<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>openSUSE News</title>
    <link>https://news.opensuse.org</link>
    <description>Latest news from the openSUSE Project</description>
    <atom:link href="https://news.opensuse.org/feed.xml" rel="self" type="application/rss+xml"/>

    <item>
      <guid>https://news.opensuse.org/2026/10/04/ZUPT/</guid>
      <title>Post-Quantum Backups Land in openSUSE Factory with ZUPT</title>
      <pubDate>Sun, 04 Oct 2026 00:02:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/10/04/ZUPT/</link>
      <author>admin@opensuse.org (Alessandro de Oliveira Faria)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/04/logo-libzupt.jpg" length="23395" type="image/jpeg" />
      <description>ZUPT, an open source backup, compression, and data protection utility, has officially been accepted into openSUSE Factory, bringing a new security-focused backup option to the openSUSE ecosystem. The project combines backup creation, compression, integrity verification, and encryption in a single tool, allowing users to package files and directories into compact...</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;ZUPT&lt;/strong&gt;, an open source backup, compression, and data protection utility, has officially been accepted into &lt;a href=&quot;https://software.opensuse.org/package/zupt&quot;&gt;openSUSE Factory&lt;/a&gt;, bringing a new security-focused backup option to the openSUSE ecosystem. The project combines backup creation, compression, integrity verification, and encryption in a single tool, allowing users to package files and directories into compact archives that are easier to store, transfer, verify, and restore.&lt;/p&gt;

&lt;p&gt;Security is one of ZUPT’s main technical highlights. In addition to &lt;strong&gt;AES-256-based encryption&lt;/strong&gt;, the tool supports a hybrid cryptographic scheme based on &lt;strong&gt;ML-KEM-768 + X25519&lt;/strong&gt;. This approach combines established public-key cryptography with a post-quantum key encapsulation mechanism designed to provide stronger protection against future cryptographic threats. For users handling long-lived or sensitive backups, this adds an additional layer of protection against so-called “harvest now, decrypt later” scenarios, in which encrypted data collected today could potentially be targeted by more powerful computing systems in the future. ZUPT also includes file integrity verification features to help detect corruption, modification, or unexpected changes in archived data.&lt;/p&gt;

&lt;p&gt;ZUPT was also designed with performance in mind. The application uses &lt;strong&gt;multithreaded processing&lt;/strong&gt; to take advantage of multiple CPU cores during backup, compression, and restore operations, reducing processing time on modern systems. It includes its own compression mechanism as well as commands for testing and validating archive contents. With its acceptance into &lt;strong&gt;openSUSE Factory&lt;/strong&gt;, ZUPT becomes an officially integrated solution for users looking for a combination of &lt;strong&gt;backup, compression, integrity verification, encryption, and post-quantum data protection&lt;/strong&gt; within the openSUSE ecosystem.&lt;/p&gt;

&lt;p&gt;For more information, go to &lt;a href=&quot;https://build.opensuse.org/package/show/openSUSE%3AFactory/zupt&quot;&gt;ZUPT&lt;/a&gt;!&lt;/p&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/10/01/tw-monthly-update-september/</guid>
      <title>Tumbleweed Monthly Update - September 2026</title>
      <pubDate>Thu, 01 Oct 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/10/01/tw-monthly-update-september/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/tw.png" length="12041" type="image/png" />
      <description>There were several software package updates for openSUSE Tumbleweed during the month of September and with openSUSE.Asia Summit 2026 about to begin, we are bringing the monthly review to you early. September delivered a stacked month of snapshots across the desktop, developer tooling, and security surface. KDE Plasma 6.7.5 landed...</description>
      <content:encoded>&lt;p&gt;There were several software package updates for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; during the month of September and with &lt;a href=&quot;https://events.opensuse.org/conferences/oSAS26&quot;&gt;openSUSE.Asia Summit 2026&lt;/a&gt; about to begin, we are bringing the monthly review to you early.&lt;/p&gt;

&lt;p&gt;September delivered a stacked month of snapshots across the desktop, developer tooling, and security surface. &lt;a href=&quot;https://kde.org/announcements/plasma/6/6.7.5/&quot;&gt;KDE Plasma 6.7.5&lt;/a&gt; landed with fixes for &lt;a href=&quot;https://invent.kde.org/plasma/kwin&quot;&gt;KWin&lt;/a&gt; display management and taskbar refinements, while &lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.30.0/&quot;&gt;KDE Frameworks 6.30.0&lt;/a&gt; and &lt;a href=&quot;https://kde.org/announcements/gear/26.08.1/&quot;&gt;KDE Gear 26.08.1&lt;/a&gt; delivered new features and bugfixes across the KDE ecosystem. &lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; jumped to 2.44 with Transparent Huge Pages tunables and optimized math functions, and &lt;a href=&quot;https://llvm.org/&quot;&gt;LLVM&lt;/a&gt; 23.1.1 arrived with important bugfixes. &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; progressed from 26.2.2 to 26.2.3 and the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; advanced through 7.2.5 to 7.2.7 with a sustained focus on security. Later in the month the GNOME desktop picked up 50.5 across &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-shell&quot;&gt;gnome-shell&lt;/a&gt; and &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter&lt;/a&gt;, &lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; advanced to 3.2.6, &lt;a href=&quot;https://www.gnu.org/software/coreutils/&quot;&gt;coreutils&lt;/a&gt; jumped to 9.12, and &lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; arrived at 3.5.1 after a sweeping audit of its path handling and daemon protocol. &lt;a href=&quot;https://curl.se/&quot;&gt;curl&lt;/a&gt; addressed seven CVEs, &lt;a href=&quot;https://www.pcre.org/&quot;&gt;pcre2&lt;/a&gt; patched six security issues, and &lt;a href=&quot;https://www.ffmpeg.org/&quot;&gt;ffmpeg&lt;/a&gt; rolled up more than 20 CVEs in one pass.&lt;/p&gt;

&lt;p&gt;As always, be sure to roll back using &lt;a href=&quot;https://github.com/openSUSE/snapper&quot;&gt;snapper&lt;/a&gt; if any issues arise.&lt;/p&gt;

&lt;p&gt;For more details on the change logs for the month, visit the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;new-features-and-enhancements&quot;&gt;New Features and Enhancements&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/plasma/6/6.7.5/&quot;&gt;KDE Plasma 6.7.5&lt;/a&gt;&lt;/strong&gt;: The fifth bugfix release of the Plasma 6.7 series brings targeted refinements across the desktop. &lt;a href=&quot;https://invent.kde.org/plasma/kwin&quot;&gt;KWin&lt;/a&gt; fixes the global removal timer timeout for unplugged outputs, and &lt;a href=&quot;https://invent.kde.org/plasma/discover&quot;&gt;Discover&lt;/a&gt; resolves update stalling when fwupd is unavailable and a regression where updates were mistaken for needing a reboot. &lt;a href=&quot;https://apps.kde.org/spectacle/&quot;&gt;Spectacle&lt;/a&gt; fixes a crash during window-under-pointer detection and annotation submenu overflow, while the taskbar applet corrects right-to-left layout rendering and prevents duplicate favorites launching on Space.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.30.0/&quot;&gt;KDE Frameworks 6.30.0&lt;/a&gt;&lt;/strong&gt;: A feature release of the KDE component libraries that arrives with refinements across &lt;a href=&quot;https://invent.kde.org/frameworks/kio&quot;&gt;KIO&lt;/a&gt;, &lt;a href=&quot;https://invent.kde.org/frameworks/kirigami&quot;&gt;Kirigami&lt;/a&gt;, and &lt;a href=&quot;https://invent.kde.org/frameworks/ktexteditor&quot;&gt;KTextEditor&lt;/a&gt;. &lt;a href=&quot;https://invent.kde.org/frameworks/kio&quot;&gt;KIO&lt;/a&gt; fixes FTP command case consistency, corrects folder size reporting to include filesystem overhead, and lets a folder with the setgid bit propagate its group to copied files. &lt;a href=&quot;https://invent.kde.org/frameworks/ktexteditor&quot;&gt;KTextEditor&lt;/a&gt; gains vi-mode filename registers and fixes block operations with tabs. &lt;a href=&quot;https://community.kde.org/Baloo&quot;&gt;Baloo&lt;/a&gt; now excludes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.snapshots&lt;/code&gt; folders from indexing, &lt;a href=&quot;https://invent.kde.org/frameworks/kcalendarcore&quot;&gt;KCalendarCore&lt;/a&gt; adds &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;recurrenceDescription&lt;/code&gt; and translated enum names, and &lt;a href=&quot;https://invent.kde.org/frameworks/kcodecs&quot;&gt;KCodecs&lt;/a&gt; improves encoding detection with better confidence scoring. &lt;a href=&quot;https://invent.kde.org/frameworks/syntax-highlighting&quot;&gt;Syntax Highlighting&lt;/a&gt; adds DotEnv, KDL, and Just language support, and &lt;a href=&quot;https://invent.kde.org/frameworks/kguiaddons&quot;&gt;KGuiAddons&lt;/a&gt; adds a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;geo:&lt;/code&gt; URI handler for Cartes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/gear/26.08.1/&quot;&gt;KDE Gear 26.08.1&lt;/a&gt;&lt;/strong&gt;: The first bugfix release of the 26.08 series arrives with targeted fixes across the KDE application collection. &lt;a href=&quot;https://apps.kde.org/dolphin/&quot;&gt;Dolphin&lt;/a&gt; fixes the active split pane not being set correctly, corrects default zoom level calculations based on preview state, and prevents zero icon sizes in item layouts. &lt;a href=&quot;https://apps.kde.org/okular/&quot;&gt;Okular&lt;/a&gt; fixes a crash on broken DVI files, addresses dangling form field pointers after saving, and backports a Synctex security fix. &lt;a href=&quot;https://apps.kde.org/konsole/&quot;&gt;Konsole&lt;/a&gt; corrects OSC22 mouse cursor shapes for splits and fixes focus shortcut issues in ViewSplitter. &lt;a href=&quot;https://invent.kde.org/pim/kitinerary&quot;&gt;Kitinerary&lt;/a&gt; adds parsers for Air Canada and Lufthansa PDF itineraries and optimizes Wikidata train station queries. &lt;a href=&quot;https://apps.kde.org/korganizer/&quot;&gt;KOrganizer&lt;/a&gt; fixes search dialog functionality after editing a result.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-shell&quot;&gt;GNOME Shell&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter&lt;/a&gt; 50.5&lt;/strong&gt;: The GNOME desktop received quality-of-life fixes that clean up day-to-day use. The unlock dialog handles keyboard navigation correctly, the screen will no longer unlock once a screen time limit has been reached, and toggling the wireless switch no longer blocks. On the compositor side, &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter&lt;/a&gt; fixes a hang on external monitor hotplug, stops multiple monitors from all being reported as primary, corrects desaturated SDR content in HDR mode, and adds per-view control over the software cursor overlay. &lt;a href=&quot;https://gitlab.gnome.org/GNOME/libadwaita&quot;&gt;libadwaita&lt;/a&gt; 1.9.4 arrived alongside with annotation and idle-callback fixes in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AdwAnimation&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AdwActionRow&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AdwTabBar&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AdwTabGrid&lt;/code&gt;, and &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-maps&quot;&gt;GNOME Maps&lt;/a&gt; 50.5 fixed the secondary icons shown for recent and favorite places in initial search results.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; 3.2.6&lt;/strong&gt;: The image editor continued its 3.2 series with a large batch of fixes and some preparation for a future GTK 4 port. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Heal&lt;/code&gt; tool no longer leaves a dark smudge at crop boundaries, the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Crop&lt;/code&gt; tool keeps vector layers in place, and the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Color Picker&lt;/code&gt; correctly honours the Sample Merged option on single-layer images. Layer groups with non-destructive filters no longer get an unwanted pass-through reduction, plug-in pipes and process watching are better managed on exit so fewer warnings appear when closing GIMP, and clipboard brush and pattern sizes are raised to 8192 on AArch64. The XCF format is bumped to version 26 to record path visibility locks and channel filters.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/shotwell&quot;&gt;Shotwell&lt;/a&gt; 33.0&lt;/strong&gt;: The GNOME photo manager completed its port to GTK 4, moving to version 33 after the long-running 0.32 series. Printing was reworked, the publishing targets gained a “peek password” icon and now use a simple localhost web server instead of a dedicated authentication helper, and toast notifications replace many of the simpler dialogs. Face detection and recognition see a long list of fixes around names, highlighting and random matching, and the viewer mode now shows system information and can be opened for arbitrary URIs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; 2.44&lt;/strong&gt;: A major version bump that brings system-wide tunables via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/etc/tunables.conf&lt;/code&gt; and a new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;glibc.elf.thp&lt;/code&gt; tunable that maps read-only segments with &lt;a href=&quot;https://www.kernel.org/doc/Documentation/admin-guide/mm/transhuge.rst&quot;&gt;Transparent Huge Pages&lt;/a&gt; when the kernel has not disabled THP. The malloc page size is now capped to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;MAX_THP_PAGESIZE&lt;/code&gt;, and the CORE-MATH project contributions bring additional optimized and correctly rounded math functions. On AArch64, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;exp&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sin&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cas&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sinh&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cosh&lt;/code&gt;, and other special cases are vectorized for SVE and AdvSIMD, while RISC-V gains vector extension optimized variants of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;memcmp&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;memcpy&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;strcmp&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;strlen&lt;/code&gt;, and more. The release also carries two security fixes for stack-based buffer clashing during tilde expansion in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;wordexp&lt;/code&gt; (&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6791.html&quot;&gt;CVE-2026-6791&lt;/a&gt;) and an invalid &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;free()&lt;/code&gt; call with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;WRDE_APPEND&lt;/code&gt; (&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6368.html&quot;&gt;CVE-2026-6368&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.libreoffice.org/&quot;&gt;LibreOffice&lt;/a&gt; 26.8.0.3&lt;/strong&gt;: A major version bump from the 26.2 series that brings updated bundled &lt;a href=&quot;https://pdfium.googlesource.com/pdfium/&quot;&gt;pdfium&lt;/a&gt; to 7681 and &lt;a href=&quot;https://skia.org/&quot;&gt;Skia&lt;/a&gt; to m147 as required by the new download configuration. The release drops Qt 5 support in Tumbleweed in favor of Qt 6, aligning with the broader KDE ecosystem move away from Qt 5. Users of the office suite will see improved compatibility and performance across Writer, Calc, and Impress.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://llvm.org/&quot;&gt;LLVM&lt;/a&gt; 23.1.1&lt;/strong&gt;: A bugfix release for the LLVM 23.1.0 series that addresses issues found since the initial release. The update is API and ABI compatible with 23.1.0, making it a safe upgrade for developers who depend on the &lt;a href=&quot;https://clang.llvm.org/&quot;&gt;Clang&lt;/a&gt; compiler, &lt;a href=&quot;https://llvm.org/&quot;&gt;LLVM&lt;/a&gt; libraries, and related tooling. This is particularly relevant for users building packages that depend on the LLVM infrastructure for compilation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/harfbuzz/harfbuzz&quot;&gt;harfbuzz&lt;/a&gt; 14.4.0 &amp;amp; 14.5.0&lt;/strong&gt;: The text shaping engine that underpins rendering in browsers, desktop environments, and document editors received important improvements. In 14.4.0, glyph positions and extents now saturate instead of overflowing, Arabic Windows-1256 fallback shaping is enabled on all platforms, the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;COLR&lt;/code&gt; sweep gradient truncation and unbounded memory use are fixed, and subsetting is faster especially for large &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GSUB&lt;/code&gt;/&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GPOS&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CFF&lt;/code&gt; tables. Version 14.5.0 then updated the Unicode data to 18.0, adding script values for Jurchen, Proto-Cuneiform and Seal along with the matching shaping support, and introduced rendering work budgets shared across the raster, vector, GPU and Cairo renderers so nested outline work stays bounded. The DirectWrite backend no longer uses the C++ runtime, and the HarfRust integration shaper sees various improvements.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/containers/bubblewrap&quot;&gt;bubblewrap&lt;/a&gt; 0.12.0&lt;/strong&gt;: The Linux sandboxing tool removes support for building a setuid binary, as all modern distributions now support unprivileged user namespaces. A security fix resolves a symlink issue where a file or directory creation during sandbox setup could follow parent symlinks out of the sandbox. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--not-a-security-boundary&lt;/code&gt; flag is added for cases where some sandbox setup failures should not be fatal.&lt;/p&gt;

&lt;h2 id=&quot;key-package-updates&quot;&gt;Key Package Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 7.2.2 through 7.2.7&lt;/strong&gt;: The kernel progressed through six point releases during September with a sustained focus on security and stability. Version 7.2.2 carried fixes for ptp vmclock read-only mapping vulnerability and GSO state stripping from fragments before forwarding . Version 7.2.3 addressed an extensive list of USB fixes including use-after-free in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;usbdev_release()&lt;/code&gt;, ALSA USB audio out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;snd_usbmidi_novation_output()&lt;/code&gt;, and KVM SEV improvements for SNP guests. Version 7.2.4 added fixes for dm-pcache use-after-free, wifi driver memory leaks across mt76, iwlwifi, and brcmfmac, and I3C device master use-after-free in the unregister path. Version 7.2.5 was dominated by backports, among them a large sweep of NFC fixes bounding device-reported lengths, rejecting undersized LLCP PDUs, and fixing an out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nci_target_active&lt;/code&gt;, alongside futex priority-inheritance races and io_uring iovec leaks. Version 7.2.6 brought an exceptionally long list of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nfsd&lt;/code&gt; hardening patches covering use-after-free in the fcache disposal path, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;layout_fence_worker&lt;/code&gt; double references, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nfsd_file&lt;/code&gt; leaks on inter-server COPY, plus a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;clocksource&lt;/code&gt; IRQ leak fix and an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;iomap&lt;/code&gt; integrity-payload fix. Version 7.2.7 wrapped up the month with a broad set covering &lt;a href=&quot;https://btrfs.readthedocs.io/&quot;&gt;Btrfs&lt;/a&gt; write-protection during data writeback, AppArmor credential use-after-free and a null-termination out-of-bounds write, mm and MGLRU correctness, and a large group of tracing use-after-free and crash fixes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; 26.2.2 &amp;amp; 26.2.3&lt;/strong&gt;: Two bugfix releases landed on the 26.2 branch. Alongside the usual stream of regression fixes, openSUSE’s build gained the rocket Gallium driver for Rockchip NPUs on aarch64, and the new Mesa-teflon-delegate subpackage ships a TensorFlow Lite delegate for NPUs. The changelogs point to the &lt;a href=&quot;https://docs.mesa3d.org/relnotes/26.2.2.html&quot;&gt;Mesa 26.2.2&lt;/a&gt; and &lt;a href=&quot;https://docs.mesa3d.org/relnotes/26.2.3.html&quot;&gt;Mesa 26.2.3&lt;/a&gt; release notes for details, and the LLVM 23 build fix that unblocked both releases came along with them. Users on AMD, Intel, or Qualcomm hardware who experienced rendering issues after earlier Mesa updates should find these releases more stable.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; 3.5.1&lt;/strong&gt;: The file synchronization tool received a sweeping security overhaul. A focused audit of path handling and the daemon protocol, a companion fuzzing pass and external reports produced 33 fixes covering restricted-directory escapes in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rrsync&lt;/code&gt;, daemon module-root &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chdir&lt;/code&gt; escapes under &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;use chroot = no&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--relative&lt;/code&gt; implied-parent creation escaping the destination tree, daemon &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--filter&lt;/code&gt; merge file bypasses, and a range of symlink races on the sender and receiver sides. The release also fixes an unauthenticated TLS connection in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rsync-ssl&lt;/code&gt; and a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hosts deny&lt;/code&gt; rule that failed open when a configured hostname could not be resolved. A 3.5.1 follow-up in the same snapshot fixed several path-handling regressions from 3.5.0, restored access to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/dev/stdin&lt;/code&gt; and friends inside user namespaces, tightened partial-directory validation on the receiver, added support for internationalised domain names, and bumped the protocol number to 33.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/pub/linux/utils/util-linux/&quot;&gt;util-linux&lt;/a&gt; 2.42.3&lt;/strong&gt;: The Linux utility suite received a security-focused point release. Four &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mount(8)&lt;/code&gt; and namespace-related CVEs are fixed, including post-mount hooks running after an external mount helper fails and a time-of-check/time-of-use race on the source path in restricted SUID mode. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;wall&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;write&lt;/code&gt; gained an additional fix for terminal escape sequence injection through the banner hostname, complementing the earlier CVE-2024-28085 work. Alongside the security work, the release fixes an out-of-bounds read of the ISO9660 root directory record in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libblkid&lt;/code&gt;, an out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;get_line()&lt;/code&gt; on invalid multibyte input, and a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg&lt;/code&gt; out-of-bounds access on a trailing tab.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://pipewire.freedesktop.org/&quot;&gt;PipeWire&lt;/a&gt; 1.6.9&lt;/strong&gt;: The sound and video server shipped a bugfix release that is API and ABI compatible with the rest of the 1.6 series. RAOP (AirPlay) support sees the most work, with encryption fixed for OpenSSL 3 and above, truncated audio and metadata update problems resolved, and RAOP over TCP fixed. The resampler cutoff frequencies were tweaked to preserve more high frequencies when upsampling, potential overflows in client node buffer checks were fixed, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pw-cat&lt;/code&gt; now handles EOF correctly for encoded files while &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pw-record&lt;/code&gt; supports A-law.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://poppler.freedesktop.org/&quot;&gt;poppler&lt;/a&gt; 26.09.0&lt;/strong&gt;: The PDF rendering library jumped two minor releases, picking up 26.08.0 on the way. Fonts are now subset when saving changes in annotations and forms through fontconfig, which required making harfbuzz a build dependency. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pdftotext&lt;/code&gt; gains a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-urls&lt;/code&gt; option to print link URLs next to their text, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pdftohtml&lt;/code&gt; no longer crashes when using data URLs and skips tiling patterns earlier for speed, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pdfimages&lt;/code&gt; gains &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;min-height&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;min-width&lt;/code&gt; options. The core also stops infinite looping on a wrong NSS password and fixes crashes on malformed documents.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://bluez.org/&quot;&gt;BlueZ&lt;/a&gt; 5.87&lt;/strong&gt;: The Bluetooth stack jumped five releases from 5.82, bringing LE Audio and profile work along with it. Version 5.83 added AVDTP TX timestamps and fixed handling of BAP PAC removal, broadcast receiver SIDs, and HID service records; 5.84 added unicast endpoint reconfiguration, encrypted broadcast sources and HFP Caller Line Identification; 5.85 added HFP call answer and simple 3-way call support and corrected battery charge level display; 5.86 added the Telephony, Ranging, GMAP and TMAP profiles and fixed the G.722 16 kHz codec ID; and 5.87 resolved a long list of BAP, BASS, PBAP, MCP, AVRCP and GATT database issues.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.com/cryptsetup/cryptsetup&quot;&gt;cryptsetup&lt;/a&gt; 2.8.8&lt;/strong&gt;: The disk encryption tool received a feature and hardening release. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;integritysetup&lt;/code&gt; gained support for keyed discards via a new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--allow-discards-keyed&lt;/code&gt; option, which permanently upgrades the superblock so that an integrity device in standalone mode with a keyed integrity algorithm can no longer have part of itself wiped with a discard pattern. The library also closes a time-of-check/time-of-use issue in LUKS header restore by opening the device only once, which affects both LUKS1 and LUKS2, hardens BITLK metadata validation against a wrong key buffer size and a deliberate infinite loop, and fixes a possible integer overflow in the anti-forensic data size calculation on 32-bit systems.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/gzip/&quot;&gt;gzip&lt;/a&gt; 1.15&lt;/strong&gt;: The ubiquitous compression utility reached a new major version, landing fixes for two earlier security issues and a batch of long-standing bugs. A buffer overflow when decompressing an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.lzh&lt;/code&gt; file after a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.Z&lt;/code&gt; file is fixed, as is a use of uninitialized memory on some malformed inputs. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gzip -d&lt;/code&gt; no longer rejects PKZIP signatures and local headers that legitimately appear in well-formed streamed zip files, diagnostics now quote file names containing unusual characters, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gzip --synchronous&lt;/code&gt; works again on platforms with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;O_PATH&lt;/code&gt;. Behaviorally, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gzip&lt;/code&gt; follows the locale from the environment instead of insisting on the C locale, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-l&lt;/code&gt; reports &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-Inf%&lt;/code&gt; rather than &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0.0%&lt;/code&gt; for an empty file.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.freedesktop.org/libinput/libinput&quot;&gt;libinput&lt;/a&gt; 1.32&lt;/strong&gt;: The input handling library arrived with input-device improvements. Circular scrolling now works on circular touchpads such as the Panasonic CF-SV1, dragging on a touchpad automatically enables a drag lock when a finger nears the edge, and disable-while-typing no longer cancels an interaction already in progress. Tablets can now map the physical eraser button to any button, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libinput record&lt;/code&gt; accepts a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--no-events&lt;/code&gt; flag.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/lightdm/lightdm&quot;&gt;lightdm&lt;/a&gt; 1.33.1&lt;/strong&gt;: The display manager received a bugfix release with a notable feature. A Qt6 client library is now shipped alongside the Qt5 one, and the release fixes user switching after logind dropped the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CanMultiSession&lt;/code&gt; property. Wayland sessions are now allowed on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;seat0&lt;/code&gt; without VTs, PAM modules that change the home directory are handled correctly, the VNC server command is honored with IPv6 tried first for the bind, a local X server is not reused when the hostname has changed, and memory leaks in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;session_child_run&lt;/code&gt; are plugged.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.freedesktop.org/wiki/Distributions/AppStream/&quot;&gt;AppStream&lt;/a&gt; 1.2.0&lt;/strong&gt;: The software metadata standard reached a new major version and marks the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libappstream-compose&lt;/code&gt; API as stable. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;appstream-compose&lt;/code&gt; gains an out-of-process media worker with a basic Landlock-based sandbox, switches image processing from GdkPixbuf to VIPS, and makes JPEG XL the default output format. New &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;heading&amp;gt;&lt;/code&gt; markup is supported in AppStream descriptions, and the news tools gain inline Markdown support along with header handling across the XML, YAML and Markdown conversions.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://tukaani.org/xz/&quot;&gt;xz&lt;/a&gt; 5.8.4&lt;/strong&gt;: The compression library received a bugfix release that includes a security fix. An invalid memory access in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lzma_alone_decoder()&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lzma_lzip_decoder()&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lzma_auto_decoder()&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lzma_microlzma_decoder()&lt;/code&gt; after a failed allocation is followed by decoder reinitialization is fixed, along with two use-after-free bugs in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xz&lt;/code&gt; itself via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--files&lt;/code&gt;/&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--files0&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--verbose&lt;/code&gt; with redirected stderr. Landlock ABI 9 support is added, a performance issue and theoretical integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lzma_index_cat()&lt;/code&gt; are fixed, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xz --list&lt;/code&gt; no longer overflows its totals.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.virtualbox.org/&quot;&gt;VirtualBox&lt;/a&gt; 7.2.18&lt;/strong&gt;: The VirtualBox hypervisor received a bugfix release. Data corruption in VDI differencing images after writing full blocks of zeroes and reopening the image is fixed, a VM process crash on Linux hosts with 3D acceleration enabled is resolved, and the shared clipboard no longer strips the first character from a file name located directly in a filesystem root. Linux 7.3-rc support is added.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gnupg.org/software/libgcrypt/&quot;&gt;libgcrypt&lt;/a&gt; 1.12.4&lt;/strong&gt;: The GnuPG cryptographic library received a follow-up point release. RSA PSS handling of very large salt lengths is fixed, the length of hashed input is validated for RSA PSS, and the RSA OAEP decoder validates all-zero padding for correctness. Padding in cSHAKE was corrected against NIST ACVP conformance vectors, and a build problem with some compiler versions around SM4 instructions is resolved.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gstreamer.freedesktop.org/&quot;&gt;GStreamer&lt;/a&gt; 1.28.7&lt;/strong&gt;: A wide-ranging update across the core and plugin packages with both security and playback fixes. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;appsrc&lt;/code&gt; element fixes a regression where pushing EOS into a blocked appsrc would stall, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;glcolorconvert&lt;/code&gt; fixes compatibility with older OpenGL and GLSL versions. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mxfdemux&lt;/code&gt; element resolves keyframe detection regressions and possible artifacts after seeking, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rtpmanager&lt;/code&gt; fixes crashes on malformed RTCP SDES due to uninitialized values. The Rust-based plugins gain DoS protection in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rtpsession&lt;/code&gt; and limit the number of remote sources tracked in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rtprecv&lt;/code&gt;. Security fixes span multiple parsers including &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pnmdec&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;onnx&lt;/code&gt;, and the x264enc high bit depth support is fixed in binary packages.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.ffmpeg.org/&quot;&gt;ffmpeg&lt;/a&gt; 8&lt;/strong&gt;: A massive security update carrying more than 20 CVE patches. Fixes address out-of-bounds reads and writes across numerous demuxers and decoders including HEVC, CineForm, TIFF, Screenpresso, and DVB subtitle parsers. The RTP muxer receives bounds checks for AV1, VC-2, and ASF objects, and the MPEG muxer rejects stream counts that overflow the system header. This is an essential update for any system that processes media files, as the vulnerabilities could be triggered by crafted input.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://dracut-ng.github.io/dracut/&quot;&gt;dracut&lt;/a&gt;&lt;/strong&gt;: Received a security fix for &lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6893.html&quot;&gt;CVE-2026-6893&lt;/a&gt;, a root code execution vulnerability via DHCP options command injection. The fix sanitizes values written to network override files, gateway files, and hostname files, and strips DHCP-supplied domains to a safe charset. This is important for any system that uses dracut-generated initrd images with network boot configurations.&lt;/p&gt;

&lt;h2 id=&quot;security-updates&quot;&gt;Security Updates&lt;/h2&gt;

&lt;h3 id=&quot;rsync-351&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; 3.5.1&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53783.html&quot;&gt;CVE-2026-53783&lt;/a&gt;&lt;/strong&gt;: Fixes an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rrsync&lt;/code&gt; restricted-directory escape via a validation-versus-execution race and an unsafe option allowlist.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53784.html&quot;&gt;CVE-2026-53784&lt;/a&gt;&lt;/strong&gt;: Addresses a daemon module-root &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chdir&lt;/code&gt; escape under &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;use chroot = no&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53785.html&quot;&gt;CVE-2026-53785&lt;/a&gt;&lt;/strong&gt;: Resolves &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--relative&lt;/code&gt; implied-parent creation escaping the destination tree.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53786.html&quot;&gt;CVE-2026-53786&lt;/a&gt;&lt;/strong&gt;: Fixes a daemon &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--filter&lt;/code&gt; merge file bypassing the module filter list.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53788.html&quot;&gt;CVE-2026-53788&lt;/a&gt;&lt;/strong&gt;: Addresses the daemon name-converter accepting newline-bearing names into its line protocol.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53789.html&quot;&gt;CVE-2026-53789&lt;/a&gt;&lt;/strong&gt;: Corrects a malicious sender expanding &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--delete&lt;/code&gt; scope by reclassifying an implied parent.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53790.html&quot;&gt;CVE-2026-53790&lt;/a&gt;&lt;/strong&gt;: Fixes command and argument injection via unquoted peer- or host-controlled values.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53791.html&quot;&gt;CVE-2026-53791&lt;/a&gt;&lt;/strong&gt;: Addresses PROXY-protocol mode letting a direct client spoof the daemon’s source address.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53792.html&quot;&gt;CVE-2026-53792&lt;/a&gt;&lt;/strong&gt;: Resolves a receiver-supplied zero checksum block length driving the sender into a negative match.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53793.html&quot;&gt;CVE-2026-53793&lt;/a&gt;&lt;/strong&gt;: Fixes a chroot &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/./&lt;/code&gt; inner-module escape via a parent-component symlink.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53794.html&quot;&gt;CVE-2026-53794&lt;/a&gt;&lt;/strong&gt;: Addresses a remote peer disabling the per-allocation sanity cap via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--max-alloc=0&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53795.html&quot;&gt;CVE-2026-53795&lt;/a&gt;&lt;/strong&gt;: Corrects a receiver write escape via an absolute &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--temp-dir&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--link-dest&lt;/code&gt; disabling rename and link confinement.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53796.html&quot;&gt;CVE-2026-53796&lt;/a&gt;&lt;/strong&gt;: Fixes a non-daemon receiver destination-&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chdir&lt;/code&gt; symlink race.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53797.html&quot;&gt;CVE-2026-53797&lt;/a&gt;&lt;/strong&gt;: Addresses a sender source-tree parent-component symlink race leading to out-of-tree disclosure.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53798.html&quot;&gt;CVE-2026-53798&lt;/a&gt;&lt;/strong&gt;: Resolves the daemon name-converter mapping an unknown name to uid/gid 0 on an empty response.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53799.html&quot;&gt;CVE-2026-53799&lt;/a&gt;&lt;/strong&gt;: Fixes receiver ACL and xattr application following a symlink race for arbitrary ACL setting and local privilege escalation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53800.html&quot;&gt;CVE-2026-53800&lt;/a&gt;&lt;/strong&gt;: Addresses sender &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--remove-source-files&lt;/code&gt; unlink following a parent-component symlink race for arbitrary file deletion outside the source tree.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53801.html&quot;&gt;CVE-2026-53801&lt;/a&gt;&lt;/strong&gt;: Corrects sender and daemon directory-scan enumeration escaping the transfer root for out-of-tree disclosure.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53802.html&quot;&gt;CVE-2026-53802&lt;/a&gt;&lt;/strong&gt;: Fixes arbitrary file read and transfer shaping via symlinked operator-supplied input files.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-53803.html&quot;&gt;CVE-2026-53803&lt;/a&gt;&lt;/strong&gt;: Addresses arbitrary file write and privilege escalation via symlinked operator-supplied output paths.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70463.html&quot;&gt;CVE-2026-70463&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;auth users&lt;/code&gt; ignoring documented comma-only parsing and silently skipping a deny or read-only rule.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70462.html&quot;&gt;CVE-2026-70462&lt;/a&gt;&lt;/strong&gt;: Addresses a peer-supplied &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;MSG_IO_TIMEOUT&lt;/code&gt; defeating the client’s own I/O timeout through signed overflow and a non-positive value.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70461.html&quot;&gt;CVE-2026-70461&lt;/a&gt;&lt;/strong&gt;: Resolves a peer-driven one-byte heap out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;add_implied_include()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70460.html&quot;&gt;CVE-2026-70460&lt;/a&gt;&lt;/strong&gt;: Fixes a daemon module-root escape through a peer-supplied &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--partial-dir&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--backup-dir&lt;/code&gt; resolving via an in-module symlink.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70459.html&quot;&gt;CVE-2026-70459&lt;/a&gt;&lt;/strong&gt;: Addresses a per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70458.html&quot;&gt;CVE-2026-70458&lt;/a&gt;&lt;/strong&gt;: Corrects an out-of-bounds write from a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;FLAG_HLINKED&lt;/code&gt; file entry accepted without &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-H&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70457.html&quot;&gt;CVE-2026-70457&lt;/a&gt;&lt;/strong&gt;: Patches an attacker-chosen-offset write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;parse_size_arg()&lt;/code&gt; error formatting.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70456.html&quot;&gt;CVE-2026-70456&lt;/a&gt;&lt;/strong&gt;: Fixes a remote out-of-bounds heap write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;read_args()&lt;/code&gt; when the argument count lands exactly on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;maxargs&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70454.html&quot;&gt;CVE-2026-70454&lt;/a&gt;&lt;/strong&gt;: Addresses &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rsync-ssl&lt;/code&gt; establishing an unauthenticated TLS connection with no CA verification and no stunnel hostname binding.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70453.html&quot;&gt;CVE-2026-70453&lt;/a&gt;&lt;/strong&gt;: Resolves quadratic CPU exhaustion in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hash_search()&lt;/code&gt; from a crafted equal-weak-checksum chain.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70464.html&quot;&gt;CVE-2026-70464&lt;/a&gt;&lt;/strong&gt;: Fixes an unauthenticated pre-transfer handshake denial of service locking out an rsync daemon module.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70455.html&quot;&gt;CVE-2026-70455&lt;/a&gt;&lt;/strong&gt;: Addresses peer-controlled Zstandard worker exhaustion on an rsync daemon.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70452.html&quot;&gt;CVE-2026-70452&lt;/a&gt;&lt;/strong&gt;: Corrects &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hosts deny&lt;/code&gt; failing open when a configured hostname cannot be resolved, admitting the host it was meant to block.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-10158.html&quot;&gt;CVE-2025-10158&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds array access via a negative index.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-41035.html&quot;&gt;CVE-2026-41035&lt;/a&gt;&lt;/strong&gt;: Addresses a count of entries mismatch leading to a use-after-free.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43617.html&quot;&gt;CVE-2026-43617&lt;/a&gt;&lt;/strong&gt;: Resolves authorization bypass via hostname resolution.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43618.html&quot;&gt;CVE-2026-43618&lt;/a&gt;&lt;/strong&gt;: Addresses a second authorization bypass, tracked separately from CVE-2026-43617.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-29518.html&quot;&gt;CVE-2026-29518&lt;/a&gt;&lt;/strong&gt;: Fixes integer overflow information disclosure.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43619.html&quot;&gt;CVE-2026-43619&lt;/a&gt;&lt;/strong&gt;: Addresses a symlink race condition via path-based syscalls.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43620.html&quot;&gt;CVE-2026-43620&lt;/a&gt;&lt;/strong&gt;: Corrects an out-of-bounds array read via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;recv_files()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45232.html&quot;&gt;CVE-2026-45232&lt;/a&gt;&lt;/strong&gt;: Fixes an off-by-one stack out-of-bounds write in HTTP CONNECT proxy response parsing.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;python313-31315&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.python.org/&quot;&gt;python313&lt;/a&gt; 3.13.15&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19672.html&quot;&gt;CVE-2026-19672&lt;/a&gt;&lt;/strong&gt;: Fixes a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tarfile&lt;/code&gt; member that leaves the destination directory and comes back.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-17084.html&quot;&gt;CVE-2026-17084&lt;/a&gt;&lt;/strong&gt;: Addresses Unicode codepoint attributes outside RFC 3454 being considered valid.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-15308.html&quot;&gt;CVE-2026-15308&lt;/a&gt;&lt;/strong&gt;: Resolves quadratic complexity in incremental parsing of long unterminated constructs in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;html.parser.HTMLParser&lt;/code&gt;, exploitable for denial of service.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6879.html&quot;&gt;CVE-2026-6879&lt;/a&gt;&lt;/strong&gt;: Corrects quadratic behavior in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xml.etree.ElementTree.Element&lt;/code&gt; &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;findall()&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;iterfind()&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;find()&lt;/code&gt; when using XPath index predicates on documents with many same-tag siblings.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4360.html&quot;&gt;CVE-2026-4360&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tarfile.TarFile.extract()&lt;/code&gt; not applying the given filter when it extracts a link target from the archive as a fallback.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-11972.html&quot;&gt;CVE-2026-11972&lt;/a&gt;&lt;/strong&gt;: Addresses &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tarfile&lt;/code&gt; seeking a stream continuing past the end of the stream.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-11940.html&quot;&gt;CVE-2026-11940&lt;/a&gt;&lt;/strong&gt;: Resolves a bypass of CVE-2025-4330 where crafted archives could create a symlink pointing outside the destination directory through the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tarfile&lt;/code&gt; data and extraction filters.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-0864.html&quot;&gt;CVE-2026-0864&lt;/a&gt;&lt;/strong&gt;: Corrects line endings in multi-line &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;configparser&lt;/code&gt; values not being normalized to LF+TAB.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-15366.html&quot;&gt;CVE-2025-15366&lt;/a&gt;&lt;/strong&gt;: Fixes NUL, CR and LF characters being accepted in IMAP commands.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;libexpat 2.8.2&lt;/strong&gt;: The bundled libexpat is updated to 2.8.2.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;util-linux-2423&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/pub/linux/utils/util-linux/&quot;&gt;util-linux&lt;/a&gt; 2.42.3&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-76642.html&quot;&gt;CVE-2026-76642&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mount(8)&lt;/code&gt; post-mount hooks executing after an external mount helper fails, allowing privileged operations on the pre-existing target filesystem.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-78410.html&quot;&gt;CVE-2026-78410&lt;/a&gt;&lt;/strong&gt;: Addresses a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mount(8)&lt;/code&gt; time-of-check/time-of-use race on the source path in restricted SUID mode, letting a local attacker redirect a privileged mount or post-mount ownership change.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-78409.html&quot;&gt;CVE-2026-78409&lt;/a&gt;&lt;/strong&gt;: Resolves an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X-mount.subdir&lt;/code&gt; symlink escape from a detached mount tree in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mount(8)&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-78408.html&quot;&gt;CVE-2026-78408&lt;/a&gt;&lt;/strong&gt;: Fixes a file descriptor leak in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nsenter(1)&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;unshare(1)&lt;/code&gt; where descriptors were not created with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;O_CLOEXEC&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;Hostname escape sequence injection&lt;/strong&gt;: An additional fix for CVE-2024-28085 sanitizes the hostname interpolated into the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;wall(1)&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;write(1)&lt;/code&gt; banner headers, which an unprivileged user could otherwise poison via a user namespace hostname.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;tesseract-ocr&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/tesseract-ocr/tesseract&quot;&gt;tesseract-ocr&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88047.html&quot;&gt;CVE-2026-88047&lt;/a&gt;&lt;/strong&gt;: Fixes a stack buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Classify::ReadNormProtos&lt;/code&gt; on a crafted traineddata file.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88048.html&quot;&gt;CVE-2026-88048&lt;/a&gt;&lt;/strong&gt;: Addresses a heap out-of-bounds write and read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;FullyConnected::Forward&lt;/code&gt; via a dimension mismatch.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88049.html&quot;&gt;CVE-2026-88049&lt;/a&gt;&lt;/strong&gt;: Resolves a heap out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;LSTM::Forward&lt;/code&gt; via an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;na_&lt;/code&gt;/gate-matrix dimension mismatch.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88050.html&quot;&gt;CVE-2026-88050&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;UnicharCompress&lt;/code&gt; via unvalidated recoder code values.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88051.html&quot;&gt;CVE-2026-88051&lt;/a&gt;&lt;/strong&gt;: Corrects a heap out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GenericVector&amp;lt;T&amp;gt;::read&lt;/code&gt; via a reserved/size_used mismatch.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88052.html&quot;&gt;CVE-2026-88052&lt;/a&gt;&lt;/strong&gt;: Patches a heap out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;UNICHARSET::load_via_fgets&lt;/code&gt; via a count/insert desynchronization.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88053.html&quot;&gt;CVE-2026-88053&lt;/a&gt;&lt;/strong&gt;: Addresses a heap out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Classify::ReadIntTemplates&lt;/code&gt; via unvalidated counts in a crafted traineddata file.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88054.html&quot;&gt;CVE-2026-88054&lt;/a&gt;&lt;/strong&gt;: Resolves a denial of service via an empty-stack dereference at model load.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-73067.html&quot;&gt;CVE-2026-73067&lt;/a&gt;&lt;/strong&gt;: Fixes a heap out-of-bounds read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SquishedDawg&lt;/code&gt; on a crafted model, already patched in the shipped 5.5.3.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;hplip-3266&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://developers.hp.com/hp-linux-imaging-and-printing&quot;&gt;hplip&lt;/a&gt; 3.26.6&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91097.html&quot;&gt;CVE-2026-91097&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in the HP Linux Imaging and Printing utilities.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91098.html&quot;&gt;CVE-2026-91098&lt;/a&gt;&lt;/strong&gt;: Addresses a security vulnerability in the HP printer and scanner backend components.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91099.html&quot;&gt;CVE-2026-91099&lt;/a&gt;&lt;/strong&gt;: Resolves a security vulnerability in HPLIP’s firmware and device handling code.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91100.html&quot;&gt;CVE-2026-91100&lt;/a&gt;&lt;/strong&gt;: Corrects a security vulnerability in the HPLIP scan backend.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91101.html&quot;&gt;CVE-2026-91101&lt;/a&gt;&lt;/strong&gt;: Patches a security vulnerability in the HPLIP print queue and status handling.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91102.html&quot;&gt;CVE-2026-91102&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in the HPLIP device discovery code.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91103.html&quot;&gt;CVE-2026-91103&lt;/a&gt;&lt;/strong&gt;: Addresses a security vulnerability in the HPLIP model and capability database.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91104.html&quot;&gt;CVE-2026-91104&lt;/a&gt;&lt;/strong&gt;: Resolves a security vulnerability in the HPLIP fax and scan utilities.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91105.html&quot;&gt;CVE-2026-91105&lt;/a&gt;&lt;/strong&gt;: Corrects a security vulnerability in the HPLIP plugin download and verification path.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-91106.html&quot;&gt;CVE-2026-91106&lt;/a&gt;&lt;/strong&gt;: Patches a security vulnerability in the HPLIP status and configuration tools.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;freeipmi-1619&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/chu11/freeipmi&quot;&gt;freeipmi&lt;/a&gt; 1.6.19&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85504.html&quot;&gt;CVE-2026-85504&lt;/a&gt;&lt;/strong&gt;: Fixes a stack-based buffer overflow via malformed Fujitsu SEL long-text responses.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85505.html&quot;&gt;CVE-2026-85505&lt;/a&gt;&lt;/strong&gt;: Addresses a denial of service via a stack-based buffer over-read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ipmi-oem&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85506.html&quot;&gt;CVE-2026-85506&lt;/a&gt;&lt;/strong&gt;: Resolves arbitrary code execution via a stack-based buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ipmi-oem&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85507.html&quot;&gt;CVE-2026-85507&lt;/a&gt;&lt;/strong&gt;: Fixes a stack-based buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_output_dell_system_info_cmc_info&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85508.html&quot;&gt;CVE-2026-85508&lt;/a&gt;&lt;/strong&gt;: Corrects a stack-based buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_output_dell_system_info_cmc_ipv6_info&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85509.html&quot;&gt;CVE-2026-85509&lt;/a&gt;&lt;/strong&gt;: Patches a stack-based buffer overflow when a BMC returns more bytes than requested.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;gvfs-1603&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/gvfs&quot;&gt;gvfs&lt;/a&gt; 1.60.3&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88924.html&quot;&gt;CVE-2026-88924&lt;/a&gt;&lt;/strong&gt;: Fixes the admin backend setting socket ownership after creation rather than before.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-84268.html&quot;&gt;CVE-2026-84268&lt;/a&gt;&lt;/strong&gt;: Addresses the sftp backend not clamping the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;read_reply&lt;/code&gt; count to the requested buffer size.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-84270.html&quot;&gt;CVE-2026-84270&lt;/a&gt;&lt;/strong&gt;: Corrects the mtp backend not validating the read size returned by the device.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;flatpak-1183&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://flatpak.org/&quot;&gt;flatpak&lt;/a&gt; 1.18.3&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-87766.html&quot;&gt;CVE-2026-87766&lt;/a&gt;&lt;/strong&gt;: Fixes a vulnerability in the bundled bubblewrap 0.12.0 sandbox component.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-93676.html&quot;&gt;CVE-2026-93676&lt;/a&gt;&lt;/strong&gt;: Addresses a vulnerability in the bundled xdg-dbus-proxy 0.1.8 filtering component.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libsoup&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/libsoup&quot;&gt;libsoup&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85534.html&quot;&gt;CVE-2026-85534&lt;/a&gt;&lt;/strong&gt;: Fixes libsoup 3 sending more body bytes than nghttp2 requested.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85197.html&quot;&gt;CVE-2026-85197&lt;/a&gt;&lt;/strong&gt;: Resolves a crash in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;on_data_read&lt;/code&gt; after the connection has been destroyed.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-77680.html&quot;&gt;CVE-2026-77680&lt;/a&gt;&lt;/strong&gt;: Corrects a flaw in HTTP Range header processing in libsoup 2.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-77014.html&quot;&gt;CVE-2026-77014&lt;/a&gt;&lt;/strong&gt;: Addresses the same HTTP Range header processing flaw in libsoup 2.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;p11-kit-0265&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.freedesktop.org/software/p11-kit/&quot;&gt;p11-kit&lt;/a&gt; 0.26.5&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18938.html&quot;&gt;CVE-2026-18938&lt;/a&gt;&lt;/strong&gt;: Fixes an overflow when decoding nested attributes.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-13757.html&quot;&gt;CVE-2026-13757&lt;/a&gt;&lt;/strong&gt;: Addresses server-side stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;sssd&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://sssd.io/&quot;&gt;sssd&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-87853.html&quot;&gt;CVE-2026-87853&lt;/a&gt;&lt;/strong&gt;: Fixes cross-user impersonation in the IDP provider by correcting user matching in access token evaluation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;packagekit-140&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.freedesktop.org/software/PackageKit/&quot;&gt;PackageKit&lt;/a&gt; 1.4.0&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19816.html&quot;&gt;CVE-2026-19816&lt;/a&gt;&lt;/strong&gt;: Fixes the dnf5 backend executing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;repo-remove&lt;/code&gt; for simulated transactions.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;curl-8220&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://curl.se/&quot;&gt;curl&lt;/a&gt; 8.22.0&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-13608.html&quot;&gt;CVE-2026-13608&lt;/a&gt;&lt;/strong&gt;: Fixes OpenLDAP SASL authentication bypass.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18924.html&quot;&gt;CVE-2026-18924&lt;/a&gt;&lt;/strong&gt;: Addresses HTTP/2 server push use-after-free.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19931.html&quot;&gt;CVE-2026-19931&lt;/a&gt;&lt;/strong&gt;: Resolves Negotiate ambient user connection reuse.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-80229.html&quot;&gt;CVE-2026-80229&lt;/a&gt;&lt;/strong&gt;: Fixes OpenSSL provider use-after-free.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-80230.html&quot;&gt;CVE-2026-80230&lt;/a&gt;&lt;/strong&gt;: Addresses OpenSSL pinning bypass.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-80255.html&quot;&gt;CVE-2026-80255&lt;/a&gt;&lt;/strong&gt;: Resolves secure cookie attribute bypass with tab character.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-82209.html&quot;&gt;CVE-2026-82209&lt;/a&gt;&lt;/strong&gt;: Fixes domain-scoped PSL domain cookie issue.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;networkmanager&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://networkmanager.dev/&quot;&gt;NetworkManager&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-10805.html&quot;&gt;CVE-2026-10805&lt;/a&gt;&lt;/strong&gt;: Fixes dhclient accepting unsafe characters in URLs and hostnames.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19685.html&quot;&gt;CVE-2026-19685&lt;/a&gt;&lt;/strong&gt;: Addresses 802.1x rejecting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ca-path&lt;/code&gt; for private connections.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;glibc-244&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; 2.44&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6791.html&quot;&gt;CVE-2026-6791&lt;/a&gt;&lt;/strong&gt;: Fixes stack-based buffer clash during tilde expansion in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;wordexp&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6368.html&quot;&gt;CVE-2026-6368&lt;/a&gt;&lt;/strong&gt;: Resolves invalid call to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;free()&lt;/code&gt; when &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;wordexp&lt;/code&gt; is used with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;WRDE_APPEND&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18374.html&quot;&gt;CVE-2026-18374&lt;/a&gt;&lt;/strong&gt;: Fixes a heap buffer overflow in the libio &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ccs=&lt;/code&gt; handling.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19499.html&quot;&gt;CVE-2026-19499&lt;/a&gt;&lt;/strong&gt;: Addresses incorrect right-justification in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;strfmon&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19542.html&quot;&gt;CVE-2026-19542&lt;/a&gt;&lt;/strong&gt;: Resolves an out-of-bounds array write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tdelete&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-77117.html&quot;&gt;CVE-2026-77117&lt;/a&gt;&lt;/strong&gt;: Fixes SHIFT_JISX0213 decoding leaving a pending character set across conversions.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-80489.html&quot;&gt;CVE-2026-80489&lt;/a&gt;&lt;/strong&gt;: Corrects the same pending character reset problem for EUC_JISX0213 decoding.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;exiv2-0289&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://exiv2.org/&quot;&gt;exiv2&lt;/a&gt; 0.28.9&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-68547.html&quot;&gt;CVE-2026-68547&lt;/a&gt;&lt;/strong&gt;: Fixes a security vulnerability in EXIF metadata processing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-68546.html&quot;&gt;CVE-2026-68546&lt;/a&gt;&lt;/strong&gt;: Addresses a security vulnerability in image metadata handling.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-49275.html&quot;&gt;CVE-2026-49275&lt;/a&gt;&lt;/strong&gt;: Resolves a security vulnerability in the metadata library.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;dracut&quot;&gt;&lt;strong&gt;&lt;a href=&quot;hhttps://dracut-ng.github.io/dracut/&quot;&gt;dracut&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6893.html&quot;&gt;CVE-2026-6893&lt;/a&gt;&lt;/strong&gt;: Fixes root code execution via DHCP options command injection.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libpcap-1107&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.tcpdump.org/&quot;&gt;libpcap&lt;/a&gt; 1.10.7&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-0799.html&quot;&gt;CVE-2026-0799&lt;/a&gt;&lt;/strong&gt;: Fixes safe M[] access in the BPF interpreter.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-31912.html&quot;&gt;CVE-2026-31912&lt;/a&gt;&lt;/strong&gt;: Addresses program bounds checking in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pcap_offline_filter()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-31911.html&quot;&gt;CVE-2026-31911&lt;/a&gt;&lt;/strong&gt;: Resolves safe opcode failure handling in the BPF interpreter.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6244.html&quot;&gt;CVE-2026-6244&lt;/a&gt;&lt;/strong&gt;: Fixes division by zero via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pcap_offline_filter()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6554.html&quot;&gt;CVE-2026-6554&lt;/a&gt;&lt;/strong&gt;: Addresses “ja L” looping limit in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pcap_offline_filter()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18313.html&quot;&gt;CVE-2026-18313&lt;/a&gt;&lt;/strong&gt;: Fixes memory leak in rpcapd.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18238.html&quot;&gt;CVE-2026-18238&lt;/a&gt;&lt;/strong&gt;: Addresses RPCAP_MSG_PACKET validation.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;ffmpeg-8&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.ffmpeg.org/&quot;&gt;ffmpeg&lt;/a&gt; 8&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75147.html&quot;&gt;CVE-2026-75147&lt;/a&gt;&lt;/strong&gt;: Fixes OBU size bounding in AV1 RTP keyframe search loop.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75146.html&quot;&gt;CVE-2026-75146&lt;/a&gt;&lt;/strong&gt;: Addresses negative fragment index in DASH demuxer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75145.html&quot;&gt;CVE-2026-75145&lt;/a&gt;&lt;/strong&gt;: Resolves OBU size narrowing to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;long&lt;/code&gt; in AV1 RTP muxer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75144.html&quot;&gt;CVE-2026-75144&lt;/a&gt;&lt;/strong&gt;: Fixes data units larger than RTP payload buffer in VC-2 muxer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75143.html&quot;&gt;CVE-2026-75143&lt;/a&gt;&lt;/strong&gt;: Addresses caller buffer size honoring in librist reader.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75142.html&quot;&gt;CVE-2026-75142&lt;/a&gt;&lt;/strong&gt;: Resolves stream count overflow in MPEG muxer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-75141.html&quot;&gt;CVE-2026-75141&lt;/a&gt;&lt;/strong&gt;: Fixes hvcC NAL array overflow in HEVC demuxer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70632.html&quot;&gt;CVE-2026-70632&lt;/a&gt;&lt;/strong&gt;: Addresses transform-2 output width validation in CineForm decoder.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70631.html&quot;&gt;CVE-2026-70631&lt;/a&gt;&lt;/strong&gt;: Resolves inflate output length check in TIFF decoder.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70630.html&quot;&gt;CVE-2026-70630&lt;/a&gt;&lt;/strong&gt;: Fixes deflate output length check in Screenpresso decoder.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70629.html&quot;&gt;CVE-2026-70629&lt;/a&gt;&lt;/strong&gt;: Addresses uninitialized data on short input in rscc decoder.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-70628.html&quot;&gt;CVE-2026-70628&lt;/a&gt;&lt;/strong&gt;: Resolves signed overflow in DVB subtitle parser capacity check.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66037.html&quot;&gt;CVE-2026-66037&lt;/a&gt;&lt;/strong&gt;: Fixes count_label validation in IAMF parser.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-66036.html&quot;&gt;CVE-2026-66036&lt;/a&gt;&lt;/strong&gt;: Addresses dynamic frame size support in hqdn3d filter.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-65706.html&quot;&gt;CVE-2026-65706&lt;/a&gt;&lt;/strong&gt;: Fixes temp row buffer sizing in swaprect filter.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-65705.html&quot;&gt;CVE-2026-65705&lt;/a&gt;&lt;/strong&gt;: Resolves unneeded variables in floodfill filter.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-65704.html&quot;&gt;CVE-2026-65704&lt;/a&gt;&lt;/strong&gt;: Fixes AC3 trim underflow in Ty demuxer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-65703.html&quot;&gt;CVE-2026-65703&lt;/a&gt;&lt;/strong&gt;: Addresses reference frame handling in TDSC decoder.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64834.html&quot;&gt;CVE-2026-64834&lt;/a&gt;&lt;/strong&gt;: Resolves ASF object size validation in RTP decoder.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64833.html&quot;&gt;CVE-2026-64833&lt;/a&gt;&lt;/strong&gt;: Fixes DTS core_size bounding in SPDIF encoder.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58049.html&quot;&gt;CVE-2026-58049&lt;/a&gt;&lt;/strong&gt;: Addresses DLTA access bounds checking in RASC decoder.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;389-ds-331&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.port389.org/&quot;&gt;389-ds&lt;/a&gt; 3.3.1&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18355.html&quot;&gt;CVE-2026-18355&lt;/a&gt;&lt;/strong&gt;: Fixes heap buffer overflow in the SASL I/O layer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18663.html&quot;&gt;CVE-2026-18663&lt;/a&gt;&lt;/strong&gt;: Addresses pre-authentication double-free via critical Session Tracking control.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-11770.html&quot;&gt;CVE-2026-11770&lt;/a&gt;&lt;/strong&gt;: Resolves pre-auth LDAP filter injection in CleanAllRUV status check.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18453.html&quot;&gt;CVE-2026-18453&lt;/a&gt;&lt;/strong&gt;: Fixes pre-authentication NULL pointer dereference via paged results.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-15722.html&quot;&gt;CVE-2026-15722&lt;/a&gt;&lt;/strong&gt;: Addresses pre-authentication stack buffer overflow via unbounded replica ID parsing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18922.html&quot;&gt;CVE-2026-18922&lt;/a&gt;&lt;/strong&gt;: Resolves stale identity installation following SASL PLAIN authentication.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-19843.html&quot;&gt;CVE-2026-19843&lt;/a&gt;&lt;/strong&gt;: Fixes Cockpit LDAP editor shell command injection.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-76560.html&quot;&gt;CVE-2026-76560&lt;/a&gt;&lt;/strong&gt;: Addresses SELFDN ACI bind-rule evaluator incorrect matching.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;xen-4220_04&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://xenproject.org/&quot;&gt;xen&lt;/a&gt; 4.22.0_04&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-62437.html&quot;&gt;CVE-2026-62437&lt;/a&gt;&lt;/strong&gt;: Fixes memory leak caused by device model IRQ binding.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-79602.html&quot;&gt;CVE-2026-79602&lt;/a&gt;&lt;/strong&gt;: Addresses improper handling of HVM emulation return codes.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-79603.html&quot;&gt;CVE-2026-79603&lt;/a&gt;&lt;/strong&gt;: Resolves TLB flushing not happening before page scrubbing.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;coreutils&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/coreutils/&quot;&gt;coreutils&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56391.html&quot;&gt;CVE-2026-56391&lt;/a&gt;&lt;/strong&gt;: Fixes read buffer overrun in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;uniq -w&lt;/code&gt; in multibyte locales.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-56392.html&quot;&gt;CVE-2026-56392&lt;/a&gt;&lt;/strong&gt;: Addresses heap overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;unexpand -t&lt;/code&gt; for tab values larger than &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SIZE_MAX/16&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;gegl-0472&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gegl.org/&quot;&gt;gegl&lt;/a&gt; 0.4.72&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-18300.html&quot;&gt;CVE-2026-18300&lt;/a&gt;&lt;/strong&gt;: Fixes vulnerability in the RGBE loader for large report files.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;cups-filters&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/OpenPrinting/cups-filters&quot;&gt;cups-filters&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64611.html&quot;&gt;CVE-2026-64611&lt;/a&gt;&lt;/strong&gt;: Fixes infinite-loop CPU-exhaustion denial of service in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cfIEEE1284NormalizeMakeModel&lt;/code&gt; on empty MDL field.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-64612.html&quot;&gt;CVE-2026-64612&lt;/a&gt;&lt;/strong&gt;: Addresses malformed PNG aborting the CUPS image filter process due to missing libpng setjmp recovery.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;alsa&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://alsa-project.org/&quot;&gt;alsa&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-90781.html&quot;&gt;CVE-2026-90781&lt;/a&gt;&lt;/strong&gt;: Fixes a denial of service via an off-by-one stack buffer overflow in the control interface parser.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;cups-2419&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.cups.org/&quot;&gt;cups&lt;/a&gt; 2.4.19&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-87875.html&quot;&gt;CVE-2026-87875&lt;/a&gt;&lt;/strong&gt;: Addresses a heap out-of-bounds read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cupsUTF32ToUTF8()&lt;/code&gt; due to a missing source-length bound, reachable from SNMP supply-description parsing.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;7-zip-2603&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.7-zip.org/&quot;&gt;7-Zip&lt;/a&gt; 26.03&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-58052.html&quot;&gt;CVE-2026-58052&lt;/a&gt;&lt;/strong&gt;: Fixes 7-Zip failing to preserve the Mark-of-the-Web when extracting a crafted archive, which let an extracted file bypass the trust check meant to keep it quarantined.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;gimp-326&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; 3.2.6&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-80101.html&quot;&gt;CVE-2026-80101&lt;/a&gt;&lt;/strong&gt;: Fixes invalid guards on XWD parameters, which could lead to a buffer overflow when loading a crafted XWD file.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;discount-3020&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.pell.portland.or.us/~orc/Code/discount/&quot;&gt;discount&lt;/a&gt; 3.0.2.0&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4833.html&quot;&gt;CVE-2026-4833&lt;/a&gt;&lt;/strong&gt;: Addresses uncontrolled recursion in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;compile()&lt;/code&gt; on deeply nested input, leading to stack exhaustion and a crash. The parser now caps nesting depth, defaulting to 200 and tunable via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--with-recursion&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libx11&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.x.org/releases/X11R7/&quot;&gt;libX11&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88806.html&quot;&gt;CVE-2026-88806&lt;/a&gt;&lt;/strong&gt;: Fixes a heap-based buffer overflow in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XkbGetMap&lt;/code&gt; reply by checking the keysym range in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_XkbReadKeyActions&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libxrender&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://www.x.org/releases/X11R7/&quot;&gt;libXrender&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-88807.html&quot;&gt;CVE-2026-88807&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds write into &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;screen-&amp;gt;subpixel&lt;/code&gt; when a malicious server replies to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XRenderQueryFormat&lt;/code&gt; with a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;numSubpixels&lt;/code&gt; count greater than the number of screens.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;libtpms&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/stefanberger/libtpms&quot;&gt;libtpms&lt;/a&gt;&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-85769.html&quot;&gt;CVE-2026-85769&lt;/a&gt;&lt;/strong&gt;: Fixes a heap out-of-bounds read in TPM2 state unmarshalling via an unchecked &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;block_skip_read()&lt;/code&gt; blocksize.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;librsvg-2624&quot;&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/librsvg&quot;&gt;librsvg&lt;/a&gt; 2.62.4&lt;/strong&gt;:&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Use-after-free with nested Xinclude&lt;/strong&gt;: Fixes a use-after-free when duplicate XML entities appear in nested Xinclude documents.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Users are advised to update to the latest versions to mitigate these vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;September was a busy month for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; with snapshots delivering a steady cadence of desktop, developer, and security improvements. &lt;a href=&quot;https://kde.org/announcements/plasma/6/6.7.5/&quot;&gt;KDE Plasma 6.7.5&lt;/a&gt; and &lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.30.0/&quot;&gt;KDE Frameworks 6.30.0&lt;/a&gt; refined the KDE desktop and added new features, while &lt;a href=&quot;https://kde.org/announcements/gear/26.08.1/&quot;&gt;KDE Gear 26.08.1&lt;/a&gt; stabilized the application suite with fixes across Dolphin, Okular, and Kitinerary. &lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; jumped to 2.44 with Transparent Huge Pages tunables and vectorized math functions, and &lt;a href=&quot;https://llvm.org/&quot;&gt;LLVM&lt;/a&gt; 23.1.1 arrived with important toolchain bugfixes. The &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; progressed through 7.2.4 with extensive CVE coverage across USB, networking, and virtualization subsystems, and &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; settled into its 26.2.2 release. &lt;a href=&quot;https://www.libreoffice.org/&quot;&gt;LibreOffice&lt;/a&gt; advanced to 26.8.0.3 and &lt;a href=&quot;https://github.com/harfbuzz/harfbuzz&quot;&gt;harfbuzz&lt;/a&gt; improved text shaping performance and correctness. The second half of September carried the month’s heaviest security load. &lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; 3.5.1 arrived after an audit of its path handling and daemon protocol that turned up more than 40 vulnerabilities, including a set of chroot and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rrsync&lt;/code&gt; escapes, a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hosts deny&lt;/code&gt; rule that failed open when a hostname could not be resolved, and an unauthenticated handshake denial of service against a daemon module. On the desktop side, the GNOME stack picked up 50.5 across &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-shell&quot;&gt;gnome-shell&lt;/a&gt; and &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;mutter&lt;/a&gt;, &lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; advanced to 3.2.6, &lt;a href=&quot;https://gitlab.gnome.org/GNOME/shotwell&quot;&gt;Shotwell&lt;/a&gt; reached 33.0, &lt;a href=&quot;https://www.gnu.org/software/bash/&quot;&gt;bash-completion&lt;/a&gt; 2.17.0 and &lt;a href=&quot;https://www.gnu.org/software/coreutils/&quot;&gt;coreutils&lt;/a&gt; 9.12 landed alongside a burst of late-month updates across &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; 26.2.3, &lt;a href=&quot;https://pipewire.freedesktop.org/&quot;&gt;PipeWire&lt;/a&gt; 1.6.9, &lt;a href=&quot;https://poppler.freedesktop.org/&quot;&gt;Poppler&lt;/a&gt; 26.09.0, &lt;a href=&quot;https://bluez.org/&quot;&gt;BlueZ&lt;/a&gt; 5.87, and &lt;a href=&quot;https://tukaani.org/xz/&quot;&gt;xz&lt;/a&gt; 5.8.4.&lt;/p&gt;

&lt;h2 id=&quot;slowroll-arrivals&quot;&gt;Slowroll Arrivals&lt;/h2&gt;
&lt;p&gt;Please note that these updates also apply to &lt;a href=&quot;https://en.opensuse.org/openSUSE:Slowroll&quot;&gt;Slowroll&lt;/a&gt; and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;contributing-to-opensuse-tumbleweed&quot;&gt;Contributing to openSUSE Tumbleweed&lt;/h2&gt;
&lt;p&gt;Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list.
For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list &lt;/a&gt;. The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.&lt;/p&gt;

&lt;p&gt;Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, Tumbleweed, KDE, Plasma, GNOME, GStreamer, Mesa, Vulkan, Firefox, glibc, curl, LLVM, harfbuzz, LibreOffice, bubblewrap, ffmpeg, postfix, 389-ds, libpcap, exiv2, pcre2, CVE, kernel, Frameworks, Gear, Nautilus, dracut, coreutils, cups-filters, libarchive, libxml2, xen, rpcbind, libgcrypt, rsync, util-linux, python313, tesseract, ImageMagick, hplip, gvfs, libsoup, p11-kit, sssd, GIMP, Shotwell, bash-completion, PipeWire, poppler, BlueZ, xz&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/30/welcome-osas26-yogyakarta/</guid>
      <title>Welcome to openSUSE Asia Summit in Yogyakarta</title>
      <pubDate>Wed, 30 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/30/welcome-osas26-yogyakarta/</link>
      <author>admin@opensuse.org (openSUSE Asia Summit Team)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/full-news-oo.png" length="816673" type="image/png" />
      <description>The wait is almost over! 🎉 The openSUSE.Asia Summit 2026 will begin on Oct. 3-4 at UIN Sunan Kalijaga, Yogyakarta. On behalf of the organizing committee, we would like to warmly welcome everyone to Yogyakarta and to this year’s Summit. We hope you enjoy the talks, workshops, discussions, and all...</description>
      <content:encoded>&lt;p&gt;The wait is almost over! 🎉&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://events.opensuse.org/conferences/oSAS26&quot;&gt;openSUSE.Asia Summit 2026&lt;/a&gt; will begin on Oct. 3-4 at UIN Sunan Kalijaga, Yogyakarta.&lt;/p&gt;

&lt;p&gt;On behalf of the organizing committee, we would like to warmly welcome everyone to Yogyakarta and to this year’s Summit. We hope you enjoy the talks, workshops, discussions, and all the activities we have prepared for you.&lt;/p&gt;

&lt;p&gt;For those visiting Yogyakarta for the first time, don’t forget to enjoy the city as well. Take some time to explore its food, culture, streets, and atmosphere. Yogyakarta has plenty to offer beyond the conference venue.&lt;/p&gt;

&lt;p&gt;And for those meeting old friends again, we hope this summit becomes a warm opportunity to reconnect, catch up, share stories, and spend some good time together with the community. ❤️&lt;/p&gt;

&lt;p&gt;Let’s make openSUSE.Asia Summit 2026 a memorable gathering!&lt;/p&gt;

&lt;p&gt;Welcome to Yogyakarta, and enjoy the Summit! 🦎💚&lt;/p&gt;
</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/30/kudos-teams/</guid>
      <title>Kudos Now Recognizes Whole Teams</title>
      <pubDate>Wed, 30 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/30/kudos-teams/</link>
      <author>admin@opensuse.org (openSUSE Kudos Team)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/08/kudos.png" length="24102" type="image/png" />
      <description>The openSUSE Kudos recognition platform has a new feature: teams. You can now thank a whole team at once, see who is part of which team, and join or start a team yourself. Why teams Peer-to-peer recognition is at the heart of Kudos, and it works well when the work...</description>
      <content:encoded>&lt;p&gt;The &lt;a href=&quot;https://kudos.opensuse.org&quot;&gt;openSUSE Kudos recognition platform&lt;/a&gt; has a new feature: &lt;strong&gt;teams&lt;/strong&gt;. You can now thank a whole team at once, see who is part of which team, and join or start a team yourself.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/wp-content/uploads/2026/09/kudos-join-team.png&quot; alt=&quot;The new Join Team button in the Kudos header&quot; /&gt;&lt;/p&gt;

&lt;h2 id=&quot;why-teams&quot;&gt;Why teams&lt;/h2&gt;

&lt;p&gt;Peer-to-peer recognition is at the heart of Kudos, and it works well when the work was done by one person. A lot of what happens in openSUSE is not like that, though. A release, an installer, a conference booth or a wiki cleanup is usually the effort of an entire group.&lt;/p&gt;

&lt;p&gt;One piece of feedback kept coming back: when someone wanted to thank a team, the kudos landed on the one or two people they happened to know by name. The rest of the people who did the work got nothing, simply because the person saying thanks could not name them.&lt;/p&gt;

&lt;p&gt;Some contributors are also simply less visible than others. They do not post much, they do not show up in every chat, and their work happens quietly in the background. That does not mean they do less. Recognizing the team as a whole makes sure that thanks reaches them too.&lt;/p&gt;

&lt;h2 id=&quot;what-you-can-do&quot;&gt;What you can do&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Thank a team, or a team and individuals together.&lt;/strong&gt; When giving kudos, teams show up in the recipient picker next to people. You can thank a team on its own, or combine it with individual contributors in the same kudo. That comes in handy because teams rarely work alone: a release team may get help from translators, testers or packagers outside the team, and now one thank-you can include all of them. Team members can thank their own team as well.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;See who is in which team.&lt;/strong&gt; Every team has its own page with its roster, and every profile now shows the teams that person belongs to. Former members stay listed as alumni, so past contributions are not forgotten.&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Join or start a team.&lt;/strong&gt; Click the &lt;strong&gt;Join Team&lt;/strong&gt; button in the header, search for your team, and ask to join. If your team is not there yet, create it right from the same box. No admin approval is needed to start a team; only linking it to a badge goes through an admin (more on that below).&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Invite people.&lt;/strong&gt; Team members can invite other Kudos users by their username. The invitation arrives by email and in the app, and the person joins once they accept.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;/wp-content/uploads/2026/09/kudos-teams-page.png&quot; alt=&quot;The Teams page on Kudos&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Once you are in a team, the button in the header turns into &lt;strong&gt;My Teams&lt;/strong&gt;, and it lets you know when an invitation or a join request is waiting for you.&lt;/p&gt;

&lt;h2 id=&quot;self-managed-teams&quot;&gt;Self-managed teams&lt;/h2&gt;

&lt;p&gt;Teams run themselves. There is no owner and no manager role. Any member can approve people who asked to join, invite others, or tidy up the roster, and anyone can leave at any time. Requests that nobody answers are approved automatically after 14 days, so nobody gets stuck waiting.&lt;/p&gt;

&lt;p&gt;Teams can also be linked with a badge. This is the one step that needs an admin, and for a good reason: a linked badge adds every holder of that badge to the team. If anyone could link any badge, a brand-new team could claim the Tumbleweed contributor badge and instantly “have” hundreds of members who never asked to join. So an admin checks that the badge really belongs to the team before linking it.&lt;/p&gt;

&lt;p&gt;Once an admin links a badge to a team, everyone on the roster gets it, and anyone who later earns the badge through other means is added to the team automatically. Until now, team badges were handed out by hand, one person at a time. Now the team keeps its own roster, and the badge follows.&lt;/p&gt;

&lt;p&gt;Every team page has a badge slot, and for most teams it still reads “Badge: TBD”. Badges live in &lt;a href=&quot;https://github.com/openSUSE/kudos-badges&quot;&gt;openSUSE/kudos-badges&lt;/a&gt; on GitHub, where new ideas and artwork arrive as ordinary pull requests, so a team that wants to fill its slot is only a pull request away. Designing the badge together can be a fun first thing for a new team to do.&lt;/p&gt;

&lt;p&gt;Badges are never taken away when someone leaves a team. A badge records what you did; the team roster shows who is there now.&lt;/p&gt;

&lt;h2 id=&quot;get-started&quot;&gt;Get started&lt;/h2&gt;

&lt;p&gt;Log in to &lt;a href=&quot;https://kudos.opensuse.org&quot;&gt;kudos.opensuse.org&lt;/a&gt;, click &lt;strong&gt;Join Team&lt;/strong&gt;, and find your team or start a new one. Then invite the people you work with, and the next time your team ships something great, thank all of them at once.&lt;/p&gt;

&lt;p&gt;Feedback is welcome, as always. Kudos is developed in the open at &lt;a href=&quot;https://github.com/openSUSE/kudos&quot;&gt;github.com/openSUSE/kudos&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/28/osas-cfh-extended/</guid>
      <title>Deadline Extended Call for Host openSUSE Asia Summit 2027</title>
      <pubDate>Mon, 28 Sep 2026 10:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/28/osas-cfh-extended/</link>
      <author>admin@opensuse.org (openSUSE Asia Summit Team)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2019/10/group.jpeg" length="501469" type="image/jpeg" />
      <description>The openSUSE.Asia Summit Organizing Committee has extended the deadline for the Call for Host to submit proposals for the 2027 Summit. Communities now have until 30 November, 2026 to apply. The extension comes in response to requests from local communities seeking more time to prepare their proposals. This is a...</description>
      <content:encoded>&lt;p&gt;The openSUSE.Asia Summit Organizing Committee has extended the deadline for the Call for Host to submit proposals for the &lt;strong&gt;2027 Summit&lt;/strong&gt;. Communities now have until &lt;strong&gt;30 November, 2026&lt;/strong&gt; to apply.&lt;/p&gt;

&lt;p&gt;The extension comes in response to requests from local communities seeking more time to prepare their proposals. This is a great opportunity to showcase your region and bring the openSUSE community together in your city.&lt;/p&gt;

&lt;p&gt;If your community is interested in hosting the openSUSE.Asia Summit 2027, come and join us at &lt;a href=&quot;https://events.opensuse.org/conferences/oSAS26&quot;&gt;openSUSE.Asia Summit 2026&lt;/a&gt; in Yogyakarta this October. The organizing committee can provide presentation slots for communities interested in hosting the 2027 Summit, giving them an opportunity to introduce their community, city, and vision for the next Summit.&lt;/p&gt;

&lt;p&gt;For more information, visit &lt;a href=&quot;https://news.opensuse.org/2026/07/14/osas-cfh/&quot;&gt;https://news.opensuse.org/2026/07/14/osas-cfh/&lt;/a&gt;.&lt;/p&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/28/leap-161-rc/</guid>
      <title>Try Immutable Mode with openSUSE Leap 16.1 RC</title>
      <pubDate>Mon, 28 Sep 2026 04:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/28/leap-161-rc/</link>
      <author>admin@opensuse.org (Lubos Kocman)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/leap.png" length="10789" type="image/png" />
      <description>Entering RC Phase openSUSE Leap 16.1 has entered the Release Candidate phase. Release Candidate images can be found at get.opensuse.org. We know that people really start testing a new release with the RC, so this is the right time to grab an image and give it a try. Users can...</description>
      <content:encoded>&lt;h3 id=&quot;entering-rc-phase&quot;&gt;Entering RC Phase&lt;/h3&gt;

&lt;p&gt;openSUSE Leap 16.1 has entered the Release Candidate phase. Release Candidate images can be found at &lt;a href=&quot;https://get.opensuse.org/leap/16.1/&quot;&gt;get.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;We know that people really start testing a new release with the RC, so this is the right time to grab an image and give it a try.&lt;/p&gt;

&lt;p&gt;Users can expect that we’ll continue publishing roughly one build a week during the RC phase. Once &lt;a href=&quot;https://www.suse.com/products/server/&quot;&gt;SUSE Linux Enterprise Server&lt;/a&gt; 16.1 announces their Gold Master, we’ll be working toward the Leap 16.1 Gold Master Candidate (GMC).&lt;/p&gt;

&lt;p&gt;Based on feedback from the &lt;a href=&quot;https://en.opensuse.org/Portal:16.0/Retrospective#Release_process&quot;&gt;Leap 16.0 retrospective&lt;/a&gt;, we’ll sync the Leap 16.1 release day with the SLES 16.1 release day, even if that means a slight delay. This way, there is no obvious gap in receiving maintenance updates after the release.&lt;/p&gt;

&lt;p&gt;Details about the schedule can be found in our &lt;a href=&quot;https://en.opensuse.org/openSUSE:Roadmap&quot;&gt;roadmap&lt;/a&gt;.&lt;/p&gt;

&lt;h3 id=&quot;usecase-try-the-new-immutable-mode&quot;&gt;Usecase: Try the new Immutable mode&lt;/h3&gt;

&lt;p&gt;Leap 16.1 is the first Leap release to offer an &lt;strong&gt;Immutable Mode&lt;/strong&gt;, a transactionally updated system with a read-only root filesystem. This is essentially what our users know from Leap Micro, just integrated directly into Leap.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Leap 16.1 in Immutable mode is replacing Leap Micro.&lt;/strong&gt; There won’t be a Leap Micro 6.3 or 7.0; Leap Immutable is the way forward for container and virtual machine hosts, edge devices and anyone who prefers atomic updates with easy rollback.&lt;/p&gt;

&lt;p&gt;The Immutable mode was added to Agama rather recently, which is exactly why we’d like you to try it. Simply boot the usual Leap 16.1 install image and pick the Immutable mode in the installer.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/wp-content/uploads/2026/09/leap161rc-agama-immutable.png&quot; alt=&quot;Agama with Immutable Mode&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Doesn’t agama with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dark theme&lt;/code&gt; look amazing? Once installed, the system is updated with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;transactional-update&lt;/code&gt;, which creates a new snapshot for every update and lets you roll back if something goes wrong.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;sudo transactional-update dup    # update the system into a new snapshot
sudo reboot                      # boot into the new snapshot
sudo transactional-update rollback  # go back if something went wrong
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Additional software is best consumed via containers with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;podman&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;distrobox&lt;/code&gt;, or via &lt;a href=&quot;https://flathub.org/&quot;&gt;Flatpak&lt;/a&gt; on desktops. Packages can still be installed with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sudo transactional-update pkg install &amp;lt;package&amp;gt;&lt;/code&gt;.&lt;/p&gt;

&lt;h3 id=&quot;leap-micro-users-appliances-are-still-here&quot;&gt;Leap Micro users: appliances are still here&lt;/h3&gt;

&lt;p&gt;Users who are used to the Leap Micro images will feel at home. The usual preconfigured appliances can be found in the alternative downloads section at &lt;a href=&quot;https://get.opensuse.org/leap/16.1/&quot;&gt;get.opensuse.org&lt;/a&gt;. This includes the Immutable Self-install image, which is recommended for USB installations, as well as images for KVM/Xen, MS Hyper-V, VMware, Harvester and Cloud, and a fully encrypted raw disk image.&lt;/p&gt;

&lt;p&gt;The appliances can be configured on first boot via &lt;a href=&quot;https://coreos.github.io/ignition/&quot;&gt;Ignition&lt;/a&gt; or &lt;a href=&quot;https://github.com/openSUSE/combustion&quot;&gt;Combustion&lt;/a&gt;, just like Leap Micro.&lt;/p&gt;

&lt;p&gt;Existing Leap Micro 6.2 installations can be migrated to Leap 16.1 in Immutable mode with the &lt;a href=&quot;https://github.com/openSUSE/opensuse-migration-tool&quot;&gt;opensuse-migration-tool&lt;/a&gt;.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;sudo transactional-update shell
# Inside the shell:
zypper in opensuse-migration-tool
opensuse-migration-tool --dry-run # optionally check how it looks
opensuse-migration-tool
exit &amp;amp;&amp;amp; reboot # boot into the new snapshot
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;The tool is still experimental, so please make sure to have a backup and let us know how the migration went.&lt;/p&gt;

&lt;h3 id=&quot;desktops-same-gnome-newer-plasma&quot;&gt;Desktops: Same GNOME, newer Plasma&lt;/h3&gt;

&lt;p&gt;Some users may expect a big GNOME update in Leap 16.1. In fact, &lt;strong&gt;Leap 16.1 ships the same GNOME 48 as Leap 16.0&lt;/strong&gt;, with bug fix updates (gnome-shell 48.8 vs. 48.4 in 16.0).&lt;/p&gt;

&lt;p&gt;Just like in Leap 15.X and the respective SUSE Linux Enterprise 15 service packs, the big GNOME update is planned over two releases.&lt;/p&gt;

&lt;p&gt;Leap 16.0 and 16.1 share the same GNOME major version, and users can expect the next big GNOME update in a future release.&lt;/p&gt;

&lt;p&gt;KDE Plasma users, on the other hand, get a noticeable bump from Plasma 6.4 to &lt;strong&gt;Plasma 6.6&lt;/strong&gt; with Qt 6.11 and KDE Frameworks 6.25.&lt;/p&gt;

&lt;p&gt;LXQt moved from 2.2 to 2.4, and Xfce on Wayland continues with 4.20.&lt;/p&gt;

&lt;h3 id=&quot;whats-new-in-leap-161&quot;&gt;What’s new in Leap 16.1&lt;/h3&gt;

&lt;p&gt;Wondering which version of your favorite package you’ll get in Leap 16.1? Rather than listing a handful of packages here, we’d like to point you to our new &lt;a href=&quot;https://opensuse.github.io/osdiff/&quot;&gt;openSUSE version diff tool&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;It’s a single page comparing source package versions across Leap 16.1, Leap 16.0 and Tumbleweed, including the latest upstream versions from Repology.&lt;/p&gt;

&lt;p&gt;The page republishes itself automatically, so it stays up to date during the whole RC phase and beyond.
You can filter packages by status, e.g. to see what was updated compared to 16.0, or download the data as JSON or CSV.&lt;/p&gt;

&lt;p&gt;The tool grew out of a community discussion at our weekly Release Engineering meeting; read more about it in &lt;a href=&quot;https://news.opensuse.org/2026/09/09/one-page-every-package/&quot;&gt;One Page, Every Package&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Ideas and contributions are welcome at &lt;a href=&quot;https://github.com/openSUSE/osdiff&quot;&gt;github.com/openSUSE/osdiff&lt;/a&gt;.&lt;/p&gt;

&lt;h3 id=&quot;help-us-with-testing&quot;&gt;Help us with testing&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Your feedback is critical at this stage. Help us with testing by following our &lt;a href=&quot;https://en.opensuse.org/Portal:16.1/ManualTesting&quot;&gt;manual test plan&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The plan covers scenarios that are hard to automate in &lt;a href=&quot;https://openqa.opensuse.org/group_overview/139&quot;&gt;openQA&lt;/a&gt;, so every test case marked as done on as many hardware combinations as possible helps us to ship a better release.&lt;/p&gt;

&lt;p&gt;Simply record your result with your openSUSE ID; we intend to award &lt;a href=&quot;https://kudos.opensuse.org&quot;&gt;Kudos&lt;/a&gt; badges to everyone participating in manual testing.&lt;/p&gt;

&lt;p&gt;Alternatively, simply install Leap 16.1 RC, try the Immutable mode, your favorite desktop or your usual server workload, and let us know how it goes.&lt;/p&gt;

&lt;p&gt;Please report any issues on &lt;a href=&quot;https://en.opensuse.org/openSUSE:Submitting_bug_reports&quot;&gt;bugzilla.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Please make sure to check the &lt;a href=&quot;https://en.opensuse.org/openSUSE:Known_bugs_16.1&quot;&gt;Known bugs wiki page&lt;/a&gt; prior to reporting a new bug.&lt;/p&gt;

&lt;p&gt;Thank you for testing and being part of the openSUSE community. Let’s shape Leap 16.1 together!&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Leap 16.1, Release Candidate, Immutable, Leap Micro, transactional-update, Agama installer, GNOME, KDE Plasma, Ignition, Combustion, testing&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/25/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 25 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/25/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. This community blog feed aggregator lists the featured highlights below from Sept. 18 - 24. This week highlights Xiaomi’s MiMo V2.6 AI family, a brightness-flickering fix for VRR on Plasma, two guides to building Flatpaks locally with...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;. This community blog feed aggregator lists the featured highlights below from Sept. 18 - 24.&lt;/p&gt;

&lt;p&gt;This week highlights Xiaomi’s MiMo V2.6 AI family, a brightness-flickering fix for VRR on Plasma, two guides to building Flatpaks locally with Foundry, the history of Madrid’s MAX classroom distribution, AkademyES 2026’s 30/20 anniversary gathering and KDE’s Marknote notebook, a sleep-mode fix for openSUSE Leap, the Flip Clock plasmoid, a weeklybeats track and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;leap-heads-into-release-candidate-phase&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/24/leap-rc/&quot;&gt;Leap Heads Into Release Candidate Phase&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org&quot;&gt;openSUSE News&lt;/a&gt; blog covers &lt;a href=&quot;https://get.opensuse.org/testing/&quot;&gt;openSUSE Leap 16.1&lt;/a&gt; nearing its Release Candidate stage. The release brings major package updates, including KDE Plasma 6.6.4, QEMU 11, MariaDB 12, and PHP 8.5, and the team is asking testers to help find any remaining issues.&lt;/p&gt;

&lt;h2 id=&quot;plasma-68-beta-2-released&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzada-la-segunda-beta-de-plasma-6-8.html&quot;&gt;Plasma 6.8 Beta 2 released&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the releases of the second beta of Plasma 6.8. It points out the improved GTK4 window decorations, a redesigned Flatpak permissions page, and Discover enhancements. This release also continues the public technical preview of the Union theming system.&lt;/p&gt;

&lt;h2 id=&quot;xiaomi-mimo-v26-xiaomi-fully-enters-the-race-for-open-ai-models&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/09/23/xiaomi-mimo-v2-6-a-xiaomi-entra-de-vez-na-disputa-pelos-modelos-abertos-de-ia/&quot;&gt;Xiaomi MiMo V2.6: Xiaomi Fully Enters the Race for Open AI Models&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s&lt;/a&gt; blog introduces Xiaomi’s MiMo V2.6 family, headlined by the trillion-parameter MoE-based MiMo-V2.6-Pro with a 1-million-token window and native text, image, video and audio support. The post details the 42-billion-active-parameter architecture, large-scale reinforcement learning and aggressive API pricing, and notes MIT-licensed weights and RL infrastructure released for the community.&lt;/p&gt;

&lt;h2 id=&quot;kde-express-episode-76-brightness-flickering-with-vrr-adaptive-sync&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/episodio-76-de-kde-express-parpadeo-de-brillo-con-sincronizacion-adaptativa-vrr.html&quot;&gt;KDE Express Episode 76: Brightness Flickering with VRR Adaptive Sync&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents episode 76 of KDE Express, where David Marzal shares a personal fix for brightness flickering with VRR, HDR and adaptive brightness on Plasma. The episode traces the issue to bug 477016 on an AMD RX 580 over DisplayPort and asks listeners with VRR monitors for feedback.&lt;/p&gt;

&lt;h2 id=&quot;building-flatpaks-locally-part-2&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/building-flatpaks-followup/&quot;&gt;Building Flatpaks Locally, Part 2&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; follows up his flatpak-builder guide with a simpler path on GNOME OS using the developer sysext. With &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;foundry init &amp;amp;&amp;amp; foundry build&lt;/code&gt; he shows how projects can be built locally without the manual builder setup.&lt;/p&gt;

&lt;h2 id=&quot;windows-or-linux-the-digital-sovereignty-dilemma-in-madrids-classrooms--episode-6-of-the-podcast-the-era-of-the-distros&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/windows-o-linux-el-dilema-de-la-soberania-digital-en-las-aulas-de-madrid-episodio-6-del-podcast-la-era-de-las-distros.html&quot;&gt;Windows or Linux? The Digital Sovereignty Dilemma in Madrid’s Classrooms – Episode 6 of the Podcast “The Era of the Distros”&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; highlights episode 6 of “La era de las distros,” which explores Madrid’s MAX distribution for schools and Spain’s early-2000s free-software classroom push. Host Lorenzo Carbonell is joined by Jose Quirino Vargas Ibáñez, Ismail Ali and Jesús González-Barahona to discuss digital sovereignty beyond license costs.&lt;/p&gt;

&lt;h2 id=&quot;tiny-wins-for-packagers-end-of-week-update-2026-09-18&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/09/22/tiny-wins/&quot;&gt;Tiny Wins for Packagers: End-of-Week Update (2026-09-18)&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org/&quot;&gt;Open Build Service&lt;/a&gt; blog welcomes new contributor wineee and notes a fix to avoid crashing on build logs for scmsync-related packages. The short update is part of the service’s regular end-of-week roundup for packagers.&lt;/p&gt;

&lt;h2 id=&quot;akademyes-2026-the-most-social-gathering-of-kde-spain-and-free-software-supporters&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/21/akademyes-2026-la-reunion-mas-social-de-kde-espana-y-simpatizantes-del-software-libre/&quot;&gt;AkademyES 2026: The Most Social Gathering of #KDE Spain and Free Software Supporters&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; announces AkademyES 2026, set for October 23-25 at Camping Arco Iris in the Madrid mountains to mark KDE’s 30th and KDE España’s 20th anniversaries. The post outlines lodging, mandatory registration and a call for talks for the community-focused camping event.&lt;/p&gt;

&lt;h2 id=&quot;kdes-markdown-notebook-marknote&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/cuaderno-de-notas-markdown-de-kde-marknote.html&quot;&gt;KDE’s Markdown Notebook, Marknote&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; introduces Marknote, KDE’s Markdown notebook for organizing notes in local .md files under Documents. It covers notebooks with icons and accent colors, rich-text and source editing, wiki-style links, a KRunner plugin and import from KNotes and maildir.&lt;/p&gt;

&lt;h2 id=&quot;sleep-mode-in-opensuse&quot;&gt;&lt;a href=&quot;https://atolstoy.wordpress.com/2026/09/20/%d1%81%d0%bf%d1%8f%d1%89%d0%b8%d0%b9-%d1%80%d0%b5%d0%b6%d0%b8%d0%bc-%d0%b2-opensuse/&quot;&gt;Sleep Mode in openSUSE&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://atolstoy.wordpress.com/tag/opensuse/&quot;&gt;Alexander Tolstoy&lt;/a&gt; details an intermittent resume-from-suspend hang on openSUSE Leap on an Intel 9th-gen system without NVIDIA, which never appeared on Fedora. After ruling out the kernel, he resolved it by disabling and masking &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;power-profiles-daemon&lt;/code&gt; and enabling &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tuned&lt;/code&gt; instead.&lt;/p&gt;

&lt;h2 id=&quot;the-classic-htc-clock-on-your-desktop-flip-clock--plasmoids-for-plasma-6-40&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/el-clasico-reloj-de-htc-en-tu-escritorio-flip-clock-plasmoides-para-plasma-6-40.html&quot;&gt;The Classic HTC Clock on Your Desktop, Flip Clock – Plasmoids for Plasma 6 (40)&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents Flip Clock, the 40th entry in its Plasma 6 plasmoids series, which brings the HTC Sense flip-card clock to the desktop. The widget shows hours and minutes on animated flaps with optional date, weather, 12/24-hour and animation settings, requiring Plasma 6.7 or newer.&lt;/p&gt;

&lt;h2 id=&quot;stolen&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/stolen/&quot;&gt;Stolen!&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; shares his weeklybeats track “Stolen!”, sampling the AI-industry debate with extra polish time on the Dirtywave M8. He describes mimicking an Analog Four filter and volume pulse technique using the M8’s four LFOs and modulator routing.&lt;/p&gt;

&lt;h2 id=&quot;bonsai-2-27b-a-new-metric-for-artificial-intelligence&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/09/19/bonsai-2-27b-uma-nova-metrica-para-a-inteligencia-artificial/&quot;&gt;Bonsai 2 27B: A New Metric for Artificial Intelligence&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s&lt;/a&gt; blog introduces PrismML’s Bonsai 2 27B, a ternary-compressed build of Qwen3.8-27B that shrinks a 54 GB FP16 model to about 5.9 GB while retaining 98.2% performance. The post explains Hadamard rotation, GGUF and MLX variants, up to 262K context and the need for a custom llama.cpp fork.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-220--early-edition&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/09/19/linux-saloon-220-early-edition/&quot;&gt;Linux Saloon 220 | Early Edition&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;Nathan Wolf&lt;/a&gt; posts the Early Edition of Linux Saloon 220, reflecting on a theater outing to the 1986 Transformers movie, browser use in 2026 and mobile trends. The episode also notes retro hardware, GOG’s big-box revival and an upcoming open mic night.&lt;/p&gt;

&lt;h2 id=&quot;let-the-polishing-begin--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/que-comience-el-pulido-esta-semana-en-plasma.html&quot;&gt;Let the Polishing Begin – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s “This Week in Plasma” report, which focuses on polishing Plasma 6.8 ahead of release. With only four open regressions, it lists UI tweaks for Wi-Fi and KWin Overview, Kup backup timing improvements and fixes across Plasma 6.6.7 through 6.9.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed--review-of-the-week-202638&quot;&gt;Tumbleweed – Review of the Week 2026/38&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/09/tumbleweed-review-of-the-week-2026-38/&quot;&gt;Dominique Leuenberger&lt;/a&gt; and &lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/18/opensuse-tumbleweed-revision-de-la-semana-38-de-2026/&quot;&gt;Victorhck&lt;/a&gt; review six Tumbleweed snapshots (0910, 0911, 0912, 0914, 0915 and 0916), headlined by Plasma 6.7.5, Frameworks 6.30 and Gear 26.08.1 followed by security updates for glibc, cups and xz. The roundup also notes Mesa’s Rockchip and Teflon additions, OpenCV’s JPEG XL/AVIF support and kernel 7.2.5.&lt;/p&gt;

&lt;h2 id=&quot;krita-534-and-krita-604-released&quot;&gt;&lt;a href=&quot;https://krita.org/en/posts/2026/krita-5-3-4-released&quot;&gt;Krita 5.3.4 and Krita 6.0.4 Released&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; notes the simultaneous releases of Krita 5.3.4 and 6.0.4, bringing bug fixes across the digital painting suite and video export on Android. The update also drops the unmaintained GIMP XCF import plugin for security reasons.&lt;/p&gt;

&lt;h2 id=&quot;building-flatpaks-locally&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/building-flatpaks-locally/&quot;&gt;Building Flatpaks Locally&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; explains building Flatpaks locally with flatpak-builder distributed as a Flathub Flatpak_org.flatpak.Builder. He walks through installing the builder and building the GNOME icon tool Shaper with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flatpak-builder --user --install&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Tumbleweed&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/24/leap-rc/</guid>
      <title>Leap Heads Into Release Candidate Phase</title>
      <pubDate>Thu, 24 Sep 2026 23:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/24/leap-rc/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/09/leaprc.png" length="11055" type="image/png" />
      <description>The openSUSE Release Team says openSUSE Leap 16.1 is close to its Release Candidate (RC) stage, with general availability planned for November. Leap Release Manager Luboš Kocman told the openSUSE project mailing list that the next build was expected to qualify as the RC. He said it should reach openQA,...</description>
      <content:encoded>&lt;p&gt;The &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE&lt;/a&gt; Release Team says &lt;a href=&quot;https://get.opensuse.org/leap/&quot;&gt;openSUSE Leap&lt;/a&gt; 16.1 is close to its &lt;a href=&quot;https://get.opensuse.org/testing/&quot;&gt;Release Candidate (RC)&lt;/a&gt; stage, with general availability planned for November.&lt;/p&gt;

&lt;p&gt;Leap Release Manager Luboš Kocman told the &lt;a href=&quot;https://lists.opensuse.org/archives/list/project@lists.opensuse.org/&quot;&gt;openSUSE project mailing list&lt;/a&gt; that the next build was expected to qualify as the RC. He said it should reach &lt;a href=&quot;https://openqa.opensuse.org/&quot;&gt;openQA&lt;/a&gt;, which is openSUSE’s automated testing system soon.&lt;/p&gt;

&lt;p&gt;Kocman said recent changes merged into &lt;a href=&quot;https://www.suse.com/products/server/&quot;&gt;SUSE Linux Enterprise Server&lt;/a&gt; (SLES) 16.1 had caused an additional delay.&lt;/p&gt;

&lt;p&gt;The RC build is expect to arrive this week.&lt;/p&gt;

&lt;p&gt;Testers can help by grabbing the latest image from &lt;a href=&quot;https://get.opensuse.org/testing&quot;&gt;get.opensuse.org/testing&lt;/a&gt;, picking a test from the &lt;a href=&quot;https://en.opensuse.org/Portal:16.1/ManualTesting&quot;&gt;Leap 16.1 manual test plan&lt;/a&gt; (high-priority and untried tests help most), and recording their result with their openSUSE username and build number; participants will receive an &lt;a href=&quot;https://kudos.opensuse.org/&quot;&gt;openSUSE Kudos&lt;/a&gt; badge as a thank-you.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://en.opensuse.org/openSUSE:Roadmap#Leap_16.1&quot;&gt;official roadmap&lt;/a&gt; had the RC build set for Sept. 16. The build is now running about a week behind that date.&lt;/p&gt;

&lt;p&gt;The team plans to produce about one build per week during the RC phase to find and fix any remaining release blockers.&lt;/p&gt;

&lt;p&gt;The release team says testing matters most at this stage. Users and contributors can help by:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Running their usual workflows on the RC builds and reporting critical issues to &lt;a href=&quot;https://bugzilla.opensuse.org/&quot;&gt;openSUSE Bugzilla&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;Checking the non-blocking bug list for items assigned to them.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Saved bug queries and known issues are on the &lt;a href=&quot;https://en.opensuse.org/openSUSE:Known_bugs_16.1#Existing_bugs&quot;&gt;openSUSE Known Bugs 16.1 wiki page&lt;/a&gt;, and the full schedule is on the &lt;a href=&quot;https://en.opensuse.org/openSUSE:Roadmap#Leap_16.1&quot;&gt;openSUSE Roadmap&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Leap 16.1 and SLES 16.1 will launch on the same day because of feedback from the &lt;a href=&quot;https://en.opensuse.org/Portal:16.0/Retrospective#Release_process&quot;&gt;Leap 16.0 release retrospective&lt;/a&gt;. Shipping together means Leap users won’t face a gap between the release and the first maintenance updates. Those updates arrive with the SLES 16.1 GA and flow directly to Leap.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-notable-package-updates&quot;&gt;What’s New: Notable Package Updates&lt;/h2&gt;

&lt;p&gt;Leap 16.1 brings a range of desktop, developer, and server updates compared with Leap 16.0:&lt;/p&gt;

&lt;table style=&quot;border-collapse:collapse;margin:1rem auto&quot;&gt;
  &lt;tr&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Package&lt;/th&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Leap 16.0&lt;/th&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Leap 16.1&lt;/th&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://kde.org/plasma-desktop/&quot;&gt;KDE Plasma&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;6.4.2&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;6.6.4&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://develop.kde.org/products/frameworks/&quot;&gt;KDE Frameworks&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;6.16.0&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;6.25.0&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://www.qt.io/&quot;&gt;Qt&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;6.9.1&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;6.11.0&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://www.gnome.org/&quot;&gt;GNOME Shell&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;48.4&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;48.8&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://www.libreoffice.org/&quot;&gt;LibreOffice&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;25.2.5&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;26.2.5&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://pipewire.org/&quot;&gt;PipeWire&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;1.4.6&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;1.6.8&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://networkmanager.dev/&quot;&gt;NetworkManager&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;1.52.0&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;1.54.3&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://www.gnu.org/software/grub/&quot;&gt;GRUB&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2.12&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2.14&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;10.0.13&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;11.0.3&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://podman.io/&quot;&gt;Podman&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;5.4.2&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;5.8.2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://llvm.org/&quot;&gt;LLVM&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;19&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;21&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://www.php.net/&quot;&gt;PHP&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;8.4.24&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;8.5.8&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://mariadb.org/&quot;&gt;MariaDB&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;11.8.8&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;12.3.2&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://www.samba.org/&quot;&gt;Samba&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;4.22.11&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;4.23.10&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;&lt;a href=&quot;https://git-scm.com/&quot;&gt;Git&lt;/a&gt;&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2.51.0&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2.53.0&lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;

&lt;p&gt;KDE users get the biggest jump: two Plasma feature releases and nine Frameworks releases, built on a newer Qt 6.11. On the server and virtualization side, QEMU moves to a new major version, MariaDB jumps to the 12 series, and PHP moves to 8.5.&lt;/p&gt;

&lt;p&gt;There are currently no known release blockers.&lt;/p&gt;

&lt;p&gt;The original announcement and follow-up are in the &lt;a href=&quot;https://lists.opensuse.org/archives/list/project@lists.opensuse.org/thread/KHRHDSARPUQE2N3AT6GGGNEQPF7QIVQF/&quot;&gt;openSUSE project mailing list thread&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Leap&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/18/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 18 Sep 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/18/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. This community blog feed aggregator lists the featured highlights below from Sept. 11 - 17. This week highlights the release of Agama 24 with a two-for-one announcement covering versions 23 and 24, the beta release of Plasma...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;. This community blog feed aggregator lists the featured highlights below from Sept. 11 - 17.&lt;/p&gt;

&lt;p&gt;This week highlights the release of Agama 24 with a two-for-one announcement covering versions 23 and 24, the beta release of Plasma 6.8 along with its first “This Week in Plasma” review, the first bug-fix update of KDE Gear 26.08 plus feature overviews of Kdenlive and Minuet, the Tumbleweed week 37 review and a September ARM update roundup, Intel’s OpenVINO 2026.4.0 release, the openSUSE Kudos report for August, the reveal of the GNOME 51 wallpapers, and a fond farewell to the Linux Hispano comic strip after 1,144 installments.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;introducing-enhanced-distribution-support&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/09/17/enhanced-distribution-support/&quot;&gt;Introducing Enhanced Distribution Support&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org&quot;&gt;Open Build Service&lt;/a&gt; blog introduces Enhanced Distribution Support, a beta feature that gives structure to distribution information through a vendor → distribution → release hierarchy, letting maintainers record what they ship, which repositories and architectures each release is built from, and dated lifecycle milestones. It’s an early, purely descriptive first iteration, and the OBS team is asking distribution maintainers what else they need to be able to describe.&lt;/p&gt;

&lt;h2 id=&quot;openvino-202640-a-new-version-announced&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/09/16/openvino-2026-4-0-nova-versao-anunciada/&quot;&gt;OpenVINO 2026.4.0: A New Version Announced&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s&lt;/a&gt; blog reports on Intel’s OpenVINO 2026.4.0 release, which broadens model support across Intel CPUs, GPUs and NPUs while adding speculative decoding with Multi-Token Prediction. The post also covers EAGLE-3 Tree Drafting, ITT tracing extended to the NPU for VTune, an ASR pipeline for Node.js and idle-model management in the OpenVINO Model Server.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed-arm-updates-in-september&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/16/tw-arm-update/&quot;&gt;Tumbleweed ARM Updates in September&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog covers September’s Tumbleweed updates for the ARM port, led by a security-heavy kernel 7.2.5, glibc 2.44 with its large AArch64 push and QEMU 11.1.1. Raspberry Pi owners get a firmware fix that clears up a Wi-Fi scan error, Rockchip and other SBCs receive MediaTek Wi-Fi kernel fixes, and GIMP 3.2.6, shotwell 33.0 and kbd 2.10.0 land AArch64-specific improvements.&lt;/p&gt;

&lt;h2 id=&quot;gnome-51-wallpapers&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/gnome51-wallpapers/&quot;&gt;GNOME 51 Wallpapers&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; reveals the GNOME 51 wallpaper set, calling the collection evolution rather than revolution as it sticks to its geometric roots. The default is a stylistic touch-up of the GNOME 50 hexagons, images now carry an embedded thumbnail that helps the Appearance panel, and attribution and license data are embedded directly into the files.&lt;/p&gt;

&lt;h2 id=&quot;download-a-random-linux-hispano-comic-strip-in-the-terminal&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/15/descarga-una-tira-aleatoria-de-linux-hispano-en-la-terminal/&quot;&gt;Download a Random Linux Hispano Comic Strip in the Terminal&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; shares a pair of scripts for revisiting the 1,144 Linux Hispano comic strips that Danigm published between 2004 and 2026 after the series came to an end. A Python scraper archived every strip into a GitHub repository, while a Bash script picks a random strip and displays it with feh along with its name and publication date.&lt;/p&gt;

&lt;h2 id=&quot;syslog-ng-repo-for-amazon-linux-2023-updated-to-syslog-ng-version-412&quot;&gt;&lt;a href=&quot;https://peter.czanik.hu/other/syslog-ng-for-amazon-linux-updated-to-4-12/&quot;&gt;Syslog-ng repo for Amazon Linux 2023 updated to syslog-ng version 4.12&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://peter.czanik.hu/&quot;&gt;Peter Czanik&lt;/a&gt; reports that his syslog-ng repository for Amazon Linux 2023 has been updated to version 4.12 after a GitHub request finally prompted an update. He recounts how the repo, first created two years ago, sat untouched due to a lack of feedback despite healthy download numbers from Copr, with Java support and slog disabled as in his other repositories.&lt;/p&gt;

&lt;h2 id=&quot;kudos-august-2026&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/09/15/kudos-august/&quot;&gt;Kudos August 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; blog presents the monthly Kudos report, in which 17 users received 24 kudos and 419 badges were awarded to 251 contributors during August. Bernhard Wiedemann tops the list with five kudos, mostly for his work on Slowroll, and four contributors reached the milestone of 100 Tumbleweed Contributions.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-in-minuet-from-kde-gear-2608-enjoy-shiny-stuff-edition&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/las-novedades-de-minuet-de-kde-gear-26-08-edicion-enjoy-shiny-stuff.html&quot;&gt;What’s New in Minuet from KDE Gear 26.08, “Enjoy Shiny Stuff” Edition&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; closes its KDE Gear 26.08 feature series with Minuet, the music education app that trains the ear through interval, chord, scale and rhythm exercises. Minuet debuts a new interface that works on both desktops and phones, with a reworked home page and navigation sidebar, exercises shown as cards and a search field that filters by translated names and descriptions.&lt;/p&gt;

&lt;h2 id=&quot;software-freedom-day-2026&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/dia-de-la-llibertat-del-programari-2026.html&quot;&gt;Software Freedom Day 2026&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the Dia de la Llibertat del Programari (Software Freedom Day) celebration organized by Caliu on September 19 at the Espai Jove La Fontana in Barcelona, an event where the KDE community is usually well represented. The post translates the Catalan agenda, listing three talks on teaching computing with values, bootstrapping a self-managed forge with Haz-CLI and security on GNU/Linux.&lt;/p&gt;

&lt;h2 id=&quot;happy-programmers-day&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/09/13/feliz-dia-do-programador-2/&quot;&gt;Happy Programmer’s Day&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s&lt;/a&gt; blog celebrates Programmer’s Day, which falls on the 256th day of the year and explains why the number 256, or 2^8, matters in computing. The post thanks developers for turning coffee into software, errors into lessons and ideas into innovation.&lt;/p&gt;

&lt;h2 id=&quot;innit&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/innit/&quot;&gt;Innit&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner&lt;/a&gt; shares how he produced the tune “Innit” for his weeklybeats 2026 project on the Elektron Analog Four rather than his usual Dirtywave M8. After years of avoiding them, he finally learned the box’s performance macros, which bundle up to five track parameters onto a single knob and make live performance far less stressful than pre-programming a sequence.&lt;/p&gt;

&lt;h2 id=&quot;plasma-68-beta-released--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzado-plasma-6-8-beta-esta-semana-en-plasma.html&quot;&gt;Plasma 6.8 Beta Released – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s weekly Plasma development report covering the 6.8 beta. Kup joins Plasma as its backup system, clipboard and MIME-action settings become far clearer, the on-screen keyboard button now behaves as expected on lock and login screens, and KWin gains support for the Wayland commit_timing protocol.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-219--butterbian-and-butterknife-distribution-exploration&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/09/12/linux-saloon-219-butterbian-and-butterknife-distribution-exploration/&quot;&gt;Linux Saloon 219 | Butterbian and ButterKnife Distribution Exploration&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;Nathan Wolf&lt;/a&gt; posts episode 219 of the Linux Saloon podcast, covering activities around the Vintage Computer Fest Midwest. The episode gathers user experiences with the Butterknife and Butterbian distributions through polls and links out to upcoming events and participant projects.&lt;/p&gt;

&lt;h2 id=&quot;first-update-of-kde-gear-2608&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/primera-actualizacion-de-kde-gear-26-08.html&quot;&gt;First Update of KDE Gear 26.08&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents the first update of KDE Gear 26.08, released almost a month after the feature set, bringing more stability, better translations and small improvements. It lists resolved issues across apps, libraries and widgets, including an arrow-orientation fix in KDE Connect, room-map handling in Kongress and an unexpected crash when saving documents in Okular.&lt;/p&gt;

&lt;h2 id=&quot;plasma-68-beta-released&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzada-la-beta-de-plasma-6-8.html&quot;&gt;Plasma 6.8 Beta Released&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; reports that the beta of Plasma 6.8 has been released and highlights changes drawn from its changelog, from the new Hanabi wallpaper replacing Waterfall in Breeze and Nepali calendar support to GTK4 window decoration fixes, an AppStream Preview backend in Discover and a QML rewrite of DrKonqi’s coredump viewer. It encourages users to install the beta and report bugs to help polish the release.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed--review-of-the-week-202637&quot;&gt;&lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/09/tumbleweed-review-of-the-week-2026-37/&quot;&gt;Tumbleweed – Review of the Week 2026/37&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://dominique.leuenberger.net/blog/&quot;&gt;Dominique Leuenberger&lt;/a&gt; and &lt;a href=&quot;https://victorhckinthefreeworld.com/2026/09/11/opensuse-tumbleweed-revision-de-la-semana-37-de-2026/&quot;&gt;Victorhck&lt;/a&gt; review the four Tumbleweed snapshots (0904, 0907, 0908 and 0909) of week 2026/37, which delivered Linux kernel 7.2.3 and 7.2.4, LibreOffice 26.8.0.3, QEMU 11.1.1, zypper 1.14.101 and more.&lt;/p&gt;

&lt;h2 id=&quot;tiny-wins-for-packagers-end-of-week-update&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/09/11/tiny-wins/&quot;&gt;Tiny Wins for Packagers: End-of-Week Update&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org/&quot;&gt;Open Build Service&lt;/a&gt; blog shares its end-of-week “Tiny Wins” update, which shipped a fix preventing a second click on the repository dropdown after an autocomplete selection and ensured the generated SBOM includes the SPDX V3 createdBy field. It also reports that build.opensuse.org served 22.8 million HTTP requests and produced 2.38 million package builds over the last seven days.&lt;/p&gt;

&lt;h2 id=&quot;agama-releasing-version-24&quot;&gt;&lt;a href=&quot;https://agama-project.github.io/blog/2026/09/11/agama-24&quot;&gt;Agama: Releasing Version 24&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://agama-project.github.io/blog/&quot;&gt;Agama blog&lt;/a&gt; announces Agama 24 in a two-for-one post covering versions 23 and 24 after a stabilization phase focused on testing and polish. Language, keyboard and time zone now share a single searchable form, network connections can be bound to devices through a sortable device table, and JSON search sections gained much more expressive device matching.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, KDE, Plasma, Tumbleweed&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/09/16/tw-arm-update/</guid>
      <title>Tumbleweed ARM Updates in September</title>
      <pubDate>Wed, 16 Sep 2026 12:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/09/16/tw-arm-update/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/sbc.png" length="36607" type="image/png" />
      <description>There were a few software package updates for openSUSE Tumbleweed ARM this month with snapshots reaching the ARM port. September’s snapshots of the ARM port carried the Linux kernel to a security-heavy 7.2.5. There was a jump to glibc 2.44 with its large AArch64 push, and QEMU reaching 11.1.1. Raspberry...</description>
      <content:encoded>&lt;p&gt;There were a few software package updates for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; &lt;a href=&quot;https://www.arm.com/&quot;&gt;ARM&lt;/a&gt; this month with snapshots reaching the &lt;a href=&quot;https://www.arm.com/&quot;&gt;ARM&lt;/a&gt; port.&lt;/p&gt;

&lt;p&gt;September’s snapshots of the &lt;a href=&quot;https://www.arm.com/&quot;&gt;ARM&lt;/a&gt; port carried the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; to a security-heavy 7.2.5. There was a jump to &lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; 2.44 with its large &lt;a href=&quot;https://en.wikipedia.org/wiki/AArch64&quot;&gt;AArch64&lt;/a&gt; push, and &lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; reaching 11.1.1. &lt;a href=&quot;https://www.raspberrypi.com/&quot;&gt;Raspberry Pi&lt;/a&gt; owners get a firmware fix that clears up a Wi-Fi scan error, the &lt;a href=&quot;https://networkmanager.dev/&quot;&gt;Networking Stack&lt;/a&gt; received security patches, and &lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; 3.2.6 brings AArch64-specific fixes.&lt;/p&gt;

&lt;h2 id=&quot;raspberry-pi&quot;&gt;Raspberry Pi&lt;/h2&gt;

&lt;p&gt;This month’s &lt;a href=&quot;https://github.com/raspberrypi/firmware&quot;&gt;raspberrypi-firmware&lt;/a&gt; update prevents the spurious “-52” error message that could appear during Wi-Fi scans (&lt;a href=&quot;https://bugzilla.opensuse.org/show_bug.cgi?id=1215134&quot;&gt;bsc#1215134&lt;/a&gt;), so scanning for networks is quieter on boards where the firmware reported a phantom failure. The &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 7.2.4 update fixed a memory leak in the brcmfmac driver’s SDIO control path, which reduces memory pressure over long uptimes on the onboard Cypress Wi-Fi chip used across recent Pi models.&lt;/p&gt;

&lt;h2 id=&quot;rockchip--other-sbcs&quot;&gt;Rockchip &amp;amp; Other SBCs&lt;/h2&gt;

&lt;p&gt;Owners of Rockchip and other single-board computers get kernel fixes for the MediaTek Wi-Fi chipsets that many boards ship with, including headroom fixes for USB/SDIO transfers on mt7925 and EEPROM size validation on the mt7915 and mt7996 drivers, which protects against malformed device data (bsc#1012628). &lt;a href=&quot;https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git&quot;&gt;kernel-firmware-qcom&lt;/a&gt; adds DSP firmware for the Qualcomm x1e80100, nord and qcs8300 platforms, improving modem, DSP and graphics support. &lt;a href=&quot;https://dracut.wiki.kernel.org/index.php/Main_Page&quot;&gt;dracut&lt;/a&gt; now includes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;leds-qcom-lpg&lt;/code&gt; in the aarch64 DRM module set, keeping RGB indicator LEDs working when booting from an initrd. Finally, &lt;a href=&quot;https://wireless.wiki.kernel.org/en/developers/regulatory&quot;&gt;wireless-regdb&lt;/a&gt; enables 320 MHz channels for Hong Kong, updates South Africa’s rules, and drops the 60 GHz DFS flag for Togo.&lt;/p&gt;

&lt;h2 id=&quot;imx--nxp&quot;&gt;i.MX &amp;amp; NXP&lt;/h2&gt;

&lt;p&gt;Developers working with NXP hardware gain the imx8mp-evk machine type in &lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; 11.1.1, which emulates the i.MX 8M Plus Evaluation Kit and makes it easier to test software for that platform without physical hardware. The kernel 7.2.3 update fixed the mxs-dcp crypto engine’s source scatterlist length access and improved the Data Co-Processor security block on i.MX System on Chips that use it for accelerated encryption. These changes make NXP hardware slightly more accessible to both emulation and crypto workloads.&lt;/p&gt;

&lt;h2 id=&quot;aarch64-virtualization-uefi--toolchain&quot;&gt;aarch64 Virtualization, UEFI &amp;amp; Toolchain&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.qemu.org/&quot;&gt;QEMU&lt;/a&gt; 11.1.1&lt;/strong&gt; is the virtualization highlight of the month, advancing the emulator with Universal Flash Storage emulation for Write Booster and Host-Initiated Defragmentation based on the UFS 4.1 specification, plus &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vhost-host-user&lt;/code&gt; support for offloading real-time clock handling through &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virtio-rtc&lt;/code&gt;. The ARM targets gain new architectural CPU features, and the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virt&lt;/code&gt; board can now specify cache topology. The ARM-specific fixes include a regression test and boundary-case fix for the SVE2 &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;whilewr&lt;/code&gt;/&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;whilerw&lt;/code&gt; instructions and a fix for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;arm_gicv3&lt;/code&gt; kconfig selection, and openSUSE disables GCS linker validation in the spec to keep the aarch64 build working.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt; 2.44&lt;/strong&gt; delivers the strongest AArch64 additions in months. On targets with the Guarded Control Stack extension, glibc now locks all GCS operations, including status, write-on-shadow-stack and push-to-shadow-stack, immediately after enabling GCS with an ENFORCED or OVERRIDE policy, closing a window where a process could still mutate its own shadow stack. Special-case paths for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;log&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;exp&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sin&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cas&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sinh&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cosh&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;asinh&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;acosh&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;atanh&lt;/code&gt; are vectorized for both SVE and AdvSIMD, and vector &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;powr&lt;/code&gt; variants are added, which speeds up floating-point-heavy code on capable Cortex-X and Neoverse cores.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/tianocore/edk2&quot;&gt;ovmf&lt;/a&gt;&lt;/strong&gt; advances to edk2-stable202608, refreshing the UEFI firmware that backs the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;qemu-uefi-aarch64&lt;/code&gt; subpackage. The update adds AArch64 host test coverage across SecurityPkg, CryptoPkg, PrmPkg, DynamicTablesPkg, MdeModulePkg and MdePkg, plus UnitTestFrameworkPkg support for GCC AArch64, which strengthens firmware quality assurance for arm64 virtual machines. The EFI Memory Attributes Protocol workaround is dropped because &lt;a href=&quot;https://www.gnu.org/software/grub/&quot;&gt;GRUB2&lt;/a&gt; now supports the protocol, so booting stays compatible with the cleaner firmware behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/openSUSE/sdbootutil&quot;&gt;sdbootutil&lt;/a&gt;&lt;/strong&gt; improved its systemd-boot handling with a new status command, parallel test execution, a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--repair&lt;/code&gt; parameter for cleanup, and better reporting of entries with missing files. The update prevents duplicate entries on non-snapper systems, keeps the exit status of sdbootutil calls intact, and avoids writing the recovery PIN to the journal, which is a meaningful privacy improvement for systems using PCR-based secure boot.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK4&lt;/a&gt; 4.22.5&lt;/strong&gt; fixes a build failure on 32-bit ARM and repairs 32-bit Vulkan image builds, so the toolkit and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gskvulkanimage&lt;/code&gt; both compile cleanly on armv7. A Wayland session crash in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gdk_wayland_toplevel_remove_from_session()&lt;/code&gt; and a memory buffer fix round out the release for desktop users on ARM.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://llvm.org/&quot;&gt;LLVM&lt;/a&gt; 23.1.1&lt;/strong&gt; arrives as a bugfix release for the 23.1.0 series, remaining API and ABI compatible while dropping the obsolete i586 build patch.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; 3.2.6&lt;/strong&gt; carries the first AArch64-specific wins for the image editor. The clipboard brush and pattern maximum size is bumped to 8192 on AArch64 as well, matching the ceiling that x86-64 and PPC64 have had since the 3.2.0 release candidates, so larger brushes and patterns survive clipboard round-trips on ARM desktops.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://wiki.gnome.org/Apps/Shotwell&quot;&gt;shotwell&lt;/a&gt; 33.0&lt;/strong&gt; makes the jump from the 0.32 series with a full port to &lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK4&lt;/a&gt; (requiring at least 4.22), a reworked printing flow, and fixes for the fullscreen toolbar auto-hide and disappearing slideshow icons. The release replaces its dedicated authentication helper with a small localhost web server for publishing, adds a “peek password” toggle to the Piwigo flow and fixes setting desktop backgrounds.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kbd-project.org/&quot;&gt;kbd&lt;/a&gt; 2.10.0&lt;/strong&gt; extends the console stack with XKB support: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;loadkeys&lt;/code&gt; can now generate console keymaps from XKB data, import XKB compose tables and handle XKB group switching, modifier handling, virtual console switching and keypad/editing remaps.&lt;/p&gt;

&lt;h2 id=&quot;snapshots-at-a-glance&quot;&gt;Snapshots at a Glance&lt;/h2&gt;

&lt;table style=&quot;border-collapse:collapse;margin:1rem 0&quot;&gt;
  &lt;tr&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Snapshot&lt;/th&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Kernel&lt;/th&gt;
    &lt;th style=&quot;border:1px solid #ccc;padding:6px 10px;text-align:left&quot;&gt;Headline changes&lt;/th&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2026-09-08&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;7.2.3&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;glibc 2.44 with AArch64 GCS and SVE/AdvSIMD math, QEMU 11.1.1 with imx8mp-evk, Raspberry Pi firmware Wi-Fi scan fix&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2026-09-12&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;7.2.4&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;edk2-stable202608 with AArch64 host tests, dracut aarch64 LED module, GTK4 32-bit ARM build fix, LLVM 23.1.1&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;2026-09-14&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;7.2.5&lt;/td&gt;
    &lt;td style=&quot;border:1px solid #ccc;padding:6px 10px&quot;&gt;kernel security batch (Tegra241 CMDQV, iommufd, nvmet, Bluetooth RFCOMM, PCI, rndis_host), GIMP 3.2.6 with AArch64 fixes, shotwell 33.0, kbd 2.10.0&lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;

&lt;h2 id=&quot;arm-resources&quot;&gt;ARM Resources&lt;/h2&gt;
&lt;p&gt;For ARM-specific discussions and support, subscribe to the &lt;a href=&quot;https://lists.opensuse.org/archives/list/arm@lists.opensuse.org/&quot;&gt;openSUSE ARM mailing list&lt;/a&gt; and check the &lt;a href=&quot;https://en.opensuse.org/openSUSE:ARM&quot;&gt;openSUSE ARM wiki&lt;/a&gt; for device support information, image downloads, and documentation. New and existing ARM users can also join the &lt;a href=&quot;https://web.libera.chat/?channel=#opensuse-arm&quot;&gt;openSUSE ARM IRC channel&lt;/a&gt; for real-time help.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, ARM, Tumbleweed, Raspberry Pi, Rockchip, Jetson, SBC, AArch64, glibc, QEMU, UEFI, kernel, Mesa, GIMP, shotwell, kbd, CVE, snapper&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

  </channel>
</rss>

