<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>openSUSE News</title>
    <link>https://news.opensuse.org</link>
    <description>Latest news from the openSUSE Project</description>
    <atom:link href="https://news.opensuse.org/feed.xml" rel="self" type="application/rss+xml"/>

    <item>
      <guid>https://news.opensuse.org/2026/09/18/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 18 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/18/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. This community blog feed aggregator lists the featured highlights below from Sept. 11 - 17. This week highlights the release of Agama 24 with a two-for-one announcement covering versions 23 and 24, the beta release of Plasma...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;. This community blog feed aggregator lists the featured highlights below from Sept. 11 - 17.&lt;/p&gt;

&lt;p&gt;This week highlights the release of Agama 24 with a two-for-one announcement covering versions 23 and 24, the beta release of Plasma 6.8 along with its first “This Week in Plasma” review, the first bug-fix update of KDE Gear 26.08 plus feature overviews of Kdenlive and Minuet, the Tumbleweed week 37 review and a September ARM update roundup, Intel’s OpenVINO 2026.4.0 release, the openSUSE Kudos report for August, the reveal of the GNOME 51 wallpapers, and a fond farewell to the Linux Hispano comic strip after 1,144 installments.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;introducing-enhanced-distribution-support&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/09/17/enhanced-distribution-support/&quot;&gt;Introducing Enhanced Distribution Support&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org&quot;&gt;Open Build Service&lt;/a&gt; blog introduces Enhanced Distribution Support, a beta feature that gives structure to distribution information through a vendor → distribution → release hierarchy, letting maintainers record what they ship, which repositories and architectures each release is built from, and dated lifecycle milestones. It’s an early, purely descriptive first iteration, and the OBS team is asking distribution maintainers what else they need to be able to describe.&lt;/p&gt;

&lt;h2 id=&quot;openvino-202640-a-new-version-announced&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/09/16/openvino-2026-4-0-nova-versao-anunciada/&quot;&gt;OpenVINO 2026.4.0: A New Version Announced&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s&lt;/a&gt; blog reports on Intel’s OpenVINO 2026.4.0 release, which broadens model support across Intel CPUs, GPUs and NPUs while adding speculative decoding with Multi-Token Prediction. The post also covers EAGLE-3 Tree Drafting, ITT tracing extended to the NPU for VTune, an ASR pipeline for Node.js and idle-model management in the OpenVINO Model Server.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed-arm-updates-in-september&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/16/tw-arm-update/&quot;&gt;Tumbleweed ARM Updates in September&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog covers September’s Tumbleweed updates for the ARM port, led by a security-heavy kernel 7.2.5, glibc 2.44 with its large AArch64 push and QEMU 11.1.1. Raspberry Pi owners get a firmware fix that clears up a Wi-Fi scan error, Rockchip and other SBCs receive MediaTek Wi-Fi kernel fixes, and GIMP 3.2.6, shotwell 33.0 and kbd 2.10.0 land AArch64-specific improvements.&lt;/p&gt;

&lt;h2 id=&quot;gnome-51-wallpapers&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/gnome51-wallpapers/&quot;&gt;GNOME 51 Wallpapers&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; reveals the GNOME 51 wallpaper set, calling the collection evolution rather than revolution as it sticks to its geometric roots. The default is a stylistic touch-up of the GNOME 50 hexagons, images now carry an embedded thumbnail that helps the Appearance panel, and attribution and license data are embedded directly into the files.&lt;/p&gt;

&lt;h2 id=&quot;download-a-random-linux-hispano-comic-strip-in-the-terminal&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/15/descarga-una-tira-aleatoria-de-linux-hispano-en-la-terminal/&quot;&gt;Download a Random Linux Hispano Comic Strip in the Terminal&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; shares a pair of scripts for revisiting the 1,144 Linux Hispano comic strips that Danigm published between 2004 and 2026 after the series came to an end. A Python scraper archived every strip into a GitHub repository, while a Bash script picks a random strip and displays it with feh along with its name and publication date.&lt;/p&gt;

&lt;h2 id=&quot;syslog-ng-repo-for-amazon-linux-2023-updated-to-syslog-ng-version-412&quot;&gt;&lt;a href=&quot;https://peter.czanik.hu/other/syslog-ng-for-amazon-linux-updated-to-4-12/&quot;&gt;Syslog-ng repo for Amazon Linux 2023 updated to syslog-ng version 4.12&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://peter.czanik.hu/&quot;&gt;Peter Czanik&lt;/a&gt; reports that his syslog-ng repository for Amazon Linux 2023 has been updated to version 4.12 after a GitHub request finally prompted an update. He recounts how the repo, first created two years ago, sat untouched due to a lack of feedback despite healthy download numbers from Copr, with Java support and slog disabled as in his other repositories.&lt;/p&gt;

&lt;h2 id=&quot;kudos-august-2026&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/15/kudos-august/&quot;&gt;Kudos August 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog presents the monthly Kudos report, in which 17 users received 24 kudos and 419 badges were awarded to 251 contributors during August. Bernhard Wiedemann tops the list with five kudos, mostly for his work on Slowroll, and four contributors reached the milestone of 100 Tumbleweed Contributions.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-in-minuet-from-kde-gear-2608-enjoy-shiny-stuff-edition&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/las-novedades-de-minuet-de-kde-gear-26-08-edicion-enjoy-shiny-stuff.html&quot;&gt;What’s New in Minuet from KDE Gear 26.08, “Enjoy Shiny Stuff” Edition&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; closes its KDE Gear 26.08 feature series with Minuet, the music education app that trains the ear through interval, chord, scale and rhythm exercises. Minuet debuts a new interface that works on both desktops and phones, with a reworked home page and navigation sidebar, exercises shown as cards and a search field that filters by translated names and descriptions.&lt;/p&gt;

&lt;h2 id=&quot;software-freedom-day-2026&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/dia-de-la-llibertat-del-programari-2026.html&quot;&gt;Software Freedom Day 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the Dia de la Llibertat del Programari (Software Freedom Day) celebration organized by Caliu on September 19 at the Espai Jove La Fontana in Barcelona, an event where the KDE community is usually well represented. The post translates the Catalan agenda, listing three talks on teaching computing with values, bootstrapping a self-managed forge with Haz-CLI and security on GNU/Linux.&lt;/p&gt;

&lt;h2 id=&quot;happy-programmers-day&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/09/13/feliz-dia-do-programador-2/&quot;&gt;Happy Programmer’s Day&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s&lt;/a&gt; blog celebrates Programmer’s Day, which falls on the 256th day of the year and explains why the number 256, or 2^8, matters in computing. The post thanks developers for turning coffee into software, errors into lessons and ideas into innovation.&lt;/p&gt;

&lt;h2 id=&quot;innit&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/innit/&quot;&gt;Innit&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; shares how he produced the tune “Innit” for his weeklybeats 2026 project on the Elektron Analog Four rather than his usual Dirtywave M8. After years of avoiding them, he finally learned the box’s performance macros, which bundle up to five track parameters onto a single knob and make live performance far less stressful than pre-programming a sequence.&lt;/p&gt;

&lt;h2 id=&quot;plasma-68-beta-released--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzado-plasma-6-8-beta-esta-semana-en-plasma.html&quot;&gt;Plasma 6.8 Beta Released – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s weekly Plasma development report covering the 6.8 beta. Kup joins Plasma as its backup system, clipboard and MIME-action settings become far clearer, the on-screen keyboard button now behaves as expected on lock and login screens, and KWin gains support for the Wayland commit_timing protocol.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-219--butterbian-and-butterknife-distribution-exploration&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/09/12/linux-saloon-219-butterbian-and-butterknife-distribution-exploration/&quot;&gt;Linux Saloon 219 | Butterbian and ButterKnife Distribution Exploration&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;Nathan Wolf&lt;/a&gt; posts episode 219 of the Linux Saloon podcast, covering activities around the Vintage Computer Fest Midwest. The episode gathers user experiences with the Butterknife and Butterbian distributions through polls and links out to upcoming events and participant projects.&lt;/p&gt;

&lt;h2 id=&quot;first-update-of-kde-gear-2608&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/primera-actualizacion-de-kde-gear-26-08.html&quot;&gt;First Update of KDE Gear 26.08&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents the first update of KDE Gear 26.08, released almost a month after the feature set, bringing more stability, better translations and small improvements. It lists resolved issues across apps, libraries and widgets, including an arrow-orientation fix in KDE Connect, room-map handling in Kongress and an unexpected crash when saving documents in Okular.&lt;/p&gt;

&lt;h2 id=&quot;plasma-68-beta-released&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzada-la-beta-de-plasma-6-8.html&quot;&gt;Plasma 6.8 Beta Released&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; reports that the beta of Plasma 6.8 has been released and highlights changes drawn from its changelog, from the new Hanabi wallpaper replacing Waterfall in Breeze and Nepali calendar support to GTK4 window decoration fixes, an AppStream Preview backend in Discover and a QML rewrite of DrKonqi’s coredump viewer. It encourages users to install the beta and report bugs to help polish the release.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed--review-of-the-week-202637&quot;&gt;&lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/09/tumbleweed-review-of-the-week-2026-37/&quot;&gt;Tumbleweed – Review of the Week 2026/37&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://dominique.leuenberger.net/blog/&quot;&gt;Dominique Leuenberger&lt;/a&gt; and &lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/11/opensuse-tumbleweed-revision-de-la-semana-37-de-2026/&quot;&gt;Victorhck&lt;/a&gt; review the four Tumbleweed snapshots (0904, 0907, 0908 and 0909) of week 2026/37, which delivered Linux kernel 7.2.3 and 7.2.4, LibreOffice 26.8.0.3, QEMU 11.1.1, zypper 1.14.101 and more.&lt;/p&gt;

&lt;h2 id=&quot;tiny-wins-for-packagers-end-of-week-update&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/09/11/tiny-wins/&quot;&gt;Tiny Wins for Packagers: End-of-Week Update&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org/&quot;&gt;Open Build Service&lt;/a&gt; blog shares its end-of-week “Tiny Wins” update, which shipped a fix preventing a second click on the repository dropdown after an autocomplete selection and ensured the generated SBOM includes the SPDX V3 createdBy field. It also reports that build.opensuse.org served 22.8 million HTTP requests and produced 2.38 million package builds over the last seven days.&lt;/p&gt;

&lt;h2 id=&quot;agama-releasing-version-24&quot;&gt;&lt;a href=&quot;https://agama-project.github.io/blog/2026/09/11/agama-24&quot;&gt;Agama: Releasing Version 24&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://agama-project.github.io/blog/&quot;&gt;Agama blog&lt;/a&gt; announces Agama 24 in a two-for-one post covering versions 23 and 24 after a stabilization phase focused on testing and polish. Language, keyboard and time zone now share a single searchable form, network connections can be bound to devices through a sortable device table, and JSON search sections gained much more expressive device matching.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Tumbleweed&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/16/tw-arm-update/</guid>
      <title>Tumbleweed ARM Updates in September</title>
      <pubDate>Wed, 16 Sep 2026 12:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/16/tw-arm-update/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/sbc.png" length="36607" type="image/png" />
      <description>There were a few software package updates for openSUSE Tumbleweed ARM this month with snapshots reaching the ARM port. September’s snapshots of the ARM port carried the Linux kernel to a security-heavy 7.2.5. There was a jump to glibc 2.44 with its large AArch64 push, and QEMU reaching 11.1.1. Raspberry...</description>
      <content:encoded>&lt;p&gt;There were a few software package updates for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; &lt;a href=&quot;https://www.arm.com/&quot;&gt;ARM&lt;/a&gt; this month with snapshots reaching the &lt;a href=&quot;https://www.arm.com/&quot;&gt;ARM&lt;/a&gt; port.&lt;/p&gt;

&lt;p&gt;September’s snapshots of the &lt;a href=&quot;https://www.arm.com/&quot;&gt;ARM&lt;/a&gt; port carried the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; to a security-heavy 7.2.5. There was a jump to &lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; 2.44 with its large &lt;a href=&quot;https://en.wikipedia.org/wiki/AArch64&quot;&gt;AArch64&lt;/a&gt; push, and &lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; reaching 11.1.1. &lt;a href=&quot;https://www.raspberrypi.com/&quot;&gt;Raspberry Pi&lt;/a&gt; owners get a firmware fix that clears up a Wi-Fi scan error, the &lt;a href=&quot;https://networkmanager.dev/&quot;&gt;Networking Stack&lt;/a&gt; received security patches, and &lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; 3.2.6 brings AArch64-specific fixes.&lt;/p&gt;

&lt;h2 id=&quot;raspberry-pi&quot;&gt;Raspberry Pi&lt;/h2&gt;

&lt;p&gt;This month’s &lt;a href=&quot;https://github.com/raspberrypi/firmware&quot;&gt;raspberrypi-firmware&lt;/a&gt; update prevents the spurious “-52” error message that could appear during Wi-Fi scans (&lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1215134&quot;&gt;bsc#1215134&lt;/a&gt;), so scanning for networks is quieter on boards where the firmware reported a phantom failure. The &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 7.2.4 update fixed a memory leak in the brcmfmac driver’s SDIO control path, which reduces memory pressure over long uptimes on the onboard Cypress Wi-Fi chip used across recent Pi models.&lt;/p&gt;

&lt;h2 id=&quot;rockchip--other-sbcs&quot;&gt;Rockchip &amp;amp; Other SBCs&lt;/h2&gt;

&lt;p&gt;Owners of Rockchip and other single-board computers get kernel fixes for the MediaTek Wi-Fi chipsets that many boards ship with, including headroom fixes for USB/SDIO transfers on mt7925 and EEPROM size validation on the mt7915 and mt7996 drivers, which protects against malformed device data (bsc#1012628). &lt;a href=&quot;https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git&quot;&gt;kernel-firmware-qcom&lt;/a&gt; adds DSP firmware for the Qualcomm x1e80100, nord and qcs8300 platforms, improving modem, DSP and graphics support. &lt;a href=&quot;https://dracut.wiki.kernel.org/index.php/Main_Page&quot;&gt;dracut&lt;/a&gt; now includes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;leds-qcom-lpg&lt;/code&gt; in the aarch64 DRM module set, keeping RGB indicator LEDs working when booting from an initrd. Finally, &lt;a href=&quot;https://wireless.wiki.kernel.org/en/developers/regulatory&quot;&gt;wireless-regdb&lt;/a&gt; enables 320 MHz channels for Hong Kong, updates South Africa’s rules, and drops the 60 GHz DFS flag for Togo.&lt;/p&gt;

&lt;h2 id=&quot;imx--nxp&quot;&gt;i.MX &amp;amp; NXP&lt;/h2&gt;

&lt;p&gt;Developers working with NXP hardware gain the imx8mp-evk machine type in &lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; 11.1.1, which emulates the i.MX 8M Plus Evaluation Kit and makes it easier to test software for that platform without physical hardware. The kernel 7.2.3 update fixed the mxs-dcp crypto engine’s source scatterlist length access and improved the Data Co-Processor security block on i.MX System on Chips that use it for accelerated encryption. These changes make NXP hardware slightly more accessible to both emulation and crypto workloads.&lt;/p&gt;

&lt;h2 id=&quot;aarch64-virtualization-uefi--toolchain&quot;&gt;aarch64 Virtualization, UEFI &amp;amp; Toolchain&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; 11.1.1&lt;/strong&gt; is the virtualization highlight of the month, advancing the emulator with Universal Flash Storage emulation for Write Booster and Host-Initiated Defragmentation based on the UFS 4.1 specification, plus &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vhost-host-user&lt;/code&gt; support for offloading real-time clock handling through &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virtio-rtc&lt;/code&gt;. The ARM targets gain new architectural CPU features, and the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virt&lt;/code&gt; board can now specify cache topology. The ARM-specific fixes include a regression test and boundary-case fix for the SVE2 &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;whilewr&lt;/code&gt;/&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;whilerw&lt;/code&gt; instructions and a fix for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;arm_gicv3&lt;/code&gt; kconfig selection, and openSUSE disables GCS linker validation in the spec to keep the aarch64 build working.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; 2.44&lt;/strong&gt; delivers the strongest AArch64 additions in months. On targets with the Guarded Control Stack extension, glibc now locks all GCS operations, including status, write-on-shadow-stack and push-to-shadow-stack, immediately after enabling GCS with an ENFORCED or OVERRIDE policy, closing a window where a process could still mutate its own shadow stack. Special-case paths for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;exp&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sin&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cas&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sinh&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cosh&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;asinh&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;acosh&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;atanh&lt;/code&gt; are vectorized for both SVE and AdvSIMD, and vector &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;powr&lt;/code&gt; variants are added, which speeds up floating-point-heavy code on capable Cortex-X and Neoverse cores.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/tianocore/edk2&quot;&gt;ovmf&lt;/a&gt;&lt;/strong&gt; advances to edk2-stable202608, refreshing the UEFI firmware that backs the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;qemu-uefi-aarch64&lt;/code&gt; subpackage. The update adds AArch64 host test coverage across SecurityPkg, CryptoPkg, PrmPkg, DynamicTablesPkg, MdeModulePkg and MdePkg, plus UnitTestFrameworkPkg support for GCC AArch64, which strengthens firmware quality assurance for arm64 virtual machines. The EFI Memory Attributes Protocol workaround is dropped because &lt;a href=&quot;https://www.gnu.org/software/grub/&quot;&gt;GRUB2&lt;/a&gt; now supports the protocol, so booting stays compatible with the cleaner firmware behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/openSUSE/sdbootutil&quot;&gt;sdbootutil&lt;/a&gt;&lt;/strong&gt; improved its systemd-boot handling with a new status command, parallel test execution, a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--repair&lt;/code&gt; parameter for cleanup, and better reporting of entries with missing files. The update prevents duplicate entries on non-snapper systems, keeps the exit status of sdbootutil calls intact, and avoids writing the recovery PIN to the journal, which is a meaningful privacy improvement for systems using PCR-based secure boot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK4&lt;/a&gt; 4.22.5&lt;/strong&gt; fixes a build failure on 32-bit ARM and repairs 32-bit Vulkan image builds, so the toolkit and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gskvulkanimage&lt;/code&gt; both compile cleanly on armv7. A Wayland session crash in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gdk_wayland_toplevel_remove_from_session()&lt;/code&gt; and a memory buffer fix round out the release for desktop users on ARM.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://llvm.org/&quot;&gt;LLVM&lt;/a&gt; 23.1.1&lt;/strong&gt; arrives as a bugfix release for the 23.1.0 series, remaining API and ABI compatible while dropping the obsolete i586 build patch.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; 3.2.6&lt;/strong&gt; carries the first AArch64-specific wins for the image editor. The clipboard brush and pattern maximum size is bumped to 8192 on AArch64 as well, matching the ceiling that x86-64 and PPC64 have had since the 3.2.0 release candidates, so larger brushes and patterns survive clipboard round-trips on ARM desktops.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://wiki.gnome.org/Apps/Shotwell&quot;&gt;shotwell&lt;/a&gt; 33.0&lt;/strong&gt; makes the jump from the 0.32 series with a full port to &lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK4&lt;/a&gt; (requiring at least 4.22), a reworked printing flow, and fixes for the fullscreen toolbar auto-hide and disappearing slideshow icons. The release replaces its dedicated authentication helper with a small localhost web server for publishing, adds a “peek password” toggle to the Piwigo flow and fixes setting desktop backgrounds.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kbd-project.org/&quot;&gt;kbd&lt;/a&gt; 2.10.0&lt;/strong&gt; extends the console stack with XKB support: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;loadkeys&lt;/code&gt; can now generate console keymaps from XKB data, import XKB compose tables and handle XKB group switching, modifier handling, virtual console switching and keypad/editing remaps.&lt;/p&gt;

&lt;h2 id=&quot;snapshots-at-a-glance&quot;&gt;Snapshots at a Glance&lt;/h2&gt;

&lt;table style=&quot;border-collapse:collapse;margin:1rem 0&quot;&gt;
  &lt;tr&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Snapshot&lt;/th&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Kernel&lt;/th&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Headline changes&lt;/th&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2026-09-08&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;7.2.3&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;glibc 2.44 with AArch64 GCS and SVE/AdvSIMD math, QEMU 11.1.1 with imx8mp-evk, Raspberry Pi firmware Wi-Fi scan fix&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2026-09-12&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;7.2.4&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;edk2-stable202608 with AArch64 host tests, dracut aarch64 LED module, GTK4 32-bit ARM build fix, LLVM 23.1.1&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2026-09-14&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;7.2.5&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;kernel security batch (Tegra241 CMDQV, iommufd, nvmet, Bluetooth RFCOMM, PCI, rndis_host), GIMP 3.2.6 with AArch64 fixes, shotwell 33.0, kbd 2.10.0&lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;

&lt;h2 id=&quot;arm-resources&quot;&gt;ARM Resources&lt;/h2&gt;
&lt;p&gt;For ARM-specific discussions and support, subscribe to the &lt;a href=&quot;https://lists.opensuse.org/archives/list/arm@lists.opensuse.org/&quot;&gt;openSUSE ARM mailing list&lt;/a&gt; and check the &lt;a href=&quot;https://en.opensuse.org/openSUSE:ARM&quot;&gt;openSUSE ARM wiki&lt;/a&gt; for device support information, image downloads, and documentation. New and existing ARM users can also join the &lt;a href=&quot;https://web.libera.chat/?channel=#opensuse-arm&quot;&gt;openSUSE ARM IRC channel&lt;/a&gt; for real-time help.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, ARM, Tumbleweed, Raspberry Pi, Rockchip, Jetson, SBC, AArch64, glibc, QEMU, UEFI, kernel, Mesa, GIMP, shotwell, kbd, CVE, snapper&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/15/kudos-august/</guid>
      <title>Kudos August 2026</title>
      <pubDate>Tue, 15 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/15/kudos-august/</link>
      <author>admin@opensuse.org (openSUSE Kudos Team)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/08/kudos.png" length="24102" type="image/png" />
      <description>Welcome to our monthly report from the openSUSE Kudos recognition platform, where we take a moment to put a spotlight on the people who stepped up, helped others, and made this community a little brighter. During the month of August 2026, 17 users received 24 kudos, and 419 badges were...</description>
      <content:encoded>&lt;p&gt;Welcome to our monthly report from the &lt;a href=&quot;https://kudos.opensuse.org&quot;&gt;openSUSE Kudos recognition platform&lt;/a&gt;, where we take a moment to put a spotlight on the people who stepped up, helped others, and made this community a little brighter.&lt;/p&gt;

&lt;p&gt;During the month of &lt;strong&gt;August 2026&lt;/strong&gt;, &lt;strong&gt;17&lt;/strong&gt; users received &lt;strong&gt;24&lt;/strong&gt; kudos, and &lt;strong&gt;419&lt;/strong&gt; badges were awarded to &lt;strong&gt;251&lt;/strong&gt; contributors. You can see &lt;a href=&quot;https://kudos.opensuse.org/stats&quot;&gt;stats&lt;/a&gt; for this and previous months.&lt;/p&gt;

&lt;h2 id=&quot;spotlight&quot;&gt;Spotlight&lt;/h2&gt;

&lt;p&gt;Top of the list in August: &lt;a href=&quot;https://kudos.opensuse.org/user/bmwiedemann&quot;&gt;Bernhard Wiedemann (@bmwiedemann)&lt;/a&gt; with &lt;strong&gt;5 kudos&lt;/strong&gt;, more than twice what anyone else collected. Most of them (&lt;strong&gt;4&lt;/strong&gt;) landed in Code &amp;amp; Engineering. That alone accounts for &lt;strong&gt;5&lt;/strong&gt; of the month’s &lt;strong&gt;24&lt;/strong&gt; kudos. Second place was a three-way tie at &lt;strong&gt;2 kudos&lt;/strong&gt; each: &lt;a href=&quot;https://kudos.opensuse.org/user/bigironman&quot;&gt;@bigironman&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/knurpht&quot;&gt;Gertjan Lettink (@knurpht)&lt;/a&gt; and &lt;a href=&quot;https://kudos.opensuse.org/user/mschreiner&quot;&gt;Martin Schreiner (@mschreiner)&lt;/a&gt;. Behind them, thirteen more people each picked up a kudo of their own, and all of them are listed below.&lt;/p&gt;

&lt;p&gt;A milestone is worth stopping for: &lt;a href=&quot;https://kudos.opensuse.org/user/dirkmueller&quot;&gt;@dirkmueller&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/jengelh&quot;&gt;@jengelh&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/krop&quot;&gt;@krop&lt;/a&gt; and &lt;a href=&quot;https://kudos.opensuse.org/user/pluskalm&quot;&gt;@pluskalm&lt;/a&gt; reached &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/tumbleweed-100&quot;&gt;100 Tumbleweed Contributions&lt;/a&gt;&lt;/strong&gt;. That is the kind of steady, long-haul contribution that rarely makes headlines. Congratulations!&lt;/p&gt;

&lt;p&gt;Not all of it is code, either. Documentation, translation, artwork, moderation and event work keep openSUSE usable and welcoming for everyone, and this month &lt;a href=&quot;https://kudos.opensuse.org/user/aplanas&quot;&gt;@aplanas&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/bmwiedemann&quot;&gt;@bmwiedemann&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/jimed-rand&quot;&gt;@jimed-rand&lt;/a&gt; and &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; earned &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/wiki-1&quot;&gt;Wiki Contributor&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;

&lt;h2 id=&quot;kudos&quot;&gt;Kudos&lt;/h2&gt;

&lt;p&gt;Here are the thank-you notes themselves: &lt;strong&gt;24&lt;/strong&gt; peer-to-peer kudos written by contributors about contributors, grouped by the person being thanked. The order follows the standings above, so August’s most recognized contributor opens the list.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/c57258b3faac137a43ddcc63deb22517?d=identicon&amp;amp;s=48&quot; alt=&quot;@bmwiedemann&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/bmwiedemann&quot;&gt;Bernhard Wiedemann (@bmwiedemann)&lt;/a&gt;&lt;/strong&gt; received the following kudos:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/levolet&quot;&gt;@levolet&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thanks for all your great work in maintaining Slowroll. Your community spirit in thinking of it and creating it is also much appreciated.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/mdhup&quot;&gt;@mdhup&lt;/a&gt; in Infrastructure Heroes&lt;/p&gt;

  &lt;p&gt;“Thank you for the work you do. Using slowroll has been a smooth experience. So much so that it ended my disro hopping. If it’s this good in beta, I can’t wait until it’s finished.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/PossiblePrinterPalace&quot;&gt;@PossiblePrinterPalace&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thank you for the wonderful Slowroll. It has been my most pain-free Linux Desktop experience, in now more than 10 years of using different Linux distros.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/dnla&quot;&gt;@dnla&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thanks for maintaining slowroll! Keep up the good work”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thank you for offering Slowroll!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/03e84f863e6ceadb3d14188d552aac20?d=identicon&amp;amp;s=48&quot; alt=&quot;@bigironman&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/bigironman&quot;&gt;@bigironman&lt;/a&gt;&lt;/strong&gt; received the following kudos:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Support &amp;amp; User Assistance&lt;/p&gt;

  &lt;p&gt;“Many thanks for your quick help with re-branching the Leap-Images Wolfgang!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Support &amp;amp; User Assistance&lt;/p&gt;

  &lt;p&gt;“Thanks you for the help with the SPICE devel project for Leap 16.X Wolfgang!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/ec2e857562f9e94f420a54d9a7ce8d79?d=identicon&amp;amp;s=48&quot; alt=&quot;@knurpht&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/knurpht&quot;&gt;Gertjan Lettink (@knurpht)&lt;/a&gt;&lt;/strong&gt; received the following kudos:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Support &amp;amp; User Assistance&lt;/p&gt;

  &lt;p&gt;“Thank you for raising the concern with spamminess of kudos bot. Thanks to our discussion and the spamminess we actually met a new friend in /bar. So the spam from kudos-bot is actually useful. And we also get to reduce the spamminess”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt; in Support &amp;amp; User Assistance&lt;/p&gt;

  &lt;p&gt;“Thank you for help and assistance at forums.o.o!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/ca245147d77420d33d7822a82875ac40?d=identicon&amp;amp;s=48&quot; alt=&quot;@mschreiner&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/mschreiner&quot;&gt;Martin Schreiner (@mschreiner)&lt;/a&gt;&lt;/strong&gt; received the following kudos:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thank you for maintaining LibreOffice!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Martin, thank you so much for going the extra mile here! It would have been much easier to simply ship the same LibreOffice version from Factory in Leap, but instead you’re putting in the effort to maintain a separate version that better fits what users expect from a long-term stable distribution. That’s a lot of extra work behind the scenes, and I and many other users really appreciate your work to make Leap an even better LTS-style distro. Thank you! &amp;lt;3”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/d2aa81338ba2ffc01631e8ddff3082d8?d=identicon&amp;amp;s=48&quot; alt=&quot;@atartamo&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/atartamo&quot;&gt;Antonello Tartamo (@atartamo)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Support &amp;amp; User Assistance&lt;/p&gt;

  &lt;p&gt;“Many thanks for your quick help on building an efficient query for OBS requests accepted within n-days Antonello! I’ll be using it for granting people Tumbleweed contributor badge in kudos. This will make sure we don’t keep OBS busy for too long:)”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/6642e79c3b53065515daf7a61898065c?d=identicon&amp;amp;s=48&quot; alt=&quot;@crameleon&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/crameleon&quot;&gt;@crameleon&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Infrastructure Heroes&lt;/p&gt;

  &lt;p&gt;“Many thanks for your help with whitelisting access from kudos-o-o to wiki and other services Georg!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/5cdd10d836bdda3796cf6bc1ab2d5a78?d=identicon&amp;amp;s=48&quot; alt=&quot;@dimstar&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/dimstar&quot;&gt;Dominique Leuenberger (@dimstar)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/victorhck&quot;&gt;@victorhck&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thanks for your work keeping Tumbleweed rolling. and for your weekly reviews!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//api.dicebear.com/9.x/identicon/svg?seed=firstyear&amp;amp;size=48&quot; alt=&quot;@firstyear&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/firstyear&quot;&gt;@firstyear&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Support &amp;amp; User Assistance&lt;/p&gt;

  &lt;p&gt;“Many thanks you for the help with the 2factor recovery William!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/e90283ee6c3b914d43e609f34f6fd979?d=identicon&amp;amp;s=48&quot; alt=&quot;@IGonzalezSosa&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/IGonzalezSosa&quot;&gt;Imobach Gonzalez Sosa (@IGonzalezSosa)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/victorhck&quot;&gt;@victorhck&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thanks Imobach &amp;amp; Ancor for their work developing Agama, and many other tools since many years..”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/23c080ae997a17e4b7dac91bde1083bc?d=identicon&amp;amp;s=48&quot; alt=&quot;@kukuk&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/kukuk&quot;&gt;Thorsten Kukuk (@kukuk)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thank you for os-update!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/977e0d76dacb86a9385d625f612fc0b3?d=identicon&amp;amp;s=48&quot; alt=&quot;@lkocman&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;Lubos Kocman (@lkocman)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thank you for answering and moderating some user questions about maintenance!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/1900ae8cc1d502032c1137e1e9dcb30f?d=identicon&amp;amp;s=48&quot; alt=&quot;@malcolmlewis&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/malcolmlewis&quot;&gt;Malcolm Lewis (@malcolmlewis)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Community Moderation&lt;/p&gt;

  &lt;p&gt;“Many thanks for your quick help with the locked SPICE thread on forums-o-o Malcolm. Users will be happy to find a pointer in case they find this thread in the future. Many thanks!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/87ef022668c93cd0911bb874dcfe7e9b?d=identicon&amp;amp;s=48&quot; alt=&quot;@pluskalm&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/pluskalm&quot;&gt;Martin Pluskal (@pluskalm)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Many thanks for your work on the openSUSE-packaging-skill Martin! I’m really happy that we have somebody who’s proactively looking into how AI can actually improve general packaging experience in openSUSE.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/32435562214f08d51d4aff895e189843?d=identicon&amp;amp;s=48&quot; alt=&quot;@Sauerland&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/Sauerland&quot;&gt;Stephan Hemeier (@Sauerland)&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt; in Support &amp;amp; User Assistance&lt;/p&gt;

  &lt;p&gt;“Thank you for help and assistance at forums.o.o!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/fc4736a2c50032dbbef0df5e264a188d?d=identicon&amp;amp;s=48&quot; alt=&quot;@shundhammer&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/shundhammer&quot;&gt;@shundhammer&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Thank you for offering Myrlyn!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/2b7bb05ef416313c314caf5ec8143eb4?d=identicon&amp;amp;s=48&quot; alt=&quot;@tiwai&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/tiwai&quot;&gt;@tiwai&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Many thanks for your support with anything kernel related Takashi! I always really appreciate your help! We might make rtl8812au users happy!”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//www.gravatar.com/avatar/84d767dccc0ebe0ba68c16b7e722d006?d=identicon&amp;amp;s=48&quot; alt=&quot;@Tobi_Peter&quot; width=&quot;48&quot; height=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;border-radius:50%;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/user/Tobi_Peter&quot;&gt;@Tobi_Peter&lt;/a&gt;&lt;/strong&gt; received a kudo:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;From &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt; in Code &amp;amp; Engineering&lt;/p&gt;

  &lt;p&gt;“Many thanks for all your work on broadcom-wl Tobi! I think many broadcom users will highly appreciate it.”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2 id=&quot;badges&quot;&gt;Badges&lt;/h2&gt;

&lt;p&gt;Here is an overview of the &lt;strong&gt;8&lt;/strong&gt; badges earned in August. The full list of badges you can earn is on the &lt;a href=&quot;https://kudos.opensuse.org/badges&quot;&gt;badges page&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/wiki-1.png&quot; alt=&quot;Wiki Contributor&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/wiki-1&quot;&gt;Wiki Contributor&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;Recognition for the first day/page documentation contribution on en.opensuse.org wiki.&lt;/em&gt;&lt;br /&gt;
Awarded this month to &lt;a href=&quot;https://kudos.opensuse.org/user/aplanas&quot;&gt;@aplanas&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/bmwiedemann&quot;&gt;@bmwiedemann&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/jimed-rand&quot;&gt;@jimed-rand&lt;/a&gt; and &lt;a href=&quot;https://kudos.opensuse.org/user/lkocman&quot;&gt;@lkocman&lt;/a&gt;.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/tumbleweed-100.png&quot; alt=&quot;100 Tumbleweed Contributions&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/tumbleweed-100&quot;&gt;100 Tumbleweed Contributions&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;For submitting 100 Submit Requests to openSUSE:Factory.&lt;/em&gt;&lt;br /&gt;
Awarded this month to &lt;a href=&quot;https://kudos.opensuse.org/user/dirkmueller&quot;&gt;@dirkmueller&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/jengelh&quot;&gt;@jengelh&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/krop&quot;&gt;@krop&lt;/a&gt; and &lt;a href=&quot;https://kudos.opensuse.org/user/pluskalm&quot;&gt;@pluskalm&lt;/a&gt;.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/tumbleweed-10.png&quot; alt=&quot;10 Tumbleweed Contributions&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/tumbleweed-10&quot;&gt;10 Tumbleweed Contributions&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;For submitting 10 Submit Requests to openSUSE:Factory.&lt;/em&gt;&lt;br /&gt;
&lt;strong&gt;35&lt;/strong&gt; contributors earned this badge this month, too many to list here, but every one of them counts.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/tumbleweed-1.png&quot; alt=&quot;First Tumbleweed Contribution&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/tumbleweed-1&quot;&gt;First Tumbleweed Contribution&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;For submitting 1 Submit Request to openSUSE:Factory.&lt;/em&gt;&lt;br /&gt;
&lt;strong&gt;210&lt;/strong&gt; contributors earned this badge this month, too many to list here, but every one of them counts.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/leap161.png&quot; alt=&quot;Leap 16.1 Contributor&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/leap-161&quot;&gt;Leap 16.1 Contributor&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;Recognition for submitting at least one pull request to Leap 16.1 or related appliance repositories on src.opensuse.org.&lt;/em&gt;&lt;br /&gt;
&lt;strong&gt;76&lt;/strong&gt; contributors earned this badge this month, too many to list here, but every one of them counts.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/leap160.png&quot; alt=&quot;Leap 16.0 Contributor&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/leap-160&quot;&gt;Leap 16.0 Contributor&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;Recognition for submitting at least one pull request to Leap 16.0 or related appliance repositories on src.opensuse.org.&lt;/em&gt;&lt;br /&gt;
&lt;strong&gt;75&lt;/strong&gt; contributors earned this badge this month, too many to list here, but every one of them counts.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/got1.png&quot; alt=&quot;Got First Kudo&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/got-1-kudos&quot;&gt;Got First Kudo&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;Received your first kudos.&lt;/em&gt;&lt;br /&gt;
Awarded this month to &lt;a href=&quot;https://kudos.opensuse.org/user/atartamo&quot;&gt;@atartamo&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/bigironman&quot;&gt;@bigironman&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/firstyear&quot;&gt;@firstyear&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/IGonzalezSosa&quot;&gt;@IGonzalezSosa&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/kukuk&quot;&gt;@kukuk&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/mschreiner&quot;&gt;@mschreiner&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/pluskalm&quot;&gt;@pluskalm&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/Sauerland&quot;&gt;@Sauerland&lt;/a&gt; and &lt;a href=&quot;https://kudos.opensuse.org/user/Tobi_Peter&quot;&gt;@Tobi_Peter&lt;/a&gt;.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;//kudos.opensuse.org/badges/previews/200/gave1.png&quot; alt=&quot;First Kudos Given&quot; width=&quot;48&quot; style=&quot;display:inline-block;vertical-align:middle;width:48px;height:auto;margin:0 0.5rem 0 0&quot; /&gt; &lt;strong&gt;&lt;a href=&quot;https://kudos.opensuse.org/badge/gave-1-kudos&quot;&gt;First Kudos Given&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;Shared your first kudos.&lt;/em&gt;&lt;br /&gt;
Awarded this month to &lt;a href=&quot;https://kudos.opensuse.org/user/C7NhtpnK&quot;&gt;@C7NhtpnK&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/dnla&quot;&gt;@dnla&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/levolet&quot;&gt;@levolet&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/mdhup&quot;&gt;@mdhup&lt;/a&gt;, &lt;a href=&quot;https://kudos.opensuse.org/user/PossiblePrinterPalace&quot;&gt;@PossiblePrinterPalace&lt;/a&gt; and &lt;a href=&quot;https://kudos.opensuse.org/user/victorhck&quot;&gt;@victorhck&lt;/a&gt;.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;strong&gt;Congrats on your kudos and badges. Keep up the great work everyone, and don’t forget to have a lot of fun!&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Generated by &lt;a href=&quot;https://src.opensuse.org/kudos/kudos-bots&quot;&gt;kudos-bot-news-o-o&lt;/a&gt; from https://kudos.opensuse.org/api/reports/monthly for the period 1-31 August 2026.&lt;/em&gt;&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, kudos, community&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/11/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 11 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/11/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. This community blog feed aggregator lists the featured highlights below from Sept. 4 - 10. This week highlights the SUSE security spotlight covering the combined spring and summer review activity plus a command-injection vulnerability in wicked that...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;. This community blog feed aggregator lists the featured highlights below from Sept. 4 - 10.&lt;/p&gt;

&lt;p&gt;This week highlights the SUSE security spotlight covering the combined spring and summer review activity plus a command-injection vulnerability in wicked that allows remote root code execution via DHCP, the fifth bug-fix update of Plasma 6.7 and the release of KDE Frameworks 6.30, an openSUSE version-diff page that covers every package, the wrap-up of openSUSE’s Google Summer of Code, the release of Audacity 4.0, and Packman’s announcement that the repository will be discontinued unless a successor steps up.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;jpeg-xl-appstream-and-better-media-processing&quot;&gt;&lt;a href=&quot;https://blog.tenstral.net/2026/09/jpeg-xl-appstream-and-better-media-processing.html&quot;&gt;JPEG-XL, AppStream, and Better Media Processing&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.tenstral.net/&quot;&gt;Matthias Klumpp&lt;/a&gt; reports on the AppStream 1.2.0 release, which makes JPEG-XL the new default image export format while redesigning the media processing pipeline with sandboxed workers. The post benchmarks JPEG-XL against PNG on Debian’s icon pool, showing bandwidth savings.&lt;/p&gt;

&lt;h2 id=&quot;the-syslog-ng-insider-2026-09-performance-openssl-containers-learning&quot;&gt;&lt;a href=&quot;https://peter.czanik.hu/other/syslog-ng-insider-2026-09-performance-openssl-containers-learning/&quot;&gt;The syslog-ng Insider 2026-09: Performance; Openssl; Containers; Learning&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.syslog-ng.com/community/b/blog/&quot;&gt;Peter Czanik&lt;/a&gt; publishes the 141st issue of the syslog-ng Insider newsletter. It covers performance tuning options that can reach 7 million events per second in lab tests, nightly AlmaLinux-based containers published on Docker Hub, and the status of OpenSSL 4.0 support.&lt;/p&gt;

&lt;h2 id=&quot;30th-update-of-kde-frameworks-6-and-kcoreaddons-library&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/trigesima-actualizacion-de-kde-frameworks-6-y-libreria-kcoreaddons.html&quot;&gt;30th update of KDE Frameworks 6 and KCoreAddons library&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces KDE Frameworks 6.30, the 30th monthly update of the libraries that underpin the KDE project, released on September 10. As part of a year-long series profiling each framework, the post introduces KCoreAddons library, which adds extensions and utilities on top of QtCore, from MIME management and automatic saving to backups, randomness generation and system user information.&lt;/p&gt;

&lt;h2 id=&quot;the-other-wtc-attack&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/the-other-wtc-attack/&quot;&gt;The Other WTC Attack&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; shares a short, personal post recalling his 1993 visit to the top of the World Trade Center, unaware at the time that it had been bombed months earlier. He reflects on that 1993 attack, the truck bomb built from around 600 kilograms of homemade explosives plus hydrogen tanks, and how later events gave the story new weight.&lt;/p&gt;

&lt;h2 id=&quot;suse-security-team-spotlight-springsummer-2026&quot;&gt;&lt;a href=&quot;https://security.opensuse.org/2026/09/10/spring-summer-spotlight.html&quot;&gt;SUSE Security Team Spotlight Spring/Summer 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://security.opensuse.org/&quot;&gt;The SUSE Security Team&lt;/a&gt; blog releases a combined spotlight covering its spring and summer review activity across dozens of D-Bus and Polkit policy rules, from upower and AppArmor’s aa-notify to fwupd and the transactional update notifier. The post also documents file-based root capabilities assigned in packages like cacti-spine’s CAP_NET_RAW and ksystemstats6’s CAP_PERFMON, and revisits the Apptainer setuid starter.&lt;/p&gt;

&lt;h2 id=&quot;how-to-keep-a-script-running-in-the-background-with-ssh-and-tmux&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/09/como-mantener-un-script-ejecutandose-en-segundo-plano-con-ssh-y-tmux/&quot;&gt;How to Keep a Script Running in the Background with SSH and tmux&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; explains how to launch a script on a remote machine over SSH and keep it running in the background using a tmux session. The tutorial covers creating a named session, detaching with the tmux prefix and ‘d’, reconnecting later with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tmux a -t&lt;/code&gt;, and closing the session when done.&lt;/p&gt;

&lt;h2 id=&quot;35-years-of-linux-35-curiosities-that-changed-computing-by-la-chica-de-sistemas&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/35-anos-de-linux-35-curiosidades-que-cambiaron-la-informatica-de-la-chica-de-sistemas.html&quot;&gt;“35 Years of Linux: 35 Curiosities That Changed Computing” by La Chica de Sistemas&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; introduces the YouTuber &lt;a href=&quot;https://www.youtube.com/@lachicadesistemas&quot;&gt;La Chica de Sistemas&lt;/a&gt;, whose channel teaching Linux and Unix system administration it had long wanted to promote. It shares her video celebrating Linux’s 35th anniversary with 35 curiosities about the operating system that changed computing.&lt;/p&gt;

&lt;h2 id=&quot;one-page-every-package&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/09/one-page-every-package/&quot;&gt;One Page, Every Package&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog presents the openSUSE version diff tool, a machine-built comparison of source package versions across Tumbleweed and the current Leap releases. Pulled directly from the download.opensuse.org archive indexes, the page covers more than 17,500 source packages in a sortable, filterable table with downloadable JSON and CSV exports, categorizing each package as older, newer, equal or exclusive to one release.&lt;/p&gt;

&lt;h2 id=&quot;fifth-update-of-plasma-67&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/quinta-actualizacion-de-plasma-6-7.html&quot;&gt;Fifth Update of Plasma 6.7&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; reports the fifth bug-fix update of Plasma 6.7 released on September 8. It recaps the branch’s recurring highlights such as independent virtual desktops per monitor, microphone volume testing, a light/dark theme switch, lunar calendar integration and print queue management, alongside the fixes in the new point release.&lt;/p&gt;

&lt;h2 id=&quot;the-packman-repository-will-be-discontinued-as-of-jan-1-2027&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/08/el-proyecto-del-repositorio-packman-quedara-discontinuado-a-partir-del-1-de-enero-de-2027/&quot;&gt;The Packman Repository Will Be Discontinued as of Jan 1, 2027&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; translates the announcement from Packman’s maintainers that after 25 years, the project will be discontinued on January 1, 2027 unless a successor is found. The post recounts the history of the repository, the reasons behind stepping down, including the growth of Flatpak and the workload involved, and what a takeover would require.&lt;/p&gt;

&lt;h2 id=&quot;optimizing-the-sudo-test&quot;&gt;&lt;a href=&quot;https://bzoltan1.github.io/optimizing-the-sudo-test/&quot;&gt;Optimizing the sudo Test&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://bzoltan1.github.io/&quot;&gt;Zoltán&lt;/a&gt; shares how the openQA sudo test for openSUSE and SLE was cut from about 9 minutes to 3 seconds while gaining broader coverage. He explains running the upstream test suite during the package build, porting functional tests to pytest, and adding a validator that checks the shipped sudoers file against common misconfigurations like targetpw.&lt;/p&gt;

&lt;h2 id=&quot;photos-as-a-substitute-for-kdes-gwenview-image-viewer&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/07/photos-como-sustituto-al-visor-de-imagenes-gwenview-de-kde/&quot;&gt;Photos as a Substitute for KDE’s Gwenview Image Viewer&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; looks at the Photos application as a substitute for KDE’s default Gwenview image viewer. The post examines what each viewer offers and what users should weigh before switching.&lt;/p&gt;

&lt;h2 id=&quot;synchronize-the-scroll-in-two-tabs-in-the-kde-kate-editor&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/07/sincronizar-el-scroll-en-dos-pestanas-en-el-editor-kate-de-kde/&quot;&gt;Synchronize the “scroll” in two tabs in the #KDE Kate editor&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; shows how to synchronize the scroll position between two tabs in the KDE editor Kate. Using the View menu, Split View and Toggle Scroll Sync, Kate shows a chain icon and keeps both documents aligned so users can read and compare them together.&lt;/p&gt;

&lt;h2 id=&quot;this-years-google-summer-of-code-wrap-up&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/07/gsoc-wrap-up/&quot;&gt;This Year’s Google Summer of Code Wrap Up&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog wraps up the 2026 Google Summer of Code season in which openSUSE mentored eight contributors. Projects ranged from enhancing the git workflow build results page and benchmarking Uyuni on Kubernetes to an AI agent for root cause analysis, an MQTT publisher with Node-RED nodes, Uyuni’s API docs ported to OpenAPI, a new mgrctl get command and native LDAP support.&lt;/p&gt;

&lt;h2 id=&quot;kde-express-episode-75-season-6-plus-akademyes-and-kde-gear-2608&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/episodio-75-de-kde-express-temporada-6-akademyes-kde-gear-26-08-akamdemyes.html&quot;&gt;KDE Express Episode 75: Season 6 plus AkademyES and KDE Gear 26.08&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents episode 75 of KDE Express, the podcast hosted by David Marzal returning after a hiatus. The episode spotlights Akademy-es 2026, scheduled for October 23-25 in Villaviciosa de Odón, and reviews KDE Gear 26.08 applications like Okular, Dolphin, Konsole and Minuet.&lt;/p&gt;

&lt;h2 id=&quot;the-hacktivist-collective-autisticiinventati-closes-its-services&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/06/el-colectivo-hacktivista-autistici-inventati-cierra-sus-servicios/&quot;&gt;The Hacktivist Collective Autistici/Inventati Closes Its Services&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; reports that after 25 years of providing privacy-preserving services to activists, the collective Autistici/Inventati is closing down. Following the U.S. government’s August 26 designation of the collective as a terrorist organization, it announced on September 6 that continuing to operate would endanger its users.&lt;/p&gt;

&lt;h2 id=&quot;audacity-40-released-renewing-the-interface&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzado-audacity-4-0-renovando-la-interfaz.html&quot;&gt;Audacity 4.0 Released, Renewing the Interface&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the release of Audacity 4.0, whose major update rebuilds the interface with Qt, introduces a new clip-based editing model, Guardable workspaces, HiDPI rendering and the new .aup4 project format. It lists the new recording, playback and effects features along with Audacity 3 functions not yet available.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-218--news-flight-night&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/09/05/linux-saloon-218-news-flight-night/&quot;&gt;Linux Saloon 218 | News Flight Night&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;Nathan Wolf&lt;/a&gt; posts episode 218 of the technology and Linux podcast and looks at California’s open-source legislation.&lt;/p&gt;

&lt;h2 id=&quot;so-many-ways-to-click-and-scroll---this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/tantas-maneras-de-hacer-clic-y-desplazarse-esta-semana-en-plasma.html&quot;&gt;So Many Ways to Click and Scroll - This Week in Plasma&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates this week’s Plasma development report, in which the last Plasma 6.8 features land along with fixes across the 6.6.7, 6.7.5 and 6.8 branches. It covers new ways to click and scroll, plus improvements to Discover, the task manager and other Plasma components.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed---review-of-the-week-202636&quot;&gt;Tumbleweed - Review of the Week 2026/36&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/09/tumbleweed-review-of-the-week-2026-36/&quot;&gt;Dominique Leuenberger&lt;/a&gt; and &lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/04/opensuse-tumbleweed-revision-de-la-semana-36-de-2026/&quot;&gt;Victorhck&lt;/a&gt; review the six Tumbleweed snapshots of week 2026/36. Kernel 7.2.2, glibc 2.44, Rust 1.98, QEMU 11.1.0 and LLVM 23.1.0 were among the headline packages delivered to the rolling release.&lt;/p&gt;

&lt;h2 id=&quot;best-linux-distros-for-new-laptops-in-2026-tested&quot;&gt;&lt;a href=&quot;https://linuxstans.com/best-linux-distros-for-new-laptops/&quot;&gt;Best Linux Distros for New Laptops in 2026 (Tested)&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://linuxstans.com/&quot;&gt;LinuxStans&lt;/a&gt; ranks seven distributions best suited to brand new laptops that need the freshest kernels, firmware and drivers. Fedora Workstation takes the top recommendation, with openSUSE Tumbleweed second for its rolling kernel updates and openQA snapshot testing, ahead of CachyOS, EndeavourOS, Pop!_OS, Ubuntu 26.04 LTS and Manjaro.&lt;/p&gt;

&lt;h2 id=&quot;complete-redesign-of-kde-connect-for-android&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/rediseno-completo-de-kde-connect-para-android.html&quot;&gt;Complete Redesign of KDE Connect for Android&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; reports on the complete redesign of KDE Connect for Android, the app that links a phone with Plasma desktops to share notifications, clipboard and files. The refresh brings a renewed visual interface to the app many users rely on daily.&lt;/p&gt;

&lt;h2 id=&quot;tiny-wins-for-packagers-end-of-week-update&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/09/04/tiny-wins/&quot;&gt;Tiny Wins for Packagers: End-of-Week Update&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org/&quot;&gt;Open Build Service&lt;/a&gt; blog shares its end-of-week “Tiny Wins” update for packagers. Shipped fixes include preventing an encoding crash when writing YAML to temp files, repairing an osc branch crash for packages with an empty element, and updates to obs-service-node_modules and obs-service-source_validator.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Tumbleweed&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/09/one-page-every-package/</guid>
      <title>One Page, Every Package</title>
      <pubDate>Wed, 09 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/09/one-page-every-package/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/source.png" length="219551" type="image/png" />
      <description>There is a question that comes up often in openSUSE forum threads or a Reddit comment section and that is what version of X does one actually get on Leap versus Tumbleweed? Until recently the honest answer was very often “go look it up yourself, package by package” unless someone...</description>
      <content:encoded>&lt;p&gt;There is a question that comes up often in openSUSE forum threads or a Reddit comment section and that is what version of X does one actually get on Leap versus Tumbleweed?&lt;/p&gt;

&lt;p&gt;Until recently the honest answer was very often “go look it up yourself, package by package” unless someone actually had the answer.&lt;/p&gt;

&lt;p&gt;Now there is a better one.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://opensuse.github.io/osdiff/&quot;&gt;openSUSE version diff tool&lt;/a&gt;!!! 
Yes &lt;a href=&quot;https://github.com/openSUSE/osdiff&quot;&gt;github.com/openSUSE/osdiff&lt;/a&gt; tooling generates a complete, machine-built comparison of source package versions across Tumbleweed and the current Leap releases.&lt;/p&gt;

&lt;p&gt;The idea of listing source package versions in a consumable format grew out of a discussion community member Axel Braun raised at a &lt;a href=&quot;https://calendar.opensuse.org/&quot;&gt;weekly Release Engineering meeting&lt;/a&gt;.
The site republishes itself automatically. No guessing, no anecdotes, no six-month-old blog post. Just the numbers.&lt;/p&gt;

&lt;p&gt;The tool pulls the archive indexes straight from &lt;a href=&quot;https://download.opensuse.org/&quot;&gt;download.opensuse.org&lt;/a&gt;; this is for open-source software (oss) and non-oss, x86_64 and noarch and it’s done for Tumbleweed, Leap 16.1, and Leap 16.0; then it compares the upstream version of every source package it finds. The result is a single sortable, filterable table with a timestamp on it.&lt;/p&gt;

&lt;p&gt;The scale is worth pausing on. A recent run covers 17,532 source packages: 17,143 in Tumbleweed, 10,574 in Leap 16.1, 10,551 in Leap 16.0, with 10,264 present in both Tumbleweed and Leap 16.1. Every package lands in one of five status buckets:&lt;/p&gt;

&lt;table style=&quot;border-collapse:collapse;margin:1rem 0&quot;&gt;
  &lt;tr&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Status&lt;/th&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Meaning&lt;/th&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Older-in-Leap&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Leap ships an earlier upstream version than Tumbleweed&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Newer-in-Leap&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Leap is actually &lt;em&gt;ahead&lt;/em&gt; — rarer than people assume, but real&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Same&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Identical upstream version in both&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Only-in-TW&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Exists in Tumbleweed, not in Leap&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Only-in-Leap&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;Exists in Leap, not in Tumbleweed&lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;

&lt;p&gt;The page carries maintainer information and it is careful about what it claims: only the upstream version is compared, not the RPM release. That distinction matters, and the tool states it up front rather than quietly blurring it.&lt;/p&gt;

&lt;p&gt;Open data changes the conversation. The single most valuable thing here isn’t the HTML page. It’s the downloads sitting at the bottom of it: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;diff.json&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;diff.json.gz&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;diff.csv&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;This open data turns a nice webpage into infrastructure. Anyone can pull the JSON, and the shape of the data is stable enough to build on. Which is where use cases start multiplying.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Prospective users deciding between Leap and Tumbleweed. Someone who needs a specific toolchain version for work can confirm it in ten seconds rather than installing and finding out.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Media, reviewers, and documentation writers can immediately find information they need to dive deeper into a related topic. This page gives a journalist instant information to help them determine if a flavor of openSUSE has exposure fixes. Distribution comparisons are notoriously prone to stale or half-remembered version numbers, and a wrong number in a review can stick around for years in search results. A citable, timestamped, auto-generated source removes the excuse for guessing. If you write about openSUSE, you now have a footnote you can actually point at.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Aggregators like DistroWatch where the site tracks package versions across dozens of distributions do enormous manual or semi-manual work to keep tables current. Machine-readable exports of an entire distribution’s package set, refreshed automatically, is exactly the kind of upstream cooperation that makes that work cheaper and more accurate. What do you say DistroWatch? Want to know “what’s in what” tables.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Packagers and maintainers get immediate knowledge. The tool attaches the maintainer names to those rows so somebody knows who to ask.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Contributors looking for a first task. One of the hardest parts of joining a distribution project is finding something concrete to do. A filtered list of packages that are behind, with maintainers listed, is a genuinely welcoming on-ramp.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Sysadmins and platform teams gain quick confirmation for their development. Before migrating a fleet from Leap 16.0 to 16.1, or evaluating whether a workload can move from Tumbleweed to Leap, the practical question is which dependencies shift and by how much. The 16.0-versus-16.1 columns answer that directly, and the CSV drops into a spreadsheet or a diff script without ceremony.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Developers targeting openSUSE will know which library versions your users will have, this is the compatibility matrix. It also tells you whether your own package is present in Leap at all.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Researchers and the merely curious can have a lot of fun with the open-data. Full-distribution version data, published openly on a recurring basis, is a dataset. Software-ecosystem researchers and people who just enjoy graphing things now have raw material that didn’t exist in convenient form before.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Having Leap package versions visible alongside Tumbleweed’s is a meaningful shift in how a release gets communicated. Historically, “what will be in the next Leap?” was answered in release notes near the end of the cycle, or reconstructed by people willing to dig through OBS. Publishing the state of the in-development distribution as it evolves means the community can see the release taking shape rather than being handed a finished summary.&lt;/p&gt;

&lt;p&gt;Small tools like this rarely get the attention they deserve, but a table that is always correct, always current, and freely downloadable quietly removes an entire category of friction from a project.
We hope you enjoy it.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, Leap, Tumbleweed&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/07/gsoc-wrap-up/</guid>
      <title>This Year&apos;s Google Summer of Code Wrap Up</title>
      <pubDate>Mon, 07 Sep 2026 10:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/07/gsoc-wrap-up/</link>
      <author>admin@opensuse.org (Cédric Bosdonnat)</author>
      <enclosure url="https://news.opensuse.org/assets/images/2021-07-05/gsoc.jpeg" length="56191" type="image/jpeg" />
      <description>Google Summer of Code is now over for openSUSE. This summer, we had the privilege of mentoring eight contributors. Mario Marín Hinojosa enhanced the openSUSE git workflow build results. He blogged about his progress and you can already see in it action on br.opensuse.org. See an example for devel:languages:python:Factory! Akash...</description>
      <content:encoded>&lt;p&gt;Google Summer of Code is now over for &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;This summer, we had the privilege of mentoring eight contributors.&lt;/p&gt;

&lt;p&gt;Mario Marín Hinojosa enhanced the openSUSE git workflow build results. He &lt;a href=&quot;https://mmarhin.github.io/gsoc2026blog/&quot;&gt;blogged about his progress&lt;/a&gt; and you can already see in it action on br.opensuse.org.
See an example for &lt;a href=&quot;https://br.opensuse.org/status/devel:languages:python:Factory?mode=matrix&quot;&gt;devel:languages:python:Factory&lt;/a&gt;!&lt;/p&gt;

&lt;p&gt;Akash Kumar wrote the foundation for an Uyuni on Kubernetes storage benchmark. This meant enhancing sumaform, the deployment tool used by the CI, to work with an existing Kubernetes cluster. He also wrote cucumber tests in the Uyuni test suite to benchmark the reposync and the download of packages from several minions. There are still other tests to add and he documented this all in the &lt;a href=&quot;https://github.com/openSUSE/mentoring/issues/252#issuecomment-5395625698&quot;&gt;github mentoring issue&lt;/a&gt;. Akash will give a presentation at the &lt;a href=&quot;https://events.opensuse.org/conferences/oSAS26&quot;&gt;openSUSE.Asia Summit&lt;/a&gt; in Yogyakarta in about a month; come and get to know him!&lt;/p&gt;

&lt;p&gt;Digvijay Rawat worked on a AI agent to help with the root cause analysis of errors on Linux machines managed by Uyuni. He documented how it works, how to install it and what is left to be done &lt;a href=&quot;https://github.com/Digvijay-x1/UyuniAI/blob/main/docs/gsoc-final-report.md&quot;&gt;in his repository&lt;/a&gt;. He also prepared a &lt;a href=&quot;https://www.youtube.com/watch?v=Omj_IG77Yl0&quot;&gt;demo video&lt;/a&gt; to show how it off.&lt;/p&gt;

&lt;div class=&quot;image-center&quot;&gt;
&lt;iframe width=&quot;560&quot; height=&quot;315&quot; src=&quot;https://www.youtube.com/embed/Omj_IG77Yl0&quot; frameborder=&quot;0&quot; allow=&quot;accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture&quot; allowfullscreen=&quot;&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;

&lt;p&gt;Geetansh Goyal added an MQTT publisher to Uyuni so its events can be used in automation.
He also added Node Red nodes to use those events. His work is described &lt;a href=&quot;https://github.com/geetxnshgoyal/gsoc-2026-uyuni-mqtt&quot;&gt;in his repository&lt;/a&gt;. Tell us your use cases. Geetansh also presented at the openSUSE conference and would like to start buildin an openSUSE mirror and community in India. Find out how Geetansh described his &lt;a href=&quot;https://news.opensuse.org/2026/09/03/gsoc-2026-uyuni-mqtt-nodered/&quot;&gt;Google Summer of Code experience&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Himanshu Jaiswal helped porting the Uyuni API docs to openAPI and Swagger. This was not just the matter of rewriting the doc from the current Javadoc to the new format, but also adding automation for it and fixing the many errors that came up. He documented the &lt;a href=&quot;https://gist.github.com/masterhj/cf62fd107059b9cd461680992315faaa&quot;&gt;state of his project in a gist&lt;/a&gt; for the curious to take a look or help.&lt;/p&gt;

&lt;p&gt;Jay Prakash added an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mgrctl get&lt;/code&gt; command to wrap up the Uyuni API in a similar way to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;kubectl get&lt;/code&gt;. This only supports systems and system groups for now, but has been written with extensibility in mind to reduce the work needed for other Uyuni objects. He documented his work &lt;a href=&quot;https://github.com/katara-Jayprakash/Gsoc-2026-uyuni-mgrctl&quot;&gt;in a special git repository&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Surya Srinivasan worked on a native support of LDAP in Uyuni. With his work in, configuring the use of an LDAP server could be done from the Uyuni web interface! He described his work and what remains to be done &lt;a href=&quot;https://gist.github.com/SURYAS1306/32dcd4d15a6ac600093020664f64316c&quot;&gt;in a gist&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Anuj Agrawal began the program this summer with us, but had to resign as he started working for Google. Congrats!! He started a chat bot project to help get started with openSUSE. The project uses a local SLM and RAG and was already nicely kicked out. To know more about the project, check out &lt;a href=&quot;https://github.com/anujagrawal380/openSUSE-leap-ai-startup-guide&quot;&gt;the code and documentation in his repository&lt;/a&gt; or read Anuj’s blog post about the &lt;a href=&quot;https://news.opensuse.org/2026/06/29/building-local-offline-opensuse-assistant/&quot;&gt;openSUSE Assistant&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Many thanks to all eight of them for their involvement. We are looking forward to keep working with you all. Many thanks also to those who mentored them, gave time and patience to help them get started with contributing to openSUSE.&lt;/p&gt;
</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/04/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 04 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/04/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. This community blog feed aggregator lists the featured highlights below from August 28 to Sept. 3. This week highlights the SUSE security review that uncovers a local root exploits and a Polkit bypass in the LACT GPU...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;. This community blog feed aggregator lists the featured highlights below from August 28 to Sept. 3.&lt;/p&gt;

&lt;p&gt;This week highlights the SUSE security review that uncovers a local root exploits and a Polkit bypass in the LACT GPU tool, an update on expanding Intel AI stack with NPU and OpenVINO support, a translation of the U.S. government placing a label on an Italian collective for offering digital infrastructure to groups of activists, the August Tumbleweed monthly update and week 2026/35 review, and a wave of KDE Gear 26.08 application features alongside the monthly KDE Linux progress report.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;multicortex-ai-intel-accelerated-cpu-gpu-and-intel-npu-ready-for-artificial-intelligence&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/09/03/multicortex-ai-intel-accelerated-cpu-gpu-e-npu-intel-pronta-para-a-inteligencia-artificial/&quot;&gt;MultiCortex AI Intel Accelerated: CPU, GPU, and Intel NPU ready for Artificial Intelligence&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro&lt;/a&gt; presents an Intel-accelerated Linux platform that bundles oneAPI, Level Zero, OpenVINO, Intel Arc and NPU drivers into a ready-to-use AI environment. The post details how a signed-integer overflow in the NPU driver’s ResourceCleaner thread triggered SIGABRT crashes, and how the fix submitted upstream via Pull Request #142 restored NPU availability for OpenVINO applications.&lt;/p&gt;

&lt;h2 id=&quot;gsoc-2026-event-driven-automation-for-uyuni-via-mqtt-and-node-red&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/03/gsoc-2026-uyuni-mqtt-nodered/&quot;&gt;GSoC 2026, Event-Driven Automation for Uyuni via MQTT and Node-RED&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog shares a Google Summer of Code student’s account of adding an MQTT publisher to Uyuni’s Java core so server events can push out in real time. On the consumer side, a custom set of Node-RED nodes lets users wire together workflows like “a minion registers, apply this state, then post to Slack” without touching the API, and the post reflects on lessons learned about transaction boundaries and deployment debugging.&lt;/p&gt;

&lt;h2 id=&quot;this-month-in-kde-linux-august-2026&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/este-mes-de-agosto-en-kde-linux.html&quot;&gt;This Month in KDE Linux: August 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; summarizes a monthly progress report on KDE Linux, the community’s upcoming distribution. Highlights include automatic Btrfs snapshots with a new kio-snapshot feature in Dolphin for restoring file versions, preinstalled CJKV text input, default Docker socket access removal for the wheel group, and several boot and installer refinements.&lt;/p&gt;

&lt;h2 id=&quot;defend-the-autisticiinventati-collective-and-the-right-to-build-resilient-communication&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/02/defiende-al-colectivo-autistici-inventati/&quot;&gt;Defend the Autistici/Inventati Collective and the Right to Build Resilient Communication&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; blogs about the U.S. Treasury designating the Italian digital-infrastructure collective Autistici/Inventati as Specially Designated Global Terrorists. The post translates parts of the collective’s open letter and raises concerns about treating privacy-preserving hosting infrastructure as “material support” for terrorism.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-in-konsole-of-kde-gear-2608-the-enjoy-shiny-stuff-edition&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/las-novedades-de-konsole-de-kde-gear-26-08-edicion-enjoy-shiny-stuff.html&quot;&gt;What’s New in Konsole of KDE Gear 26.08, the “Enjoy Shiny Stuff” Edition&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the Konsole improvements in KDE Gear 26.08. The terminal now supports holding Alt and dragging underlined filenames, and can also drag links, email addresses and color terms to other applications, opening pages, downloading HTML or filling layers in Krita.&lt;/p&gt;

&lt;h2 id=&quot;using-syslog-ng-with-elasticsearch-95&quot;&gt;&lt;a href=&quot;https://www.syslog-ng.com/community/b/blog/posts/using-syslog-ng-with-elasticsearch-9-5&quot;&gt;Using syslog-ng with Elasticsearch 9.5&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.syslog-ng.com/community/b/blog/&quot;&gt;Peter Czanik&lt;/a&gt; writes about installing Elasticsearch 9.5 with Kibana to verify claims that using Elasticsearch has become more difficult, testing how syslog-ng works with it. The post runs through the setup and configuration needed to make the combination work smoothly.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed-monthly-update---august-2026&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/02/tw-monthly-update-august/&quot;&gt;Tumbleweed Monthly Update - August 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog recaps an August that delivered 23 Tumbleweed snapshots across 31 days. The month brought KDE Plasma 6.7.4, KDE Frameworks 6.29.0 and KDE Gear 26.08.0, plus GNOME Shell 50.4, Firefox 154.0 with over 40 security fixes, the Linux kernel 7.2.0, and a steady stream of CVE-driven updates.&lt;/p&gt;

&lt;h2 id=&quot;reverse-dependencies-as-a-zypper-plugin&quot;&gt;&lt;a href=&quot;https://bzoltan1.github.io/reverse-dependencies-as-a-zypper-plugin/&quot;&gt;Reverse Dependencies as a zypper Plugin&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://bzoltan1.github.io/&quot;&gt;Zoltán&lt;/a&gt; revisits his &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rdepends&lt;/code&gt; hackweek tool now that zypper natively gained reverse-dependency support via the –requires-pkg flag. He explains how the built-in feature changed the project and what the updated plugin approach looks like today.&lt;/p&gt;

&lt;h2 id=&quot;mobile-linux-hackday-8-record-turnout-in-suses-new-prague-office&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/01/mobile-hackday-8/&quot;&gt;Mobile Linux Hackday #8: Record Turnout in SUSE’s New Prague Office&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog recounts a record-attendance Mobile Linux Hackday #8 held in SUSE’s renovated Prague office. Attendees split into freeform working groups on AI tools, BengalOS and Qualcomm Snapdragon 845 kernel hacking, and shared feedback on how the Czech Linux community discovers such events.&lt;/p&gt;

&lt;h2 id=&quot;100000-computers-with-linux-the-miracle-no-big-tech-could-stop---episode-4-of-the-the-age-of-the-dystres-podcast&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/100-000-ordenadores-con-linux-el-milagro-que-ninguna-gran-tecnologica-pudo-detener-episodio-4-del-podcast-la-era-de-las-distros.html&quot;&gt;100,000 Computers with Linux: The Miracle No Big Tech Could Stop - Episode 4 of the “The Age of the Dystres” Podcast&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; promotes Episode 4 of the “The Age of the Dystres” podcast, which tells the story of the Spanish regional GNU/Linux distribution. The episode focuses on the technical side, covering the engineering, hardware challenges and teaching passion behind the project with several key contributors.&lt;/p&gt;

&lt;h2 id=&quot;translation-of-the-richard-stallman-interview-at-foss-force&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/08/31/traduccion-de-la-entrevista-a-richard-stallman-en-la-web-foss-force/&quot;&gt;Translation of the Richard Stallman Interview at FOSS Force&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; offers a Spanish translation of Christine Hall’s August 30 email interview with Richard Stallman published on FOSS Force. The interview covers GNU, the open-source split, large language models, SaaSS and digital surveillance, and argues that software freedom remains a moral question.&lt;/p&gt;

&lt;h2 id=&quot;vertical-clock-for-your-desktop---plasmoids-for-plasma-6-39&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/reloj-vertical-para-tu-escritorio-con-vertical-clock-plasmoides-para-plasma-6-39.html&quot;&gt;Vertical Clock for Your Desktop - Plasmoids for Plasma 6 (39)&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents Vertical Clock. Created by cyberbessa, the widget handles narrow vertical panels well, offering eight visual styles, automatic scaling, and calendar integration, all built using only public API so it survives Plasma updates.&lt;/p&gt;

&lt;h2 id=&quot;opensuse-expands-ai-support-with-intel-npu-driver-1350-and-openvino-202631&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/08/31/NPU-openVINO/&quot;&gt;openSUSE Expands AI Support with Intel NPU Driver 1.35.0 and OpenVINO 2026.3.1&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog reports that Intel NPU Driver 1.35.0 and OpenVINO 2026.3.1 are now packaged for Tumbleweed, Leap 16.0, and Leap 16.1. Testing uncovered a bug that prevented the NPU from initializing on some systems, which was fixed and submitted upstream to the Intel NPU driver project.&lt;/p&gt;

&lt;h2 id=&quot;lact-polkit-authentication-bypass-and-temporary-file-handling-issues&quot;&gt;&lt;a href=&quot;https://security.opensuse.org/2026/08/31/lact-gpu-control.html&quot;&gt;LACT: Polkit Authentication Bypass and Temporary File Handling Issues&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://security.opensuse.org/&quot;&gt;SUSE Security&lt;/a&gt; blog publishes a review of the LACT GPU control daemon that found a Polkit authentication bypass and a predictable temporary file issue. A PID-race flaw (CVE-2026-75037) could allow local root escalation via profile hooks, while a predictable tarball path (CVE-2026-75038) enabled denial of service and information leaks, with both fixed in upstream.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-in-dolphin-of-kde-gear-2608-the-enjoy-shiny-stuff-edition&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/las-novedades-de-dolphin-de-kde-gear-26-08-edicion-enjoy-shiny-stuff.html&quot;&gt;What’s New in Dolphin of KDE Gear 26.08, the “Enjoy Shiny Stuff” Edition&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; rounds up the Dolphin improvements in KDE Gear 26.08. The file manager adds better KDE Connect integration, a filter bar supporting plain text, globbing and regular expressions, independent grouping and sorting, and the ability to close tabs on either side with a right-click.&lt;/p&gt;

&lt;h2 id=&quot;binary-function-coverage-part-2-scaling-up-fixing-daemons-and-asking-the-kernel&quot;&gt;&lt;a href=&quot;https://bzoltan1.github.io/binary-function-coverage-part-2-scaling-up-fixing-daemons-and-asking-the-kernel/&quot;&gt;Binary Function Coverage Part 2: Scaling Up, Fixing Daemons, and Asking the Kernel&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://bzoltan1.github.io/&quot;&gt;Zoltán&lt;/a&gt; continues his series on binary function coverage with funkoverage eBPF tracing. He explains how daemons like sshd, cups and postgresql could not be wrapped until the shim was fixed to forward SIGTERM and relay sd_notify so systemd’s service lifecycle worked correctly.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-217--application-potluck&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/08/29/linux-saloon-217-application-potluck/&quot;&gt;Linux Saloon 217 | Application Potluck&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;Linux Saloon&lt;/a&gt; posts a roundup of technology and Linux updates, including a live weekend discussion about Fedora experiences and Linux security roles at Epic Games. It also covers IBM’s chip architecture advances and Dell overtaking HP in U.S. PC sales amid a shrinking market.&lt;/p&gt;

&lt;h2 id=&quot;qtwidgets-applications-join-union---this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/las-aplicaciones-de-qtwidgets-se-unen-a-union-esta-semana-en-plasma.html&quot;&gt;QtWidgets Applications Join Union - This Week in Plasma&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates a weekly report on the work shaping Plasma 6.8. It highlights the first support for styling QtWidgets apps in the new Union theming system, plus a long list of interface, performance and bug-fix improvements across Plasma 6.6.7, 6.7.5 and 6.8.&lt;/p&gt;

&lt;h2 id=&quot;my-plasma-desktop-for-august-2026&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/mi-escritorio-plasma-de-agosto-2026-viernesdeescritorio.html&quot;&gt;My Plasma Desktop for August 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; shares the 75th installment of his monthly Plasma desktop showcase. Running on a Slimbook Evo with KDE Neon and Plasma 6.7.4 on Wayland, the post celebrates the huge variety of ways users organize their workspaces.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed---review-of-the-week-202635&quot;&gt;Tumbleweed - Review of the Week 2026/35&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/08/tumbleweed-review-of-the-week-2026-35/&quot;&gt;Dominique Leuenberger&lt;/a&gt; and &lt;a href=&quot;https://victorhckinthefreeworld.com/2026/08/28/opensuse-tumbleweed-revision-de-la-semana-35-de-2026/&quot;&gt;Victorhck&lt;/a&gt; details Tumbleweed’s week 2026/35 with its five snapshots. Qt 6.11.2, KDE Gear 26.08.0, Linux Kernel 7.2.0 with Cache-Aware Scheduling and Firefox 154.0 were the headline deliveries, while Rust 1.98, Kernel 7.2.2, LLVM 23.1.0 and glibc 2.44 continue through the staging projects.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Tumbleweed&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/03/gsoc-2026-uyuni-mqtt-nodered/</guid>
      <title>GSoC 2026, Event-Driven Automation for Uyuni via MQTT and Node-RED</title>
      <pubDate>Thu, 03 Sep 2026 07:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/03/gsoc-2026-uyuni-mqtt-nodered/</link>
      <author>admin@opensuse.org (Geetansh Goyal)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/uyuni-mqtt-nodered-slack.png" length="165311" type="image/png" />
      <description>Hello, openSUSE community! My name is Geetansh Goyal, and I was a Google Summer of Code (GSoC) 2026 mentee with Uyuni and the openSUSE project. This is my first year contributing to a project of this size, and this post is my account of the summer working on “Event-Driven Automation...</description>
      <content:encoded>&lt;p&gt;Hello, &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE&lt;/a&gt; community!&lt;/p&gt;

&lt;p&gt;My name is Geetansh Goyal, and I was a Google Summer of Code (GSoC) 2026 mentee with &lt;a href=&quot;https://www.uyuni-project.org/&quot;&gt;Uyuni&lt;/a&gt; and the &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE&lt;/a&gt; project. This is my first year contributing to a project of this size, and this post is my account of the summer working on &lt;strong&gt;“Event-Driven Automation for Uyuni via MQTT and Node-RED,”&lt;/strong&gt; mentored by Ondrej Holecek and Abid Mehmood, both from the &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE&lt;/a&gt; community.&lt;/p&gt;

&lt;h2 id=&quot;the-problem&quot;&gt;The problem&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://www.uyuni-project.org/&quot;&gt;Uyuni&lt;/a&gt; already knows the moment something interesting happens: a system registers, a Salt job returns, a state applies, a software channel finishes building. None of that left the server. If you wanted to react to it, your only option was polling the XML-RPC API on a timer, which means either hammering the API for low latency or accepting a delay you didn’t choose. The goal of the project was to let events push out instead, so external tools can react as they happen.&lt;/p&gt;

&lt;h2 id=&quot;what-i-built&quot;&gt;What I built&lt;/h2&gt;

&lt;p&gt;The project has two halves. On the Uyuni side, I added an MQTT publisher to the Java core that publishes nine event types, five from the Salt reactor (system registration, job returns, state application, image deployment and batch starts) and four from domain code (org creation, user creation, and content lifecycle management builds starting and completing). Everything is off by default behind a set of configuration properties, so an existing installation notices nothing until an administrator explicitly turns it on.&lt;/p&gt;

&lt;p&gt;On the consumer side, I built &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;node-red-contrib-uyuni&lt;/code&gt;, a package of custom Node-RED nodes: one to subscribe to Uyuni events, one to call back into the API to apply a state or schedule a reboot, one to query system data, and two config nodes to hold credentials. The idea is that someone who has never touched Uyuni’s API can still wire together “a minion registers, then apply this state, then post to Slack” entirely by dragging nodes onto a canvas.&lt;/p&gt;

&lt;p&gt;To make the whole thing easy to try, I also put together container images for a preconfigured Mosquitto broker and for Node-RED with the Uyuni nodes pre-installed, and a small library of example flows: a Slack alert on patch application, automatic Jira ticket creation, email notifications, and a couple more.&lt;/p&gt;

&lt;h2 id=&quot;what-i-learned&quot;&gt;What I learned&lt;/h2&gt;

&lt;p&gt;I came into this as a first-year student who had never worked in a codebase anywhere near this size, and for the first few weeks I mostly felt like I was guessing. Uyuni’s Java core has years of history in it, and just finding where an event &lt;em&gt;should&lt;/em&gt; be published, let alone where it safely could be, took longer than I want to admit.&lt;/p&gt;

&lt;p&gt;The moment that actually changed how I think about code happened in review. Abid pointed out that my events were sometimes going out before the database transaction that produced them had even committed, meaning a subscriber could hear about something that, a moment later, technically hadn’t happened. I patched it the way I imagine a lot of people patch their first real bug: I found the closest thing that looked like “after commit” and hooked into that. It didn’t work, because I was deferring to the wrong transaction entirely, one that was never doing the actual write. Getting the real fix, which turned out to be as simple as changing the order a handler gets registered in, meant sitting with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ActionExecutor&lt;/code&gt; until I actually understood what “each handler runs in its own transaction” meant for the code I’d written, instead of poking at it until the symptom went away. That’s the lesson I’ll carry past this project: a fix you don’t understand is just a different bug wearing the first one’s clothes.&lt;/p&gt;

&lt;p&gt;The rest of what I learned came from being embarrassingly wrong in front of a real server. I’d copy a file into a running container, restart it to test, and watch my change vanish, because I didn’t yet know that a jar in there was a symlink and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ant deploy&lt;/code&gt; was quietly doing nothing. I’d get a working config, restart the service to confirm it, and lose everything, because a line I hadn’t noticed in the systemd unit was wiping the container clean on every restart. I found a password sitting in a log file in plain text and realized I’d put it there myself, as a JVM argument, which is exactly why every credential in this project now also accepts an environment variable. None of that was in a diff anywhere. I only found it by breaking my own deployment enough times that I stopped trusting anything I hadn’t watched work end to end, which is how I ended up actually measuring it: about 0.112 seconds from a Salt job finishing to a subscriber hearing about it, checked with my own eyes on a real machine, not assumed.&lt;/p&gt;

&lt;h2 id=&quot;where-the-project-stands&quot;&gt;Where the project stands&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://github.com/uyuni-project/uyuni/pull/12385&quot;&gt;implementation PR&lt;/a&gt; and the &lt;a href=&quot;https://github.com/uyuni-project/uyuni-rfc/pull/119&quot;&gt;RFC&lt;/a&gt; are both open and under review as I write this, and the Administration Guide documentation is up for review too. Of the stretch goals, the example flow library is done, MQTT over TLS and a Grafana annotation node are still open for whoever picks this up next, including possibly me.&lt;/p&gt;

&lt;h2 id=&quot;thanks&quot;&gt;Thanks&lt;/h2&gt;

&lt;p&gt;Thank you to Ondrej and Abid for the review that actually made me fix the ordering bug properly instead of papering over it, and to openSUSE and GSoC for the chance to spend a summer inside a codebase this size as a first-year student. It was the first time I had to reason about transaction boundaries in someone else’s production system, and I’d do it again.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, Google Summer of Code, GSoC, Uyuni, MQTT&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/02/tw-monthly-update-august/</guid>
      <title>Tumbleweed Monthly Update - August 2026</title>
      <pubDate>Wed, 02 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/02/tw-monthly-update-august/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/tw.png" length="12041" type="image/png" />
      <description>There were several software package updates for openSUSE Tumbleweed during the month of August, which delivered 23 snapshots across 31 days. August delivered a packed month of snapshots across the desktop, developer tooling, and security surface. KDE Plasma 6.7.4 landed with KWin GPU management fixes and a workaround for libepoxy...</description>
      <content:encoded>&lt;p&gt;There were several software package updates for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; during the month of August, which delivered 23 snapshots across 31 days.&lt;/p&gt;

&lt;p&gt;August delivered a packed month of snapshots across the desktop, developer tooling, and security surface. &lt;a href=&quot;https://kde.org/announcements/plasma/6/6.7.4/&quot;&gt;KDE Plasma 6.7.4&lt;/a&gt; landed with &lt;a href=&quot;https://invent.kde.org/plasma/kwin&quot;&gt;KWin&lt;/a&gt; GPU management fixes and a workaround for &lt;a href=&quot;https://github.com/anholt/libepoxy&quot;&gt;libepoxy&lt;/a&gt; issues when a GPU reset happens. &lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.29.0/&quot;&gt;KDE Frameworks 6.29.0&lt;/a&gt; and &lt;a href=&quot;https://kde.org/announcements/gear/26.08.0/&quot;&gt;KDE Gear 26.08.0&lt;/a&gt; also arrived in the month. &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-shell&quot;&gt;GNOME Shell 50.4&lt;/a&gt; and &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter 50.4&lt;/a&gt; arrived with HiDPI cursor fixes and HDR output improvements. &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; settled into its 26.2 series, and the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; progressed from 7.1.5 to 7.2.0 with a long tail of CVE fixes.&lt;/p&gt;

&lt;p&gt;As always, be sure to roll back using &lt;a href=&quot;https://github.com/openSUSE/snapper&quot;&gt;snapper&lt;/a&gt; if any issues arise.&lt;/p&gt;

&lt;p&gt;For more details on the change logs for the month, visit the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;new-features-and-enhancements&quot;&gt;New Features and Enhancements&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/plasma/6/6.7.4/&quot;&gt;KDE Plasma 6.7.4&lt;/a&gt;&lt;/strong&gt;: The fourth bugfix release of the Plasma 6.7 series brings targeted stability improvements across the desktop. &lt;a href=&quot;https://invent.kde.org/plasma/kwin&quot;&gt;KWin&lt;/a&gt; no longer removes GPUs that have no outputs, which prevents a regression where external monitors connected via docks could disappear. A workaround for &lt;a href=&quot;https://github.com/anholt/libepoxy&quot;&gt;libepoxy&lt;/a&gt; failing when a GPU resets helps stabilize gaming and GPU-accelerated workloads on systems with multiple graphics adapters. The digital clock applet now applies its font family to the time zone label, and dragging items on the taskbar onto grouped tasks no longer breaks when floating applets are enabled. &lt;a href=&quot;https://apps.kde.org/spectacle/&quot;&gt;Spectacle&lt;/a&gt; gained QR code scanning when editing existing screenshots, and &lt;a href=&quot;https://github.com/KDE/kscreen&quot;&gt;KScreen&lt;/a&gt; added a keyboard shortcut to trigger the Configure button from the OSD.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.29.0/&quot;&gt;KDE Frameworks 6.29.0&lt;/a&gt;&lt;/strong&gt;: A new feature release of the KDE component libraries arrived with refinements across &lt;a href=&quot;https://invent.kde.org/frameworks/kio&quot;&gt;KIO&lt;/a&gt;, &lt;a href=&quot;https://invent.kde.org/frameworks/kirigami&quot;&gt;Kirigami&lt;/a&gt; and &lt;a href=&quot;https://invent.kde.org/frameworks/krunner&quot;&gt;KRunner&lt;/a&gt;.  &lt;a href=&quot;https://invent.kde.org/frameworks/solid&quot;&gt;Solid&lt;/a&gt; now returns the mount point as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;filePath()&lt;/code&gt; for the root filesystem through its udisks2 backend, &lt;a href=&quot;https://invent.kde.org/frameworks/bluez-qt&quot;&gt;bluez-qt&lt;/a&gt; resolves a race condition in Bluetooth object manager initialization, and &lt;a href=&quot;https://invent.kde.org/frameworks/ktexteditor&quot;&gt;KTextEditor&lt;/a&gt; gained a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;disabledPlugins&lt;/code&gt; property. A separate &lt;a href=&quot;https://invent.kde.org/plasma/kwin&quot;&gt;KWin&lt;/a&gt; patch improved behavior after unplugging outputs by increasing the Wayland global removal timer timeout.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/gear/26.08.0/&quot;&gt;KDE Gear 26.08.0&lt;/a&gt;&lt;/strong&gt;: The August feature release of the KDE applications collection brought updates across &lt;a href=&quot;https://apps.kde.org/dolphin/&quot;&gt;Dolphin&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/konsole/&quot;&gt;Konsole&lt;/a&gt;, &lt;a href=&quot;https://kate-editor.org/&quot;&gt;Kate&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/okular/&quot;&gt;Okular&lt;/a&gt;, and the &lt;a href=&quot;https://api.kde.org/kdepim/akonadi/html/index.html&quot;&gt;Akonadi&lt;/a&gt; personal information management stack. &lt;a href=&quot;https://apps.kde.org/konsole/&quot;&gt;Konsole&lt;/a&gt; implements the Kitty keyboard protocol and gains direct Copy and Open actions for URLs shown as escape-sequence hotspots. &lt;a href=&quot;https://apps.kde.org/okular/&quot;&gt;Okular&lt;/a&gt; adds copy-and-paste support for annotations and no longer executes load-scripts on signed documents, while &lt;a href=&quot;https://kate-editor.org/&quot;&gt;Kate&lt;/a&gt; fixes working-directory handling when invoking git and possible out-of-bounds reads.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mozilla.org/firefox/&quot;&gt;Firefox&lt;/a&gt; 154.0&lt;/strong&gt;: The browser’s monthly milestone rolled out with a heavy load of &lt;a href=&quot;https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures&quot;&gt;Common Vulnerabilities and Exposures&lt;/a&gt; (CVE) fixes addressing more than 40 issues. The release covers a sandbox escape in the Remote Settings client, same-origin policy bypasses in service workers and cookie handling, use-after-free issues across WebAssembly, image loading, and layout text handling, plus multiple privilege escalation and site isolation issues in the graphics stack. It also refreshed &lt;a href=&quot;https://firefox-source-docs.mozilla.org/security/nss/index.html&quot;&gt;mozilla-nss&lt;/a&gt; to 3.126.1 and &lt;a href=&quot;https://spidermonkey.dev/&quot;&gt;mozjs140&lt;/a&gt; to 140.14.0. Tumbleweed users should update to stay protected.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-shell&quot;&gt;GNOME Shell 50.4&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter 50.4&lt;/a&gt;&lt;/strong&gt;: The GNOME desktop received quality-of-life fixes that clean up day-to-day use. Switching to a minimized window on another workspace no longer causes a visual glitch, and the magnified cursor is correctly scaled on HiDPI displays. A sound glitch caused by pushing redundant volume changes has been eliminated, and menu animations are smoother. On the compositor side, &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter&lt;/a&gt; fixes blurred rendering with non-pixel-aligned monitors, fills in mastering display metadata for HDR output, and corrects invalid redraw clips on rotated monitors. &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-control-center&quot;&gt;GNOME Control Center&lt;/a&gt; 50.4 arrived alongside with updated translations.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gstreamer.freedesktop.org/&quot;&gt;GStreamer&lt;/a&gt; 1.28.6&lt;/strong&gt;: A wide-ranging update across the core and plugin packages with both security and playback fixes. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;playbin3&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;playbin&lt;/code&gt; elements fix stalls that occurred after re-enabling previously disabled subtitles, and the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;h265parser&lt;/code&gt; resolves out-of-bounds writes in RPS parsing. RTP retransmission bitrate estimation is improved, and the Rust (f)mp4 muxers gain H.266/VVC muxing support. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;webrtcsink&lt;/code&gt; fixes H.264 level and profile negotiation and adds support for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nvv4l2h265enc&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.openssh.com/&quot;&gt;OpenSSH&lt;/a&gt; 10.5p1&lt;/strong&gt;: A security-focused release addressing an important vulnerability in agent forwarding. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ssh-agent&lt;/code&gt; interaction between locking and the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;session-bind@openssh.com&lt;/code&gt; extension was broken, meaning operations intended to be limited to local use only could be performed remotely when the agent was locked. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;restrict&lt;/code&gt; keyword in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;authorized_keys&lt;/code&gt; now correctly applies to tunnel forwarding. A potential &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;realloc&lt;/code&gt; use-after-free in the client when a remote forwarding is added via the multiplexing socket is fixed, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ssh-keygen&lt;/code&gt; gains the ability to set or clear touch-required and verify-required flags on FIDO private keys during passphrase reset.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/harfbuzz/harfbuzz&quot;&gt;harfbuzz&lt;/a&gt; 14.3.0 &amp;amp; 14.3.1&lt;/strong&gt;: The text shaping engine that underpins rendering in browsers, desktop environments, and document editors received important improvements. Mark positioning now respects lookup order in the cross-direction, improving compatibility with DirectWrite and Core Text. Mark attachment to ligatures formed from decomposed glyphs is fixed, and the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;calt&lt;/code&gt; feature in Hangul text is now disabled only for the Jamos rather than the entire buffer. The release also adds support for partially instancing of the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;avar&lt;/code&gt; table and the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CFF2&lt;/code&gt; table, relevant for variable font workflows. A follow-up 14.3.1 release arrived later in the month with fuzzing and subsetting fixes, a fix for AAT insertion at the end of the text, and rendering fixes in the experimental GPU library.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; 11.1.0&lt;/strong&gt;: The machine emulator advanced from 11.0.3 with a substantial feature release. Highlights include Universal Flash Storage (UFS) emulation support for Write Booster and Host-Initiated Defragmentation based on the UFS 4.1 specification, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vhost-host-user&lt;/code&gt; support for offloading real-time clock handling from the hypervisor when using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virtio-rtc&lt;/code&gt;. The GUI subsystem gained improvements to virtual console handling and GTK/VNC. ARM support expanded with the new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;imx8mp-evk&lt;/code&gt; machine type and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virt&lt;/code&gt; board cache topology specification.&lt;/p&gt;

&lt;h2 id=&quot;key-package-updates&quot;&gt;Key Package Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 7.1.5 through 7.2.2&lt;/strong&gt;: The kernel progressed through four point releases and a feature release during August with a sustained focus on security and stability. Version 7.1.6 carried fixes for KVM x86 module reload use-after-free, arm64 TLBI errata mitigation, and a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virtiofs&lt;/code&gt; use-after-free on submount umount. Version 7.1.7 added CVE fixes for &lt;a href=&quot;https://www.open-mesh.org/projects/batman-adv/wiki&quot;&gt;batman-adv&lt;/a&gt;, ntfs3, and several networking and driver subsystems. Version 7.1.8 addressed an extensive list of CVEs including Bluetooth &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;btusb&lt;/code&gt; use-after-free, ksmbd deferred file use-after-free, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rtl8723bs&lt;/code&gt; out-of-bounds reads and writes, and RDMA fixes across &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;irdma&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;erdma&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mana_ib&lt;/code&gt;. The &lt;a href=&quot;https://btrfs.readthedocs.io/&quot;&gt;Btrfs&lt;/a&gt; filesystem received fixes for free space cache validation and root leaks during relocation. The 7.2.0 version refreshed the kernel configuration and carried updated AMD Display Core patches. The month closed with the 7.2.2 release, which resovled &lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-80590.html&quot;&gt;CVE-2026-80590&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; 26.1.6, 26.2.0 &amp;amp; 26.2.1&lt;/strong&gt;: The graphics stack made a major jump from 26.1.5 to the 26.2 series during the month. The 26.1.6 bugfix release addressed regressions from the previous stable series, while the 26.2.0 release brought a new batch of driver improvements for AMD, Intel, and Qualcomm hardware. The 26.2.1 bugfix release soon followed, and the &lt;a href=&quot;https://docs.oasis-open.org/virtio/virtio/v1.2/csd01/virtio-v1.2-csd01.html&quot;&gt;VirtIO&lt;/a&gt; Vulkan driver is now enabled in openSUSE’s build, bringing Vulkan support to virtualized environments. Users on AMD and Intel GPUs who experienced rendering issues after earlier Mesa updates should find these releases more stable. The Vulkan drivers continue to see corrections for gaming workloads.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://cryptography.io/&quot;&gt;python-cryptography&lt;/a&gt; 50.0.0&lt;/strong&gt;: A major version bump that deprecates Diffie-Hellman key exchange over finite fields and adds the Cobblestone recipe for streaming authenticated encryption. The most important change is a security fix for Bleichenbacher oracle in PKCS7 decryption; &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pkcs7_decrypt_der&lt;/code&gt; no longer exposes distinguishable errors or timing when unwrapping a RecipientInfo’s encryptedKey. X.509 verification APIs are now considered stable, and ML-DSA public keys and signatures are permitted by default.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.libssh2.org/&quot;&gt;libssh2&lt;/a&gt;&lt;/strong&gt;: Received two rounds of critical security patches during August. The first batch addressed a heap buffer overflow and the second batch fixed arbitrary code execution via double-free in SFTP sessions, denial of service via integer underflow in AES-GCM cipher negotiation, a heap out-of-bounds read, and heap buffer overflow during SSH negotiation. These are essential updates for any system using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libssh2&lt;/code&gt; for SSH or SFTP operations.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.vim.org/&quot;&gt;vim&lt;/a&gt; 9.2.0901&lt;/strong&gt;: A massive update carrying over 100 fixes including eight security patches. Security fixes address arbitrary code execution via keyword lookup, code injection in netrw via bookmarks, heap overflow when adding more than 65,535 text properties, stack buffer overflow in the socket server, and a use-after-free on JSON decode error. The update also fixes numerous memory leaks, a deeply nested regexp pattern stack overflow, and a GTK4 hardware rendering performance regression.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/NLnetLabs/unbound&quot;&gt;unbound&lt;/a&gt; 1.26.0&lt;/strong&gt;: The DNS resolver received a major update with a large list of fixes and new features. New options include &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;max-transfer-size&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;max-transfer-time&lt;/code&gt; for limiting auth-zone and RPZ transfers, and new local-zone types &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;block_aaaa&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;block_a_wdata&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;block_aaaa_wdata&lt;/code&gt;. A heap out-of-bounds write via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;size_t&lt;/code&gt;-to-int truncation is fixed, along with DNSSEC validation fixes for noncanonical RSA DNSKEYs and a race condition causing segfaults when starting threads.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.qt.io/product/qt6&quot;&gt;Qt 6&lt;/a&gt; 6.11.2&lt;/strong&gt;: The second bugfix release of the 6.11 series landed across the full module range from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;qt6-base&lt;/code&gt; through &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;qt6-webengine&lt;/code&gt;. The update fixes a regression in icon loading and carries multiple stability corrections for the toolkit that &lt;a href=&quot;https://kde.org/plasma-desktop&quot;&gt;Plasma&lt;/a&gt; and most KDE applications build on. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;qt6-webengine&lt;/code&gt; also merges an upstream fix for AMD VA-API flickering on Wayland.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://w1.fi/&quot;&gt;wpa_supplicant&lt;/a&gt; 2.12&lt;/strong&gt;: The Wi-Fi authentication daemon adds more complete EHT/IEEE 802.11be/Wi-Fi 7 support including fixes for message validation issues that could enable denial-of-service attacks, and group key rekeying is corrected. SAE group 20 is now enabled by default when SAE-EXT-KEY is available, and IEEE 802.11bi functionality is supported including changing SAE password identifiers, EPPKE, and association frame encryption. RSN overriding (WPA3-Personal Compatibility Mode) is supported, and Automated Frequency Coordination (AFC) on the 6 GHz band is now available. The build enables &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CONFIG_IEEE80211BE&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CONFIG_SAE_PK&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CONFIG_PMKSA_PRIVACY&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CONFIG_IEEE8021X_AUTH&lt;/code&gt; by default.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.postgresql.org/&quot;&gt;postgresql18&lt;/a&gt; 18.6&lt;/strong&gt;: A major security release for PostgreSQL 18 that fixes more than two dozen CVEs covering remote code execution and denial of service issues. Notable fixes include heap buffer overflows in regular expression matching, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;to_char&lt;/code&gt; formatting, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_stat_statements&lt;/code&gt; that could execute arbitrary code, a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;psql&lt;/code&gt; issue where early failures in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;COPY FROM STDIN&lt;/code&gt; process data lines as command input, and a logical decoding flaw that could &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dlopen&lt;/code&gt; an arbitrary file. Database administrators on Tumbleweed should plan an update soon.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://flatpak.org/&quot;&gt;flatpak&lt;/a&gt; 1.18.1&lt;/strong&gt;: A security-focused bugfix release addressing several sandbox escape and privilege escalation paths in the application framework. Fixes include a sandbox escape with full host filesystem read/write access via a symlink attack on app data directories, a local root privilege escalation via revokefs symlink path traversal and commit tampering, and arbitrary root writes through path traversal in extra-data extraction and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flatpak build-init&lt;/code&gt;. The release also corrects an anti-downgrade bypass that allowed unprivileged users to downgrade system applications.&lt;/p&gt;

&lt;h2 id=&quot;security-updates&quot;&gt;Security Updates&lt;/h2&gt;

&lt;h3 id=&quot;libssh2&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.libssh2.org/&quot;&gt;libssh2&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58050.html&quot;&gt;CVE-2026-58050&lt;/a&gt;&lt;/strong&gt;: Fixes a heap buffer overflow via attacker-controlled attribute count from a publickey-subsystem response.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58051.html&quot;&gt;CVE-2026-58051&lt;/a&gt;&lt;/strong&gt;: Addresses uninitialized pointer being freed when a malformed response is sent by an SSH server.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66032.html&quot;&gt;CVE-2026-66032&lt;/a&gt;&lt;/strong&gt;: Resolves arbitrary code execution via double-free in SFTP session.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66033.html&quot;&gt;CVE-2026-66033&lt;/a&gt;&lt;/strong&gt;: Fixes denial of service via integer underflow in AES-GCM cipher negotiation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66034.html&quot;&gt;CVE-2026-66034&lt;/a&gt;&lt;/strong&gt;: Addresses heap out-of-bounds read leading to information disclosure and potential arbitrary code execution.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66035.html&quot;&gt;CVE-2026-66035&lt;/a&gt;&lt;/strong&gt;: Fixes heap buffer overflow during SSH negotiation.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;samba-4245&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.samba.org/&quot;&gt;Samba&lt;/a&gt; 4.24.5&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6949.html&quot;&gt;CVE-2026-6949&lt;/a&gt;&lt;/strong&gt;: Fixes TSIG packet with crafted name compression crashing the internal DNS server.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58224.html&quot;&gt;CVE-2026-58224&lt;/a&gt;&lt;/strong&gt;: Addresses CTDB heap out-of-bounds read via unchecked packet length fields.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58216.html&quot;&gt;CVE-2026-58216&lt;/a&gt;&lt;/strong&gt;: Resolves 6-byte heap out-of-bounds read in kpasswd service packet parser.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58218.html&quot;&gt;CVE-2026-58218&lt;/a&gt;&lt;/strong&gt;: Fixes DNS TKEY negotiation storing unauthenticated GSS contexts in a fixed FIFO before authentication completes.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58221.html&quot;&gt;CVE-2026-58221&lt;/a&gt;&lt;/strong&gt;: Addresses authenticated LDAP access to internal LDB special DNs permitting domain takeover.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58222.html&quot;&gt;CVE-2026-58222&lt;/a&gt;&lt;/strong&gt;: Resolves LDAP Compare filter injection and trusted-request confusion disclosing protected attributes.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;vim-920901&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.vim.org/&quot;&gt;vim&lt;/a&gt; 9.2.0901&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8339.html&quot;&gt;CVE-2026-8339&lt;/a&gt;&lt;/strong&gt;: Fixes arbitrary code execution via keyword lookup.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8340.html&quot;&gt;CVE-2026-8340&lt;/a&gt;&lt;/strong&gt;: Addresses code injection in netrw via bookmarks.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8341.html&quot;&gt;CVE-2026-8341&lt;/a&gt;&lt;/strong&gt;: Resolves heap overflow when adding more than 65,535 text properties.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8342.html&quot;&gt;CVE-2026-8342&lt;/a&gt;&lt;/strong&gt;: Fixes stack buffer overflow in the socket server.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8343.html&quot;&gt;CVE-2026-8343&lt;/a&gt;&lt;/strong&gt;: Addresses popup opacity mask indexed out of bounds.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8344.html&quot;&gt;CVE-2026-8344&lt;/a&gt;&lt;/strong&gt;: Resolves use-after-free on JSON decode error.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8345.html&quot;&gt;CVE-2026-8345&lt;/a&gt;&lt;/strong&gt;: Fixes arbitrary Ex command execution during C omni-completion.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8346.html&quot;&gt;CVE-2026-8346&lt;/a&gt;&lt;/strong&gt;: Addresses heap buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;set_sofo()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;linux-kernel-716-717--718&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 7.1.6, 7.1.7 &amp;amp; 7.1.8&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64490.html&quot;&gt;CVE-2026-64490&lt;/a&gt;&lt;/strong&gt;: Fixes ALSA virtio control metadata validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64489.html&quot;&gt;CVE-2026-64489&lt;/a&gt;&lt;/strong&gt;: Addresses ALSA ymfpci &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;snd_ctl_new1&lt;/code&gt; return value check.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64486.html&quot;&gt;CVE-2026-64486&lt;/a&gt;&lt;/strong&gt;: Resolves ALSA cmipci &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;snd_ctl_new1&lt;/code&gt; return value check.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64481.html&quot;&gt;CVE-2026-64481&lt;/a&gt;&lt;/strong&gt;: Fixes ALSA hda-cs35l41 firmware load work teardown.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64480.html&quot;&gt;CVE-2026-64480&lt;/a&gt;&lt;/strong&gt;: Addresses ALSA ice1712 &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;snd_ctl_new1&lt;/code&gt; return value check.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64477.html&quot;&gt;CVE-2026-64477&lt;/a&gt;&lt;/strong&gt;: Resolves x86 fs/resctrl out-of-bounds access.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64476.html&quot;&gt;CVE-2026-64476&lt;/a&gt;&lt;/strong&gt;: Fixes VFIO PCI &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;disable_idle_d3&lt;/code&gt; per-device latch.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64475.html&quot;&gt;CVE-2026-64475&lt;/a&gt;&lt;/strong&gt;: Addresses VFIO PCI VGA arbiter client release on registration.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64474.html&quot;&gt;CVE-2026-64474&lt;/a&gt;&lt;/strong&gt;: Resolves VFIO infinite loop in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vfio_mig_get_next&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64471.html&quot;&gt;CVE-2026-64471&lt;/a&gt;&lt;/strong&gt;: Fixes Bluetooth btusb use-after-free on registration.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64466.html&quot;&gt;CVE-2026-64466&lt;/a&gt;&lt;/strong&gt;: Addresses Rust binder freeze listener cleanup on node removal.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64437.html&quot;&gt;CVE-2026-64437&lt;/a&gt;&lt;/strong&gt;: Resolves ksmbd use-after-free of a deferred file location.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64436.html&quot;&gt;CVE-2026-64436&lt;/a&gt;&lt;/strong&gt;: Fixes net af_key uninitialized &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;alg_key_len&lt;/code&gt; for IPComp.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64433.html&quot;&gt;CVE-2026-64433&lt;/a&gt;&lt;/strong&gt;: Addresses Bluetooth MGMT use-after-free of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hci_conn_params&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64432.html&quot;&gt;CVE-2026-64432&lt;/a&gt;&lt;/strong&gt;: Resolves ntfs3 Dirty Page Table capacity validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64431.html&quot;&gt;CVE-2026-64431&lt;/a&gt;&lt;/strong&gt;: Fixes ntfs avoid calling &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;post_write_mst_fixup&lt;/code&gt; for invalid ranges.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64430.html&quot;&gt;CVE-2026-64430&lt;/a&gt;&lt;/strong&gt;: Addresses NTB EPF avoid calling &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pci_irq_vector&lt;/code&gt; from hardirq.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64424.html&quot;&gt;CVE-2026-64424&lt;/a&gt;&lt;/strong&gt;: Resolves netpoll use-after-free on shutdown path.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64449.html&quot;&gt;CVE-2026-64449&lt;/a&gt;&lt;/strong&gt;: Fixes staging vme_user bound slave read/write to the buffer size.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64445.html&quot;&gt;CVE-2026-64445&lt;/a&gt;&lt;/strong&gt;: Addresses staging rtl8723bs WEP length underflow and buffer overflow.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64444.html&quot;&gt;CVE-2026-64444&lt;/a&gt;&lt;/strong&gt;: Resolves staging rtl8723bs out-of-bounds read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;OnAssocRsp&lt;/code&gt; IE.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64441.html&quot;&gt;CVE-2026-64441&lt;/a&gt;&lt;/strong&gt;: Fixes staging rtl8723bs out-of-bounds reads in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rtw_get_sec&lt;/code&gt; functions.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64440.html&quot;&gt;CVE-2026-64440&lt;/a&gt;&lt;/strong&gt;: Addresses staging rtl8723bs out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HT_caps_hand&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64599.html&quot;&gt;CVE-2026-64599&lt;/a&gt;&lt;/strong&gt;: Resolves crypto amlogic double cleanup in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;meson_cr&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;firefox-1540&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mozilla.org/firefox/&quot;&gt;Firefox&lt;/a&gt; 154.0&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75874.html&quot;&gt;CVE-2026-75874&lt;/a&gt;&lt;/strong&gt;: Fixes a sandbox escape in the Remote Settings client component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74934.html&quot;&gt;CVE-2026-74934&lt;/a&gt;&lt;/strong&gt;: Addresses a site isolation issue in the Graphics CanvasWebGL component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74936.html&quot;&gt;CVE-2026-74936&lt;/a&gt;&lt;/strong&gt;: Resolves a use-after-free in the JavaScript WebAssembly component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74937.html&quot;&gt;CVE-2026-74937&lt;/a&gt;&lt;/strong&gt;: Fixes a use-after-free in the JavaScript GC component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74939.html&quot;&gt;CVE-2026-74939&lt;/a&gt;&lt;/strong&gt;: Addresses a privilege escalation in the DOM Navigation component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74943.html&quot;&gt;CVE-2026-74943&lt;/a&gt;&lt;/strong&gt;: Resolves a use-after-free in the Graphics ImageLib component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74944.html&quot;&gt;CVE-2026-74944&lt;/a&gt;&lt;/strong&gt;: Fixes a use-after-free in the DOM Core &amp;amp; HTML component.
https://github.com/KDE/kscreen&lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74953.html&quot;&gt;CVE-2026-74953&lt;/a&gt;&lt;/strong&gt;: Addresses a privilege escalation in the Networking Cookies component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74956.html&quot;&gt;CVE-2026-74956&lt;/a&gt;&lt;/strong&gt;: Resolves a same-origin policy bypass in the DOM Service Workers component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74969.html&quot;&gt;CVE-2026-74969&lt;/a&gt;&lt;/strong&gt;: Fixes a use-after-free in the Layout Text and Fonts component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-74976.html&quot;&gt;CVE-2026-74976&lt;/a&gt;&lt;/strong&gt;: Addresses a JIT miscompilation in the JavaScript Engine JIT component.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;webkitgtk-2526&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://webkitgtk.org/&quot;&gt;WebKitGTK&lt;/a&gt; 2.52.6&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43804.html&quot;&gt;CVE-2026-43804&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in the WebKit rendering engine.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64713.html&quot;&gt;CVE-2026-64713&lt;/a&gt;&lt;/strong&gt;: Addresses a memory corruption issue in the WebKit rendering engine.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64719.html&quot;&gt;CVE-2026-64719&lt;/a&gt;&lt;/strong&gt;: Resolves a security vulnerability in the WebKit rendering engine.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64728.html&quot;&gt;CVE-2026-64728&lt;/a&gt;&lt;/strong&gt;: Fixes a memory safety issue in the WebKit rendering engine.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64730.html&quot;&gt;CVE-2026-64730&lt;/a&gt;&lt;/strong&gt;: Addresses a security vulnerability in the JavaScriptCore engine.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64757.html&quot;&gt;CVE-2026-64757&lt;/a&gt;&lt;/strong&gt;: Resolves a memory corruption issue in the WebKit rendering engine.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64783.html&quot;&gt;CVE-2026-64783&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in the WebKit rendering engine.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;postgresql18-186&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.postgresql.org/&quot;&gt;postgresql18&lt;/a&gt; 18.6&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6464.html&quot;&gt;CVE-2026-6464&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;psql&lt;/code&gt; processing data lines as command input after an early failure in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;COPY FROM STDIN&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6471.html&quot;&gt;CVE-2026-6471&lt;/a&gt;&lt;/strong&gt;: Addresses logical decoding being able to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dlopen&lt;/code&gt; an arbitrary file.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-14662.html&quot;&gt;CVE-2026-14662&lt;/a&gt;&lt;/strong&gt;: Resolves undersize allocations for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tsvector&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tsquery&lt;/code&gt; via integer wraparound.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-14664.html&quot;&gt;CVE-2026-14664&lt;/a&gt;&lt;/strong&gt;: Fixes a regexp heap buffer overflow that executes arbitrary code.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-14669.html&quot;&gt;CVE-2026-14669&lt;/a&gt;&lt;/strong&gt;: Addresses a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;to_char&lt;/code&gt; heap buffer overflow that executes arbitrary code.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-14676.html&quot;&gt;CVE-2026-14676&lt;/a&gt;&lt;/strong&gt;: Resolves a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_stat_statements&lt;/code&gt; heap buffer overflow that executes arbitrary code.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-14679.html&quot;&gt;CVE-2026-14679&lt;/a&gt;&lt;/strong&gt;: Fixes a stack buffer overflow in argument match that writes to server memory.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-15741.html&quot;&gt;CVE-2026-15741&lt;/a&gt;&lt;/strong&gt;: Addresses SQL injection via an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;EXTRACT&lt;/code&gt; argument during expression deparse.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18408.html&quot;&gt;CVE-2026-18408&lt;/a&gt;&lt;/strong&gt;: Resolves &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;psql&lt;/code&gt; &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;\unrestrict&lt;/code&gt; letting a superuser execute arbitrary code in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;psql&lt;/code&gt; client.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19385.html&quot;&gt;CVE-2026-19385&lt;/a&gt;&lt;/strong&gt;: Fixes a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_dump&lt;/code&gt; heap buffer overflow that executes arbitrary code.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;expat-282&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://libexpat.github.io/&quot;&gt;expat&lt;/a&gt; 2.8.2&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-50219.html&quot;&gt;CVE-2026-50219&lt;/a&gt;&lt;/strong&gt;: Fixes memory corruption affecting Expat bindings by disallowing reentrant calls to functions such as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_GetBuffer&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_Parse&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_ParserFree&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56131.html&quot;&gt;CVE-2026-56131&lt;/a&gt;&lt;/strong&gt;: Addresses &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_ResumeParser&lt;/code&gt; being called from a handler, plugging a hole in the CVE-2026-50219 fix.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56132.html&quot;&gt;CVE-2026-56132&lt;/a&gt;&lt;/strong&gt;: Resolves an out-of-bounds scaffolding index store in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;doProlog&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56403.html&quot;&gt;CVE-2026-56403&lt;/a&gt;&lt;/strong&gt;: Fixes an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;storeAtts&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56404.html&quot;&gt;CVE-2026-56404&lt;/a&gt;&lt;/strong&gt;: Addresses an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;addBinding&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56405.html&quot;&gt;CVE-2026-56405&lt;/a&gt;&lt;/strong&gt;: Resolves an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;getAttributeId&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56406.html&quot;&gt;CVE-2026-56406&lt;/a&gt;&lt;/strong&gt;: Fixes an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_ParseBuffer&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56407.html&quot;&gt;CVE-2026-56407&lt;/a&gt;&lt;/strong&gt;: Addresses an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;textLen&lt;/code&gt; handling.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56408.html&quot;&gt;CVE-2026-56408&lt;/a&gt;&lt;/strong&gt;: Resolves an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;copyString&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56409.html&quot;&gt;CVE-2026-56409&lt;/a&gt;&lt;/strong&gt;: Fixes an integer overflow in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xmlwf&lt;/code&gt; output path join.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56410.html&quot;&gt;CVE-2026-56410&lt;/a&gt;&lt;/strong&gt;: Addresses an integer overflow in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xmlwf&lt;/code&gt; &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;resolveSystemId&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56411.html&quot;&gt;CVE-2026-56411&lt;/a&gt;&lt;/strong&gt;: Resolves an integer overflow in notation list allocation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56412.html&quot;&gt;CVE-2026-56412&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_TOK_DATA_CHARS&lt;/code&gt; handler calls in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;doCdataSection&lt;/code&gt;, plugging a hole in the CVE-2026-50219 fix.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;c-ares-1348&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://c-ares.org/&quot;&gt;c-ares&lt;/a&gt; 1.34.8&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33630.html&quot;&gt;CVE-2026-33630&lt;/a&gt;&lt;/strong&gt;: Fixes a use-after-free and double-free in query-completion handling remotely triggerable via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ares_getaddrinfo()&lt;/code&gt; over TCP.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-69184.html&quot;&gt;CVE-2026-69184&lt;/a&gt;&lt;/strong&gt;: Addresses a CPU-exhaustion denial of service via unbounded DNS name compression pointer chains.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-69186.html&quot;&gt;CVE-2026-69186&lt;/a&gt;&lt;/strong&gt;: Resolves a memory-amplification denial of service via unvalidated DNS header record counts.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;busybox&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://busybox.net/&quot;&gt;busybox&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-38755.html&quot;&gt;CVE-2026-38755&lt;/a&gt;&lt;/strong&gt;: Fixes stack exhaustion in the ash applet caused by unbounded shell function recursion.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-38754.html&quot;&gt;CVE-2026-38754&lt;/a&gt;&lt;/strong&gt;: Addresses an out-of-bounds read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ifsbreakup()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-38753.html&quot;&gt;CVE-2026-38753&lt;/a&gt;&lt;/strong&gt;: Resolves a use-after-free in the awk applet regexp processing code during text replacement operations.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-38752.html&quot;&gt;CVE-2026-38752&lt;/a&gt;&lt;/strong&gt;: Fixes stack exhaustion in the awk applet caused by unbounded function call recursion.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2023-42366.html&quot;&gt;CVE-2023-42366&lt;/a&gt;&lt;/strong&gt;: Addresses a heap buffer overflow in the awk applet when a regexp ends with a backslash.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;openexr-3414&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.openexr.com/&quot;&gt;OpenEXR&lt;/a&gt; 3.4.14&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-68513.html&quot;&gt;CVE-2026-68513&lt;/a&gt;&lt;/strong&gt;: Fixes a PyOpenEXR prefixed literal RGB key collision heap buffer overflow.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-68514.html&quot;&gt;CVE-2026-68514&lt;/a&gt;&lt;/strong&gt;: Addresses a PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59183.html&quot;&gt;CVE-2026-59183&lt;/a&gt;&lt;/strong&gt;: Resolves a signed integer overflow leading to out-of-bounds memory access in deep tile decoding.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59186.html&quot;&gt;CVE-2026-59186&lt;/a&gt;&lt;/strong&gt;: Fixes an ILP32 &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;TiledRgbaInputFile&lt;/code&gt; large tile Array2D heap out-of-bounds write.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59187.html&quot;&gt;CVE-2026-59187&lt;/a&gt;&lt;/strong&gt;: Addresses an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;exrmetrics&lt;/code&gt; deep pixelmode heap buffer overflow.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59981.html&quot;&gt;CVE-2026-59981&lt;/a&gt;&lt;/strong&gt;: Resolves an OpenEXRUtil SampleCountChannel row nonzero dataWindow heap out-of-bounds read.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59985.html&quot;&gt;CVE-2026-59985&lt;/a&gt;&lt;/strong&gt;: Fixes an ILP32 OpenEXRCore RLE decode heap out-of-bounds read denial of service.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-61555.html&quot;&gt;CVE-2026-61555&lt;/a&gt;&lt;/strong&gt;: Addresses a crash on empty multiView &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;viewFromChannelName&lt;/code&gt; files.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-62986.html&quot;&gt;CVE-2026-62986&lt;/a&gt;&lt;/strong&gt;: Resolves a PyOpenEXR deep prefixed RGB stale lane disclosure.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;python313&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.python.org/&quot;&gt;python313&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-0864.html&quot;&gt;CVE-2026-0864&lt;/a&gt;&lt;/strong&gt;: Fixes mixed line ending handling in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;configparser&lt;/code&gt; by normalizing all line endings.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-11972.html&quot;&gt;CVE-2026-11972&lt;/a&gt;&lt;/strong&gt;: Addresses &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tarfile._Stream.seek&lt;/code&gt; not breaking at end of file.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4360.html&quot;&gt;CVE-2026-4360&lt;/a&gt;&lt;/strong&gt;: Resolves a missing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;filter_function&lt;/code&gt; pass-through to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;TarFile._extract_one()&lt;/code&gt; during &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.extract()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-15308.html&quot;&gt;CVE-2026-15308&lt;/a&gt;&lt;/strong&gt;: Fixes quadratic complexity in incremental &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HTMLParser&lt;/code&gt; parsing enabling CPU exhaustion.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;gzip&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/gzip/&quot;&gt;gzip&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-41992.html&quot;&gt;CVE-2026-41992&lt;/a&gt;&lt;/strong&gt;: Fixes global buffer overflow in the LZH decompression logic.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libxfont2&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.freedesktop.org/xorg/lib/libxfont&quot;&gt;libXfont2&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59679.html&quot;&gt;CVE-2026-59679&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fs_read_glyphs()&lt;/code&gt; heap out-of-bounds read/write via encoding array index mismatch.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44950.html&quot;&gt;CVE-2026-44950&lt;/a&gt;&lt;/strong&gt;: Addresses &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;fs_read_glyphs()&lt;/code&gt; heap buffer overflow via cumulative glyph data overflow.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;glib2-2883&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/glib&quot;&gt;glib2&lt;/a&gt; 2.88.3&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-15588.html&quot;&gt;CVE-2026-15588&lt;/a&gt;&lt;/strong&gt;: Fixes GDBusServer pre-authentication denial of service via unbounded SASL line buffering.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;dracut&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://dracut.wiki.kernel.org/&quot;&gt;dracut&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-15816.html&quot;&gt;CVE-2026-15816&lt;/a&gt;&lt;/strong&gt;: Addresses root code execution via unescaped error message written to sourced emergency hook script in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;die()&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;python-cryptography-5000&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://cryptography.io/&quot;&gt;python-cryptography&lt;/a&gt; 50.0.0&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-69247.html&quot;&gt;CVE-2026-69247&lt;/a&gt;&lt;/strong&gt;: Fixes Bleichenbacher oracle in PKCS7 decryption where distinguishable errors or timing could leak information when unwrapping a RecipientInfo’s encryptedKey.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libostree-20263&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://ostreedev.github.io/ostree/&quot;&gt;libostree&lt;/a&gt; 2026.3&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58055.html&quot;&gt;CVE-2026-58055&lt;/a&gt;&lt;/strong&gt;: Fixes unbounded LZMA decompression in static delta processing allowing denial of service.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58056.html&quot;&gt;CVE-2026-58056&lt;/a&gt;&lt;/strong&gt;: Addresses heap buffer overflow via integer truncation in static delta bspatch on 32-bit systems.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;gdm-502&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://wiki.gnome.org/Projects/GDM&quot;&gt;gdm&lt;/a&gt; 50.2&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58058.html&quot;&gt;CVE-2026-58058&lt;/a&gt;&lt;/strong&gt;: Fixes path traversal vulnerability where a compromised greeter could load arbitrary &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.desktop&lt;/code&gt; files via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SelectSession&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58059.html&quot;&gt;CVE-2026-58059&lt;/a&gt;&lt;/strong&gt;: Addresses autologin bypass where a compromised greeter could request autologin for any local account.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58060.html&quot;&gt;CVE-2026-58060&lt;/a&gt;&lt;/strong&gt;: Resolves denial of service where an invalid session name from the greeter would cause the entire daemon to exit.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;udisks2-2112&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://udisks.freedesktop.org/&quot;&gt;udisks2&lt;/a&gt; 2.11.2&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7867.html&quot;&gt;CVE-2026-7867&lt;/a&gt;&lt;/strong&gt;: Fixes an unprivileged D-Bus caller using the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;as-user&lt;/code&gt; Filesystem.Mount() option combined with fstab entries containing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;user&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;users&lt;/code&gt; mount options to mount on behalf of another user without polkit authorization.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;php8-859&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.php.net/&quot;&gt;php8&lt;/a&gt; 8.5.9&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-17543.html&quot;&gt;CVE-2026-17543&lt;/a&gt;&lt;/strong&gt;: Fixes SQL injection via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;E&apos;...&apos;&lt;/code&gt; backslash breakout in PostgreSQL.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-17544.html&quot;&gt;CVE-2026-17544&lt;/a&gt;&lt;/strong&gt;: Addresses out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;bccomp()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7260.html&quot;&gt;CVE-2026-7260&lt;/a&gt;&lt;/strong&gt;: Resolves crash via recursive symlinks in Phar.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-9672.html&quot;&gt;CVE-2026-9672&lt;/a&gt;&lt;/strong&gt;: Fixes a vulnerability in the GD library upgrade.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libssh2-1&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.libssh2.org/&quot;&gt;libssh2&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58050.html&quot;&gt;CVE-2026-58050&lt;/a&gt;&lt;/strong&gt;: Fixes heap buffer overflow via attacker-controlled attribute count from a publickey-subsystem response.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58051.html&quot;&gt;CVE-2026-58051&lt;/a&gt;&lt;/strong&gt;: Addresses uninitialized pointer freed when a malformed response is sent by an SSH server.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;python-pip-262&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://pip.pypa.io/&quot;&gt;python-pip&lt;/a&gt; 26.2&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-13346.html&quot;&gt;CVE-2026-13346&lt;/a&gt;&lt;/strong&gt;: Fixes double decoding of the URL path while determining a link filename.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;gimp&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gimp.org/&quot;&gt;gimp&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66757.html&quot;&gt;CVE-2026-66757&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in GIMP image processing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66758.html&quot;&gt;CVE-2026-66758&lt;/a&gt;&lt;/strong&gt;: Addresses a security vulnerability in GIMP.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66759.html&quot;&gt;CVE-2026-66759&lt;/a&gt;&lt;/strong&gt;: Resolves a security vulnerability in GIMP.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59087.html&quot;&gt;CVE-2026-59087&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in GIMP image processing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59088.html&quot;&gt;CVE-2026-59088&lt;/a&gt;&lt;/strong&gt;: Addresses a security vulnerability in GIMP.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59090.html&quot;&gt;CVE-2026-59090&lt;/a&gt;&lt;/strong&gt;: Resolves a security vulnerability in GIMP.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-59091.html&quot;&gt;CVE-2026-59091&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in GIMP.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libheif-1231&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/nickvdp/libheif&quot;&gt;libheif&lt;/a&gt; 1.23.1&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-62289.html&quot;&gt;CVE-2026-62289&lt;/a&gt;&lt;/strong&gt;: Fixes integer underflow in Fraction constructor via double clap transform application.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-62291.html&quot;&gt;CVE-2026-62291&lt;/a&gt;&lt;/strong&gt;: Addresses heap out-of-bounds write in uncompressed encoder when writing images with mismatched auxiliary alpha dimensions.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-62292.html&quot;&gt;CVE-2026-62292&lt;/a&gt;&lt;/strong&gt;: Resolves out-of-bounds read in uncompressed unci tile range slicing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-62377.html&quot;&gt;CVE-2026-62377&lt;/a&gt;&lt;/strong&gt;: Fixes reachable assertion in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HeifContext::get_track()&lt;/code&gt; aborting on a valid-but-empty HEIF sequence file.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;nghttp2-1700&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://nghttp2.org/&quot;&gt;nghttp2&lt;/a&gt; 1.70.0&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58055.html&quot;&gt;CVE-2026-58055&lt;/a&gt;&lt;/strong&gt;: Fixes out-of-bounds read in the base64 decoder.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libgit2-197&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://libgit2.org/&quot;&gt;libgit2&lt;/a&gt; 1.9.7&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5917.html&quot;&gt;CVE-2026-5917&lt;/a&gt;&lt;/strong&gt;: Fixes improper escaping of remote repository paths in libssh2.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;bzip2&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://sourceware.org/bzip2/&quot;&gt;bzip2&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42250.html&quot;&gt;CVE-2026-42250&lt;/a&gt;&lt;/strong&gt;: Fixes an off-by-one error in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;bzip2recover&lt;/code&gt; utility when processing a specially crafted file that can lead to a crash.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;openssl-3-3x&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.openssl.org/&quot;&gt;openssl-3&lt;/a&gt; 3.x&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75803.html&quot;&gt;CVE-2026-75803&lt;/a&gt;&lt;/strong&gt;: Fixes AEAD forgeries with empty ciphertext when using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;EVP_Cipher()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-14456.html&quot;&gt;CVE-2026-14456&lt;/a&gt;&lt;/strong&gt;: Addresses unbounded memory growth in QUIC server incoming channel queue.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-14457.html&quot;&gt;CVE-2026-14457&lt;/a&gt;&lt;/strong&gt;: Resolves RPK server signature algorithm selection dereferencing a missing certificate.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18798.html&quot;&gt;CVE-2026-18798&lt;/a&gt;&lt;/strong&gt;: Fixes QUIC server triggering a double free when processing an INITIAL packet.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34181.html&quot;&gt;CVE-2026-34181&lt;/a&gt;&lt;/strong&gt;: Addresses PKCS#12 files with PBMAC1 being accepted with short HMAC keys.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-54874.html&quot;&gt;CVE-2026-54874&lt;/a&gt;&lt;/strong&gt;: Resolves excessive memory use buffering DTLS records for a future epoch.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-63072.html&quot;&gt;CVE-2026-63072&lt;/a&gt;&lt;/strong&gt;: Fixes a heap buffer overflow in CMS key unwrapping.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-63073.html&quot;&gt;CVE-2026-63073&lt;/a&gt;&lt;/strong&gt;: Addresses untrusted sender DN used as format string in CMP response validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-63074.html&quot;&gt;CVE-2026-63074&lt;/a&gt;&lt;/strong&gt;: Resolves CMP indefinite cache growth of ExtraCerts.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-63075.html&quot;&gt;CVE-2026-63075&lt;/a&gt;&lt;/strong&gt;: Fixes QUIC ACK-only packet retention causing memory exhaustion.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-63076.html&quot;&gt;CVE-2026-63076&lt;/a&gt;&lt;/strong&gt;: Addresses invalid pointer dereference in CMP server via crafted &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;protectionAlg&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;java-25-openjdk-25041&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://openjdk.org/&quot;&gt;java-25-openjdk&lt;/a&gt; 25.0.4.1&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-60589.html&quot;&gt;CVE-2026-60589&lt;/a&gt;&lt;/strong&gt;: Fixes resource resolving vulnerability.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-61308.html&quot;&gt;CVE-2026-61308&lt;/a&gt;&lt;/strong&gt;: Addresses HTTP connection enhancement security issue.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70907.html&quot;&gt;CVE-2026-70907&lt;/a&gt;&lt;/strong&gt;: Resolves TLS server security vulnerability.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70906.html&quot;&gt;CVE-2026-70906&lt;/a&gt;&lt;/strong&gt;: Fixes font loading security vulnerability.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;cpio&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/cpio/&quot;&gt;cpio&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66484.html&quot;&gt;CVE-2026-66484&lt;/a&gt;&lt;/strong&gt;: Fixes path traversal allowing creation of hard links outside the intended directory via malicious tar archives.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66485.html&quot;&gt;CVE-2026-66485&lt;/a&gt;&lt;/strong&gt;: Addresses denial of service via uncontrolled memory allocation from crafted archives.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66486.html&quot;&gt;CVE-2026-66486&lt;/a&gt;&lt;/strong&gt;: Resolves terminal control sequence injection via crafted archive member names.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libvirt&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://libvirt.org/&quot;&gt;libvirt&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-77159.html&quot;&gt;CVE-2026-77159&lt;/a&gt;&lt;/strong&gt;: Fixes QEMU TPM following symlinks when chown’ing log files.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18917.html&quot;&gt;CVE-2026-18917&lt;/a&gt;&lt;/strong&gt;: Addresses integer overflow in RPC handler for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virNodeGetFreePages&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;multipath-tools&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools&quot;&gt;multipath-tools&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hmcm-9cq4-r2xm&quot;&gt;GHSA-hmcm-9cq4-r2xm&lt;/a&gt;&lt;/strong&gt;: Fixes denial of service on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;multipathd&lt;/code&gt; socket by blocking IPC send operations.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools/security/advisories/GHSA-pvp6-c9p3-25fp&quot;&gt;GHSA-pvp6-c9p3-25fp&lt;/a&gt;&lt;/strong&gt;: Addresses denial of service on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;multipathd&lt;/code&gt; socket by exhausting connections.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools/security/advisories/GHSA-g5mh-253r-jjw5&quot;&gt;GHSA-g5mh-253r-jjw5&lt;/a&gt;&lt;/strong&gt;: Resolves heap out-of-bounds read in custom format string parser via trailing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;%&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools/security/advisories/GHSA-pxwh-g75c-95pc&quot;&gt;GHSA-pxwh-g75c-95pc&lt;/a&gt;&lt;/strong&gt;: Fixes heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools/security/advisories/GHSA-p6rh-9x9j-3hvx&quot;&gt;GHSA-p6rh-9x9j-3hvx&lt;/a&gt;&lt;/strong&gt;: Addresses &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;kpartx&lt;/code&gt; heap out-of-bounds read in GPT header validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools/security/advisories/GHSA-gr7q-prfc-q636&quot;&gt;GHSA-gr7q-prfc-q636&lt;/a&gt;&lt;/strong&gt;: Resolves path traversal in device-mapper-multipath &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;failed_wwids&lt;/code&gt; management.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hj7j-qr9h-5fv6&quot;&gt;GHSA-hj7j-qr9h-5fv6&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libmpathpersist&lt;/code&gt; PRIN READ FULL STATUS parser unbounded descriptor rewrite causing root heap overflow.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Users are advised to update to the latest versions to mitigate these vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;August was a busy month for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; with 23 snapshots delivering a steady cadence of desktop, developer, and security improvements. &lt;a href=&quot;https://kde.org/announcements/plasma/6/6.7.4/&quot;&gt;KDE Plasma 6.7.4&lt;/a&gt; delivered targeted desktop fixes while &lt;a href=&quot;https://kde.org/announcements/gear/26.08.0/&quot;&gt;KDE Gear 26.08.0&lt;/a&gt; and &lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.29.0/&quot;&gt;KDE Frameworks 6.29.0&lt;/a&gt; advanced the KDE application and library stacks, and &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-shell&quot;&gt;GNOME Shell 50.4&lt;/a&gt; polished the GNOME desktop. &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; settled into its 26.2 series, the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; progressed through point releases to 7.2.0 with extensive CVE coverage, &lt;a href=&quot;https://www.mozilla.org/firefox/&quot;&gt;Firefox&lt;/a&gt; 154.0 shipped more than 40 security fixes, and &lt;a href=&quot;https://gstreamer.freedesktop.org/&quot;&gt;GStreamer&lt;/a&gt; 1.28.6 brought playback and security fixes across the multimedia stack. Developer tools saw significant updates: &lt;a href=&quot;https://www.gnu.org/software/emacs/&quot;&gt;Emacs&lt;/a&gt; jumped to 31.1, &lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; advanced to 11.1.0 with UFS emulation and RISC-V extensions, &lt;a href=&quot;https://gcc.gnu.org/&quot;&gt;GCC&lt;/a&gt; reached 16.2, &lt;a href=&quot;https://www.qt.io/product/qt6&quot;&gt;Qt 6&lt;/a&gt; advanced to 6.11.2, &lt;a href=&quot;https://www.openssh.com/&quot;&gt;OpenSSH&lt;/a&gt; 10.5p1 fixed critical agent forwarding issues, and &lt;a href=&quot;https://www.vim.org/&quot;&gt;vim&lt;/a&gt; addressed eight security vulnerabilities. &lt;a href=&quot;https://www.freerdp.com/&quot;&gt;FreeRDP&lt;/a&gt; 3.31.0 patched more than 20 CVEs while improving YUV decoding performance, &lt;a href=&quot;https://w1.fi/&quot;&gt;wpa_supplicant&lt;/a&gt; 2.12 brought Wi-Fi 7 support, and &lt;a href=&quot;https://chronyproject.org/&quot;&gt;chrony&lt;/a&gt; 4.9 added NTP-over-PTP and new stratum-bounding directives. Security remained a dominant theme, with critical patches in &lt;a href=&quot;https://www.libssh2.org/&quot;&gt;libssh2&lt;/a&gt;, &lt;a href=&quot;https://www.samba.org/&quot;&gt;Samba&lt;/a&gt;, &lt;a href=&quot;https://www.postgresql.org/&quot;&gt;postgresql18&lt;/a&gt;, &lt;a href=&quot;https://www.openssl.org/&quot;&gt;openssl&lt;/a&gt;, &lt;a href=&quot;https://libexpat.github.io/&quot;&gt;expat&lt;/a&gt;, &lt;a href=&quot;https://webkitgtk.org/&quot;&gt;webkitgtk&lt;/a&gt;, &lt;a href=&quot;https://www.openexr.com/&quot;&gt;openexr&lt;/a&gt;, &lt;a href=&quot;https://flatpak.org/&quot;&gt;flatpak&lt;/a&gt;, &lt;a href=&quot;https://cryptography.io/&quot;&gt;python-cryptography&lt;/a&gt;, &lt;a href=&quot;https://openvpn.net/&quot;&gt;openvpn&lt;/a&gt;, &lt;a href=&quot;https://wiki.gnome.org/Projects/GDM&quot;&gt;gdm&lt;/a&gt;, &lt;a href=&quot;https://udisks.freedesktop.org/&quot;&gt;udisks2&lt;/a&gt;, &lt;a href=&quot;https://github.com/opensvc/multipath-tools&quot;&gt;multipath-tools&lt;/a&gt;, and &lt;a href=&quot;https://www.php.net/&quot;&gt;php8&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;slowroll-arrivals&quot;&gt;Slowroll Arrivals&lt;/h2&gt;
&lt;p&gt;Please note that these updates also apply to &lt;a href=&quot;https://en.opensuse.org/openSUSE:Slowroll&quot;&gt;Slowroll&lt;/a&gt; and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;contributing-to-opensuse-tumbleweed&quot;&gt;Contributing to openSUSE Tumbleweed&lt;/h2&gt;
&lt;p&gt;Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list.
For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list &lt;/a&gt;. The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.&lt;/p&gt;

&lt;p&gt;Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, Tumbleweed, KDE, Plasma, GNOME, GStreamer, Mesa, Vulkan, OpenSSH, harfbuzz, Samba, nano, openvpn, GCC, libssh2, CVE, kernel, Firefox, vim, gzip, dracut, python-cryptography, Frameworks, Gear, Qt, postgresql, flatpak, webkitgtk, expat, OpenEXR, busybox, emacs, QEMU, FreeRDP, chrony, wpa_supplicant, openssl, libjpeg-turbo, multipath-tools, java-openjdk&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/01/mobile-hackday-8/</guid>
      <title>Mobile Linux Hackday #8: Record Turnout in SUSE&apos;s New Prague Office</title>
      <pubDate>Tue, 01 Sep 2026 10:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/01/mobile-hackday-8/</link>
      <author>admin@opensuse.org (Lubos Kocman)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/mobile-hackday.jpg" length="282402" type="image/jpeg" />
      <description>On Friday, August 28th, the SUSE Prague office hosted Mobile Linux Hackday #8. This event marked two major milestones: we hit a new record attendance for Prague, and attendees got their first hands-on experience in our freshly renovated Karlín space. If you missed the event, here is a recap of...</description>
      <content:encoded>&lt;p&gt;On Friday, August 28th, the SUSE Prague office hosted &lt;strong&gt;Mobile Linux Hackday #8&lt;/strong&gt;. This event marked two major milestones: we hit a new record attendance for Prague, and attendees got their first hands-on experience in our freshly renovated Karlín space.&lt;/p&gt;

&lt;p&gt;If you missed the event, here is a recap of the community highlights, kernel hacking sessions, and key takeaways from the day.&lt;/p&gt;

&lt;h3 id=&quot;renovated-prague-office-great-coffee-and-full-capacity&quot;&gt;Renovated Prague Office: Great Coffee and Full Capacity&lt;/h3&gt;

&lt;p&gt;Returning attendees and newcomers were welcomed into our newly reconstructed Karlín office. The expanded social hub in the kitchen was an immediate favorite, providing comfortable sofas for breaks and technical discussions.&lt;/p&gt;

&lt;p&gt;The highlight for many was the upgraded coffee station. Attendees put the manual lever espresso machine and external grinder through its paces, while a fully automatic machine served as a reliable backup.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Community Growth and Room Merging&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;With a peak crowd of 20 to 25 attendees, we set a new record for a Prague Mobile Linux Hackday and put our workspace flexibility to the test. The numbers were strong, especially when compared with earlier community gatherings such as the first Pilsen Mobile Hackday or the combined Budweis and SUSE Labs events, which had historically drawn larger crowds and set the benchmark for what a really “prime” event could look like. This turnout is a clear sign that our outreach and event marketing are gaining traction, and it is encouraging to see the community respond so strongly.&lt;/p&gt;

&lt;p&gt;We originally booked the &lt;strong&gt;Mint&lt;/strong&gt; meeting room, but as more people arrived, we pulled open the sliding partition panel and took over the adjoining &lt;strong&gt;Avocado&lt;/strong&gt; room as well. Even after expanding into a double-sized room, we still had to borrow almost every chair from the surrounding area to seat everyone. Moving forward, we will definitely make sure we have plenty of extra seating ready for future gatherings.&lt;/p&gt;

&lt;h3 id=&quot;flexible-formats-and-the-kitchen-talk-dilemma&quot;&gt;Flexible Formats and the Kitchen Talk Dilemma&lt;/h3&gt;

&lt;p&gt;Unlike previous editions with rigid agendas, this Hackday was a bit more freestyle. Attendees naturally split into smaller working groups, alongside a remote session with David, who joined us from Switzerland and kindly made time for a deeper discussion on a more established topic.&lt;/p&gt;

&lt;p&gt;This casual approach sparked fantastic side discussions, but it also highlighted a fun new challenge: the renovated kitchen space was so inviting that some attendees spent most of the day there, drifting into long hallway-track conversations. A big kudos to the facilities team for creating such a comfortable, social space that people simply did not want to leave!&lt;/p&gt;

&lt;p&gt;While informal networking is a core part of community building, balancing casual chatter with structured technical sessions is something we plan to fine-tune for future events. We are actively looking into light-touch scheduling methods to help guide attendees smoothly between casual kitchen banter and hands-on coding.&lt;/p&gt;

&lt;h3 id=&quot;outreach-insights-where-the-czech-linux-community-gathers&quot;&gt;Outreach Insights: Where the Czech Linux Community Gathers&lt;/h3&gt;

&lt;p&gt;During the event, we surveyed attendees on how they discovered the event to help refine our future community outreach.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Root.cz:&lt;/strong&gt; The primary source for most attendees.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;AbcLinuxu.cz:&lt;/strong&gt; Brought in several key community members.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Word of Mouth:&lt;/strong&gt; Direct recommendations from friends and colleagues played a major role in bringing in fresh faces.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;LinuxExpres.cz:&lt;/strong&gt; This was the first time we included it in our promotion mix. It did not produce a noticeable spike in attendance, but it was still a useful extra step in widening our reach beyond the usual community channels.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Mastodon:&lt;/strong&gt; The main communication channel for the community, and many attendees learned about the event through the &lt;a href=&quot;https://mastodonczech.cz/@mobilni_linux_cs_sk&quot;&gt;Mobile Linux CZ/SK Mastodon account&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every newcomer made sure to leave with plenty of openSUSE swag to mark their first event.&lt;/p&gt;

&lt;h3 id=&quot;technical-highlights-ai-tools-bengalos-and-snapdragon-hacking&quot;&gt;Technical Highlights: AI Tools, BengalOS, and Snapdragon Hacking&lt;/h3&gt;

&lt;p&gt;Led by &lt;strong&gt;Petr Hodina&lt;/strong&gt;, Mesa 3D GPU driver developer and community maintainer, the technical tracks covered several cutting-edge topics across mobile ecosystem development.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key Topics Covered:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;LLMs and Developer AI:&lt;/strong&gt; Practical applications of Large Language Models to streamline daily developer workflows.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;BengalOS Architecture:&lt;/strong&gt; An overview of BengalOS, including instructions on how to build and test the OS on hardware.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Qualcomm Snapdragon 845 Kernel Hacking:&lt;/strong&gt; Hands-on kernel debugging and testing focused on sdm845-based devices, including the OnePlus 6/6T, Xiaomi Poco F1, and Shift 6MQ.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;join-the-next-mobile-linux-hackday&quot;&gt;Join the Next Mobile Linux Hackday&lt;/h3&gt;

&lt;p&gt;A huge thank you to &lt;strong&gt;Petr Hodina&lt;/strong&gt; for driving the sessions, keeping the momentum high, and running an outstanding workshop. As a small token of our appreciation for his dedication to the community, Petr was awarded a giant plush openSUSE chameleon!&lt;/p&gt;

&lt;p&gt;Photos from the event, along with broader shots of the refreshed SUSE Prague office, are available in our shared &lt;a href=&quot;https://photos.app.goo.gl/8hBodWuXZsuQhfpTA&quot;&gt;Google Photos album&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;To stay updated on upcoming hackdays, follow the &lt;strong&gt;Mobile Linux CZ/SK&lt;/strong&gt; community on Mastodon, or keep an eye out on local tech portals like Root.cz. See you at Hackday #9!&lt;/p&gt;
</content:encoded>
    </item>

  </channel>
</rss>

