) @arbulu89 * Cluster state e2e tests (#4036) @arbulu89 * Add prometheus hosts for ansible PR usage (#4035) @arbulu89 * Make docker-compose SElinux-compatible (#3986) @skrech * Increase the :pool_size when running tests (#3991) @skrech * Analytics Storybook Fix (#3983) @jagabomb * Package analytics GTM_ID value (#3987) @arbulu89 * Bump BCI references to 15.7 (#3984) @nelsonkopliku * CI - Fix PR-ENV docker-network-name (#3982) @skrech * CI - Correct ansible args on PR-ENV (#3980) @skrech * [TRNT-4139] Update unversioned paths in API calls (#3956) @antgamdia * Fix package-lock.json after last PR (#3960) @skrech [#]## Dependencies
163 changes * Bump fast-uri from 3.1.0 to 3.1.2 in /assets (#4280) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the common-workflows group with 3 updates (#4311) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump cypress-io/github-action from 7.1.9 to 7.1.10 (#4316) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump fast-uri from 3.1.0 to 3.1.2 in /test/e2e (#4279) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/plugin-transform-modules-systemjs from 7.29.0 to 7.29.4 in /test/e2e (#4284) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump globals from 17.5.0 to 17.6.0 in /test/e2e (#4315) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/preset-env from 7.29.2 to 7.29.3 in /assets (#4310) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the eslint group in /test/e2e with 2 updates (#4314) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 16.6.0 to 16.6.3 (#4318) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump prettier from 3.8.1 to 3.8.3 in /assets (#4263) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.4 to 5.0.5 (#4258) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.5.0 to 2.6.0 (#4259) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/github-script from 8.0.0 to 9.0.0 (#4227) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.3.3 to 10.3.6 in /assets (#4230) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump axios from 1.15.0 to 1.16.1 in /assets (#4271) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump prettier from 3.8.1 to 3.8.3 in /test/e2e (#4261) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump npm from 11.12.1 to 11.13.0 in /test/e2e (#4282) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/plugin-transform-modules-systemjs from 7.29.0 to 7.29.4 in /assets (#4285) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump autoprefixer from 10.4.27 to 10.5.0 in /assets (#4260) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the eslint group across 1 directory with 2 updates (#4262) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 16.1.0 to 16.6.0 (#4283) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.364.6 to 1.369.3 in /assets (#4265) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the common-workflows group with 3 updates (#4281) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump systeminformation from 5.31.5 to 5.31.6 in /test/e2e (#4296) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump protobufjs from 7.5.5 to 7.5.8 in /assets (#4295) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the cypress group across 1 directory with 3 updates (#4179) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump postcss from 8.4.49 to 8.5.12 in /test/e2e (#4248) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump postcss from 8.5.8 to 8.5.12 in /assets (#4247) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#4231) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the eslint group across 1 directory with 3 updates (#4181) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.3.3 to 10.3.4 in /assets (#4206) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.4 to 0.28.0 in /assets (#4205) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-docs from 10.3.3 to 10.3.4 in /assets (#4204) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 4.0.0 to 4.1.0 (#4203) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump totp-generator from 1.0.0 to 2.0.1 in /test/e2e (#4202) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 16.0.0 to 16.1.0 (#4201) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump protobufjs from 7.5.4 to 7.5.5 in /assets (#4198) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.364.3 to 1.364.4 in /assets (#4191) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dompurify from 3.3.2 to 3.4.0 in /assets (#4193) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/core from 7.28.5 to 7.29.0 in /assets (#4185) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump npm from 10.9.6 to 11.12.1 in /test/e2e (#4184) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump date-fns from 3.3.1 to 4.1.0 in /test/e2e (#4183) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/preset-env from 7.29.0 to 7.29.2 in /assets (#4180) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump prettier from 2.6.2 to 3.8.1 in /test/e2e (#4182) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump openapi-diff from 2.0.1 to 2.1.7 (#4194) @antgamdia * Bump the common-workflows group with 3 updates (#4190) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump follow-redirects from 1.15.11 to 1.16.0 in /assets (#4176) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump postcss from 8.5.6 to 8.5.8 in /assets (#4150) @[dependabot[bot]](https://github.com/apps/dependabot) * Updating mix dependencies for liveview to 1.1 (#4173) @chargio * Bump axios from 1.13.5 to 1.15.0 in /assets (#4167) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.0.0 to 1.5.1 (#4151) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump jest from 30.2.0 to 30.3.0 in /assets (#4152) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.23 to 4.18.1 in /test/e2e (#4145) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.23 to 4.18.1 in /assets (#4144) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump babel-jest from 30.2.0 to 30.3.0 in /assets (#4137) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/compat from 2.0.2 to 2.0.3 in /assets (#4136) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump semver from 7.7.3 to 7.7.4 in /assets (#4135) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/setup-buildx-action from 3 to 4 (#4062) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 15.3.0 to 16.0.0 in /assets (#4128) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump jaxxstorm/action-install-gh-release from 2.1.0 to 3.0.0 (#4132) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-jest from 29.12.2 to 29.15.1 in /assets (#4131) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.358.1 to 1.364.2 in /assets (#4130) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @faker-js/faker from 10.3.0 to 10.4.0 in /assets (#4129) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump brace-expansion from 1.1.12 to 1.1.13 in /test/e2e (#4126) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.13.0 to 7.13.2 in /assets (#4124) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-error-boundary from 6.0.0 to 6.1.1 in /assets (#4123) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump minimatch in /test/e2e (#4125) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.2.6 to 10.3.3 in /assets (#4122) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump serialize-javascript and terser-webpack-plugin in /assets (#4121) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump babel-loader from 10.0.0 to 10.1.1 in /assets (#4118) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump jest-environment-jsdom from 30.2.0 to 30.3.0 in /assets (#4116) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump axios-auth-refresh from 3.3.6 to 5.0.2 in /assets (#4117) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-webpack5-compiler-babel from 4.0.0 to 4.0.1 in /assets (#4115) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump release-drafter/release-drafter from 6 to 7 (#4099) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump autoprefixer from 10.4.21 to 10.4.27 in /assets (#4108) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.3 to 0.27.4 in /assets (#4111) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-storybook from 10.2.8 to 10.3.3 in /assets (#4110) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump picomatch from 2.3.1 to 2.3.2 in /assets (#4112) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dawidd6/action-ansible-playbook from 7 to 9 (#4107) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump picomatch in /test/e2e (#4105) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 15.2.0 to 16.0.0 (#4109) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump stefanzweifel/git-auto-commit-action from 5 to 7 (#4093) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.2.6 to 10.2.15 in /assets (#4058) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump flatted from 3.2.5 to 3.4.2 in /test/e2e (#4091) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/build-push-action from 6 to 7 (#4074) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.336.4 to 1.358.1 in /assets (#4059) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 15.0.0 to 15.2.0 in /assets (#4057) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-docs from 10.2.4 to 10.2.15 in /assets (#4056) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 3.7.0 to 4.0.0 (#4055) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.2.6 to 10.2.8 in /assets (#4023) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump geekyeggo/delete-artifact from 5 to 6 (#4086) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump flatted from 3.3.3 to 3.4.2 in /assets (#4092) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dorny/paths-filter from 3 to 4 (#4083) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dompurify from 3.3.1 to 3.3.2 in /assets (#4067) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/checkout from 4 to 6 (#4073) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump tar and npm in /test/e2e (#4077) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 7 to 8 (#4046) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 6 to 7 (#4045) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.2 to 0.27.3 in /assets (#4031) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump storybook from 10.2.8 to 10.2.13 in /assets (#4047) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump minimatch from 3.1.2 to 3.1.5 in /assets (#4049) @[dependabot[bot]](https://github.com/apps/dependabot) * Make prettier npm dev dependency explicit (#4053) @arbulu89 * Remove unused eslint-prettier-cli (#4052) @arbulu89 * Fix npm yaml dependency missmatch (#4051) @arbulu89 * Bump ajv from 6.12.6 to 6.14.0 in /test/e2e (#4038) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 15.0.0 to 15.2.0 (#4041) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump qs from 6.14.1 to 6.14.2 in /test/e2e (#4033) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/compat from 2.0.0 to 2.0.2 in /assets (#4024) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump axios from 1.13.2 to 1.13.5 in /assets (#4027) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @faker-js/faker from 10.2.0 to 10.3.0 in /assets (#4025) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-storybook from 10.2.3 to 10.2.8 in /assets (#4026) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump webpack from 5.94.0 to 5.105.0 in /test/e2e (#4016) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-dom from 19.2.3 to 19.2.4 in /assets (#4009) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-jest from 29.9.0 to 29.12.2 in /assets (#4014) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @testing-library/react from 16.3.0 to 16.3.2 in /assets (#4013) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump webpack from 5.102.1 to 5.105.0 in /assets (#4017) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @faker-js/faker from 9.9.0 to 10.2.0 in /assets (#4010) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump html-webpack-plugin from 5.6.5 to 5.6.6 in /assets (#4015) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-webpack5-compiler-babel from 3.0.6 to 4.0.0 in /assets (#4002) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.2.3 to 10.2.6 in /assets (#4011) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump storybook from 10.2.5 to 10.2.6 in /assets (#4012) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 13.3.4 to 15.0.0 in /assets (#4003) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/preset-env from 7.28.5 to 7.29.0 in /assets (#4008) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 13.3.5 to 15.0.0 (#3998) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react from 10.2.3 to 10.2.4 in /assets (#3999) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump fishery from 2.3.1 to 2.4.0 in /assets (#4007) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.3 to 2.5.0 (#4006) @[dependabot[bot]](https://github.com/apps/dependabot) * Replace npm install with npm ci (#4004) @EMaksy * Bump @storybook/addon-docs from 10.1.11 to 10.2.4 in /assets (#4000) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-react-hooks from 5.2.0 to 7.0.1 in /assets (#3994) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/react-webpack5 from 10.0.8 to 10.2.3 in /assets (#3995) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.309.1 to 1.336.4 in /assets (#3996) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-storybook from 10.0.8 to 10.2.3 in /assets (#3997) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dawidd6/action-ansible-playbook from 6 to 7 (#3992) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.12.0 to 7.13.0 in /assets (#3993) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @babel/plugin-transform-modules-commonjs from 7.27.1 to 7.28.6 in /assets (#3966) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump tailwindcss from 3.4.18 to 3.4.19 in /assets (#3965) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 3.6.0 to 3.7.0 (#3989) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump cypress-io/github-action from 6 to 7 (#3979) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.21 to 4.17.23 in /assets (#3978) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump lodash from 4.17.21 to 4.17.23 in /test/e2e (#3977) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/js from 9.39.1 to 9.39.2 in /assets (#3946) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-dom from 19.2.0 to 19.2.3 in /assets (#3944) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump preact from 10.27.2 to 10.28.2 in /assets (#3952) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump qs and @cypress/request in /test/e2e (#3955) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump esbuild from 0.27.0 to 0.27.2 in /assets (#3945) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.11.0 to 7.12.0 in /assets (#3954) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.2 to 2.4.3 (#3953) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @storybook/addon-docs from 10.0.8 to 10.1.10 in /assets (#3943) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump storybook from 10.0.8 to 10.1.10 in /assets (#3941) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromaui/action from 13.3.4 to 13.3.5 (#3949) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump dawidd6/action-ansible-playbook from 5 to 6 (#3947) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump mdast-util-to-hast from 13.2.0 to 13.2.1 in /assets (#3934) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/metadata-action from 5.9.0 to 5.10.0 (#3933) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.1 to 2.4.2 (#3935) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 4 to 5 (#3938) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 5 to 6 (#3939) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 6 to 7 (#3940) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump react-router from 7.9.5 to 7.9.6 in /assets (#3928) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump eslint-plugin-jest from 29.1.0 to 29.2.1 in /assets (#3927) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump posthog-js from 1.297.0 to 1.298.0 in /assets (#3926) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump @eslint/compat from 1.4.1 to 2.0.0 in /assets (#3922) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump chromatic from 13.3.3 to 13.3.4 in /assets (#3921) @[dependabot[bot]](https://github.com/apps/dependabot)
* *Full Changelog**: https://github.com/trento-project/web/compare/3.0.0...3.1.0 ------------------------------------------------------------------ ------------------ 2026-5-19 - May 19 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaThunderbird: - Use BuildRequires: libclang13 to instead of llvm21-libclang13 on Leap 16.1 * Built llvm21 coming from SLFO does not name a llvm versioned libclang13 ++++ agama-web-ui: - Update axios dependency to prevent CVE-2026-42041 and CVE-2026-42264 (bsc#1264160, bsc#1264802). - Update webpack-dev-server to prevent CVE-2025-7339 (bsc#1246678). ++++ apache-commons-logging: - No need to verify sources during the build ++++ apparmor: - Update apparmor-lessopen-profile.patch: * Allow execution of /usr/bin/zstd (bsc#1265620) ++++ chromium: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input ++++ chromium: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input ++++ chromium: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input ++++ chromium: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input ++++ chromium: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input ++++ chromium: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input ++++ chromium: - Chromium 148.0.7778.178 (boo#1265848) * CVE-2026-9111: Use after free in WebRTC * CVE-2026-9110: Inappropriate implementation in UI * CVE-2026-9112: Use after free in GPU * CVE-2026-9113: Out of bounds read in GPU * CVE-2026-9114: Use after free in QUIC * CVE-2026-9115: Insufficient policy enforcement in Service Worker * CVE-2026-9116: Insufficient policy enforcement in ServiceWorker * CVE-2026-9117: Type Confusion in GFX * CVE-2026-9118: Use after free in XR * CVE-2026-9119: Heap buffer overflow in WebRTC * CVE-2026-9120: Use after free in WebRTC * CVE-2026-9126: Use after free in DOM * CVE-2026-9121: Out of bounds read in GPU * CVE-2026-9122: Out of bounds read in GPU * CVE-2026-9123: Heap buffer overflow in Chromecast * CVE-2026-9124: Insufficient validation of untrusted input in Input ++++ kernel-64kb: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-64kb: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-64kb: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-azure: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-azure: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-azure: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-default: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-default: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-default: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-rt: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-rt: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-rt: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ docker-stable: - executor: validate container IDs centrally Backport of . (bsc#1261078, CVE-2026-33748) * 0019-CVE-2026-33748-Fix-git-normalize-and-validate-subdir.patch - git: normalize and validate subdir paths Backport of . (bsc#1260967, CVE-2026-33747) * 0020-CVE-2026-33747-Fix-executor-validate-container-IDs-c.patch ++++ docker-stable: - executor: validate container IDs centrally Backport of . (bsc#1261078, CVE-2026-33748) * 0019-CVE-2026-33748-Fix-git-normalize-and-validate-subdir.patch - git: normalize and validate subdir paths Backport of . (bsc#1260967, CVE-2026-33747) * 0020-CVE-2026-33747-Fix-executor-validate-container-IDs-c.patch ++++ dtb-aarch64: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ dtb-aarch64: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ dtb-aarch64: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ helm: - update distribution dependency to v3.1.1 to address (bsc#1265428, CVE-2026-41888) - update x/net to 0.53.0 (bsc#1265758, CVE-2026-33814) ++++ helm: - update distribution dependency to v3.1.1 to address (bsc#1265428, CVE-2026-41888) - update x/net to 0.53.0 (bsc#1265758, CVE-2026-33814) ++++ helm: - update distribution dependency to v3.1.1 to address (bsc#1265428, CVE-2026-41888) - update x/net to 0.53.0 (bsc#1265758, CVE-2026-33814) ++++ helm: - update distribution dependency to v3.1.1 to address (bsc#1265428, CVE-2026-41888) - update x/net to 0.53.0 (bsc#1265758, CVE-2026-33814) ++++ hplip: - Adjust the version condition not to build scan_utils since %suse_version macro has been changed to 1610 in Leap 16.1 ++++ hplip: - Adjust the version condition not to build scan_utils since %suse_version macro has been changed to 1610 in Leap 16.1 ++++ kernel-source: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-source: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-source: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-docs: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-docs: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-docs: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-kvmsmall: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-kvmsmall: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-kvmsmall: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-obs-build: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-obs-build: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-obs-build: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-obs-qa: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-obs-qa: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-obs-qa: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-syms: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-syms: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-syms: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-zfcpdump: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-zfcpdump: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ kernel-zfcpdump: - xfs: remove xfs_attr_leaf_hasname (CVE-2026-43153 bsc#1264586). - commit 78141a4 - perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001 CVE-2026-31528). - commit 953abda - RDMA/irdma: Fix deadlock during netdev reset with active connections (CVE-2026-31565 bsc#1263064) - commit 768a64a ++++ libapparmor: - Update apparmor-lessopen-profile.patch: * Allow execution of /usr/bin/zstd (bsc#1265620) ++++ libzypp: - Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933) - StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735) - version 17.38.9 (35) ++++ mcp-server-trento: - Release 1.1.0 [#]# What's Changed * Release trigger 1.1.0 (#122) @skrech * [TRNT-4358] Update license headers (#118) @antgamdia * [TRNT-4317] Pin GHA to SHA instead of tags (#109) @antgamdia * [TRNT-4227] Pass metadata labels in GHA (#107) @antgamdia * Implements dependabot cooldown (#110) @gagandeepb * [TRNT-4227] Update container readme (#106) @antgamdia [#]## Features * [TNRT-4326] Use prebuilt RPM in the OBS container image (#113) @antgamdia * [TRNT-4227] Add additional labels to the container image (#92) @antgamdia [#]## Maintenance * Updated ci.yaml to use common workflows (#114) @skrech [#]## Dependencies
26 changes * Bump the common-workflows group across 1 directory with 3 updates (#119) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/getkin/kin-openapi from 0.135.0 to 0.137.0 (#120) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/getkin/kin-openapi from 0.134.0 to 0.135.0 (#116) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.4 to 5.0.5 (#117) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/modelcontextprotocol/go-sdk from 1.4.1 to 1.5.0 (#115) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.0.0 to 1.5.1 (#112) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump awalsh128/cache-apt-pkgs-action from 1.5.3 to 1.6.0 (#111) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/getkin/kin-openapi from 0.133.0 to 0.134.0 (#104) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump release-drafter/release-drafter from 6 to 7 (#105) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump geekyeggo/delete-artifact from 5 to 6 (#103) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/modelcontextprotocol/go-sdk from 1.4.0 to 1.4.1 (#102) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/metadata-action from 5 to 6 (#101) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/build-push-action from 6 to 7 (#100) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/setup-buildx-action from 3 to 4 (#99) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/setup-qemu-action from 3 to 4 (#98) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 3 to 4 (#97) @[dependabot[bot]](https://github.com/apps/dependabot) * [TRNT-4230] Update base container image to 15.7 (#93) @antgamdia * Bump github.com/modelcontextprotocol/go-sdk from 1.2.0 to 1.4.0 (#96) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 7 to 8 (#94) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 6 to 7 (#95) @[dependabot[bot]](https://github.com/apps/dependabot) * [TRNT-4228] Fix linter issues (#91) @antgamdia * Bump github.com/modelcontextprotocol/go-sdk from 1.1.0 to 1.2.0 (#88) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 6 to 7 (#87) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 5 to 6 (#86) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 4 to 5 (#85) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 (#84) @[dependabot[bot]](https://github.com/apps/dependabot)
* *Full Changelog**: https://github.com/trento-project/mcp-server/compare/1.0.0...1.1.0 ++++ mcp-server-trento: - Release 1.1.0 [#]# What's Changed * Release trigger 1.1.0 (#122) @skrech * [TRNT-4358] Update license headers (#118) @antgamdia * [TRNT-4317] Pin GHA to SHA instead of tags (#109) @antgamdia * [TRNT-4227] Pass metadata labels in GHA (#107) @antgamdia * Implements dependabot cooldown (#110) @gagandeepb * [TRNT-4227] Update container readme (#106) @antgamdia [#]## Features * [TNRT-4326] Use prebuilt RPM in the OBS container image (#113) @antgamdia * [TRNT-4227] Add additional labels to the container image (#92) @antgamdia [#]## Maintenance * Updated ci.yaml to use common workflows (#114) @skrech [#]## Dependencies
26 changes * Bump the common-workflows group across 1 directory with 3 updates (#119) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/getkin/kin-openapi from 0.135.0 to 0.137.0 (#120) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/getkin/kin-openapi from 0.134.0 to 0.135.0 (#116) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.4 to 5.0.5 (#117) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/modelcontextprotocol/go-sdk from 1.4.1 to 1.5.0 (#115) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.0.0 to 1.5.1 (#112) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump awalsh128/cache-apt-pkgs-action from 1.5.3 to 1.6.0 (#111) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/getkin/kin-openapi from 0.133.0 to 0.134.0 (#104) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump release-drafter/release-drafter from 6 to 7 (#105) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump geekyeggo/delete-artifact from 5 to 6 (#103) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/modelcontextprotocol/go-sdk from 1.4.0 to 1.4.1 (#102) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/metadata-action from 5 to 6 (#101) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/build-push-action from 6 to 7 (#100) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/setup-buildx-action from 3 to 4 (#99) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/setup-qemu-action from 3 to 4 (#98) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump docker/login-action from 3 to 4 (#97) @[dependabot[bot]](https://github.com/apps/dependabot) * [TRNT-4230] Update base container image to 15.7 (#93) @antgamdia * Bump github.com/modelcontextprotocol/go-sdk from 1.2.0 to 1.4.0 (#96) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 7 to 8 (#94) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 6 to 7 (#95) @[dependabot[bot]](https://github.com/apps/dependabot) * [TRNT-4228] Fix linter issues (#91) @antgamdia * Bump github.com/modelcontextprotocol/go-sdk from 1.1.0 to 1.2.0 (#88) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/download-artifact from 6 to 7 (#87) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 5 to 6 (#86) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 4 to 5 (#85) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 (#84) @[dependabot[bot]](https://github.com/apps/dependabot)
* *Full Changelog**: https://github.com/trento-project/mcp-server/compare/1.0.0...1.1.0 ++++ python-Twisted: - CVE-2026-42304: Prevent resource exhaustion during DNS name decompression * Add patch CVE-2026-42304-compressed-name-loop-detection.patch (bsc#1265265) ++++ rsync: - Security update: - CVE-2025-10158, bsc#1254441: Out of bounds array access via negative index - CVE-2026-41035, bsc#1262223: count of entries mismatch can lead to a use-after-free - CVE-2026-43617, bsc#1264515: Authorization Bypass via Hostname Resolution - CVE-2026-29518, bsc#1264512: Integer Overflow Information Disclosure - CVE-2026-43619, bsc#1264514: Symlink Race Condition via Path-Based Syscalls - CVE-2026-43620, bsc#1264513: Out-of-Bounds Array Read via recv_files() - CVE-2026-45232, bsc#1265296: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing - List of patches added + hardening pre-requisite patches: - rsync-hardening-0001-bool-is-a-keyword-in-C23.patch - rsync-hardening-0002-syscall-fix-a-Y2038-bug-by-replacing-Int32x32To64-wi.patch - rsync-hardening-0003-options.c-Fix-segv-if-poptGetContext-returns-NULL.patch - rsync-hardening-0004-Using-a-correct-time-in-log-file.patch - rsync-hardening-0005-configure.ac-check-for-xattr-support-both-in-libc-an.patch - rsync-hardening-0006-util-fixed-issue-in-clean_fname.patch - rsync-hardening-0007-testsuite-added-clean-fname-underflow-test.patch - rsync-hardening-0008-CVE-2025-10158-fixed-an-invalid-access-to-files-array.patch - rsync-hardening-0009-fix-uninitialized-buf1-in-get_checksum2-MD4-path.patch - rsync-hardening-0010-reject-negative-token-values-in-compressed-stream-re.patch - rsync-hardening-0011-acl-fixed-ACL-ID-mapping-for-non-root.patch - rsync-hardening-0012-fix-uninitialized-mul_one-in-AVX2-checksum-and-add-S.patch - rsync-hardening-0013-Fix-glibc-2.43-constness-warnings.patch - rsync-hardening-0015-fix-signed-integer-overflow-in-proxy-protocol-v2-hea.patch - rsync-hardening-0016-zero-all-new-memory-from-allocations.patch - rsync-hardening-0017-CVE-2026-41035-xattrs-fixed-count-in-qsort.patch - rsync-hardening-0018-call-tzset-before-chroot-to-cache-timezone-data.patch - rsync-hardening-0019-testsuite-xattrs-ignore-SUNWattr_-in-the-Solaris-xls.patch - rsync-hardening-0020-syscall-use-openat2-RESOLVE_BENEATH-on-Linux-for-sec.patch - rsync-hardening-0021-syscall-also-use-O_RESOLVE_BENEATH-on-FreeBSD-and-Ma.patch - rsync-hardening-0022-testsuite-skip-symlink-dirlink-basis-on-platforms-wi.patch - rsync-hardening-0023-CVE-2026-29518-syscall-clientserver-am_chrooted-and-use_secure_syml.patch - rsync-hardening-0024-CVE-2026-29518-sender-fix-read-path-TOCTOU-by-opening-from-module-r.patch - rsync-hardening-0025-CVE-2026-43619-syscall-receiver-secure-receiver-side-do_chmod-again.patch - rsync-hardening-0026-CVE-2026-43619-util1-secure-change_dir-against-symlink-race-chdir-e.patch - rsync-hardening-0027-CVE-2026-43619-syscall-add-symlink-race-safe-do_-_at-wrappers-and-h.patch - rsync-hardening-0028-CVE-2026-43619-util1-syscall-secure-copy_file-source-dest-opens-bar.patch - rsync-hardening-0029-CVE-2026-43619-testsuite-end-to-end-regression-test-for-chdir-symli.patch - rsync-hardening-0030-CVE-2026-43618-token-harden-compressed-token-decoding-against-integ.patch - rsync-hardening-0031-CVE-2026-43618-testsuite-cover-refuse-options-compress-for-the-daem.patch - rsync-hardening-0032-CVE-2026-43620-receiver-add-parent_ndx-0-guard-mirroring-797e17f.patch - rsync-hardening-0033-CVE-2026-43617-clientserver-fix-hostname-ACL-bypass-when-using-daem.patch - rsync-hardening-0034-CVE-2026-43618-defence-in-depth-bound-wire-supplied-counts-and-leng.patch - rsync-hardening-0035-CVE-2026-43618-defence-in-depth-guard-cumulative-snprintf-against-l.patch - rsync-hardening-0036-CVE-2026-43620-defence-in-depth-receiver-block-index-bounds-read_de.patch - rsync-hardening-0037-ci-add-Ubuntu-22.04-and-AlmaLinux-8-workflows-for-ba.patch - rsync-hardening-0039-Fix-flaky-hardlinks-test.patch - rsync-hardening-0040-rsync.h-lower-MAX_WIRE_DEL_STAT-to-avoid-signed-int-.patch - rsync-hardening-0041-CVE-2026-45232-socket-reject-over-long-proxy-response-line.patch - rsync-hardening-0042-main-reject-hyphen-prefixed-remote-shell-hostnames.patch - rsync-hardening-0043-util1-handle-out-of-range-times-in-timestring.patch - Replaced patches: - rsync-no-libattr.patch - > rsync-hardening-0005-configure.ac-check-for-xattr-support-both-in-libc-an.patch - rsync341-gcc15-bool.patch - > rsync-hardening-0001-bool-is-a-keyword-in-C23.patch - rsync-CVE-2025-10158.patch - > rsync-hardening-0008-CVE-2025-10158-fixed-an-invalid-access-to-files-array.patch - rsync-CVE-2026-41035.patch - > rsync-hardening-0017-CVE-2026-41035-xattrs-fixed-count-in-qsort.patch - Patches not applied/required for openSUSE (left for reference, they are NOT missing neither it was a mistake not to include them): - rsync-hardening-0014-zlib-convert-K-R-function-definitions-to-ANSI-style - rsync-hardening-0038-CI-fix-workflows-for-backport-testing ++++ rsync: - Security update: - CVE-2025-10158, bsc#1254441: Out of bounds array access via negative index - CVE-2026-41035, bsc#1262223: count of entries mismatch can lead to a use-after-free - CVE-2026-43617, bsc#1264515: Authorization Bypass via Hostname Resolution - CVE-2026-29518, bsc#1264512: Integer Overflow Information Disclosure - CVE-2026-43619, bsc#1264514: Symlink Race Condition via Path-Based Syscalls - CVE-2026-43620, bsc#1264513: Out-of-Bounds Array Read via recv_files() - CVE-2026-45232, bsc#1265296: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing - List of patches added + hardening pre-requisite patches: - rsync-hardening-0001-bool-is-a-keyword-in-C23.patch - rsync-hardening-0002-syscall-fix-a-Y2038-bug-by-replacing-Int32x32To64-wi.patch - rsync-hardening-0003-options.c-Fix-segv-if-poptGetContext-returns-NULL.patch - rsync-hardening-0004-Using-a-correct-time-in-log-file.patch - rsync-hardening-0005-configure.ac-check-for-xattr-support-both-in-libc-an.patch - rsync-hardening-0006-util-fixed-issue-in-clean_fname.patch - rsync-hardening-0007-testsuite-added-clean-fname-underflow-test.patch - rsync-hardening-0008-CVE-2025-10158-fixed-an-invalid-access-to-files-array.patch - rsync-hardening-0009-fix-uninitialized-buf1-in-get_checksum2-MD4-path.patch - rsync-hardening-0010-reject-negative-token-values-in-compressed-stream-re.patch - rsync-hardening-0011-acl-fixed-ACL-ID-mapping-for-non-root.patch - rsync-hardening-0012-fix-uninitialized-mul_one-in-AVX2-checksum-and-add-S.patch - rsync-hardening-0013-Fix-glibc-2.43-constness-warnings.patch - rsync-hardening-0015-fix-signed-integer-overflow-in-proxy-protocol-v2-hea.patch - rsync-hardening-0016-zero-all-new-memory-from-allocations.patch - rsync-hardening-0017-CVE-2026-41035-xattrs-fixed-count-in-qsort.patch - rsync-hardening-0018-call-tzset-before-chroot-to-cache-timezone-data.patch - rsync-hardening-0019-testsuite-xattrs-ignore-SUNWattr_-in-the-Solaris-xls.patch - rsync-hardening-0020-syscall-use-openat2-RESOLVE_BENEATH-on-Linux-for-sec.patch - rsync-hardening-0021-syscall-also-use-O_RESOLVE_BENEATH-on-FreeBSD-and-Ma.patch - rsync-hardening-0022-testsuite-skip-symlink-dirlink-basis-on-platforms-wi.patch - rsync-hardening-0023-CVE-2026-29518-syscall-clientserver-am_chrooted-and-use_secure_syml.patch - rsync-hardening-0024-CVE-2026-29518-sender-fix-read-path-TOCTOU-by-opening-from-module-r.patch - rsync-hardening-0025-CVE-2026-43619-syscall-receiver-secure-receiver-side-do_chmod-again.patch - rsync-hardening-0026-CVE-2026-43619-util1-secure-change_dir-against-symlink-race-chdir-e.patch - rsync-hardening-0027-CVE-2026-43619-syscall-add-symlink-race-safe-do_-_at-wrappers-and-h.patch - rsync-hardening-0028-CVE-2026-43619-util1-syscall-secure-copy_file-source-dest-opens-bar.patch - rsync-hardening-0029-CVE-2026-43619-testsuite-end-to-end-regression-test-for-chdir-symli.patch - rsync-hardening-0030-CVE-2026-43618-token-harden-compressed-token-decoding-against-integ.patch - rsync-hardening-0031-CVE-2026-43618-testsuite-cover-refuse-options-compress-for-the-daem.patch - rsync-hardening-0032-CVE-2026-43620-receiver-add-parent_ndx-0-guard-mirroring-797e17f.patch - rsync-hardening-0033-CVE-2026-43617-clientserver-fix-hostname-ACL-bypass-when-using-daem.patch - rsync-hardening-0034-CVE-2026-43618-defence-in-depth-bound-wire-supplied-counts-and-leng.patch - rsync-hardening-0035-CVE-2026-43618-defence-in-depth-guard-cumulative-snprintf-against-l.patch - rsync-hardening-0036-CVE-2026-43620-defence-in-depth-receiver-block-index-bounds-read_de.patch - rsync-hardening-0037-ci-add-Ubuntu-22.04-and-AlmaLinux-8-workflows-for-ba.patch - rsync-hardening-0039-Fix-flaky-hardlinks-test.patch - rsync-hardening-0040-rsync.h-lower-MAX_WIRE_DEL_STAT-to-avoid-signed-int-.patch - rsync-hardening-0041-CVE-2026-45232-socket-reject-over-long-proxy-response-line.patch - rsync-hardening-0042-main-reject-hyphen-prefixed-remote-shell-hostnames.patch - rsync-hardening-0043-util1-handle-out-of-range-times-in-timestring.patch - Replaced patches: - rsync-no-libattr.patch - > rsync-hardening-0005-configure.ac-check-for-xattr-support-both-in-libc-an.patch - rsync341-gcc15-bool.patch - > rsync-hardening-0001-bool-is-a-keyword-in-C23.patch - rsync-CVE-2025-10158.patch - > rsync-hardening-0008-CVE-2025-10158-fixed-an-invalid-access-to-files-array.patch - rsync-CVE-2026-41035.patch - > rsync-hardening-0017-CVE-2026-41035-xattrs-fixed-count-in-qsort.patch - Patches not applied/required for openSUSE (left for reference, they are NOT missing neither it was a mistake not to include them): - rsync-hardening-0014-zlib-convert-K-R-function-definitions-to-ANSI-style - rsync-hardening-0038-CI-fix-workflows-for-backport-testing ++++ supportutils-plugin-trento: - Release 3.1.0 [#]# What's Changed * Release Trigger 3.1.0 (#27) @skrech * [TRNT-4358] Add license headers (#25) @antgamdia * [TRNT-4358] Update LICENSE to match Apache-2.0 verbatim text (#24) @antgamdia * Extract db usage stats (#23) @balanza * Exclude common workflows from dependabot cooldown (#22) @skrech * New CI (#21) @skrech * [TRNT-4330] Add Dependabot configuration (#16) @antgamdia * [TRNT-4317] Pin GHA to SHA instead of tags (#15) @antgamdia * Collect scenario dump (#14) @Thr3d * *Full Changelog**: https://github.com/trento-project/support/compare/3.0.0...3.1.0 ++++ timezone: - Update to 2026b: * British Columbia moved to permanent -07 on 2026-03-09. (bsc#1264965) * Some more overflow bugs have been fixed in zic. - Change SUSE-Public-Domain license to LicenseRef-SUSE-Public-Domain to fix rpmlint errors ++++ trento-agent: - Release 3.1.0 [#]# What's Changed * Release trigger for 3.1.0 (#584) @skrech * [TRNT-4358] Add license headers (#581) @antgamdia * [TRNT-4358] Update LICENSE to match Apache-2.0 verbatim text (#580) @antgamdia * [TRNT-4317] Pin GHA to SHA instead of tags (#568) @antgamdia * Set node_exporter modules on Grafana Alloy configuration (#566) @balanza * Heartbeat interval configuration (#563) @balanza * Set basic auth as default (#558) @balanza * Deadcode linter (#552) @arbulu89 * Add generate alloy configuration command (#539) @balanza * Use native errors package (#537) @arbulu89 * Specify node exporter name in config (#534) @balanza * remove node exporter as dependency (#531) @balanza * add push mode (#529) @balanza * Bump workbench dep to include cluster resource refresh op (#527) @arbulu89 * Discover host last boot time (#519) @balanza [#]## Features * Improve cluster online/offline detection (#560) @arbulu89 * Tidy operator error messages up (#556) @arbulu89 * Improve operations error message reporting (#557) @arbulu89 * Get cluster state (#553) @arbulu89 * Merge Workbench (#551) @arbulu89 * Do not make prometheus-mode flag required from cli (#540) @nelsonkopliku [#]## Bug Fixes * Saptune gatherer check argument (#536) @arbulu89 * Fix sending empty unit_file_state (#533) @skrech [#]## Maintenance * Group changes for common workflows into single PR (#575) @skrech * Migrated to common workflows (#573) @skrech * Remove dependabot auto merge job (#572) @vicenteqa * Implements dependabot cooldown (#567) @gagandeepb * Add network service depedency on systemd startup (#565) @arbulu89 * Fix typo in operator error message (#555) @arbulu89 [#]## Dependencies
20 changes * Bump trento-project/.github/.github/workflows/git-release.yaml from 1.5.0 to 1.6.0 (#574) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump google.golang.org/grpc from 1.67.3 to 1.79.3 in the go_modules group across 1 directory (#569) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump release-drafter/release-drafter from 6 to 7 (#562) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/mod from 0.33.0 to 0.34.0 (#561) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/sync from 0.19.0 to 0.20.0 (#559) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/prometheus-community/pro-bing from 0.7.0 to 0.8.0 (#543) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.3 to 5.0.4 (#564) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.3 to 2.5.0 (#538) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.2 to 5.0.3 (#535) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/coreos/go-systemd/v22 from 22.6.0 to 22.7.0 (#532) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.5.0 to 1.5.1 (#530) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.1 to 5.0.2 (#528) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump gopkg.in/ini.v1 from 1.67.0 to 1.67.1 (#526) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/sync from 0.18.0 to 0.19.0 (#517) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/mod from 0.30.0 to 0.31.0 (#518) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump google.golang.org/protobuf from 1.36.10 to 1.36.11 (#521) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 4.3.0 to 5.0.1 (#523) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.4.1 to 1.5.0 (#520) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.1 to 2.4.3 (#524) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 (#515) @[dependabot[bot]](https://github.com/apps/dependabot)
* *Full Changelog**: https://github.com/trento-project/agent/compare/3.0.0...3.1.0 ++++ trento-agent: - Release 3.1.0 [#]# What's Changed * Release trigger for 3.1.0 (#584) @skrech * [TRNT-4358] Add license headers (#581) @antgamdia * [TRNT-4358] Update LICENSE to match Apache-2.0 verbatim text (#580) @antgamdia * [TRNT-4317] Pin GHA to SHA instead of tags (#568) @antgamdia * Set node_exporter modules on Grafana Alloy configuration (#566) @balanza * Heartbeat interval configuration (#563) @balanza * Set basic auth as default (#558) @balanza * Deadcode linter (#552) @arbulu89 * Add generate alloy configuration command (#539) @balanza * Use native errors package (#537) @arbulu89 * Specify node exporter name in config (#534) @balanza * remove node exporter as dependency (#531) @balanza * add push mode (#529) @balanza * Bump workbench dep to include cluster resource refresh op (#527) @arbulu89 * Discover host last boot time (#519) @balanza [#]## Features * Improve cluster online/offline detection (#560) @arbulu89 * Tidy operator error messages up (#556) @arbulu89 * Improve operations error message reporting (#557) @arbulu89 * Get cluster state (#553) @arbulu89 * Merge Workbench (#551) @arbulu89 * Do not make prometheus-mode flag required from cli (#540) @nelsonkopliku [#]## Bug Fixes * Saptune gatherer check argument (#536) @arbulu89 * Fix sending empty unit_file_state (#533) @skrech [#]## Maintenance * Group changes for common workflows into single PR (#575) @skrech * Migrated to common workflows (#573) @skrech * Remove dependabot auto merge job (#572) @vicenteqa * Implements dependabot cooldown (#567) @gagandeepb * Add network service depedency on systemd startup (#565) @arbulu89 * Fix typo in operator error message (#555) @arbulu89 [#]## Dependencies
20 changes * Bump trento-project/.github/.github/workflows/git-release.yaml from 1.5.0 to 1.6.0 (#574) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump google.golang.org/grpc from 1.67.3 to 1.79.3 in the go_modules group across 1 directory (#569) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump release-drafter/release-drafter from 6 to 7 (#562) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/mod from 0.33.0 to 0.34.0 (#561) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/sync from 0.19.0 to 0.20.0 (#559) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/prometheus-community/pro-bing from 0.7.0 to 0.8.0 (#543) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.3 to 5.0.4 (#564) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.3 to 2.5.0 (#538) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.2 to 5.0.3 (#535) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/coreos/go-systemd/v22 from 22.6.0 to 22.7.0 (#532) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.5.0 to 1.5.1 (#530) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 5.0.1 to 5.0.2 (#528) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump gopkg.in/ini.v1 from 1.67.0 to 1.67.1 (#526) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/sync from 0.18.0 to 0.19.0 (#517) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump golang.org/x/mod from 0.30.0 to 0.31.0 (#518) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump google.golang.org/protobuf from 1.36.10 to 1.36.11 (#521) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 4.3.0 to 5.0.1 (#523) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.4.1 to 1.5.0 (#520) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump isbang/compose-action from 2.4.1 to 2.4.3 (#524) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump github.com/spf13/cobra from 1.10.1 to 1.10.2 (#515) @[dependabot[bot]](https://github.com/apps/dependabot)
* *Full Changelog**: https://github.com/trento-project/agent/compare/3.0.0...3.1.0 ++++ trento-checks: - Release 1.3.0 [#]# What's Changed * Release trigger 1.3.0 (#70) @skrech * [TRNT-4358] Add license headers (#68) @antgamdia * [TRNT-4358] Update LICENSE to match GPL-3.0-or-later verbatim text (#67) @antgamdia * Migrated CI to the common workflows (#64) @skrech * [TRNT-4330] Add Dependabot configuration (#61) @antgamdia * [TRNT-4221] Extract publish-container GHA (#60) @antgamdia * Versioning (#59) @balanza * [TRNT-4227] Use metadata GHA action (#57) @antgamdia * [TRNT-4317] Pin GHA to SHA instead of tags (#58) @antgamdia * added metadata angi to 8F6363 and changed property call notation for… (#55) @ksanjeet * [TRNT-4227] Add additional labels to the container image (#56) @antgamdia * Bump BCI references to 15.7 (#54) @nelsonkopliku [#]## Maintenance * Group changes for common workflows into single PR (#65) @skrech [#]## Dependencies * Bump the common-workflows group with 3 updates (#66) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump styfle/cancel-workflow-action from 0.12.1 to 0.13.1 (#63) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/checkout from 4.3.1 to 6.0.2 (#62) @[dependabot[bot]](https://github.com/apps/dependabot) * *Full Changelog**: https://github.com/trento-project/checks/compare/1.2.0...1.3.0 ++++ trento-checks: - Release 1.3.0 [#]# What's Changed * Release trigger 1.3.0 (#70) @skrech * [TRNT-4358] Add license headers (#68) @antgamdia * [TRNT-4358] Update LICENSE to match GPL-3.0-or-later verbatim text (#67) @antgamdia * Migrated CI to the common workflows (#64) @skrech * [TRNT-4330] Add Dependabot configuration (#61) @antgamdia * [TRNT-4221] Extract publish-container GHA (#60) @antgamdia * Versioning (#59) @balanza * [TRNT-4227] Use metadata GHA action (#57) @antgamdia * [TRNT-4317] Pin GHA to SHA instead of tags (#58) @antgamdia * added metadata angi to 8F6363 and changed property call notation for… (#55) @ksanjeet * [TRNT-4227] Add additional labels to the container image (#56) @antgamdia * Bump BCI references to 15.7 (#54) @nelsonkopliku [#]## Maintenance * Group changes for common workflows into single PR (#65) @skrech [#]## Dependencies * Bump the common-workflows group with 3 updates (#66) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump styfle/cancel-workflow-action from 0.12.1 to 0.13.1 (#63) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/checkout from 4.3.1 to 6.0.2 (#62) @[dependabot[bot]](https://github.com/apps/dependabot) * *Full Changelog**: https://github.com/trento-project/checks/compare/1.2.0...1.3.0 ++++ trento-wanda: - Release 2.1.0 [#]# What's Changed * Release trigger for 2.1.0 (#715) @skrech * [TRNT-4358] Add license headers (#709) @antgamdia * [TRNT-4358] Update LICENSE to match Apache-2.0 verbatim text (#710) @antgamdia * Read checks version (#694) @balanza * Fix rhai_rustler vendoring (#693) @skrech * Add service info (#691) @balanza * [TRNT-4317] Pin GHA to SHA instead of tags (#687) @antgamdia * Implements dependabot cooldown (#686) @gagandeepb * [TRNT-4227] Add missing arg in dockerfile (#680) @antgamdia * [TRNT-4227] Add additional labels to the container image (#677) @antgamdia * Add placeholder value for GTM_ID (#675) @arbulu89 * Document saptune check gatherer (#673) @arbulu89 [#]## Features * Publish operation request failed (#684) @arbulu89 * Update database start/stop to handle multi-tier system replication (#682) @arbulu89 * Operation completed errors (#674) @arbulu89 * Add cluster resource refresh operation (#670) @arbulu89 [#]## Maintenance * [TRNT-4376] Align DB dependencies (#712) @antgamdia * Group Dependabot updates for our common workflows into a single PR (#703) @skrech * Exclude our common workflows from cooldown (#698) @skrech * Remove _services file from packaging (#697) @skrech * New release process (#696) @skrech * New obs-sync for rolling (#692) @skrech * Make ci.yaml to use publish-containers workflow (#685) @arbulu89 * Workaround api_docs_checks linter to use previous version (#683) @arbulu89 * Bump BCI references to 15.7 (#672) @nelsonkopliku [#]## Dependencies
15 changes * updating gen_rmq to point to a fork in Trento (#714) @chargio * Bump actions/cache from 5.0.4 to 5.0.5 (#705) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 7.0.0 to 7.0.1 (#706) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the common-workflows group across 1 directory with 3 updates (#713) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/setup-node from 6.3.0 to 6.4.0 (#711) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump the common-workflows group with 3 updates (#704) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump trento-project/.github/.github/workflows/publish-containers.yaml from 1.4.3 to 1.5.0 (#699) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump peter-evans/repository-dispatch from 3.0.0 to 4.0.1 (#690) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump endorama/asdf-parse-tool-versions from 1.0.0 to 1.5.1 (#689) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump release-drafter/release-drafter from 6 to 7 (#679) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump styfle/cancel-workflow-action from 0.13.0 to 0.13.1 (#678) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 6 to 7 (#676) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump styfle/cancel-workflow-action from 0.12.1 to 0.13.0 (#671) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/upload-artifact from 5 to 6 (#669) @[dependabot[bot]](https://github.com/apps/dependabot) * Bump actions/cache from 4 to 5 (#668) @[dependabot[bot]](https://github.com/apps/dependabot)
* *Full Changelog**: https://github.com/trento-project/wanda/compare/2.0.0...2.1.0 ------------------------------------------------------------------ ------------------ 2026-5-18 - May 18 2026 ------------------- ------------------------------------------------------------------ ++++ GraphicsMagick: - added patches CVE-2026-42050: Stack buffer overflow in XTileImage [bsc#1265048] * GraphicsMagick-CVE-2026-42050.patch ++++ GraphicsMagick: - added patches CVE-2026-42050: Stack buffer overflow in XTileImage [bsc#1265048] * GraphicsMagick-CVE-2026-42050.patch ++++ GraphicsMagick: - added patches CVE-2026-42050: Stack buffer overflow in XTileImage [bsc#1265048] * GraphicsMagick-CVE-2026-42050.patch ++++ rmt-server: - Version 3.0 * Set version to 3.0.0 * Security fix: Remove unused ActionMailer/ActionMailbox components to eliminate CVE-2026-42256 (bsc#1265369) * Split Rails meta-gem into individual components for better security control ++++ chromium: - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS ++++ chromium: - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS ++++ chromium: - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS ++++ chromium: - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS ++++ chromium: - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS ++++ chromium: - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS ++++ chromium: - add system-wide chromium.conf as in fedora package enable several features by default and disable ai features allow to override via setting CHROMIUM_USER_FLAGS ++++ kernel-64kb: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-64kb: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-64kb: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-azure: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-azure: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-azure: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-default: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-default: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-default: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-rt: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-rt: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-rt: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ distribution: - update to 3.1.1 (bsc#1265429, CVE-2026-41888): * Fixes CVE-2026-41888 * Bounds-check the file basename in PurgeUploads Walk callback * Add S3 Express One Zone support to the S3 storage driver * Fix tag list endpoint in proxy mode * Clamp oversized `n` query parameter in proxy mode instead of returning 400 * See the full changelog below for the full list of changes. * internal/client/auth/challenge: cleanups and minor refactor * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp from 0.18.0 to 0.19.0 in the go_modules group across 1 directory * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otl ptrace/otlptracehttp from 1.42.0 to 1.43.0 in the go_modules group across 1 directory * build(deps): bump github/codeql-action from 4.34.1 to 4.35.1 * chore(build): Bump go version to latest * refactor: use slices.Backward to simplify the code * fix(proxy): fix tag list endpoint in proxy mode * Update docker-compose structure in deploying.md * build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 * build(deps): bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 * build(deps): bump docker/login-action from 4.0.0 to 4.1.0 * build(deps): bump docker/bake-action from 7.0.0 to 7.1.0 * fix(proxy): clamp oversized n query param instead of returning 400 * feat(s3): add express zone one support to S3 driver * fix(storage): bounds-check the file basename in PurgeUploads Walk callback * chore(release): prepare for v3.1.1 release ++++ dtb-aarch64: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ dtb-aarch64: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ dtb-aarch64: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ libheif: - added patches CVE-2026-3950: manipulation of the component stsz/stts can lead to out-of-bounds read [bsc#1259544] * libheif-CVE-2026-3950.patch ++++ git-bug: - Fix CVE-2026-1229 and CVE-2026-41506 - CVE-2026-1229: CIRCL has an incorrect calculation in secp384r1 CombinedMult (bsc#1265416, GO-2026-4550) update github.com/cloudflare/circl to v1.6.3 - CVE-2026-41506: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264955, GO-2026-4910), update github.com/go-git/go-git/v5 to v5.17.1 - Fix CVE-2026-1229 and CVE-2026-41506 - CVE-2026-1229: CIRCL has an incorrect calculation in secp384r1 CombinedMult (GO-2026-4550) update github.com/cloudflare/circl to v1.6.3 - CVE-2026-41506: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264955, GO-2026-4910), update github.com/go-git/go-git/v5 to v5.17.1 ++++ kernel-source: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-source: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-source: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-docs: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-docs: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-docs: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-kvmsmall: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-kvmsmall: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-kvmsmall: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-obs-build: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-obs-build: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-obs-build: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-obs-qa: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-obs-qa: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-obs-qa: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-syms: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-syms: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-syms: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-zfcpdump: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-zfcpdump: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ kernel-zfcpdump: - virt: sev-guest: Do not use host-controlled page order in cleanup path (git-fixes). - commit 27d6e80 - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - commit c4afa7d - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - commit 42e71c7 - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - spi: zynq-qspi: fix controller deregistration (git-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: zynq-qspi: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - commit de422d6 - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - commit 64f2c72 ++++ xz: - Fix buffer overflow in lzma_index_append (bsc#1261280, CVE-2026-34743) * CVE-2026-34743.patch ++++ systemd: - Move systemd-pcrlock out from the experimental sub-package to udev (bsc#1248261 jsc#PED-15946) ++++ systemd: - Move systemd-pcrlock out from the experimental sub-package to udev (bsc#1248261 jsc#PED-15946) ++++ maven: - Upgrade to upstream version 3.9.16 * Bug Fixes + Trim threadConfiguration to accept input surrounded with spaces + Backport: Maven 3.10.x fixed plugin resolution * Dependency updates + Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.11.0 + [3.9.x] Bump to parent POM 48 + Bump commons-io:commons-io from 2.21.0 to 2.22.0 + Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre + Bump actions/cache from 5.0.4 to 5.0.5 ++++ maven-dependency-analyzer: - Upgrade to upstream version 1.17.1 * New features and improvements + Optimize artifact lookup in DefaultProjectDependencyAnalyzer * Maintenance + Add tag-template to release-drafter configuration + Implement missing tests and cleanup TODOs in DependencyVisitorTest * Dependency updates + Update parent 48 + Bump mavenVersion from 3.9.12 to 3.9.15 ++++ objectweb-asm: - Upgrade to verision 9.10 * new Opcodes.V27 constant for Java 27 * bug fixes + 318041: Compilation failure with JDK 5 + 318043: TraceSignatureVisitor bug ++++ objectweb-asm: - Upgrade to version 9.10 * new Opcodes.V27 constant for Java 27 * bug fixes + 318041: Compilation failure with JDK 5 + 318043: TraceSignatureVisitor bug ++++ perl-HTTP-Tiny: - updated to 0.094 see /usr/share/doc/packages/perl-HTTP-Tiny/Changes 0.094 2026-05-17 10:31:00+02:00 Europe/Brussels - No changes from 0.093-TRIAL 0.093 2026-05-11 17:18:12+02:00 Europe/Brussels (TRIAL RELEASE) - fix to prevent invalid characters in all headers, and prevent header smuggling (CVE-2026-7010) bsc#1264992 ++++ perl-libwww-perl: - added patches CVE-2026-8368: Authorization and Proxy-Authorization headers are leaked on cross-origin redirects [bsc#1265156] * perl-libwww-perl-CVE-2026-8368.patch ++++ python-Pillow: - CVE-2026-42308: Integer overflow in font processing (bsc#1265359) Add patch CVE-2026-42308.patch ++++ python-urllib3: - CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267) Add patch CVE-2026-44431.patch ++++ python-urllib3_1: - CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267) Add patch CVE-2026-44431.patch ++++ systemd-mini: - Move systemd-pcrlock out from the experimental sub-package to udev (bsc#1248261 jsc#PED-15946) ++++ systemd-mini: - Move systemd-pcrlock out from the experimental sub-package to udev (bsc#1248261 jsc#PED-15946) ------------------------------------------------------------------ ------------------ 2026-5-17 - May 17 2026 ------------------- ------------------------------------------------------------------ ++++ opensuse-migration-tool: - Update to version 20260517.df4e731: * Update README.md * ci: set minimal token permissions for shellcheck workflow * fix: avoid shellcheck false positives for os-release vars * Initial plan * Potential fix for pull request finding * Run shellcheck also on post scripts * Initial addressing of shellcheck issues * Add shellcheck workflow * Use consistently command -v for toolcheck * Ensure that we pass DIALOGCMD to sudo * Update screenshot with susedialog * Use susedialog if available * Potential fix for pull request finding * Handle prerelease states local distro.json fallback * Remove leftover debug print and add a little bit of quoting ++++ perl-IO-Compress: - updated to 2.220.0 (2.220) see /usr/share/doc/packages/perl-IO-Compress/Changes 2.220 16 May 2026 * remove use of eval in globmapper. #73 CVE-2026-48962 bsc#1266382 Sat May 16 17:48:34 2026 +0100 f2db247bf90d4cc7ee2710be384946081f3b4610 * Update zipdetails to version 4.006. CVE-2026-48961 bsc#1266381 Sat May 16 13:43:12 2026 +0100 33c89d03d6e746ed2ead4f2f6570d47864c61bc7 * Fix typo in fastForward #72 Fri May 15 23:18:39 2026 +0100 68db44076f4c1a86a2ffe53a958eac6cabaf72e2 * Fix issue with "rawdeflate` option in AnyInflate. #71 Fri May 15 22:56:20 2026 +0100 fba3efe40208bd07034b6a3cf6bf9fc3b8b4f215 ++++ shadowsocks-common: - Initial package for version 1.0.0 and shadowsocks-libev, shadowsocks-rust * Fix boo#1264355, use sysuser istead of command in %pre to create shadowsocks system account * Provide the common SELinux module for shadowsocks-libev and shadowsocks-rust (bnc#1212862 and boo#1263916) ------------------------------------------------------------------ ------------------ 2026-5-16 - May 16 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaThunderbird: - Mozilla Thunderbird 140.11.0 ESR MFSA 2026-51 (bsc#1265212) * CVE-2026-8946 (bmo#2029070) Incorrect boundary conditions in the Audio/Video: Web Codecs component * CVE-2026-8388 (bmo#2036978) Incorrect boundary conditions in the JavaScript Engine: JIT component * CVE-2026-8947 (bmo#2038439) Use-after-free in the DOM: Bindings (WebIDL) component * CVE-2026-8391 (bmo#2038575) Other issue in the JavaScript Engine component * CVE-2026-8401 (bmo#2038679) Sandbox escape in the Profile Backup component * CVE-2026-8949 (bmo#1355639) Integer overflow in the Widget: Win32 component * CVE-2026-8950 (bmo#1965430) Same-origin policy bypass in the Networking: HTTP component * CVE-2026-8953 (bmo#2029511) Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-8954 (bmo#2030747) Incorrect boundary conditions, integer overflow in the Audio/Video component * CVE-2026-8955 (bmo#2031064) Privilege escalation in the DOM: Workers component * CVE-2026-8956 (bmo#2032427) Integer overflow in the Networking: JAR component * CVE-2026-8957 (bmo#2033850) Privilege escalation in the Enterprise Policies component * CVE-2026-8958 (bmo#2034713) Information disclosure, sandbox escape in the Security: Process Sandboxing component * CVE-2026-8959 (bmo#2034754) Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component * CVE-2026-8961 (bmo#1962625) Spoofing issue in the Form Autofill component * CVE-2026-8962 (bmo#2004804) Mitigation bypass in the DOM: Security component * CVE-2026-8968 (bmo#2030467) Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component * CVE-2026-8970 (bmo#2032174) Privilege escalation in the Security component * CVE-2026-8974 (bmo#1784128, bmo#1883230, bmo#1983677, bmo#2022390, bmo#2023116, bmo#2023657, bmo#2024255, bmo#2024418, bmo#2024441, bmo#2024447, bmo#2024966, bmo#2025412, bmo#2025467, bmo#2025940, bmo#2025950, bmo#2025956, bmo#2026284, bmo#2027247, bmo#2027255, bmo#2027288, bmo#2027306, bmo#2027322, bmo#2027332, bmo#2027333, bmo#2028266, bmo#2028292, bmo#2028319, bmo#2028526, bmo#2028870, bmo#2028876, bmo#2028882, bmo#2029062, bmo#2029309, bmo#2029414, bmo#2029422, bmo#2029428, bmo#2029447, bmo#2029732, bmo#2029785, bmo#2029793, bmo#2029813, bmo#2029899, bmo#2031028, bmo#2031457, bmo#2032039, bmo#2033610, bmo#2033854, bmo#2034498, bmo#2034628, bmo#2034978, bmo#2035966, bmo#2036668, bmo#2036905, bmo#2036930) Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151 * CVE-2026-8975 (bmo#1860195, bmo#2029325, bmo#2029429, bmo#2029910, bmo#2035915, bmo#2038669, bmo#2038678) Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151 - removed obsolete patches * thunderbird-bmo2006630.patch * mozilla-bmo2031958.patch ++++ kernel-64kb: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-64kb: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-64kb: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-azure: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-azure: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-azure: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-default: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-default: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-default: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-rt: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-rt: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-rt: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ dtb-aarch64: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ dtb-aarch64: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ dtb-aarch64: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-source: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-source: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-source: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-docs: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-docs: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-docs: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-kvmsmall: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-kvmsmall: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-kvmsmall: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-obs-build: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-obs-build: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-obs-build: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-obs-qa: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-obs-qa: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-obs-qa: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-syms: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-syms: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-syms: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-zfcpdump: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-zfcpdump: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ++++ kernel-zfcpdump: - drm/loongson: Use managed KMS polling (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - commit 98a8998 ------------------------------------------------------------------ ------------------ 2026-5-15 - May 15 2026 ------------------- ------------------------------------------------------------------ ++++ agama-yast: - Adapt code to new suseconnect-ng version (bsc#1265239) ++++ agama-yast: - Adapt code to new suseconnect-ng version (bsc#1265239) ++++ libarchive: - Fix CVE-2026-4424, 257-byte heap memory leak when processing a 170-byte RAR3 (CVE-2026-4424, bsc#1259928) * CVE-2026-4424.patch - Fix CVE-2026-4426, undefined behavior due to unvalidated operand in shift expression of the zisofs decompression code 3.8.1 in function apply_substitution in file tar/subst.c (CVE-2026-4426, bsc#1259931) * CVE-2026-4426.patch - Fix CVE-2026-4111, logical deadlock the RAR5 filter subsystem and the half-window output limiter leads to infinite loop and DoS (CVE-2026-4111, bsc#1259635) * CVE-2026-4111.patch - Fix CVE-2026-5121, missing validation check for pz_log2_bs can a heap buffer overflow write (CVE-2026-5121, bsc#1261186) * CVE-2026-5121.patch ++++ kernel-64kb: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-64kb: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-64kb: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-64kb: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-azure: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-azure: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-azure: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-azure: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-default: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-default: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-default: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-default: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-rt: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-rt: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-rt: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-rt: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ samba: - CVE-2026-4480: Fix Unauthenticated Remote Code Execution; (bso#16033); (bsc#1261161). - CVE-2026-4408: Fix Remote Code Execution in SAMR;(bso#16034); (bsc#1261163). - CVE-2026-3238: Fix unauthenticated udp packet crashes AD DC nbt server; (bso#16012); (bsc#1261160). - CVE-2026-3012: Fix CVE-2026-3012 group policy certificate enrollment using http:// without validation;(bso#16003); (bsc#1261159). - CVE-2026-1933: Fix missing access check on reparse point operations; (bso#15992); (bsc#1261188). - CVE-2026-2340: vfs_worm does not block directory modification; (bso#15997); (bsc#1261158). ++++ dtb-aarch64: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ dtb-aarch64: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ dtb-aarch64: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ dtb-aarch64: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ gitea-tea: - update to 0.14.1: * fix(deps): update module github.com/go-authgate/sdk-go to v0.11.0 in #988 * fix(deps): update module golang.org/x/term to v0.43.0 in #989 * fix(deps): update module code.gitea.io/sdk/gitea to v0.25.1 in [#991] * fix(deps): update module github.com/urfave/cli/v3 to v3.9.0 in [#992] * fix(deps): update github.com/urfave/cli to v3.9.0 in #993 * Fix login edit to check config existence in #987 * fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 in [#984] * fix: pass the name flag value as the organization FullName in [#832] * Fix login edit to open one editor only in #977 * fix(deps): update module github.com/go-authgate/sdk-go to v0.10.0 in #976 * feat: add additional admin users subcommands in #842 * feat(ssh-keys): add ssh-keys command to manage SSH public keys in #940 * Multiple PRs in #848 * Move integration tests to tests/ directory in #973 * fix(deps): update module github.com/go-authgate/sdk-go to v0.9.0 in #974 * fix(deps): update module github.com/go-authgate/sdk-go to v0.8.0 in #972 * fix(webhook): Fix when creating webhook, branch filter and auth header cannot be added in #964 * fix: read --assignee flag value instead of nonexistent - -assigned-to in #971 * Fix man page section in #969 * fix(deps): update module github.com/go-authgate/sdk-go to v0.7.0 in #970 * chore(deps): update docker.gitea.com/gitea docker tag to v1.26.1 in #968 * fix(pagination): replace Page:-1 with explicit pagination loops in #967 * fix(cmd): Update CmdRepos description and usage in repos.go in [#946] * fix(context): skip local repo detection for repo slugs in #960 * fix(deps): update module charm.land/lipgloss/v2 to v2.0.3 in [#959] * fix(deps): update module github.com/go-git/go-git/v5 to v5.18.0 in #961 * chore(deps): update docker.gitea.com/gitea docker tag to v1.26.0 in #962 ++++ helm: - Update to version 3.21.0: * [v3] Bump to version v3.21 e0878d4 (George Jenkins) * fix: upgrade opentelemetry packages to patch CVEs 13d5fc4 (Terry Howe) * fix: Chart dot-name path bug 2552884 (George Jenkins) * fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow ec05dd5 (Terry Howe) * add image index test b0dfec5 (Pedro Tôrres) * fix pulling charts from OCI indices e629995 (Pedro Tôrres) * Remove refactorring changes from coalesce_test.go e2df39f (Evans Mungai) * Fix import 97affe0 (Evans Mungai) * Update pkg/chart/common/util/coalesce_test.go c264166 (Evans Mungai) * Fix lint warning d409df8 (Evans Mungai) * Preserve nil values in chart already 6fdd101 (Evans Mungai) * fix(values): preserve nil values when chart default is empty map b13743c (Evans Mungai) * chore(deps): bump the k8s-io group with 7 updates * chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 * chore(deps): bump golang.org/x/term from 0.39.0 to 0.40.0 * chore(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 * chore(deps): bump golang.org/x/text from 0.33.0 to 0.34.0 * chore(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1 * chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 ++++ helm: - Update to version 3.21.0: * [v3] Bump to version v3.21 e0878d4 (George Jenkins) * fix: upgrade opentelemetry packages to patch CVEs 13d5fc4 (Terry Howe) * fix: Chart dot-name path bug 2552884 (George Jenkins) * fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow ec05dd5 (Terry Howe) * add image index test b0dfec5 (Pedro Tôrres) * fix pulling charts from OCI indices e629995 (Pedro Tôrres) * Remove refactorring changes from coalesce_test.go e2df39f (Evans Mungai) * Fix import 97affe0 (Evans Mungai) * Update pkg/chart/common/util/coalesce_test.go c264166 (Evans Mungai) * Fix lint warning d409df8 (Evans Mungai) * Preserve nil values in chart already 6fdd101 (Evans Mungai) * fix(values): preserve nil values when chart default is empty map b13743c (Evans Mungai) * chore(deps): bump the k8s-io group with 7 updates * chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 * chore(deps): bump golang.org/x/term from 0.39.0 to 0.40.0 * chore(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 * chore(deps): bump golang.org/x/text from 0.33.0 to 0.34.0 * chore(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1 * chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 ++++ helm: - Update to version 3.21.0: * [v3] Bump to version v3.21 e0878d4 (George Jenkins) * fix: upgrade opentelemetry packages to patch CVEs 13d5fc4 (Terry Howe) * fix: Chart dot-name path bug 2552884 (George Jenkins) * fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow ec05dd5 (Terry Howe) * add image index test b0dfec5 (Pedro Tôrres) * fix pulling charts from OCI indices e629995 (Pedro Tôrres) * Remove refactorring changes from coalesce_test.go e2df39f (Evans Mungai) * Fix import 97affe0 (Evans Mungai) * Update pkg/chart/common/util/coalesce_test.go c264166 (Evans Mungai) * Fix lint warning d409df8 (Evans Mungai) * Preserve nil values in chart already 6fdd101 (Evans Mungai) * fix(values): preserve nil values when chart default is empty map b13743c (Evans Mungai) * chore(deps): bump the k8s-io group with 7 updates * chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 * chore(deps): bump golang.org/x/term from 0.39.0 to 0.40.0 * chore(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 * chore(deps): bump golang.org/x/text from 0.33.0 to 0.34.0 * chore(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1 * chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 ++++ helm: - Update to version 3.21.0: * [v3] Bump to version v3.21 e0878d4 (George Jenkins) * fix: upgrade opentelemetry packages to patch CVEs 13d5fc4 (Terry Howe) * fix: Chart dot-name path bug 2552884 (George Jenkins) * fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow ec05dd5 (Terry Howe) * add image index test b0dfec5 (Pedro Tôrres) * fix pulling charts from OCI indices e629995 (Pedro Tôrres) * Remove refactorring changes from coalesce_test.go e2df39f (Evans Mungai) * Fix import 97affe0 (Evans Mungai) * Update pkg/chart/common/util/coalesce_test.go c264166 (Evans Mungai) * Fix lint warning d409df8 (Evans Mungai) * Preserve nil values in chart already 6fdd101 (Evans Mungai) * fix(values): preserve nil values when chart default is empty map b13743c (Evans Mungai) * chore(deps): bump the k8s-io group with 7 updates * chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 * chore(deps): bump golang.org/x/term from 0.39.0 to 0.40.0 * chore(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 * chore(deps): bump golang.org/x/text from 0.33.0 to 0.34.0 * chore(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1 * chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 ++++ kernel-source: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-source: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-source: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-source: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-docs: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-docs: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-docs: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-docs: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-kvmsmall: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-kvmsmall: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-kvmsmall: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-kvmsmall: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-obs-build: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-obs-build: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-obs-build: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-obs-build: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-obs-qa: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-obs-qa: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-obs-qa: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-obs-qa: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-syms: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-syms: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-syms: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-syms: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-zfcpdump: - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 ++++ kernel-zfcpdump: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-zfcpdump: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ kernel-zfcpdump: - net: phy: DP83TC811: add reading of abilities (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - selinux: shrink critical section in sel_write_load() (stable-fixes). - selinux: prune /sys/fs/selinux/disable (stable-fixes). - net: phy: broadcom: Save PHY counters during suspend (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: hci_event: fix memset typo (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: cw1200: Revert "Fix locking in error paths" (git-fixes). - wifi: ath12k: use lockdep_assert_in_rcu_read_lock() for RCU assertions (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (git-fixes). - net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: pcmtest: Return -EFAULT on pattern read copy failure (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ipmi: Add limits to event and receive message requests (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - selinux: don't reserve xattr slot when we won't fill it (stable-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (stable-fixes). - iio: frequency: admv1013: fix NULL pointer dereference on str (git-fixes). - iio: frequency: admv1013: add dev variable (stable-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - commit 7b0ff1e - kabi assert: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - kabi: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308). - commit f8f4ca2 - net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (CVE-2026-31658 bsc#1263052). - ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (CVE-2026-43038 bsc#1264097). - commit 25154e4 - netfilter: ip6t_eui64: reject invalid MAC header for all packets (CVE-2026-31685 bsc#1263668). - commit ebc3df3 - netfilter: ctnetlink: ignore explicit helper on new expectations (CVE-2026-43025 bsc#1263931). - commit f7d829f - netfilter: nf_conntrack_helper: pass helper to expect cleanup (CVE-2026-43027 bsc#1263933). - commit 09b2b4e - netfilter: xt_tcpmss: check remaining length before reading optlen (CVE-2026-43190 bsc#1264848). - commit 81f4cf4 - net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (CVE-2026-43441 bsc#1264674). - commit 1eba512 - net: txgbe: leave space for null terminators on property_entry (CVE-2026-43082 bsc#1264233). - vxlan: validate ND option lengths in vxlan_na_create (CVE-2026-31738 bsc#1264059). - commit 5117d0a - selftests/bpf: Add more precision tracking tests for atomics (CVE-2026-43009 bsc#1264014). - commit 8a6ae29 - bpf: Fix incorrect pruning due to atomic fetch precision tracking (CVE-2026-43009 bsc#1264014). - commit e98d57a - btrfs: qgroup: update all parent qgroups when doing quick inherit (bsc#1258933). - commit e80dd17 ++++ util-linux-systemd: - loopdev: Prevent unauthorized read access to symlinked filesystem images (bsc#1261606, CVE-2026-27456, util-linux-CVE-2026-27456.patch). ++++ tigervnc: - U_Use-locks-to-avoid-races-with-input-thread.patch * fixes random crashes with stack overflow (boo#1265303) ++++ util-linux: - loopdev: Prevent unauthorized read access to symlinked filesystem images (bsc#1261606, CVE-2026-27456, util-linux-CVE-2026-27456.patch). ++++ lldpd: - Update to version 1.0.22 * Fix CVE-2026-46433, out-of-bound read access when removing VLAN tag (#787). * Reject 0-length management address in LLDP. * Fix race condition when creating the control socket. * Fix FDP MAC address. * Fix memory leak in the BSD bridge query path. * Fix duplicate management addresses when merging EDP VLAN frames. ++++ open-vm-tools: - update to 13.1.0 release based on build 25218885: (boo#1265304) Please refer to the Release Notes at https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md. Support for GNOME Toolkit version 4. This release of open-vm-tools supports building with either the GNOME Toolkit version 4 (GTK4) or to continue using version 3 (GTK3). The configure script will accept options to restrict the build to either GTK3 or GTK4. If no restriction is applied, the latest version for which the required development package(s) are installed will be used. Please see the What's New section of the Release Notes for details. The following github issues have been resolved: - issue #707 - issue #763 The granular changes that have gone into the open-vm-tools 13.1.0 release are in the ChangeLog at https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/open-vm-tools/ChangeLog. For a more complete description of what is new in this release, see the What's New and Resolved Issues sections of the Release Notes. https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md#whatsnew https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md#resolved-issues ++++ migrate-sles-to-sles4sap: - the migrate-sles-to-sles4sap package need to adapt SLE16 (bsc#1265271) ++++ python-libmount: - loopdev: Prevent unauthorized read access to symlinked filesystem images (bsc#1261606, CVE-2026-27456, util-linux-CVE-2026-27456.patch). ++++ python-python-multipart: - CVE-2026-42561: python-python-multipart: denial of service vulnerability in multipart part header parsing (bsc#1265250) Add CVE-2026-42561.patch ++++ python-python-multipart: - CVE-2026-42561: python-python-multipart: denial of service vulnerability in multipart part header parsing (bsc#1265250) Add CVE-2026-42561.patch ++++ rubygem-agama-yast: - Adapt code to new suseconnect-ng version (bsc#1265239) ++++ rubygem-agama-yast: - Adapt code to new suseconnect-ng version (bsc#1265239) ------------------------------------------------------------------ ------------------ 2026-5-14 - May 14 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - added patches CVE-2026-42050: VUL-0: CVE-2026-42050: ImageMagick: Stack buffer overflow in XTileImage [bsc#1265048] + ImageMagick-CVE-2026-42050.patch ++++ OpenSMTPD: - Updated to version 7.8.0p1: (boo#1263040) - table_proc: ensure the request does not contain newlines - Removed OpenSMTPD-reduced-permissions-on-SMTPD_SOCKET.patch to support use case described in boo#1263040 - Further hardened the systemd service configuration by switching RestrictAddressFamilies from blocklist to allowlist ++++ apache-commons-configuration2: - Upgrade to version 2.15.0 * Changes + Disable include schemes http[s] by default, see AbstractFileLocationStrategy + Detect and avoid processing cycles in YAML input (YAMLConfiguration) (bsc#1265299, CVE-2026-45205) + Extend scheme validation to inner schemes of jar: URLs - Upgrade to version 2.14.0 * New features + Add XMLConfiguration.read(Element) + Add ConfigurationException.ConfigurationException(String, Object...) + Add ConfigurationException.ConfigurationException(Throwable, String, Object...) + Add ConversionException.ConversionException(String, Object...) + Add ConversionException.ConversionException(Throwable, String, Object...) + Add ConfigurationRuntimeException .ConfigurationRuntimeException(Throwable, String, Object...) * Fixed Bugs + Fix Apache RAT plugin console warnings + Migrate from deprecated APIs - Upgrade to version 2.13.0 * New features + Add org.apache.commons.configuration2.ImmutableConfiguration .entrySet() + Add org.apache.commons.configuration2.ImmutableConfiguration .forEach(BiConsumer) + Add VEX entry for CVE-2025-48924 * Fixed Bugs + Shared primitive variable "throwExceptionOnMissing" in one thread may not yield the value of the most recent write from another thread [org.apache.commons.configuration2 .AbstractConfiguration] At AbstractConfiguration.java: [line 1493] AT_STALE_THREAD_WRITE_OF_PRIMITIVE + Shared primitive variable "forceSingleLine" in one thread may not yield the value of the most recent write from another thread [org.apache.commons.configuration2 .PropertiesConfigurationLayout] At PropertiesConfigurationLayout.java:[line 821] AT_STALE_THREAD_WRITE_OF_PRIMITIVE + CONFIGURATION-849: Fix undoubling of strings + CONFIGURATION-852: Mark the package jakarta.servlet.* import as optional in OSGi + Fix build [WARNING] Parameter 'forkMode' is unknown for plugin 'maven-surefire-plugin:3.5.3:test (default-test)' - Upgrade to version 2.12.0 * New features: + Add PrefixedKeysIterator.toString() to package-private PrefixedKeysIterator + CONFIGURATION-836: New web configurations using the jakarta.servlet namespace are now available + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletConfiguration + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletContextConfiguration + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletFilterConfiguration + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletRequestConfiguration + Add org.apache.commons.configuration2 .AbstractHierarchicalConfiguration.getKeysInternal(String, String) * Fixed Bugs: + PropertyConverter.to(Class, Object, DefaultConversionHandler) doesn't convert custom java.lang.Number subclasses + DefaultConversionHandler.convertValue(Object, Class, ConfigurationInterpolator) doesn't convert custom java.lang .Number subclasses + DefaultConversionHandler.to(Object, Class, ConfigurationInterpolator) doesn't convert custom java.lang .Number subclasses + CONFIGURATION-848: SubsetConfiguration does not account for delimiters as it did in 2.9.0 + CONFIGURATION-848: CompositeConfiguration does not account for delimiters as it did in 2.9.0 + Describe the security model + De-emphasize the 1.x version line on the website + CONFIGURATION-851: HomeDirectoryLocationStrategy no longer resolves the user HOME directory correctly - Upgrade to version 2.11.0 * New features + CONFIGURATION-844: Add support for empty sections + Add ImmutableConfiguration.containsValue(Object) * Fixed Bugs + Fail-fast with a NullPointerException if DataConfiguration .DataConfiguration(Configuration) is called with null + Fail-fast with a NullPointerException if XMLPropertiesConfiguration.XMLPropertiesConfiguration(Element) is called with null + Fail-fast with a NullPointerException if a SubsetConfiguration constructor is called with a null Configuration + CONFIGURATION-843: Methods should not be empty + Guard MapConfiguration against null maps + Fail-fast with a NullPointerException if AppletConfiguration(Applet) is called with null + Fail-fast with a NullPointerException if ServletConfiguration(Servlet) is called with null + Fail-fast with a NullPointerException if ServletConfiguration(ServletConfig) is called with null + Fail-fast with a NullPointerException if ServletContextConfiguration(Servlet) is called with null + Fail-fast with a NullPointerException if ServletContextConfiguration(ServletContext) is called with null + Fail-fast with a NullPointerException if ServletFilterConfiguration(FilterConfig) is called with null + Fail-fast with a NullPointerException if ServletRequestConfiguration(ServletRequest) is called with null + Deprecate DatabaseConfiguration.getDatasource() in favor of getDataSource() + Fix PMD DynamicCombinedConfiguration in AbstractImmutableNodeHandler + Fix PMD DynamicCombinedConfiguration in AbstractListDelimiterHandler + Fix PMD DynamicCombinedConfiguration in DefaultPrefixLookupsHolder + Fix PMD DynamicCombinedConfiguration in DynamicCombinedConfiguration + Fix PMD DynamicCombinedConfiguration in PropertiesConfiguration + CONFIGURATION-846: Restore previous behavior allowing Spring to inject multiple values + CONFIGURATION-847: Property with an empty string value was not processed ++++ apache-commons-configuration2: - Upgrade to version 2.15.0 * Changes + Disable include schemes http[s] by default, see AbstractFileLocationStrategy + Detect and avoid processing cycles in YAML input (YAMLConfiguration) (bsc#1265299, CVE-2026-45205) + Extend scheme validation to inner schemes of jar: URLs - Upgrade to version 2.14.0 * New features + Add XMLConfiguration.read(Element) + Add ConfigurationException.ConfigurationException(String, Object...) + Add ConfigurationException.ConfigurationException(Throwable, String, Object...) + Add ConversionException.ConversionException(String, Object...) + Add ConversionException.ConversionException(Throwable, String, Object...) + Add ConfigurationRuntimeException .ConfigurationRuntimeException(Throwable, String, Object...) * Fixed Bugs + Fix Apache RAT plugin console warnings + Migrate from deprecated APIs - Upgrade to version 2.13.0 * New features + Add org.apache.commons.configuration2.ImmutableConfiguration .entrySet() + Add org.apache.commons.configuration2.ImmutableConfiguration .forEach(BiConsumer) + Add VEX entry for CVE-2025-48924 * Fixed Bugs + Shared primitive variable "throwExceptionOnMissing" in one thread may not yield the value of the most recent write from another thread [org.apache.commons.configuration2 .AbstractConfiguration] At AbstractConfiguration.java: [line 1493] AT_STALE_THREAD_WRITE_OF_PRIMITIVE + Shared primitive variable "forceSingleLine" in one thread may not yield the value of the most recent write from another thread [org.apache.commons.configuration2 .PropertiesConfigurationLayout] At PropertiesConfigurationLayout.java:[line 821] AT_STALE_THREAD_WRITE_OF_PRIMITIVE + CONFIGURATION-849: Fix undoubling of strings + CONFIGURATION-852: Mark the package jakarta.servlet.* import as optional in OSGi + Fix build [WARNING] Parameter 'forkMode' is unknown for plugin 'maven-surefire-plugin:3.5.3:test (default-test)' - Upgrade to version 2.12.0 * New features: + Add PrefixedKeysIterator.toString() to package-private PrefixedKeysIterator + CONFIGURATION-836: New web configurations using the jakarta.servlet namespace are now available + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletConfiguration + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletContextConfiguration + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletFilterConfiguration + CONFIGURATION-836: Add org.apache.commons.configuration2.web .JakartaServletRequestConfiguration + Add org.apache.commons.configuration2 .AbstractHierarchicalConfiguration.getKeysInternal(String, String) * Fixed Bugs: + PropertyConverter.to(Class, Object, DefaultConversionHandler) doesn't convert custom java.lang.Number subclasses + DefaultConversionHandler.convertValue(Object, Class, ConfigurationInterpolator) doesn't convert custom java.lang .Number subclasses + DefaultConversionHandler.to(Object, Class, ConfigurationInterpolator) doesn't convert custom java.lang .Number subclasses + CONFIGURATION-848: SubsetConfiguration does not account for delimiters as it did in 2.9.0 + CONFIGURATION-848: CompositeConfiguration does not account for delimiters as it did in 2.9.0 + Describe the security model + De-emphasize the 1.x version line on the website + CONFIGURATION-851: HomeDirectoryLocationStrategy no longer resolves the user HOME directory correctly - Upgrade to version 2.11.0 * New features + CONFIGURATION-844: Add support for empty sections + Add ImmutableConfiguration.containsValue(Object) * Fixed Bugs + Fail-fast with a NullPointerException if DataConfiguration .DataConfiguration(Configuration) is called with null + Fail-fast with a NullPointerException if XMLPropertiesConfiguration.XMLPropertiesConfiguration(Element) is called with null + Fail-fast with a NullPointerException if a SubsetConfiguration constructor is called with a null Configuration + CONFIGURATION-843: Methods should not be empty + Guard MapConfiguration against null maps + Fail-fast with a NullPointerException if AppletConfiguration(Applet) is called with null + Fail-fast with a NullPointerException if ServletConfiguration(Servlet) is called with null + Fail-fast with a NullPointerException if ServletConfiguration(ServletConfig) is called with null + Fail-fast with a NullPointerException if ServletContextConfiguration(Servlet) is called with null + Fail-fast with a NullPointerException if ServletContextConfiguration(ServletContext) is called with null + Fail-fast with a NullPointerException if ServletFilterConfiguration(FilterConfig) is called with null + Fail-fast with a NullPointerException if ServletRequestConfiguration(ServletRequest) is called with null + Deprecate DatabaseConfiguration.getDatasource() in favor of getDataSource() + Fix PMD DynamicCombinedConfiguration in AbstractImmutableNodeHandler + Fix PMD DynamicCombinedConfiguration in AbstractListDelimiterHandler + Fix PMD DynamicCombinedConfiguration in DefaultPrefixLookupsHolder + Fix PMD DynamicCombinedConfiguration in DynamicCombinedConfiguration + Fix PMD DynamicCombinedConfiguration in PropertiesConfiguration + CONFIGURATION-846: Restore previous behavior allowing Spring to inject multiple values + CONFIGURATION-847: Property with an empty string value was not processed ++++ apache-commons-text: - Upgrade to version 1.15.0 * New features + Add experimental CycloneDX VEX file + TEXT-235: Add Damerau-Levenshtein distance + Add unit tests to increase coverage + Add new test for CharSequenceTranslator#with() + Add tests and assertions to org.apache.commons.text.similarity to get to 100% code coverage * Fixed Bugs + Fix exception message typo in XmlStringLookup .XmlStringLookup(Map, Path...) + TEXT-236: Inserting at the end of a TextStringBuilder throws a StringIndexOutOfBoundsException + Fix TextStringBuilderTest.testAppendToCharBuffer() to use proper argument type + Fix Apache RAT plugin console warnings + Fix site XML to use version 2.0.0 XML schema + Removed unreachable threshold verification code in src/main/java/org/apache/commons/text/similarity + Enable secure processing for the XML parser in XmlStringLookup in case the underlying JAXP implementation doesn't - Upgrade to version 1.14.0 * New features + Interface StringLookup now extends UnaryOperator + Interface TextRandomProvider extends IntUnaryOperator + Add RandomStringGenerator.Builder .usingRandom(IntUnaryOperator) + Add PMD check to default Maven goal + Add org.apache.commons.text.RandomStringGenerator.Builder .setAccumulate(boolean) * Fixed Bugs + Fix PMD UnnecessaryFullyQualifiedName in StringLookupFactory + Fix PMD UnnecessaryFullyQualifiedName in DefaultStringLookupsHolder + Fix PMD UnnecessaryFullyQualifiedName in PropertiesStringLookup + Fix PMD UnnecessaryFullyQualifiedName in JavaPlatformStringLookup + Fix PMD UnnecessaryFullyQualifiedName in StringSubstitutor + Fix PMD UnnecessaryFullyQualifiedName in StrSubstitutor + Fix PMD UnnecessaryFullyQualifiedName in AlphabetConverter + Fix PMD AvoidBranchingStatementAsLastInLoop in TextStringBuilder + Fix PMD AvoidBranchingStatementAsLastInLoop in StrBuilder + org.apache.commons.text.translate.LookupTranslator .LookupTranslator(Map CharSequence>) now throws NullPointerException instead of java.security.InvalidParameterException - Upgrade to version 1.13.1 * Fixed Bugs + Remove -nouses directive from maven-bundle-plugin. OSGi package imports now state 'uses' definitions for package imports, this doesn't affect JPMS (from org.apache.commons:commons-parent:80) + Deprecate EntityArrays.EntityArrays() + StringLookupFactory.DefaultStringLookupsHolder .createDefaultStringLookups() maps DefaultStringLookup .LOCAL_HOST twice instead of once for LOCAL_HOST and LOOPBACK_ADDRESS - Upgrade to version 1.13.0 * New features + Add StringLookupFactory.loopbackAddressStringLookup() + Add StringLookupFactory.KEY_LOOPBACK_ADDRESS + Add DefaultStringLookup.LOOPBACK_ADDRESS + Add richer inputs in package org.apache.commons.text .similarity with SimilarityInput + Add HammingDistance.apply(SimilarityInput, SimilarityInput) + Add JaccardDistance.apply(SimilarityInput, SimilarityInput) + Add JaccardSimilarity.apply(SimilarityInput, SimilarityInput) + Add JaroWinklerDistance.apply(SimilarityInput, SimilarityInput) + Add JaroWinklerSimilarity.apply(SimilarityInput, SimilarityInput) + Add LevenshteinDetailedDistance.apply(SimilarityInput, SimilarityInput) + Add LevenshteinDistance.apply(SimilarityInput, SimilarityInput) * Fixed Bugs + Fix build on Java 22 + Fix build on Java 23-ea + Make package-private constructor private: StrLookup.MapStrLookup.MapStrLookup(Map) + Make package-private constructor private: StrLookup .SystemPropertiesStrLookup.SystemPropertiesStrLookup() + Make package-private class private and final: MapStrLookup + Make package-private class private: StrMatcher.CharMatcher + Make package-private class private: StrMatcher.CharSetMatcher + Make package-private class private: StrMatcher.NoMatcher + Make package-private class private: StrMatcher.StringMatcher + Make package-private class private: StrMatcher.TrimMatcher + Make package-private class private and final: IntersectionSimilarity.BagCount + Make package-private class private and final: IntersectionSimilarity.TinyCount + Deprecate LevenshteinDistance.LevenshteinDistance() in favor of LevenshteinDistance.getDefaultInstance() + Deprecate LevenshteinDetailedDistance .LevenshteinDetailedDistance() in favor of LevenshteinDetailedDistance.getDefaultInstance() + TEXT-234: Improve StrBuilder documentation for new line text + TEXT-234: Improve TextStringBuilder documentation for new line text + TEXT-233: Required OSGi Import-Package version numbers in MANIFEST.MF - Upgrade to version 1.12.0 * New features + Add StringLookupFactory.fileStringLookup(Path...) and deprecated fileStringLookup() + Add StringLookupFactory.propertiesStringLookup(Path...) and deprecated propertiesStringLookup() + Add StringLookupFactory.xmlStringLookup(Map, Path...) and deprecated xmlStringLookup() and xmlStringLookup(Map) + Add StringLookupFactory.builder() for fencing Path resolution of the file, properties and XML lookups + Add DoubleFormat.Builder.get() as Builder now implements Supplier * Fixed Bugs + TEXT-232: WordUtils.containsAllWords?() may throw PatternSyntaxException + TEXT-175: Fix regression for determining whitespace in WordUtils + Deprecate Builder in favor of Supplier - Upgrade to version 1.11.0 * New features + TEXT-224: Set SecureProcessing feature in XmlStringLookup by default + TEXT-224: Add StringLookupFactory.xmlStringLookup(Map...) + Add @FunctionalInterface to FormatFactory + Add RandomStringGenerator.builder() + TEXT-229: Add XmlEncoderStringLookup/XmlDecoderStringLookup + Add StringSubstitutor.toString() * Fixed Bugs + TEXT-219: Fix StringTokenizer.getTokenList to return an independent modifiable list + Fix Javadoc for StringEscapeUtils.escapeHtml4 + TextStringBuidler#hashCode() allocates a String on each call + TEXT-221: Fix Bundle-SymbolicName to use the package name org.apache.commons.text + Add and use a package-private singleton for RegexTokenizer + Add and use a package-private singleton for CosineSimilarity + Add and use a package-private singleton for LongestCommonSubsequence + Add and use a package-private singleton for JaroWinklerSimilarity + Add and use a package-private singleton for JaccardSimilarity + [StepSecurity] ci: Harden GitHub Actions + Improve AlphabetConverter Javadoc + Fix exception message in IntersectionResult to make set-theoretic sense + Add null-check in RandomStringGenerator#Builder#selectFrom() to avoid NullPointerException + Add null-check in RandomStringGenerator#Builder#withinRange() to avoid NullPointerException + TEXT-228: Fix TextStringBuilder to over-allocate when ensuring capacity + Constructor for ResourceBundleStringLookup should be private instead of package-private + Constructor for UrlDecoderStringLookup should be private instead of package-private + Constructor for UrlEncoderStringLookup should be private instead of package-private + TEXT-230: Javadoc of org.apache.commons.text.lookup .DefaultStringLookup.XML is incorrect + Update DoubleFormat to state it is based on Double.toString ++++ apache2: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-devel: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-devel: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-event: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-event: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-manual: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-manual: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-prefork: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-prefork: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-utils: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-utils: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-worker: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ apache2-worker: * Fix bsc#1263957 / CVE-2026-23918. * Fix bsc#1263953 / CVE-2026-33523. * Fix bsc#1263955 / CVE-2026-33006. * Fix bsc#1263956 / CVE-2026-29169. * Fix bsc#1263935 / CVE-2026-24072. * Fix bsc#1263950 / CVE-2026-34059. * Fix bsc#1263951 / CVE-2026-34032. * Add patch files: - CVE-2026-23918.patch - CVE-2026-33523.patch - CVE-2026-33006.patch - CVE-2026-29169.patch - CVE-2026-24072.patch - CVE-2026-34059.patch - CVE-2026-34032.patch ++++ binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ kernel-64kb: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-64kb: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-64kb: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-64kb: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-64kb: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-azure: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-azure: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-azure: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-azure: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-azure: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-default: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-default: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-default: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-default: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-default: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-rt: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-rt: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-rt: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-rt: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-rt: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ cross-aarch64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-arm-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-avr-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-bpf-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-epiphany-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-hppa-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-hppa64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-i386-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-ia64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-loongarch64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-m68k-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-mips-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-ppc-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-ppc64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-ppc64le-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-pru-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-riscv64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-rx-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-s390-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-s390x-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-sparc-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-sparc64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-spu-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-x86_64-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ cross-xtensa-binutils: - Add pr33427-fix-loongarch64-glibc-build-with-gcc16.patch to backport a fix for assertion failures when building glibc for loongarch64 with GCC 16. ++++ samba: - vfs_snapper failing to access or enumerate files in subfolders; (bso#16058); (bsc#1259667). ++++ dtb-aarch64: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ dtb-aarch64: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ dtb-aarch64: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ dtb-aarch64: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ dtb-aarch64: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ grpc: - Update to release 1.60 (bsc#1264447). * Implemented dualstack IPv4 and IPv6 backend support, as per draft gRFC A61. xDS support currently guarded by GRPC_EXPERIMENTAL_XDS_DUALSTACK_ENDPOINTS env var. * Support for setting proxy for addresses. * Add v1 reflection. - Added patches: * ARM-Unaligned-access-fixes.patch Fix unaligned access on ARM which causes issues on AArch64 kernels * Fix-compilation-on-RHEL-7-ppc64le-gcc-4.8.patch Fix FTBFS on ppc64le when using gcc-7 (boo#1208794) - Refreshed patches: * grpc-CVE-2024-7246.patch ++++ kernel-source: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-source: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-source: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-source: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-source: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-docs: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-docs: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-docs: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-docs: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-docs: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-kvmsmall: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-kvmsmall: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-kvmsmall: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-kvmsmall: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-kvmsmall: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-build: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-build: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-build: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-build: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-build: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-qa: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-qa: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-qa: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-qa: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-obs-qa: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-syms: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-syms: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-syms: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-syms: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-syms: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-zfcpdump: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-zfcpdump: - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-zfcpdump: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-zfcpdump: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ kernel-zfcpdump: - netfilter: xt_multiport: validate range encoding in checkentry (CVE-2026-31681 bsc#1263593). - commit 51b6dbb - netfilter: nft_ct: drop pending enqueued packets on removal (CVE-2026-43060 bsc#1264183). - commit 45a5b23 - netfilter: flowtable: strictly check for maximum number of actions (CVE-2026-43329 bsc#1265085). - commit 2044fe7 - netfilter: nf_conntrack_expect: skip expectations in other netns via proc (CVE-2026-31496 bsc#1262673). - commit c2fbef4 - net: af_key: zero aligned sockaddr tail in PF_KEY exports (CVE-2026-43088 bsc#1264469). - commit d4c3a74 - io_uring/kbuf: check if target buffer list is still legacy on recycle (CVE-2026-43366 bsc#1265116). - commit 3d68eb1 - mm/pagewalk: fix race between concurrent split and refault (CVE-2026-31456 bsc#1262627). - commit 66d2a63 - KVM: nVMX: Add consistency check for TSC_MULTIPLIER=0 (git-fixes). - commit e1d61c7 - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - commit 8c874fe - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - commit 91ba5ef - io-wq: check that the predecessor is hashed in io_wq_remove_pending() (git-fixes). - commit 7709fe4 ++++ rqlite: - Update to version 10.0.5: significantly improves clustering, data integrity guarantees, and makes managing rqlite easier. * introduces a major improvement to the Raft Snapshot and Log Truncation process. Previously, a Snapshot stream to a Follower would block the Leader from taking new Snapshots. Normally a subsequent retry of the snapshot operation would succeed, but a persistently slow Follower that kept requiring Snapshots could starve the Leader entirely. With v10, Snapshotting on the Leader is no longer blocked by any other operation happening in the Snapshot Store, including streaming a pre-existing snapshot to a Follower. * Concurrent read and write access to the database has been improved. In previous releases Raft snapshotting -- and, as a result, writes -- could be blocked for an extended period if there was a long-running read. In v10 the Raft snapshotting process is canceled and retried later if a long-running read is active. * v10 also uses CRC32 checksumming more comprehensively to detect issues such as file system corruption and inadvertent modification of the underlying data files by systems other than rqlite. * introduces a new built-in console app, making it more convenient to manage a rqlite deployment. The console app is available at http://localhost:4001/console by default. * Upgrading from v7 or later is seamless and has been extensively tested, though upgrading first to the latest v9 release is recommended. Upgrading to v10 supports rolling upgrades, but you cannot join a new v10 node to a v9 (or earlier) cluster. Upgrade your existing cluster to v10 before adding new nodes. Back up your rqlite system before upgrading. * cli change: -on-disk-path has been removed. It provided little benefit while making it too easy to corrupt a node. To upgrade a rqlite system which uses this flag first backup your rqlite node deploy a new v10 system, and then initialize the new deployment using the backup. * cli change: -raft-timeout is now -raft-heartbeat-timeout, to better reflect its purpose. ++++ rqlite: - Update to version 10.0.5: significantly improves clustering, data integrity guarantees, and makes managing rqlite easier. * introduces a major improvement to the Raft Snapshot and Log Truncation process. Previously, a Snapshot stream to a Follower would block the Leader from taking new Snapshots. Normally a subsequent retry of the snapshot operation would succeed, but a persistently slow Follower that kept requiring Snapshots could starve the Leader entirely. With v10, Snapshotting on the Leader is no longer blocked by any other operation happening in the Snapshot Store, including streaming a pre-existing snapshot to a Follower. * Concurrent read and write access to the database has been improved. In previous releases Raft snapshotting -- and, as a result, writes -- could be blocked for an extended period if there was a long-running read. In v10 the Raft snapshotting process is canceled and retried later if a long-running read is active. * v10 also uses CRC32 checksumming more comprehensively to detect issues such as file system corruption and inadvertent modification of the underlying data files by systems other than rqlite. * introduces a new built-in console app, making it more convenient to manage a rqlite deployment. The console app is available at http://localhost:4001/console by default. * Upgrading from v7 or later is seamless and has been extensively tested, though upgrading first to the latest v9 release is recommended. Upgrading to v10 supports rolling upgrades, but you cannot join a new v10 node to a v9 (or earlier) cluster. Upgrade your existing cluster to v10 before adding new nodes. Back up your rqlite system before upgrading. * cli change: -on-disk-path has been removed. It provided little benefit while making it too easy to corrupt a node. To upgrade a rqlite system which uses this flag first backup your rqlite node deploy a new v10 system, and then initialize the new deployment using the backup. * cli change: -raft-timeout is now -raft-heartbeat-timeout, to better reflect its purpose. - includes fix for CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (boo#1265706) ------------------------------------------------------------------ ------------------ 2026-5-13 - May 13 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaFirefox: - Firefox Extended Support Release 140.11.0 ESR * Fixed: Various security fixes. MFSA 2026-48 (bsc#1265212) * CVE-2026-8946 (bmo#2029070) Incorrect boundary conditions in the Audio/Video: Web Codecs component * CVE-2026-8388 (bmo#2036978) Incorrect boundary conditions in the JavaScript Engine: JIT component * CVE-2026-8947 (bmo#2038439) Use-after-free in the DOM: Bindings (WebIDL) component * CVE-2026-8391 (bmo#2038575) Other issue in the JavaScript Engine component * CVE-2026-8401 (bmo#2038679) Sandbox escape in the Profile Backup component * CVE-2026-8949 (bmo#1355639) Integer overflow in the Widget: Win32 component * CVE-2026-8950 (bmo#1965430) Same-origin policy bypass in the Networking: HTTP component * CVE-2026-8953 (bmo#2029511) Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-8954 (bmo#2030747) Incorrect boundary conditions, integer overflow in the Audio/Video component * CVE-2026-8955 (bmo#2031064) Privilege escalation in the DOM: Workers component * CVE-2026-8956 (bmo#2032427) Integer overflow in the Networking: JAR component * CVE-2026-8957 (bmo#2033850) Privilege escalation in the Enterprise Policies component * CVE-2026-8958 (bmo#2034713) Information disclosure, sandbox escape in the Security: Process Sandboxing component * CVE-2026-8959 (bmo#2034754) Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component * CVE-2026-8961 (bmo#1962625) Spoofing issue in the Form Autofill component * CVE-2026-8962 (bmo#2004804) Mitigation bypass in the DOM: Security component * CVE-2026-8968 (bmo#2030467) Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component * CVE-2026-8970 (bmo#2032174) Privilege escalation in the Security component * CVE-2026-8974 (bmo#1784128, bmo#1883230, bmo#1983677, bmo#2022390, bmo#2023116, bmo#2023657, bmo#2024255, bmo#2024418, bmo#2024441, bmo#2024447, bmo#2024966, bmo#2025412, bmo#2025467, bmo#2025940, bmo#2025950, bmo#2025956, bmo#2026284, bmo#2027247, bmo#2027255, bmo#2027288, bmo#2027306, bmo#2027322, bmo#2027332, bmo#2027333, bmo#2028266, bmo#2028292, bmo#2028319, bmo#2028526, bmo#2028870, bmo#2028876, bmo#2028882, bmo#2029062, bmo#2029309, bmo#2029414, bmo#2029422, bmo#2029428, bmo#2029447, bmo#2029732, bmo#2029785, bmo#2029793, bmo#2029813, bmo#2029899, bmo#2031028, bmo#2031457, bmo#2032039, bmo#2033610, bmo#2033854, bmo#2034498, bmo#2034628, bmo#2034978, bmo#2035966, bmo#2036668, bmo#2036905, bmo#2036930) Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 * CVE-2026-8975 (bmo#1860195, bmo#2029325, bmo#2029429, bmo#2029910, bmo#2035915, bmo#2038669, bmo#2038678) Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 ++++ MozillaFirefox: - Firefox Extended Support Release 140.11.0 ESR * Fixed: Various security fixes. MFSA 2026-48 (bsc#1265212) * CVE-2026-8946 (bmo#2029070) Incorrect boundary conditions in the Audio/Video: Web Codecs component * CVE-2026-8388 (bmo#2036978) Incorrect boundary conditions in the JavaScript Engine: JIT component * CVE-2026-8947 (bmo#2038439) Use-after-free in the DOM: Bindings (WebIDL) component * CVE-2026-8391 (bmo#2038575) Other issue in the JavaScript Engine component * CVE-2026-8401 (bmo#2038679) Sandbox escape in the Profile Backup component * CVE-2026-8949 (bmo#1355639) Integer overflow in the Widget: Win32 component * CVE-2026-8950 (bmo#1965430) Same-origin policy bypass in the Networking: HTTP component * CVE-2026-8953 (bmo#2029511) Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-8954 (bmo#2030747) Incorrect boundary conditions, integer overflow in the Audio/Video component * CVE-2026-8955 (bmo#2031064) Privilege escalation in the DOM: Workers component * CVE-2026-8956 (bmo#2032427) Integer overflow in the Networking: JAR component * CVE-2026-8957 (bmo#2033850) Privilege escalation in the Enterprise Policies component * CVE-2026-8958 (bmo#2034713) Information disclosure, sandbox escape in the Security: Process Sandboxing component * CVE-2026-8959 (bmo#2034754) Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component * CVE-2026-8961 (bmo#1962625) Spoofing issue in the Form Autofill component * CVE-2026-8962 (bmo#2004804) Mitigation bypass in the DOM: Security component * CVE-2026-8968 (bmo#2030467) Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component * CVE-2026-8970 (bmo#2032174) Privilege escalation in the Security component * CVE-2026-8974 (bmo#1784128, bmo#1883230, bmo#1983677, bmo#2022390, bmo#2023116, bmo#2023657, bmo#2024255, bmo#2024418, bmo#2024441, bmo#2024447, bmo#2024966, bmo#2025412, bmo#2025467, bmo#2025940, bmo#2025950, bmo#2025956, bmo#2026284, bmo#2027247, bmo#2027255, bmo#2027288, bmo#2027306, bmo#2027322, bmo#2027332, bmo#2027333, bmo#2028266, bmo#2028292, bmo#2028319, bmo#2028526, bmo#2028870, bmo#2028876, bmo#2028882, bmo#2029062, bmo#2029309, bmo#2029414, bmo#2029422, bmo#2029428, bmo#2029447, bmo#2029732, bmo#2029785, bmo#2029793, bmo#2029813, bmo#2029899, bmo#2031028, bmo#2031457, bmo#2032039, bmo#2033610, bmo#2033854, bmo#2034498, bmo#2034628, bmo#2034978, bmo#2035966, bmo#2036668, bmo#2036905, bmo#2036930) Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151 * CVE-2026-8975 (bmo#1860195, bmo#2029325, bmo#2029429, bmo#2029910, bmo#2035915, bmo#2038669, bmo#2038678) Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151 ++++ apache2: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-devel: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-devel: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-devel: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-event: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-event: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-event: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-manual: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-manual: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-manual: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-prefork: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-prefork: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-prefork: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-utils: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-utils: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-utils: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-worker: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-worker: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ apache2-worker: - Version update to 2.4.66 (jsc#PED-16181) * ) SECURITY: CVE-2025-66200: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (cve.mitre.org) mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: from 2.4.7 through 2.4.65. * ) SECURITY: CVE-2025-65082: Apache HTTP Server: CGI environment variable override (cve.mitre.org) Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs. This issue affects Apache HTTP Server from 2.4.0 through 2.4.65. * ) SECURITY: CVE-2025-59775: Apache HTTP Server: NTLM Leakage on Windows through UNC SSRF (cve.mitre.org) Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content * ) SECURITY: CVE-2025-58098: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (cve.mitre.org) Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. * ) SECURITY: CVE-2025-55753: Apache HTTP Server: mod_md (ACME), unintended retry intervals (cve.mitre.org) An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. * ) mod_http2: Fix handling of 304 responses from mod_cache. * ) mod_http2/mod_proxy_http2: fix a bug in calculating the log2 value of integers, used in push diaries and proxy window size calculations. * ) mod_md: update to version 2.6.5 - New directive `MDInitialDelay`, controlling how longer to wait after a server restart before checking certificates for renewal. [Michael Kaufmann] - Hardening: when build with OpenSSL older than 1.0.2 or old libressl versions, the parsing of ASN.1 time strings did not do a length check. - Hardening: when reading back OCSP responses stored in the local JSON store, missing 'valid' key led to uninitialized values, resulting in wrong refresh behaviour. * ) mod_md: update to version 2.6.6 - Fix a small memory leak when using OpenSSL's BIGNUMs. - Fix reuse of curl easy handles by resetting them. * ) mod_http2: update to version 2.0.35 New directive `H2MaxStreamErrors` to control how much bad behaviour by clients is tolerated before the connection is closed. * ) mod_proxy_http2: add support for ProxyErrorOverride directive. * ) mpm_common: Add new ListenTCPDeferAccept directive that allows to specify the value set for the TCP_DEFER_ACCEPT socket option on listen sockets. * ) mod_ssl: Add SSLVHostSNIPolicy directive to control the virtual host compatibility policy. * ) mod_md: update to version 2.6.2 - Fix error retry delay calculation to not already doubling the wait on the first error. * ) mod_md: update to version 2.6.1 - Increasing default `MDRetryDelay` to 30 seconds to generate less bursty traffic on errored renewals for the ACME CA. This leads to error retries of 30s, 1 minute, 2, 4, etc. up to daily attempts. - Checking that configuring `MDRetryDelay` will result in a positive duration. A delay of 0 is not accepted. - Fix a bug in checking Content-Type of responses from the ACME server. - Added ACME ARI support (rfc9773) to the module. Enabled by default. New directive "MDRenewViaARI on|off" for controlling this. - Removing tailscale support. It has not been working for a long time as the company decided to change their APIs. Away with the dead code, documentation and tests. - Fixed a compilation issue with pre-industrial versions of libcurl. - httpd testsuite of svn revision 1929573 - Remove the following patches, as they've been upstream as of 2.4.66: * CVE-2024-42516.patch * CVE-2024-43204.patch * CVE-2024-47252.patch * CVE-2025-23048.patch * CVE-2025-49630.patch * CVE-2025-49812.patch * CVE-2025-53020.patch * CVE-2025-55753.patch * CVE-2025-58098.patch * CVE-2025-65082.patch * CVE-2025-66200.patch - Refresh patches: * apache-test-application-xml-type.patch * apache-test-turn-off-variables-in-ssl-var-lookup.patch * apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch * apache2-LimitRequestFieldSize-limits-headers.patch ++++ libcaca: - Improve the fix of CVE-2026-42046 for 32bit system. [Fix-32-bit-overflow-in-CVE-2026-42046-patch.patch, bsc#1264984, CVE-2026-42046] ++++ kernel-64kb: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-64kb: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-64kb: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-64kb: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-64kb: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-azure: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-azure: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-azure: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-azure: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-azure: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-default: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-default: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-default: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-default: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-default: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-rt: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-rt: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-rt: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-rt: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-rt: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ docker: - Update to Docker 29.4.0. See upstream changelog online at - Update to buildx 0.33.0. See upstream changelog online at - Rebased patches: * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch - Removed patch * 0007-CVE-2025-58181-fix-vendor-crypto-ssh.patch (applicable only when docker version < v29.1.0) ++++ docker: - Update to Docker 29.4.0. See upstream changelog online at - Update to buildx 0.33.0. See upstream changelog online at - Rebased patches: * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch - Removed patch * 0007-CVE-2025-58181-fix-vendor-crypto-ssh.patch (applicable only when docker version < v29.1.0) ++++ dtb-aarch64: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ dtb-aarch64: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ dtb-aarch64: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ dtb-aarch64: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ dtb-aarch64: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ elemental-system-agent: - Update to version 0.3.16: * setup for immutable releases (#274) * align system-agent image publishing for signed releases (#270) * Bumo github.com/docker/cli to v29.2.0 and go.opentelemetry.io/otel to v1.43.0 * run go mod tidy in /test folder * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (bsc#1260277 CVE-2026-33186) * Bump github.com/docker/cli in /test * export CATTLE_NODE_NAME if SYSTEM_UPGRADE_NODE_NAME is set * use correct prefix for system-agent binary (#273) * checksum validation (#271) * Add `validate` subcommand for configuration validation (#250) * Update CODEOWNERS * Pin GH Actions to commit sha * chore: bump sles to 15.7 * Extend remote plan e2e tests * Fix agent restart issue and introduce constants * chore: bump go to v1.25 * Setup e2e test infrastructure * chores(deps): Bump k8s dependencies * Define linter rules * Fix CI failures * Introduce an extended Makefile * Switch workflows to use name makefile * Replace dapper with multi stage builds * Remove dapper scripts * Add multiple improvements for ignore files * fix: remove umask command from the system-agent unit-file * fix-system-agent-umask * [1.34] bumped dependencies for 1.34 support (#242) * Bump K8s patch level to 1.33.5 and Go patch level to 1.24.6 * fix: properly handle traps after unsuccessful SUC job execution * fix: do not unconditionally reset failure-counts * fix: remove resetFailureCountOnStartup, always reset failure counts on first start * un-rc wrangler and lasso * drop windows 2019 when running PR CI ++++ ffmpeg-4: - Add ffmpeg-4-CVE-2026-40962.patch: Use 64bit in CENC subsample bounds checks. (CVE-2026-40962, bsc#1262237) ++++ ffmpeg-4: - Add ffmpeg-4-CVE-2026-40962.patch: Use 64bit in CENC subsample bounds checks. (CVE-2026-40962, bsc#1262237) ++++ ffmpeg-4: - Add ffmpeg-4-CVE-2026-40962.patch: Use 64bit in CENC subsample bounds checks. (CVE-2026-40962, bsc#1262237) ++++ ffmpeg-7: - Add ffmpeg-7-CVE-2026-40962.patch: Use 64bit in CENC subsample bounds checks. (CVE-2026-40962, bsc#1262237) ++++ ffmpeg-7: - Add ffmpeg-7-CVE-2026-40962.patch: Use 64bit in CENC subsample bounds checks. (CVE-2026-40962, bsc#1262237) ++++ gdm: - Drop xdm-integration in SLE 16.1 to remove the update-alternatives dependency (bsc#1264389, jsc#PED-15673). ++++ glab: - Update to version 1.97.0: * Features - 2b685d63: feat(orbit): add 'glab orbit local' command + extract binarymgr package (Kai Armstrong karmstrong@gitlab.com) * Others - ee2757f9: test(ask): skip flaky TestAskCmd ahead of removal (Kai Armstrong karmstrong@gitlab.com) - Update to version 1.96.0: * Features - 43f15255: feat: add duo cli support for arm64 windows (Andrei Zubov azubov@gitlab.com) * Bug Fixes - d14064ca: fix(cmdutils): Avoid race on global viper state in GroupOverride (Caleb Madara calebmadara58@gmail.com) * Dependencies - ce62ac33: chore(deps): bump go to v1.26.3 (Kai Armstrong karmstrong@gitlab.com) - cd438239: chore(deps): update dependency @commitlint/cli to ^20.5.3 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - 5a11bf9b: chore(dep): update x/net (Filip Aleksic faleksic@gitlab.com) - 31255b35: refactor(git): decouple StandardGitCommand from run.PrepareCmd (Gary Holtz gholtz@gitlab.com) ++++ go-sendxmpp: - Update to 0.15.8: * Fix windows build (windows doesn't support syscalls Setgid and Setuid). - Update to 0.15.7: * Fix http-upload with legacy PGP encryption. * Fix reading of environment variables. * Fix a bug in looking up host meta 2. * Try to drop root privileges before connecting to the server. * Fix crash if a config key has no value. * Use a salt for stored FAST token. * Increase scrypt iterations for storing FAST token from 32768 to 65536. * Log a warning when --no-tls-verify or -n is set. ++++ google-guest-agent: - Add CVE-2026-33186.patch to fix authorization bypass in grpc-go due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260264, CVE-2026-33186) ++++ google-guest-agent: - Packaging improvements: * Remove define github project name components no longer needed * Define shortname corresponding to binary name when different from package name. Use shortname where applicable to normalize common lines across Go app packages, similar to name macro. * Drop BuildRequires: golang-packaging. The original macros for file movements into GOPATH are obsolete with Go modules. Macro go_nostrip is no longer needed with current binutils and Go. * Remove go_nostrip macro which is no longer recommended * Re-enable binary stripping and debuginfo boo#1210938 * Remove goprep macro which is no longer recommended * Build PIE with pattern that may become recommended procedure: %%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build A go toolchain buildmode default config would be preferable but none exist at this time. * Drop export CGO_ENABLED="0". Use the default unless there is a defined requirement or benefit. * For this package, we were seeing the expected error "-buildmode=pie requires external (cgo) linking, but cgo is not enabled" when using buildmode=pie and CGO_ENABLED=0. The error manifested only on s390x and i586 architectures, which was not expected. Resolve by using default CGO_ENABLED. * Remove ldflags -s (Omit symbol table and debug info) and -w (Omit DWARF symbol table). This information is used to produce separate debuginfo packages and binaries are stripped for reduced size by GNU strip during RPM build. * Remove ldflags -X entry for embedding build version metadata. This information is embedded in binaries with go1.18+ and available via go version -m or runtime/debug.ReadBuildInfo(). * Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable ++++ google-guest-agent: - Packaging improvements: * Remove define github project name components no longer needed * Define shortname corresponding to binary name when different from package name. Use shortname where applicable to normalize common lines across Go app packages, similar to name macro. * Drop BuildRequires: golang-packaging. The original macros for file movements into GOPATH are obsolete with Go modules. Macro go_nostrip is no longer needed with current binutils and Go. * Remove go_nostrip macro which is no longer recommended * Re-enable binary stripping and debuginfo boo#1210938 * Remove goprep macro which is no longer recommended * Build PIE with pattern that may become recommended procedure: %%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build A go toolchain buildmode default config would be preferable but none exist at this time. * Drop export CGO_ENABLED="0". Use the default unless there is a defined requirement or benefit. * For this package, we were seeing the expected error "-buildmode=pie requires external (cgo) linking, but cgo is not enabled" when using buildmode=pie and CGO_ENABLED=0. The error manifested only on s390x and i586 architectures, which was not expected. Resolve by using default CGO_ENABLED. * Remove ldflags -s (Omit symbol table and debug info) and -w (Omit DWARF symbol table). This information is used to produce separate debuginfo packages and binaries are stripped for reduced size by GNU strip during RPM build. * Remove ldflags -X entry for embedding build version metadata. This information is embedded in binaries with go1.18+ and available via go version -m or runtime/debug.ReadBuildInfo(). * Drop mod=vendor, go1.14+ will detect vendor dir and auto-enable - Add CVE-2026-33186.patch to fix authorization bypass in grpc-go due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260264, CVE-2026-33186) ++++ google-osconfig-agent: - Update to version 20260511.00 * switch to t2a-standard-2 on ARM package build (#977) - from version 20260505.03 * Cover zypper_patch by unit tests (#958) - from version 20260505.02 * Remove unused functions DisableAutoUpdates (#970) - from version 20260505.01 * Bump go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc (#966) - from version 20260505.00 * Upgrade a few dependencies across the repo (#968) + github.com/go-git/go-git/v5 5.16.2->5.18.0 (bsc#1264923, CVE-2026-41506) + github.com/go-jose/go-jose/v4 4.1.3->4.1.4 (bsc#1262926, CVE-2026-34986) + github.com/go-viper/mapstructure/v2 2.3.0->2.4.0 + go.opentelemetry.io/otel 1.40.0->1.41.0 + go.opentelemetry.io/otel/sdk 1.39.0->1.43.0 - from version 20260504.01 * bump github.com/docker/cli to 29.2.0 (#962) - from version 20260504.00 * Bump github.com/opencontainers/selinux (#960) - Add missing CVE reference to previous changelog entry - Drop CVE-2026-34986.patch, merged upstream ++++ helmfile: - Update to version 1.5.1: * fix: add trackFailOnError option to control kubedog exit code by @yxxhero in #2576 * docs: update helmfile skill to reflect v1.1 documentation by @yxxhero in #2577 * fix(state): resolve OCI repo prefix in ad-hoc release dependencies by @dschmidt in #2579 * feat(state): add mergeStrategy: fallback for first-file-wins env values by @dschmidt in #2578 * Expose internal apis by @ceriath in #2520 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.1 to 1.101.0 by @dependabot[bot] in #2581 * chore: Deduplicate preparation code of sync and apply by @ceriath in #2523 * build(deps): bump gitpython from 3.1.47 to 3.1.49 in /docs by @dependabot[bot] in #2582 * chore: Emit "cleanup" events later to match the behavior in "apply" by @ceriath in #2522 * build(deps): bump golang.org/x/term from 0.42.0 to 0.43.0 by @dependabot[bot] in #2584 * build(deps): bump gitpython from 3.1.49 to 3.1.50 in /docs by @dependabot[bot] in #2585 * fix: template helmDefaults.postRendererArgs with release data by @yxxhero in #2583 ++++ helmfile: - Update to version 1.5.1: * fix: add trackFailOnError option to control kubedog exit code by @yxxhero in #2576 * docs: update helmfile skill to reflect v1.1 documentation by @yxxhero in #2577 * fix(state): resolve OCI repo prefix in ad-hoc release dependencies by @dschmidt in #2579 * feat(state): add mergeStrategy: fallback for first-file-wins env values by @dschmidt in #2578 * Expose internal apis by @ceriath in #2520 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.1 to 1.101.0 by @dependabot[bot] in #2581 * chore: Deduplicate preparation code of sync and apply by @ceriath in #2523 * build(deps): bump gitpython from 3.1.47 to 3.1.49 in /docs by @dependabot[bot] in #2582 * chore: Emit "cleanup" events later to match the behavior in "apply" by @ceriath in #2522 * build(deps): bump golang.org/x/term from 0.42.0 to 0.43.0 by @dependabot[bot] in #2584 * build(deps): bump gitpython from 3.1.49 to 3.1.50 in /docs by @dependabot[bot] in #2585 * fix: template helmDefaults.postRendererArgs with release data by @yxxhero in #2583 ++++ helmfile: - Update to version 1.5.1: * fix: add trackFailOnError option to control kubedog exit code by @yxxhero in #2576 * docs: update helmfile skill to reflect v1.1 documentation by @yxxhero in #2577 * fix(state): resolve OCI repo prefix in ad-hoc release dependencies by @dschmidt in #2579 * feat(state): add mergeStrategy: fallback for first-file-wins env values by @dschmidt in #2578 * Expose internal apis by @ceriath in #2520 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.1 to 1.101.0 by @dependabot[bot] in #2581 * chore: Deduplicate preparation code of sync and apply by @ceriath in #2523 * build(deps): bump gitpython from 3.1.47 to 3.1.49 in /docs by @dependabot[bot] in #2582 * chore: Emit "cleanup" events later to match the behavior in "apply" by @ceriath in #2522 * build(deps): bump golang.org/x/term from 0.42.0 to 0.43.0 by @dependabot[bot] in #2584 * build(deps): bump gitpython from 3.1.49 to 3.1.50 in /docs by @dependabot[bot] in #2585 * fix: template helmDefaults.postRendererArgs with release data by @yxxhero in #2583 ++++ helmfile: - Update to version 1.5.1: * fix: add trackFailOnError option to control kubedog exit code by @yxxhero in #2576 * docs: update helmfile skill to reflect v1.1 documentation by @yxxhero in #2577 * fix(state): resolve OCI repo prefix in ad-hoc release dependencies by @dschmidt in #2579 * feat(state): add mergeStrategy: fallback for first-file-wins env values by @dschmidt in #2578 * Expose internal apis by @ceriath in #2520 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.1 to 1.101.0 by @dependabot[bot] in #2581 * chore: Deduplicate preparation code of sync and apply by @ceriath in #2523 * build(deps): bump gitpython from 3.1.47 to 3.1.49 in /docs by @dependabot[bot] in #2582 * chore: Emit "cleanup" events later to match the behavior in "apply" by @ceriath in #2522 * build(deps): bump golang.org/x/term from 0.42.0 to 0.43.0 by @dependabot[bot] in #2584 * build(deps): bump gitpython from 3.1.49 to 3.1.50 in /docs by @dependabot[bot] in #2585 * fix: template helmDefaults.postRendererArgs with release data by @yxxhero in #2583 ++++ kernel-source: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-source: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-source: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-source: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-source: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-docs: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-docs: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-docs: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-docs: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-docs: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-kvmsmall: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-kvmsmall: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-kvmsmall: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-kvmsmall: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-kvmsmall: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-obs-build: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-obs-build: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-obs-build: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-obs-build: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-obs-build: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-obs-qa: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-obs-qa: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-obs-qa: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-obs-qa: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-obs-qa: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-syms: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-syms: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-syms: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-syms: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-syms: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-zfcpdump: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-zfcpdump: - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 ++++ kernel-zfcpdump: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-zfcpdump: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ kernel-zfcpdump: - pmdomain: bcm: bcm2835-power: Increase ASB control timeout (CVE-2026-31550 bsc#1263104) - commit b1bcef2 - net: skbuff: propagate shared-frag marker through pskb_copy() (CVE-2026-46300 bsc#1265209). - commit f71c962 - drm/panthor: fix for dma-fence safe access rules (CVE-2025-71302 bsc#1264837). - commit e1e86cf - KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (CVE-2026-43265 bsc#1264427). - commit e23f394 - openvswitch: vport: fix self-deadlock on release of tunnel ports (git-fixes). - commit 7143335 - Refresh patches.suse/x86-CPU-AMD-Prevent-improper-isolation-of-shared-resources.patch. - commit 26bf91f - openvswitch: defer tunnel netdev_put to RCU release (CVE-2026-31678 bsc#1263562). - commit 56e44f5 - nfnetlink_osf: validate individual option lengths in fingerprints (CVE-2026-23397 bsc#1260728). - commit 86012c7 - xfs: fix undersized l_iclog_roundoff values (CVE-2026-43365 bsc#1265119). - commit 0d027d9 - net: sched: act_csum: validate nested VLAN headers (CVE-2026-31684 bsc#1263596). - commit cfad388 - net/sched: cls_fw: fix NULL dereference of "old" filters before change() (git-fixes). - commit 3fc3976 - ipv6: avoid overflows in ip6_datagram_send_ctl() (CVE-2026-31415 bsc#1262099). - net/sched: cls_fw: fix NULL pointer dereference on shared blocks (CVE-2026-31421 bsc#1262061). - ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037 bsc#1263995). - af_key: validate families in pfkey_send_migrate() (CVE-2026-31515 bsc#1262752). - openvswitch: validate MPLS set/set_masked payload length (CVE-2026-31679 bsc#1263592). - commit 1dd4910 - net/sched: sch_netem: fix out-of-bounds access in packet corruption (CVE-2026-31675 bsc#1263556). - commit 9c1c60a - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - commit 45266f7 - net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (CVE-2026-31700 bsc#1263882). - commit 2ec21fc ++++ keylime: - Update to version 7.14.2 (CVE-2026-6420, bsc#1264265): * Bump to version 7.14.2 * verifier: Fix hardcoded attestation challenge nonce (CVE-2026-6420) * verifier: Extend TOCTOU race guard to TENANT_FAILED state * test: Add unit tests for _complete_deletion_if_terminated * verifier: Fix pyright reportArgumentType for mtls_cert * verifier: Fix TOCTOU race in process_agent state writes * docs: address wildcard bind feedback, document 0.0.0.0 / :: instead of * * Document verifier wildcard bind address * Place attestation fields in correct API version docs * Add attestation_status, attestation_period, maximum_attestation_interval * verifier: Fix type error in mtls_cert guard * ci: Replace /var/run/dbus with /run/dbus in test wrapper * installer: Replace /var/run/keylime with /run/keylime * Replace /var/run/keylime with /run/keylime in Python code * shared_data: Remove log calls from cleanup * shared_data: Use temp dir when /var/run/keylime/ is not usable * [Automatic] Update Keylime base image 2026-05-04 * [Automatic] Update Keylime base image 2026-05-01 * installer: Add tmpfiles.d config for all keylime directories * shared_data: Move SyncManager socket to /var/run/keylime/ * test: Support test execution for installed package * timestamp: Fix timezone handling in Unix timestamp conversion * shared_data: Ignore SIGTERM and SIGINT on Manager and parent processes * verifier: Cancel pending poll timer on agent stop * test: Add tests for pending-event and attestation storage * verifier: Prevent race condition when deleting agent * verifier: Replace assert with proper error handling * json: Suppress mypy call-overload false positive * Switch from CA organization of MITLL to Keylime * [Automatic] Update Keylime base image 2026-04-01 * Add unit tests for shutdown coordination and drain logic * Add graceful shutdown and lifecycle hooks to new Server architecture * Cancel pending retries and drain in-flight work on verifier shutdown * Add shutdown coordination module * Fix SharedDataManager cleanup crash in forked worker processes * docs: Add tables with push-attestation configuration options * templates: Sync agent config options with keylime-agent.conf * templates: Remove unused ima_ml_count_file option * Remove enable_authentication agent config option * fix(mem leak) - remove unbounded functools.cache from latest_attestation * fix: Add fork-safety to DBManager via dispose() * fix: Check active flag in _extract_identity and guard receive_pop * db: Clean up scoped session after each request * refactor: Remove dead code AuthSession.authenticate_agent() * Align black configuration between tox and pre-commit * Fix linter errors in PersistableModel.get() and .all() * Fix race condition on in SessionManager * Address some improvements from code review * Include thread-safe session management * Close DB sessions to prevent connection exhaustion * docs: Add v3.0 registrar API reference and changelog entry * tests: Add unit tests for v3 registrar routes and VersionController * registrar: Add routes for API version 3.0 * [Automatic] Update Keylime base image 2026-03-02 * [Automatic] Update Keylime base image 2026-03-01 * Document agent-driven (push) attestation * fix misspelling of overridden (#1856) * web: fix typo in base/route.py * Bump to version 7.14.1 * ca: Add Subject Alternative Names to the certificates * config: move push-mode options to [verifier] section in template * packit: Add missing tests * Fix session_lifetime default to prevent immediate token expiry * migrations: Fix migration to drop invalid sessions * tenant: Only negotiate API version v2.x * Fix leftover formatting issues * tests: fix measured boot tests to skip when efivarlibs is missing * tests: fix setup-rpm-tests to define _topdir ++++ postgresql18: - Update to version 18.4: * bsc#1265172, CVE-2026-6472: ensure the user has CREATE privilege on the schema specified * bsc#1265173, CVE-2026-6473: integer overflows in memory-allocation calculations * bsc#1265174, CVE-2026-6474: Guard against malicious time zone names * bsc#1265175, CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind * bsc#1265176, CVE-2026-6476: Properly quote subscription names in pg_createsubscriber * bsc#1265177, CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq * bsc#1265178, CVE-2026-6478: Use timing-safe string comparisons in authentication code * bsc#1265179, CVE-2026-6479: Prevent unbounded recursion while processing startup packets * bsc#1265180, CVE-2026-6575: Detect faulty input when restoring attribute MCV statistics * bsc#1265181, CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi * bsc#1265182, CVE-2026-6638: Properly quote object names in logical replication origin checks * https://www.postgresql.org/docs/release/18.4/ ++++ rrdtool: - Add fix-graph-overlapping-legends.patch * Fix overlapping graph labels (bsc#1262407) ++++ systemd: - Add a weak runtime dependency on libtss2-tcti-device0 (bsc#1260357) ++++ systemd: - Add a weak runtime dependency on libtss2-tcti-device0 (bsc#1260357) ++++ openssh: - Improve %prep LDAP regex to preserve subdirectories (e.g., ope- nbsd-compat/) and handle optional [ab]/ prefixes. ++++ pcr-oracle: - Update to 0.6.2 + Update the SBAT offset boundary check (bsc#1265042) ++++ postgresql-jdbc: - Limit SCRAM PBKDF2 iterations accepted from the server. CVE-2026-42198 (bsc#1264174) * Added: CVE-2026-42198.patch ++++ postgresql14: - Update to version 14.23: * bsc#1265172, CVE-2026-6472: ensure the user has CREATE privilege on the schema specified * bsc#1265173, CVE-2026-6473: integer overflows in memory-allocation calculations * bsc#1265174, CVE-2026-6474: Guard against malicious time zone names * bsc#1265175, CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind * bsc#1265177, CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq * bsc#1265178, CVE-2026-6478: Use timing-safe string comparisons in authentication code * bsc#1265179, CVE-2026-6479: Prevent unbounded recursion while processing startup packets * bsc#1265181, CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi * https://www.postgresql.org/docs/release/14.23/ ++++ postgresql15: - Update to version 15.18: * bsc#1265172, CVE-2026-6472: ensure the user has CREATE privilege on the schema specified * bsc#1265173, CVE-2026-6473: integer overflows in memory-allocation calculations * bsc#1265174, CVE-2026-6474: Guard against malicious time zone names * bsc#1265175, CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind * bsc#1265177, CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq * bsc#1265178, CVE-2026-6478: Use timing-safe string comparisons in authentication code * bsc#1265179, CVE-2026-6479: Prevent unbounded recursion while processing startup packets * bsc#1265181, CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi * https://www.postgresql.org/docs/release/15.18/ ++++ postgresql16: - Update to version 16.13: * bsc#1265172, CVE-2026-6472: ensure the user has CREATE privilege on the schema specified * bsc#1265173, CVE-2026-6473: integer overflows in memory-allocation calculations * bsc#1265174, CVE-2026-6474: Guard against malicious time zone names * bsc#1265175, CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind * bsc#1265177, CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq * bsc#1265178, CVE-2026-6478: Use timing-safe string comparisons in authentication code * bsc#1265179, CVE-2026-6479: Prevent unbounded recursion while processing startup packets * bsc#1265181, CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi * bsc#1265182, CVE-2026-6638: Properly quote object names in logical replication origin checks * https://www.postgresql.org/docs/release/16.13/ ++++ postgresql17: - Update to version 17.10: * bsc#1265172, CVE-2026-6472: ensure the user has CREATE privilege on the schema specified * bsc#1265173, CVE-2026-6473: integer overflows in memory-allocation calculations * bsc#1265174, CVE-2026-6474: Guard against malicious time zone names * bsc#1265175, CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind * bsc#1265176, CVE-2026-6476: Properly quote subscription names in pg_createsubscriber * bsc#1265177, CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq * bsc#1265178, CVE-2026-6478: Use timing-safe string comparisons in authentication code * bsc#1265179, CVE-2026-6479: Prevent unbounded recursion while processing startup packets * bsc#1265181, CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi * bsc#1265182, CVE-2026-6638: Properly quote object names in logical replication origin checks * https://www.postgresql.org/docs/release/17.10/ ++++ postgresql18-mini: - Update to version 18.4: * bsc#1265172, CVE-2026-6472: ensure the user has CREATE privilege on the schema specified * bsc#1265173, CVE-2026-6473: integer overflows in memory-allocation calculations * bsc#1265174, CVE-2026-6474: Guard against malicious time zone names * bsc#1265175, CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind * bsc#1265176, CVE-2026-6476: Properly quote subscription names in pg_createsubscriber * bsc#1265177, CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq * bsc#1265178, CVE-2026-6478: Use timing-safe string comparisons in authentication code * bsc#1265179, CVE-2026-6479: Prevent unbounded recursion while processing startup packets * bsc#1265180, CVE-2026-6575: Detect faulty input when restoring attribute MCV statistics * bsc#1265181, CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi * bsc#1265182, CVE-2026-6638: Properly quote object names in logical replication origin checks * https://www.postgresql.org/docs/release/18.4/ ++++ pqcverification-zypp-plugin: - initial commit [jsc#PED-11922] ++++ python-Pillow: - CVE-2026-42310: infinite loop and resource exhaustion when processing specially crafted PDFs (bsc#1265154) Add patch CVE-2026-42310.patch - CVE-2026-42309: heap buffer overflow when processing nested list coordinates (bsc#1265153) Add patch CVE-2026-42309.patch ++++ supportutils: + Changes to version 3.2.14 - Integrates supportutils-scrub for data obfuscation, use -j (PED-7324, bsc#1259520, #302) - santize env.txt (pr#301) - ha.txt: Collect hacluster passwd entry (pr#299) - Added systemd cat unit.service output (pr#294) - Added softirqs to proc (bsc#1258069. pr#298) - Check for /usr/lib/pam.d (pr#296) - Ignore deprecated crash variable message (pr#297) - Update supportconfig with note about bpftool (pr#285) - Added /boot/grub2/grubenv (bsc#1257383, pr#292) - Verify procps pkg (pr#293) ++++ systemd-mini: - Add a weak runtime dependency on libtss2-tcti-device0 (bsc#1260357) ++++ systemd-mini: - Add a weak runtime dependency on libtss2-tcti-device0 (bsc#1260357) ++++ zypper: - Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-only changes) and package (hides all release-only changes). - version 1.14.97 ------------------------------------------------------------------ ------------------ 2026-5-12 - May 12 2026 ------------------- ------------------------------------------------------------------ ++++ amazon-ssm-agent: - Add CVE-2025-22869.patch to fix Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239342, CVE-2025-22869) - Add CVE-2026-41506.patch to fix HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264952, CVE-2026-41506) ++++ apache2-mod_php8: - version update to 8.4.21 Core: Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors). Fixed bug GH-21478 (Forward property operations to real instance for initialized lazy proxies). Fixed bug GH-21605 (Missing addref for Countable::count()). Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving self::/parent::/static:: callables if the error handler throws). Fixed bug GH-21603 (Missing addref for __unset). Fixed bug GH-21760 (Trait with class constant name conflict against enum case causes SEGV). CLI: Fixed bug GH-21754 (`--rf` command line option with a method triggers ext/reflection deprecation warnings). Curl: Add support for brotli and zstd on Windows. DOM: Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263) Fixed bug GH-21688 (segmentation fault on empty HTMLDocument). Upgrade to lexbor v2.7.0. FPM: Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) Iconv: Fixed bug GH-17399 (iconv memory leak on bailout). MBString: Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()). (CVE-2026-6104) Opcache: Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in zend_jit_use_reg). Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch). Fixed bug GH-21460 (COND optimization regression). Fixed faulty returns out of zend_try block in zend_jit_trace(). OpenSSL: Fix a bunch of memory leaks and crashes on edge cases. PDO_Firebird: Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) Phar: Restore is_link handler in phar_intercept_functions_shutdown. Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when SCRIPT_NAME is absent from SAPI environment). Fix memory leak in Phar::offsetGet(). Fix memory leak in phar_add_file(). Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from phar_stream_close). Fix memory leak in phar_verify_signature() when md_ctx is invalid. Random: Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize() accepts all-zero state). Session: Fixed memory leak when session GC callback return a refcounted value. SOAP: Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) SPL: Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent free). Fix concurrent iteration and deletion issues in SplObjectStorage. Standard: Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) Streams: Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). XSL: Fixed bug GH-21600 (Segfault on module shutdown). Zip: Fixed bug GH-21698 (memory leak with ZipArchive::addGlob() early return statements). - version update to 8.4.20 Bz2: Fix truncation of total output size causing erroneous errors. Core: Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in get_property_ptr_ptr for lazy proxies). DOM: Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and xml:lang attributes). FFI: Fixed resource leak in FFI::cdef() onsymbol resolution failure. GD: Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support). Opcache: Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results). Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with IS_UNDEF property in polymorphic context). Fixed bug GH-21395 (uaf in jit). OpenSSL: Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based keys). Fix missing error propagation for BIO_printf() calls. PCRE: Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl, php_pcre_split_impl, and php_pcre_grep_impl. PGSQL: Fixed preprocessor silently guarding PGSQL_SUPPRESS_TIMESTAMPS support due to a typo. SNMP: Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with NULL arguments). SOAP: Fixed Set-Cookie parsing bug wrong offset while scanning attributes. SPL: Fixed bug GH-21454 (missing write lock validation in SplHeap). Standard: Fixed bug GH-20906 (Assertion failure when messing up output buffers). Fixed bug GH-20627 (Cannot identify some avif images with getimagesize). Sysvshm: Fix memory leak in shm_get_var() when variable is corrupted. XSL: Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with Dom\XMLDocument). Fixed bug GH-21496 (UAF in dom_objects_free_storage). - version update to 8.4.19 Core: Fixed bug GH-21029 (zend_mm_heap corrupted on Aarch64, LTO builds). Fixed bug GH-20657 (Assertion failure in zend_lazy_object_get_info triggered by setRawValueWithoutLazyInitialization() and newLazyGhost()). Fixed bug GH-20504 (Assertion failure in zend_get_property_guard when accessing properties on Reflection LazyProxy via isset()). Fixed OSS-Fuzz #478009707 (Borked assign-op/inc/dec on untyped hooked property backing value). Fixed bug GH-21215 (Build fails with -std=). Fixed bug GH-13674 (Build system installs libtool wrappers when using slibtool). Curl: Fixed bug GH-21023 (CURLOPT_XFERINFOFUNCTION crash with a null callback). Don't truncate length. Date: Fixed bug GH-20936 (DatePeriod::__set_state() cannot handle null start). Fix timezone offset with seconds losing precision. DOM: Fixed bug GH-21077 (Accessing Dom\Node::baseURI can throw TypeError). Fixed bug GH-21097 (Accessing Dom\Node properties can can throw TypeError). MBString: Fixed bug GH-21223; mb_guess_encoding no longer crashes when passed huge list of candidate encodings (with 200,000+ entries). Opcache: Fixed bug GH-20718 ("Insufficient shared memory" when using JIT on Solaris). Fixed bug GH-21227 (Borked SCCP of array containing partial object). Fixed bug GH-21052 (Preloaded constant erroneously propagated to file-cached script). OpenSSL: Fix a bunch of leaks and error propagation. PCNTL: Fixed pcntl_setns() internal errors handling regarding errnos. Fixed cpuset leak in pcntl_setcpuaffinity on out-of-range CPU ID on NetBSD/Solaris platforms. Fixed pcntl_signal() signal table registering the callback first OS-wise before the internal list. Fixed pcntl_signal_dispatch() stale pointer and exception handling. PCRE: Fixed preg_match memory leak with invalid regexes. PDO_PGSQL: Fixed bug GH-21055 (connection attribute status typo for GSS negotiation). PGSQL: Fixed bug GH-21162 (pg_connect() memory leak on error). Sockets: Fixed bug GH-21161 (socket_set_option() crash with array 'addr' entry as null). Fixed possible addr length overflow with socket_connect() and AF_UNIX family sockets. - version update to 8.4.18 Core: Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown function triggered by bailout in php_output_lock_error()). Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). Fixed bug GH-GH-20914 (Internal enums can be cloned and compared). Fix OSS-Fuzz #474613951 (Leaked parent property default value). Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked backing value). Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may uaf). Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). Fixed bug GH-20479 (Hooked object properties overflow). Date: Update timelib to 2022.16. DOM: Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts). MbString: Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is invalid in the encoding). Fixed bug GH-20836 (Stack overflow in mb_convert_variables with recursive array references). Opcache: Fixed bug GH-20818 (Segfault in Tracing JIT with object reference). OpenSSL: Fix memory leaks when sk_X509_new_null() fails. Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails. Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails. Phar: Fixed bug GH-20882 (buildFromIterator breaks with missing base directory). PGSQL: Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible UB. Readline: Fixed bug GH-18139 (Memory leak when overriding some settings via readline_info()). SPL: Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator when modifying during iteration). Standard: Fixed bug #74357 (lchown fails to change ownership of symlink with ZTS) (Jakub Zelenka) Fixed bug GH-20843 (var_dump() crash with nested objects) (David Carlier) - version u pdate to 8.4.17 Core: Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature with dynamic class const lookup default argument). Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing malformed INI input via parse_ini_string()). Fixed bug GH-20714 (Uncatchable exception thrown in generator). Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant ob_start() during error deactivation). Bz2: Fixed bug GH-20620 (bzcompress overflow on large source size). DOM: Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning via clone on malformed objects). Fixed bug GH-20444 (Dom\XMLDocument::C14N() seems broken compared to DOMDocument::C14N()). GD: Fixed bug GH-20622 (imagestring/imagestringup overflow). Intl: Fix leak in umsg_format_helper(). LDAP: Fix memory leak in ldap_set_options(). Mbstring: Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator). PCNTL: Fixed bug with pcntl_getcpuaffinity() on solaris regarding invalid process ids handling. Phar: Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails). Fix SplFileInfo::openFile() in write mode. Fix build on legacy OpenSSL 1.1.0 systems. Fixed bug #74154 (Phar extractTo creates empty files). POSIX: Fixed crash on posix groups to php array creation on macos. SPL: Fixed bug GH-20678 (resource created by GlobIterator crashes with fclose()). Sqlite3: Fixed bug GH-20699 (SQLite3Result fetchArray return array|false, null returned). Standard: Fix error check for proc_open() command. Fix memory leak in mail() when header key is numeric. Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). Zlib: Fix OOB gzseek() causing assertion failure. - modified patches * php-build-reproducible-phar.patch (refreshed) - fixes CVE-2025-14179 [bsc#1264778] CVE-2026-7568 [bsc#1264769] CVE-2026-7263 [bsc#1264770] CVE-2026-7261 [bsc#1264772] CVE-2026-7259 [bsc#1264773] CVE-2026-7258 [bsc#1264774] CVE-2026-6722 [bsc#1264776] CVE-2026-6104 [bsc#1264777] CVE-2026-6735 [bsc#1264775] CVE-2026-7262 [bsc#1264771] ++++ libcaca: - Prevent undefined behaviour in overflow check. [Prevent-undefined-behaviour-in-overflow-check.patch, bsc#1264984, CVE-2026-42046] ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions ++++ chromium: - Chromium 148.0.7778.167 (boo#1265159) * CVE-2026-8509: Heap buffer overflow in WebML * CVE-2026-8510: Integer overflow in Skia * CVE-2026-8511: Use after free in UI * CVE-2026-8512: Use after free in FileSystem * CVE-2026-8513: Use after free in Input * CVE-2026-8514: Use after free in Aura * CVE-2026-8515: Use after free in HID * CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer * CVE-2026-8517: Object lifecycle issue in WebShare * CVE-2026-8518: Use after free in Blink * CVE-2026-8519: Integer overflow in ANGLE * CVE-2026-8520: Race in Payments * CVE-2026-8521: Use after free in Tab Groups * CVE-2026-8522: Use after free in Downloads * CVE-2026-8523: Use after free in Mojo * CVE-2026-8558: Out of bounds write in Fonts * CVE-2026-8524: Out of bounds write in WebAudio * CVE-2026-8525: Heap buffer overflow in ANGLE * CVE-2026-8526: Out of bounds write in WebRTC * CVE-2026-8527: Insufficient validation of untrusted input in Downloads * CVE-2026-8528: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8529: Heap buffer overflow in Codecs * CVE-2026-8530: Use after free in Network * CVE-2026-8531: Heap buffer overflow in WebML * CVE-2026-8532: Integer overflow in XML * CVE-2026-8533: Use after free in Accessibility * CVE-2026-8534: Integer overflow in GPU * CVE-2026-8535: Out of bounds read in Media * CVE-2026-8536: Insufficient validation of untrusted input in ReadingMode * CVE-2026-8537: Insufficient policy enforcement in ViewTransitions * CVE-2026-8538: Insufficient validation of untrusted input in GPU * CVE-2026-8539: Script injection in SanitizerAPI * CVE-2026-8540: Type Confusion in V8 * CVE-2026-8541: Out of bounds read in UI * CVE-2026-8542: Use after free in Core * CVE-2026-8543: Out of bounds read in FileSystem * CVE-2026-8544: Use after free in Media * CVE-2026-8545: Object corruption in Compositing * CVE-2026-8546: Out of bounds read in GPU * CVE-2026-8547: Insufficient policy enforcement in Passwords * CVE-2026-8548: Out of bounds write in Media * CVE-2026-8549: Use after free in Media * CVE-2026-8550: Use after free in Google Lens * CVE-2026-8551: Use after free in Downloads * CVE-2026-8552: Heap buffer overflow in GPU * CVE-2026-8553: Use after free in GPU * CVE-2026-8554: Type Confusion in ANGLE * CVE-2026-8555: Use after free in GTK * CVE-2026-8556: Inappropriate implementation in ANGLE * CVE-2026-8557: Use after free in Accessibility * CVE-2026-8559: Integer overflow in Internationalization * CVE-2026-8560: Heap buffer overflow in SwiftShader * CVE-2026-8561: Incorrect security UI in Fullscreen * CVE-2026-8562: Side-channel information leakage in Navigation * CVE-2026-8563: Insufficient policy enforcement in IFrame Sandbox * CVE-2026-8564: Incorrect security UI in Downloads * CVE-2026-8565: Inappropriate implementation in Downloads * CVE-2026-8566: Insufficient policy enforcement in Payments * CVE-2026-8567: Integer overflow in ANGLE * CVE-2026-8568: Insufficient policy enforcement in AI * CVE-2026-8569: Out of bounds write in Codecs * CVE-2026-8570: Type Confusion in V8 * CVE-2026-8571: Insufficient policy enforcement in GPU * CVE-2026-8572: Insufficient policy enforcement in Network * CVE-2026-8573: Integer overflow in Codecs * CVE-2026-8574: Use after free in Core * CVE-2026-8575: Use after free in UI * CVE-2026-8576: Inappropriate implementation in CORS * CVE-2026-8577: Integer overflow in Fonts * CVE-2026-8578: Out of bounds read in GPU * CVE-2026-8579: Insufficient validation of untrusted input in Skia * CVE-2026-8580: Use after free in Mojo * CVE-2026-8581: Use after free in GPU * CVE-2026-8582: Object lifecycle issue in Dawn * CVE-2026-8583: Insufficient policy enforcement in WebXR * CVE-2026-8584: Inappropriate implementation in Views * CVE-2026-8585: Inappropriate implementation in Media * CVE-2026-8586: Inappropriate implementation in Chromoting * CVE-2026-8587: Use after free in Extensions ++++ kernel-64kb: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-64kb: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-64kb: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-azure: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-azure: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-azure: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-default: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-default: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-default: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-rt: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-rt: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-rt: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ cosign: - update to 3.0.6 (bsc#1261859, CVE-2026-39395): * Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801) * Handle whitespace-only certificate annotation (#4760) * fix(sign): closing SignerVerifier too early when signing with a security key (#4761) * Disallow --new-bundle-format and --rfc3161-timestamp (#4762) * support managed keys in conformance testing (#4728) * Add support for GCE metadata server env var (#4732) * fix: preserve per-layer annotations in WriteAttestationsReferrer (#4709) * Fix parsing of in-toto for string predicates * Mark batch of flags for deprecation (#4698) * disallow key and cert identity being used together during verification (#4636) * support key creation in GitLab group (#4704) ++++ dnsmasq: - Update to security release 2.92rel2: * CVE-2026-2291, bsc#1258251: dnsmasq can be abused to record false cached data enabling DoS or attacker redirect. * CVE-2026-4890, bsc#1265001: DoS vulnerability in the DNSSEC validation. * CVE-2026-4891, bsc#1265002: heap-based out-of-bounds read vulnerability in the DNSSEC validation. * CVE-2026-4892, bsc#1265003: heap-based out-of-bounds write vulnerability in the DHCPv6 implementation. * CVE-2026-4893, bsc#1265004: information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks. * CVE-2026-5172, bsc#1265006: buffer overflow in dnsmasq’s extract_addresses() function. ++++ dnsmasq: - Update to security release 2.92rel2: * CVE-2026-2291, bsc#1258251: dnsmasq can be abused to record false cached data enabling DoS or attacker redirect. * CVE-2026-4890, bsc#1265001: DoS vulnerability in the DNSSEC validation. * CVE-2026-4891, bsc#1265002: heap-based out-of-bounds read vulnerability in the DNSSEC validation. * CVE-2026-4892, bsc#1265003: heap-based out-of-bounds write vulnerability in the DHCPv6 implementation. * CVE-2026-4893, bsc#1265004: information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks. * CVE-2026-5172, bsc#1265006: buffer overflow in dnsmasq’s extract_addresses() function. ++++ dovecot24: - Update to 2.4.4 (boo#1265146 boo#1265147 boo#1265148 boo#1265149 boo#1265150) - core * CVE-2026-27851: lib-var-expand: Safe filter marks all following pipelines safe. * CVE-2026-33603: auth: CRAM-SHA-*-PLUS channel binding could be faked. MITM attacker with a certificate trusted by the client could have bypassed the requirement for channel binding. * CVE-2026-40020: IMAP folders can be shared-spammed to everyone. * CVE-2026-42006: An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete. * indexer-worker, quota-status, script-login, program-client-local: Root privileges are now dropped permanently before serving requests. * indexer-worker: Default restart_request_count changed to 1 to work correctly after permanent root privilege drop. * lmtp: Add back service_extra_groups=$SET:default_internal_group that was incorrectly removed in v2.4.3. * master: inet_listener_reuse_port has been replaced by service_reuse_port. The new setting properly pre-creates all listener sockets at startup and assigns one unique socket per process. Using this allows evenly distributing incoming connections to login processes. See https://doc.dovecot.org/latest/core/config/service.html#service_reuse_port for details. - auth: Fix LDAP escaping of 0x13 control character. - auth: Use timing-safe comparison for certificate and public key fingerprints. - fts: Correctly handle internal http-client response errors. - fts: Don't send request to Tika if there is no body text. - fts: Fix address header indexing for RFC 2047 encoded-words. - fts: tika, fts-solr: Fix use-after-free crash during DNS lookup. - imap: Fix assertion panic on invalid REPLACE 0 command. - lib-auth-client: Avoid "unknown id" errors for aborted auth requests. - lib-dcrypt: Fix potential crash if trying to access untrusted/corrupted keys. - lib-dcrypt: Improve error message if keys aren't in hex format as expected. - lib-index: Fix potential crash if fsck fails. - lib-ldap: Fix using OpenLDAP default CA when ssl_client_ca_dir/file is unset. v2.4.3 regression. - lib-master, master: Fix behavior for services with client_limit>1 and restart_request_count so that processes reaching restart_request_count are no longer counted towards process_limit. - lib-master: Fix crash when reaching client_limit with restart_request_count>1. - lib-master: haproxy - Don't trust client certificate common name when HAProxy reports verification failure. - lib-sasl: cram-md5 - Fix out of bounds memory read. - lib-sasl: oauth2 - Fix one byte out of bounds read. - lib-sql: cassandra - Fix reusing Cassandra SSL connections. - lib-sql: sqlite - Fix sqlite_journal_mode=wal to actually work. - lib-storage: Auto-rename non-NFC subscription file entries to NFC on read. - lib-storage: Prevent non-atom SEARCH keywords from causing IMAP command injection. - lib-var-expand-crypt: Return error if hex decoding fails. - lib-var-expand: Fix crash (SIGFPE) with non-positive divisor for / and %. - log: Fix memory leak at deinit. - login-common: When process is full, don't destroy clients waiting on master auth. - login-proxy: Fix crash with rawlog and multiplexing during reconnection. - mail-compress: Fix panic when save method unavailable. - mail-crypt: Fix crash when HMAC-based algorithm is used. - mail-crypt: Use AEAD instead of HMAC with ChaCha20-Poly1305. - mdbox: Create files with O_NOFOLLOW. - push-notification: ox - Fix use-after-free crash during DNS lookup. - quota: quota-status - Limit input buffer size to 1 kB. - pigeonhole: * CVE-2026-40016: sieve :contains and :matches operators could have been using excessive amount of CPU. Limit the CPU to sieve_max_cpu_time. - Fix potential crashes parsing corrupted Sieve binaries. - lib-sieve: matches - Fix trailing literal match when it fills value exactly. v2.4.3 regression. ++++ dtb-aarch64: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ dtb-aarch64: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ dtb-aarch64: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ javapackages-tools: - Upgrade to upstream version 6.5.1 * Changes Bump actions/setup-python from 5 to 6 Bump actions/checkout from 4 to 6 Bump codecov/codecov-action from 4.6.0 to 5.5.2 Remove Codecov call from GitHub CI workflow Remove unused and outdated Vagrantfile Java launcher script improvements Add jpackage_script manpage Implement feature contitionals Fix installation of jpackage_script.7 manpage - Modified patch: * python-optional.patch * suse-use-libdir.patch + rediff - Make the gradle and ivy support configurable ++++ javapackages-tools: - Upgrade to upstream version 6.5.1 * Changes Bump actions/setup-python from 5 to 6 Bump actions/checkout from 4 to 6 Bump codecov/codecov-action from 4.6.0 to 5.5.2 Remove Codecov call from GitHub CI workflow Remove unused and outdated Vagrantfile Java launcher script improvements Add jpackage_script manpage Implement feature contitionals Fix installation of jpackage_script.7 manpage - Modified patch: * python-optional.patch * suse-use-libdir.patch + rediff - Make the gradle and ivy support configurable ++++ javapackages-tools-extras: - Upgrade to upstream version 6.5.1 * Changes Bump actions/setup-python from 5 to 6 Bump actions/checkout from 4 to 6 Bump codecov/codecov-action from 4.6.0 to 5.5.2 Remove Codecov call from GitHub CI workflow Remove unused and outdated Vagrantfile Java launcher script improvements Add jpackage_script manpage Implement feature contitionals Fix installation of jpackage_script.7 manpage - Modified patch: * python-optional.patch * suse-use-libdir.patch + rediff - Make the gradle and ivy support configurable ++++ javapackages-tools-extras: - Upgrade to upstream version 6.5.1 * Changes Bump actions/setup-python from 5 to 6 Bump actions/checkout from 4 to 6 Bump codecov/codecov-action from 4.6.0 to 5.5.2 Remove Codecov call from GitHub CI workflow Remove unused and outdated Vagrantfile Java launcher script improvements Add jpackage_script manpage Implement feature contitionals Fix installation of jpackage_script.7 manpage - Modified patch: * python-optional.patch * suse-use-libdir.patch + rediff - Make the gradle and ivy support configurable ++++ kdenlive: - Add upstream changes (CVE-2026-45184, boo#1264711) * 0001-Cleanup-proxy-parameters.patch * 0002-Sanitize-proxy-parameters.patch ++++ kernel-source: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-source: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-source: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-docs: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-docs: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-docs: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-kvmsmall: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-kvmsmall: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-kvmsmall: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-obs-build: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-obs-build: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-obs-build: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-obs-qa: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-obs-qa: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-obs-qa: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-syms: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-syms: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-syms: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-zfcpdump: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-zfcpdump: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ kernel-zfcpdump: - smb: client: fix krb5 mount with username option (bsc#1261788 CVE-2026-31392) - commit dc306e2 - KVM: SVM: Disallow EFER.LMSLE when not supported by hardware (git-fixes). - commit abdb6dd - KVM: x86: Advertise EferLmsleUnsupported to userspace (git-fixes). - commit 1a12381 - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested [#]VMEXIT (git-fixes). - commit 0bcee83 - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - net/mlx5: Fix HCA caps leak on notifier init failure (git-fixes). - tg3: replace placeholder MAC address with device property (git-fixes). - commit a806d46 - igb: remove napi_synchronize() in igb_down() (CVE-2026-31691 bsc#1263604). - commit fa98b35 ++++ openexr: - added patches CVE-2026-42216: missing checks in `IDManifest::init()` can lead to out-of-bounds read during prefix expansion [bsc#1264354] * openexr-CVE-2026-42216.patch CVE-2026-41142: integer overflow in `ImageChannel::resize` can lead to a heap out-of-bounds write via OpenEXRUtil public API [bsc#1264356] * openexr-CVE-2026-41142.patch CVE-2026-42217: missing bounds check for shift counter in `readVariableLengthInteger` can lead to shift exponent overflow and cause undefined behavior [bsc#1264353] * openexr-CVE-2026-42217.patch ++++ libzypp: - Mandatory signature verification plugin support (PED#11922) - version 17.38.8 (35) ++++ neonmodem: - Update golang.org/x/image dependency to v0.38.0 due to bsc#1260727 - Update golang.org/x/term dependency to v0.42.0 due to bsc#1260727 ++++ pcr-oracle: - Update to 0.6.1 + Advance the comparison event pointer after comparison + Partially support shim extra files + Locate shim extra files + Synthesize shim extra events + Fix various issues from review by Claude Code and introduce adversarial testing ++++ perl-XML-LibXML: - added patches CVE-2026-8177: versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences [bsc#1264715] * perl-XML-LibXML-CVE-2026-8177.patch ++++ php8: - version update to 8.4.21 Core: Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors). Fixed bug GH-21478 (Forward property operations to real instance for initialized lazy proxies). Fixed bug GH-21605 (Missing addref for Countable::count()). Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving self::/parent::/static:: callables if the error handler throws). Fixed bug GH-21603 (Missing addref for __unset). Fixed bug GH-21760 (Trait with class constant name conflict against enum case causes SEGV). CLI: Fixed bug GH-21754 (`--rf` command line option with a method triggers ext/reflection deprecation warnings). Curl: Add support for brotli and zstd on Windows. DOM: Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263) Fixed bug GH-21688 (segmentation fault on empty HTMLDocument). Upgrade to lexbor v2.7.0. FPM: Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) Iconv: Fixed bug GH-17399 (iconv memory leak on bailout). MBString: Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()). (CVE-2026-6104) Opcache: Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in zend_jit_use_reg). Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch). Fixed bug GH-21460 (COND optimization regression). Fixed faulty returns out of zend_try block in zend_jit_trace(). OpenSSL: Fix a bunch of memory leaks and crashes on edge cases. PDO_Firebird: Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) Phar: Restore is_link handler in phar_intercept_functions_shutdown. Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when SCRIPT_NAME is absent from SAPI environment). Fix memory leak in Phar::offsetGet(). Fix memory leak in phar_add_file(). Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from phar_stream_close). Fix memory leak in phar_verify_signature() when md_ctx is invalid. Random: Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize() accepts all-zero state). Session: Fixed memory leak when session GC callback return a refcounted value. SOAP: Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) SPL: Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent free). Fix concurrent iteration and deletion issues in SplObjectStorage. Standard: Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) Streams: Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). XSL: Fixed bug GH-21600 (Segfault on module shutdown). Zip: Fixed bug GH-21698 (memory leak with ZipArchive::addGlob() early return statements). - version update to 8.4.20 Bz2: Fix truncation of total output size causing erroneous errors. Core: Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in get_property_ptr_ptr for lazy proxies). DOM: Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and xml:lang attributes). FFI: Fixed resource leak in FFI::cdef() onsymbol resolution failure. GD: Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support). Opcache: Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results). Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with IS_UNDEF property in polymorphic context). Fixed bug GH-21395 (uaf in jit). OpenSSL: Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based keys). Fix missing error propagation for BIO_printf() calls. PCRE: Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl, php_pcre_split_impl, and php_pcre_grep_impl. PGSQL: Fixed preprocessor silently guarding PGSQL_SUPPRESS_TIMESTAMPS support due to a typo. SNMP: Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with NULL arguments). SOAP: Fixed Set-Cookie parsing bug wrong offset while scanning attributes. SPL: Fixed bug GH-21454 (missing write lock validation in SplHeap). Standard: Fixed bug GH-20906 (Assertion failure when messing up output buffers). Fixed bug GH-20627 (Cannot identify some avif images with getimagesize). Sysvshm: Fix memory leak in shm_get_var() when variable is corrupted. XSL: Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with Dom\XMLDocument). Fixed bug GH-21496 (UAF in dom_objects_free_storage). - version update to 8.4.19 Core: Fixed bug GH-21029 (zend_mm_heap corrupted on Aarch64, LTO builds). Fixed bug GH-20657 (Assertion failure in zend_lazy_object_get_info triggered by setRawValueWithoutLazyInitialization() and newLazyGhost()). Fixed bug GH-20504 (Assertion failure in zend_get_property_guard when accessing properties on Reflection LazyProxy via isset()). Fixed OSS-Fuzz #478009707 (Borked assign-op/inc/dec on untyped hooked property backing value). Fixed bug GH-21215 (Build fails with -std=). Fixed bug GH-13674 (Build system installs libtool wrappers when using slibtool). Curl: Fixed bug GH-21023 (CURLOPT_XFERINFOFUNCTION crash with a null callback). Don't truncate length. Date: Fixed bug GH-20936 (DatePeriod::__set_state() cannot handle null start). Fix timezone offset with seconds losing precision. DOM: Fixed bug GH-21077 (Accessing Dom\Node::baseURI can throw TypeError). Fixed bug GH-21097 (Accessing Dom\Node properties can can throw TypeError). MBString: Fixed bug GH-21223; mb_guess_encoding no longer crashes when passed huge list of candidate encodings (with 200,000+ entries). Opcache: Fixed bug GH-20718 ("Insufficient shared memory" when using JIT on Solaris). Fixed bug GH-21227 (Borked SCCP of array containing partial object). Fixed bug GH-21052 (Preloaded constant erroneously propagated to file-cached script). OpenSSL: Fix a bunch of leaks and error propagation. PCNTL: Fixed pcntl_setns() internal errors handling regarding errnos. Fixed cpuset leak in pcntl_setcpuaffinity on out-of-range CPU ID on NetBSD/Solaris platforms. Fixed pcntl_signal() signal table registering the callback first OS-wise before the internal list. Fixed pcntl_signal_dispatch() stale pointer and exception handling. PCRE: Fixed preg_match memory leak with invalid regexes. PDO_PGSQL: Fixed bug GH-21055 (connection attribute status typo for GSS negotiation). PGSQL: Fixed bug GH-21162 (pg_connect() memory leak on error). Sockets: Fixed bug GH-21161 (socket_set_option() crash with array 'addr' entry as null). Fixed possible addr length overflow with socket_connect() and AF_UNIX family sockets. - version update to 8.4.18 Core: Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown function triggered by bailout in php_output_lock_error()). Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). Fixed bug GH-GH-20914 (Internal enums can be cloned and compared). Fix OSS-Fuzz #474613951 (Leaked parent property default value). Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked backing value). Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may uaf). Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). Fixed bug GH-20479 (Hooked object properties overflow). Date: Update timelib to 2022.16. DOM: Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts). MbString: Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is invalid in the encoding). Fixed bug GH-20836 (Stack overflow in mb_convert_variables with recursive array references). Opcache: Fixed bug GH-20818 (Segfault in Tracing JIT with object reference). OpenSSL: Fix memory leaks when sk_X509_new_null() fails. Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails. Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails. Phar: Fixed bug GH-20882 (buildFromIterator breaks with missing base directory). PGSQL: Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible UB. Readline: Fixed bug GH-18139 (Memory leak when overriding some settings via readline_info()). SPL: Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator when modifying during iteration). Standard: Fixed bug #74357 (lchown fails to change ownership of symlink with ZTS) (Jakub Zelenka) Fixed bug GH-20843 (var_dump() crash with nested objects) (David Carlier) - version u pdate to 8.4.17 Core: Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature with dynamic class const lookup default argument). Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing malformed INI input via parse_ini_string()). Fixed bug GH-20714 (Uncatchable exception thrown in generator). Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant ob_start() during error deactivation). Bz2: Fixed bug GH-20620 (bzcompress overflow on large source size). DOM: Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning via clone on malformed objects). Fixed bug GH-20444 (Dom\XMLDocument::C14N() seems broken compared to DOMDocument::C14N()). GD: Fixed bug GH-20622 (imagestring/imagestringup overflow). Intl: Fix leak in umsg_format_helper(). LDAP: Fix memory leak in ldap_set_options(). Mbstring: Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator). PCNTL: Fixed bug with pcntl_getcpuaffinity() on solaris regarding invalid process ids handling. Phar: Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails). Fix SplFileInfo::openFile() in write mode. Fix build on legacy OpenSSL 1.1.0 systems. Fixed bug #74154 (Phar extractTo creates empty files). POSIX: Fixed crash on posix groups to php array creation on macos. SPL: Fixed bug GH-20678 (resource created by GlobIterator crashes with fclose()). Sqlite3: Fixed bug GH-20699 (SQLite3Result fetchArray return array|false, null returned). Standard: Fix error check for proc_open() command. Fix memory leak in mail() when header key is numeric. Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). Zlib: Fix OOB gzseek() causing assertion failure. - modified patches * php-build-reproducible-phar.patch (refreshed) - fixes CVE-2025-14179 [bsc#1264778] CVE-2026-7568 [bsc#1264769] CVE-2026-7263 [bsc#1264770] CVE-2026-7261 [bsc#1264772] CVE-2026-7259 [bsc#1264773] CVE-2026-7258 [bsc#1264774] CVE-2026-6722 [bsc#1264776] CVE-2026-6104 [bsc#1264777] CVE-2026-6735 [bsc#1264775] CVE-2026-7262 [bsc#1264771] ++++ php8-embed: - version update to 8.4.21 Core: Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors). Fixed bug GH-21478 (Forward property operations to real instance for initialized lazy proxies). Fixed bug GH-21605 (Missing addref for Countable::count()). Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving self::/parent::/static:: callables if the error handler throws). Fixed bug GH-21603 (Missing addref for __unset). Fixed bug GH-21760 (Trait with class constant name conflict against enum case causes SEGV). CLI: Fixed bug GH-21754 (`--rf` command line option with a method triggers ext/reflection deprecation warnings). Curl: Add support for brotli and zstd on Windows. DOM: Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263) Fixed bug GH-21688 (segmentation fault on empty HTMLDocument). Upgrade to lexbor v2.7.0. FPM: Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) Iconv: Fixed bug GH-17399 (iconv memory leak on bailout). MBString: Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()). (CVE-2026-6104) Opcache: Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in zend_jit_use_reg). Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch). Fixed bug GH-21460 (COND optimization regression). Fixed faulty returns out of zend_try block in zend_jit_trace(). OpenSSL: Fix a bunch of memory leaks and crashes on edge cases. PDO_Firebird: Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) Phar: Restore is_link handler in phar_intercept_functions_shutdown. Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when SCRIPT_NAME is absent from SAPI environment). Fix memory leak in Phar::offsetGet(). Fix memory leak in phar_add_file(). Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from phar_stream_close). Fix memory leak in phar_verify_signature() when md_ctx is invalid. Random: Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize() accepts all-zero state). Session: Fixed memory leak when session GC callback return a refcounted value. SOAP: Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) SPL: Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent free). Fix concurrent iteration and deletion issues in SplObjectStorage. Standard: Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) Streams: Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). XSL: Fixed bug GH-21600 (Segfault on module shutdown). Zip: Fixed bug GH-21698 (memory leak with ZipArchive::addGlob() early return statements). - version update to 8.4.20 Bz2: Fix truncation of total output size causing erroneous errors. Core: Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in get_property_ptr_ptr for lazy proxies). DOM: Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and xml:lang attributes). FFI: Fixed resource leak in FFI::cdef() onsymbol resolution failure. GD: Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support). Opcache: Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results). Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with IS_UNDEF property in polymorphic context). Fixed bug GH-21395 (uaf in jit). OpenSSL: Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based keys). Fix missing error propagation for BIO_printf() calls. PCRE: Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl, php_pcre_split_impl, and php_pcre_grep_impl. PGSQL: Fixed preprocessor silently guarding PGSQL_SUPPRESS_TIMESTAMPS support due to a typo. SNMP: Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with NULL arguments). SOAP: Fixed Set-Cookie parsing bug wrong offset while scanning attributes. SPL: Fixed bug GH-21454 (missing write lock validation in SplHeap). Standard: Fixed bug GH-20906 (Assertion failure when messing up output buffers). Fixed bug GH-20627 (Cannot identify some avif images with getimagesize). Sysvshm: Fix memory leak in shm_get_var() when variable is corrupted. XSL: Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with Dom\XMLDocument). Fixed bug GH-21496 (UAF in dom_objects_free_storage). - version update to 8.4.19 Core: Fixed bug GH-21029 (zend_mm_heap corrupted on Aarch64, LTO builds). Fixed bug GH-20657 (Assertion failure in zend_lazy_object_get_info triggered by setRawValueWithoutLazyInitialization() and newLazyGhost()). Fixed bug GH-20504 (Assertion failure in zend_get_property_guard when accessing properties on Reflection LazyProxy via isset()). Fixed OSS-Fuzz #478009707 (Borked assign-op/inc/dec on untyped hooked property backing value). Fixed bug GH-21215 (Build fails with -std=). Fixed bug GH-13674 (Build system installs libtool wrappers when using slibtool). Curl: Fixed bug GH-21023 (CURLOPT_XFERINFOFUNCTION crash with a null callback). Don't truncate length. Date: Fixed bug GH-20936 (DatePeriod::__set_state() cannot handle null start). Fix timezone offset with seconds losing precision. DOM: Fixed bug GH-21077 (Accessing Dom\Node::baseURI can throw TypeError). Fixed bug GH-21097 (Accessing Dom\Node properties can can throw TypeError). MBString: Fixed bug GH-21223; mb_guess_encoding no longer crashes when passed huge list of candidate encodings (with 200,000+ entries). Opcache: Fixed bug GH-20718 ("Insufficient shared memory" when using JIT on Solaris). Fixed bug GH-21227 (Borked SCCP of array containing partial object). Fixed bug GH-21052 (Preloaded constant erroneously propagated to file-cached script). OpenSSL: Fix a bunch of leaks and error propagation. PCNTL: Fixed pcntl_setns() internal errors handling regarding errnos. Fixed cpuset leak in pcntl_setcpuaffinity on out-of-range CPU ID on NetBSD/Solaris platforms. Fixed pcntl_signal() signal table registering the callback first OS-wise before the internal list. Fixed pcntl_signal_dispatch() stale pointer and exception handling. PCRE: Fixed preg_match memory leak with invalid regexes. PDO_PGSQL: Fixed bug GH-21055 (connection attribute status typo for GSS negotiation). PGSQL: Fixed bug GH-21162 (pg_connect() memory leak on error). Sockets: Fixed bug GH-21161 (socket_set_option() crash with array 'addr' entry as null). Fixed possible addr length overflow with socket_connect() and AF_UNIX family sockets. - version update to 8.4.18 Core: Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown function triggered by bailout in php_output_lock_error()). Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). Fixed bug GH-GH-20914 (Internal enums can be cloned and compared). Fix OSS-Fuzz #474613951 (Leaked parent property default value). Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked backing value). Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may uaf). Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). Fixed bug GH-20479 (Hooked object properties overflow). Date: Update timelib to 2022.16. DOM: Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts). MbString: Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is invalid in the encoding). Fixed bug GH-20836 (Stack overflow in mb_convert_variables with recursive array references). Opcache: Fixed bug GH-20818 (Segfault in Tracing JIT with object reference). OpenSSL: Fix memory leaks when sk_X509_new_null() fails. Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails. Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails. Phar: Fixed bug GH-20882 (buildFromIterator breaks with missing base directory). PGSQL: Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible UB. Readline: Fixed bug GH-18139 (Memory leak when overriding some settings via readline_info()). SPL: Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator when modifying during iteration). Standard: Fixed bug #74357 (lchown fails to change ownership of symlink with ZTS) (Jakub Zelenka) Fixed bug GH-20843 (var_dump() crash with nested objects) (David Carlier) - version u pdate to 8.4.17 Core: Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature with dynamic class const lookup default argument). Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing malformed INI input via parse_ini_string()). Fixed bug GH-20714 (Uncatchable exception thrown in generator). Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant ob_start() during error deactivation). Bz2: Fixed bug GH-20620 (bzcompress overflow on large source size). DOM: Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning via clone on malformed objects). Fixed bug GH-20444 (Dom\XMLDocument::C14N() seems broken compared to DOMDocument::C14N()). GD: Fixed bug GH-20622 (imagestring/imagestringup overflow). Intl: Fix leak in umsg_format_helper(). LDAP: Fix memory leak in ldap_set_options(). Mbstring: Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator). PCNTL: Fixed bug with pcntl_getcpuaffinity() on solaris regarding invalid process ids handling. Phar: Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails). Fix SplFileInfo::openFile() in write mode. Fix build on legacy OpenSSL 1.1.0 systems. Fixed bug #74154 (Phar extractTo creates empty files). POSIX: Fixed crash on posix groups to php array creation on macos. SPL: Fixed bug GH-20678 (resource created by GlobIterator crashes with fclose()). Sqlite3: Fixed bug GH-20699 (SQLite3Result fetchArray return array|false, null returned). Standard: Fix error check for proc_open() command. Fix memory leak in mail() when header key is numeric. Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). Zlib: Fix OOB gzseek() causing assertion failure. - modified patches * php-build-reproducible-phar.patch (refreshed) - fixes CVE-2025-14179 [bsc#1264778] CVE-2026-7568 [bsc#1264769] CVE-2026-7263 [bsc#1264770] CVE-2026-7261 [bsc#1264772] CVE-2026-7259 [bsc#1264773] CVE-2026-7258 [bsc#1264774] CVE-2026-6722 [bsc#1264776] CVE-2026-6104 [bsc#1264777] CVE-2026-6735 [bsc#1264775] CVE-2026-7262 [bsc#1264771] ++++ php8-fastcgi: - version update to 8.4.21 Core: Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors). Fixed bug GH-21478 (Forward property operations to real instance for initialized lazy proxies). Fixed bug GH-21605 (Missing addref for Countable::count()). Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving self::/parent::/static:: callables if the error handler throws). Fixed bug GH-21603 (Missing addref for __unset). Fixed bug GH-21760 (Trait with class constant name conflict against enum case causes SEGV). CLI: Fixed bug GH-21754 (`--rf` command line option with a method triggers ext/reflection deprecation warnings). Curl: Add support for brotli and zstd on Windows. DOM: Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263) Fixed bug GH-21688 (segmentation fault on empty HTMLDocument). Upgrade to lexbor v2.7.0. FPM: Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) Iconv: Fixed bug GH-17399 (iconv memory leak on bailout). MBString: Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()). (CVE-2026-6104) Opcache: Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in zend_jit_use_reg). Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch). Fixed bug GH-21460 (COND optimization regression). Fixed faulty returns out of zend_try block in zend_jit_trace(). OpenSSL: Fix a bunch of memory leaks and crashes on edge cases. PDO_Firebird: Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) Phar: Restore is_link handler in phar_intercept_functions_shutdown. Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when SCRIPT_NAME is absent from SAPI environment). Fix memory leak in Phar::offsetGet(). Fix memory leak in phar_add_file(). Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from phar_stream_close). Fix memory leak in phar_verify_signature() when md_ctx is invalid. Random: Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize() accepts all-zero state). Session: Fixed memory leak when session GC callback return a refcounted value. SOAP: Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) SPL: Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent free). Fix concurrent iteration and deletion issues in SplObjectStorage. Standard: Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) Streams: Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). XSL: Fixed bug GH-21600 (Segfault on module shutdown). Zip: Fixed bug GH-21698 (memory leak with ZipArchive::addGlob() early return statements). - version update to 8.4.20 Bz2: Fix truncation of total output size causing erroneous errors. Core: Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in get_property_ptr_ptr for lazy proxies). DOM: Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and xml:lang attributes). FFI: Fixed resource leak in FFI::cdef() onsymbol resolution failure. GD: Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support). Opcache: Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results). Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with IS_UNDEF property in polymorphic context). Fixed bug GH-21395 (uaf in jit). OpenSSL: Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based keys). Fix missing error propagation for BIO_printf() calls. PCRE: Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl, php_pcre_split_impl, and php_pcre_grep_impl. PGSQL: Fixed preprocessor silently guarding PGSQL_SUPPRESS_TIMESTAMPS support due to a typo. SNMP: Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with NULL arguments). SOAP: Fixed Set-Cookie parsing bug wrong offset while scanning attributes. SPL: Fixed bug GH-21454 (missing write lock validation in SplHeap). Standard: Fixed bug GH-20906 (Assertion failure when messing up output buffers). Fixed bug GH-20627 (Cannot identify some avif images with getimagesize). Sysvshm: Fix memory leak in shm_get_var() when variable is corrupted. XSL: Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with Dom\XMLDocument). Fixed bug GH-21496 (UAF in dom_objects_free_storage). - version update to 8.4.19 Core: Fixed bug GH-21029 (zend_mm_heap corrupted on Aarch64, LTO builds). Fixed bug GH-20657 (Assertion failure in zend_lazy_object_get_info triggered by setRawValueWithoutLazyInitialization() and newLazyGhost()). Fixed bug GH-20504 (Assertion failure in zend_get_property_guard when accessing properties on Reflection LazyProxy via isset()). Fixed OSS-Fuzz #478009707 (Borked assign-op/inc/dec on untyped hooked property backing value). Fixed bug GH-21215 (Build fails with -std=). Fixed bug GH-13674 (Build system installs libtool wrappers when using slibtool). Curl: Fixed bug GH-21023 (CURLOPT_XFERINFOFUNCTION crash with a null callback). Don't truncate length. Date: Fixed bug GH-20936 (DatePeriod::__set_state() cannot handle null start). Fix timezone offset with seconds losing precision. DOM: Fixed bug GH-21077 (Accessing Dom\Node::baseURI can throw TypeError). Fixed bug GH-21097 (Accessing Dom\Node properties can can throw TypeError). MBString: Fixed bug GH-21223; mb_guess_encoding no longer crashes when passed huge list of candidate encodings (with 200,000+ entries). Opcache: Fixed bug GH-20718 ("Insufficient shared memory" when using JIT on Solaris). Fixed bug GH-21227 (Borked SCCP of array containing partial object). Fixed bug GH-21052 (Preloaded constant erroneously propagated to file-cached script). OpenSSL: Fix a bunch of leaks and error propagation. PCNTL: Fixed pcntl_setns() internal errors handling regarding errnos. Fixed cpuset leak in pcntl_setcpuaffinity on out-of-range CPU ID on NetBSD/Solaris platforms. Fixed pcntl_signal() signal table registering the callback first OS-wise before the internal list. Fixed pcntl_signal_dispatch() stale pointer and exception handling. PCRE: Fixed preg_match memory leak with invalid regexes. PDO_PGSQL: Fixed bug GH-21055 (connection attribute status typo for GSS negotiation). PGSQL: Fixed bug GH-21162 (pg_connect() memory leak on error). Sockets: Fixed bug GH-21161 (socket_set_option() crash with array 'addr' entry as null). Fixed possible addr length overflow with socket_connect() and AF_UNIX family sockets. - version update to 8.4.18 Core: Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown function triggered by bailout in php_output_lock_error()). Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). Fixed bug GH-GH-20914 (Internal enums can be cloned and compared). Fix OSS-Fuzz #474613951 (Leaked parent property default value). Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked backing value). Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may uaf). Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). Fixed bug GH-20479 (Hooked object properties overflow). Date: Update timelib to 2022.16. DOM: Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts). MbString: Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is invalid in the encoding). Fixed bug GH-20836 (Stack overflow in mb_convert_variables with recursive array references). Opcache: Fixed bug GH-20818 (Segfault in Tracing JIT with object reference). OpenSSL: Fix memory leaks when sk_X509_new_null() fails. Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails. Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails. Phar: Fixed bug GH-20882 (buildFromIterator breaks with missing base directory). PGSQL: Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible UB. Readline: Fixed bug GH-18139 (Memory leak when overriding some settings via readline_info()). SPL: Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator when modifying during iteration). Standard: Fixed bug #74357 (lchown fails to change ownership of symlink with ZTS) (Jakub Zelenka) Fixed bug GH-20843 (var_dump() crash with nested objects) (David Carlier) - version u pdate to 8.4.17 Core: Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature with dynamic class const lookup default argument). Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing malformed INI input via parse_ini_string()). Fixed bug GH-20714 (Uncatchable exception thrown in generator). Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant ob_start() during error deactivation). Bz2: Fixed bug GH-20620 (bzcompress overflow on large source size). DOM: Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning via clone on malformed objects). Fixed bug GH-20444 (Dom\XMLDocument::C14N() seems broken compared to DOMDocument::C14N()). GD: Fixed bug GH-20622 (imagestring/imagestringup overflow). Intl: Fix leak in umsg_format_helper(). LDAP: Fix memory leak in ldap_set_options(). Mbstring: Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator). PCNTL: Fixed bug with pcntl_getcpuaffinity() on solaris regarding invalid process ids handling. Phar: Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails). Fix SplFileInfo::openFile() in write mode. Fix build on legacy OpenSSL 1.1.0 systems. Fixed bug #74154 (Phar extractTo creates empty files). POSIX: Fixed crash on posix groups to php array creation on macos. SPL: Fixed bug GH-20678 (resource created by GlobIterator crashes with fclose()). Sqlite3: Fixed bug GH-20699 (SQLite3Result fetchArray return array|false, null returned). Standard: Fix error check for proc_open() command. Fix memory leak in mail() when header key is numeric. Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). Zlib: Fix OOB gzseek() causing assertion failure. - modified patches * php-build-reproducible-phar.patch (refreshed) - fixes CVE-2025-14179 [bsc#1264778] CVE-2026-7568 [bsc#1264769] CVE-2026-7263 [bsc#1264770] CVE-2026-7261 [bsc#1264772] CVE-2026-7259 [bsc#1264773] CVE-2026-7258 [bsc#1264774] CVE-2026-6722 [bsc#1264776] CVE-2026-6104 [bsc#1264777] CVE-2026-6735 [bsc#1264775] CVE-2026-7262 [bsc#1264771] ++++ php8-fpm: - version update to 8.4.21 Core: Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors). Fixed bug GH-21478 (Forward property operations to real instance for initialized lazy proxies). Fixed bug GH-21605 (Missing addref for Countable::count()). Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving self::/parent::/static:: callables if the error handler throws). Fixed bug GH-21603 (Missing addref for __unset). Fixed bug GH-21760 (Trait with class constant name conflict against enum case causes SEGV). CLI: Fixed bug GH-21754 (`--rf` command line option with a method triggers ext/reflection deprecation warnings). Curl: Add support for brotli and zstd on Windows. DOM: Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263) Fixed bug GH-21688 (segmentation fault on empty HTMLDocument). Upgrade to lexbor v2.7.0. FPM: Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) Iconv: Fixed bug GH-17399 (iconv memory leak on bailout). MBString: Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()). (CVE-2026-6104) Opcache: Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in zend_jit_use_reg). Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch). Fixed bug GH-21460 (COND optimization regression). Fixed faulty returns out of zend_try block in zend_jit_trace(). OpenSSL: Fix a bunch of memory leaks and crashes on edge cases. PDO_Firebird: Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) Phar: Restore is_link handler in phar_intercept_functions_shutdown. Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when SCRIPT_NAME is absent from SAPI environment). Fix memory leak in Phar::offsetGet(). Fix memory leak in phar_add_file(). Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from phar_stream_close). Fix memory leak in phar_verify_signature() when md_ctx is invalid. Random: Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize() accepts all-zero state). Session: Fixed memory leak when session GC callback return a refcounted value. SOAP: Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) SPL: Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent free). Fix concurrent iteration and deletion issues in SplObjectStorage. Standard: Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) Streams: Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). XSL: Fixed bug GH-21600 (Segfault on module shutdown). Zip: Fixed bug GH-21698 (memory leak with ZipArchive::addGlob() early return statements). - version update to 8.4.20 Bz2: Fix truncation of total output size causing erroneous errors. Core: Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in get_property_ptr_ptr for lazy proxies). DOM: Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and xml:lang attributes). FFI: Fixed resource leak in FFI::cdef() onsymbol resolution failure. GD: Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support). Opcache: Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results). Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with IS_UNDEF property in polymorphic context). Fixed bug GH-21395 (uaf in jit). OpenSSL: Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based keys). Fix missing error propagation for BIO_printf() calls. PCRE: Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl, php_pcre_split_impl, and php_pcre_grep_impl. PGSQL: Fixed preprocessor silently guarding PGSQL_SUPPRESS_TIMESTAMPS support due to a typo. SNMP: Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with NULL arguments). SOAP: Fixed Set-Cookie parsing bug wrong offset while scanning attributes. SPL: Fixed bug GH-21454 (missing write lock validation in SplHeap). Standard: Fixed bug GH-20906 (Assertion failure when messing up output buffers). Fixed bug GH-20627 (Cannot identify some avif images with getimagesize). Sysvshm: Fix memory leak in shm_get_var() when variable is corrupted. XSL: Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with Dom\XMLDocument). Fixed bug GH-21496 (UAF in dom_objects_free_storage). - version update to 8.4.19 Core: Fixed bug GH-21029 (zend_mm_heap corrupted on Aarch64, LTO builds). Fixed bug GH-20657 (Assertion failure in zend_lazy_object_get_info triggered by setRawValueWithoutLazyInitialization() and newLazyGhost()). Fixed bug GH-20504 (Assertion failure in zend_get_property_guard when accessing properties on Reflection LazyProxy via isset()). Fixed OSS-Fuzz #478009707 (Borked assign-op/inc/dec on untyped hooked property backing value). Fixed bug GH-21215 (Build fails with -std=). Fixed bug GH-13674 (Build system installs libtool wrappers when using slibtool). Curl: Fixed bug GH-21023 (CURLOPT_XFERINFOFUNCTION crash with a null callback). Don't truncate length. Date: Fixed bug GH-20936 (DatePeriod::__set_state() cannot handle null start). Fix timezone offset with seconds losing precision. DOM: Fixed bug GH-21077 (Accessing Dom\Node::baseURI can throw TypeError). Fixed bug GH-21097 (Accessing Dom\Node properties can can throw TypeError). MBString: Fixed bug GH-21223; mb_guess_encoding no longer crashes when passed huge list of candidate encodings (with 200,000+ entries). Opcache: Fixed bug GH-20718 ("Insufficient shared memory" when using JIT on Solaris). Fixed bug GH-21227 (Borked SCCP of array containing partial object). Fixed bug GH-21052 (Preloaded constant erroneously propagated to file-cached script). OpenSSL: Fix a bunch of leaks and error propagation. PCNTL: Fixed pcntl_setns() internal errors handling regarding errnos. Fixed cpuset leak in pcntl_setcpuaffinity on out-of-range CPU ID on NetBSD/Solaris platforms. Fixed pcntl_signal() signal table registering the callback first OS-wise before the internal list. Fixed pcntl_signal_dispatch() stale pointer and exception handling. PCRE: Fixed preg_match memory leak with invalid regexes. PDO_PGSQL: Fixed bug GH-21055 (connection attribute status typo for GSS negotiation). PGSQL: Fixed bug GH-21162 (pg_connect() memory leak on error). Sockets: Fixed bug GH-21161 (socket_set_option() crash with array 'addr' entry as null). Fixed possible addr length overflow with socket_connect() and AF_UNIX family sockets. - version update to 8.4.18 Core: Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown function triggered by bailout in php_output_lock_error()). Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). Fixed bug GH-GH-20914 (Internal enums can be cloned and compared). Fix OSS-Fuzz #474613951 (Leaked parent property default value). Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked backing value). Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may uaf). Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). Fixed bug GH-20479 (Hooked object properties overflow). Date: Update timelib to 2022.16. DOM: Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts). MbString: Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is invalid in the encoding). Fixed bug GH-20836 (Stack overflow in mb_convert_variables with recursive array references). Opcache: Fixed bug GH-20818 (Segfault in Tracing JIT with object reference). OpenSSL: Fix memory leaks when sk_X509_new_null() fails. Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails. Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails. Phar: Fixed bug GH-20882 (buildFromIterator breaks with missing base directory). PGSQL: Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible UB. Readline: Fixed bug GH-18139 (Memory leak when overriding some settings via readline_info()). SPL: Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator when modifying during iteration). Standard: Fixed bug #74357 (lchown fails to change ownership of symlink with ZTS) (Jakub Zelenka) Fixed bug GH-20843 (var_dump() crash with nested objects) (David Carlier) - version u pdate to 8.4.17 Core: Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature with dynamic class const lookup default argument). Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing malformed INI input via parse_ini_string()). Fixed bug GH-20714 (Uncatchable exception thrown in generator). Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant ob_start() during error deactivation). Bz2: Fixed bug GH-20620 (bzcompress overflow on large source size). DOM: Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning via clone on malformed objects). Fixed bug GH-20444 (Dom\XMLDocument::C14N() seems broken compared to DOMDocument::C14N()). GD: Fixed bug GH-20622 (imagestring/imagestringup overflow). Intl: Fix leak in umsg_format_helper(). LDAP: Fix memory leak in ldap_set_options(). Mbstring: Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator). PCNTL: Fixed bug with pcntl_getcpuaffinity() on solaris regarding invalid process ids handling. Phar: Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails). Fix SplFileInfo::openFile() in write mode. Fix build on legacy OpenSSL 1.1.0 systems. Fixed bug #74154 (Phar extractTo creates empty files). POSIX: Fixed crash on posix groups to php array creation on macos. SPL: Fixed bug GH-20678 (resource created by GlobIterator crashes with fclose()). Sqlite3: Fixed bug GH-20699 (SQLite3Result fetchArray return array|false, null returned). Standard: Fix error check for proc_open() command. Fix memory leak in mail() when header key is numeric. Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). Zlib: Fix OOB gzseek() causing assertion failure. - modified patches * php-build-reproducible-phar.patch (refreshed) - fixes CVE-2025-14179 [bsc#1264778] CVE-2026-7568 [bsc#1264769] CVE-2026-7263 [bsc#1264770] CVE-2026-7261 [bsc#1264772] CVE-2026-7259 [bsc#1264773] CVE-2026-7258 [bsc#1264774] CVE-2026-6722 [bsc#1264776] CVE-2026-6104 [bsc#1264777] CVE-2026-6735 [bsc#1264775] CVE-2026-7262 [bsc#1264771] ++++ php8-test: - version update to 8.4.21 Core: Fixed bug GH-19983 (GC assertion failure with fibers, generators and destructors). Fixed bug GH-21478 (Forward property operations to real instance for initialized lazy proxies). Fixed bug GH-21605 (Missing addref for Countable::count()). Fixed bug GH-21699 (Assertion failure in shutdown_executor when resolving self::/parent::/static:: callables if the error handler throws). Fixed bug GH-21603 (Missing addref for __unset). Fixed bug GH-21760 (Trait with class constant name conflict against enum case causes SEGV). CLI: Fixed bug GH-21754 (`--rf` command line option with a method triggers ext/reflection deprecation warnings). Curl: Add support for brotli and zstd on Windows. DOM: Fixed GHSA-4jhr-8w89-j733 and GH-21566 (Dom\XMLDocument::C14N() emits duplicate xmlns declarations after setAttributeNS()). (CVE-2026-7263) Fixed bug GH-21688 (segmentation fault on empty HTMLDocument). Upgrade to lexbor v2.7.0. FPM: Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) Iconv: Fixed bug GH-17399 (iconv memory leak on bailout). MBString: Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) Fixed GHSA-74r9-qxhc-fx53 (Out-of-bounds access in mbfl_name2encoding_ex()). (CVE-2026-6104) Opcache: Fixed bug GH-21158 (JIT: Assertion jit->ra[var].flags & (1<<0) failed in zend_jit_use_reg). Fixed bug GH-21593 (Borked function JIT JMPNZ smart branch). Fixed bug GH-21460 (COND optimization regression). Fixed faulty returns out of zend_try block in zend_jit_trace(). OpenSSL: Fix a bunch of memory leaks and crashes on edge cases. PDO_Firebird: Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) Phar: Restore is_link handler in phar_intercept_functions_shutdown. Fixed bug GH-21797 (phar: NULL dereference in Phar::webPhar() when SCRIPT_NAME is absent from SAPI environment). Fix memory leak in Phar::offsetGet(). Fix memory leak in phar_add_file(). Fixed bug GH-21799 (phar: propagate phar_stream_flush return value from phar_stream_close). Fix memory leak in phar_verify_signature() when md_ctx is invalid. Random: Fixed bug GH-21731 (Random\Engine\Xoshiro256StarStar::__unserialize() accepts all-zero state). Session: Fixed memory leak when session GC callback return a refcounted value. SOAP: Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) SPL: Fixed bug GH-21499 (RecursiveArrayIterator getChildren UAF after parent free). Fix concurrent iteration and deletion issues in SplObjectStorage. Standard: Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) Streams: Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). XSL: Fixed bug GH-21600 (Segfault on module shutdown). Zip: Fixed bug GH-21698 (memory leak with ZipArchive::addGlob() early return statements). - version update to 8.4.20 Bz2: Fix truncation of total output size causing erroneous errors. Core: Fixed bugs GH-20875, GH-20873, GH-20854 (Propagate IN_GET guard in get_property_ptr_ptr for lazy proxies). DOM: Fixed bug GH-21486 (Dom\HTMLDocument parser mangles xml:space and xml:lang attributes). FFI: Fixed resource leak in FFI::cdef() onsymbol resolution failure. GD: Fixed bug GH-21431 (phpinfo() to display libJPEG 10.0 support). Opcache: Fixed bug GH-20838 (JIT compiler produces wrong arithmetic results). Fixed bug GH-21267 (JIT tracing: infinite loop on FETCH_OBJ_R with IS_UNDEF property in polymorphic context). Fixed bug GH-21395 (uaf in jit). OpenSSL: Fixed bug GH-21083 (Skip private_key_bits validation for EC/curve-based keys). Fix missing error propagation for BIO_printf() calls. PCRE: Fixed re-entrancy issue on php_pcre_match_impl, php_pcre_replace_impl, php_pcre_split_impl, and php_pcre_grep_impl. PGSQL: Fixed preprocessor silently guarding PGSQL_SUPPRESS_TIMESTAMPS support due to a typo. SNMP: Fixed bug GH-21336 (SNMP::setSecurity() undefined behavior with NULL arguments). SOAP: Fixed Set-Cookie parsing bug wrong offset while scanning attributes. SPL: Fixed bug GH-21454 (missing write lock validation in SplHeap). Standard: Fixed bug GH-20906 (Assertion failure when messing up output buffers). Fixed bug GH-20627 (Cannot identify some avif images with getimagesize). Sysvshm: Fix memory leak in shm_get_var() when variable is corrupted. XSL: Fix GH-21357 (XSLTProcessor works with DOMDocument, but fails with Dom\XMLDocument). Fixed bug GH-21496 (UAF in dom_objects_free_storage). - version update to 8.4.19 Core: Fixed bug GH-21029 (zend_mm_heap corrupted on Aarch64, LTO builds). Fixed bug GH-20657 (Assertion failure in zend_lazy_object_get_info triggered by setRawValueWithoutLazyInitialization() and newLazyGhost()). Fixed bug GH-20504 (Assertion failure in zend_get_property_guard when accessing properties on Reflection LazyProxy via isset()). Fixed OSS-Fuzz #478009707 (Borked assign-op/inc/dec on untyped hooked property backing value). Fixed bug GH-21215 (Build fails with -std=). Fixed bug GH-13674 (Build system installs libtool wrappers when using slibtool). Curl: Fixed bug GH-21023 (CURLOPT_XFERINFOFUNCTION crash with a null callback). Don't truncate length. Date: Fixed bug GH-20936 (DatePeriod::__set_state() cannot handle null start). Fix timezone offset with seconds losing precision. DOM: Fixed bug GH-21077 (Accessing Dom\Node::baseURI can throw TypeError). Fixed bug GH-21097 (Accessing Dom\Node properties can can throw TypeError). MBString: Fixed bug GH-21223; mb_guess_encoding no longer crashes when passed huge list of candidate encodings (with 200,000+ entries). Opcache: Fixed bug GH-20718 ("Insufficient shared memory" when using JIT on Solaris). Fixed bug GH-21227 (Borked SCCP of array containing partial object). Fixed bug GH-21052 (Preloaded constant erroneously propagated to file-cached script). OpenSSL: Fix a bunch of leaks and error propagation. PCNTL: Fixed pcntl_setns() internal errors handling regarding errnos. Fixed cpuset leak in pcntl_setcpuaffinity on out-of-range CPU ID on NetBSD/Solaris platforms. Fixed pcntl_signal() signal table registering the callback first OS-wise before the internal list. Fixed pcntl_signal_dispatch() stale pointer and exception handling. PCRE: Fixed preg_match memory leak with invalid regexes. PDO_PGSQL: Fixed bug GH-21055 (connection attribute status typo for GSS negotiation). PGSQL: Fixed bug GH-21162 (pg_connect() memory leak on error). Sockets: Fixed bug GH-21161 (socket_set_option() crash with array 'addr' entry as null). Fixed possible addr length overflow with socket_connect() and AF_UNIX family sockets. - version update to 8.4.18 Core: Fixed bug GH-20837 (NULL dereference when calling ob_start() in shutdown function triggered by bailout in php_output_lock_error()). Fix OSS-Fuzz #471533782 (Infinite loop in GC destructor fiber). Fix OSS-Fuzz #472563272 (Borked block_pass JMP[N]Z optimization). Fixed bug GH-GH-20914 (Internal enums can be cloned and compared). Fix OSS-Fuzz #474613951 (Leaked parent property default value). Fixed bug GH-20766 (Use-after-free in FE_FREE with GC interaction). Fix OSS-Fuzz #471486164 (Broken by-ref assignment to uninitialized hooked backing value). Fix OSS-Fuzz #438780145 (Nested finally with repeated return type check may uaf). Fixed bug GH-20905 (Lazy proxy bailing __clone assertion). Fixed bug GH-20479 (Hooked object properties overflow). Date: Update timelib to 2022.16. DOM: Fixed GH-21041 (Dom\HTMLDocument corrupts closing tags within scripts). MbString: Fixed bug GH-20833 (mb_str_pad() divide by zero if padding string is invalid in the encoding). Fixed bug GH-20836 (Stack overflow in mb_convert_variables with recursive array references). Opcache: Fixed bug GH-20818 (Segfault in Tracing JIT with object reference). OpenSSL: Fix memory leaks when sk_X509_new_null() fails. Fix crash when in openssl_x509_parse() when i2s_ASN1_INTEGER() fails. Fix crash in openssl_x509_parse() when X509_NAME_oneline() fails. Phar: Fixed bug GH-20882 (buildFromIterator breaks with missing base directory). PGSQL: Fixed INSERT/UPDATE queries building with PQescapeIdentifier() and possible UB. Readline: Fixed bug GH-18139 (Memory leak when overriding some settings via readline_info()). SPL: Fixed bug GH-20856 (heap-use-after-free in SplDoublyLinkedList iterator when modifying during iteration). Standard: Fixed bug #74357 (lchown fails to change ownership of symlink with ZTS) (Jakub Zelenka) Fixed bug GH-20843 (var_dump() crash with nested objects) (David Carlier) - version u pdate to 8.4.17 Core: Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature with dynamic class const lookup default argument). Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing malformed INI input via parse_ini_string()). Fixed bug GH-20714 (Uncatchable exception thrown in generator). Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant ob_start() during error deactivation). Bz2: Fixed bug GH-20620 (bzcompress overflow on large source size). DOM: Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning via clone on malformed objects). Fixed bug GH-20444 (Dom\XMLDocument::C14N() seems broken compared to DOMDocument::C14N()). GD: Fixed bug GH-20622 (imagestring/imagestringup overflow). Intl: Fix leak in umsg_format_helper(). LDAP: Fix memory leak in ldap_set_options(). Mbstring: Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator). PCNTL: Fixed bug with pcntl_getcpuaffinity() on solaris regarding invalid process ids handling. Phar: Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails). Fix SplFileInfo::openFile() in write mode. Fix build on legacy OpenSSL 1.1.0 systems. Fixed bug #74154 (Phar extractTo creates empty files). POSIX: Fixed crash on posix groups to php array creation on macos. SPL: Fixed bug GH-20678 (resource created by GlobIterator crashes with fclose()). Sqlite3: Fixed bug GH-20699 (SQLite3Result fetchArray return array|false, null returned). Standard: Fix error check for proc_open() command. Fix memory leak in mail() when header key is numeric. Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). Zlib: Fix OOB gzseek() causing assertion failure. - modified patches * php-build-reproducible-phar.patch (refreshed) - fixes CVE-2025-14179 [bsc#1264778] CVE-2026-7568 [bsc#1264769] CVE-2026-7263 [bsc#1264770] CVE-2026-7261 [bsc#1264772] CVE-2026-7259 [bsc#1264773] CVE-2026-7258 [bsc#1264774] CVE-2026-6722 [bsc#1264776] CVE-2026-6104 [bsc#1264777] CVE-2026-6735 [bsc#1264775] CVE-2026-7262 [bsc#1264771] ++++ plexus-classworlds: - Upgrade to version 2.11.0 * New features and improvements + Add Automatic-Module-Name to JAR manifest for JPMS compatibility * Bug Fixes + Restore Maven 2 compatibility - revert "Drop deprecated package org.codehaus.classworlds" * Dependency updates + Bump org.jacoco:jacoco-maven-plugin from 0.8.12 to 0.8.14 - Upgrade to version 2.10.0 * Breaking changes + Drop deprecated package org.codehaus.classworlds * Maintenance + Add comprehensive test coverage improvements + Bump jakarta.xml.bind:jakarta.xml.bind-api from 4.0.2 to 4.0.4 + JUnit Jupiter best practices + Some automatic code cleanups + Remove no longer needed code * Dependency updates + Bump org.codehaus.plexus:plexus from 20 to 25 ++++ plexus-classworlds: - Upgrade to version 2.11.0 * New features and improvements + Add Automatic-Module-Name to JAR manifest for JPMS compatibility * Bug Fixes + Restore Maven 2 compatibility - revert "Drop deprecated package org.codehaus.classworlds" * Dependency updates + Bump org.jacoco:jacoco-maven-plugin from 0.8.12 to 0.8.14 - Upgrade to version 2.10.0 * Breaking changes + Drop deprecated package org.codehaus.classworlds * Maintenance + Add comprehensive test coverage improvements + Bump jakarta.xml.bind:jakarta.xml.bind-api from 4.0.2 to 4.0.4 + JUnit Jupiter best practices + Some automatic code cleanups + Remove no longer needed code * Dependency updates + Bump org.codehaus.plexus:plexus from 20 to 25 ++++ python-mistune: - CVE-2026-33079: ReDoS in `LINK_TITLE_RE` can lead to denial of service via a crafted Markdown (bsc#1264347) * added CVE-2026-33079-CVE-2026-33441.patch - CVE-2026-33441: processing of malformed reference links can lead to excessive resource consumption and denial of service (bsc#1264752) * added CVE-2026-33079-CVE-2026-33441.patch - CVE-2026-44708: improper HTML escaping in the math plugin can lead to XSS (bsc#1264751) * added CVE-2026-44708.patch - CVE-2026-44896: improper escaping in `render_figure` can lead to attribute injection and XSS (bsc#1264754) * added CVE-2026-44896.patch - CVE-2026-44897: improper sanitization of user-controlled input in `HTMLRenderer.heading` can lead to XSS (bsc#1264750) * added CVE-2026-44897.patch - CVE-2026-44898: improper sanitization of user-supplied HTML input in `render_toc_ul` can lead to XSS (bsc#1265052) * added CVE-2026-44898.patch - CVE-2026-44899: improper input verification in Image directive plugin and improper escaping in `render_block_image` can lead to CSS injection (bsc#1265053) * added CVE-2026-44899.patch ++++ python-mistune: - CVE-2026-33079: ReDoS in `LINK_TITLE_RE` can lead to denial of service via a crafted Markdown (bsc#1264347) * added CVE-2026-33079-CVE-2026-33441.patch - CVE-2026-33441: processing of malformed reference links can lead to excessive resource consumption and denial of service (bsc#1264752) * added CVE-2026-33079-CVE-2026-33441.patch - CVE-2026-44708: improper HTML escaping in the math plugin can lead to XSS (bsc#1264751) * added CVE-2026-44708.patch - CVE-2026-44896: improper escaping in `render_figure` can lead to attribute injection and XSS (bsc#1264754) * added CVE-2026-44896.patch - CVE-2026-44897: improper sanitization of user-controlled input in `HTMLRenderer.heading` can lead to XSS (bsc#1264750) * added CVE-2026-44897.patch - CVE-2026-44898: improper sanitization of user-supplied HTML input in `render_toc_ul` can lead to XSS (bsc#1265052) * added CVE-2026-44898.patch - CVE-2026-44899: improper input verification in Image directive plugin and improper escaping in `render_block_image` can lead to CSS injection (bsc#1265053) * added CVE-2026-44899.patch ++++ trivy: - update go-git to 5.18.0 (bsc#1264873, CVE-2026-41506) ++++ trivy: - update go-git to 5.18.0 (bsc#1264873, CVE-2026-41506) ++++ trivy: - update go-git to 5.18.0 (bsc#1264873, CVE-2026-41506) ++++ trivy: - update go-git to 5.18.0 (bsc#1264873, CVE-2026-41506) ++++ wicked2nm: - Update v1.5.0 * Respect create-cid and client-id in interface xml * Require at least one file for migrate and show commands * Perform extra validation for correct xml file * Improve dhcp.update default and user info * Update dependencies * Allow DHCP+staticIP addresses * Fix DHCLIENT_SET_DEFAULT_ROUTE="no" * Handle 'STATIC_FALLBACK' and 'NetworkManager' in netconfig * Implement team to bond migration * Update agama-network to remove dependency on curl - Reenable `update` in cargo vendor service ------------------------------------------------------------------ ------------------ 2026-5-11 - May 11 2026 ------------------- ------------------------------------------------------------------ ++++ ImageMagick: - fix overflow check (CVE-2026-31853 [bsc#1259528]) - modified patches * ImageMagick-CVE-2026-31853.patch ++++ ImageMagick: - fix overflow check (CVE-2026-31853 [bsc#1259528]) - modified patches * ImageMagick-CVE-2026-31853.patch ++++ apache-commons-cli: - Update to 1.11.0 * New Features + Add CommandLine.getOptionCount() to measure option repetition * Fixed Bugs + CLI-351: Multiple trailing BREAK_CHAR_SET characters cause infinite loop in HelpFormatter + CLI-351: Fix issue with groups not being reported in help output * Updates + Bump org.apache.commons:commons-parent from 85 to 91 + Bump commons-io:commons-io from 2.20.0 to 2.21.0 - Modified patch: * CLI-253-workaround.patch + rediff ++++ apache-commons-collections4: - Upgrade to upstream version 4.5.0 * New features + Add IteratorUtils.toSet(Iterator) + Add IteratorUtils.toSet(Iterator, int) + Add EnumerationUtils.toSet(Enumeration) + COLLECTIONS-693: Please add OWASP Dependency Check to the build * Fixed Bugs + Refactor AbstractPropertiesFactory.load(File) to use NIO + Refactor AbstractPropertiesFactory.load(String) to use NIO * Changes + Bump commons-codec:commons-codec from 1.17.1 to 1.18.0 + Bump org.apache.commons:commons-parent from 78 to 81 + Bump commons.jacoco.version from 0.8.13-SNAPSHOT to 0.13.0 + [test] Bump commons-io:commons-io from 2.18.0 to 2.19.0 - Update to 1.28.0 * New Features + Add GzipParameters.getModificationInstant() + Add GzipParameters.setModificationInstant(Instant) + Add GzipParameters.OS, setOS(OS), getOS() + Add GzipParameters.toString() + COMPRESS-638: Add GzipParameters.setFileNameCharset(Charset) and getFileNameCharset() to override the default ISO-8859-1 Charset + Add support for gzip extra subfields, see GzipParameters.setExtra(HeaderExtraField) + Add CompressFilterOutputStream and refactor to use + Add ZipFile.stream() + GzipCompressorInputStream reads the modification time (MTIME) and stores its value incorrectly multiplied by 1,000 + GzipCompressorInputStream writes the modification time (MTIME) the value incorrectly divided by 1,000 + Add optional FHCRC to GZIP header + Add GzipCompressorInputStream.Builder allowing to customize the file name and comment Charsets + Add GzipCompressorInputStream.Builder .setOnMemberStart(IOConsumer) to monitor member parsing + Add GzipCompressorInputStream.Builder .setOnMemberEnd(IOConsumer) to monitor member parsing + Add PMD check to default Maven goal + Add SevenZFile.Builder.setMaxMemoryLimitKiB(int) + Add MemoryLimitException.MemoryLimitException(long, int, Throwable) and deprecate MemoryLimitException .MemoryLimitException(long, int, Exception) + COMPRESS-692: Add support for zstd compression in zip archives + Add support for XZ compression in ZIP archives + COMPRESS-695: Add ZipArchiveInputStream .createZstdInputStream(InputStream) to provide a different InputStream implementation for Zstandard (Zstd) + Add org.apache.commons.compress.harmony.pack200 .Pack200Exception.Pack200Exception(String, Throwable) + COMPRESS-697: Move BitStream.nextBit() method to BitInputStream + Add org.apache.commons.compress.compressors.lzma .LZMACompressorInputStream.builder/Builder() + Add org.apache.commons.compress.compressors.lzma .LZMACompressorOutputStream.builder/Builder() + Add org.apache.commons.compress.compressors.xz .XZCompressorInputStream.builder/Builder() + Add org.apache.commons.compress.compressors.xz .XZCompressorOutputStream.builder/Builder() + Add org.apache.commons.compress.compressors.xz .ZstdCompressorOutputStream.builder/Builder() + Add org.apache.commons.compress.compressors.xz.ZstdConstants + Add org.apache.commons.compress.archivers.ArchiveException .requireNonNull(T, Supplier) + Add org.apache.commons.compress.compressors .CompressorException as the root for all custom exceptions ArchiveException and CompressorException + Add ArchiveException.ArchiveException(String, Throwable) + Add ArchiveException.ArchiveException(Throwable) + Add org.apache.commons.compress.archivers.sevenz .SevenZArchiveEntry.isEmptyStream() + Add generics for org.apache.commons.compress.compressors .CompressorStreamProvider.createCompressorOutputStream(String, T) * Fixed Bugs + COMPRESS-686: Better exception messages in SeekableInMemoryByteChannel + COMPRESS-691: ZipArchiveOutputStream.addRawArchiveEntry() should check is2PhaseSource + ArchiveException extends IOException + CompressorException extends IOException + Update outdated descriptions in IOUtils and IOUtilsTest + Remove unused local variable in ZipFile + Optimize ZipEightByteInteger + ZipEightByteInteger.toString() now returns a number string without text prefix, like BigInteger + Throw an IllegalArgumentException when a file name or comment in gzip parameters encodes to a byte array with a 0 byte + Update outdated links in ZipMethod Javadoc + Deprecate ZipUtil.signedByteToUnsignedInt(byte) in favor of Byte.toUnsignedInt(byte) + ZipArchiveOutputStream.close() does not close its underlying output stream + ZipArchiveOutputStream.close() does not close its underlying output stream + Don't use deprecated code in TarArchiveInputStream + Don't use deprecated code in TarFile + CpioArchiveInputStream.read(byte[], int, int) now throws an IOException on a data pad count mismatch + CpioArchiveInputStream.readNewEntry(boolean) now throws an IOException on a header pad count mismatch + CpioArchiveInputStream.readOldBinaryEntry(boolean) now throws an IOException on a header pad count mismatch + Fix Javadoc and names in the org.apache.commons.compress .archivers.sevenz package to specify kibibyte scale in memory limits + Fix Javadoc and names in the org.apache.commons.compress .compressors.lzw package to specify kibibyte scale in memory limits + Fix Javadoc and names in the org.apache.commons.compress .compressors.z package to specify kibibyte scale in memory limits + Refactor LZ77Compressor block classes to reduce duplication + Package-private and private classes can be final + Deprecate ArjArchiveEntry.HostOs.HostOs() + Drop coveralls reference (no longer needed) + Some ZIP operations won't read all data from a non-blocking file channel + COMPRESS-696: ZipArchiveInputStream.getCompressedCount() throws NullPointerException if called before getNextEntry() + org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getConstantPoolEntry(int, long) now throws Pack200Exception instead of Error and does better range checking of the index argument + org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getInitMethodPoolEntry(int, long, String) now throws Pack200Exception instead of Error and does better range checking of the index argument + org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getInitMethodPoolEntry(int, long, String) now throws Pack200Exception instead of Error on bad constant pool type input + org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getClassSpecificPoolEntry(int, long, String) now throws Pack200Exception instead of Error on bad constant pool type input + org.apache.commons.compress.harmony.unpack200 .SegmentConstantPool.getClassPoolEntry(String) now throws Pack200Exception instead of Error on some bad inputs and states + org.apache.commons.compress.harmony.unpack200.bytecode .ByteCode.extractOperands(OperandManager, Segment, int) now throws Pack200Exception instead of Error on some bad inputs and states + org.apache.commons.compress.harmony.unpack200.bytecode.forms .ByteCodeForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states + org.apache.commons.compress.harmony.unpack200.bytecode .CodeAttribute.CodeAttribute(int, int, byte[], Segment, OperandManager, List) now throws Pack200Exception instead of Error on some bad inputs and states + org.apache.commons.compress.harmony.unpack200.bytecode.forms .IMethodRefForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states + org.apache.commons.compress.harmony.unpack200.bytecode.forms .MultiANewArrayForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states + org.apache.commons.compress.harmony.unpack200.bytecode.forms .NewClassRefForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states + org.apache.commons.compress.harmony.unpack200.bytecode.forms .ReferenceForm.setByteCodeOperands(ByteCode, OperandManager, int) now throws Pack200Exception instead of Error on some bad inputs and states + Deprecate org.apache.commons.compress.harmony.pack200 .CanonicalCodecFamilies.CanonicalCodecFamilies() + Deprecate FileNameUtils#getBaseName(Path) + Deprecate FileNameUtils#getExtension(Path) + org.apache.commons.compress.harmony.unpack200.Archive.unpack() should not log to system out (the console) + [site] Fix minor zip docs type: remove extraneous 'a' + Throw a better exception in org.apache.commons.compress .archivers.sevenz.SevenZFile.readFilesInfo(ByteBuffer, Archive) + MemoryLimitException now extends CompressException instead of IOException (CompressException extends IOException) + DumpArchiveException now extends ArchiveException instead of IOException (ArchiveException extends CompressException) + PasswordRequiredException now extends CompressException instead of IOException (CompressException extends IOException) + Pack200Exception now extends CompressException instead of IOException (CompressException extends IOException) + ArArchiveInputStream.getBSDLongName(String) now throws its EOFException with a message + ZipEncodingHelper.getZipEncoding(*) can throw NullPointerException and IllegalArgumentException on bad input instead of returning a value using the default Charset + Javadoc improvements throughout + COMPRESS-699: ArchiveStreamFactory.detect(inputStream) ArchiveException for TAR regression + COMPRESS-700: Can't detect file flutter_awesome_buttons-0.1.0.tar as a TAR file + Deprecate org.apache.commons.compress.utils.TimeUtils .toUnixTime(FileTime) in favor of org.apache.commons.io.file .attribute.FileTimes.toUnixTime(FileTime) + Deprecate org.apache.commons.compress.utils.TimeUtils .truncateToHundredNanos(FileTime) * Changes + Bump org.apache.commons:commons-parent from 72 to 85 + Bump com.github.luben:zstd-jni from 1.5.6-4 to 1.5.7-4 + Bump org.apache.commons:commons-lang3 from 3.16.0 to 3.18.0 + Bump commons-io:commons-io from 2.16.1 to 2.20.0 + Bump com.github.marschall:memoryfilesystem from 2.8.0 to 2.8.1 + Bump org.ow2.asm:asm from 9.7 to 9.7.1 + Bump commons-codec:commons-codec from 1.17.1 to 1.19.0 * Removed + COMPRESS-638: GzipCompressorOutputStream no longer percent-endcodes in US-ASCII a file name or comment that the Charset in GzipParameters.setFileNameCharset(Charset) cannot encode + Remove ZstdCompressorOutputStream.toString(), it was misleading by returning the delegate's toString() - Changes of version 1.27.1 * Fixed Bugs + COMPRESS-686: Compression into BZip2 format has unexpected end of file when using a BufferedOutputStream + Changes + Bump org.apache.commons:commons-lang3 from 3.15.0 to 3.16.0 - Changes of version 1.27.0 * New Features + Add ArchiveInputStream.forEach(IOConsumer) + Add ArchiveInputStream.iterator() + Add ArchiveOutputStream.isFinished() + Add ArchiveOutputStream.checkFinished() * Fixed Bugs + Fix PMD UnnecessaryFullyQualifiedName and others + COMPRESS-681: Support reading a 7z file that writing archive properties + Upgrade commons-io from 2.15.1 to 2.16.1 + CompressorOutputStream now extends FilterOutputStream + ArchiveOutputStream now extends FilterOutputStream + COMPRESS-685: Update Javadoc description for GzipCompressorInputStream + Replace FileNameUtil.getCompressedFileName(String) use of Locale.ENGLISH with Locale.ROOT + Fix SpotBugs DLS_DEAD_LOCAL_STORE in SevenZFile.readPackInfo(ByteBuffer, Archive) + Fix SpotBugs NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE in ZipFile.openZipChannel(Path, long, OpenOption[]) + Fix SpotBugs UC_USELESS_OBJECT in unpack200.CpBands.parseCpSignature(InputStream) + Fix PMD UselessOverridingMethod in unpack200.bytecode.InnerClassesAttribute + Fix PMD UselessOverridingMethod in unpack200.bytecode.LineNumberTableAttribute + Fix PMD CheckSkipResult in ZipArchiveInputStream.closeEntry() * Changes + COMPRESS-684: Replace assert with Exception + Bump org.apache.commons:commons-parent from 69 to 72 + Bump PMD from 6.x to 7.2.0 + Bump commons-codec:commons-codec from 1.17.0 to 1.17.1 + Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.15.0 + Bump com.github.luben:zstd-jni from 1.5.6-3 to 1.5.6-4 + Bump org.tukaani:xz from 1.9 to 1.10 + Bump org.hamcrest:hamcrest from 2.2 to 3.0 - Removed patches: * 0001-Remove-Brotli-compressor.patch * 0002-Remove-ZSTD-compressor.patch * 0003-Remove-Pack200-compressor.patch + we have now the dependencies for zstd and brotli ++++ apache-commons-exec: - Upgrade to version 1.6.0 * New features: + TimeoutObserver now extends Consumer + Add org.apache.commons.exec.Watchdog.getTimeout() * Fixed Bugs: + Watchdog.builder().get() now uses a default timeout of 30 seconds instead of throwing a NullPointerException + ExecuteWatchdog.builder().get() now uses a default timeout of 30 seconds instead of throwing a NullPointerException + Calling org.apache.commons.exec.Watchdog.Builder .setTimeout(Duration) with null now resets to the default INFINITE_TIMEOUT_DURATION timeout + Calling org.apache.commons.exec.ExecuteWatchdog.Builder .setTimeout(Duration) with null now resets to the default INFINITE_TIMEOUT_DURATION timeout + Calling org.apache.commons.exec.Watchdog.Builder .setThreadFactory(ThreadFactory) with null now resets to the default java.util.concurrent.Executors.defaultThreadFactory() + Calling org.apache.commons.exec.ExecuteWatchdog.Builder .setThreadFactory(ThreadFactory) with null now resets to the default java.util.concurrent.Executors.defaultThreadFactory() + Fix Checkstyle issues + Fix StringUtils.quoteArgument(String) when input contains single and double quotes #309 + Fix Apache RAT plugin console warnings * Changes: + Bump org.apache.commons:commons-parent from 83 to 93 + Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0 - Upgrade to version 1.5.0 * New features: + Add Maven property project.build.outputTimestamp for build reproducibility + Add CommandLine.CommandLine(Path) + Add Executor.getWorkingDirectoryPath() + Add DefaultExecutor.Builder.setWorkingDirectory(Path) + Add CommandLauncher.exec(CommandLine, Map, Path) * Fixed Bugs: + EXEC-122: Document PumpStreamHandler stream thread-safety requirements + Fix CI only running on Ubuntu and improve OS-specific tests + Fix PMD UnnecessaryFullyQualifiedName in DefaultExecutor + Fix PMD EmptyCatchBlock by allowing commented blocks + Fix PMD EmptyControlStatement by allowing commented blocks + Replace OS.OS_* use of Locale.ENGLISH with Locale.ROOT + Deprecate DebugUtils.DebugUtils() + Deprecate MapUtils.MapUtils() + Deprecate StringUtils.StringUtils() + Fix Javadoc warnings + Fix SpotBugs AT_STALE_THREAD_WRITE_OF_PRIMITIVE: Shared primitive variable "shouldDestroy" in one thread may not yield the value of the most recent write from another thread [org.apache.commons.exec.ShutdownHookProcessDestroyer $ProcessDestroyerThread] + Fix SpotBugs AT_STALE_THREAD_WRITE_OF_PRIMITIVE: Shared primitive variable "added" in one thread may not yield the value of the most recent write from another thread [org.apache.commons.exec.ShutdownHookProcessDestroyer] * Changes: + Bump org.apache.commons:commons-parent from 65 to 83 * Removed: + Remove obsolete and unmaintained Ant build file - Generate Ant build file for our build - Removed patch: * commons-exec-1.3-build_xml.patch + not needed anymore - Upgrade to version 1.4.0 * New features: + Add ShutdownHookProcessDestroyer.isEmpty() + Add DefaultExecuteResultHandler.waitFor(Duration) + Add Watchdog.Watchdog(Duration) + Add ExecuteWatchdog.ExecuteWatchdog(Duration) + Add PumpStreamHandler.setStopTimeout(Duration) and deprecate PumpStreamHandler.setStopTimeout(long) + Add DefaultExecutor.Builder + Add DaemonExecutor.Builder + Add ExecuteWatchdog.Builder + Add Watchdog.Builder * Fixed Bugs: + EXEC-105: Fix code snippet in tutorial page + EXEC-100: Sync org.apache.commons.exec.OS with the newest Ant source file. + EXEC-64: DefaultExecutor swallows IOException cause instead of propagating it (work-round for Java 1.5) + Java-style Array declaration and remove empty finally block + Use JUnit 5 assertThrows() + [StepSecurity] ci: Harden GitHub Actions + Port from JUnit 4 to 5 + [Javadoc] CommandLine.toCleanExecutable(final String dirtyExecutable) IllegalArgumentException #61 + ExecuteException propagates its cause to its IOException superclass + Propagate exception in DebugUtils.handleException(String, Exception) + Deprecate StringUtils.toString(String[], String) in favor of String.join(CharSequence, CharSequence...) + EXEC-78: No need to use System.class.getMethod("getenv",...) any more + EXEC-70: Delegate thread creation to java.util.concurrent.ThreadFactory + Avoid NullPointerException in MapUtils.prefix(Map, String) * Changes: + Bump github actions #52 + EXEC-111: Update from Java 5 to 6 + Update from Java 7 to 8 + Bump actions/cache from 2 to 3.0.11 + Bump actions/checkout from 2.3.2 to 3.1.0 + Bump actions/setup-java from 1.4.0 to 3.8.0 + Bump junit from 4.13 to 5.9.1 Vintage + Bump maven-pmd-plugin from 2.7.1 to 3.19.0 + Bump maven-checkstyle-plugin from 2.13 to 3.2.0 + Bump commons-parent from 52 to 65 + Bump japicmp-maven-plugin from 0.15.6 to 0.16.0 * Removed: + Deprecate DefaultExecuteResultHandler.waitFor(long) + Deprecate ExecuteWatchdog.ExecuteWatchdog(long) + Deprecate Watchdog.Watchdog(long) + Drop obsolete and unmaintained Ant build + Drop CLIRR plugin, replaced by JApiCmp ++++ apache-commons-lang3: - Update to 3.20.0 * New features: + Add SystemProperties.getPath(String, Supplier) + Add JavaVersion.JAVA_25 + Add JavaVersion.JAVA_26 + Add SystemUtils.IS_JAVA_25 + Add SystemUtils.IS_JAVA_26 + Add MutablePair.ofNonNull(Map.Entry) + Add TimedSemaphore.builder(), Builder, and deprecate constructors + LANG-1504: Adding labels and history to split StopWatch * Fixed Bugs: + Optimize ObjectToStringComparator.compare() method + [javadoc] Improve StringUtils Javadoc + Fix internal inverted logic in private isEnum() method and correct its usage in getFirstEnum() + Use accessors in ToStringStyle so subclasses can effectively override them + 'LocaleUtils.toLocale(String)' for a 2 letter country code now returns a value instead of throwing an 'IllegalArgumentException' + Fix typo in StringUtils.trunctate() IllegalArgumentException message and test assertion messages + Fix test fixture in ReflectionDiffBuilderTest.testTransientFieldDifference() + LANG-1789: NullPointerException when generating NoSuchMethodException in MethodUtils + LANG-1786: Map deprecated TimeZone short IDs and avoid JRE WARNINGs to the console + LANG-1792: TypeUtils.toString() skips angle brackets for Class type + Mention JDK 25 LTS as a tested version in the release notes * Changes: + Bump org.apache.commons:commons-parent from 88 to 92 - Update to 3.19.0 * New features: + Add ArrayUtils.SOFT_MAX_ARRAY_LENGTH + Add SystemUtils.IS_OS_NETWARE + Add MethodUtils.getAccessibleMethod(Class, Method) + Add documentation to site for CVE-2025-48924 ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs + Add StringUtils.indexOfAny(CharSequence, int, char...) + Add ConcurrentException.ConcurrentException(String) + Add DateUtils.toLocalDateTime(Date[, TimeZone]) + Add DateUtils.toOffsetDateTime(Date[, TimeZone]) + Add DateUtils.toZonedDateTime(Date[, TimeZone]) + Add ByteConsumer + Add ByteSupplier + Add FailableByteConsumer + Add FailableByteSupplier + LANG-1784: Add Functions methods for null-safe mapping and chaining + LANG-1784: Add Failable methods for null-safe mapping and chaining + Add DoubleRange.fit(double) + Add IntegerRange.fit(int) + Add LongRange.fit(long) + Add DurationUtils.get(String, TemporalUnit, long) + Add DurationUtils.getMillis(String, long) + Add DurationUtils.getSeconds(String, long) + Add SystemProperties.getBoolean(Class, String, boolean) + Add SystemProperties.getInt(Class, String, int) + Add SystemProperties.getLong(Class, String, long) * Fixed Bugs: + LANG-1778: MethodUtils.getMatchingMethod() doesn't respect the hierarchy of methods + MethodUtils.getMethodObject(Class, String, Class...) now returns null instead of throwing a NullPointerException, as it does for other exception types + Reduce spurious failures in ArrayUtilsTest methods that test ArrayUtils.shuffle() methods + MethodUtils cannot find or invoke a public method on a public class implemented in its package-private superclass + AtomicSafeInitializer.get() can spin internally if the FailableSupplier given to AbstractConcurrentInitializer .AbstractBuilder.setInitializer(FailableSupplier) throws a RuntimeException + LANG-1783: WordUtils.containsAllWords?() may throw PatternSyntaxException + LANG-1782: MethodUtils cannot find or invoke vararg methods without providing vararg types or values + MethodUtils cannot find or invoke vararg methods of interface types + MethodUtils cannot find or invoke vararg methods when widening primitive types following the JLS 5.1.2. Widening Primitive Conversion + LANG-1597: Invocation fails because matching varargs method found but then discarded + Don't check accessibility twice in MemberUtils .setAccessibleWorkaround(T) + LANG-1774: Improve handling of ClassUtils .getShortCanonicalName() for invalid input + LANG-1720: Improve Javadocs for Conversion + Fix CalendarUtils.toLocalDate() Javadoc return type description + Fix the method name in Javadoc examples for CharUtils.isHex() + Deprecate NumberUtils.compare(byte, byte) in favor of Byte.compare(byte, byte) + Deprecate NumberUtils.compare(int, int) in favor of Integer.compare(int, int) + Deprecate NumberUtils.compare(long, long) in favor of Long.compare(long, long) + Deprecate NumberUtils.compare(short, short) in favor of Short.compare(short, short) + Deprecate obsolete system property constant SystemProperties.AWT_TOOLKIT + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_FONTS + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_GRAPHICSENV + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_HEADLESS + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_PRINTERJOB + Deprecate obsolete system property constant SystemProperties.JAVA_COMPILER + Deprecate obsolete system property constant SystemProperties.JAVA_ENDORSED_DIRS + Deprecate obsolete system property constant SystemProperties.JAVA_EXT_DIRS + Deprecate method for obsolete system property constant SystemProperties.getAwtToolkit() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtFonts() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtGraphicsenv() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtHeadless() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtPrinterjob() + Deprecate method for obsolete system property constant SystemProperties.getJavaCompiler() + Deprecate method for obsolete system property constant SystemProperties.getJavaEndorsedDirs() + Deprecate method for obsolete system property constant SystemProperties.getJavaExtDirs() + Deprecate method for obsolete system property constant SystemUtils.isJavaAwtHeadless() + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_FONTS + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_GRAPHICSENV + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_HEADLESS + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_PRINTERJOB + Deprecate constants for obsolete system property SystemUtils.JAVA_COMPILER + Deprecate constants for obsolete system property SystemUtils.JAVA_ENDORSED_DIRS + Deprecate constants for obsolete system property SystemUtils.JAVA_EXT_DIRS + [javadoc] General improvements + [javadoc] Fix thrown exception documentation for MethodUtils.getMethodObject(Class, String, Class...) + [javadoc] Strings::equalsAny: CI doc string should show it's insensitive + [javadoc] General Javadoc improvements + LANG-1780: [javadoc] Fix Strings Javadoc + [javadoc] Fix typo in Javadoc of Strings instances + [javadoc] Fix Javadocs in ClassUtils + [javadoc] Fix @deprecated link for StringUtils#startsWithAny + Replace old feather logotype with new oak logotype * Changes: + [test] Bump org.apache.commons:commons-text from 1.13.1 to 1.14.0 + Bump org.apache.commons:commons-parent from 85 to 88 ++++ apache-commons-logging: - Upgrade to 1.3.6 * Fixed Bugs + Fix running spotbugs:check: Unable to parse configuration of mojo + Update deprecated call in PathableClassLoader.addLogicalLib(String) + Fix malformed Javadoc comments + Fix log level in Slf4jLogFactory.error(Object, Throwable) * Changes + Bump org.apache.commons:commons-parent from 81 to 97 + Bump org.slf4j:slf4j-api from 2.0.16 to 2.0.17 + Bump com.h3xstream.findsecbugs:findsecbugs-plugin from 1.13.0 to 1.14.0 + Bump log4j2.version from 2.24.3 to 2.25.3 + Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0 + Bump ch.qos.logback:logback-core from 1.3.14 to 1.3.16 - Removed patch: * commons-logging-1.3.3-dependencies.patch + not needed (the two files it is removing can be removed from the spec file) ++++ brotli-java: - Update to version 1.2.0 * Added + decoder: BrotliDecoderAttachDictionary + decoder: BrotliDecoderOnFinish callback behind BROTLI_REPORTING + decoder: BrotliDecoderSetMetadataCallbacks + encoder: BrotliEncoderPrepareDictionary, BrotliEncoderDestroyPreparedDictionary, BrotliEncoderAttachPreparedDictionary + decoder: BrotliEncoderOnFinish callback behind BROTLI_REPORTING + decoder / encoder: added static initialization to reduce binary size + common: BrotliSharedDictionaryCreateInstance, BrotliSharedDictionaryDestroyInstance, BrotliSharedDictionaryAttach + java: encoder wrapper: Parameters.mode + java: Brotli{Input|Output}Stream.attachDictionary + java: wrapper: partial byte array input * Removed + java: dropped finalize() for native entities * Fixed + java: JNI decoder failed sometimes on power of 2 payloads + java: in compress pass correct length to native encoder * Improved + java / js: smaller decoder footprint + decoder: faster decoding + encoder: faster encoding + encoder: smaller stack frames * Changed + decoder / encoder: static tables use "small" model (allows 2GiB+ binaries) - Rewrite build system to use ant in order to build this early ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ chromium: - added patches: * disable-ai.patch (do not attempt to download AI code behind the users back) - changed patch ranges, global patches up to 449, ppc patches from 450-599 now ++++ kernel-64kb: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-64kb: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-64kb: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-azure: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-azure: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-azure: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-default: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-default: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-default: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-rt: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-rt: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-rt: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ glibc-cross-aarch64-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-cross-aarch64-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-cross-ppc64le-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-cross-ppc64le-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-cross-riscv64-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-cross-riscv64-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-cross-s390x-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-cross-s390x-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ dtb-aarch64: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ dtb-aarch64: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ dtb-aarch64: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ elemental-toolkit: - Update to v2.3.3: * 8b4af274 Avoid pulling binaries with curl * d46e30f4 Bump golangci/golangci-lint-action to v9 * 02caf200 Bump github.com/spf13/cobra library * e29e1fbf Bump github.com/jaypipes/ghw library * 652654e1 Bump github.com/bramvdbogaerde/go-scp library * f94a0c58 Bump google.golang.org/grpc library (bsc#1260277 CVE-2026-33186) * dc1a2056 Bump github.com/ulikunitz/xz library * 337a986c Update headers to 2026 * d6aac085 Switch from TW to Leap 16.0 for green flavor ++++ exec-maven-plugin: - Upgrade to upstream version 3.6.3 * Documentation updates + Document thread group isolation limitation in java goal * Maintenance + JUnit 5 best practices + Move ExecJavaMojoTest, ExecMojoTest to JUnit 5 + Add support for JEP 512 for for package-private static main method + Move to JUnit 5 * Dependency updates + Bump asm.version from 9.9 to 9.9.1 + Bump org.apache.commons:commons-exec from 1.5.0 to 1.6.0 - Upgrade to upstream version 3.6.2 * New features and improvements + Add JPMS ServiceLoader Support with Multi-Release JAR * Dependency updates + Bump asm.version from 9.8 to 9.9 - Upgrade to upstream version 3.6.1 * Bug Fixes + Revert change from #480 - plugin dependencies must be resolved from plugin repositories * Dependency updates + Bump org.codehaus.mojo:mojo-parent from 93 to 94 - Upgrade to upstream version 3.6.0 * New features and improvements + [ExecMojo]Add getShebang method to correctly set the command line executable name JEP 512 Support * Bug Fixes + fix inheritIo option + Fix for #479 - Wrong repositories used to collect deps * Maintenance + Use JSR-330 for component injection + Re-run failed tests + Restore default matrix build * Dependency updates + Use Maven 3.9.11 in dependencies, still requires 3.6.3 as minimum + Bump org.codehaus.mojo:mojo-parent from 89 to 93 ++++ glibc: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-utils-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ glibc-utils-src: - ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream (CVE-2026-5928, bsc#1262464, BZ #33998) - scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008) ++++ kernel-source: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-source: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-source: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-docs: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-docs: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-docs: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-kvmsmall: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-kvmsmall: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-kvmsmall: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-obs-build: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-obs-build: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-obs-build: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-obs-qa: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-obs-qa: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-obs-qa: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-syms: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-syms: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-syms: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-zfcpdump: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-zfcpdump: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ kernel-zfcpdump: - io_uring/timeout: check unused sqe fields (git-fixes). - commit a4e675d - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - commit 1ee1250 - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use the crc32c() function (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - commit 7b714a9 - wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit (CVE-2026-31579 bsc#1263074). - commit e06a63d - seg6: separate dst_cache for input and output paths in seg6 lwtunnel (CVE-2026-31668 bsc#1263140). - tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (CVE-2026-31662 bsc#1263131). - bridge: br_nd_send: linearize skb before parsing ND options (CVE-2026-31682 bsc#1263595). - iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (CVE-2026-31505 bsc#1263093). - udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503 bsc#1263077). - atm: lec: fix use-after-free in sock_def_readable() (CVE-2026-43050 bsc#1264082). - commit a38bbef - mkspec: Add signature to source list only when it exists - commit e496e84 - nvme-apple: drop invalid put of admin queue reference count (git-fixes). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - commit 045f69b ++++ lcms2: - Fix CVE-2026-41254 (bsc#1264994), integer overflow in CubeSize in cmslut.c * CVE-2026-41254.patch * CVE-2026-41254-2.patch - Fix CVE-2026-42798 (bsc#1263703), integer overflow in ParseCube in cmscgats.c * CVE-2026-42798.patch ++++ canfigger: - canfigger 0.3.2 + Add canfigger_cache_dir(): $XDG_CACHE_HOME/appname or $HOME/.cache/appname on POSIX; %LOCALAPPDATA%\appname on Windows + Add canfigger_config_file(): returns $XDG_CONFIG_HOME/filename or $HOME/.config/filename, for config files that live directly under the config root rather than in a per-application subdirectory * Headers are now installed to /usr/include/canfigger/; the pkgconfig Cflags is updated accordingly so #include continues to work without changes * Only build examples if not a subproject ++++ maven: - There is no need to link the jansi-native library into the tree, since our jansi java library will load it from the system anyway ++++ maven-dependency-tree: - Update to version 3.3.0 * Bug Fixes + MSHARED-1286: Display if dependency is optional in tree * Dependency updates + MSHARED-1400: Bump org.apache.maven.shared :maven-shared-components from 40 to 42 + Bump apache/maven-gh-actions-shared from 3 to 4 + Bump parent from 37 to 39 + Bump apache/maven-gh-actions-shared from 2 to 3 * Maintenance + Bump org.junit.jupiter:junit-jupiter-api from 5.9.3 to 5.10.2 ++++ openssh: - Added openssh-cve-2026-35385-scp-setuid-modes.patch (CVE-2026-35385, bsc#1261427), ensuring setuid bits default to being masked out by scp. - Added openssh-cve-2026-35414-mishandled-ca-commas.patch (CVE-2026-35414, bsc#1261430), fixing mishandling of comma characters in CA in certain situations. - Updated openssh-7.7p1-fips.patch and openssh-8.0p1-gssapi-keyex.patch (bsc#1262555): Don't bail out on startup if a non-FIPS algorithm is requested. Filter it out and warn instead. - Updated openssh-8.1p1-audit.patch (bsc#1252890): Fix race condition in monitor protocol. - Rebased openssh-mitigate-lingering-secrets.patch. ++++ openssh: - Added openssh-cve-2026-35385-scp-setuid-modes.patch (CVE-2026-35385, bsc#1261427), ensuring setuid bits default to being masked out by scp. - Added openssh-cve-2026-35414-mishandled-ca-commas.patch (CVE-2026-35414, bsc#1261430), fixing mishandling of comma characters in CA in certain situations. - Updated openssh-7.7p1-fips.patch and openssh-8.0p1-gssapi-keyex.patch (bsc#1262555): Don't bail out on startup if a non-FIPS algorithm is requested. Filter it out and warn instead. - Updated openssh-8.1p1-audit.patch (bsc#1252890): Fix race condition in monitor protocol. - Rebased openssh-mitigate-lingering-secrets.patch. ++++ perl-CryptX: - updated to 0.89.0 (0.089) see /usr/share/doc/packages/perl-CryptX/Changes 0.089 2026-05-10 - new: Crypt::ASN1 - new: Crypt::AuthEnc::SIV - new: Crypt::AuthEnc::XChaCha20Poly1305 - new: Crypt::Cipher::SM4 - new: Crypt::Digest::TurboSHAKE - new: Crypt::Digest::KangarooTwelve - new: Crypt::PK::Ed448 - new: Crypt::PK::X448 - new: Crypt::Stream::XChaCha - new: Crypt::Stream::XSalsa20 - Crypt::PK::Ed25519 - new functions: sign_message_ctx, verify_message_ctx, sign_message_ph, verify_message_ph - Crypt::Digest: object digest accessors now finalize the object; use reset() before reuse - Crypt::Mac + Crypt::AuthEnc: finalized-object lifecycle is now enforced consistently - security/hardening fixes across Digest/Mac/AuthEnc/Mode/Stream/PK/PRNG - fixes related to wycheproof test suite - documentation cleanup & improvements - support for RFC 8702 RSA-PSS-SHAKE128/256 and ECDSA-SHAKE128/256 - support for FRP256v1 elliptic-curve - bundled libtomcrypt update branch:develop (commit: 8b5af49b 2026-05-06) - CVE-2026-41565 bsc#1266804 0.088 2026-04-23 - Crypt::KeyDerivation - new functions: pbkdf1_openssl, bcrypt_pbkdf, scrypt_pbkdf, argon2_pbkdf - Crypt::Misc - new functions: random_v7uuid, is_uuid - bundled libtomcrypt update branch:develop (commit: 2e441a17 2026-04-15) - bundled libtommath update branch:develop (commit: ae40a87 2026-04-20) - security fix CVE-2026-41564 https://github.com/DCIT/perl-CryptX/security/advisories/GHSA-24c2-gp6c-24c6 bsc#1262697 - CVE-2026-41565 bsc#1266804 ++++ perl-YAML-Syck: - Remove workaround for gcc15 https://github.com/cpan-authors/YAML-Syck/issues/61 Fixed in https://github.com/cpan-authors/YAML-Syck/pull/69 ++++ perl-YAML-Syck: - Remove workaround for gcc15 https://github.com/cpan-authors/YAML-Syck/issues/61 Fixed in https://github.com/cpan-authors/YAML-Syck/pull/69 ++++ plexus-archiver: - Removed patch: * 0001-Remove-support-for-zstd.patch + we now have the dependencies to be able to build the zstd support ++++ python-GitPython: - CVE-2026-42215: Command injection via Git options bypass (bsc#1264604) * added CVE-2026-42215.patch - CVE-2026-42284: Unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605) * added CVE-2026-42284.patch - CVE-2026-44243: Path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository (bsc#1264606) * added CVE-2026-44243.patch - CVE-2026-44244: Newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608) * added CVE-2026-44244.patch ++++ python-PyGithub: - Add upstream patches: * normalize-app-id-to-string.patch, gh#PyGithub/PyGithub#3272, bsc#1263802 * update-test-key-pair.patch, gh#PyGithub/PyGithub#3453 ++++ python-pydata-sphinx-theme: - Refresh vendored tarball (CVE-2026-6321, bsc#1264374) ++++ python-pydata-sphinx-theme: - Refresh vendored tarball (CVE-2026-6321, bsc#1264374) ++++ supportutils-plugin-ha-sap: - Update to version 0.0.9+git.1778500769.8c44b8b * collect XSA information (jsc#PED-16103, jsc#PED-16105, jsc#PED-16104) * fix error for 'saphostexec -status' and adapt change in HANA installation (read /etc/sysctl.d/sap_hdb_sysctl.conf) ++++ xmvn: - Adapt to no libjansi.so linked into the arch independent path ++++ xmvn-tools: - The new commons-compress needs commons-lang3 ++++ zstd-jni: - Update to v1.5.7.8 * no structured changelog provided by upstream - Rewrite the build system to use ant - Update patch: * 00-load-system-library.patch - Remove the flags used for SLE_12_SP5, since we are not building on that version anymore. This simplifies and cleans up the spec file. ++++ zstd-jni: - Update to v1.5.7.8 * no structured changelog provided by upstream - Rewrite the build system to use ant - Update patch: * 00-load-system-library.patch - Remove the flags used for SLE_12_SP5, since we are not building on that version anymore. This simplifies and cleans up the spec file. ------------------------------------------------------------------ ------------------ 2026-5-10 - May 10 2026 ------------------- ------------------------------------------------------------------ ++++ apache-parent: - Update to 38: 👻 * Maintenance + Update banner links * Dependency updates + Bump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.1 + Bump org.apache.maven.plugins:maven-resources-plugin from 3.4.0 to 3.5.0 + Bump org.apache.maven.plugins:maven-shade-plugin from 3.6.1 to 3.6.2 + Bump org.apache.apache.resources :apache-source-release-assembly-descriptor from 1.7 to 1.8 + Bump version.maven-surefire from 3.5.4 to 3.5.5 + Bump org.apache.maven.plugins:maven-dependency-plugin from 3.9.0 to 3.10.0 + Bump org.apache.maven.plugins:maven-compiler-plugin from 3.14.1 to 3.15.0 ++++ go-sendxmpp: - Update to 0.15.6: Added: * New config option allow_plain. Changed: * Explain each configuration option in manpage go-sendxmpp(5). * Improve config parsing robustness. * Update link in manpage as Gitlab calls issues now work items. * Recognize stanza size limit updates after authentication (via go-xmpp >= v0.3.3). * Tell connection target in error message when failing to connect. - Drop tar-scm service and use regular tarball and go_modules ++++ jline3: - Update to upstream version 3.30.13 * Bug Fixes + fix: correct inverted bounds check in readBuffered methods + fix: remove proactive isNativeAccessEnabled() checks from terminal providers + fix: status bar duplication after vertical resize ++++ jline3: - Update to upstream version 3.30.13 * Bug Fixes + fix: correct inverted bounds check in readBuffered methods + fix: remove proactive isNativeAccessEnabled() checks from terminal providers + fix: status bar duplication after vertical resize ++++ jline3: - Update to upstream version 3.30.13 * Bug Fixes + fix: correct inverted bounds check in readBuffered methods + fix: remove proactive isNativeAccessEnabled() checks from terminal providers + fix: status bar duplication after vertical resize ++++ maven-parent: - Upgrade to Apache Maven parent POM version 48 * New features and improvements + Add configuration for rerunning failing integration tests * Bug Fixes + Fix enforce-bytecode-version configuration for ignored scopes * Maintenance + Update banner links + Simplify docs configuration + Remove taglist/jxr/checkstyle/surefire/pmd-reports + Update Maven logos * Dependency updates + Bump org.junit:junit-bom from 5.14.3 to 5.14.4 + Bump com.diffplug.spotless:spotless-maven-plugin from 3.1.0 to 3.4.0 + Bump com.palantir.javaformat:palantir-java-format from 2.83.0 to 2.90.0 + Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3 + Bump org.codehaus.mojo:extra-enforcer-rules from 1.11.0 to 1.12.0 + Bump org.codehaus.modello:modello-maven-plugin from 2.5.1 to 2.6.0 + Bump org.junit:junit-bom from 5.14.2 to 5.14.3 + Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 ------------------------------------------------------------------ ------------------ 2026-5-9 - May 9 2026 ------------------- ------------------------------------------------------------------ ++++ openQA: - Update to version 5.1778257070.d9915684: * docs: show document levels in generated TOC * feat(search): Add link to job in job modules search * feat(test overview): Make "Job result/state" in filter form clickable * test(test overview): Test filtering for "None" * fix(test overview): Bring query for "None" in-line with accounting * feat(test overview): Improve accounting for certain states * feat(test overview): Add distinct counter/button for canceled jobs ++++ openQA: - Update to version 5.1778257070.d9915684: * docs: show document levels in generated TOC * feat(search): Add link to job in job modules search * feat(test overview): Make "Job result/state" in filter form clickable * test(test overview): Test filtering for "None" * fix(test overview): Bring query for "None" in-line with accounting * feat(test overview): Improve accounting for certain states * feat(test overview): Add distinct counter/button for canceled jobs ++++ openQA: - Update to version 5.1778257070.d9915684: * docs: show document levels in generated TOC * feat(search): Add link to job in job modules search * feat(test overview): Make "Job result/state" in filter form clickable * test(test overview): Test filtering for "None" * fix(test overview): Bring query for "None" in-line with accounting * feat(test overview): Improve accounting for certain states * feat(test overview): Add distinct counter/button for canceled jobs ------------------------------------------------------------------ ------------------ 2026-5-8 - May 8 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaThunderbird: - Mozilla Thunderbird 140.10.2 MFSA 2026-44 (bsc#1264378) * CVE-2026-8090 (bmo#2034352) Use-after-free in the DOM: Networking component * CVE-2026-8094 (bmo#2035939) Other issue in the WebRTC component * CVE-2026-8092 (bmo#1806249, bmo#2021977, bmo#2022576, bmo#2022722, bmo#2024439, bmo#2027883, bmo#2029463, bmo#2030323, bmo#2032042, bmo#2032043, bmo#2033270, bmo#2033637, bmo#2034422, bmo#2034496, bmo#2035879, bmo#2036516) Memory safety bugs fixed in Thunderbird ESR 140.10.2 and Thunderbird 150.0.2 ++++ aqute-bnd: - Remove unnecessary dependency on jline ++++ bnd-maven-plugin: - The maven build considers the SOURCE_DATE_EPOCH automatically now ++++ busybox: - Fix heap buffer overflow vulnerability in the DHCPv6 client (CVE-2026-29004, bsc#1263989) * 0001-udhcpc6-fix-buffer-overflow.patch * 0002-udhcpc6-check-the-size-of-D6_OPT_IAPREFIX-option.patch ++++ kernel-64kb: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-64kb: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-64kb: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-64kb: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-64kb: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-64kb: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-azure: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-azure: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-azure: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-azure: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-azure: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-azure: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-default: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-default: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-default: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-default: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-default: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-default: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-rt: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-rt: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-rt: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-rt: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-rt: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-rt: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ dtb-aarch64: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ dtb-aarch64: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ dtb-aarch64: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ dtb-aarch64: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ dtb-aarch64: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ dtb-aarch64: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ glab: - Update to version 1.95.0: * Features - e5b53d65: feat(duo): add --install and --yes flags to duo cli command (Kai Armstrong karmstrong@gitlab.com) - 76d00d65: feat(skills): add glab skills install to install bundled agent skill (experimental) (Thomas Schmidt tschmidt@gitlab.com) * Documentation - d173eac2: docs(issuable): add synopsis to close, note, reopen, subscribe, and unsubscribe (Brendan Lynch blynch@gitlab.com) - de019774: docs(mr): add synopsis to approve, approvers, diff, close, delete, for,... (Brendan Lynch blynch@gitlab.com) - 4fbb1820: docs(mr): add synopsis to list, view, create, checkout, merge, and update (Brendan Lynch blynch@gitlab.com) - 86d43fd9: docs: Add synopsis to CI/CD pipeline and job commands (Brendan Lynch blynch@gitlab.com) - 655b6ca3: docs: add info on deprecation messages (Brendan Lynch blynch@gitlab.com) - 634601b0: docs: add synopsis to experimental subcommands (Brendan Lynch blynch@gitlab.com) - 49d4b88e: docs: add synopsis to fork, opentofu, and auth docker commands (Brendan Lynch blynch@gitlab.com) - a84c20e7: docs: add synopsis to list and view commands (Brendan blynch@gitlab.com) - d225cb5d: docs: add synopsis to set, update, list, and export (Brendan blynch@gitlab.com) - ea774f21: docs: add synopsis to trace, lint, and config compile (Brendan Lynch blynch@gitlab.com) * Dependencies - 6e175217: chore(deps): update module github.com/modelcontextprotocol/go-sdk to v1.6.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) ++++ java-17-openj9: - Update to OpenJDK 17.0.19 with OpenJ9 0.59.0 virtual machine - Including Oracle April 2026 CPU changes * CVE-2026-22007 (bsc#1262490), CVE-2026-22013 (bsc#1262494), CVE-2026-22016 (bsc#1262495), CVE-2026-22018 (bsc#1262496), CVE-2026-22021 (bsc#1262497), CVE-2026-23865 (bsc#1259118), CVE-2026-34268 (bsc#1262500), CVE-2026-34282 (bsc#1262501) - OpenJ9 specific security fix * CVE-2026-1188 (bsc#1265261) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/ ++++ java-21-openj9: - Update to OpenJDK 21.0.11 with OpenJ9 0.59.0 virtual machine - Including Oracle April 2026 CPU changes * CVE-2026-22007 (bsc#1262490), CVE-2026-22013 (bsc#1262494), CVE-2026-22016 (bsc#1262495), CVE-2026-22018 (bsc#1262496), CVE-2026-22021 (bsc#1262497), CVE-2026-23865 (bsc#1259118), CVE-2026-34268 (bsc#1262500), CVE-2026-34282 (bsc#1262501) - OpenJ9 specific security fix * CVE-2026-1188 (bsc#1265261) * OpenJ9 changes, see https://www.eclipse.org/openj9/docs/version0.59/ ++++ kernel-source: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-source: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-source: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-source: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-source: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-source: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-docs: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-docs: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-docs: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-docs: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-docs: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-docs: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-kvmsmall: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-kvmsmall: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-kvmsmall: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-kvmsmall: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-kvmsmall: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-kvmsmall: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-obs-build: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-obs-build: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-obs-build: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-obs-build: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-obs-build: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-obs-build: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-obs-qa: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-obs-qa: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-obs-qa: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-obs-qa: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-obs-qa: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-obs-qa: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-syms: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-syms: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-syms: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-syms: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-syms: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-syms: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-zfcpdump: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-zfcpdump: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-zfcpdump: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 ++++ kernel-zfcpdump: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-zfcpdump: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ kernel-zfcpdump: - Update config files: disable unsupported CONFIG_AFS_FS and CONFIG_AF_RXRPC - commit a035dd7 - net: lan966x: fix use-after-free and leak in lan966x_fdma_reload() (CVE-2026-31644 bsc#1263048). - net: macb: use the current queue number for stats (CVE-2026-31494 bsc#1262671). - net: cadence: macb: Synchronize stats calculations (CVE-2026-31494 bsc#1262671). - commit decc1b9 ++++ mcphost: - Updated to version 0.34.0 * Features: - Upgrade charmbracelet libs to v2 (bubbletea, lipgloss, bubbles) - Add Google Vertex AI support for Claude models - Add new models. * Fixes: - Eliminate escape sequence leak from spinner tea.Program instances. - Fix anthropic api issue. - Convert JSON Schema draft-07 exclusive bounds to draft-04 format. * Upgrade all dependencies to latest versions, resolve security issues and to obtain Go 1.26 compatibility. This addresses CVE-2025-30153 GO-2025-3533 (bsc#1264762). - Fixed CVEs: * CVE-2026-33186 GO-2026-4762 (bsc#1260224) * CVE-2026-32285 GO-2026-4514 (bsc#1264759) ++++ mcphost: - Updated to version 0.34.0 * Features: - Upgrade charmbracelet libs to v2 (bubbletea, lipgloss, bubbles) - Add Google Vertex AI support for Claude models - Add new models. * Fixes: - Eliminate escape sequence leak from spinner tea.Program instances. - Fix anthropic api issue. - Convert JSON Schema draft-07 exclusive bounds to draft-04 format. * Upgrade all dependencies to latest versions, resolve security issues and to obtain Go 1.26 compatibility. This addresses CVE-2025-30153 GO-2025-3533 (bsc#1264762). - Fixed CVEs: * CVE-2026-33186 GO-2026-4762 (bsc#1260224) * CVE-2026-32285 GO-2026-4514 (bsc#1264759) ++++ modello: - Upgrade to upstream version 2.7.0 * New features and improvements + XDOC: document required fields in generated model docs * Bug Fixes + Refactor PLURAL_EXCEPTIONS to use ThreadLocal for thread safety + Initialize model parameters in VelocityGenerator + Use correct getter method prefix for type "Boolean" * Dependency updates + Bump org.codehaus.plexus:plexus-utils from 3.0.24 to 3.6.1 in /modello-maven-plugin/src/it/maven-model + Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3 + Bump org.codehaus.woodstox:stax2-api from 4.2.2 to 4.3.0 + Bump com.fasterxml.jackson:jackson-bom from 2.21.0 to 2.21.2 + Bump org.yaml:snakeyaml from 2.5 to 2.6 + Bump org.apache.maven.plugins:maven-shade-plugin from 3.6.1 to 3.6.2 + Bump sisu.version from 0.9.0.M4 to 1.0.0 + Bump plexus.compiler.version from 2.16.1 to 2.16.2 ++++ modello-maven-plugin: - Upgrade to upstream version 2.7.0 * New features and improvements + XDOC: document required fields in generated model docs * Bug Fixes + Refactor PLURAL_EXCEPTIONS to use ThreadLocal for thread safety + Initialize model parameters in VelocityGenerator + Use correct getter method prefix for type "Boolean" * Dependency updates + Bump org.codehaus.plexus:plexus-utils from 3.0.24 to 3.6.1 in /modello-maven-plugin/src/it/maven-model + Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3 + Bump org.codehaus.woodstox:stax2-api from 4.2.2 to 4.3.0 + Bump com.fasterxml.jackson:jackson-bom from 2.21.0 to 2.21.2 + Bump org.yaml:snakeyaml from 2.5 to 2.6 + Bump org.apache.maven.plugins:maven-shade-plugin from 3.6.1 to 3.6.2 + Bump sisu.version from 0.9.0.M4 to 1.0.0 + Bump plexus.compiler.version from 2.16.1 to 2.16.2 ++++ openQA: - Update to version 5.1778239460.4b750ff3: * feat(search): Add job id to search results response ++++ openQA: - Update to version 5.1778239460.4b750ff3: * feat(search): Add job id to search results response ++++ openQA: - Update to version 5.1778239460.4b750ff3: * feat(search): Add job id to search results response ++++ os-autoinst: - Update to version 5.1778246511.7a6bac3: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years ++++ os-autoinst: - Update to version 5.1778246511.7a6bac3: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years ++++ os-autoinst: - Update to version 5.1778246511.7a6bac3: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years ++++ picocli: - Update to version 4.7.7 * Enhancements: + picocli.shell.jline3.PicocliCommands::invoke now returns ParseResult instead of null + Avoid syntax error in auto-completion script for invalid option names and paramLabel values starting with a digit + Variable interpolation should work for ArgGroup.heading attribute * Bug fixes: + The built-in help subcommand should return the exit code of the subcommand's exitCodeOnUsageHelp value for the subcommand whose help was requested + Module info missing in all jars except the main picocli jar file + AutoComplete with jline3 was showing hidden commands + NullPointerException when using PropertiesDefaultProvider + negatable=true option in an ArgGroup should not add negated option twice + Duplicate help output for ArgGroup from a Mixin + Options get doubled in non validating ArgGroup when used in Mixin + Incorrect results when using ArgGroup + defaultValue + split + List/Set + DuplicateOptionAnnotationsException on using negatable option in ArgGroup + boolean with arity=0 and defaultValue=false behaved unexpectedly * Documentation fixes: + User guide, CDI 2.0 (JSR 365) section: fix example and add warning about dynamic proxies + Fix line-endings in generated asciidoc HTML + Fix broken link + Add at least a link to how to use the CodeGen APT under Bazel ++++ plexus-interactivity: - Removed patch: * plexus-interactivity-jline2.patch + Build against the jline3's jline-reader as the upstream does ++++ selinux-policy: - Update to version 20250627+git368.7e5f975a1: * Add boolean ntp_refclock_access (bsc#1262711) * Add /var/log/ntp in ntp named filetrans interface (bsc#1262711) * Allow cloud init to domtrans into ssh keygen (bsc#1249964) ++++ selinux-policy: - Update to version 20250627+git368.7e5f975a1: * Add boolean ntp_refclock_access (bsc#1262711) * Add /var/log/ntp in ntp named filetrans interface (bsc#1262711) * Allow cloud init to domtrans into ssh keygen (bsc#1249964) ++++ tor: - Update to 0.4.9.8 * Fix out-of-bounds read (boo#1264341, CVE-2026-44597, TROVE-2026-011) * Do not attempt or accept BEGIN_DIR via conflux legs (boo#1264342, CVE-2026-44599,TROVE-2026-008) * Adjust conflux out-of-order queue accounting when clearing a queue (boo#1264343, CVE-2026-44600, TROVE-2026-010) * Fix a client-side crash caused by double-close of a circuit while under circuit queue memory pressure (boo#1264344, CVE-2026-44601, TROVE-2026-009) * Fix null pointer dereference when receiving a CERT cell out of order (boo#1264345, CVE-2026-44602, TROVE-2026-006) * Fix off-by-one out-of-bounds read if a malformed BEGIN cell is received (boo#1264346, CVE-2026-44603, TROVE-2026-007) ++++ tor: - Update to 0.4.9.8 * Fix out-of-bounds read (boo#1264341, CVE-2026-44597, TROVE-2026-011) * Do not attempt or accept BEGIN_DIR via conflux legs (boo#1264342, CVE-2026-44599,TROVE-2026-008) * Adjust conflux out-of-order queue accounting when clearing a queue (boo#1264343, CVE-2026-44600, TROVE-2026-010) * Fix a client-side crash caused by double-close of a circuit while under circuit queue memory pressure (boo#1264344, CVE-2026-44601, TROVE-2026-009) * Fix null pointer dereference when receiving a CERT cell out of order (boo#1264345, CVE-2026-44602, TROVE-2026-006) * Fix off-by-one out-of-bounds read if a malformed BEGIN cell is received (boo#1264346, CVE-2026-44603, TROVE-2026-007) ------------------------------------------------------------------ ------------------ 2026-5-7 - May 7 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.2 ESR * Fixed: Various security fixes. MFSA 2026-41 (bsc#1264378) * CVE-2026-8090 (bmo#2034352) Use-after-free in the DOM: Networking component * CVE-2026-8091 (bmo#2029301) Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-8094 (bmo#2035939) Other issue in the WebRTC component * CVE-2026-8092 (bmo#1806249, bmo#2021977, bmo#2022576, bmo#2022722, bmo#2024439, bmo#2027883, bmo#2029463, bmo#2030323, bmo#2032042, bmo#2032043, bmo#2033270, bmo#2033637, bmo#2034422, bmo#2034496, bmo#2035879, bmo#2036516) Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.2 ESR * Fixed: Various security fixes. MFSA 2026-41 (bsc#1264378) * CVE-2026-8090 (bmo#2034352) Use-after-free in the DOM: Networking component * CVE-2026-8091 (bmo#2029301) Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-8094 (bmo#2035939) Other issue in the WebRTC component * CVE-2026-8092 (bmo#1806249, bmo#2021977, bmo#2022576, bmo#2022722, bmo#2024439, bmo#2027883, bmo#2029463, bmo#2030323, bmo#2032042, bmo#2032043, bmo#2033270, bmo#2033637, bmo#2034422, bmo#2034496, bmo#2035879, bmo#2036516) Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.2 ESR * Fixed: Various security fixes. MFSA 2026-41 (bsc#1264378) * CVE-2026-8090 (bmo#2034352) Use-after-free in the DOM: Networking component * CVE-2026-8091 (bmo#2029301) Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-8094 (bmo#2035939) Other issue in the WebRTC component * CVE-2026-8092 (bmo#1806249, bmo#2021977, bmo#2022576, bmo#2022722, bmo#2024439, bmo#2027883, bmo#2029463, bmo#2030323, bmo#2032042, bmo#2032043, bmo#2033270, bmo#2033637, bmo#2034422, bmo#2034496, bmo#2035879, bmo#2036516) Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.2 ESR * Fixed: Various security fixes. MFSA 2026-41 (bsc#1264378) * CVE-2026-8090 (bmo#2034352) Use-after-free in the DOM: Networking component * CVE-2026-8091 (bmo#2029301) Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-8094 (bmo#2035939) Other issue in the WebRTC component * CVE-2026-8092 (bmo#1806249, bmo#2021977, bmo#2022576, bmo#2022722, bmo#2024439, bmo#2027883, bmo#2029463, bmo#2030323, bmo#2032042, bmo#2032043, bmo#2033270, bmo#2033637, bmo#2034422, bmo#2034496, bmo#2035879, bmo#2036516) Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2 ++++ kernel-64kb: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-64kb: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-64kb: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-64kb: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-64kb: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-64kb: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-azure: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-azure: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-azure: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-azure: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-azure: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-azure: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-default: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-default: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-default: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-default: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-default: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-default: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-rt: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-rt: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-rt: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-rt: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-rt: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-rt: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ dtb-aarch64: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ dtb-aarch64: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ dtb-aarch64: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ dtb-aarch64: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ dtb-aarch64: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ dtb-aarch64: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ go1.25: - go1.25.10 (released 2026-05-07) includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages. Refs boo#1244485 go1.25 release tracking CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 * go#78812 go#78803 boo#1264508 security: fix CVE-2026-33811 net: crash when handling long CNAME response * go#78477 go#78476 boo#1264506 security: fix CVE-2026-33814 net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE * go#78790 go#78778 boo#1264505 security: fix CVE-2026-39817 cmd/go: "go tool pack" does not sanitize output paths * go#78587 go#78584 boo#1264504 security: fix CVE-2026-39819 cmd/go: "go bug" follows symlinks in predictable temporary filenames * go#78567 go#78566 boo#1264503 security: fix CVE-2026-39820 net/mail: quadratic string concatentation in consumeComment * go#79031 go#78913 boo#1264509 security: fix CVE-2026-39823 html/template: bypass of meta content URL escaping causes XSS * go#78985 go#78948 boo#1264500 security: fix CVE-2026-39825 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79024 go#78981 boo#1264507 security: fix CVE-2026-39826 html/template: escaper bypass leads to XSS * go#79028 go#79006 boo#1264501 security: fix CVE-2026-39836 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79003 go#78987 boo#1264502 security: fix CVE-2026-42499 net/mail: quadratic string concatenation in consumePhrase * go#79072 go#79070 boo#1264499 security: fix CVE-2026-42501 cmd/go: malicious module proxy can bypass checksum database * go#77298 cmd/compile: go1.22+ cmd with go.mod 1.21 generates per-loop variable when using line directive * go#78374 cmd/compile: incorrect loop trip count * go#78405 cmd/link: stop requiring gold on arm64 when GNU ld is fixed * go#78411 cmd/go: test -cover can't find covdata tool with switched toolchain and empty tests * go#78510 cmd/cgo/internal/testsanitizers: TestLSAN/lsan1,2, and 3 always fail on linux with glibc 2.42 * go#78581 cmd/compile: panic on invalid generic append with type parameter spread * go#78582 cmd/go: test cache uses stale coverage data with -coverpkg * go#78675 cmd/compile: ice expecting positive value on loop iterating by math.MinInt64 (regression) * go#78866 os: RemoveAll can leak internal errSymlink as a user-visible PathError on Unix * go#78983 lib/fips140: update certified and inprocess aliases * go#79020 crypto/fips140: missing package comment - Packaging improvements: * Drop dont-force-gold-on-arm64.patch as upstream no longer forces gold on arm64 Fixes boo#1170826 ++++ go1.25: - go1.25.10 (released 2026-05-07) includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the compiler, the linker, the runtime, and the crypto/fips140, go/types, and os packages. Refs boo#1244485 go1.25 release tracking CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 * go#78812 go#78803 boo#1264508 security: fix CVE-2026-33811 net: crash when handling long CNAME response * go#78477 go#78476 boo#1264506 security: fix CVE-2026-33814 net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE * go#78790 go#78778 boo#1264505 security: fix CVE-2026-39817 cmd/go: "go tool pack" does not sanitize output paths * go#78587 go#78584 boo#1264504 security: fix CVE-2026-39819 cmd/go: "go bug" follows symlinks in predictable temporary filenames * go#78567 go#78566 boo#1264503 security: fix CVE-2026-39820 net/mail: quadratic string concatentation in consumeComment * go#79031 go#78913 boo#1264509 security: fix CVE-2026-39823 html/template: bypass of meta content URL escaping causes XSS * go#78985 go#78948 boo#1264500 security: fix CVE-2026-39825 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79024 go#78981 boo#1264507 security: fix CVE-2026-39826 html/template: escaper bypass leads to XSS * go#79028 go#79006 boo#1264501 security: fix CVE-2026-39836 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79003 go#78987 boo#1264502 security: fix CVE-2026-42499 net/mail: quadratic string concatenation in consumePhrase * go#79072 go#79070 boo#1264499 security: fix CVE-2026-42501 cmd/go: malicious module proxy can bypass checksum database * go#77298 cmd/compile: go1.22+ cmd with go.mod 1.21 generates per-loop variable when using line directive * go#78374 cmd/compile: incorrect loop trip count * go#78405 cmd/link: stop requiring gold on arm64 when GNU ld is fixed * go#78411 cmd/go: test -cover can't find covdata tool with switched toolchain and empty tests * go#78510 cmd/cgo/internal/testsanitizers: TestLSAN/lsan1,2, and 3 always fail on linux with glibc 2.42 * go#78581 cmd/compile: panic on invalid generic append with type parameter spread * go#78582 cmd/go: test cache uses stale coverage data with -coverpkg * go#78675 cmd/compile: ice expecting positive value on loop iterating by math.MinInt64 (regression) * go#78866 os: RemoveAll can leak internal errSymlink as a user-visible PathError on Unix * go#78983 lib/fips140: update certified and inprocess aliases * go#79020 crypto/fips140: missing package comment - Packaging improvements: * Drop dont-force-gold-on-arm64.patch as upstream no longer forces gold on arm64 Fixes boo#1170826 ++++ go1.26: - go1.26.3 (released 2026-05-07) includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the crypto/fips140, crypto/tls, go/types, and os packages. Refs boo#1255111 go1.26 release tracking CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 * go#78813 go#78803 boo#1264508 security: fix CVE-2026-33811 net: crash when handling long CNAME response * go#78478 go#78476 boo#1264506 security: fix CVE-2026-33814 net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE * go#78791 go#78778 boo#1264505 security: fix CVE-2026-39817 cmd/go: "go tool pack" does not sanitize output paths * go#78588 go#78584 boo#1264504 security: fix CVE-2026-39819 cmd/go: "go bug" follows symlinks in predictable temporary filenames * go#78568 go#78566 boo#1264503 security: fix CVE-2026-39820 net/mail: quadratic string concatentation in consumeComment * go#79032 go#78913 boo#1264509 security: fix CVE-2026-39823 html/template: bypass of meta content URL escaping causes XSS * go#78986 go#78948 boo#1264500 security: fix CVE-2026-39825 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79025 go#78981 boo#1264507 security: fix CVE-2026-39826 html/template: escaper bypass leads to XSS * go#79029 go#79006 boo#1264501 security: fix CVE-2026-39836 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79004 go#78987 boo#1264502 security: fix CVE-2026-42499 net/mail: quadratic string concatenation in consumePhrase * go#79073 go#79070 boo#1264499 security: fix CVE-2026-42501 cmd/go: malicious module proxy can bypass checksum database * go#77297 cmd/compile: go1.22+ cmd with go.mod 1.21 generates per-loop variable when using line directive * go#77801 cmd/fix: change -diff to exit 1 if diffs exist * go#77931 runtime: regression Synology's Linux fork of linux causes syscall conflict on older kernel versions * go#77935 runtime: on 32bits arches timespec (64) definition is wrong * go#78155 testing: within a B.Loop loop, assigning function result to _ allows body to be optimized away (1.26 regression) * go#78198 cmd/compile: panic on invalid generic append with type parameter spread * go#78354 crypto/internal/fips140/drbg: unnecessary linear memory increase on Wasm with Go 1.26 * go#78372 crypto/tls: X25519MLKEM768 listed in allowedCurvePreferencesFIPS but always fails under GODEBUG=fips140=only * go#78375 cmd/compile: incorrect loop trip count * go#78406 cmd/link: stop requiring gold on arm64 when GNU ld is fixed * go#78409 cmd/compile: devirtualization causes incorrect runtime panic on promoted method of value-embedded generic struct * go#78412 cmd/go: test -cover can't find covdata tool with switched toolchain and empty tests * go#78511 cmd/cgo/internal/testsanitizers: TestLSAN/lsan1,2, and 3 always fail on linux with glibc 2.42 * go#78583 cmd/go: test cache uses stale coverage data with -coverpkg * go#78676 cmd/compile: ice expecting positive value on loop iterating by math.MinInt64 (regression) * go#78867 os: RemoveAll can leak internal errSymlink as a user-visible PathError on Unix * go#78984 lib/fips140: update certified and inprocess aliases * go#79021 crypto/fips140: missing package comment - Packaging improvements: * Drop dont-force-gold-on-arm64.patch as upstream no longer forces gold on arm64 Fixes boo#1170826 ++++ go1.26: - go1.26.3 (released 2026-05-07) includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the crypto/fips140, crypto/tls, go/types, and os packages. Refs boo#1255111 go1.26 release tracking CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 * go#78813 go#78803 boo#1264508 security: fix CVE-2026-33811 net: crash when handling long CNAME response * go#78478 go#78476 boo#1264506 security: fix CVE-2026-33814 net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE * go#78791 go#78778 boo#1264505 security: fix CVE-2026-39817 cmd/go: "go tool pack" does not sanitize output paths * go#78588 go#78584 boo#1264504 security: fix CVE-2026-39819 cmd/go: "go bug" follows symlinks in predictable temporary filenames * go#78568 go#78566 boo#1264503 security: fix CVE-2026-39820 net/mail: quadratic string concatentation in consumeComment * go#79032 go#78913 boo#1264509 security: fix CVE-2026-39823 html/template: bypass of meta content URL escaping causes XSS * go#78986 go#78948 boo#1264500 security: fix CVE-2026-39825 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79025 go#78981 boo#1264507 security: fix CVE-2026-39826 html/template: escaper bypass leads to XSS * go#79029 go#79006 boo#1264501 security: fix CVE-2026-39836 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79004 go#78987 boo#1264502 security: fix CVE-2026-42499 net/mail: quadratic string concatenation in consumePhrase * go#79073 go#79070 boo#1264499 security: fix CVE-2026-42501 cmd/go: malicious module proxy can bypass checksum database * go#77297 cmd/compile: go1.22+ cmd with go.mod 1.21 generates per-loop variable when using line directive * go#77801 cmd/fix: change -diff to exit 1 if diffs exist * go#77931 runtime: regression Synology's Linux fork of linux causes syscall conflict on older kernel versions * go#77935 runtime: on 32bits arches timespec (64) definition is wrong * go#78155 testing: within a B.Loop loop, assigning function result to _ allows body to be optimized away (1.26 regression) * go#78198 cmd/compile: panic on invalid generic append with type parameter spread * go#78354 crypto/internal/fips140/drbg: unnecessary linear memory increase on Wasm with Go 1.26 * go#78372 crypto/tls: X25519MLKEM768 listed in allowedCurvePreferencesFIPS but always fails under GODEBUG=fips140=only * go#78375 cmd/compile: incorrect loop trip count * go#78406 cmd/link: stop requiring gold on arm64 when GNU ld is fixed * go#78409 cmd/compile: devirtualization causes incorrect runtime panic on promoted method of value-embedded generic struct * go#78412 cmd/go: test -cover can't find covdata tool with switched toolchain and empty tests * go#78511 cmd/cgo/internal/testsanitizers: TestLSAN/lsan1,2, and 3 always fail on linux with glibc 2.42 * go#78583 cmd/go: test cache uses stale coverage data with -coverpkg * go#78676 cmd/compile: ice expecting positive value on loop iterating by math.MinInt64 (regression) * go#78867 os: RemoveAll can leak internal errSymlink as a user-visible PathError on Unix * go#78984 lib/fips140: update certified and inprocess aliases * go#79021 crypto/fips140: missing package comment - Packaging improvements: * Drop dont-force-gold-on-arm64.patch as upstream no longer forces gold on arm64 Fixes boo#1170826 ++++ go1.26-openssl: - Update to version 1.26.3 cut from the go1.25-fips-release branch at the revision tagged go1.26.3-1-openssl-fips. Refs jsc#SLE-18320 * Rebase to 1.26.3 * Improve performance in HKDF Expand-Label - go1.26.3 (released 2026-05-07) includes security fixes to the go command, the pack tool, and the html/template, net, net/http, net/http/httputil, net/mail, and syscall packages, as well as bug fixes to the go command, the go fix command, the compiler, the linker, the runtime, and the crypto/fips140, crypto/tls, go/types, and os packages. Refs boo#1255111 go1.26 release tracking CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 * go#78813 go#78803 boo#1264508 security: fix CVE-2026-33811 net: crash when handling long CNAME response * go#78478 go#78476 boo#1264506 security: fix CVE-2026-33814 net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE * go#78791 go#78778 boo#1264505 security: fix CVE-2026-39817 cmd/go: "go tool pack" does not sanitize output paths * go#78588 go#78584 boo#1264504 security: fix CVE-2026-39819 cmd/go: "go bug" follows symlinks in predictable temporary filenames * go#78568 go#78566 boo#1264503 security: fix CVE-2026-39820 net/mail: quadratic string concatentation in consumeComment * go#79032 go#78913 boo#1264509 security: fix CVE-2026-39823 html/template: bypass of meta content URL escaping causes XSS * go#78986 go#78948 boo#1264500 security: fix CVE-2026-39825 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79025 go#78981 boo#1264507 security: fix CVE-2026-39826 html/template: escaper bypass leads to XSS * go#79029 go#79006 boo#1264501 security: fix CVE-2026-39836 net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters * go#79004 go#78987 boo#1264502 security: fix CVE-2026-42499 net/mail: quadratic string concatenation in consumePhrase * go#79073 go#79070 boo#1264499 security: fix CVE-2026-42501 cmd/go: malicious module proxy can bypass checksum database * go#77297 cmd/compile: go1.22+ cmd with go.mod 1.21 generates per-loop variable when using line directive * go#77801 cmd/fix: change -diff to exit 1 if diffs exist * go#77931 runtime: regression Synology's Linux fork of linux causes syscall conflict on older kernel versions * go#77935 runtime: on 32bits arches timespec (64) definition is wrong * go#78155 testing: within a B.Loop loop, assigning function result to _ allows body to be optimized away (1.26 regression) * go#78198 cmd/compile: panic on invalid generic append with type parameter spread * go#78354 crypto/internal/fips140/drbg: unnecessary linear memory increase on Wasm with Go 1.26 * go#78372 crypto/tls: X25519MLKEM768 listed in allowedCurvePreferencesFIPS but always fails under GODEBUG=fips140=only * go#78375 cmd/compile: incorrect loop trip count * go#78406 cmd/link: stop requiring gold on arm64 when GNU ld is fixed * go#78409 cmd/compile: devirtualization causes incorrect runtime panic on promoted method of value-embedded generic struct * go#78412 cmd/go: test -cover can't find covdata tool with switched toolchain and empty tests * go#78511 cmd/cgo/internal/testsanitizers: TestLSAN/lsan1,2, and 3 always fail on linux with glibc 2.42 * go#78583 cmd/go: test cache uses stale coverage data with -coverpkg * go#78676 cmd/compile: ice expecting positive value on loop iterating by math.MinInt64 (regression) * go#78867 os: RemoveAll can leak internal errSymlink as a user-visible PathError on Unix * go#78984 lib/fips140: update certified and inprocess aliases * go#79021 crypto/fips140: missing package comment - Packaging improvements: * Drop dont-force-gold-on-arm64.patch as upstream no longer forces gold on arm64 Fixes boo#1170826 ++++ iproute2: - add DPLL support (bsc#1255752 jsc#PED-14083) * patches/dpll-Add-dpll-command.patch * patches/dpll-Fix-missing-notifications-in-monitor-mode.patch * patches/dpll-Send-object-per-event-in-JSON-monitor-mode.patch * patches/dpll-add-client-side-filtering-for-device-show.patch * patches/dpll-add-client-side-filtering-for-pin-show.patch * patches/dpll-add-direction-and-state-filtering-for-pin-show.patch * patches/dpll-add-mode-setting-support.patch * patches/dpll-add-pin-filtering-by-parent-device-and-parent-p.patch * patches/dpll-add-support-for-fractional-frequency-offset-in-.patch * patches/dpll-fix-pin-id-get-type-filter-parsing.patch * patches/lib-Add-str_to_bool-helper-function.patch * patches/lib-Move-mnlg-to-lib-for-shared-use.patch * patches/sync-UAPI-header-copies-with-SL-16.0.patch - refresh * patches/ss-escape-characters-in-command-name.patch ++++ kernel-source: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-source: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-source: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-source: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-source: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-source: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-docs: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-docs: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-docs: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-docs: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-docs: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-docs: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-kvmsmall: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-kvmsmall: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-kvmsmall: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-kvmsmall: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-kvmsmall: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-kvmsmall: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-obs-build: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-obs-build: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-obs-build: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-obs-build: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-obs-build: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-obs-build: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-obs-qa: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-obs-qa: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-obs-qa: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-obs-qa: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-obs-qa: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-obs-qa: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-syms: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-syms: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-syms: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-syms: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-syms: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-syms: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-zfcpdump: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-zfcpdump: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-zfcpdump: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe ++++ kernel-zfcpdump: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-zfcpdump: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ kernel-zfcpdump: - supported.conf: drop rxrpc completely (bsc#1264450) - commit 2dc3b0f - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). - commit afc97fe - drm/xe: Fix missing runtime PM reference in ccs_mode_store (CVE-2026-31547 bsc#1263018). - commit fed53ff - fuse: reject oversized dirents in page cache (CVE-2026-31694 bsc#1263901). - commit 0f4f926 - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - commit 7ce1887 ++++ libsndfile: - Fix IMA-ADPCM integer overflow (bsc#1263695, CVE-2026-37555): libsndfile-CVE-2026-37555.patch - Fix buffer overflow in the ircam_read_header function (bsc#1248458, CVE-2025-52194): libsndfile-CVE-2025-52194.patch ++++ libsndfile-progs: - Fix IMA-ADPCM integer overflow (bsc#1263695, CVE-2026-37555): libsndfile-CVE-2026-37555.patch - Fix buffer overflow in the ircam_read_header function (bsc#1248458, CVE-2025-52194): libsndfile-CVE-2025-52194.patch ++++ openQA: - Update to version 5.1778134320.e889287c: * test: simplify postgres healthcheck in docker-compose * fix: correctly handle MOJO_CLIENT_DEBUG in Helm chart * test: add yamale and yamllint to test_helm_chart dependencies * test: fail early in test_helm_chart if dependencies are missing * test: use isolated environment for helm chart tests * test: serialize helm chart test execution * refactor: Remove superfluous line in script usage * style: Enforce perlcritic policy Subroutines::RequireArgUnpacking * fix: ktap: ignore selftest status comments * fix(apparmor): allow write to /dev/tty necessary for Leap 16 * chore(spec): Exclude devel sub package from builds for Leap < 16 * ci: Ensure all required dependencies are part of the devel container * fix(apparmor): allow further paths for 16.x ++++ openQA: - Update to version 5.1778134320.e889287c: * test: simplify postgres healthcheck in docker-compose * fix: correctly handle MOJO_CLIENT_DEBUG in Helm chart * test: add yamale and yamllint to test_helm_chart dependencies * test: fail early in test_helm_chart if dependencies are missing * test: use isolated environment for helm chart tests * test: serialize helm chart test execution * refactor: Remove superfluous line in script usage * style: Enforce perlcritic policy Subroutines::RequireArgUnpacking * fix: ktap: ignore selftest status comments * fix(apparmor): allow write to /dev/tty necessary for Leap 16 * chore(spec): Exclude devel sub package from builds for Leap < 16 * ci: Ensure all required dependencies are part of the devel container * fix(apparmor): allow further paths for 16.x ++++ openQA: - Update to version 5.1778134320.e889287c: * test: simplify postgres healthcheck in docker-compose * fix: correctly handle MOJO_CLIENT_DEBUG in Helm chart * test: add yamale and yamllint to test_helm_chart dependencies * test: fail early in test_helm_chart if dependencies are missing * test: use isolated environment for helm chart tests * test: serialize helm chart test execution * refactor: Remove superfluous line in script usage * style: Enforce perlcritic policy Subroutines::RequireArgUnpacking * fix: ktap: ignore selftest status comments * fix(apparmor): allow write to /dev/tty necessary for Leap 16 * chore(spec): Exclude devel sub package from builds for Leap < 16 * ci: Ensure all required dependencies are part of the devel container * fix(apparmor): allow further paths for 16.x ++++ rsync: - Security update (CVE-2026-41035, bsc#1262223): rsync: count of entries mismatch can lead to a use-after-free - Add rsync-CVE-2026-41035.patch ++++ rsync: - Security update (CVE-2026-41035, bsc#1262223): rsync: count of entries mismatch can lead to a use-after-free - Add rsync-CVE-2026-41035.patch ++++ rsync: - Security update (CVE-2026-41035, bsc#1262223): rsync: count of entries mismatch can lead to a use-after-free - Add rsync-CVE-2026-41035.patch ------------------------------------------------------------------ ------------------ 2026-5-6 - May 6 2026 ------------------- ------------------------------------------------------------------ ++++ agama: - Update "time" crate to prevent CVE-2026-25727 (bsc#1257930). ++++ agama: - Update "time" crate to prevent CVE-2026-25727 (bsc#1257930). ++++ agama: - Update "time" crate to prevent CVE-2026-25727 (bsc#1257930). ++++ alloy: - Update to version 1.16.1 * Bug Fixes logging: Fix startup deadlock when components log before logging config is evaluated Update to Beyla 3.9.8 Migrate from Docker to Moby - CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263530) * Add 0002-Bump-Apache-Thrift.patch ++++ alloy: - Update to version 1.16.1 * Bug Fixes logging: Fix startup deadlock when components log before logging config is evaluated Update to Beyla 3.9.8 Migrate from Docker to Moby - CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263530) * Add 0002-Bump-Apache-Thrift.patch ++++ apache-commons-codec: - Update to 1.22.0 * New features + CODEC-326: Add Base58 support + Add BaseNCodecInputStream.AbstracBuilder.setByteArray(byte[]) + CODEC-335: Add GitIdentifiers to compute Git blob and tree object identifiers * Fixed Bugs + CODEC-249: Fix Incorrect transform of CH digraph according Metaphone basic rules #423 + CODEC-317: ColognePhonetic can create duplicate consecutive codes in some cases + Add boundary tests for BinaryCodec.fromAscii partial-bit inputs #425 + CODEC-336: Base64.Builder.setUrlSafe(boolean) Javadoc incorrectly states null is accepted for primitive boolean parameter * Changes + Bump org.apache.commons:commons-parent from 96 to 98 ++++ apache-commons-io: - Upgrade to 2.22.0 * New features + Add and use IOUtils.closeQuietlySuppress(Closeable, Throwable) + Add ProxyWriter.setReference(Writer) + Add ProxyWriter.unwrap() + Add ProxyReader.setReference(Reader) +Add ProxyReader.unrwap() + IO-883: ByteArraySeekableByteChannel should optionally configure a read-only channel + IO-883: Add ByteArraySeekableByteChannel.Builder and builder() + IO-883: Add AbstractStreamBuilder.getByteArray() + CloseShieldInputStream now supports a custom close shield as a function + Add FlushShieldOutputStream to workaround issues in generic code that ends up calling third parties like like org.tukaani.xz.LZMAOutputStream.flush() + Add filter channels * Fixed Bugs + Fix Apache RAT plugin console warnings + ByteArraySeekableByteChannel.position(long) and truncate(long) shouldn't throw an IllegalArgumentException for a new positive position that's too large + Fix malformed Javadoc comments + ReadAheadInputStream.close() doesn't always close its filtered input stream + ReadAheadInputStream now restores the current thread's interrupt flag when catching InterruptedException + FileAlterationMonitor.stop(long) now restores the current thread's interrupt flag when catching InterruptedException + FileCleaningTracker now restores the current thread's interrupt flag when catching InterruptedException + ThreadMonitor.run() now restores the current thread's interrupt flag when catching InterruptedException + ThrottledInputStream.throttle() now restores the current thread's interrupt flag when catching InterruptedException + ThrottledInputStream.throttle() doesn't preserve the original InterruptedException as the cause of its InterruptedIOException + All thread names are now prefixed with "commons-io-" + IO-639: ReversedLinesFileReader does not read first line if its empty + IO-886: Fixed incorrect regular expression in PathUtils.RelativeSortedPaths.extractKey(String, String) + Fix typos in Javadoc of FileUtils and related test classes + IO-887: WriterOutputStream from a builder fails on malformed or unmappable input bytes + BoundedReader now extends ProxyReader + AbstractStreamBuilder.setOpenOptions(OpenOption...) now makes a defensive copy of its input array + IO-885: Path visits follow links + BOMInputStream fail-fast and tracks its ByteOrderMark as a final + Refactor UnixLineEndingInputStream and WindowsLineEndingInputStream for duplication + IO-857: [Javadoc] PathUtils.cleanDirectory() methods vs FileUtils + Fix JaCoCo report generation (code coverage) + AbstractStreamBuilder.setBufferSizeDefault(int) now resets to default for input less than or equal to zero * Changes + Bump org.apache.commons:commons-parent from 91 to 98 + Bump commons-codec:commons-codec from 1.19.0 to 1.21.0 + Bump commons.bytebuddy.version from 1.17.8 to 1.18.8 + Bump commons-lang3 from 3.19.0 to 3.20.0 ++++ apptainer: - Fix CVE-2026-34986 (bsc#1262956) * github.com/go-jose/go-jose/v4@v4.1.4 CVE-2026-33186 GO-2026-4762 (bsc#1260311) * google.golang.org/grpc@v1.79.3 CVE-2026-24137 GO-2026-4358 (bsc#1264177) * github.com/sigstore/sigstore@v1.10.4 Fix fallout: github.com/moby/go-archive@v0.1.0 github.com/containers/image/v5=github.com/containers/image/v5@v5.36.0 - Building Add `%%with_suid` macro to optionally build the `suid` starter (default: off). ++++ apptainer: - Fix CVE-2026-34986 (bsc#1262956) * github.com/go-jose/go-jose/v4@v4.1.4 CVE-2026-33186 GO-2026-4762 (bsc#1260311) * google.golang.org/grpc@v1.79.3 CVE-2026-24137 GO-2026-4358 (bsc#1264177) * github.com/sigstore/sigstore@v1.10.4 Fix fallout: github.com/moby/go-archive@v0.1.0 github.com/containers/image/v5=github.com/containers/image/v5@v5.36.0 - Building Add `%%with_suid` macro to optionally build the `suid` starter (default: off). ++++ apptainer: - Fix CVE-2026-34986 (bsc#1262956) * github.com/go-jose/go-jose/v4@v4.1.4 CVE-2026-33186 GO-2026-4762 (bsc#1260311) * google.golang.org/grpc@v1.79.3 CVE-2026-24137 GO-2026-4358 (bsc#1264177) * github.com/sigstore/sigstore@v1.10.4 Fix fallout: github.com/moby/go-archive@v0.1.0 github.com/containers/image/v5=github.com/containers/image/v5@v5.36.0 - Building Add `%%with_suid` macro to optionally build the `suid` starter (default: off). ++++ apptainer: - Fix CVE-2026-34986 (bsc#1262956) * github.com/go-jose/go-jose/v4@v4.1.4 CVE-2026-33186 GO-2026-4762 (bsc#1260311) * google.golang.org/grpc@v1.79.3 CVE-2026-24137 GO-2026-4358 (bsc#1264177) * github.com/sigstore/sigstore@v1.10.4 Fix fallout: github.com/moby/go-archive@v0.1.0 github.com/containers/image/v5=github.com/containers/image/v5@v5.36.0 - Building Add `%%with_suid` macro to optionally build the `suid` starter (default: off). ++++ apptainer: - Fix CVE-2026-34986 (bsc#1262956) * github.com/go-jose/go-jose/v4@v4.1.4 CVE-2026-33186 GO-2026-4762 (bsc#1260311) * google.golang.org/grpc@v1.79.3 CVE-2026-24137 GO-2026-4358 (bsc#1264177) * github.com/sigstore/sigstore@v1.10.4 Fix fallout: github.com/moby/go-archive@v0.1.0 github.com/containers/image/v5=github.com/containers/image/v5@v5.36.0 - Building Add `%%with_suid` macro to optionally build the `suid` starter (default: off). ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ chromium: - Chromium 148 (148.0.7778.96) promoted to stable (boo#1264175) * CVE-2026-7896: Integer overflow in Blink * CVE-2026-7897: Use after free in Mobile * CVE-2026-7898: Use after free in Chromoting * CVE-2026-7899: Out of bounds read and write in V8 * CVE-2026-7900: Heap buffer overflow in ANGLE * CVE-2026-7901: Use after free in ANGLE * CVE-2026-7902: Out of bounds memory access in V8 * CVE-2026-7903: Integer overflow in ANGLE * CVE-2026-7904: Out of bounds read in Fonts * CVE-2026-7905: Insufficient validation of untrusted input in Media * CVE-2026-7906: Use after free in SVG * CVE-2026-7907: Use after free in DOM * CVE-2026-7908: Use after free in Fullscreen * CVE-2026-7909: Inappropriate implementation in ServiceWorker * CVE-2026-7910: Use after free in Views * CVE-2026-7911: Use after free in Aura * CVE-2026-7912: Integer overflow in GPU * CVE-2026-7913: Insufficient policy enforcement in DevTools * CVE-2026-7914: Type Confusion in Accessibility * CVE-2026-7915: Insufficient data validation in DevTools * CVE-2026-7916: Insufficient data validation in InterestGroups * CVE-2026-7917: Use after free in Fullscreen * CVE-2026-7918: Use after free in GPU * CVE-2026-7919: Use after free in Aura * CVE-2026-7920: Use after free in Skia * CVE-2026-7921: Use after free in Passwords * CVE-2026-7922: Use after free in ServiceWorker * CVE-2026-7923: Out of bounds write in Skia * CVE-2026-7924: Uninitialized Use in Dawn * CVE-2026-7925: Use after free in Chromoting * CVE-2026-7926: Use after free in PresentationAPI * CVE-2026-7927: Type Confusion in Runtime * CVE-2026-7928: Use after free in WebRTC * CVE-2026-7929: Use after free in MediaRecording * CVE-2026-7930: Insufficient validation of untrusted input in Cookies * CVE-2026-7931: Insufficient validation of untrusted input in iOS * CVE-2026-7932: Insufficient policy enforcement in Downloads * CVE-2026-7933: Out of bounds read in WebCodecs * CVE-2026-7934: Insufficient validation of untrusted input in Popup Blocker * CVE-2026-7935: Inappropriate implementation in Speech * CVE-2026-7936: Object lifecycle issue in V8 * CVE-2026-7937: Insufficient policy enforcement in DevTools * CVE-2026-7938: Use after free in CSS * CVE-2026-7939: Inappropriate implementation in SanitizerAPI * CVE-2026-7940: Use after free in V8 * CVE-2026-7941: Insufficient validation of untrusted input in Mobile * CVE-2026-7942: Integer overflow in ANGLE * CVE-2026-7943: Insufficient validation of untrusted input in ANGLE * CVE-2026-7944: Insufficient validation of untrusted input in Persistent Cache * CVE-2026-7945: Insufficient validation of untrusted input in COOP * CVE-2026-7946: Insufficient policy enforcement in WebUI * CVE-2026-7947: Insufficient validation of untrusted input in Network * CVE-2026-7948: Race in Chromoting * CVE-2026-7949: Out of bounds read in Skia * CVE-2026-7950: Out of bounds read and write in GFX * CVE-2026-7951: Out of bounds write in WebRTC * CVE-2026-7952: Insufficient policy enforcement in Extensions * CVE-2026-7953: Insufficient validation of untrusted input in Omnibox * CVE-2026-7954: Race in Shared Storage * CVE-2026-7955: Uninitialized Use in GPU * CVE-2026-7956: Use after free in Navigation * CVE-2026-7957: Out of bounds write in Media * CVE-2026-7958: Inappropriate implementation in ServiceWorker * CVE-2026-7959: Inappropriate implementation in Navigation * CVE-2026-7960: Race in Speech * CVE-2026-7961: Insufficient validation of untrusted input in Permissions * CVE-2026-7962: Insufficient policy enforcement in DirectSockets * CVE-2026-7963: Inappropriate implementation in ServiceWorker * CVE-2026-7964: Insufficient validation of untrusted input in FileSystem * CVE-2026-7965: Insufficient validation of untrusted input in DevTools * CVE-2026-7966: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-7967: Insufficient validation of untrusted input in Navigation * CVE-2026-7968: Insufficient validation of untrusted input in CORS * CVE-2026-7969: Integer overflow in Network * CVE-2026-7970: Use after free in TopChrome * CVE-2026-7971: Inappropriate implementation in ORB * CVE-2026-7972: Uninitialized Use in GPU * CVE-2026-7973: Integer overflow in Dawn * CVE-2026-7974: Use after free in Blink * CVE-2026-7975: Use after free in DevTools * CVE-2026-7976: Use after free in Views * CVE-2026-7977: Inappropriate implementation in Canvas * CVE-2026-7978: Inappropriate implementation in Companion * CVE-2026-7979: Inappropriate implementation in Media * CVE-2026-7980: Use after free in WebAudio * CVE-2026-7981: Out of bounds read in Codecs * CVE-2026-7982: Uninitialized Use in WebCodecs * CVE-2026-7983: Out of bounds read in Dawn * CVE-2026-7984: Use after free in ReadingMode * CVE-2026-7985: Use after free in GPU * CVE-2026-7986: Insufficient policy enforcement in Autofill * CVE-2026-7987: Use after free in WebRTC * CVE-2026-7988: Type Confusion in WebRTC * CVE-2026-7989: Insufficient data validation in DataTransfer * CVE-2026-7990: Insufficient validation of untrusted input in Updater * CVE-2026-7991: Use after free in UI * CVE-2026-7992: Insufficient validation of untrusted input in UI * CVE-2026-7993: Insufficient validation of untrusted input in Payments * CVE-2026-7994: Inappropriate implementation in Chromoting * CVE-2026-7995: Out of bounds read in AdFilter * CVE-2026-7996: Insufficient validation of untrusted input in SSL * CVE-2026-7997: Insufficient validation of untrusted input in Updater * CVE-2026-7998: Insufficient validation of untrusted input in Dialog * CVE-2026-7999: Inappropriate implementation in V8 * CVE-2026-8000: Insufficient validation of untrusted input in ChromeDriver * CVE-2026-8001: Use after free in Printing * CVE-2026-8002: Use after free in Audio * CVE-2026-8003: Insufficient validation of untrusted input in TabGroups * CVE-2026-8004: Insufficient policy enforcement in DevTools * CVE-2026-8005: Insufficient validation of untrusted input in Cast * CVE-2026-8006: Insufficient policy enforcement in DevTools * CVE-2026-8007: Insufficient validation of untrusted input in Cast * CVE-2026-8008: Inappropriate implementation in DevTools * CVE-2026-8009: Inappropriate implementation in Cast * CVE-2026-8010: Insufficient validation of untrusted input in SiteIsolation * CVE-2026-8011: Insufficient policy enforcement in Search * CVE-2026-8012: Inappropriate implementation in MHTML * CVE-2026-8013: Insufficient validation of untrusted input in FedCM * CVE-2026-8014: Inappropriate implementation in Preload * CVE-2026-8015: Inappropriate implementation in Media * CVE-2026-8016: Use after free in WebRTC * CVE-2026-8017: Side-channel information leakage in Media * CVE-2026-8018: Insufficient policy enforcement in DevTools * CVE-2026-8019: Insufficient policy enforcement in WebApp * CVE-2026-8020: Uninitialized Use in GPU * CVE-2026-8021: Script injection in UI * CVE-2026-8022: Inappropriate implementation in MHTML - Fix build failure in seccomp_bpf sandbox previously chromium-fix-sandbox-with-glibc-2.43.patch add chromium-148-sandbox-glibc-2.43.patch - bump version in buildrequires for gn (0.20260331) (needs variable inputs added in March 2026) - added patches: * chromium-148-revert_std_ranges_iota.patch (revert for llvm < 20, error: no member named 'iota' in namespace 'std::ranges') * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (from upstream, add missing implementation for ppc) * chromium-148-no_dep_on_intree_rustc_binary.patch (do not depend on intree binary of rustc) - added patches: * chromium-148-only_address_sanitizer.patch (prevent undefined symbol __sanitizer_set_death_callback) * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch (revert upstream change) * ppc-chromium-v8-3d60e0915e8a0caec994a400627f9dfa00e717d0.patch (obsolete, upstream) - removed patches: * chromium-147-ffmpeg_includes.patch (upstream) * chromium-3bccbdead3efa7e91f7c9d4078106dedaed84fb8.patch (upstream) - modified patches: * ppc-fedora-fix-different-data-layouts.patch * ppc-fedora-skia-vsx-instructions.patch * ppc-fedora-0002-regenerate-xnn-buildgn.patch * chromium-146-ignore-for-ubsan.patch * chromium-f14702bb2b25c940cc95eb772110e715618bd069.patch adjust context for changes made in 7120cf7 * chromium-146-value_or.patch (one more place in v8) * chromium-147-blink_renderer_need_ffmpeg.patch (new hunk added) - keeplibs: added: third_party/gperf (needed by blink/renderer/core/css/parser/at_rule_descriptors.cc) change: third_party/harfbuzz-ng to third_party/harfbuzz drop: third_party/libaom/source/libaom/third_party/SVT-AV1 - force link to system gperf binary instead of hardcoded x86 in tree copy ++++ kernel-64kb: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-64kb: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-64kb: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-azure: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-azure: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-azure: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-default: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-default: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-default: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-rt: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-rt: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-rt: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ dracut-pcr-signature: - Update to version 0.7+0: * Boot the ESP in /sysefi during initrd ++++ dtb-aarch64: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ dtb-aarch64: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ dtb-aarch64: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ glab: - Update to version 1.94.0: * Features - f620f7a2: feat(mr note create): add --reply flag and refactor to options struct (Tomas Vik tvik@gitlab.com) - bed805c0: feat(mr): create diff comments (Tomas Vik (OOO back on 2026-05-11) tvik@gitlab.com) - 56718ff9: feat(orbit): add glab orbit subcommands (experimental) (Dmitry Gruzd dgruzd@gitlab.com) - 56b22863: feat(workitems): add glab work-items create (Carlos Corona ccorona@gitlab.com) - 5b4bc4a6: feat: add --reviewer flag to glab stack sync (Gary Holtz gholtz@gitlab.com) - fa792f3c: feat: add glab work-items delete (Carlos Corona ccorona@gitlab.com) - 5d59e0be: feat: render Markdown links as OSC 8 hyperlinks in help text (Brendan Lynch blynch@gitlab.com) * Bug Fixes - 9a6f9de4: fix(repo create): clone instead of git init when - -readme is used (Kai Armstrong karmstrong@gitlab.com) - 339ff8cc: fix(snapcraft): /etc/gitconfig permissions (Filip Aleksic faleksic@gitlab.com) - 7f22b23c: fix: correct inverted condition for GITLAB_RELEASE_ASSETS_USE_PACKAGE_REGISTRY env var (Kai Armstrong karmstrong@gitlab.com) - 3394d202: fix: eliminate data race in ci and job tests by avoiding global os.Stdout/os.Stderr mutation (Timo Furrer tfurrer@gitlab.com) - a07c2c1c: fix: update flag description and remove backticks (Brendan blynch@gitlab.com) * Documentation - 774ea4f2: docs: add carapace completions note (Jonathan Bowe jonathan@bowedev.com) - 53918c5a: docs: document both head and merge ref formats for MR pipelines (Kai Armstrong karmstrong@gitlab.com) - da6f7b2f: docs: ensure glab check-update is accurately described (Brendan blynch@gitlab.com) * Dependencies - a0e977eb: chore(deps): update dependency @commitlint/cli to ^20.5.2 (GitLab Renovate Bot gitlab-bot@gitlab.com) - d7008ef5: chore(deps): update module charm.land/bubbletea/v2 to v2.0.6 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5453a863: chore(deps): update module github.com/docker/cli to v29.4.1+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - ea1e87bd: chore(deps): update module github.com/docker/cli to v29.4.2+incompatible (GitLab Renovate Bot gitlab-bot@gitlab.com) - ea24f0a9: chore(deps): update module github.com/docker/docker-credential-helpers to v0.9.6 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 8bb00fb6: chore(deps): update module github.com/gdamore/tcell/v2 to v2.13.9 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 5762ad2e: chore(deps): update module github.com/mattn/go-isatty to v0.0.21 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 41d476fc: chore(deps): update module github.com/mattn/go-isatty to v0.0.22 (GitLab Renovate Bot gitlab-bot@gitlab.com) - f1c53172: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.21.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 58ca66f7: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.22.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 6f317c36: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.24.0 (GitLab Renovate Bot gitlab-bot@gitlab.com) - 230c924a: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.24.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) - bd77d705: chore(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.24.1 (GitLab Renovate Bot gitlab-bot@gitlab.com) * Maintenance - ada4904f: chore: sync commit-lint script from gitlab-lsp (Kai Armstrong karmstrong@gitlab.com) - f60689c7: chore: update docs linting tools and docs linting container image (Evan Read eread@gitlab.com) - 9e274d09: ci: add Duo agent environment configuration (Thomas Schmidt tschmidt@gitlab.com) - 76ba508c: refactor(checkout): inject GitRunner dependency for testability (Gary Holtz gholtz@gitlab.com) - fe74aaf3: refactor(duo): improve Duo CLI update notification message (Arthur Foltz afoltz@gitlab.com) ++++ gnutls: - Security fixes: * CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705) * CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708) * CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704) * CVE-2026-42010: lib/auth/rsa_psk: fix binary PSK identity lookup (bsc#1263709) * CVE-2026-3833: x509/name-constraints: compare domain names case-insensitive (bsc#1263707) * CVE-2026-42011: x509/name_constraints: fix intersecting empty constraints (bsc#1263710) * CVE-2026-42012: x509/hostname-verify: make URI/SRV SAN preclude CN fallback (bsc#1263711) * CVE-2026-42013: x509: prevent fallback on oversized SAN (bsc#1263712) * CVE-2026-42014: pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin (bsc#1263713) * CVE-2026-42015: x509/pkcs12_bag: fix off-by-one in bag element bounds check (bsc#1263714) * CVE-2026-5260: lib/pkcs11_privkey: guard against overreading on short ciphertexts (bsc#1263715) * CVE-2026-3832: cert-session: fix multi-entry OCSP revocation bypass (bsc#1263706) * CVE-2026-5419: gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free (bsc#1263716) * Add patches: gnutls-CVE-2026-33846.patch gnutls-CVE-2026-42009.patch gnutls-CVE-2026-33845.patch gnutls-CVE-2026-42010.patch gnutls-CVE-2026-3833.patch gnutls-CVE-2026-42011.patch gnutls-CVE-2026-42012.patch gnutls-CVE-2026-42013.patch gnutls-CVE-2026-42014.patch gnutls-CVE-2026-5260.patch gnutls-CVE-2026-42015.patch gnutls-CVE-2026-3832.patch gnutls-CVE-2026-5419.patch ++++ hauler: - update to 1.4.3 ( bsc#1262353, CVE-2026-39984, bsc#1262942, CVE-2026-34986): * [1.4] Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 in the go_modules group across 1 directory * [1.4] Bump github.com/sigstore/timestamp-authority/v2 from 2.0.4 to 2.0.6 in the go_modules group across 1 directory * [1.4] Bump google.golang.org/grpc from 1.78.0 to 1.79.3 in the go_modules group across 1 directory * fixed versions and dependencies on release/1.4 * [1.4] removed unnecessary rewrite flag from sync * added makefile command for vulnerability checks (backport [#577]) * remove cherrypick bot and add mergify details (backport #581) ++++ hauler: - update to 1.4.3 ( bsc#1262353, CVE-2026-39984, bsc#1262942, CVE-2026-34986): * [1.4] Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 in the go_modules group across 1 directory * [1.4] Bump github.com/sigstore/timestamp-authority/v2 from 2.0.4 to 2.0.6 in the go_modules group across 1 directory * [1.4] Bump google.golang.org/grpc from 1.78.0 to 1.79.3 in the go_modules group across 1 directory * fixed versions and dependencies on release/1.4 * [1.4] removed unnecessary rewrite flag from sync * added makefile command for vulnerability checks (backport [#577]) * remove cherrypick bot and add mergify details (backport #581) ++++ hauler: - update to 1.4.3 ( bsc#1262353, CVE-2026-39984, bsc#1262942, CVE-2026-34986): * [1.4] Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 in the go_modules group across 1 directory * [1.4] Bump github.com/sigstore/timestamp-authority/v2 from 2.0.4 to 2.0.6 in the go_modules group across 1 directory * [1.4] Bump google.golang.org/grpc from 1.78.0 to 1.79.3 in the go_modules group across 1 directory * fixed versions and dependencies on release/1.4 * [1.4] removed unnecessary rewrite flag from sync * added makefile command for vulnerability checks (backport [#577]) * remove cherrypick bot and add mergify details (backport #581) ++++ hauler: - update to 1.4.3 ( bsc#1262353, CVE-2026-39984, bsc#1262942, CVE-2026-34986): * [1.4] Bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 in the go_modules group across 1 directory * [1.4] Bump github.com/sigstore/timestamp-authority/v2 from 2.0.4 to 2.0.6 in the go_modules group across 1 directory * [1.4] Bump google.golang.org/grpc from 1.78.0 to 1.79.3 in the go_modules group across 1 directory * fixed versions and dependencies on release/1.4 * [1.4] removed unnecessary rewrite flag from sync * added makefile command for vulnerability checks (backport [#577]) * remove cherrypick bot and add mergify details (backport #581) ++++ health-checker: - Update to version 1.13+git20260414.bb3e4ad: * Update configure.ac with autoupdate * Remove dependencies on cloud-init [bsc#1244078] and for removed plugins * Revert "fix(systemd): Fix dependency cycle with other systemd services" * fix(systemd): Fix dependency cycle with other systemd services * fix(dracut): Skip dracut module on BLS systems * Release version 1.13 * Use Automatic Boot Assessment for systemd-boot/grub2-bls * README: clearify services in After section * Set RemainAfterExit=yes ++++ helmfile: - Update to version 1.5.0: * feat: add --write-output flag to helmfile fetch for air-gapped environments by @yxxhero in #2572 * feat: add 'create' subcommand to scaffold helmfile deployment projects by @yxxhero in #2574 * docs: restructure documentation and improve newcomer experience by @yxxhero in #2573 * docs: deduplicate Technical Details sections in values-and-merging.md by @yxxhero in #2575 ++++ helmfile: - Update to version 1.5.0: * feat: add --write-output flag to helmfile fetch for air-gapped environments by @yxxhero in #2572 * feat: add 'create' subcommand to scaffold helmfile deployment projects by @yxxhero in #2574 * docs: restructure documentation and improve newcomer experience by @yxxhero in #2573 * docs: deduplicate Technical Details sections in values-and-merging.md by @yxxhero in #2575 ++++ helmfile: - Update to version 1.5.0: * feat: add --write-output flag to helmfile fetch for air-gapped environments by @yxxhero in #2572 * feat: add 'create' subcommand to scaffold helmfile deployment projects by @yxxhero in #2574 * docs: restructure documentation and improve newcomer experience by @yxxhero in #2573 * docs: deduplicate Technical Details sections in values-and-merging.md by @yxxhero in #2575 ++++ helmfile: - Update to version 1.5.0: * feat: add --write-output flag to helmfile fetch for air-gapped environments by @yxxhero in #2572 * feat: add 'create' subcommand to scaffold helmfile deployment projects by @yxxhero in #2574 * docs: restructure documentation and improve newcomer experience by @yxxhero in #2573 * docs: deduplicate Technical Details sections in values-and-merging.md by @yxxhero in #2575 ++++ junit5: - Update to upstream version 5.14.4 * Principal changes: + Fixed a race condition in NodeTestTask.parentContext in Junit Platform + @EnabledOnJre and @DisabledOnJre once again work reliably when used with JRE.OTHER in a test running on a Java runtime whose version is higher than the version of the last JAVA_* constant in the JRE enum (Junit Jupiter) + Legacy XML reports now include the index of @ClassTemplate/@ParameterizedClass invocations in test names to make them unique (Junit Jupiter) + Legacy XML reports now include parent display names to make it easier to distinguish between invocations for different parameters (Junit Jupiter) - Follow the same pattern of Bundle-SymbolicName in the artifacts of junit5-minimal as in the rest of artifacts contained in the main junit5 package. And align the Bundle-SymbolicName to what the upstream gradle build produces ++++ junit5: - Update to upstream version 5.14.4 * Principal changes: + Fixed a race condition in NodeTestTask.parentContext in Junit Platform + @EnabledOnJre and @DisabledOnJre once again work reliably when used with JRE.OTHER in a test running on a Java runtime whose version is higher than the version of the last JAVA_* constant in the JRE enum (Junit Jupiter) + Legacy XML reports now include the index of @ClassTemplate/@ParameterizedClass invocations in test names to make them unique (Junit Jupiter) + Legacy XML reports now include parent display names to make it easier to distinguish between invocations for different parameters (Junit Jupiter) - Follow the same pattern of Bundle-SymbolicName in the artifacts of junit5-minimal as in the rest of artifacts contained in the main junit5 package. And align the Bundle-SymbolicName to what the upstream gradle build produces ++++ junit5-minimal: - Update to upstream version 5.14.4 * Principal changes: + Fixed a race condition in NodeTestTask.parentContext in Junit Platform + @EnabledOnJre and @DisabledOnJre once again work reliably when used with JRE.OTHER in a test running on a Java runtime whose version is higher than the version of the last JAVA_* constant in the JRE enum (Junit Jupiter) + Legacy XML reports now include the index of @ClassTemplate/@ParameterizedClass invocations in test names to make them unique (Junit Jupiter) + Legacy XML reports now include parent display names to make it easier to distinguish between invocations for different parameters (Junit Jupiter) - Follow the same pattern of Bundle-SymbolicName in the artifacts of junit5-minimal as in the rest of artifacts contained in the main junit5 package. And align the Bundle-SymbolicName to what the upstream gradle build produces ++++ junit5-minimal: - Update to upstream version 5.14.4 * Principal changes: + Fixed a race condition in NodeTestTask.parentContext in Junit Platform + @EnabledOnJre and @DisabledOnJre once again work reliably when used with JRE.OTHER in a test running on a Java runtime whose version is higher than the version of the last JAVA_* constant in the JRE enum (Junit Jupiter) + Legacy XML reports now include the index of @ClassTemplate/@ParameterizedClass invocations in test names to make them unique (Junit Jupiter) + Legacy XML reports now include parent display names to make it easier to distinguish between invocations for different parameters (Junit Jupiter) - Follow the same pattern of Bundle-SymbolicName in the artifacts of junit5-minimal as in the rest of artifacts contained in the main junit5 package. And align the Bundle-SymbolicName to what the upstream gradle build produces ++++ kernel-source: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-source: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-source: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-docs: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-docs: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-docs: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-kvmsmall: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-kvmsmall: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-kvmsmall: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-obs-build: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-obs-build: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-obs-build: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-obs-qa: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-obs-qa: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-obs-qa: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-syms: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-syms: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-syms: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-zfcpdump: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-zfcpdump: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ kernel-zfcpdump: - futex: Require sys_futex_requeue() to have identical flags (CVE-2026-31554 bsc#1263107). - commit ce7d9f8 - kABI fix after KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit a1ea62d - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - commit 9cbc888 - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - commit 360d18b - KVM: x86: Use scratch field in MMIO fragment to hold small write values (CVE-2026-31588 bsc#1263165). - commit 19429bd - Refresh patches.suse/btrfs-fix-incorrect-return-value-after-changing-leaf-in-lo.patch. - commit 45e3335 - selftests/bpf: Add tests for sdiv32/smod32 with INT_MIN dividend (CVE-2026-31525 bsc#1262725). - commit 6ce77a2 - bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (CVE-2026-31525 bsc#1262725). - commit 6e6a9d2 ++++ krb5: - Fix Fix two NegoEx parsing vulnerabilities: * CVE-2026-40355, bsc#1263366 * CVE-2026-40356, bsc#1263367 - Add patch 0011-Fix-two-NegoEx-parsing-vulnerabilities.patch ++++ krb5: - Fix Fix two NegoEx parsing vulnerabilities: * CVE-2026-40355, bsc#1263366 * CVE-2026-40356, bsc#1263367 - Add patch 0011-Fix-two-NegoEx-parsing-vulnerabilities.patch ++++ maven-invoker-plugin: - Upgrade to upstream version 3.10.1 * Bug Fixes + Provide separate logs for each execution for rerunning jobs * Dependency updates + Bump commons-codec:commons-codec from 1.21.0 to 1.22.0 + Bump commons-io:commons-io from 2.21.0 to 2.22.0 ++++ os-autoinst: - Update to version 5.1778097909.35320dd: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years - Update to version 5.1778069368.c751b82: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset ++++ os-autoinst: - Update to version 5.1778097909.35320dd: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years - Update to version 5.1778069368.c751b82: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset ++++ os-autoinst: - Update to version 5.1778097909.35320dd: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * style: unify copyright headers by dropping years - Update to version 5.1778069368.c751b82: * feat(qemu): improve port conflict detection and VNC error diagnostics * fix: restore serial marker hook after switching users * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset ++++ python-Django: - Add security patches: * CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass (bsc#1264153) * CVE-2026-5766.patch * CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST (bsc#1264154) * CVE-2026-35192.patch * CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware (bsc#1264152) * CVE-2026-6907.patch ++++ python-Django: - Add security patches: * CVE-2026-5766: Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass (bsc#1264153) * CVE-2026-5766.patch * CVE-2026-35192: Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST (bsc#1264154) * CVE-2026-35192.patch * CVE-2026-6907: Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMiddleware (bsc#1264152) * CVE-2026-6907.patch ++++ sdbootutil: - Update to version 1+git20260506.25d47bf: * Drop systemd.machine_id if /etc/machine-id is present * Support XBOOTLDR partition * Add CLAUDE.md file * Use command -v instead of hash * Remove dead code * Fix regular expression non-capturing group * Add comment about default values in config file * Clarify when swap is mounted * Fix typo in comment * Exit early if we are outside the initrd * Fix variable name * Fix typo * When cleaning pcrlock.d remove only the content * Do not check in_buildroot when updating entries * update_kernels: Update entries for the system if no snapshot is provided ++++ valkey: - Update to 8.0.9: - Security fixes * (CVE-2026-23479, bsc#1264164) Use-After-Free in unblock client flow * (CVE-2026-25243, bsc#1264166) Invalid Memory Access in RESTORE command * (CVE-2026-23631, bsc#1264165) Use-after-free when full sync occurs during a yielding Lua/function execution ------------------------------------------------------------------ ------------------ 2026-5-5 - May 5 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaThunderbird: - Migrate from deprecated %suse_update_desktop_file to %translate_suse_desktop. (boo#1158957) - Add thunderbird-glibc-2.43.patch as source22 and apply it only if glibc newer than 2.42 is installed in the build environment. It serves to remove conflicting definitions and adapt the syscall in accordance with glibc-2.43. ++++ assimp: - Add upstream changes: * 0001-ASE-Fix-possible-out-of-bound-access.patch (CVE-2025-3015 bsc#1240412) * 0001-MDL-Limit-max-texture-sizes.patch (gh#assimp/assimp#6022) * 0001-MDL-Fix-overflow-check.patch (gh#assimp/assimp#6009) (CVE-2025-2591 bsc#1239920) * CVE-2025-2151.patch (CVE-2025-2151, boo#1239220) * 0001-Bugfix-Fix-possible-nullptr-dereferencing.patch (gh#assimp/assimp#6025) * 0001-Potential-use-after-free.patch * 0001-ASE-Use-correct-vertex-container.patch (gh#assimp/assimp#6024) * 0001-CMS-Fix-possible-overflow-access.patch (gh#assimp/assimp#6010) (CVE-2025-2592, bsc#1239916) ++++ assimp: - Add upstream changes: * 0001-ASE-Fix-possible-out-of-bound-access.patch (CVE-2025-3015 bsc#1240412) * 0001-MDL-Limit-max-texture-sizes.patch (gh#assimp/assimp#6022) * 0001-MDL-Fix-overflow-check.patch (gh#assimp/assimp#6009) (CVE-2025-2591 bsc#1239920) * CVE-2025-2151.patch (CVE-2025-2151, boo#1239220) * 0001-Bugfix-Fix-possible-nullptr-dereferencing.patch (gh#assimp/assimp#6025) * 0001-Potential-use-after-free.patch * 0001-ASE-Use-correct-vertex-container.patch (gh#assimp/assimp#6024) * 0001-CMS-Fix-possible-overflow-access.patch (gh#assimp/assimp#6010) (CVE-2025-2592, bsc#1239916) ++++ kernel-64kb: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-64kb: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-64kb: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-64kb: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-64kb: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-azure: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-azure: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-azure: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-azure: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-azure: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-default: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-default: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-default: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-default: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-default: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-rt: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-rt: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-rt: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-rt: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-rt: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ coturn: - Update to version 4.11.0 * Filc harness and pointer typedefs (#1896). * Load generator mode in turnutils_uclient (#1894). * Cache hot lookups in TURN data-path handlers (#1893). * Inline get_ioa_addr_len() in the header (#1891). * Trim two redundant checks from per-packet relay hot path. * Hoist turn_server_get_engine() out of per-packet hot path. * Add fuzz coverage for integrity helpers (#1888). * Add deterministic challenge-response builder to FuzzStun. * Seed address-mapping table in fuzz initializer (#1885). * Unblock fuzz coverage for is_http and rare STUN attributes. * HTTP parsing fixes (#1882). * Out of bound HTTP detection in parser (#1877). * Delete log line per relay thread on start (#1876). * Add Unity-based unit test scaffolding (#1875). * Drop udp_relay_servers_number config and clean up dead UDP id-space (#1874). * Fix build failure: define _GNU_SOURCE for recvmmsg() on Linux. * Pin session origin only after MESSAGE-INTEGRITY validates. * Abort on malformed allowed/denied-peer-ip at startup (#1872). * Fix format-string injection in Redis DB driver (#1870). * Use constant-time compare for STUN MESSAGE-INTEGRITY HMAC. ++++ glibc-cross-aarch64-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-cross-aarch64-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-cross-ppc64le-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-cross-ppc64le-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-cross-riscv64-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-cross-riscv64-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-cross-s390x-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-cross-s390x-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ dtb-aarch64: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ dtb-aarch64: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ dtb-aarch64: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ dtb-aarch64: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ dtb-aarch64: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ glibc: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-utils-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ glibc-utils-src: - ibm139x-pending-char-state.patch: Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980) ++++ kernel-source: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-source: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-source: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-source: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-source: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-docs: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-docs: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-docs: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-docs: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-docs: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-kvmsmall: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-kvmsmall: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-kvmsmall: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-kvmsmall: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-kvmsmall: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-obs-build: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-obs-build: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-obs-build: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-obs-build: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-obs-build: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-obs-qa: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-obs-qa: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-obs-qa: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-obs-qa: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-obs-qa: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-syms: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-syms: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-syms: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-syms: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-syms: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-zfcpdump: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-zfcpdump: - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 ++++ kernel-zfcpdump: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-zfcpdump: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ kernel-zfcpdump: - iommu/vt-d: Remove LPIG from page group response descriptor (jsc#PED-16113). - commit 02909a4 - mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176 CVE-2026-31586). - commit ceea29f - ipmi:si: Return state to normal if message allocation fails (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - commit f949a9a - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - commit 998ec99 - mptcp: fix slab-use-after-free in __inet_lookup_established (CVE-2026-31669 bsc#1263141). - commit 9fd5bc5 - net: fix fanout UAF in packet_release() via NETDEV_UP race (CVE-2026-31504 bsc#1263085). - commit f302432 - net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (CVE-2026-31533 bsc#1262758). - commit 6f034ca - x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013 CVE-2025-54518). - commit b2d5a21 - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - Refresh patches.suse/dpll-zl3073x-Add-functions-to-access-hardware-regist.patch. - commit 6bfd04c - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - commit c6899d0 - net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (CVE-2026-31507 bsc#1263095). - commit 962222e - net: stmmac: fix integer underflow in chain mode (CVE-2026-31649 bsc#1263582). - net-shapers: don't free reply skb after genlmsg_reply() (git-fixes). - commit 9dae3e5 ++++ sqlite3: - Update to version 3.53.1: * Fixes for problems in 3.53.0 reported by users. * See the check-in timeline for details: https://sqlite.org/src/timeline?from=version-3.53.0&to=version-3.53.1 ++++ tree-sitter: - Also don't provide lib%{name}%{somajor}: this is already the sub package's exact name and as such is implicitly provided. ++++ tree-sitter: - Also don't provide lib%{name}%{somajor}: this is already the sub package's exact name and as such is implicitly provided. ++++ mutt: - Add upstream commits as patches (boo#1264047) * boo1263892-ebfa2969.patch (boo#1263892 CVE-2026-43864) * boo1263893-fdc04a17.patch (boo#1263893 CVE-2026-43863) * boo1263894-f547a849.patch (boo#1263894 CVE-2026-43862) * boo1263895-12f54fe3.patch (boo#1263895 CVE-2026-43861) * boo1263896-834c5a2e.patch (boo#1263896 CVE-2026-43860, boo#1263897 CVE-2026-43859) ++++ openQA: - Update to version 5.1777995277.b985bea2: * style: Enforce perlcritic policy Variables::ProtectPrivateVars * fix(docs): Fix links to documentation after converting to Markdown * docs: fix broken references to former .asciidoc files * docs: Fix wrapping list of directories after Markdown migration * docs: Improve documentation of `git_auto_clone` feature * docs: Make remark about worker cache service clearer using a comma * docs: Fix casing of Git in the section about setting up Git support * feat: Include log in IPA results * feat: enhance dynamic job limit with fast ramp-up ++++ openQA: - Update to version 5.1777995277.b985bea2: * style: Enforce perlcritic policy Variables::ProtectPrivateVars * fix(docs): Fix links to documentation after converting to Markdown * docs: fix broken references to former .asciidoc files * docs: Fix wrapping list of directories after Markdown migration * docs: Improve documentation of `git_auto_clone` feature * docs: Make remark about worker cache service clearer using a comma * docs: Fix casing of Git in the section about setting up Git support * feat: Include log in IPA results * feat: enhance dynamic job limit with fast ramp-up ++++ openQA: - Update to version 5.1777995277.b985bea2: * style: Enforce perlcritic policy Variables::ProtectPrivateVars * fix(docs): Fix links to documentation after converting to Markdown * docs: fix broken references to former .asciidoc files * docs: Fix wrapping list of directories after Markdown migration * docs: Improve documentation of `git_auto_clone` feature * docs: Make remark about worker cache service clearer using a comma * docs: Fix casing of Git in the section about setting up Git support * feat: Include log in IPA results * feat: enhance dynamic job limit with fast ramp-up ++++ postfix: - VUL-0: CVE-2026-43964: postfix: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062) Add upstream patch: buffer-over-read.patch ++++ postfix-bdb: - VUL-0: CVE-2026-43964: postfix: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062) Add upstream patch: buffer-over-read.patch ++++ python-lxml: - CVE-2026-41066: Information disclosure via untrusted XML input leading to local file read (bsc#1263254) Add patch CVE-2026-41066.patch ++++ python-click: - CVE-2026-7246: Arbitrary command execution via command injection in click.edit() (bsc#1263898) * CVE-2026-7246.patch ------------------------------------------------------------------ ------------------ 2026-5-4 - May 4 2026 ------------------- ------------------------------------------------------------------ ++++ kernel-64kb: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-64kb: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-64kb: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-azure: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-azure: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-azure: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-default: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-default: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-default: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-rt: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-rt: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-rt: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ crypto-policies: - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default * Add crypto-policies-OpenSSH-PQC.patch ++++ dnsdist: - update to 1.9.13: https://www.dnsdist.org/changelog.html#change-1.9.13 * bsc#1262536 (CVE-2026-33257): Insufficient input validation of internal webserver * bsc#1262537 (CVE-2026-33260): Insufficient input validation of internal webserver * bsc#1262538 (CVE-2026-33254): Resource exhaustion via DoQ/DoH3 connections * bsc#1262539 (CVE-2026-33602): Off-by-one access when processing crafted UDP responses * bsc#1262540 (CVE-2026-33599): Out-of-bounds read in service discovery * bsc#1262541 (CVE-2026-33598): Out-of-bounds read in cache inspection via Lua * bsc#1262542 (CVE-2026-33597): PRSD detection denial of service * bsc#1262543 (CVE-2026-33596): TCP backend stream ID overflow * bsc#1262544 (CVE-2026-33595): DoQ/DoH3 excessive memory allocation * bsc#1262545 (CVE-2026-33594): Outgoing DoH excessive memory allocation * bsc#1262546 (CVE-2026-33593): Denial of service via crafted DNSCrypt query ++++ dtb-aarch64: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ dtb-aarch64: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ dtb-aarch64: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ google-cloud-sap-agent: - Update to version 3.13 * Replace strings.TrimSuffix with strings.TrimSpace in hanabackup.go * Improve error messages in hanabackup.go. * Add system state logging and logical device verification. * Minor version bump * Improve SAP instance comparison for process metrics collectors to prevent unnecessary restarts of collectors. * Delete supportbundlehandler package. * Remove configurehandler from sapguestactions. * Delete hanadiskbackuphandler from sapguestactions. * Remove Guest Actions and GCBDR Actions from initial daemon start. * Remove `gsutil` check from collection definition. * Delete performancediagnosticshandler package. * Remove unused handlers and shell command execution. * status feature fixes - pass secret name * Fix an issue in system discovery if discovering a network fails, particularly due to an IAM permission error. * Add verification for HANA data volume state after disk restore. * Error handling for rescanVolumegroups and improved logging. * Add link to What's New page in the sapagent README. * Add secret manager IAM checks if secret key is preset in status ++++ google-guest-agent: - Update to version 20260430.00 * Update OWNERS (#609) * Update THIRD_PARTY_LICENSES to be package specific location. (#608) * Update dependencies and go version to 1.26.2 (#607) (bsc#1265762, CVE-2026-33814) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) (bsc#1260264, CVE-2026-33186) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) (bsc#1239334, CVE-2025-22869, bsc#1253889, CVE-2025-58181) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) - from version 20260424.00 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) - from version 20260423.01 * Update THIRD_PARTY_LICENSES to be package specific location. (#608) - from version 20260423.00 * Update dependencies and go version to 1.26.2 (#607) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) - from version 20260422.01 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) - from version 20260422.00 * Update dependencies and go version to 1.26.2 (#607) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) - from version 20260421.00 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) - from version 20260414.00 * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) - Bump Go API version to 1.26 - Drop CVE-2026-34986.patch, merged upstream ++++ google-guest-agent: - Update to version 20260430.00 * Update OWNERS (#609) * Update THIRD_PARTY_LICENSES to be package specific location. (#608) * Update dependencies and go version to 1.26.2 (#607) (bsc#1265762, CVE-2026-33814) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) (bsc#1260264, CVE-2026-33186) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) (bsc#1239334, CVE-2025-22869, bsc#1253889, CVE-2025-58181) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) - from version 20260424.00 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) - from version 20260423.01 * Update THIRD_PARTY_LICENSES to be package specific location. (#608) - from version 20260423.00 * Update dependencies and go version to 1.26.2 (#607) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) - from version 20260422.01 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) - from version 20260422.00 * Update dependencies and go version to 1.26.2 (#607) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) - from version 20260421.00 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) - from version 20260414.00 * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) - Bump Go API version to 1.26 - Drop CVE-2026-34986.patch, merged upstream ++++ google-guest-oslogin: - Update to version 20260430.00 * URLEncode request parameters sent to the metadata server. (#182) ++++ google-osconfig-agent: - Update to version 20260428.00 * Add/improve unit tests for agentendpoint/agentendpoint.go (#930) - from version 20260427.03 * Cover config/file.go by unit tests (#935) - from version 20260422.01 * Cover patch_linux.go by unit tests (#932) - from version 20260422.00 * upgrade grpc package in main package and e2e tests (#959) (bsc#1260264, CVE-2026-33186) - from version 20260417.04 * Bump OSV-Scalibr version to v0.4.3 (#956) - from version 20260417.03 * Add unit tests for updates_linux.go (#937) - from version 20260417.02 * Add zone to CreateDisk step (#955) - from version 20260417.01 * Change disk type for deb11 (#954) - from version 20260417.00 * Add unit tests for policies/apt.go PART 1 (#950) - from version 20260410.02 * Add unit tests for packages/pty_linux.go (#943) - from version 20260410.01 * fix disk type for arm workflows (#948) - from version 20260410.00 * Change machine type for arm based workflows (#946) - Drop CVE-2026-33186.patch, merged upstream ++++ grafana: - CVE-2026-34986: Fix panic in JWE decryption (bsc#1262950) * Add 0007-Bump-github.com-go-jose-go-jose.patch - CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) * Add 0008-Bump-github.com-apache-thrift.patch ++++ grafana: - CVE-2026-34986: Fix panic in JWE decryption (bsc#1262950) * Add 0007-Bump-github.com-go-jose-go-jose.patch - CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) * Add 0008-Bump-github.com-apache-thrift.patch ++++ htop: - update to 3.5.1: * Consolidate ClockMeter code into DateTimeMeter code * Linux/PCP: Replace M_SHARE (SHR) with M_PRIV (PRIV) in default Main screen columns * PCP: Fix dynamic screen column (instance) sorting (incorrect cast and field offsets) * PCP: Fix units used when printing M_PRIV memory column values * PCP: Add Darwin swap metric values and a fallback on Linux for SwapMeter * Fix null pointer dereference in actionBacktrace() (GCC LTO - O2 -flto, Ubuntu 24.04) * Make search function activate following on find consistently * Make a panel click abort the search function ++++ hugo: - update to 0.161.1: * resources: Honor Retry-After header in resources.GetRemote retries c4eba928 @bep #14828 * warpc: Move to parson.c in https://github.com/kgabis/parson 8b40a96b @bep #14823 * config/security: Add AllowChildProcess to security.node.permissions d65af84d @bep #14824 * config/security: Restrict default http.urls "@" deny to userinfo 454450a6 @bep #14825 - update to 0.161.0: * This release contains two security hardening fixes: * We now run the Node tools PostCSS, Babel and TailwindCSS, by default, with the `--permission` flag with the permissions defined in security.node.permissions. This means that you need Node >= 22 installed and that `css.TailwindCSS` now requires that the Tailwind CSS CLI must be installed as a Node.js package. The standalone executable is no longer supported * We have made the defaults in security.http.urls more restrictive. - update to 0.160.1: * Fix panic when passthrough elements are used in headings 8b00030b @bep #14677 * Fix panic on edit of legacy mapped template names that's also a valid path in the new setup c4855167 @bep #14740 * Fix RenderShortcodes leaking context markers when indented 161d0d47 @bep #12457 * Strip nested page context markers from standalone RenderShortcodes 45e45966 @bep #14732 * Rename deprecated cascade._target to cascade.target in tests 58927aa1 @bep * Fix auto-creation of root sections in multilingual sites ce009e3a @bep #14681 * readme: Fix links 07558724 @chicks-net - Update to version 0.161.1: * releaser: Bump versions for release of 0.161.1 * resources: Honor Retry-After header in resources.GetRemote retries * warpc: Move to parson.c in https://github.com/kgabis/parson * config/security: Add AllowChildProcess to security.node.permissions * config/security: Restrict default http.urls "@" deny to userinfo * releaser: Prepare repository for 0.162.0-DEV * releaser: Bump versions for release of 0.161.0 * build(deps): bump github.com/getkin/kin-openapi from 0.135.0 to 0.137.0 * build(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.12 to 2.24.13 * css: Support nested hugo:vars/ imports * github: Update GitHub actions versions * hugolib: Do not render aliases if the page is not rendered * langs/i18n: Improve default content language fallback * Replace deprecated .Site.Sites/.Page.Sites with hugo.Sites intests * helpers: Remove unused code * common/constants: Remove unused consts * common/paths: Remove unused code * langs/i18n: Fix translation lookup when using language variants * tests: Update Ruby setup action to v1.305.0 * build(deps): bump github.com/magefile/mage from 1.17.1 to 1.17.2 * deps: Upgrade github.com/bep/imagemeta v0.17.1 => v0.17.2 * langs: Use Language.Locale as primary localization key * config/security: Add "! " negation to Whitelist, harden default http.urls * build(deps): bump github.com/aws/aws-sdk-go-v2/service/cloudfront (#14789) * build(deps): bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21 (#14788) * build(deps): bump github.com/bep/mclib (#14787) * Harden Node tool execution with --permission flag * tpl/collections: Honor the Eqer interface in where comparisons * build(deps): bump google.golang.org/api from 0.267.0 to 0.276.0 * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.41.5 to 1.41.6 * modules: Ignore non-require blocks in go.mod rewrite * Replace the concurrent map with an identical upstream version * build(deps): bump github.com/getkin/kin-openapi from 0.134.0 to 0.135.0 (#14781) * build(deps): bump github.com/bep/goportabletext from 0.1.0 to 0.2.0 (#14779) * build(deps): bump golang.org/x/image from 0.38.0 to 0.39.0 (#14780) * deps: Upgrade github.com/bep/imagemeta v0.17.0 => v0.17.1 (#14775) * Add slice-based permalinks config with PageMatcher target * commands: Add missing import * Revert "common/hugo: Deprecate extended and extended_withdeploy editions" * Adjust the SECURITY.md slightly * create: Fix non-deterministic conflict detection in hugo new content * build(deps): bump golang.org/x/tools from 0.43.0 to 0.44.0 * resources/page: Add passing test for Issue #14325 * agents: Add a note about having the issue ID in test names * commands: Fix environment isolation for configuration settings * build(deps): bump github.com/evanw/esbuild from 0.27.4 to 0.28.0 * build(deps): bump github.com/aws/aws-sdk-go-v2 from 1.41.1 to 1.41.5 * build(deps): bump github.com/pelletier/go-toml/v2 from 2.2.4 to 2.3.0 * build(deps): bump github.com/tdewolff/minify/v2 from 2.24.11 to 2.24.12 * Fix filename dimension identifiers (_role_X_, _version_X_) to replace mount config * Add a more flexible filename identifier scheme that also allows setting roles and versions (#14754) * Fix it so we never auto-fallback to page resources in other roles/versions * common/hugo: Deprecate extended and extended_withdeploy editions * parser/pageparser: Add a parser fuzz test * releaser: Bump versions for release of 0.160.1 * Fix panic when passthrough elements are used in headings * Fix panic on edit of legacy mapped template names that's also a valid path in the new setup * Fix RenderShortcodes leaking context markers when indented * Strip nested page context markers from standalone RenderShortcodes * Rename deprecated cascade._target to cascade.target in tests * Fix auto-creation of root sections in multilingual sites * readme: Fix links * releaser: Prepare repository for 0.161.0-DEV ++++ kernel-source: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-source: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-source: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-docs: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-docs: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-docs: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-kvmsmall: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-kvmsmall: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-kvmsmall: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-obs-build: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-obs-build: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-obs-build: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-obs-qa: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-obs-qa: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-obs-qa: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-syms: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-syms: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-syms: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-zfcpdump: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-zfcpdump: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ kernel-zfcpdump: - btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() (CVE-2026-31666 bsc#1263138). - commit e74f8c2 - btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (CVE-2026-31519 bsc#1263012). - commit 8e45f1b - netfs: Fix read abandonment during retry (CVE-2026-31435 bsc#1262601). - commit fd2ee6f - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - spi: cadence: fix unclocked access on unbind (git-fixes). - spi: rockchip: Read ISR, not IMR, to detect cs-inactive IRQ (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - commit 5a35487 - rds: ib: reject FRMR registration before IB connection is established (CVE-2026-31425 bsc#1262074). - bridge: mrp: reject zero test interval to avoid OOM panic (CVE-2026-31420 bsc#1262055). - net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (CVE-2026-31411 bsc#1261752). - commit e9e6eaa - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - commit b9f0fc5 - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ACPI: video: Move Lenovo Legion S7 15ACH6 quirk to the right section (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - commit 1cbf4e0 ++++ sssd: - Reduce the message severity logged when the LDAP server hosts multiple naming contexts without defining a default one in the rootdse; (bsc#1264185); Add patch 0016-sdap-Reduce-log-level-when-get_naming_context-fails.patch - Do not ignore tests result at build time; (bsc#1246196); - Skip tests depending on soft-hsm; Add patch 0015-TESTS-Disable-pam-srv-and-certmap-cmocka-tests.patch ++++ tree-sitter: - We actually don’t provide lower version APIs and it is not right to claim so. Also, packages linking to this library will ignore it anyway. ++++ tree-sitter: - We actually don’t provide lower version APIs and it is not right to claim so. Also, packages linking to this library will ignore it anyway. ++++ mcp-server-systemd: - update to v0.3.4 which only added the man tool is man is available ++++ openCryptoki: - Applied an updated patch provided by IBM (bsc#1263819 (CVE-2026-40253)) * openCryptoki-CVE-2026-40253-commit-ed378f4.patch ++++ openCryptoki: - Applied an updated patch provided by IBM (bsc#1263819 (CVE-2026-40253)) * openCryptoki-CVE-2026-40253-commit-ed378f4.patch ++++ openQA: - Update to version 5.1777888278.38a3a85c: * style: Enforce perlcritic policy ProhibitUselessTopic * style: Enforce perlcritic policy BuiltinFunctions::RequireBlockGrep ++++ openQA: - Update to version 5.1777888278.38a3a85c: * style: Enforce perlcritic policy ProhibitUselessTopic * style: Enforce perlcritic policy BuiltinFunctions::RequireBlockGrep ++++ openQA: - Update to version 5.1777888278.38a3a85c: * style: Enforce perlcritic policy ProhibitUselessTopic * style: Enforce perlcritic policy BuiltinFunctions::RequireBlockGrep ++++ os-autoinst: - Update to version 5.1777891128.f572829: * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * fix(test): handle D-Bus AccessDenied in Open vSwitch test ++++ os-autoinst: - Update to version 5.1777891128.f572829: * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * fix(test): handle D-Bus AccessDenied in Open vSwitch test ++++ os-autoinst: - Update to version 5.1777891128.f572829: * fix: handle pre-marker pending text in script_output * fix: echo json_cmd_token in isotovideo responses * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * fix(test): handle D-Bus AccessDenied in Open vSwitch test ++++ python-pyOpenSSL: - CVE-2026-40475: improper input handling of null bytes can lead to silent data truncation and security-state inconsistency (bsc#1262803) * CVE-2026-40475.patch ++++ rear29a: - bsc1246136-fixes-for-SLE16.patch is https://github.com/rear/rear/commit/f7fb5211e6b22ba351e33d8d6f1dbfcfc3336eb3 from the ReaR upstream pull request https://github.com/rear/rear/pull/3569 that fixes the ReaR upstream issue https://github.com/rear/rear/issues/3567 (bsc#1246136) - For SLE 16 and openSUSE Leap 16.x and openSUSE Factory specify OS_VERSION="16" in /etc/rear/os.conf ------------------------------------------------------------------ ------------------ 2026-5-3 - May 3 2026 ------------------- ------------------------------------------------------------------ ++++ coredns: - Update to version 1.14.3: * This release introduces Windows service support, along with full TSIG verification across DoH, DoH3, QUIC, and gRPC transports, and improved TSIG propagation and DoH request validation. * It also adds optional TLS for the metrics endpoint. * Performance and stability are improved through cache prefetching, QUIC optimizations, and a new max_age option in the forward plugin. * Additional updates include enhanced SVCB/HTTPS support, improved zone transfer behavior, and various DNSSEC, PROXY protocol, and concurrency fixes. * The release is built with Go 1.26.2, which includes security fixes addressing CVE-2026-32282, CVE-2026-32289, CVE-2026-33810, CVE-2026-27144, CVE-2026-27143, CVE-2026-32288, CVE-2026-32283, and CVE-2026-27140, and also includes fixes for CVE-2026-32936, CVE-2026-33190, CVE-2026-33489, CVE-2026-32934, and CVE-2026-35579. ++++ coredns: - Update to version 1.14.3: * This release introduces Windows service support, along with full TSIG verification across DoH, DoH3, QUIC, and gRPC transports, and improved TSIG propagation and DoH request validation. * It also adds optional TLS for the metrics endpoint. * Performance and stability are improved through cache prefetching, QUIC optimizations, and a new max_age option in the forward plugin. * Additional updates include enhanced SVCB/HTTPS support, improved zone transfer behavior, and various DNSSEC, PROXY protocol, and concurrency fixes. * The release is built with Go 1.26.2, which includes security fixes addressing CVE-2026-32282, CVE-2026-32289, CVE-2026-33810, CVE-2026-27144, CVE-2026-27143, CVE-2026-32288, CVE-2026-32283, and CVE-2026-27140, and also includes fixes for CVE-2026-32936, CVE-2026-33190, CVE-2026-33489, CVE-2026-32934, and CVE-2026-35579. ++++ helmfile: - Update to version 1.4.5: * build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 by @dependabot[bot] in #2524 * chore: rename variables to match in apply and sync by @ceriath in #2521 * chore: bump Helm to v4.1.4 by @Copilot in #2525 * build(deps): bump golang.org/x/term from 0.41.0 to 0.42.0 by @dependabot[bot] in #2529 * bump helm v3.20.1 to v3.20.2 by @Copilot in #2530 * build(deps): bump github.com/helmfile/vals from 0.43.8 to 0.43.9 by @dependabot[bot] in #2533 * Update Go from 1.25.8 to 1.26.2 by @Copilot in #2535 * fix: boolean false overrides dropped in multi-document helmfiles (#2527) by @yxxhero in #2532 * build(deps): bump github.com/helmfile/chartify from 0.26.2 to 0.26.3 by @dependabot[bot] in #2538 * fix: add mutex lock for concurrent rewriteChartDependencies access by @yxxhero in #2509 * fix: update state values files handling to replace arrays instead of merging by @Moglum in #2537 * fix: helmDefaults.postRendererArgs not passed to helm commands by @yxxhero in #2510 * enabledns flags available on template command by @Diliz in #2511 * build(deps): bump k8s.io/apimachinery from 0.35.3 to 0.35.4 by @dependabot[bot] in #2540 * build(deps): bump k8s.io/client-go from 0.35.3 to 0.35.4 by @dependabot[bot] in #2539 * build(deps): bump github.com/zclconf/go-cty from 1.18.0 to 1.18.1 by @dependabot[bot] in #2542 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.14 to 1.32.15 by @dependabot[bot] in #2543 * fix: eliminate race condition in rewriteChartDependencies by @yxxhero in #2541 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.0 to 1.99.1 by @dependabot[bot] in #2546 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.15 to 1.32.16 by @dependabot[bot] in #2547 * build(deps): bump k8s.io/apimachinery from 0.35.4 to 0.36.0 by @dependabot[bot] in #2553 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.1 to 1.100.0 by @dependabot[bot] in #2552 * Fix helmfile init failing to update outdated helm plugins with Helm v4 by @Copilot in #2554 * fix: skip subhelmfiles when selectors conflict with CLI selectors by @yxxhero in #2545 * build(deps): bump gitpython from 3.1.41 to 3.1.47 in /docs by @dependabot[bot] in #2555 * fix: apply post-renderer to output-dir-template output by @yxxhero in #2531 * build(deps): bump go.uber.org/zap from 1.27.1 to 1.28.0 by @dependabot[bot] in #2557 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.0 to 1.100.1 by @dependabot[bot] in #2558 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.16 to 1.32.17 by @dependabot[bot] in #2559 * update readme add install from source by @Sianao in #2561 * Honor skipSchemaValidation during chartification when forceNamespace is set by @Copilot in #2550 * build(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 by @dependabot[bot] in #2565 * fix: deduplicate chart dependencies in helmfile.lock by @yxxhero in #2567 * build(deps): replace werf/kubedog-for-werf-helm with werf/kubedog by @yxxhero in #2568 * build(deps): bump helmfile/vals from v0.43.9 to v0.44.0 by @yxxhero in #2569 * fix: use --post-renderer-args=VALUE format to prevent Helm flag parsing failure by @yxxhero in #2570 - Update to golang(API) 1.26. ++++ helmfile: - Update to version 1.4.5: * build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 by @dependabot[bot] in #2524 * chore: rename variables to match in apply and sync by @ceriath in #2521 * chore: bump Helm to v4.1.4 by @Copilot in #2525 * build(deps): bump golang.org/x/term from 0.41.0 to 0.42.0 by @dependabot[bot] in #2529 * bump helm v3.20.1 to v3.20.2 by @Copilot in #2530 * build(deps): bump github.com/helmfile/vals from 0.43.8 to 0.43.9 by @dependabot[bot] in #2533 * Update Go from 1.25.8 to 1.26.2 by @Copilot in #2535 * fix: boolean false overrides dropped in multi-document helmfiles (#2527) by @yxxhero in #2532 * build(deps): bump github.com/helmfile/chartify from 0.26.2 to 0.26.3 by @dependabot[bot] in #2538 * fix: add mutex lock for concurrent rewriteChartDependencies access by @yxxhero in #2509 * fix: update state values files handling to replace arrays instead of merging by @Moglum in #2537 * fix: helmDefaults.postRendererArgs not passed to helm commands by @yxxhero in #2510 * enabledns flags available on template command by @Diliz in #2511 * build(deps): bump k8s.io/apimachinery from 0.35.3 to 0.35.4 by @dependabot[bot] in #2540 * build(deps): bump k8s.io/client-go from 0.35.3 to 0.35.4 by @dependabot[bot] in #2539 * build(deps): bump github.com/zclconf/go-cty from 1.18.0 to 1.18.1 by @dependabot[bot] in #2542 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.14 to 1.32.15 by @dependabot[bot] in #2543 * fix: eliminate race condition in rewriteChartDependencies by @yxxhero in #2541 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.0 to 1.99.1 by @dependabot[bot] in #2546 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.15 to 1.32.16 by @dependabot[bot] in #2547 * build(deps): bump k8s.io/apimachinery from 0.35.4 to 0.36.0 by @dependabot[bot] in #2553 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.1 to 1.100.0 by @dependabot[bot] in #2552 * Fix helmfile init failing to update outdated helm plugins with Helm v4 by @Copilot in #2554 * fix: skip subhelmfiles when selectors conflict with CLI selectors by @yxxhero in #2545 * build(deps): bump gitpython from 3.1.41 to 3.1.47 in /docs by @dependabot[bot] in #2555 * fix: apply post-renderer to output-dir-template output by @yxxhero in #2531 * build(deps): bump go.uber.org/zap from 1.27.1 to 1.28.0 by @dependabot[bot] in #2557 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.0 to 1.100.1 by @dependabot[bot] in #2558 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.16 to 1.32.17 by @dependabot[bot] in #2559 * update readme add install from source by @Sianao in #2561 * Honor skipSchemaValidation during chartification when forceNamespace is set by @Copilot in #2550 * build(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 by @dependabot[bot] in #2565 * fix: deduplicate chart dependencies in helmfile.lock by @yxxhero in #2567 * build(deps): replace werf/kubedog-for-werf-helm with werf/kubedog by @yxxhero in #2568 * build(deps): bump helmfile/vals from v0.43.9 to v0.44.0 by @yxxhero in #2569 * fix: use --post-renderer-args=VALUE format to prevent Helm flag parsing failure by @yxxhero in #2570 - Update to golang(API) 1.26. ++++ helmfile: - Update to version 1.4.5: * build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 by @dependabot[bot] in #2524 * chore: rename variables to match in apply and sync by @ceriath in #2521 * chore: bump Helm to v4.1.4 by @Copilot in #2525 * build(deps): bump golang.org/x/term from 0.41.0 to 0.42.0 by @dependabot[bot] in #2529 * bump helm v3.20.1 to v3.20.2 by @Copilot in #2530 * build(deps): bump github.com/helmfile/vals from 0.43.8 to 0.43.9 by @dependabot[bot] in #2533 * Update Go from 1.25.8 to 1.26.2 by @Copilot in #2535 * fix: boolean false overrides dropped in multi-document helmfiles (#2527) by @yxxhero in #2532 * build(deps): bump github.com/helmfile/chartify from 0.26.2 to 0.26.3 by @dependabot[bot] in #2538 * fix: add mutex lock for concurrent rewriteChartDependencies access by @yxxhero in #2509 * fix: update state values files handling to replace arrays instead of merging by @Moglum in #2537 * fix: helmDefaults.postRendererArgs not passed to helm commands by @yxxhero in #2510 * enabledns flags available on template command by @Diliz in #2511 * build(deps): bump k8s.io/apimachinery from 0.35.3 to 0.35.4 by @dependabot[bot] in #2540 * build(deps): bump k8s.io/client-go from 0.35.3 to 0.35.4 by @dependabot[bot] in #2539 * build(deps): bump github.com/zclconf/go-cty from 1.18.0 to 1.18.1 by @dependabot[bot] in #2542 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.14 to 1.32.15 by @dependabot[bot] in #2543 * fix: eliminate race condition in rewriteChartDependencies by @yxxhero in #2541 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.0 to 1.99.1 by @dependabot[bot] in #2546 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.15 to 1.32.16 by @dependabot[bot] in #2547 * build(deps): bump k8s.io/apimachinery from 0.35.4 to 0.36.0 by @dependabot[bot] in #2553 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.1 to 1.100.0 by @dependabot[bot] in #2552 * Fix helmfile init failing to update outdated helm plugins with Helm v4 by @Copilot in #2554 * fix: skip subhelmfiles when selectors conflict with CLI selectors by @yxxhero in #2545 * build(deps): bump gitpython from 3.1.41 to 3.1.47 in /docs by @dependabot[bot] in #2555 * fix: apply post-renderer to output-dir-template output by @yxxhero in #2531 * build(deps): bump go.uber.org/zap from 1.27.1 to 1.28.0 by @dependabot[bot] in #2557 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.0 to 1.100.1 by @dependabot[bot] in #2558 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.16 to 1.32.17 by @dependabot[bot] in #2559 * update readme add install from source by @Sianao in #2561 * Honor skipSchemaValidation during chartification when forceNamespace is set by @Copilot in #2550 * build(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 by @dependabot[bot] in #2565 * fix: deduplicate chart dependencies in helmfile.lock by @yxxhero in #2567 * build(deps): replace werf/kubedog-for-werf-helm with werf/kubedog by @yxxhero in #2568 * build(deps): bump helmfile/vals from v0.43.9 to v0.44.0 by @yxxhero in #2569 * fix: use --post-renderer-args=VALUE format to prevent Helm flag parsing failure by @yxxhero in #2570 - Update to golang(API) 1.26. ++++ helmfile: - Update to version 1.4.5: * build(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 by @dependabot[bot] in #2524 * chore: rename variables to match in apply and sync by @ceriath in #2521 * chore: bump Helm to v4.1.4 by @Copilot in #2525 * build(deps): bump golang.org/x/term from 0.41.0 to 0.42.0 by @dependabot[bot] in #2529 * bump helm v3.20.1 to v3.20.2 by @Copilot in #2530 * build(deps): bump github.com/helmfile/vals from 0.43.8 to 0.43.9 by @dependabot[bot] in #2533 * Update Go from 1.25.8 to 1.26.2 by @Copilot in #2535 * fix: boolean false overrides dropped in multi-document helmfiles (#2527) by @yxxhero in #2532 * build(deps): bump github.com/helmfile/chartify from 0.26.2 to 0.26.3 by @dependabot[bot] in #2538 * fix: add mutex lock for concurrent rewriteChartDependencies access by @yxxhero in #2509 * fix: update state values files handling to replace arrays instead of merging by @Moglum in #2537 * fix: helmDefaults.postRendererArgs not passed to helm commands by @yxxhero in #2510 * enabledns flags available on template command by @Diliz in #2511 * build(deps): bump k8s.io/apimachinery from 0.35.3 to 0.35.4 by @dependabot[bot] in #2540 * build(deps): bump k8s.io/client-go from 0.35.3 to 0.35.4 by @dependabot[bot] in #2539 * build(deps): bump github.com/zclconf/go-cty from 1.18.0 to 1.18.1 by @dependabot[bot] in #2542 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.14 to 1.32.15 by @dependabot[bot] in #2543 * fix: eliminate race condition in rewriteChartDependencies by @yxxhero in #2541 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.0 to 1.99.1 by @dependabot[bot] in #2546 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.15 to 1.32.16 by @dependabot[bot] in #2547 * build(deps): bump k8s.io/apimachinery from 0.35.4 to 0.36.0 by @dependabot[bot] in #2553 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.99.1 to 1.100.0 by @dependabot[bot] in #2552 * Fix helmfile init failing to update outdated helm plugins with Helm v4 by @Copilot in #2554 * fix: skip subhelmfiles when selectors conflict with CLI selectors by @yxxhero in #2545 * build(deps): bump gitpython from 3.1.41 to 3.1.47 in /docs by @dependabot[bot] in #2555 * fix: apply post-renderer to output-dir-template output by @yxxhero in #2531 * build(deps): bump go.uber.org/zap from 1.27.1 to 1.28.0 by @dependabot[bot] in #2557 * build(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.100.0 to 1.100.1 by @dependabot[bot] in #2558 * build(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.32.16 to 1.32.17 by @dependabot[bot] in #2559 * update readme add install from source by @Sianao in #2561 * Honor skipSchemaValidation during chartification when forceNamespace is set by @Copilot in #2550 * build(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 by @dependabot[bot] in #2565 * fix: deduplicate chart dependencies in helmfile.lock by @yxxhero in #2567 * build(deps): replace werf/kubedog-for-werf-helm with werf/kubedog by @yxxhero in #2568 * build(deps): bump helmfile/vals from v0.43.9 to v0.44.0 by @yxxhero in #2569 * fix: use --post-renderer-args=VALUE format to prevent Helm flag parsing failure by @yxxhero in #2570 - Update to golang(API) 1.26. ++++ nvidia-open-driver-G06-signed-cuda: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ++++ nvidia-open-driver-G07-signed-cuda: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ++++ nvidia-open-driver-G07-signed-cuda: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ++++ nvidia-open-driver-G07-signed-cuda: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ++++ nvidia-open-driver-G06-signed: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ++++ nvidia-open-driver-G07-signed: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ++++ nvidia-open-driver-G07-signed: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ++++ nvidia-open-driver-G07-signed: - fix-objtool-warnings.patch (not applied on aarch64) * Get rid of "'naked' return found in MITIGATION_RETHUNK build" objtool warnings (boo#1212841, boo#1263834) - remove again disable-objtool-override.patch ------------------------------------------------------------------ ------------------ 2026-5-1 - May 1 2026 ------------------- ------------------------------------------------------------------ ++++ kernel-64kb: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-64kb: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-64kb: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-64kb: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-64kb: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-64kb: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-64kb: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-azure: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-azure: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-azure: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-azure: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-azure: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-azure: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-azure: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-default: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-default: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-default: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-default: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-default: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-default: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-default: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-rt: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-rt: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-rt: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-rt: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-rt: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-rt: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-rt: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ dtb-aarch64: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ dtb-aarch64: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ dtb-aarch64: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ dtb-aarch64: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ dtb-aarch64: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ dtb-aarch64: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ dtb-aarch64: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-source: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-source: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-source: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-source: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-source: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-source: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-source: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-docs: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-docs: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-docs: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-docs: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-docs: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-docs: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-docs: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-kvmsmall: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-kvmsmall: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-kvmsmall: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-kvmsmall: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-kvmsmall: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-kvmsmall: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-kvmsmall: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-build: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-build: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-build: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-build: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-build: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-build: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-build: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-qa: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-qa: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-qa: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-qa: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-qa: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-qa: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-obs-qa: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-syms: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-syms: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-syms: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-syms: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-syms: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-syms: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-syms: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-zfcpdump: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-zfcpdump: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-zfcpdump: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-zfcpdump: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-zfcpdump: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-zfcpdump: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ kernel-zfcpdump: - crypto: authencesn - Fix src offset when decrypting in-place (bsc#1262573 CVE-2026-31431). - commit 66d7b47 - crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption (bsc#1262573 CVE-2026-31431). - commit d5fe1c6 - crypto: authenc - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - Refresh patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch - commit 3e7ba77 ++++ openQA: - Update to version 5.1777617029.fd9e1e69: * style: Enforce perlcritic policy ProhibitSingleCharAlternation * fix(apparmor): Add jsonnet to worker profile * style: Enforce perlcritic policy CodeLayout::ProhibitQuotedWordLists * style: Enforce perlcritic policy RequireNumberSeparators * build(deps-dev): bump eslint from 10.1.0 to 10.2.1 * style: Enforce perlcritic policy Variables::ProhibitUnusedVariables * feat: Ensure temporary directory exists when caching assets * fix(docs): fix mobile view rendering by ensuring CSS override * chore(lint): extend stylelint to cover documentation CSS * refactor: break down create_from_settings into smaller functions * feat: automatically add configurable worker classes to jobs ++++ openQA: - Update to version 5.1777617029.fd9e1e69: * style: Enforce perlcritic policy ProhibitSingleCharAlternation * fix(apparmor): Add jsonnet to worker profile * style: Enforce perlcritic policy CodeLayout::ProhibitQuotedWordLists * style: Enforce perlcritic policy RequireNumberSeparators * build(deps-dev): bump eslint from 10.1.0 to 10.2.1 * style: Enforce perlcritic policy Variables::ProhibitUnusedVariables * feat: Ensure temporary directory exists when caching assets * fix(docs): fix mobile view rendering by ensuring CSS override * chore(lint): extend stylelint to cover documentation CSS * refactor: break down create_from_settings into smaller functions * feat: automatically add configurable worker classes to jobs ++++ openQA: - Update to version 5.1777617029.fd9e1e69: * style: Enforce perlcritic policy ProhibitSingleCharAlternation * fix(apparmor): Add jsonnet to worker profile * style: Enforce perlcritic policy CodeLayout::ProhibitQuotedWordLists * style: Enforce perlcritic policy RequireNumberSeparators * build(deps-dev): bump eslint from 10.1.0 to 10.2.1 * style: Enforce perlcritic policy Variables::ProhibitUnusedVariables * feat: Ensure temporary directory exists when caching assets * fix(docs): fix mobile view rendering by ensuring CSS override * chore(lint): extend stylelint to cover documentation CSS * refactor: break down create_from_settings into smaller functions * feat: automatically add configurable worker classes to jobs ++++ susedialog: - Update to version 20260501.3969402: * Add gettext support with initial set of 30 langs * Improve gauge example which looked bit stuck * Use examples.gif from the project * Add examples of all features * Add dialog-compatible gauge and radiolist support * Same termination experience as with dialog * Document user config and ctrl+t a11y toggle * Add 'infobox' to widgets list in README ++++ syft: - Update to version 1.44.0: * Added Features - Add support for linux-riscv64 [#4757 @luhenry] * Bug Fixes - Yarn lockfile cataloguing does not handle aliases [#4833 [#4836] @cyphercodes] - Some snippet files are saved in the previous test directory [#4829 #4830 @witchcraze] - empty rockspec causes index out of range [#4824 #4827 @aki1770-del] - PE cataloger shows asp.net core ref assemblies using fileversion build stamp instead of productversion [#4813 [#4814] @rezmoss] - Syft safeCopy silently swallows archive decompression errors [#4806 #4807 @SAY-5] ------------------------------------------------------------------ ------------------ 2026-4-30 - Apr 30 2026 ------------------- ------------------------------------------------------------------ ++++ kernel-64kb: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-64kb: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-64kb: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-64kb: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-64kb: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-64kb: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-64kb: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-azure: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-azure: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-azure: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-azure: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-azure: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-azure: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-azure: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-default: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-default: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-default: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-default: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-default: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-default: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-default: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-rt: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-rt: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-rt: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-rt: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-rt: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-rt: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-rt: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ containerd: - Add patch for CVE-2026-33186 (bsc#1260296): * 0002-CVE-2026-33186-containerd-google.golang.org-grpc-aut.patch ++++ dtb-aarch64: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ dtb-aarch64: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ dtb-aarch64: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ dtb-aarch64: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ dtb-aarch64: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ dtb-aarch64: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ dtb-aarch64: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ gleam: - Update to 1.16.0: * Changelog v1.16.0: https://gleam.run/news/javascript-source-maps/ ++++ gn: - Update to version 0.20260429: * Run update reference in CI * Add `gn suggest` subcommand. * Update documentation * [apple] Optimise enumeration of additional files for Xcode project * [gn] Split SOURCE_SET phony targets to exclude additional outputs from linking * Run formatter in CI * Rework update_reference.sh to run correctly in CI. * IWYU: gn/target.h * Revert "Run formatter and update reference in CI" * Revert "Fix: Ensure only actual object files are included in link inputs" * Run formatter and update reference in CI * Add --diff to run_formatter and update_reference * Fix: Ensure only actual object files are included in link inputs * Run `infra/recipes.py test train`. * Improve EXPECT_EQ diff printing * Simplify success expectations in GN. * Add support for c_additional_outputs in config * Add diffs to EXPECT_EQ. * Advertise QtCreator v20+ built-in GN support * Rename impl:$MODULE to $MODULE_Private. * Only output -fmodule-map-file for the root generated modulemap. * Add function `expand_directory` to gn. * Refactor ModuleType from an enum to a bitset. * Generate two modulemaps per target. * Put dependencies in modulemaps * Run formatter * Include your own modulemap files in module_deps_no_self. * Change default module name in GN to be the full label. ++++ kernel-source: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-source: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-source: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-source: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-source: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-source: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-source: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-docs: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-docs: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-docs: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-docs: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-docs: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-docs: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-docs: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-kvmsmall: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-kvmsmall: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-kvmsmall: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-kvmsmall: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-kvmsmall: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-kvmsmall: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-kvmsmall: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-obs-build: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-build: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-build: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-build: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-build: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-obs-build: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-obs-build: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-obs-qa: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-qa: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-qa: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-qa: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-obs-qa: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-obs-qa: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-obs-qa: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-syms: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-syms: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-syms: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-syms: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-syms: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-syms: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-syms: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-zfcpdump: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-zfcpdump: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-zfcpdump: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-zfcpdump: - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b ++++ kernel-zfcpdump: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-zfcpdump: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ kernel-zfcpdump: - kabi fix for "md/raid1: serialize overlap io for writemostly disk" (bsc#1261555). - commit 513848b - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573 CVE-2026-31431). - commit 748d5b2 - crypto: algif_aead - Revert to operating out-of-place (bsc#1262573 CVE-2026-31431). - commit 02b8598 - crypto: algif_aead - use memcpy_sglist() instead of null skciphe (bsc#1262573 CVE-2026-31431). - crypto: algif_aead - use memcpy_sglist() instead of null skcipher (bsc#1262573 CVE-2026-31431). - commit 28e785f - crypto: scatterwalk - Fix memcpy_sglist() to always succeed (bsc#1262573 CVE-2026-31431). - commit 620f22b - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431). - commit 429a54b - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - commit 45eb229 - md/raid1: fix the comparing region of interval tree (bsc#1261555). - commit ee6cef0 - x86/vmware: Parse MP tables for SEV-SNP enabled guests under VMware hypervisors (git-fixes). - commit 38c10be - Update patches.suse/virt-tdx-guest-Fix-handling-of-host-controlled-quote.patch (git-fixes CVE-2026-31470 bsc#1262665). - commit 294c5ed - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - net: mana: Move current_speed debugfs file to mana_init_port() (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - hv_sock: update outdated comment for renamed vsock_stream_recvmsg() (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - add mainline tag to mana patch - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - commit 5250ed2 - ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616 CVE-2026-31449). - commit 063bf67 - x86/tsx: Get the tsx= command line parameter with early_param() (bsc#1263044 bsc#1250951). - commit f6ec4ca - x86/tsx: Make tsx_ctrl_state static (bsc#1263044 bsc#1250951). - commit 8a63eed - Set CONFIG_INTEL_TSX_MODE to follow upstream AUTO default (bsc#1263044) Upstream is now using CONFIG_TSX_MODE_AUTO following upstream commit f8c7600d468b ("x86/tsx: Set default TSX mode to auto"). Flip the switch in our kernel to follow the upstream default and match recent SLE15 configurations. - commit 0e1fa3a ++++ leancrypto: - Calculate the FIPS HMAC for the leancrypto and the leancrypto-fips libraries. (bsc#1262399) ++++ leancrypto-kmp: - Calculate the FIPS HMAC for the leancrypto and the leancrypto-fips libraries. (bsc#1262399) ++++ postgresql18: - bsc#1263804: After dropping update-alternatives we have to package /usr/bin/pg_config as an actual symlink, not %ghost. - Fix spelling of build conditionals. ++++ libgcrypt: - CVE-2026-41990: libgcrypt: lack of bound check can lead to mishandling of Dilithium signing (bsc#1262693) * Added libgcrypt-CVE-2026-41990.patch ++++ pcg-c: - pcg 0.94 * initial package ++++ pcg-c: - pcg 0.94.1 * initial package ++++ wireshark: - Wireshark 4.4.15 * CVE-2026-5299: ICMPv6 dissector crash (bsc#1263757) * CVE-2026-5401: AFP dissector crash (bsc#1263756) * CVE-2026-5403: SBC audio codec crash (bsc#1263765) * CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766) * CVE-2026-5405: RDP dissector crash (bsc#1263767) * CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754) * CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753) * CVE-2026-5408: BT-DHT dissector crash (bsc#1263752) * CVE-2026-5409: Monero dissector crash (bsc#1263751) * CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750) * CVE-2026-5654: AMR-NB audio codec crash (bsc#1263749) * CVE-2026-5656: Profile import crash and possible code execution (bsc#1263809) * CVE-2026-5657: iLBC audio codec crash (bsc#1263747) * CVE-2026-6519: MBIM protocol dissector infinite loop (bsc#1263746) * CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop (bsc#1263745) * CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744) * CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743) * CVE-2026-6523: GNW protocol dissector infinite loop (bsc#1263742) * CVE-2026-6524: MySQL protocol dissector crash (bsc#1263741) * CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739) * CVE-2026-6529: iLBC audio codec crash (bsc#1263737) * CVE-2026-6530: DCP-ETSI protocol dissector crash (bsc#1263736) * CVE-2026-6531: SANE protocol dissector infinite loop (bsc#1263735) * CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734) * CVE-2026-6533: Dissection engine LZ77 decompression crash (bsc#1263733) * CVE-2026-6534: USB HID dissector infinite loop (bsc#1263732) * CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731) * CVE-2026-6537: ZigBee dissector crash (bsc#1263729) * CVE-2026-6538: BEEP dissector crash (bsc#1263728) * CVE-2026-6868: HTTP protocol dissector crash (bsc#1263762) * CVE-2026-6869: WebSocket protocol dissector crash (bsc#1263726) - Many more features, bug fixes and updated protocol support as listed in: https://www.wireshark.org/docs/relnotes/wireshark-4.4.15.html ++++ mcp-server-systemd: - update to v0.3.3 with following changes: * allow man page sections like 3p1 * call authorization before file access ++++ os-autoinst: - Update to version 5.1777537682.913fce0: * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * feat: disable storage check in CI environments * fix(test): handle D-Bus AccessDenied in Open vSwitch test * fix: Avoid restarting openvswitch/NM after OVS bridge setup * refactor: import IO::Socket::UNIX explicitly wherever is used ++++ os-autoinst: - Update to version 5.1777537682.913fce0: * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * feat: disable storage check in CI environments * fix(test): handle D-Bus AccessDenied in Open vSwitch test * fix: Avoid restarting openvswitch/NM after OVS bridge setup * refactor: import IO::Socket::UNIX explicitly wherever is used ++++ os-autoinst: - Update to version 5.1777537682.913fce0: * fix: re-install serial marker hook after console reset * fix: support pretty_serial_markers in script_output regex * feat: disable storage check in CI environments * fix(test): handle D-Bus AccessDenied in Open vSwitch test * fix: Avoid restarting openvswitch/NM after OVS bridge setup * refactor: import IO::Socket::UNIX explicitly wherever is used ++++ perl-Text-CSV_XS: - added patches CVE-2026-7111: Text:CSV_XS versions before 1.62 for Perl have a [bsc#1263690] * perl-Text-CSV_XS-CVE-2026-7111.patch ++++ postgresql14: - bsc#1263804: After dropping update-alternatives we have to package /usr/bin/pg_config as an actual symlink, not %ghost. - Fix spelling of build conditionals. ++++ postgresql15: - bsc#1263804: After dropping update-alternatives we have to package /usr/bin/pg_config as an actual symlink, not %ghost. - Fix spelling of build conditionals. ++++ postgresql16: - bsc#1263804: After dropping update-alternatives we have to package /usr/bin/pg_config as an actual symlink, not %ghost. - Fix spelling of build conditionals. ++++ postgresql17: - bsc#1263804: After dropping update-alternatives we have to package /usr/bin/pg_config as an actual symlink, not %ghost. - Fix spelling of build conditionals. ++++ postgresql18-mini: - bsc#1263804: After dropping update-alternatives we have to package /usr/bin/pg_config as an actual symlink, not %ghost. - Fix spelling of build conditionals. ++++ python-pytest: - CVE-2025-71176: Add patch CVE-2025-71176-do-not-follow-symlinks.patch: * Do not follow symlinks in temporary directories. (bsc#1257090) ++++ strongswan: - Update version to 6.0.6 (PED#16145) Vulnerabilities * CVE-2026-35328 - Fixed a vulnerability in libtls related to the processing of the supported_versions extension in TLS that can result in an infinite loop. Affects 5.9.2 and newer(bsc#1261712). * CVE-2026-35329 - Fixed a vulnerability in libstrongswan and the pkcs7 plugin related to the processing of encrypted PKCS#7(bsc#1261717) containers that can result in a crash. Affects 5.0.2 and newer. * CVE-2026-35330 - Fixed a vulnerability in libsimaka related to the processing of certain EAP-SIM/AKA attributes that can result in an infinite loop or a heap-based buffer overflow and potentially remote code execution. Affects 4.3.6 and newer.(bsc#1261705) * CVE-2026-35331 - Fixed a vulnerability in the constraints plugin related to the processing of X.509 name constraints that can allow authentication with certificates that violate the constraints. Affects 4.5.1 and newer.(bsc#1261718) * CVE-2026-35332 - Fixed a vulnerability in libtls related to the processing of ECDH public values in TLS < 1.3 that can result in a crash. Affects 4.5.0 and newer. (bsc#1261708) * CVE-2026-35333 - Fixed a vulnerability in libradius related to the processing of RADIUS attributes that can result in an infinite loop or an out-of-bounds read that may cause a crash. Affects 4.2.14 and newer.(bsc#1261706) * CVE-2026-35334 - Fixed a vulnerability in the gmp plugin related to RSA decryption that can result in a crash. Affects 4.3.2 and newer. (bsc#1261720) Enhancements and Optimizations Added the unique ID to the log messages when creating an IKE SA as responder and when deleting such a half-open SA The credential factory now enforces an upper limit of 10 when creating nested credentials. Added Georgian translation to the NM plugin. Fixes * IKEv2 fragments with a total fragment count lower than before are now dropped as mandated by the RFC . * Fixed a potential out-of-bounds read when parsing EAP-SIM/AKA attributes with actual length field. * Fixed a potential out-of-bounds read when enumerating hashes in OCSP CERTREQ payloads . * Fixed a potential crash in the vici plugin when parsing messages that encode the length of a VICI_LIST_ITEM incorrectly. * Avoid allocating a large buffer for TLS cipher suites on the stack using alloca() . Whether this could be a potential problem depends on the stack size per thread, on typical systems it shouldn't be an issue. * Ensure TLS 1.3 CertificateRequest structures are valid on the client. * Prevent an infinite loop if the EAP-SIM version list on the client contains more than one entry . * Fixed a crash in the tnccs_11 plugin if TNCCS-ReasonStrings is empty or only contains empty nodes . * Fixed verification of RSA signatures with SHA3-224 via botan plugin. * Close the internal IPv6 socket when a tun_device_t is destroyed . * Update the address family in the SA selector when the addresses of a tunnel mode IPsec SA change in the kernel-netlink plugin. Removed Patch * 0001-FIX-CVE-2026-25075-strongswan-Integer-Underflow-When.patch - Update to release 6.0.5 * Fixed a vulnerability in the eap-ttls plugin related to processing EAP-TTLS AVPs that can lead to resource exhaustion or a crash. [CVE-2026-25075] * The new `icmp` option enables the forwarding of certain ICMP error messages (e.g. Fragmentation Needed), even if their source address doesn't match the negotiated traffic selectors, when running on Linux kernels that support this (v6.9+). * charon-cmd now supports childless IKE SA initiation with the `--childless` option. * The dhcp plugin now keeps track of address leases across make-before-break reauthentications to avoid releasing the address when the old SA is terminated * Added support for `organizationIdentifier` RDNs, which are used in e.g. eIDAS certificates, when parsing ASN.1 DN identities from strings. ++++ strongswan: - Update version to 6.0.6 (PED#16145) Vulnerabilities * CVE-2026-35328 - Fixed a vulnerability in libtls related to the processing of the supported_versions extension in TLS that can result in an infinite loop. Affects 5.9.2 and newer(bsc#1261712). * CVE-2026-35329 - Fixed a vulnerability in libstrongswan and the pkcs7 plugin related to the processing of encrypted PKCS#7(bsc#1261717) containers that can result in a crash. Affects 5.0.2 and newer. * CVE-2026-35330 - Fixed a vulnerability in libsimaka related to the processing of certain EAP-SIM/AKA attributes that can result in an infinite loop or a heap-based buffer overflow and potentially remote code execution. Affects 4.3.6 and newer.(bsc#1261705) * CVE-2026-35331 - Fixed a vulnerability in the constraints plugin related to the processing of X.509 name constraints that can allow authentication with certificates that violate the constraints. Affects 4.5.1 and newer.(bsc#1261718) * CVE-2026-35332 - Fixed a vulnerability in libtls related to the processing of ECDH public values in TLS < 1.3 that can result in a crash. Affects 4.5.0 and newer. (bsc#1261708) * CVE-2026-35333 - Fixed a vulnerability in libradius related to the processing of RADIUS attributes that can result in an infinite loop or an out-of-bounds read that may cause a crash. Affects 4.2.14 and newer.(bsc#1261706) * CVE-2026-35334 - Fixed a vulnerability in the gmp plugin related to RSA decryption that can result in a crash. Affects 4.3.2 and newer. (bsc#1261720) Enhancements and Optimizations Added the unique ID to the log messages when creating an IKE SA as responder and when deleting such a half-open SA The credential factory now enforces an upper limit of 10 when creating nested credentials. Added Georgian translation to the NM plugin. Fixes * IKEv2 fragments with a total fragment count lower than before are now dropped as mandated by the RFC . * Fixed a potential out-of-bounds read when parsing EAP-SIM/AKA attributes with actual length field. * Fixed a potential out-of-bounds read when enumerating hashes in OCSP CERTREQ payloads . * Fixed a potential crash in the vici plugin when parsing messages that encode the length of a VICI_LIST_ITEM incorrectly. * Avoid allocating a large buffer for TLS cipher suites on the stack using alloca() . Whether this could be a potential problem depends on the stack size per thread, on typical systems it shouldn't be an issue. * Ensure TLS 1.3 CertificateRequest structures are valid on the client. * Prevent an infinite loop if the EAP-SIM version list on the client contains more than one entry . * Fixed a crash in the tnccs_11 plugin if TNCCS-ReasonStrings is empty or only contains empty nodes . * Fixed verification of RSA signatures with SHA3-224 via botan plugin. * Close the internal IPv6 socket when a tun_device_t is destroyed . * Update the address family in the SA selector when the addresses of a tunnel mode IPsec SA change in the kernel-netlink plugin. Removed Patch * 0001-FIX-CVE-2026-25075-strongswan-Integer-Underflow-When.patch - Update to release 6.0.5 * Fixed a vulnerability in the eap-ttls plugin related to processing EAP-TTLS AVPs that can lead to resource exhaustion or a crash. [CVE-2026-25075] * The new `icmp` option enables the forwarding of certain ICMP error messages (e.g. Fragmentation Needed), even if their source address doesn't match the negotiated traffic selectors, when running on Linux kernels that support this (v6.9+). * charon-cmd now supports childless IKE SA initiation with the `--childless` option. * The dhcp plugin now keeps track of address leases across make-before-break reauthentications to avoid releasing the address when the old SA is terminated * Added support for `organizationIdentifier` RDNs, which are used in e.g. eIDAS certificates, when parsing ASN.1 DN identities from strings. ------------------------------------------------------------------ ------------------ 2026-4-29 - Apr 29 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaThunderbird: - Further tests have shown that the rule which llvm version should be used, can be simplified: only on TW, Slowroll and Factory we need to explicitly BuildRequire the llvm21 based packages, while on all other (i.e. Leap) distribution versions we can stick with the distro's default release of llvm. - Mozilla Thunderbird 140.10.1 ESR MFSA 2026-39 (bsc#1263110) * CVE-2026-7320 (bmo#2027433) Information disclosure due to incorrect boundary conditions in the Audio/Video component * CVE-2026-7321 (bmo#2029461) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158, bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231, bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700, bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108, bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040) Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1 * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121, bmo#2033602) Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1 - added mozilla-bmo2031958.patch to fix incompatible pointer types (bmo#2031958) - Explicitly BuildIgnore: clang-tools to avoid pulling in the remaining llvm22 packages. Also add BuildRequire for libclang13 provided by the llvm version we use. - LLVM22 breaks building firefox-esr and MozillaThunderbird, restrict clang-devel to clang21-devel on TW, Slowroll and Factory. Use clang19-devel on all older distributions. ++++ alloy: - Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815) - CVE-2026-4427: Fix potential Go vuln in github.com/jackc/pgproto3 (bsc#1259919) * Add 0001-Bump-sql_exporter.patch - Use latest openSUSE Tumbleweed image for building web UI assets - Install nvm to set node version specified upstream ++++ alloy: - Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815) - CVE-2026-4427: Fix potential Go vuln in github.com/jackc/pgproto3 (bsc#1259919) * Add 0001-Bump-sql_exporter.patch - Use latest openSUSE Tumbleweed image for building web UI assets - Install nvm to set node version specified upstream ++++ alloy: - Use systemd tmpfiles.d to create /var/lib/alloy hierarchy (jsc#PED-14815) - CVE-2026-4427: Fix potential Go vuln in github.com/jackc/pgproto3 (bsc#1259919) * Add 0001-Bump-sql_exporter.patch - Use latest openSUSE Tumbleweed image for building web UI assets - Install nvm to set node version specified upstream ++++ amazon-ecs-init: - Update to version 1.103.0 * Enhancement - Golang bump: 1.25.9 (#4935) * Enhancement - Use env variable to read user input when mounting FSx volumes (#4934) * Enhancement - Enhancement - Replace SSM Dualstack endpoint resolution logic with UseDualStackEndpoint (#4931) * Enhancement - Emit duration metrics for TACS connect/disconnect (#4928) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream from 1.6.10 to 1.7.8 in /agent (#4922) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream from 1.6.5 to 1.7.8 in /ecs-init (#4925) * Enhancement - Track and emit metric for disconnect time from ACS (#4920) * Enhancement - engine: skip execution role checks when task desired status is stopped (#4918) * Enhancement - Add NeuronDevices type and sysfs-based device discovery (#4919) * Bugfix - Fix release workflow branch handling and add GitHub App token (#4929) * Bugfix - fix(netlib): Conditionally add IPv6 subnet to IPAM config when IPv6 (#4916) - from version 1.102.2 * Enhancement - Update SSM exec agent version to 3.3.4108.0 (#4912) * Enhancement - Update Go version to 1.25.8 (#4894) * Enhancement - Apply skip-gpg-check to both ecs-init and ssm agent (#4901) * Enhancement - Bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#4906) - Bump Go version to 1.25.9 ++++ rmt-server: - Version 3.0.alpha * Update Ruby to version 3.4.8 and Rails to version 7.1.6 ++++ bubblewrap: - Fix CVE-2026-41163 (bsc#1263113): + bubblewrap-dont-run-privilege-separated-code-bumpable.patch + bubblewrap-harden-privsep-parent.patch ++++ kernel-64kb: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-64kb: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-64kb: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-azure: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-azure: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-azure: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-default: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-default: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-default: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-rt: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-rt: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-rt: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ dealers-choice: - Add 0001-server-skip-buffered-MSG_PING_RESPONSE-at-game-start.patch (fixes s390x build / pool/dealers-choice/pulls/1#issuecomment-135113) ++++ dealers-choice: - Add 0001-server-skip-buffered-MSG_PING_RESPONSE-at-game-start.patch (fixes s390x build / pool/dealers-choice/pulls/1#issuecomment-135113) ++++ dealers-choice: - Add 0001-server-skip-buffered-MSG_PING_RESPONSE-at-game-start.patch (fixes s390x build / pool/dealers-choice/pulls/1#issuecomment-135113) ++++ dtb-aarch64: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ dtb-aarch64: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ dtb-aarch64: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ erlang: - CVE-2026-32147: erlang: Improper Limitation of a Pathname to a kRestricted Directory ('Path Traversal') in SFTP chroot (bsc#1262503) * fix-CVE-2026-32147.patch ++++ iproute2: - add netshaper support (bsc#1253044) * netshaper-Add-netshaper-command.patch * netshaper-update-include-files.patch * netshaper-fix-build-failure.patch * netshaper-remove-unused-variable.patch * netshaper-ignore-build-result.patch * netshaper-fix-grammar-and-style-issues-in-man-page.patch ++++ iproute2: - add netshaper support (bsc#1253044) * netshaper-Add-netshaper-command.patch * netshaper-update-include-files.patch * netshaper-fix-build-failure.patch * netshaper-remove-unused-variable.patch * netshaper-ignore-build-result.patch * netshaper-fix-grammar-and-style-issues-in-man-page.patch ++++ jline3: - Update to upstream version 3.30.11 * Bug Fixes + Add GraalVM native-image support for FFM terminal provider - Update to upstream version 3.30.10 * Bug Fixes + Catch LinkageError during provider loading + Prevent ArrayIndexOutOfBoundsException in KillRing.yankPop() + Fix off-by-one bounds check in KeyMap.unbind() + Handle EOF in color parsing to prevent infinite loop + Close HttpURLConnection in ConsoleEngineImpl.urlExists() + Guard AnsiConsole.providers() call to avoid NoSuchMethodError + Guard waitDirty against spurious wakeups + Restore waitDirty timeout in forced dump to prevent busy-loop spinning + Remove spurious (short) casts in Size setters + Fix AttributedStyle color chaining + Avoid NPE when closing terminal with null masterOutput + Close PTY streams before shutdown to prevent hang on macOS - Update to upstream version 3.30.9 * Bug Fixes + Suppress dumb terminal warning when no streams are TTYs In CI environments (like GitHub Actions), the "Unable to create a system terminal" warning is no longer emitted when falling back to a dumb terminal is expected because no TTY is available - Update to upstream version 3.30.8 * Bug Fixes + Fix JNI terminal failing to load on JDK 21.0.10+ - Module.isNativeAccessEnabled() was backported to some JDK 21 builds (e.g. 21.0.10), causing a false UnsupportedOperationException since the method returns false even though JNI works without --enable-native-access. JNI native access restrictions are only enforced from JDK 24+, so the check is now skipped on earlier versions. - Update to upstream version 3.30.7 * New Features & Improvements + Windows codepage auto-detection: Restored automatic detection of Windows console output codepage, fixing Unicode rendering issues since JLine 3.22 + MSYS2 environment detection: Expanded IS_MSYSTEM to detect all MSYS2 environments (UCRT64, CLANG64, CLANGARM64, MINGW32), fixing backspace in git-bash + JDK 24+ compatibility: Check native access before loading JNI library to prevent restricted method warnings + Unicode 16.0: Updated WCWidth character width tables to Unicode 16.0 + which command: Added which builtin command to ConsoleEngine + Display resize fix: Display.resize() now handles terminals with buffer wider than visible window + Terminal closure enforcement: Accessing terminal streams after close() now logs a warning by default, configurable via jline.terminal.closeMode property + Standard SPI: Terminal providers now use standard Java ServiceLoader for discovery + Key binding docs: Fixed incorrect example for binding terminal capabilities - use KeyMap.key() instead of raw getStringCapability() * Bug Fixes + Fix MenuSupport left/right navigation when GROUP_PERSIST is on + Fix StringIndexOutOfBoundsException in CompletionMatcherImpl + Fix doubled quotes when completing quoted words with multiple candidates + Fix ASCII fallback for box-drawing characters when alt charset is unsupported + Fix DefaultParser emitting trailing empty word for non-completion contexts + Fix Ctrl+C propagation as UserInterruptException in console-ui prompts + Fix newline binding for dumb terminal support in prompts + Fix BRACKETED_PASTE_OFF not sent when option is explicitly disabled + Fix terminal content preservation during resize with status bar + Fix inherited input stream being closed on Windows + Fix nested shell interruption handling + Fix Nano keypad state management + Fix auto-suggestion menu list not cleared when no completions match + Suppress IOException in PosixPtyTerminal pump threads during close + Do not raise native signals on Windows if not enabled + AnsiConsole now fails on repeated uninstalls + Allow single-digit options like -1 in Options parser + Fix setting line reader options via system properties + Support ls /, pseudo pipe operators, and ignore unknown pipe names ++++ jline3: - Update to upstream version 3.30.11 * Bug Fixes + Add GraalVM native-image support for FFM terminal provider - Update to upstream version 3.30.10 * Bug Fixes + Catch LinkageError during provider loading + Prevent ArrayIndexOutOfBoundsException in KillRing.yankPop() + Fix off-by-one bounds check in KeyMap.unbind() + Handle EOF in color parsing to prevent infinite loop + Close HttpURLConnection in ConsoleEngineImpl.urlExists() + Guard AnsiConsole.providers() call to avoid NoSuchMethodError + Guard waitDirty against spurious wakeups + Restore waitDirty timeout in forced dump to prevent busy-loop spinning + Remove spurious (short) casts in Size setters + Fix AttributedStyle color chaining + Avoid NPE when closing terminal with null masterOutput + Close PTY streams before shutdown to prevent hang on macOS - Update to upstream version 3.30.9 * Bug Fixes + Suppress dumb terminal warning when no streams are TTYs In CI environments (like GitHub Actions), the "Unable to create a system terminal" warning is no longer emitted when falling back to a dumb terminal is expected because no TTY is available - Update to upstream version 3.30.8 * Bug Fixes + Fix JNI terminal failing to load on JDK 21.0.10+ - Module.isNativeAccessEnabled() was backported to some JDK 21 builds (e.g. 21.0.10), causing a false UnsupportedOperationException since the method returns false even though JNI works without --enable-native-access. JNI native access restrictions are only enforced from JDK 24+, so the check is now skipped on earlier versions. - Update to upstream version 3.30.7 * New Features & Improvements + Windows codepage auto-detection: Restored automatic detection of Windows console output codepage, fixing Unicode rendering issues since JLine 3.22 + MSYS2 environment detection: Expanded IS_MSYSTEM to detect all MSYS2 environments (UCRT64, CLANG64, CLANGARM64, MINGW32), fixing backspace in git-bash + JDK 24+ compatibility: Check native access before loading JNI library to prevent restricted method warnings + Unicode 16.0: Updated WCWidth character width tables to Unicode 16.0 + which command: Added which builtin command to ConsoleEngine + Display resize fix: Display.resize() now handles terminals with buffer wider than visible window + Terminal closure enforcement: Accessing terminal streams after close() now logs a warning by default, configurable via jline.terminal.closeMode property + Standard SPI: Terminal providers now use standard Java ServiceLoader for discovery + Key binding docs: Fixed incorrect example for binding terminal capabilities - use KeyMap.key() instead of raw getStringCapability() * Bug Fixes + Fix MenuSupport left/right navigation when GROUP_PERSIST is on + Fix StringIndexOutOfBoundsException in CompletionMatcherImpl + Fix doubled quotes when completing quoted words with multiple candidates + Fix ASCII fallback for box-drawing characters when alt charset is unsupported + Fix DefaultParser emitting trailing empty word for non-completion contexts + Fix Ctrl+C propagation as UserInterruptException in console-ui prompts + Fix newline binding for dumb terminal support in prompts + Fix BRACKETED_PASTE_OFF not sent when option is explicitly disabled + Fix terminal content preservation during resize with status bar + Fix inherited input stream being closed on Windows + Fix nested shell interruption handling + Fix Nano keypad state management + Fix auto-suggestion menu list not cleared when no completions match + Suppress IOException in PosixPtyTerminal pump threads during close + Do not raise native signals on Windows if not enabled + AnsiConsole now fails on repeated uninstalls + Allow single-digit options like -1 in Options parser + Fix setting line reader options via system properties + Support ls /, pseudo pipe operators, and ignore unknown pipe names ++++ jline3: - Update to upstream version 3.30.11 * Bug Fixes + Add GraalVM native-image support for FFM terminal provider - Update to upstream version 3.30.10 * Bug Fixes + Catch LinkageError during provider loading + Prevent ArrayIndexOutOfBoundsException in KillRing.yankPop() + Fix off-by-one bounds check in KeyMap.unbind() + Handle EOF in color parsing to prevent infinite loop + Close HttpURLConnection in ConsoleEngineImpl.urlExists() + Guard AnsiConsole.providers() call to avoid NoSuchMethodError + Guard waitDirty against spurious wakeups + Restore waitDirty timeout in forced dump to prevent busy-loop spinning + Remove spurious (short) casts in Size setters + Fix AttributedStyle color chaining + Avoid NPE when closing terminal with null masterOutput + Close PTY streams before shutdown to prevent hang on macOS - Update to upstream version 3.30.9 * Bug Fixes + Suppress dumb terminal warning when no streams are TTYs In CI environments (like GitHub Actions), the "Unable to create a system terminal" warning is no longer emitted when falling back to a dumb terminal is expected because no TTY is available - Update to upstream version 3.30.8 * Bug Fixes + Fix JNI terminal failing to load on JDK 21.0.10+ - Module.isNativeAccessEnabled() was backported to some JDK 21 builds (e.g. 21.0.10), causing a false UnsupportedOperationException since the method returns false even though JNI works without --enable-native-access. JNI native access restrictions are only enforced from JDK 24+, so the check is now skipped on earlier versions. - Update to upstream version 3.30.7 * New Features & Improvements + Windows codepage auto-detection: Restored automatic detection of Windows console output codepage, fixing Unicode rendering issues since JLine 3.22 + MSYS2 environment detection: Expanded IS_MSYSTEM to detect all MSYS2 environments (UCRT64, CLANG64, CLANGARM64, MINGW32), fixing backspace in git-bash + JDK 24+ compatibility: Check native access before loading JNI library to prevent restricted method warnings + Unicode 16.0: Updated WCWidth character width tables to Unicode 16.0 + which command: Added which builtin command to ConsoleEngine + Display resize fix: Display.resize() now handles terminals with buffer wider than visible window + Terminal closure enforcement: Accessing terminal streams after close() now logs a warning by default, configurable via jline.terminal.closeMode property + Standard SPI: Terminal providers now use standard Java ServiceLoader for discovery + Key binding docs: Fixed incorrect example for binding terminal capabilities - use KeyMap.key() instead of raw getStringCapability() * Bug Fixes + Fix MenuSupport left/right navigation when GROUP_PERSIST is on + Fix StringIndexOutOfBoundsException in CompletionMatcherImpl + Fix doubled quotes when completing quoted words with multiple candidates + Fix ASCII fallback for box-drawing characters when alt charset is unsupported + Fix DefaultParser emitting trailing empty word for non-completion contexts + Fix Ctrl+C propagation as UserInterruptException in console-ui prompts + Fix newline binding for dumb terminal support in prompts + Fix BRACKETED_PASTE_OFF not sent when option is explicitly disabled + Fix terminal content preservation during resize with status bar + Fix inherited input stream being closed on Windows + Fix nested shell interruption handling + Fix Nano keypad state management + Fix auto-suggestion menu list not cleared when no completions match + Suppress IOException in PosixPtyTerminal pump threads during close + Do not raise native signals on Windows if not enabled + AnsiConsole now fails on repeated uninstalls + Allow single-digit options like -1 in Options parser + Fix setting line reader options via system properties + Support ls /, pseudo pipe operators, and ignore unknown pipe names ++++ kernel-source: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-source: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-source: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-docs: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-docs: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-docs: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-kvmsmall: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-kvmsmall: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-kvmsmall: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-obs-build: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-obs-build: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-obs-build: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-obs-qa: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-obs-qa: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-obs-qa: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-syms: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-syms: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-syms: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-zfcpdump: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-zfcpdump: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kernel-zfcpdump: - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - commit 0c4b00a - Update patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch (bsc#1255459 bsc#1256288 ltc#216797). - commit 95af467 - kABI workaround for struct uart_8250_port changes (bsc#1262480). - commit 74e0542 - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - commit e766d6d - Revert "serial: 8250: Switch to nbcon console" (bsc#1262480). - blacklist.conf: dropped - Refresh patches.suse/serial-8250-Touch_watchdog_in_write_atomic.patch. - commit 9a39429 - Revert "serial: 8250: Revert "drop lockdep annotation from serial8250_clear_IER()"" (bsc#1262480). - blacklist.conf: removed - commit ce204eb - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - commit 5338634 - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - commit 94e5300 ++++ kf6-kcoreaddons: - Add upstream fix (CVE-2026-41526, boo#1263441) * 0001-Remove-control-characters-when-quoting-args.patch ++++ sssd: - With the 2.10 update sssd runs under unprivileged user which is not possible in certain scenarios. This update reverts to run as root with minimum privileges; (bsc#1259436); Add patch 0012-run-as-root.patch - Let krb5 child tolerate missing capabilities; Add patch 0013-KRB5-let-krb5_child-tolerate-missing-cap-set-id.patch - Add support for UsrEtc; (bsc#1257643); Add patch 0014-UsrEtc.patch - The default configuration file is installed now in /usr/etc/sssd/sssd.conf. It can be completely overridden by manually creating the system specific config file /etc/sssd/sssd.conf, or partially overridden by creating config snippets in /etc/sssd/conf.d/ directory. Check sssd.conf manpage for more details. ++++ sssd: - With the 2.10 update sssd runs under unprivileged user which is not possible in certain scenarios. This update reverts to run as root with minimum privileges; (bsc#1259436); Add patch 0012-run-as-root.patch - Let krb5 child tolerate missing capabilities; Add patch 0013-KRB5-let-krb5_child-tolerate-missing-cap-set-id.patch - Add support for UsrEtc; (bsc#1257643); Add patch 0014-UsrEtc.patch - The default configuration file is installed now in /usr/etc/sssd/sssd.conf. It can be completely overridden by manually creating the system specific config file /etc/sssd/sssd.conf, or partially overridden by creating config snippets in /etc/sssd/conf.d/ directory. Check sssd.conf manpage for more details. ++++ mariadb: - Add MDEV-38811.patch * Fixes crash in information_schema.table_constraints when --skip-grant-tables (bsc#1263153) ++++ mariadb: - Add MDEV-38811.patch * Fixes crash in information_schema.table_constraints when --skip-grant-tables (bsc#1263153) ++++ libsodium: - Update to 1.0.22: (jsc#PED-16206) * Post-quantum key encapsulation is now available. ML-KEM768, the NIST-standardized lattice-based KEM, is accessible through the crypto_kem_mlkem768_*() functions. * X-Wing, a hybrid KEM combining ML-KEM768 with X25519 for protection against both classical and quantum adversaries, is available through the crypto_kem_*() functions. X-Wing is the recommended KEM for most applications. * SHA-3 hash functions are now available as crypto_hash_sha3256_*() and crypto_hash_sha3512_*(), with both one-shot and streaming APIs. * Performance: NEON optimizations for Argon2 on ARM platforms. * Performance: SHA3 (Keccak1600) now leverages ARM SHA3 instructions when available on ARM platforms. * Performance: WebAssembly SIMD implementations of Argon2 have been added. * XOF state alignment has been relaxed. * crypto_core_keccak1600_state has been added. * Export missing crypto_ipcrypt_nd_keygen() helper function. * crypto_auth_hmacsha256_init and crypto_auth_hmacsha512_init now accept NULL key pointers (with a zero key length), for consistency with other _init functions. * Fixed compilation with GCC on aarch64 and gcc 4.x. * On aarch64, aes256-gcm is now enabled even when not using clang, including MSVC. * Libsodium can be directly used as a dependency in a Zig project. * Remove patch libsodium-Fix-compilation-with-GCC-on-aarch64.patch ++++ openQA: - Update to version 5.1777474261.55e5cd5e: * build(deps): bump postcss from 8.5.8 to 8.5.12 * fix(apparmor): adjust the /usr/bin/ssh child profile for 16.x * fix: Fix rendering bugrefs as links in lists and other structures * feat: use full job group name for priority check by default * chore(AGENTS.md): refine coverage requirements * fix(apparmor): allow worker to execute "df" * feat: Restore styling and TOC for API documentation * feat: add "badge" option to openqa-clone-job for markdown output * fix(AMQP): Avoid keeping unused AMQP connections around * test: Use more compact syntax in AMQP tests * test: Use signatures in AMQP tests * fix(apparmor): allow access to all Python 3 versions * style: Add tools/ to perlcritic check * fix(Plugin::IssueReporter): prevent erroneous "mailto" links * perf: tweak jobs evaluated on job groups based on recent improvement * fix: try to resolve package conflicts with zypper * docs: Keep filenames in links for GitHub but strip them in build * docs: fix typo in WritingTests * fix: dynamically check pandoc support in generate-documentation * fix: dynamically check pandoc support in generate-docs * fix: add python3-weasyprint for build-docs * feat(ui): Simplify warning about full storage * feat(scheduler): Consider all relevant paths in storage space check * docs: Polish rendering and fix conversion artifacts * style: Enforce perlcritic policy RequireQuotedHeredocTerminator * refactor: Reduce complexity in openqa-load-templates * style: Enable strictures before first line of code * style: Add script/ to perlcritic check * docs: Mimic Asciidoctor style with custom CSS and Pandoc template * docs: Fix broken anchors and rendering issues in generate-documentation * docs: Post-conversion cleanup of artifacts and broken links * docs: Switch PDF engine to weasyprint in generate-documentation * docs: Improve glossary highlighting and remove redundant divs * style: Remove trailing whitespace from Markdown files * docs: Enable section numbering and clean up index.md * feat: Convert documentation from AsciiDoc to Markdown * git subrepo pull (merge) --force external/os-autoinst-common * fix(t/33-developer_mode): make needle renaming robust * fix(t/33-developer_mode): bypass storage space check * build(deps-dev): bump prettier from 3.8.1 to 3.8.3 * build(deps): bump delaunator from 5.0.1 to 5.1.0 * fix(apparmor): adapt snd2png path to os-autoinst#2881 * feat: Throttle consistently failing test scenarios * test: fix sporadic failure in scheduling-and-worker-scalability * perf: optimize compute_build_results with DB-level aggregation * feat: disable dashboard inclusion checkbox if ignored by config * fix: remove redundant title attribute in group property editor * refactor: Avoid duplicate access like `$details->{$nickname_field}` * feat: Make all assignments configurable on login via OAuth2 configurable * feat: Make assignment of fullname on login via OAuth2 configurable * fix: Improve auth logic to support API fallback and fix CSRF handling ++++ openQA: - Update to version 5.1777474261.55e5cd5e: * build(deps): bump postcss from 8.5.8 to 8.5.12 * fix(apparmor): adjust the /usr/bin/ssh child profile for 16.x * fix: Fix rendering bugrefs as links in lists and other structures * feat: use full job group name for priority check by default * chore(AGENTS.md): refine coverage requirements * fix(apparmor): allow worker to execute "df" * feat: Restore styling and TOC for API documentation * feat: add "badge" option to openqa-clone-job for markdown output * fix(AMQP): Avoid keeping unused AMQP connections around * test: Use more compact syntax in AMQP tests * test: Use signatures in AMQP tests * fix(apparmor): allow access to all Python 3 versions * style: Add tools/ to perlcritic check * fix(Plugin::IssueReporter): prevent erroneous "mailto" links * perf: tweak jobs evaluated on job groups based on recent improvement * fix: try to resolve package conflicts with zypper * docs: Keep filenames in links for GitHub but strip them in build * docs: fix typo in WritingTests * fix: dynamically check pandoc support in generate-documentation * fix: dynamically check pandoc support in generate-docs * fix: add python3-weasyprint for build-docs * feat(ui): Simplify warning about full storage * feat(scheduler): Consider all relevant paths in storage space check * docs: Polish rendering and fix conversion artifacts * style: Enforce perlcritic policy RequireQuotedHeredocTerminator * refactor: Reduce complexity in openqa-load-templates * style: Enable strictures before first line of code * style: Add script/ to perlcritic check * docs: Mimic Asciidoctor style with custom CSS and Pandoc template * docs: Fix broken anchors and rendering issues in generate-documentation * docs: Post-conversion cleanup of artifacts and broken links * docs: Switch PDF engine to weasyprint in generate-documentation * docs: Improve glossary highlighting and remove redundant divs * style: Remove trailing whitespace from Markdown files * docs: Enable section numbering and clean up index.md * feat: Convert documentation from AsciiDoc to Markdown * git subrepo pull (merge) --force external/os-autoinst-common * fix(t/33-developer_mode): make needle renaming robust * fix(t/33-developer_mode): bypass storage space check * build(deps-dev): bump prettier from 3.8.1 to 3.8.3 * build(deps): bump delaunator from 5.0.1 to 5.1.0 * fix(apparmor): adapt snd2png path to os-autoinst#2881 * feat: Throttle consistently failing test scenarios * test: fix sporadic failure in scheduling-and-worker-scalability * perf: optimize compute_build_results with DB-level aggregation * feat: disable dashboard inclusion checkbox if ignored by config * fix: remove redundant title attribute in group property editor * refactor: Avoid duplicate access like `$details->{$nickname_field}` * feat: Make all assignments configurable on login via OAuth2 configurable * feat: Make assignment of fullname on login via OAuth2 configurable * fix: Improve auth logic to support API fallback and fix CSRF handling ++++ openQA: - Update to version 5.1777474261.55e5cd5e: * build(deps): bump postcss from 8.5.8 to 8.5.12 * fix(apparmor): adjust the /usr/bin/ssh child profile for 16.x * fix: Fix rendering bugrefs as links in lists and other structures * feat: use full job group name for priority check by default * chore(AGENTS.md): refine coverage requirements * fix(apparmor): allow worker to execute "df" * feat: Restore styling and TOC for API documentation * feat: add "badge" option to openqa-clone-job for markdown output * fix(AMQP): Avoid keeping unused AMQP connections around * test: Use more compact syntax in AMQP tests * test: Use signatures in AMQP tests * fix(apparmor): allow access to all Python 3 versions * style: Add tools/ to perlcritic check * fix(Plugin::IssueReporter): prevent erroneous "mailto" links * perf: tweak jobs evaluated on job groups based on recent improvement * fix: try to resolve package conflicts with zypper * docs: Keep filenames in links for GitHub but strip them in build * docs: fix typo in WritingTests * fix: dynamically check pandoc support in generate-documentation * fix: dynamically check pandoc support in generate-docs * fix: add python3-weasyprint for build-docs * feat(ui): Simplify warning about full storage * feat(scheduler): Consider all relevant paths in storage space check * docs: Polish rendering and fix conversion artifacts * style: Enforce perlcritic policy RequireQuotedHeredocTerminator * refactor: Reduce complexity in openqa-load-templates * style: Enable strictures before first line of code * style: Add script/ to perlcritic check * docs: Mimic Asciidoctor style with custom CSS and Pandoc template * docs: Fix broken anchors and rendering issues in generate-documentation * docs: Post-conversion cleanup of artifacts and broken links * docs: Switch PDF engine to weasyprint in generate-documentation * docs: Improve glossary highlighting and remove redundant divs * style: Remove trailing whitespace from Markdown files * docs: Enable section numbering and clean up index.md * feat: Convert documentation from AsciiDoc to Markdown * git subrepo pull (merge) --force external/os-autoinst-common * fix(t/33-developer_mode): make needle renaming robust * fix(t/33-developer_mode): bypass storage space check * build(deps-dev): bump prettier from 3.8.1 to 3.8.3 * build(deps): bump delaunator from 5.0.1 to 5.1.0 * fix(apparmor): adapt snd2png path to os-autoinst#2881 * feat: Throttle consistently failing test scenarios * test: fix sporadic failure in scheduling-and-worker-scalability * perf: optimize compute_build_results with DB-level aggregation * feat: disable dashboard inclusion checkbox if ignored by config * fix: remove redundant title attribute in group property editor * refactor: Avoid duplicate access like `$details->{$nickname_field}` * feat: Make all assignments configurable on login via OAuth2 configurable * feat: Make assignment of fullname on login via OAuth2 configurable * fix: Improve auth logic to support API fallback and fix CSRF handling ++++ python-pip: - CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442) Add patch CVE-2026-6357.patch ++++ python-pip: - CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442) Add patch CVE-2026-6357.patch ++++ rpmlint: - Update to version 2.7.0+git20260429.f70bc58d (bsc#1261308): * AlternativesCheck: Fix .conf files regex * CI: Use leap containers instead of TW ++++ rpmlint-strict: - Update to version 2.7.0+git20260429.f70bc58d (bsc#1261308): * AlternativesCheck: Fix .conf files regex * CI: Use leap containers instead of TW ------------------------------------------------------------------ ------------------ 2026-4-28 - Apr 28 2026 ------------------- ------------------------------------------------------------------ ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.1 ESR * Fixed: Various security fixes. MFSA 2026-36 (bsc#1263110) * CVE-2026-7320 (bmo#2027433) Information disclosure due to incorrect boundary conditions in the Audio/Video component * CVE-2026-7321 (bmo#2029461) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158, bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231, bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700, bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108, bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121, bmo#2033602) Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.1 ESR * Fixed: Various security fixes. MFSA 2026-36 (bsc#1263110) * CVE-2026-7320 (bmo#2027433) Information disclosure due to incorrect boundary conditions in the Audio/Video component * CVE-2026-7321 (bmo#2029461) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158, bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231, bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700, bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108, bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121, bmo#2033602) Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.1 ESR * Fixed: Various security fixes. MFSA 2026-36 (bsc#1263110) * CVE-2026-7320 (bmo#2027433) Information disclosure due to incorrect boundary conditions in the Audio/Video component * CVE-2026-7321 (bmo#2029461) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158, bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231, bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700, bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108, bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121, bmo#2033602) Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.1 ESR * Fixed: Various security fixes. MFSA 2026-36 (bsc#1263110) * CVE-2026-7320 (bmo#2027433) Information disclosure due to incorrect boundary conditions in the Audio/Video component * CVE-2026-7321 (bmo#2029461) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158, bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231, bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700, bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108, bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121, bmo#2033602) Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.1 ESR * Fixed: Various security fixes. MFSA 2026-36 (bsc#1263110) * CVE-2026-7320 (bmo#2027433) Information disclosure due to incorrect boundary conditions in the Audio/Video component * CVE-2026-7321 (bmo#2029461) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158, bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231, bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700, bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108, bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121, bmo#2033602) Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 ++++ MozillaFirefox: - Firefox Extended Support Release 140.10.1 ESR * Fixed: Various security fixes. MFSA 2026-36 (bsc#1263110) * CVE-2026-7320 (bmo#2027433) Information disclosure due to incorrect boundary conditions in the Audio/Video component * CVE-2026-7321 (bmo#2029461) Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158, bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231, bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700, bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108, bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040) Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121, bmo#2033602) Memory safety bugs fixed in Firefox ESR 140.10.1, Thunderbird ESR 140.10.1, Firefox 150.0.1 and Thunderbird 150.0.1 ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ chromium: - Chromium 147.0.7727.137 (boo#1263158) * CVE-2026-7363: Use after free in Canvas * CVE-2026-7361: Use after free in iOS * CVE-2026-7344: Use after free in Accessibility * CVE-2026-7343: Use after free in Views * CVE-2026-7333: Use after free in GPU * CVE-2026-7360: Insufficient validation of untrusted input in Compositing * CVE-2026-7359: Use after free in ANGLE * CVE-2026-7358: Use after free in Animation * CVE-2026-7334: Use after free in Views * CVE-2026-7357: Use after free in GPU * CVE-2026-7356: Use after free in Navigation * CVE-2026-7354: Out of bounds read and write in Angle * CVE-2026-7353: Heap buffer overflow in Skia * CVE-2026-7352: Use after free in Media * CVE-2026-7351: Race in MHTML * CVE-2026-7350: Use after free in WebMIDI * CVE-2026-7349: Use after free in Cast * CVE-2026-7348: Use after free in Codecs * CVE-2026-7335: Use after free in media * CVE-2026-7336: Use after free in WebRTC * CVE-2026-7337: Type Confusion in V8 * CVE-2026-7347: Use after free in Chromoting * CVE-2026-7346: Inappropriate implementation in Tint * CVE-2026-7345: Insufficient validation of untrusted input in Feedback * CVE-2026-7338: Use after free in Cast * CVE-2026-7342: Use after free in WebView * CVE-2026-7341: Use after free in WebRTC * CVE-2026-7339: Heap buffer overflow in WebRTC * CVE-2026-7340: Integer overflow in ANGLE * CVE-2026-7355: Use after free in Media ++++ kernel-64kb: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-64kb: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-64kb: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-azure: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-azure: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-azure: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-default: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-default: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-default: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-rt: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-rt: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-rt: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ samba: - Update to 4.22.9 * leases torture test flappy; (bso#15978). * incorrect behavior on rpcclient enumport with rpcd_spoolss; (bso#16019). * "use-kerberos=desired" broken; (bso#15789); (bsc#1255755). * rpc workers with long living clients grow server memory keytab; (bso#16042); (bsc#1257200). * CTDB's statd_callout fails on sm-notify; (bso#15938). * CTDB statd_callout_notify notifies unnecessary clients and loses their state; (bso#15939). ++++ cups: - Version upgrade to 2.4.19: See https://github.com/openprinting/cups/releases Release 2.4.19 contains another hotfix after CVE-2026-27447 fix: * Fixed a regression in shared printing from non-local accounts (Issue #1557) Issues are those at https://github.com/OpenPrinting/cups/issues - Adapted downgrade-autoconf-requirement.patch for CUPS 2.4.19 - Added 'Michael R Sweet' key to cups.keyring because cups-2.4.19-source.tar.gz.sig belongs to him. ++++ dtb-aarch64: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ dtb-aarch64: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ dtb-aarch64: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ google-guest-oslogin: - Add /var/google-sudoers.d to tmpfile config + The /var/google-users.d directory is pre-created in the Makefile but the google-sudoers.d is not. But the code wil not behave as expected if the directory is not there. Because of the pre-creation missing in Makefile this was missed initially. ++++ gosec: - Update to version 2.26.1: * Update cosign to v3.0.6 (#1659) * Sync taint rule docs and add missing CWE mappings for G113/G307 (#1658) * Update all dependencies (#1657) * Add G710 rule for open redirect via taint analysis (#1654) * Fix formatting * Update the default models use by autofix and phase out the older models * Format and clean-up the README * Add HTTP file-serving function to the skins of pathtraversal analyzer (#1647) * Skip flaging the TLS min version for go 1.18+ (#1646) * chore(deps): bump go.opentelemetry.io/otel from 1.39.0 to 1.41.0 (#1645) * Added filepath.Abs as a sanitizer (#1643) * Allow rune to byte conversion (#1642) * Allow platform specific conversions (#1641) * chore(deps): update all dependencies (#1639) * chore(deps): update all dependencies (#1634) * chore(go): update supported Go versions to 1.25.9 and 1.26.2 (#1633) * Fix: Bump go-version: 1.25.8 to 1.25.9 in ci (#1632) * fix(taint): gate *http.Request auto-taint on entry-point detection (#1630) * chore(deps): update all dependencies (#1631) * Added a visited cycle-detection guard in the *ssa.Phi case (#1626) * chore(deps): update all dependencies (#1625) * fix(G706): scope slog sinks to msg arg only to prevent false positives on structured attributes (#1623) * Gate the AI security review by the security-review environment (#1621) * Fix anthropic autofix after dependencies update (#1620) * chore(deps): update all dependencies (#1619) * chore(action): bump gosec to 2.25.0 (#1618) ++++ ipmitool: - Fix bad pid file creation in ipmievd by removing the interface number from the file name (bsc#1259310) A fix_pid_file.patch - Use manual service instead of localonly ++++ kernel-source: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-source: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-source: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-docs: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-docs: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-docs: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-kvmsmall: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-kvmsmall: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-kvmsmall: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-obs-build: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-obs-build: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-obs-build: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-obs-qa: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-obs-qa: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-obs-qa: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-syms: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-syms: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-syms: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-zfcpdump: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-zfcpdump: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ kernel-zfcpdump: - xen/privcmd: fix double free via VMA splitting (XSA-487 CVE-2026-31787 bsc#1262181). - commit e092d1b - Buffer overflow in drivers/xen/sys-hypervisor.c (XSA-485 git-fixes bsc#1262179). - commit c0b7cdd - wifi: rtw88: Add BUFFALO WI-U3-866DHP to the USB ID list (bsc#1263135). - wifi: rtw88: rtw8822bu VID/PID for BUFFALO WI-U2-866DM (bsc#1263135). - wifi: rtw88: Add support for Mercusys MA30N and D-Link DWA-T185 rev. A1 (bsc#1263135). - wifi: rtw88: Add additional USB IDs for RTL8812BU (bsc#1263135). - commit 7870f4c - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - commit e6bc750 - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - commit b9cce49 - KVM: arm64: Read PMUVer as unsigned (git-fixes). - commit e3a8c5f - KVM: arm64: Set ID_{AA64PFR0,PFR1}_EL1.GIC when GICv3 is configured (git-fixes). - commit 35b6759 - Delete patches.suse/PCI-Enable-ACS-after-configuring-IOMMU-for-OF-platfor.patch (bsc#1261348). It causes IOMMU issues and was reverted in the stable tree too. - commit e031ca2 - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - commit fb49ffc ++++ tree-sitter: Review corrections: 1. Fixed SLPP violation: Moved tree-sitter-load-path.el and the grammar directory from the shared library package (libtree-sitter0_26) to the main tree-sitter package. This allows different library versions to be installed in parallel. 2. Removed legacy transition logic: Deleted the Provides and Obsoletes for older library versions (0_22 and 0_25) that were causing hard-dependency conflicts during upgrades. 3. Eliminated conflicting symlink: Added a command in the %install section to remove the unused libtree-sitter.so.0 symlink, preventing potential file conflicts. 4. Verified configuration: Confirmed baselibs.conf correctly references the current library package. ++++ tree-sitter: Review corrections: 1. Fixed SLPP violation: Moved tree-sitter-load-path.el and the grammar directory from the shared library package (libtree-sitter0_26) to the main tree-sitter package. This allows different library versions to be installed in parallel. 2. Removed legacy transition logic: Deleted the Provides and Obsoletes for older library versions (0_22 and 0_25) that were causing hard-dependency conflicts during upgrades. 3. Eliminated conflicting symlink: Added a command in the %install section to remove the unused libtree-sitter.so.0 symlink, preventing potential file conflicts. 4. Verified configuration: Confirmed baselibs.conf correctly references the current library package. ++++ nvidia-open-driver-G06-signed-cuda: - update CUDA variant to 580.159.03 ++++ nvidia-open-driver-G07-signed-cuda: - update CUDA variant to 595.71.05 ++++ nvidia-open-driver-G07-signed-cuda: - update CUDA variant to 595.71.05 ++++ nvidia-open-driver-G07-signed-cuda: - update CUDA variant to 595.71.05 ++++ nvidia-open-driver-G06-signed: - update CUDA variant to 580.159.03 ++++ nvidia-open-driver-G07-signed: - update CUDA variant to 595.71.05 ++++ nvidia-open-driver-G07-signed: - update CUDA variant to 595.71.05 ++++ nvidia-open-driver-G07-signed: - update CUDA variant to 595.71.05 ++++ openSUSE-signkey-cert: - select for installation if you install virtualbox-kmp-default (bsc#1263027) ++++ python-pip: - CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429) Add patch CVE-2026-3219.patch ++++ python-pip: - CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429) Add patch CVE-2026-3219.patch ------------------------------------------------------------------ ------------------ 2026-4-27 - Apr 27 2026 ------------------- ------------------------------------------------------------------ ++++ avahi: - Add avahi-CVE-2026-34933.patch: refuse to accept publish flags where both wide_area and multicast are set. (CVE-2026-34933, bsc#1261546) ++++ avahi-glib2: - Add avahi-CVE-2026-34933.patch: refuse to accept publish flags where both wide_area and multicast are set. (CVE-2026-34933, bsc#1261546) ++++ kernel-64kb: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-64kb: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-64kb: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-azure: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-azure: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-azure: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-default: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-default: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-default: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-rt: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-rt: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-rt: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ distribution: - update to 3.1.0 ( bsc#1262096, CVE-2026-35172, bsc#1261793, CVE-2026-33540, bsc#1260283, CVE-2026-33186, bsc#1262951, CVE-2026-34986, bsc#1259718): * Fixes CVE-2026-35172 * Fixes CVE-2026-33540 * Adds support for tag pagination * Fixes default credentials in Azure storage provider * Drops support for go1.23 and go1.24 and updates to go1.25 * See the full changelog below for the full list of changes. * docs: Update to refer to new image tag v3 * Fix default_credentials in azure storage provider * chore: make function comment match function name * build(deps): bump golang.org/x/net from 0.37.0 to 0.38.0 in the go_modules group across 1 directory * fix: implement JWK thumbprint for Ed25519 public keys * fix: Annotate code block from validation.indexes configuration docs * feat: extract redis config to separate struct * Fix: resolve issue #4478 by using a temporary file for non- append writes * build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 * docs: Add note about `OTEL_TRACES_EXPORTER` * fix: set OTEL traces to disabled by default * Fix markdown syntax for OTEL traces link in docs * Switch UUIDs to UUIDv7 * refactor: replace map iteration with maps.Copy/Clone * s3-aws: fix build for 386 * docs: Add OpenTelemetry links to quickstart docs * Fix S3 driver loglevel param * Fixed data race in TestSchedule test * Fixes #4683 - uses X/Y instead of Gx/Gy for thumbprint of ecdsa keys * build(deps): bump actions/checkout from 4 to 5 * Fix broken link to Docker Hub fair use policy * fix(registry/handlers/app): redis CAs * build(deps): bump actions/labeler from 5 to 6 * build(deps): bump actions/setup-go from 5 to 6 * build(deps): bump actions/upload-pages-artifact from 3 to 4 * build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 * build(deps): bump github/codeql-action from 3.26.5 to 4.30.7 * build(deps): bump github/codeql-action from 4.30.7 to 4.30.8 * chore: labeler: add area/client mapping for internal/client/** * client: add Accept headers to Exists() HEAD * feat(registry): Make graceful shutdown test robust * fix(registry): Correct log formatting for upstream challenge * build(deps): bump github/codeql-action from 4.30.8 to 4.30.9 * build(deps): bump github/codeql-action from 4.30.9 to 4.31.3 * refactor: remove redundant variable declarations in for loops * "should" -> "must" regarding redis eviction policy * build(deps): bump actions/checkout from 5 to 6 * Incorrect warning hint * Add return error when list object * build(deps): bump actions/checkout from 5.0.1 to 6.0.0 * build(deps): bump peter-evans/dockerhub-description from 4 to 5 * fix: Logging regression for manifest HEAD requests * Add boolean parsing util * Expose `useFIPSEndpoint` for S3 * Add Cloudfleet Container Registry to adopters * fix(ci): Fix broken Azure e2e storage tests * BUG: Fix notification filtering to work with actions when mediatypes is empty * build(deps): bump actions/checkout from 6.0.0 to 6.0.1 * build(deps): bump actions/upload-artifact from 4.6.2 to 6.0.0 * build(deps): bump github/codeql-action from 4.31.3 to 4.31.10 * build(deps): bump github/codeql-action from 4.31.10 to 4.32.2 * build(deps): bump actions/checkout from 6.0.1 to 6.0.2 * update golangci-lint to v2.9 and fix linting issues * update to go1.25.7, alpine 3.23, xx v1.9.0 * vendor: github.com/sirupsen/logrus v1.9.4 * vendor: update golang.org/x/* dependencies * vendor: github.com/docker/docker-credential-helpers v0.9.5 * vendor: github.com/opencontainers/image-spec v1.1.1 * vendor: github.com/klauspost/compress v1.18.4 * fix: prefer otel variables over hard coded service name * vendor: github.com/spf13/cobra v1.10.2 * vendor: github.com/bshuster-repo/logrus-logstash-hook v1.1.0 * fix: sync parent dir to ensure data is reliably stored * modernize code * vendor: github.com/docker/go-events 605354379745 * vendor: github.com/go-jose/go-jose/v4 v4.1.3 * build(deps): bump github/codeql-action from 4.32.2 to 4.32.5 * build(deps): bump docker/login-action from 3 to 4 * build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 * build(deps): bump docker/setup-buildx-action from 3 to 4 * build(deps): bump docker/bake-action from 6 to 7 * build(deps): bump docker/metadata-action from 5 to 6 * fix: nil-check scheduler in `proxyingRegistry.Close()` * fix: set MD5 on GCS writer before first `Write` call in `putContent` * docs: pull through cache will pull from remote multiple times * Update s3.md regionendpoint option * chore(deps): Bump Go to latest 1.25 in CI workflows and go.mod * fix: correct Ed25519 JWK thumbprint `kty` from `"OTP"` to `"OKP"` * Update vacuum.go * Opt: refector tag list pagination support (stage 1) * Correctly match environment variables to YAML-inlined structs in configuration * Enable Redis TLS without client certificates * build(deps): bump actions/deploy-pages from 4 to 5 * build(deps): bump github/codeql-action from 4.32.5 to 4.34.1 * fix(registry/proxy): use detached context when flushing write buffer * ci: pin actions and apply zizmor auto-fixes * build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 * build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in the go_modules group across 1 directory * chore(app): warn when partial TLS config is used in Redis * feat(registry): enhance authentication checks in htpasswd implementation * Opt: refactor tag list pagination support * build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0 * build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 * fix(vendor): fix broke vendor validation * chore(ci): Prep for v3.1 release - Update to version 3.1.0: * chore(ci): Prep for v3.1 release * fix(vendor): fix broke vendpor validation * Opt: refactor tag list pagination support * build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0 * fix redis repo-scoped blob descriptor revocation * build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 * proxy: bind bearer realms to upstream trust boundary ++++ distribution: - update to 3.1.0 ( bsc#1262096, CVE-2026-35172, bsc#1261793, CVE-2026-33540, bsc#1260283, CVE-2026-33186, bsc#1262951, CVE-2026-34986, bsc#1259718): * Fixes CVE-2026-35172 * Fixes CVE-2026-33540 * Adds support for tag pagination * Fixes default credentials in Azure storage provider * Drops support for go1.23 and go1.24 and updates to go1.25 * See the full changelog below for the full list of changes. * docs: Update to refer to new image tag v3 * Fix default_credentials in azure storage provider * chore: make function comment match function name * build(deps): bump golang.org/x/net from 0.37.0 to 0.38.0 in the go_modules group across 1 directory * fix: implement JWK thumbprint for Ed25519 public keys * fix: Annotate code block from validation.indexes configuration docs * feat: extract redis config to separate struct * Fix: resolve issue #4478 by using a temporary file for non- append writes * build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 * docs: Add note about `OTEL_TRACES_EXPORTER` * fix: set OTEL traces to disabled by default * Fix markdown syntax for OTEL traces link in docs * Switch UUIDs to UUIDv7 * refactor: replace map iteration with maps.Copy/Clone * s3-aws: fix build for 386 * docs: Add OpenTelemetry links to quickstart docs * Fix S3 driver loglevel param * Fixed data race in TestSchedule test * Fixes #4683 - uses X/Y instead of Gx/Gy for thumbprint of ecdsa keys * build(deps): bump actions/checkout from 4 to 5 * Fix broken link to Docker Hub fair use policy * fix(registry/handlers/app): redis CAs * build(deps): bump actions/labeler from 5 to 6 * build(deps): bump actions/setup-go from 5 to 6 * build(deps): bump actions/upload-pages-artifact from 3 to 4 * build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 * build(deps): bump github/codeql-action from 3.26.5 to 4.30.7 * build(deps): bump github/codeql-action from 4.30.7 to 4.30.8 * chore: labeler: add area/client mapping for internal/client/** * client: add Accept headers to Exists() HEAD * feat(registry): Make graceful shutdown test robust * fix(registry): Correct log formatting for upstream challenge * build(deps): bump github/codeql-action from 4.30.8 to 4.30.9 * build(deps): bump github/codeql-action from 4.30.9 to 4.31.3 * refactor: remove redundant variable declarations in for loops * "should" -> "must" regarding redis eviction policy * build(deps): bump actions/checkout from 5 to 6 * Incorrect warning hint * Add return error when list object * build(deps): bump actions/checkout from 5.0.1 to 6.0.0 * build(deps): bump peter-evans/dockerhub-description from 4 to 5 * fix: Logging regression for manifest HEAD requests * Add boolean parsing util * Expose `useFIPSEndpoint` for S3 * Add Cloudfleet Container Registry to adopters * fix(ci): Fix broken Azure e2e storage tests * BUG: Fix notification filtering to work with actions when mediatypes is empty * build(deps): bump actions/checkout from 6.0.0 to 6.0.1 * build(deps): bump actions/upload-artifact from 4.6.2 to 6.0.0 * build(deps): bump github/codeql-action from 4.31.3 to 4.31.10 * build(deps): bump github/codeql-action from 4.31.10 to 4.32.2 * build(deps): bump actions/checkout from 6.0.1 to 6.0.2 * update golangci-lint to v2.9 and fix linting issues * update to go1.25.7, alpine 3.23, xx v1.9.0 * vendor: github.com/sirupsen/logrus v1.9.4 * vendor: update golang.org/x/* dependencies * vendor: github.com/docker/docker-credential-helpers v0.9.5 * vendor: github.com/opencontainers/image-spec v1.1.1 * vendor: github.com/klauspost/compress v1.18.4 * fix: prefer otel variables over hard coded service name * vendor: github.com/spf13/cobra v1.10.2 * vendor: github.com/bshuster-repo/logrus-logstash-hook v1.1.0 * fix: sync parent dir to ensure data is reliably stored * modernize code * vendor: github.com/docker/go-events 605354379745 * vendor: github.com/go-jose/go-jose/v4 v4.1.3 * build(deps): bump github/codeql-action from 4.32.2 to 4.32.5 * build(deps): bump docker/login-action from 3 to 4 * build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 * build(deps): bump docker/setup-buildx-action from 3 to 4 * build(deps): bump docker/bake-action from 6 to 7 * build(deps): bump docker/metadata-action from 5 to 6 * fix: nil-check scheduler in `proxyingRegistry.Close()` * fix: set MD5 on GCS writer before first `Write` call in `putContent` * docs: pull through cache will pull from remote multiple times * Update s3.md regionendpoint option * chore(deps): Bump Go to latest 1.25 in CI workflows and go.mod * fix: correct Ed25519 JWK thumbprint `kty` from `"OTP"` to `"OKP"` * Update vacuum.go * Opt: refector tag list pagination support (stage 1) * Correctly match environment variables to YAML-inlined structs in configuration * Enable Redis TLS without client certificates * build(deps): bump actions/deploy-pages from 4 to 5 * build(deps): bump github/codeql-action from 4.32.5 to 4.34.1 * fix(registry/proxy): use detached context when flushing write buffer * ci: pin actions and apply zizmor auto-fixes * build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 * build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in the go_modules group across 1 directory * chore(app): warn when partial TLS config is used in Redis * feat(registry): enhance authentication checks in htpasswd implementation * Opt: refactor tag list pagination support * build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0 * build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 * fix(vendor): fix broke vendor validation * chore(ci): Prep for v3.1 release - Update to version 3.1.0: * chore(ci): Prep for v3.1 release * fix(vendor): fix broke vendpor validation * Opt: refactor tag list pagination support * build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0 * fix redis repo-scoped blob descriptor revocation * build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 * proxy: bind bearer realms to upstream trust boundary ++++ dtb-aarch64: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ dtb-aarch64: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ dtb-aarch64: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ evince: - Update to version 48.1+6: + build: bump DjVuLibre version required + libview: Fix crash in the accessible code when page cache text is NULL + po: Fix xml element in Hindi translation + Updated translations. - Drop evince-a11y-crash.patch: Fixed upstream. ++++ google-cloud-sap-agent: - Add CVE-2026-34986.patch to fix crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262936, CVE-2026-34986) ++++ google-cloud-sap-agent: - Add CVE-2026-34986.patch to fix crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262936, CVE-2026-34986) ++++ google-guest-agent: - Add CVE-2026-34986.patch to fix crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262926, CVE-2026-34986) ++++ google-guest-agent: - Add CVE-2026-34986.patch to fix crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262926, CVE-2026-34986) ++++ google-osconfig-agent: - Add CVE-2026-34986.patch to fix crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262926, CVE-2026-34986) ++++ hauler: - update to 1.4.2 (bsc#1258614, CVE-2026-24122): * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 in the go_modules group across 1 directory * fix for new helm chart features * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 in the go_modules group across 1 directory * Bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 in the go_modules group across 1 directory * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * update cosign fork to 3.0.4 plus dep tidy * fix: Fix file:// dependency chart path resolution * update github.com/olekukonko/tablewriter to v1.1.2 * keep registry on image rewrite if not specified * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * fix: handling of file referenced dependencies without repository field * Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in the go_modules group across 1 directory * dev.md file * smaller changes and updates for v1.4.2 release ++++ hauler: - update to 1.4.2 (bsc#1258614, CVE-2026-24122): * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 in the go_modules group across 1 directory * fix for new helm chart features * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 in the go_modules group across 1 directory * Bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 in the go_modules group across 1 directory * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * update cosign fork to 3.0.4 plus dep tidy * fix: Fix file:// dependency chart path resolution * update github.com/olekukonko/tablewriter to v1.1.2 * keep registry on image rewrite if not specified * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * fix: handling of file referenced dependencies without repository field * Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in the go_modules group across 1 directory * dev.md file * smaller changes and updates for v1.4.2 release ++++ hauler: - update to 1.4.2 (bsc#1258614, CVE-2026-24122): * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 in the go_modules group across 1 directory * fix for new helm chart features * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 in the go_modules group across 1 directory * Bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 in the go_modules group across 1 directory * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * update cosign fork to 3.0.4 plus dep tidy * fix: Fix file:// dependency chart path resolution * update github.com/olekukonko/tablewriter to v1.1.2 * keep registry on image rewrite if not specified * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * fix: handling of file referenced dependencies without repository field * Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in the go_modules group across 1 directory * dev.md file * smaller changes and updates for v1.4.2 release ++++ hauler: - update to 1.4.2 (bsc#1258614, CVE-2026-24122): * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 in the go_modules group across 1 directory * fix for new helm chart features * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 in the go_modules group across 1 directory * Bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 in the go_modules group across 1 directory * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * update cosign fork to 3.0.4 plus dep tidy * fix: Fix file:// dependency chart path resolution * update github.com/olekukonko/tablewriter to v1.1.2 * keep registry on image rewrite if not specified * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * fix: handling of file referenced dependencies without repository field * Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in the go_modules group across 1 directory * dev.md file * smaller changes and updates for v1.4.2 release ++++ hauler: - update to 1.4.2 (bsc#1258614, CVE-2026-24122): * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 to 2.3.1 in the go_modules group across 1 directory * fix for new helm chart features * Bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 in the go_modules group across 1 directory * Bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 in the go_modules group across 1 directory * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * update cosign fork to 3.0.4 plus dep tidy * fix: Fix file:// dependency chart path resolution * update github.com/olekukonko/tablewriter to v1.1.2 * keep registry on image rewrite if not specified * Bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 to 2.4.1 in the go_modules group across 1 directory * fix: handling of file referenced dependencies without repository field * Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 in the go_modules group across 1 directory * dev.md file * smaller changes and updates for v1.4.2 release ++++ hwdata: - update to 0.406: * Update pci and vendor ids ++++ kernel-source: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-source: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-source: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-docs: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-docs: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-docs: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-kvmsmall: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-kvmsmall: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-kvmsmall: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-obs-build: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-obs-build: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-obs-build: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-obs-qa: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-obs-qa: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-obs-qa: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-syms: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-syms: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-syms: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-zfcpdump: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-zfcpdump: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ kernel-zfcpdump: - tpm: Use kfree_sensitive() to free auth session in tpm_dev_release() (git-fixes). - Refresh patches.kabi/tpm_chip-kabi-workaround.patch. - commit 0e9ec43 - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() (git-fixes). - tpm: Fix auth session leak in tpm2_get_random() error path (git-fixes). - commit da5bf2c - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes) - commit fb667c1 - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes) - commit 6558288 - drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (CVE-2026-23468 bsc#1261692). - commit 8dbe5ae ++++ avahi-qt6: - Add avahi-CVE-2026-34933.patch: refuse to accept publish flags where both wide_area and multicast are set. (CVE-2026-34933, bsc#1261546) ++++ mupdf: - update to 1.27.2: * Add ImageMask operation in image rewriter. * SText vector merging, and 'fuzzy-vectors' option. * SText corruption fixes. * SText Depth First Search iterator fixes. - drop cve-2026-25556.patch (upstream) ++++ tiff: - * CVE-2026-4775: Signed integer overflow in putcontig8bitYCbCr44tile (bsc#1260411) Add tiff-CVE-2026-4775.patch ++++ tiff-man: - * CVE-2026-4775: Signed integer overflow in putcontig8bitYCbCr44tile (bsc#1260411) Add tiff-CVE-2026-4775.patch ++++ open-vm-tools: - Fix build with glibc 2.43 (boo#1257312) + Add patch: - glibc243.patch ++++ libzypp: - Fix purge-kernel -rc kernel handling (bsc#1239718) - Explicitly_set_pool_DISTTYPE_RPM (fixes #726) - version 17.38.7 (35) ++++ ltrace: - Add ltrace-add-yama-hint.patch (jsc#PED-15928) to give a hint when ltrace -p fails on a system where yama is active. ++++ php-composer2: - added patches CVE-2026-40176: command injection via malicious Perforce repository definition [bsc#1262254] * php-composer2-CVE-2026-40176.patch CVE-2026-40261: command injection via malicious Perforce source reference/url [bsc#1262255] * php-composer2-CVE-2026-40261.patch ++++ powerpc-utils: - Update to version 1.3.14 (jsc#PED-14528) * Unified version number across tools * Add Resource group monitoring support to lparstat (jsc#PED-14516). * lparstat: print 'Maximum System Processors' * lsslot: don't report an error for an empty PHB list - Drop upstreamed patches * smtstate-Start-smtstate-service-after-network-target.patch * lparstat-Use-pool_capacity-for-determining-active-cp.patch * sys_ident-Quiet-strncpy-warning.patch * nvram.c-Correct-librtas-function-prototypes.patch * pseries_platform.h-Fix-ifdef-guard-typo.patch * Fix-HNV-installation-network-conflicts-across-all-di.patch * lparstat-print-memory-mode-correctly.patch * ppc64_cpu-Fix-handling-of-non-contiguous-CPU-IDs.patch * cpu_info_helpers-Add-helper-function-to-retrieve-pre.patch * drmgr-pci-Return-0-for-success-from-do_replace.patch * lparstat-Fix-negative-values-for-idle-PURR.patch - Refresh ofpathname_powernv.patch ++++ product-composer: - update to version 0.9.6 * Speed-up reading of rpm headers * Flush output lines to get get correct timestamps in OBS ++++ product-composer: - update to version 0.9.6 * Speed-up reading of rpm headers * Flush output lines to get get correct timestamps in OBS ++++ product-composer: - update to version 0.9.6 * Speed-up reading of rpm headers * Flush output lines to get get correct timestamps in OBS ++++ salt: - BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900) - Added: * bdsa-2025-60810-harden-against-invalid-http-reason-p.patch * read-full-uri-from-ldap-pillar-config-753.patch ++++ salt-test: - BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases - Read full URI from ldap pillar config (bsc#1254900) - Added: * bdsa-2025-60810-harden-against-invalid-http-reason-p.patch * read-full-uri-from-ldap-pillar-config-753.patch ++++ susedialog: - Update to version 20260427.b33f52d: * Add bash completion - Update to version 20260427.02fbcf9: * Support both top-left + centered dialogs * Add infobox support based on Jan's early feedback * Revisit high-contrast theme * Add rainbow support for our rainbow friends * Introduce SUSEDIALOG_THEME_TOGGLE_KEY * Support user and system-wide config with themes - Reorder go_modules service ++++ trivy: - Update to version 0.70.0 ( bsc#1260193, CVE-2026-33186, bsc#1260971, CVE-2026-33747, bsc#1261052, CVE-2026-33748, bsc#1262389, CVE-2026-39984, bsc#1262893, CVE-2026-34986): * release: v0.70.0 [main] (#10105) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (#10496) * chore(deps): bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 (#10526) * chore(deps): bump the common group across 1 directory with 8 updates (#10540) * chore(deps): bump the docker group across 1 directory with 2 updates (#10538) * fix: use Development category for GoReleaser discussions (#10530) * chore(deps): bump testcontainers-go to v0.42.0 (#10531) * chore: update CODEOWNERS (#10529) * chore(deps): bump helm.sh/helm/v3 from 3.20.1 to 3.20.2 (#10511) * chore(deps): bump github.com/hashicorp/go-getter from 1.8.5 to 1.8.6 (#10510) * chore(deps): bump github.com/moby/buildkit from 0.27.1 to 0.28.1 (#10449) * ci: migrate from mkdocs-material-insiders to mkdocs-material (#10509) * chore: remove aquasecurity/homebrew-trivy tap from GoReleaser (#10508) * ci: update runners for workflows that interact with GitHub API (#10502) * ci: rename tokens and update runners (#10500) * ci: trigger helm chart publishing via helm-charts workflow (#10474) * ci: remove ruleset update step from release-please workflow (#10499) * ci: use large runner and replace ORG_REPO_TOKEN in release-please workflow (#10498) * ci: trigger rpm/deb deployment via trivy-repo workflow (#10476) * fix: remove os.Stdout from wazero module config (#10403) * chore(deps): bump the common group across 1 directory with 22 updates (#10408) * chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#10407) * fix(flag): validate template file extension (#10296) * fix(sbom): preserve Red Hat BuildInfo when scanning SBOMs without layer info (#10378) * fix: handle Go 1.26 GOEXPERIMENT version format change (#10351) * fix(python): handle multiple version specifiers in requirements.txt (#10361) * ci: run Trivy version bump in trivy-action (#10272) * fix(python): nil pointer dereference with optional poetry groups without dependencies (#10359) * ci: replace personal email with github-actions[bot] in workflows (#10369) * chore: replace smithy epoch parsing with stdlib time.Unix (#10286) * test: update golden files for purl changes (#10372) * ci: add zizmor to scan GitHub Actions workflows (#10322) * refactor: log statuses as strings (#10285) * ci: add build provenance attestations for release artifacts (#10316) * fix(sbom): add NOASSERTION for licenseDeclared/licenseConcluded in SPDX non-library packages (#10368) * fix(report): set correct sarif ROOTPATH uri when scanning a git repository (#10366) * perf(plugin): optimize directory traversal by replacing filepath.Walk with filepath.WalkDir (#10325) * docs: correct typos in CHANGELOG and diagram (#10320) * chore: delete roadmap wf (#10295) * ci(helm): bump Trivy version to 0.69.3 for Trivy Helm Chart 0.21.3 (#10310) * fix(cyclonedx): include CVSS v4 vulnerability ratings (#10313) * fix: detected vulnerability fields in azure and mariner detector (#10275) * ci: add persist-credentials: false to checkout steps (#10306) * ci(helm): bump Trivy version to 0.69.2 for Trivy Helm Chart 0.21.2 (#10270) * chore(deps): bump the common group across 1 directory with 8 updates (#10248) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#10257) * chore(deps): bump the aws group across 1 directory with 6 updates (#10249) * chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 (#10241) * ci: remove apidiff workflow (#10259) * chore(deps): bump github.com/docker/cli from 29.1.4+incompatible to 29.2.1+incompatible in the docker group across 1 directory (#10221) * ci: bump golangci-lint to v2.10 in cache-test-assets (#10243) * feat(java): add support for proxy configuration from Maven settings.xml (#10187) * chore(deps): bump the github-actions group across 3 directories with 11 updates (#10242) * feat(python): add pylock.toml support (#10137) * chore: bump SPDX license IDs and exceptions to `v3.28.0` (#10233) * docs: fix typos and upgrade insecure HTTP links to HTTPS (#10219) * chore: bump golangci-lint to v2.10.0 (#10223) * feat(misconf): support for azurerm_network_interface_security_group_association (#10215) * ci: pin Docker Engine to v29 for integration tests (#10232) * feat(go): detect version from ELF symbol table for binaries built with -trimpath (#10197) * docs: migrate private registry documentation from GCR to GAR (#10208) * chore(deps): bump the common group across 1 directory with 24 updates (#10206) * chore(deps): update Docker client SDK to v29 (#10202) * test: update Docker Engine integration tests for Docker API v0.29.0+ compatibility (#10199) * fix(misconf): initialize custom annotation field if empty (#10123) * feat(ubuntu): add eol data for 25.10 (#10181) * docs: fix incorrect count of Python package managers (#10175) * chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (#10179) * feat(misconf): resolve Azure resources via resource_id (#10173) * ci(helm): bump Trivy version to 0.69.1 for Trivy Helm Chart 0.21.1 (#10155) * refactor: remove unused Insecure field from ServiceOption (#10113) * refactor: reduce complexity of init in detect.go (#10163) * feat(misconf): adapt ARM k8s clusters (#9696) (#10125) * docs: update version endpoint example in client/server documentation (#10151) * feat(vuln): skip third-party packages in common Detect function (#10129) * ci: add composite action for Go setup (#10146) * fix(misconf): apply check aliases when filtering results via .trivyignore (#10112) * docs(terraform): add limitation for data sources and computed resource attributes (#10128) * fix: update PhotonOS feed URL (#10122) * feat(server): include server version info in JSON output for client/server mode (#10075) * chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs (#10107) * refactor: unify scanner error limit and compiler limit (#10106) * ci(helm): bump Trivy version to 0.69.0 for Trivy Helm Chart 0.21.0 (#10103) * fix(java): Disable overwriting exclusions (#10088) * refactor(rust): use txtar format for cargo analyzer test data (#10104) * feat(python): add pylock.toml (PEP 751) parser (#9632) * chore(deps): bump the aws group across 1 directory with 6 updates (#10068) * fix(server): exclude JavaDB and CheckBundle from /version endpoint (#10100) ++++ trivy: - Update to version 0.70.0 ( bsc#1260193, CVE-2026-33186, bsc#1260971, CVE-2026-33747, bsc#1261052, CVE-2026-33748, bsc#1262389, CVE-2026-39984, bsc#1265648, CVE-2026-33814, bsc#1262893, CVE-2026-34986): * release: v0.70.0 [main] (#10105) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (#10496) * chore(deps): bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 (#10526) * chore(deps): bump the common group across 1 directory with 8 updates (#10540) * chore(deps): bump the docker group across 1 directory with 2 updates (#10538) * fix: use Development category for GoReleaser discussions (#10530) * chore(deps): bump testcontainers-go to v0.42.0 (#10531) * chore: update CODEOWNERS (#10529) * chore(deps): bump helm.sh/helm/v3 from 3.20.1 to 3.20.2 (#10511) * chore(deps): bump github.com/hashicorp/go-getter from 1.8.5 to 1.8.6 (#10510) * chore(deps): bump github.com/moby/buildkit from 0.27.1 to 0.28.1 (#10449) * ci: migrate from mkdocs-material-insiders to mkdocs-material (#10509) * chore: remove aquasecurity/homebrew-trivy tap from GoReleaser (#10508) * ci: update runners for workflows that interact with GitHub API (#10502) * ci: rename tokens and update runners (#10500) * ci: trigger helm chart publishing via helm-charts workflow (#10474) * ci: remove ruleset update step from release-please workflow (#10499) * ci: use large runner and replace ORG_REPO_TOKEN in release-please workflow (#10498) * ci: trigger rpm/deb deployment via trivy-repo workflow (#10476) * fix: remove os.Stdout from wazero module config (#10403) * chore(deps): bump the common group across 1 directory with 22 updates (#10408) * chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#10407) * fix(flag): validate template file extension (#10296) * fix(sbom): preserve Red Hat BuildInfo when scanning SBOMs without layer info (#10378) * fix: handle Go 1.26 GOEXPERIMENT version format change (#10351) * fix(python): handle multiple version specifiers in requirements.txt (#10361) * ci: run Trivy version bump in trivy-action (#10272) * fix(python): nil pointer dereference with optional poetry groups without dependencies (#10359) * ci: replace personal email with github-actions[bot] in workflows (#10369) * chore: replace smithy epoch parsing with stdlib time.Unix (#10286) * test: update golden files for purl changes (#10372) * ci: add zizmor to scan GitHub Actions workflows (#10322) * refactor: log statuses as strings (#10285) * ci: add build provenance attestations for release artifacts (#10316) * fix(sbom): add NOASSERTION for licenseDeclared/licenseConcluded in SPDX non-library packages (#10368) * fix(report): set correct sarif ROOTPATH uri when scanning a git repository (#10366) * perf(plugin): optimize directory traversal by replacing filepath.Walk with filepath.WalkDir (#10325) * docs: correct typos in CHANGELOG and diagram (#10320) * chore: delete roadmap wf (#10295) * ci(helm): bump Trivy version to 0.69.3 for Trivy Helm Chart 0.21.3 (#10310) * fix(cyclonedx): include CVSS v4 vulnerability ratings (#10313) * fix: detected vulnerability fields in azure and mariner detector (#10275) * ci: add persist-credentials: false to checkout steps (#10306) * ci(helm): bump Trivy version to 0.69.2 for Trivy Helm Chart 0.21.2 (#10270) * chore(deps): bump the common group across 1 directory with 8 updates (#10248) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#10257) * chore(deps): bump the aws group across 1 directory with 6 updates (#10249) * chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 (#10241) * ci: remove apidiff workflow (#10259) * chore(deps): bump github.com/docker/cli from 29.1.4+incompatible to 29.2.1+incompatible in the docker group across 1 directory (#10221) * ci: bump golangci-lint to v2.10 in cache-test-assets (#10243) * feat(java): add support for proxy configuration from Maven settings.xml (#10187) * chore(deps): bump the github-actions group across 3 directories with 11 updates (#10242) * feat(python): add pylock.toml support (#10137) * chore: bump SPDX license IDs and exceptions to `v3.28.0` (#10233) * docs: fix typos and upgrade insecure HTTP links to HTTPS (#10219) * chore: bump golangci-lint to v2.10.0 (#10223) * feat(misconf): support for azurerm_network_interface_security_group_association (#10215) * ci: pin Docker Engine to v29 for integration tests (#10232) * feat(go): detect version from ELF symbol table for binaries built with -trimpath (#10197) * docs: migrate private registry documentation from GCR to GAR (#10208) * chore(deps): bump the common group across 1 directory with 24 updates (#10206) * chore(deps): update Docker client SDK to v29 (#10202) * test: update Docker Engine integration tests for Docker API v0.29.0+ compatibility (#10199) * fix(misconf): initialize custom annotation field if empty (#10123) * feat(ubuntu): add eol data for 25.10 (#10181) * docs: fix incorrect count of Python package managers (#10175) * chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (#10179) * feat(misconf): resolve Azure resources via resource_id (#10173) * ci(helm): bump Trivy version to 0.69.1 for Trivy Helm Chart 0.21.1 (#10155) * refactor: remove unused Insecure field from ServiceOption (#10113) * refactor: reduce complexity of init in detect.go (#10163) * feat(misconf): adapt ARM k8s clusters (#9696) (#10125) * docs: update version endpoint example in client/server documentation (#10151) * feat(vuln): skip third-party packages in common Detect function (#10129) * ci: add composite action for Go setup (#10146) * fix(misconf): apply check aliases when filtering results via .trivyignore (#10112) * docs(terraform): add limitation for data sources and computed resource attributes (#10128) * fix: update PhotonOS feed URL (#10122) * feat(server): include server version info in JSON output for client/server mode (#10075) * chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs (#10107) * refactor: unify scanner error limit and compiler limit (#10106) * ci(helm): bump Trivy version to 0.69.0 for Trivy Helm Chart 0.21.0 (#10103) * fix(java): Disable overwriting exclusions (#10088) * refactor(rust): use txtar format for cargo analyzer test data (#10104) * feat(python): add pylock.toml (PEP 751) parser (#9632) * chore(deps): bump the aws group across 1 directory with 6 updates (#10068) * fix(server): exclude JavaDB and CheckBundle from /version endpoint (#10100) ++++ trivy: - Update to version 0.70.0 ( bsc#1260193, CVE-2026-33186, bsc#1260971, CVE-2026-33747, bsc#1261052, CVE-2026-33748, bsc#1262389, CVE-2026-39984, bsc#1265648, CVE-2026-33814, bsc#1262893, CVE-2026-34986): * release: v0.70.0 [main] (#10105) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (#10496) * chore(deps): bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 (#10526) * chore(deps): bump the common group across 1 directory with 8 updates (#10540) * chore(deps): bump the docker group across 1 directory with 2 updates (#10538) * fix: use Development category for GoReleaser discussions (#10530) * chore(deps): bump testcontainers-go to v0.42.0 (#10531) * chore: update CODEOWNERS (#10529) * chore(deps): bump helm.sh/helm/v3 from 3.20.1 to 3.20.2 (#10511) * chore(deps): bump github.com/hashicorp/go-getter from 1.8.5 to 1.8.6 (#10510) * chore(deps): bump github.com/moby/buildkit from 0.27.1 to 0.28.1 (#10449) * ci: migrate from mkdocs-material-insiders to mkdocs-material (#10509) * chore: remove aquasecurity/homebrew-trivy tap from GoReleaser (#10508) * ci: update runners for workflows that interact with GitHub API (#10502) * ci: rename tokens and update runners (#10500) * ci: trigger helm chart publishing via helm-charts workflow (#10474) * ci: remove ruleset update step from release-please workflow (#10499) * ci: use large runner and replace ORG_REPO_TOKEN in release-please workflow (#10498) * ci: trigger rpm/deb deployment via trivy-repo workflow (#10476) * fix: remove os.Stdout from wazero module config (#10403) * chore(deps): bump the common group across 1 directory with 22 updates (#10408) * chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#10407) * fix(flag): validate template file extension (#10296) * fix(sbom): preserve Red Hat BuildInfo when scanning SBOMs without layer info (#10378) * fix: handle Go 1.26 GOEXPERIMENT version format change (#10351) * fix(python): handle multiple version specifiers in requirements.txt (#10361) * ci: run Trivy version bump in trivy-action (#10272) * fix(python): nil pointer dereference with optional poetry groups without dependencies (#10359) * ci: replace personal email with github-actions[bot] in workflows (#10369) * chore: replace smithy epoch parsing with stdlib time.Unix (#10286) * test: update golden files for purl changes (#10372) * ci: add zizmor to scan GitHub Actions workflows (#10322) * refactor: log statuses as strings (#10285) * ci: add build provenance attestations for release artifacts (#10316) * fix(sbom): add NOASSERTION for licenseDeclared/licenseConcluded in SPDX non-library packages (#10368) * fix(report): set correct sarif ROOTPATH uri when scanning a git repository (#10366) * perf(plugin): optimize directory traversal by replacing filepath.Walk with filepath.WalkDir (#10325) * docs: correct typos in CHANGELOG and diagram (#10320) * chore: delete roadmap wf (#10295) * ci(helm): bump Trivy version to 0.69.3 for Trivy Helm Chart 0.21.3 (#10310) * fix(cyclonedx): include CVSS v4 vulnerability ratings (#10313) * fix: detected vulnerability fields in azure and mariner detector (#10275) * ci: add persist-credentials: false to checkout steps (#10306) * ci(helm): bump Trivy version to 0.69.2 for Trivy Helm Chart 0.21.2 (#10270) * chore(deps): bump the common group across 1 directory with 8 updates (#10248) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#10257) * chore(deps): bump the aws group across 1 directory with 6 updates (#10249) * chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 (#10241) * ci: remove apidiff workflow (#10259) * chore(deps): bump github.com/docker/cli from 29.1.4+incompatible to 29.2.1+incompatible in the docker group across 1 directory (#10221) * ci: bump golangci-lint to v2.10 in cache-test-assets (#10243) * feat(java): add support for proxy configuration from Maven settings.xml (#10187) * chore(deps): bump the github-actions group across 3 directories with 11 updates (#10242) * feat(python): add pylock.toml support (#10137) * chore: bump SPDX license IDs and exceptions to `v3.28.0` (#10233) * docs: fix typos and upgrade insecure HTTP links to HTTPS (#10219) * chore: bump golangci-lint to v2.10.0 (#10223) * feat(misconf): support for azurerm_network_interface_security_group_association (#10215) * ci: pin Docker Engine to v29 for integration tests (#10232) * feat(go): detect version from ELF symbol table for binaries built with -trimpath (#10197) * docs: migrate private registry documentation from GCR to GAR (#10208) * chore(deps): bump the common group across 1 directory with 24 updates (#10206) * chore(deps): update Docker client SDK to v29 (#10202) * test: update Docker Engine integration tests for Docker API v0.29.0+ compatibility (#10199) * fix(misconf): initialize custom annotation field if empty (#10123) * feat(ubuntu): add eol data for 25.10 (#10181) * docs: fix incorrect count of Python package managers (#10175) * chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (#10179) * feat(misconf): resolve Azure resources via resource_id (#10173) * ci(helm): bump Trivy version to 0.69.1 for Trivy Helm Chart 0.21.1 (#10155) * refactor: remove unused Insecure field from ServiceOption (#10113) * refactor: reduce complexity of init in detect.go (#10163) * feat(misconf): adapt ARM k8s clusters (#9696) (#10125) * docs: update version endpoint example in client/server documentation (#10151) * feat(vuln): skip third-party packages in common Detect function (#10129) * ci: add composite action for Go setup (#10146) * fix(misconf): apply check aliases when filtering results via .trivyignore (#10112) * docs(terraform): add limitation for data sources and computed resource attributes (#10128) * fix: update PhotonOS feed URL (#10122) * feat(server): include server version info in JSON output for client/server mode (#10075) * chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs (#10107) * refactor: unify scanner error limit and compiler limit (#10106) * ci(helm): bump Trivy version to 0.69.0 for Trivy Helm Chart 0.21.0 (#10103) * fix(java): Disable overwriting exclusions (#10088) * refactor(rust): use txtar format for cargo analyzer test data (#10104) * feat(python): add pylock.toml (PEP 751) parser (#9632) * chore(deps): bump the aws group across 1 directory with 6 updates (#10068) * fix(server): exclude JavaDB and CheckBundle from /version endpoint (#10100) ++++ trivy: - Update to version 0.70.0 ( bsc#1260193, CVE-2026-33186, bsc#1260971, CVE-2026-33747, bsc#1261052, CVE-2026-33748, bsc#1262389, CVE-2026-39984, bsc#1265648, CVE-2026-33814, bsc#1262893, CVE-2026-34986): * release: v0.70.0 [main] (#10105) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 (#10496) * chore(deps): bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 (#10526) * chore(deps): bump the common group across 1 directory with 8 updates (#10540) * chore(deps): bump the docker group across 1 directory with 2 updates (#10538) * fix: use Development category for GoReleaser discussions (#10530) * chore(deps): bump testcontainers-go to v0.42.0 (#10531) * chore: update CODEOWNERS (#10529) * chore(deps): bump helm.sh/helm/v3 from 3.20.1 to 3.20.2 (#10511) * chore(deps): bump github.com/hashicorp/go-getter from 1.8.5 to 1.8.6 (#10510) * chore(deps): bump github.com/moby/buildkit from 0.27.1 to 0.28.1 (#10449) * ci: migrate from mkdocs-material-insiders to mkdocs-material (#10509) * chore: remove aquasecurity/homebrew-trivy tap from GoReleaser (#10508) * ci: update runners for workflows that interact with GitHub API (#10502) * ci: rename tokens and update runners (#10500) * ci: trigger helm chart publishing via helm-charts workflow (#10474) * ci: remove ruleset update step from release-please workflow (#10499) * ci: use large runner and replace ORG_REPO_TOKEN in release-please workflow (#10498) * ci: trigger rpm/deb deployment via trivy-repo workflow (#10476) * fix: remove os.Stdout from wazero module config (#10403) * chore(deps): bump the common group across 1 directory with 22 updates (#10408) * chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#10407) * fix(flag): validate template file extension (#10296) * fix(sbom): preserve Red Hat BuildInfo when scanning SBOMs without layer info (#10378) * fix: handle Go 1.26 GOEXPERIMENT version format change (#10351) * fix(python): handle multiple version specifiers in requirements.txt (#10361) * ci: run Trivy version bump in trivy-action (#10272) * fix(python): nil pointer dereference with optional poetry groups without dependencies (#10359) * ci: replace personal email with github-actions[bot] in workflows (#10369) * chore: replace smithy epoch parsing with stdlib time.Unix (#10286) * test: update golden files for purl changes (#10372) * ci: add zizmor to scan GitHub Actions workflows (#10322) * refactor: log statuses as strings (#10285) * ci: add build provenance attestations for release artifacts (#10316) * fix(sbom): add NOASSERTION for licenseDeclared/licenseConcluded in SPDX non-library packages (#10368) * fix(report): set correct sarif ROOTPATH uri when scanning a git repository (#10366) * perf(plugin): optimize directory traversal by replacing filepath.Walk with filepath.WalkDir (#10325) * docs: correct typos in CHANGELOG and diagram (#10320) * chore: delete roadmap wf (#10295) * ci(helm): bump Trivy version to 0.69.3 for Trivy Helm Chart 0.21.3 (#10310) * fix(cyclonedx): include CVSS v4 vulnerability ratings (#10313) * fix: detected vulnerability fields in azure and mariner detector (#10275) * ci: add persist-credentials: false to checkout steps (#10306) * ci(helm): bump Trivy version to 0.69.2 for Trivy Helm Chart 0.21.2 (#10270) * chore(deps): bump the common group across 1 directory with 8 updates (#10248) * chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#10257) * chore(deps): bump the aws group across 1 directory with 6 updates (#10249) * chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 (#10241) * ci: remove apidiff workflow (#10259) * chore(deps): bump github.com/docker/cli from 29.1.4+incompatible to 29.2.1+incompatible in the docker group across 1 directory (#10221) * ci: bump golangci-lint to v2.10 in cache-test-assets (#10243) * feat(java): add support for proxy configuration from Maven settings.xml (#10187) * chore(deps): bump the github-actions group across 3 directories with 11 updates (#10242) * feat(python): add pylock.toml support (#10137) * chore: bump SPDX license IDs and exceptions to `v3.28.0` (#10233) * docs: fix typos and upgrade insecure HTTP links to HTTPS (#10219) * chore: bump golangci-lint to v2.10.0 (#10223) * feat(misconf): support for azurerm_network_interface_security_group_association (#10215) * ci: pin Docker Engine to v29 for integration tests (#10232) * feat(go): detect version from ELF symbol table for binaries built with -trimpath (#10197) * docs: migrate private registry documentation from GCR to GAR (#10208) * chore(deps): bump the common group across 1 directory with 24 updates (#10206) * chore(deps): update Docker client SDK to v29 (#10202) * test: update Docker Engine integration tests for Docker API v0.29.0+ compatibility (#10199) * fix(misconf): initialize custom annotation field if empty (#10123) * feat(ubuntu): add eol data for 25.10 (#10181) * docs: fix incorrect count of Python package managers (#10175) * chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (#10179) * feat(misconf): resolve Azure resources via resource_id (#10173) * ci(helm): bump Trivy version to 0.69.1 for Trivy Helm Chart 0.21.1 (#10155) * refactor: remove unused Insecure field from ServiceOption (#10113) * refactor: reduce complexity of init in detect.go (#10163) * feat(misconf): adapt ARM k8s clusters (#9696) (#10125) * docs: update version endpoint example in client/server documentation (#10151) * feat(vuln): skip third-party packages in common Detect function (#10129) * ci: add composite action for Go setup (#10146) * fix(misconf): apply check aliases when filtering results via .trivyignore (#10112) * docs(terraform): add limitation for data sources and computed resource attributes (#10128) * fix: update PhotonOS feed URL (#10122) * feat(server): include server version info in JSON output for client/server mode (#10075) * chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs (#10107) * refactor: unify scanner error limit and compiler limit (#10106) * ci(helm): bump Trivy version to 0.69.0 for Trivy Helm Chart 0.21.0 (#10103) * fix(java): Disable overwriting exclusions (#10088) * refactor(rust): use txtar format for cargo analyzer test data (#10104) * feat(python): add pylock.toml (PEP 751) parser (#9632) * chore(deps): bump the aws group across 1 directory with 6 updates (#10068) * fix(server): exclude JavaDB and CheckBundle from /version endpoint (#10100) ------------------------------------------------------------------ ------------------ 2026-4-26 - Apr 26 2026 ------------------- ------------------------------------------------------------------ ++++ OpenIPMI: - Adopt path to executable in systemd service file (bsc#1252941) ++++ alloy: - update to 1.16.0: * Features - Add clustering for loki.source.kubernetes_events (#6027) (3dbf587) (@petewall) - Add otelcol.auth.google client auth provider (#5526) (da99a66) (@dashpole, @clayton-cornell) - beyla.ebpf: Bump to v3.7.0 (#5966) (5126c2e) (@marctc) - database_observability: Add support for GCP Cloud SQL metadata (#5875) (5d23245) (@cristiangreco, @clayton-cornell) - database_observability: Make targets optional (#5924) (54664b2) (@matthewnolf) - database_observability: Update default excluded schemas and users (#6080) (b386fff) (@cristiangreco) - faro.receiver: Add sourcemap fetching from remote locations (#4614) (b6cb5da) (@Oxel40) - helm: Add support for global.image.pullPolicy (#6069) (2e2ce72) (@petewall) - helm: Allow configuring image pull policy for config reloader (#5923) (991539b) (@kalleep) - loki.secretfilter: Add label_timed_out option to mark timed-out log lines (#5898) (2ad8834) (@kleimkuhler) - loki.secretfilter: Add secrets_redacted_by_category_total metric combining rule and origin (#5855) (053a2f7) (@kleimkuhler) - loki.secretfilter: Change secretfilter to use go-re2 regex library instead of stdlib (#5909) (c16a660) (@mikefat) - loki.secretfilter: Remove redundant secrets_redacted_by_rule_total and secrets_redacted_by_origin metrics (#5970) (b16decb) (@kleimkuhler) - Oracle exporter can scrape more than one DB (#6008) (6fbad38) (@ptodev) - prometheus.exporter.cloudwatch: Upgrade YACE and drop aws-sdk-go v1 support (#5936) (f1c036d) (@x1unix) - prometheus.exporter.mysql: Update to mysqld_exporter 0.19.0 (#5836) (4f49b57) (@cristiangreco) - prometheus.remote_write: Sync WAL with upstream Prometheus (#5907) (e74a91b) (@x1unix) - pyroscope: Add support for extra async-profiler CLI arguments (#5472) (9251e33) (@ivanape) - pyroscope: Replace Parca gRPC debuginfo upload with Pyroscope Connect API (#5891) (e7ea34a) (@korniltsev-grafanista) - pyroscope: Update debuginfo client for HTTP/1.1 upload API (#6037) (879d8e5) (@korniltsev-grafanista) * Bug Fixes - Change service stop command from 'sc' to 'net' (#5906) (450973d) (@mateuszdrab) - database_observability.mysql: Refactor explain plan loop batch size (#5894) (f0fcd6b) (@cristiangreco) - database_observability.postgres: Cleanup embedded exporter collectors on reconnection (#6079) (f30d9ae) (@cristiangreco) - database_observability.postgres: Fix EXPLAIN param count when placeholders repeat (#6082) (b612b81) (@rgeyer) - database_observability: Drop schema_detection from logs (#6076) (b0105cb) (@cristiangreco) - database_observability: Ensure connection_info_monitor goroutine exits on Stop (#5874) (1e3334b) (@cristiangreco) - deps: Update module github.com/aws/aws-sdk-go-v2/service/s3 to v1.97.3 [SECURITY] (#6004) (38f4346) - deps: Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY] (#5934) (a5154af) - deps: Update module github.com/go-git/go-git/v5 to v5.18.0 [SECURITY] (#6090) (0e59d64) - deps: Update module github.com/nwaples/rardecode/v2 to v2.2.0 [SECURITY] (b44d51a) (@jharvey10) - deps: Update module go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp to v1.43.0 [SECURITY] (#6016) (d92c5c0) - deps: Update module go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to v1.43.0 [SECURITY] (#6017) (e655bbc) - deps: Update module go.opentelemetry.io/otel/sdk to v1.43.0 [SECURITY] (#6018) (94006e8) - deps: Update some minor go dep versions (#5896) (4ddd0ed) (@jharvey10) - go: Update alloy builder image to Go 1.25.9 (#6012) (d2ae8b8) (@x1unix) - go: Upgrade to Go 1.25.9 (#6019) (d777ed1) (@x1unix, @kalleep) - Helm: RBAC template handles empty rule arrays (#4860) (c9430e9) (@naptalie, @dehaansa, @kalleep) - loki.process: Eliminate per-stream goroutines in multiline stage (#6036) (c089e2e) (@kgeckhart) - loki.process: Prevent stage.structured_metadata from adding the same metadata several times (#5965) (0ec8a26) (@kalleep, @thampiotr) - loki.process: Wrap template in a custom type and move validation to syntax.Validator (#5910) (700dd7d) (@kalleep) - prometheus.exporter.postgres: Close DB connections on update (#6021) (8da97cf) (@kalleep) - prometheus.scrape: Update scrape_native_histograms to be updated at runtime (#6087) (18b205c) (@kalleep) - pyroscope.ebpf: Fix deadlock on LRU eviction in irsymcache (#5911) (03ca563) (@luweglarz) - pyroscope.ebpf: Move Pyroscope ebpf metrics registration after component error handling (#5540) (a3c57c0) (@crbednarz, @marcsanmi) - pyroscope: Set user agent on debuginfo connect-go client (#6022) (38ad1ef) (@korniltsev-grafanista) - ui: Large arguments are downloaded as files instead of rendered (#5268) (26c67b3) (@ptodev) - Update go-m1cpu v0.1.7 -> v0.2.1 to fix M5 chip crash (#6034) (7fa0cbc) (@ymotongpoo) - windows-installer: Increase service restart on failure delays (#5969) (add15b1) (@rknightion) - add script to package webassets inside a podman container, to not endanger or pollute the host system with npm ++++ alloy: - update to 1.16.0: * Features - Add clustering for loki.source.kubernetes_events (#6027) (3dbf587) (@petewall) - Add otelcol.auth.google client auth provider (#5526) (da99a66) (@dashpole, @clayton-cornell) - beyla.ebpf: Bump to v3.7.0 (#5966) (5126c2e) (@marctc) - database_observability: Add support for GCP Cloud SQL metadata (#5875) (5d23245) (@cristiangreco, @clayton-cornell) - database_observability: Make targets optional (#5924) (54664b2) (@matthewnolf) - database_observability: Update default excluded schemas and users (#6080) (b386fff) (@cristiangreco) - faro.receiver: Add sourcemap fetching from remote locations (#4614) (b6cb5da) (@Oxel40) - helm: Add support for global.image.pullPolicy (#6069) (2e2ce72) (@petewall) - helm: Allow configuring image pull policy for config reloader (#5923) (991539b) (@kalleep) - loki.secretfilter: Add label_timed_out option to mark timed-out log lines (#5898) (2ad8834) (@kleimkuhler) - loki.secretfilter: Add secrets_redacted_by_category_total metric combining rule and origin (#5855) (053a2f7) (@kleimkuhler) - loki.secretfilter: Change secretfilter to use go-re2 regex library instead of stdlib (#5909) (c16a660) (@mikefat) - loki.secretfilter: Remove redundant secrets_redacted_by_rule_total and secrets_redacted_by_origin metrics (#5970) (b16decb) (@kleimkuhler) - Oracle exporter can scrape more than one DB (#6008) (6fbad38) (@ptodev) - prometheus.exporter.cloudwatch: Upgrade YACE and drop aws-sdk-go v1 support (#5936) (f1c036d) (@x1unix) - prometheus.exporter.mysql: Update to mysqld_exporter 0.19.0 (#5836) (4f49b57) (@cristiangreco) - prometheus.remote_write: Sync WAL with upstream Prometheus (#5907) (e74a91b) (@x1unix) - pyroscope: Add support for extra async-profiler CLI arguments (#5472) (9251e33) (@ivanape) - pyroscope: Replace Parca gRPC debuginfo upload with Pyroscope Connect API (#5891) (e7ea34a) (@korniltsev-grafanista) - pyroscope: Update debuginfo client for HTTP/1.1 upload API (#6037) (879d8e5) (@korniltsev-grafanista) * Bug Fixes - Change service stop command from 'sc' to 'net' (#5906) (450973d) (@mateuszdrab) - database_observability.mysql: Refactor explain plan loop batch size (#5894) (f0fcd6b) (@cristiangreco) - database_observability.postgres: Cleanup embedded exporter collectors on reconnection (#6079) (f30d9ae) (@cristiangreco) - database_observability.postgres: Fix EXPLAIN param count when placeholders repeat (#6082) (b612b81) (@rgeyer) - database_observability: Drop schema_detection from logs (#6076) (b0105cb) (@cristiangreco) - database_observability: Ensure connection_info_monitor goroutine exits on Stop (#5874) (1e3334b) (@cristiangreco) - deps: Update module github.com/aws/aws-sdk-go-v2/service/s3 to v1.97.3 [SECURITY] (#6004) (38f4346) - deps: Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY] (#5934) (a5154af) - deps: Update module github.com/go-git/go-git/v5 to v5.18.0 [SECURITY] (#6090) (0e59d64) - deps: Update module github.com/nwaples/rardecode/v2 to v2.2.0 [SECURITY] (b44d51a) (@jharvey10) - deps: Update module go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp to v1.43.0 [SECURITY] (#6016) (d92c5c0) - deps: Update module go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to v1.43.0 [SECURITY] (#6017) (e655bbc) - deps: Update module go.opentelemetry.io/otel/sdk to v1.43.0 [SECURITY] (#6018) (94006e8) - deps: Update some minor go dep versions (#5896) (4ddd0ed) (@jharvey10) - go: Update alloy builder image to Go 1.25.9 (#6012) (d2ae8b8) (@x1unix) - go: Upgrade to Go 1.25.9 (#6019) (d777ed1) (@x1unix, @kalleep) - Helm: RBAC template handles empty rule arrays (#4860) (c9430e9) (@naptalie, @dehaansa, @kalleep) - loki.process: Eliminate per-stream goroutines in multiline stage (#6036) (c089e2e) (@kgeckhart) - loki.process: Prevent stage.structured_metadata from adding the same metadata several times (#5965) (0ec8a26) (@kalleep, @thampiotr) - loki.process: Wrap template in a custom type and move validation to syntax.Validator (#5910) (700dd7d) (@kalleep) - prometheus.exporter.postgres: Close DB connections on update (#6021) (8da97cf) (@kalleep) - prometheus.scrape: Update scrape_native_histograms to be updated at runtime (#6087) (18b205c) (@kalleep) - pyroscope.ebpf: Fix deadlock on LRU eviction in irsymcache (#5911) (03ca563) (@luweglarz) - pyroscope.ebpf: Move Pyroscope ebpf metrics registration after component error handling (#5540) (a3c57c0) (@crbednarz, @marcsanmi) - pyroscope: Set user agent on debuginfo connect-go client (#6022) (38ad1ef) (@korniltsev-grafanista) - ui: Large arguments are downloaded as files instead of rendered (#5268) (26c67b3) (@ptodev) - Update go-m1cpu v0.1.7 -> v0.2.1 to fix M5 chip crash (#6034) (7fa0cbc) (@ymotongpoo) - windows-installer: Increase service restart on failure delays (#5969) (add15b1) (@rknightion) - add script to package webassets inside a podman container, to not endanger or pollute the host system with npm ++++ alloy: - update to 1.16.0: * Features - Add clustering for loki.source.kubernetes_events (#6027) (3dbf587) (@petewall) - Add otelcol.auth.google client auth provider (#5526) (da99a66) (@dashpole, @clayton-cornell) - beyla.ebpf: Bump to v3.7.0 (#5966) (5126c2e) (@marctc) - database_observability: Add support for GCP Cloud SQL metadata (#5875) (5d23245) (@cristiangreco, @clayton-cornell) - database_observability: Make targets optional (#5924) (54664b2) (@matthewnolf) - database_observability: Update default excluded schemas and users (#6080) (b386fff) (@cristiangreco) - faro.receiver: Add sourcemap fetching from remote locations (#4614) (b6cb5da) (@Oxel40) - helm: Add support for global.image.pullPolicy (#6069) (2e2ce72) (@petewall) - helm: Allow configuring image pull policy for config reloader (#5923) (991539b) (@kalleep) - loki.secretfilter: Add label_timed_out option to mark timed-out log lines (#5898) (2ad8834) (@kleimkuhler) - loki.secretfilter: Add secrets_redacted_by_category_total metric combining rule and origin (#5855) (053a2f7) (@kleimkuhler) - loki.secretfilter: Change secretfilter to use go-re2 regex library instead of stdlib (#5909) (c16a660) (@mikefat) - loki.secretfilter: Remove redundant secrets_redacted_by_rule_total and secrets_redacted_by_origin metrics (#5970) (b16decb) (@kleimkuhler) - Oracle exporter can scrape more than one DB (#6008) (6fbad38) (@ptodev) - prometheus.exporter.cloudwatch: Upgrade YACE and drop aws-sdk-go v1 support (#5936) (f1c036d) (@x1unix) - prometheus.exporter.mysql: Update to mysqld_exporter 0.19.0 (#5836) (4f49b57) (@cristiangreco) - prometheus.remote_write: Sync WAL with upstream Prometheus (#5907) (e74a91b) (@x1unix) - pyroscope: Add support for extra async-profiler CLI arguments (#5472) (9251e33) (@ivanape) - pyroscope: Replace Parca gRPC debuginfo upload with Pyroscope Connect API (#5891) (e7ea34a) (@korniltsev-grafanista) - pyroscope: Update debuginfo client for HTTP/1.1 upload API (#6037) (879d8e5) (@korniltsev-grafanista) * Bug Fixes - Change service stop command from 'sc' to 'net' (#5906) (450973d) (@mateuszdrab) - database_observability.mysql: Refactor explain plan loop batch size (#5894) (f0fcd6b) (@cristiangreco) - database_observability.postgres: Cleanup embedded exporter collectors on reconnection (#6079) (f30d9ae) (@cristiangreco) - database_observability.postgres: Fix EXPLAIN param count when placeholders repeat (#6082) (b612b81) (@rgeyer) - database_observability: Drop schema_detection from logs (#6076) (b0105cb) (@cristiangreco) - database_observability: Ensure connection_info_monitor goroutine exits on Stop (#5874) (1e3334b) (@cristiangreco) - deps: Update module github.com/aws/aws-sdk-go-v2/service/s3 to v1.97.3 [SECURITY] (#6004) (38f4346) - deps: Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY] (#5934) (a5154af) - deps: Update module github.com/go-git/go-git/v5 to v5.18.0 [SECURITY] (#6090) (0e59d64) - deps: Update module github.com/nwaples/rardecode/v2 to v2.2.0 [SECURITY] (b44d51a) (@jharvey10) - deps: Update module go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp to v1.43.0 [SECURITY] (#6016) (d92c5c0) - deps: Update module go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp to v1.43.0 [SECURITY] (#6017) (e655bbc) - deps: Update module go.opentelemetry.io/otel/sdk to v1.43.0 [SECURITY] (#6018) (94006e8) - deps: Update some minor go dep versions (#5896) (4ddd0ed) (@jharvey10) - go: Update alloy builder image to Go 1.25.9 (#6012) (d2ae8b8) (@x1unix) - go: Upgrade to Go 1.25.9 (#6019) (d777ed1) (@x1unix, @kalleep) - Helm: RBAC template handles empty rule arrays (#4860) (c9430e9) (@naptalie, @dehaansa, @kalleep) - loki.process: Eliminate per-stream goroutines in multiline stage (#6036) (c089e2e) (@kgeckhart) - loki.process: Prevent stage.structured_metadata from adding the same metadata several times (#5965) (0ec8a26) (@kalleep, @thampiotr) - loki.process: Wrap template in a custom type and move validation to syntax.Validator (#5910) (700dd7d) (@kalleep) - prometheus.exporter.postgres: Close DB connections on update (#6021) (8da97cf) (@kalleep) - prometheus.scrape: Update scrape_native_histograms to be updated at runtime (#6087) (18b205c) (@kalleep) - pyroscope.ebpf: Fix deadlock on LRU eviction in irsymcache (#5911) (03ca563) (@luweglarz) - pyroscope.ebpf: Move Pyroscope ebpf metrics registration after component error handling (#5540) (a3c57c0) (@crbednarz, @marcsanmi) - pyroscope: Set user agent on debuginfo connect-go client (#6022) (38ad1ef) (@korniltsev-grafanista) - ui: Large arguments are downloaded as files instead of rendered (#5268) (26c67b3) (@ptodev) - Update go-m1cpu v0.1.7 -> v0.2.1 to fix M5 chip crash (#6034) (7fa0cbc) (@ymotongpoo) - windows-installer: Increase service restart on failure delays (#5969) (add15b1) (@rknightion) - add script to package webassets inside a podman container, to not endanger or pollute the host system with npm ++++ apparmor: - Add and use tmpfiles.d/apparmor.conf for log and cache path creation (jsc#PED-14916) (jsc#PED-14917) + drop removal of pre-2.12 cache location + retain "apparmor_parser --purge-cache" calls for non-transactional systems ++++ apparmor: - Add and use tmpfiles.d/apparmor.conf for log and cache path creation (jsc#PED-14916) (jsc#PED-14917) + drop removal of pre-2.12 cache location + retain "apparmor_parser --purge-cache" calls for non-transactional systems ++++ kernel-64kb: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-64kb: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-64kb: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-azure: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-azure: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-azure: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-default: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-default: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-default: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-rt: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-rt: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ kernel-rt: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ cpp-httplib: - Fix CVE-2026-21428, server-side request forgery via header injection (CVE-2026-21428, bsc#1255835) * CVE-2026-21428.patch - Fix CVE-2026-22776, unsafe handling of compressed HTTP request can cause a denial of service (CVE-2026-22776, bsc#1256518) * CVE-2026-22776.patch - Fix CVE-2026-28434, default exception handler may leak e.what() to clients via EXCEPTION_WHAT response header (CVE-2026-28434, bsc#1259221) * CVE-2026-28434.patch - Fix CVE-2026-28435, payload size limit bypass via gzip decompression in ContentReader (streaming) can lead to denial of service (CVE-2026-28435, bsc#1259220) * CVE-2026-28435.patch - Fix CVE-2026-29076, denial of service via crafted HTTP POST request (CVE-2026-29076, bsc#1259373) * CVE-2026-29076.patch ++++ dtb-aarch64: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ dtb-aarch64: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ dtb-aarch64: - bpf: Fix exception exit lock checking for subprogs (CVE-2026-31526 bsc#1262662). - commit e8bea84 - bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI (git-fixes). - commit 4c19788 - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - interconnect: debugfs: fix devm_kstrdup and kfree mismatch (git-fixes). - extcon: Fixed sysfs duplicate filename issue (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - bus: mhi: host: pci_generic: Switch to async power up to avoid boot delays (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ad7192: Revert "properly check spi_get_device_match_data()" (stable-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: mpc52xx: fix use-after-free on registration failure (git-fixes). - spi: topcliff-pch: fix use-after-free on unbind (git-fixes). - spi: topcliff-pch: fix controller deregistration (git-fixes). - spi: orion: fix controller deregistration (git-fixes). - spi: mxic: fix controller deregistration (git-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mpc52xx: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: mtk-snfi: fix memory leak in probe (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: pcmtest: Fix resource leaks in module init error paths (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: pcmtest: fix reference leak on failed device registration (git-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: virtio: drop an extaneous kernel-doc comment (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - commit 01d4865 ++++ vim: - Fix bsc#1261833 / CVE-2026-39881. - Update to 9.2.0398. - Changes: * 9.2.0398: MS-Windows: missing strptime() support * 9.2.0397: tabpanel: double-click opens a new tab * 9.2.0396: tests: Test_error_callback_terminal is flaky on macOS * 9.2.0395: tests: Test_backupskip() may read from $HOME * 9.2.0394: xxd: offsets greater than LONG_MAX print as negative * 9.2.0393: MS-Windows: link error with XPM support on UCRT64 * 9.2.0392: tests: Some tests are flaky * 9.2.0391: tests: Comment in test_vim9_cmd breaks syntax highlighting * 9.2.0390: filetype: some Beancount files are not recognized * 9.2.0389: DECRQM still leaves stray "pp" on Apple Terminal.app * 9.2.0388: strange indent in update_topline() * 9.2.0387: DECRQM request may leave stray chars in terminal * 9.2.0386: No scroll/scrollbar support in the tabpanel * 9.2.0385: Integer overflow with "ze" and large 'sidescrolloff' * 9.2.0384: stale Insstart after cursor move breaks undo * 9.2.0383: [security]: runtime(netrw): shell-injection via sftp: and file: URLs * 9.2.0382: Wayland: focus-stealing is non-working * 9.2.0381: Vim9: Missing check_secure() in exec_instructions() * 9.2.0380: completion: a few issues in completion code * 9.2.0379: gui.color_approx is never used * 9.2.0378: Using int as bool type in win_T struct * 9.2.0377: Using int as bool type in gui_T struct * 9.2.0376: Vim9: elseif condition compiled in dead branch * 9.2.0375: prop_find() does not find a virt text in starting line * 9.2.0374: c_CTRL-{G,T} does not handle offset * 9.2.0373: Ctrl-R mapping not triggered during completion * 9.2.0372: pum: rendering issues with multibyte text and opacity * 9.2.0371: filetype: ghostty config files are not recognized * 9.2.0370: duplicate code with literal string_T assignment * 9.2.0369: multiple definitions of STRING_INIT macro * 9.2.0368: too many strlen() calls when adding strings to dicts * 9.2.0367: runtime(netrw): ~ note expanded on MS Windows * 9.2.0366: pum: flicker when updating pum in place * 9.2.0365: using int as bool * 9.2.0364: tests: test_smoothscroll_textoff_showbreak() fails * 9.2.0363: Vim9: variable shadowed by script-local function * 9.2.0362: division by zero with smoothscroll and small windows * 9.2.0361: tests: no tests for ch_listen() with IPs * 9.2.0360: Cannot handle mouse-clicks in the tabpanel * 9.2.0359: wrong VertSplitNC highlighting on winbar * 9.2.0358: runtime(vimball): still path traversal attacks possible * 9.2.0357: [security]: command injection via backticks in tag files * 9.2.0356: Cannot apply 'scrolloff' context lines at end of file * 9.2.0355: runtime(tar): missing path traversal checks in tar#Extract() * 9.2.0354: filetype: not all Bitbake include files are recognized * 9.2.0353: Missing out-of-memory check in register.c * 9.2.0352: 'winhighlight' of left window blends into right window * 9.2.0351: repeat_string() can be improved * 9.2.0350: Enabling modelines poses a risk * 9.2.0349: cannot style non-current window separator * 9.2.0348: potential buffer underrun when setting statusline like option * 9.2.0347: Vim9: script-local variable not found * 9.2.0346: Wrong cursor position when entering command line window * 9.2.0345: Wrong autoformatting with 'autocomplete' * 9.2.0344: channel: ch_listen() can bind to network interface * 9.2.0343: tests: test_clientserver may fail on slower systems * 9.2.0342: tests: test_excmd.vim leaves swapfiles behind * 9.2.0341: some functions can be run from the sandbox * 9.2.0340: pum_redraw() may cause flicker * 9.2.0339: regexp: nfa_regmatch() allocates and frees too often * 9.2.0338: Cannot handle mouseclicks in the tabline * 9.2.0337: list indexing broken on big-endian 32-bit platforms * 9.2.0336: libvterm: no terminal reflow support * 9.2.0335: json_encode() uses recursive algorithm * 9.2.0334: GTK: window geometry shrinks with with client-side decorations * 9.2.0333: filetype: PklProject files are not recognized * 9.2.0332: popup: still opacity rendering issues * 9.2.0331: spellfile: stack buffer overflows in spell file generation * 9.2.0330: tests: some patterns in tar and zip plugin tests not strict enough * 9.2.0329: tests: test_indent.vim leaves swapfiles behind * 9.2.0328: Cannot handle mouseclicks in the statusline * 9.2.0327: filetype: uv scripts are not detected * 9.2.0326: runtime(tar): but with dotted path * 9.2.0325: runtime(tar): bug in zstd handling * 9.2.0324: 0x9b byte not unescaped in mapping * 9.2.0323: filetype: buf.lock files are not recognized * 9.2.0322: tests: test_popupwin fails * 9.2.0321: MS-Windows: No OpenType font support * 9.2.0320: several bugs with text properties * 9.2.0319: popup: rendering issues with partially transparent popups * 9.2.0318: cannot configure opacity for popup menu * 9.2.0317: listener functions do not check secure flag * 9.2.0316: [security]: command injection in netbeans interface via defineAnnoType * 9.2.0315: missing bound-checks * 9.2.0314: channel: can bind to all network interfaces * 9.2.0313: Callback channel not registered in GUI * 9.2.0312: C-type names are marked as translatable * 9.2.0311: redrawing logic with text properties can be improved * 9.2.0310: unnecessary work in vim_strchr() and find_term_bykeys() * 9.2.0309: Missing out-of-memory check to may_get_cmd_block() * 9.2.0308: Error message E1547 is wrong * 9.2.0307: more mismatches between return types and documentation * 9.2.0306: runtime(tar): some issues with lz4 support * 9.2.0305: mismatch between return types and documentation * 9.2.0304: tests: test for 9.2.0285 doesn't always fail without the fix * 9.2.0303: tests: zip plugin tests don't check for warning message properly * 9.2.0302: runtime(netrw): RFC2396 decoding double escaping spaces * 9.2.0301: Vim9: void function return value inconsistent * 9.2.0300: The vimball plugin needs some love * 9.2.0299: runtime(zip): may write using absolute paths * 9.2.0298: Some internal variables are not modified * 9.2.0297: libvterm: can improve CSI overflow code * 9.2.0296: Redundant and incorrect integer pointer casts in drawline.c * 9.2.0295: 'showcmd' shows wrong Visual block size with 'linebreak' * 9.2.0294: if_lua: lua interface does not work with lua 5.5 * 9.2.0293: :packadd may lead to heap-buffer-overflow * 9.2.0292: E340 internal error when using method call on void value * 9.2.0291: too many strlen() calls * 9.2.0290: Amiga: no support for AmigaOS 3.x * 9.2.0289: 'linebreak' may lead to wrong Visual block highlighting * 9.2.0288: libvterm: signed integer overflow parsing long CSI args * 9.2.0287: filetype: not all ObjectScript routines are recognized * 9.2.0286: still some unnecessary (int) casts in alloc() * 9.2.0285: :syn sync grouphere may go beyond end of line * 9.2.0284: tabpanel: crash when tabpanel expression returns variable line count * 9.2.0283: unnecessary (int) casts before alloc() calls * 9.2.0282: tests: Test_viminfo_len_overflow() fails * 9.2.0281: tests: Test_netrw_FileUrlEdit.. fails on Windows ++++ java-25-openjdk: - Update to upstream tag jdk-25.0.3+9 (April 2026 CPU) * CVEs + CVE-2026-22007 (bsc#1262490) + CVE-2026-22008 (bsc#1262493) + CVE-2026-22013 (bsc#1262494) + CVE-2026-22016 (bsc#1262495) + CVE-2026-22018 (bsc#1262496) + CVE-2026-22021 (bsc#1262497) + CVE-2026-23865 (bsc#1259118) + CVE-2026-34268 (bsc#1262500) + CVE-2026-34282 (bsc#1262501) * Changes + JDK-7191877: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/ /CheckLeaseLeak.java failing intermittently + JDK-8030957: AIX: Implement OperatingSystemMXBean .getSystemCpuLoad() and .getProcessCpuLoad() on AIX + JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update + JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java + JDK-8212084: G1: Implement UseGCOverheadLimit + JDK-8244336: Restrict algorithms at JCE layer + JDK-8246037: Shenandoah: update man pages to mention - XX:+UseShenandoahGC + JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException + JDK-8256289: java/awt/Focus/AppletInitialFocusTest/ /AppletInitialFocusTest1.java failed with "RuntimeException: Wrong focus owner: java.awt.Button[button1,41,36,56x23,label=Button1]" + JDK-8274082: Wrong test name in jtreg run tag for java/awt/print/PrinterJob/SwingUIText.java + JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially + JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/nativeAndMH/ /Test.java fails with Out of space in CodeCache + JDK-8287062: com/sun/jndi/ldap/LdapPoolTimeoutTest.java failed due to different timeout message + JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support + JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit + JDK-8307495: Specialize atomic bitset functions for aix-ppc + JDK-8313770: jdk/internal/platform/docker/ /TestSystemMetrics.java fails on Ubuntu + JDK-8316274: javax/swing/ButtonGroup/ /TestButtonGroupFocusTraversal.java fails in Ubuntu 23.10 with Motif LAF + JDK-8317838: java/nio/channels/Channels/ /SocketChannelStreams.java running into timeout (aix) + JDK-8318662: Refactor some jdk/java/net/httpclient/http2 tests to JUnit + JDK-8320677: Printer tests use invalid '@run main/manual=yesno + JDK-8333857: Test sun/security/ssl/SSLSessionImpl/ /ResumeChecksServer.java failed: Existing session was used + JDK-8333871: Check return values of sysinfo + JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use + JDK-8335646: Nimbus : JLabel not painted with LAF defined foreground color on Ubuntu 24.04 + JDK-8336695: Update Commons BCEL to Version 6.10.0 + JDK-8339791: Refactor MiscUndecorated/ActiveAWTWindowTest.java + JDK-8341039: compiler/cha/TypeProfileFinalMethod.java fails with assertEquals expected: 0 but was: 2 + JDK-8342175: MemoryEaterMT fails intermittently with ExceptionInInitializerError + JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts + JDK-8342640: GenShen: Silently ignoring ShenandoahGCHeuristics considered poor user-experience + JDK-8342659: Test vmTestbase/nsk/jdi/ObjectReference/ /referringObjects/referringObjects002/referringObjects002.java failed: Class nsk.share.jdi.TestClass1 was not unloaded + JDK-8343316: Review and update tests using explicit provider names + JDK-8343340: Swapping checking do not work for MetricsMemoryTester failcount + JDK-8343474: [updates] Customize README.md to specifics of update project + JDK-8344073: Test runtime/cds/appcds/ /TestParallelGCWithCDS.java#id0 failed + JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally + JDK-8346962: Test CRLReadTimeout.java fails with -Xcomp on a fastdebug build + JDK-8348014: Enhance certificate processing + JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000) + JDK-8352149: Test java/awt/Frame/MultiScreenTest.java fails: Window list is empty + JDK-8353755: Add a helper method to Util - findComponent() + JDK-8354244: Use random data in MinMaxRed_Long data arrays + JDK-8354469: Keytool exposes the password in plain text when command is piped using | grep + JDK-8354894: java/lang/Thread/virtual/Starvation.java timeout on server with high CPUs + JDK-8354937: Cleanup some sparc related coding in os_linux + JDK-8356548: Use ClassFile API instead of ASM to transform classes in tests + JDK-8356868: Not all cgroup parameters are made available + JDK-8357277: Update OpenSSL library for interop tests + JDK-8357380: java/lang/StringBuilder/RacingSBThreads.java times out with C1 + JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system + JDK-8357470: src/java.base/share/classes/sun/security/util/ /Debug.java implement the test for args.toLowerCase + JDK-8357570: [macOS] os::Bsd::available_memory() might return too low values + JDK-8357591: Re-enable CDS test cases for jvmci after JDK-8345826 + JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently + JDK-8358159: Empty mode/padding in cipher transformations + JDK-8358529: GenShen: Heuristics do not respond to changes in SoftMaxHeapSize + JDK-8358679: [asan] vmTestbase/nsk/jvmti tests show memory issues + JDK-8358686: CDS and AOT can cause buffer truncation warning even when logging is disabled + JDK-8358735: GenShen: block_start() may be incorrect after class unloading + JDK-8358756: [s390x] Test StartupOutput.java crash due to CodeCache size + JDK-8358801: javac produces class that does not pass verifier. + JDK-8359064: Expose reason for marking nmethod non-entrant to JVMCI client + JDK-8359182: Use @requires instead of SkippedException for MaxPath.java + JDK-8359388: Stricter checking for cipher transformations + JDK-8359418: Test "javax/swing/text/GlyphView/bug4188841.java" failed because the phrase of text pane does not match the instructions + JDK-8359472: JVM crashes when attaching a dynamic agent before JVMTI_PHASE_LIVE + JDK-8359707: Add classfile modification code to RedefineClassHelper + JDK-8359868: Shenandoah: Free threshold heuristic does not use SoftMaxHeapSize + JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine + JDK-8360049: CodeInvalidationReasonTest.java fails with ZGC on AArch64 + JDK-8360160: ubuntu-22-04 machine is failing client tests + JDK-8360169: Problem list CodeInvalidationReasonTest.java on linux-riscv64 until JDK-8360168 is fixed + JDK-8360271: String.indexOf intrinsics fail with +EnableX86ECoreOpts and -CompactStrings + JDK-8360395: sun/security/tools/keytool/i18n.java user country is current user location instead of the language + JDK-8360539: DTLS handshakes fails due to improper cookie validation logic + JDK-8360562: sun/security/tools/keytool/i18n.java add an ability to add comment for failures + JDK-8360702: runtime/Thread/AsyncExceptionTest.java timed out + JDK-8360882: Tests throw SkippedException when they should fail + JDK-8361067: Test ExtraButtonDrag.java requires frame.dispose in finally block + JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException + JDK-8361363: ShenandoahAsserts::print_obj() does not work for forwarded objects and UseCompactObjectHeaders + JDK-8361381: GlyphLayout behavior differs on JDK 11+ compared to JDK 8 + JDK-8361492: [IR Framework] Has too restrictive regex for load and store + JDK-8361521: BogusFocusableWindowState.java fails with StackOverflowError on Linux + JDK-8361530: Test javax/swing/GraphicsConfigNotifier/ /StalePreferredSize.java timed out + JDK-8361613: System.console() should only be available for interactive terminal + JDK-8361894: sun/security/krb5/config/native/ /TestDynamicStore.java ensure that the test is run with sudo + JDK-8362284: RISC-V: cleanup NativeMovRegMem + JDK-8362979: C2 fails with unexpected node in SuperWord truncation: CmpLTMask, RoundF + JDK-8363950: Incorrect jtreg header in TestLayoutVsICU.java + JDK-8364373: Transform Affine transformations + JDK-8364465: Enhance behavior of some intrinsics + JDK-8364580: Test compiler/vectorization/ /TestSubwordTruncation.java fails on platforms without RoundF/RoundD + JDK-8364741: [asan] runtime/ErrorHandling/ /PrintVMInfoAtExitTest.java fails because output differs slightly + JDK-8364756: JFR: Improve slow tests + JDK-8364936: Shenandoah: Switch nmethod entry barriers to conc_instruction_and_data_patch + JDK-8365065: cancelled ForkJoinPool tasks no longer throw CancellationException + JDK-8365184: sun/tools/jhsdb/ /HeapDumpTestWithActiveProcess.java Re-enable SerialGC flag on debuggee process + JDK-8365305: The ARIA role ‘contentinfo’ is not valid for the element